Encoding vs encryption vs hashing
TL;DR
Encoding, encryption and hashing get mixed up constantly. Encoding is reversible with no secret (it’s not security). Encryption is reversible with a key (confidentiality). Hashing is one-way with no key (integrity and passwords).
What they are
Three different jobs that look similar because they all turn data into something unreadable-looking:
| Reversible? | Needs a key? | For | |
|---|---|---|---|
| Encoding (base64, hex, URL) | Yes, by anyone | No | Safe transport of data |
| Encryption (AES, RSA) | Yes, with the key | Yes | Confidentiality |
| Hashing (SHA-256, bcrypt) | No | No | Integrity, passwords |
Why it matters
The mistakes follow from the confusion. Base64 is not encryption — anyone can decode it, so it protects nothing. Passwords should be hashed (with a salt and a slow algorithm like bcrypt), never encrypted or encoded. Spotting “they encoded it and thought it was safe” is a genuinely common finding.