What is encryption? Keys, hashes and checksums
Encryption transforms readable information into ciphertext that can be recovered with the right key. Its purpose is to keep data confidential during transfer or storage. Hashing and checksums solve different problems: their output is not decrypted to recover the original message. Confusing these operations can lead to a false sense of security.
Keys and the encryption process
An encryption algorithm combines plaintext with a key to produce ciphertext. In symmetric encryption, the parties share a secret key. In asymmetric systems, a public key and a corresponding private key have different roles. The algorithm, operating mode, key quality and key storage all matter. Saying that a file is “encrypted” says little about its security if the password is easy to guess or the key is sent in the same unprotected message. Modern applications should use established protocols and authenticated encryption rather than an improvised series of text conversions.
How hashes and checksums differ
A cryptographic hash produces a fixed-size digest of data; it is not an encrypted copy of the input. A SHA-256 digest can help compare a downloaded file with a trustworthy publisher’s stated digest. That comparison checks equality, but does not hide the file. Password storage needs specialised password-hashing methods with salts and adjustable computational cost. CRC32 is useful for detecting accidental transmission errors, but is not an authentication mechanism against deliberate changes. MD5 and SHA-1 are unsuitable for new uses requiring collision resistance. NIST describes its transition away from SHA-1.
Two common examples
To share a confidential document, choose a trusted application that encrypts and authenticates the file, and communicate the passphrase through a separate protected channel. The recipient can recover the content with the right key. To check a downloaded archive, instead calculate its hash and compare it with a value obtained from an authentic publisher page. These are different workflows: the hash does not protect the archive from being read. If a website displays Base64 text, anyone can decode it without a secret key; encoding is not encryption.
Limits to remember
TLS protects data in transit between endpoints, but it does not guarantee that either endpoint itself is trustworthy. Malware on a device, a disclosed key or a weak recovery process can defeat otherwise sound cryptography. When selecting an online text tool, identify whether the selected operation encrypts, hashes or merely encodes. Do not paste private documents or credentials into an unfamiliar service just because its button says “secure”. Verify how data is processed and retained before using it.
