Can you tell me the difference between coding, encryption and hashing, and why they are important?
Let's begin with what coding, encryption, and hashing mean and their importance to IT security. Encoding - to encode something is to communicate a message so that the receiver will clearly understand. Hashing - is an integrity method to validate data. Encryption makes data unreadable by anyone except those who know the secret shared key. All three are important to enable security at every level. If an interviewer asks about coding standards, he's looking for these codes.....Encoding - Base64, UTF-8, ASCII, Hashing - SHA1, SHA256, SHAKE256, and Encryption - AES, Blowfish, and RSA.
"I have a thorough understanding of encoding, hashing, and encryption. I know that with encoding, I need to be mindful of the standards that are used for the receiver and sender since every receiver will not support the same standards. For hashing, my main purpose is to secure the storage of passwords. As far as encryption, I like to make sure that whomever I send an encrypted message to has the capability and secret key to decrypt my message. This is a safe and secure way to communicate with others who are the intended party to your message."
"The way I see it is that encoding, hashing, and encryption are used together to keep our information safe and out of the hands of hackers, and not intended for unauthorized parties. The purpose of a base64 encoded message to an application is to hash the integrity of that message so it can be verified by the receiver. My practice has always been to follow the industry code standards set for all three. They are:
o Encoding standards: Base64, UTF-8, and ASCII
o Encryption algorithms: AES, Blowfish, and RSA.
o Hashing algorithms: SHA1, SHA256, and SHAKE256"
Knowing the difference between coding, encryption, and hashing is very important if you want to get past the first round of interviews. This is a common question used to weed out junior-level IT Security candidates. As a qualified cyber security professional, you should be able to answer this question easily. Start by describing each of these techniques used to protect the organization's information. Your answer should also include specific codes each technique employs. This will convince the interviewer you're qualified for the position.
Unlock all 47 Cyber Security questions
Prepare for technical scenarios and security assessments that interviewers prioritize.
Get Started