Cryptography Basics
Hashing, encryption and signatures: what to use, and never building your own.
Backend Engineer track
Junior
Write correct code, ship small changes safely, ask good questions.
- Base64An encoding of bytes as text; not encryption.
- Don't Roll Your Own CryptoUse vetted libraries; homemade cryptography is almost always broken.
- Encryption in TransitEncrypting data as it travels, with TLS.
- Hashing vs Encryption vs EncodingA one-way fingerprint vs reversible with a key vs just a different format.
Mid-level
Own a feature end to end without hand-holding.
- Cryptographic Hash (SHA-256)A hash where finding collisions is infeasible.
- CryptographyThe math of keeping data secret and verifying it.
- Digital SignatureProving who created data and that it hasn't been changed.
- Encryption at RestEncrypting stored data on disk.
- HMACA keyed hash proving a message came from someone holding the secret.
- Public-Key CryptographyA public key encrypts or verifies; a private key decrypts or signs.
- Secure Random NumbersCryptographically secure randomness for tokens and keys.
- Symmetric EncryptionOne shared key both encrypts and decrypts, as with AES.
Senior
Own a system, its failure modes, and its trade-offs.
- End-to-End EncryptionOnly the communicating users can read the data, not the server.
- Envelope EncryptionEncrypting data with a data key, then encrypting that key with a master key.
- Key Management (KMS)Generating, storing, rotating and controlling access to keys.
- Nonce / IVA value used once so encrypting the same data gives different output.
- Timing AttackLeaking secrets through how long comparisons take.
Staff
Shape how many teams build, across systems.
Nothing here yet.
Principal
Set technical direction for the organization.
- Post-Quantum CryptographyAlgorithms designed to resist attacks from quantum computers.
Data Engineer track
Junior
Build and fix pipelines from clear specs; write correct SQL.
- Base64An encoding of bytes as text; not encryption.
- Don't Roll Your Own CryptoUse vetted libraries; homemade cryptography is almost always broken.
- Encryption in TransitEncrypting data as it travels, with TLS.
- Hashing vs Encryption vs EncodingA one-way fingerprint vs reversible with a key vs just a different format.
Mid-level
Own pipelines and models end to end, including their quality.
- Cryptographic Hash (SHA-256)A hash where finding collisions is infeasible.
- CryptographyThe math of keeping data secret and verifying it.
- Digital SignatureProving who created data and that it hasn't been changed.
- Encryption at RestEncrypting stored data on disk.
- HMACA keyed hash proving a message came from someone holding the secret.
- Public-Key CryptographyA public key encrypts or verifies; a private key decrypts or signs.
- Secure Random NumbersCryptographically secure randomness for tokens and keys.
- Symmetric EncryptionOne shared key both encrypts and decrypts, as with AES.
Senior
Design the platform's storage, processing and modeling choices.
- End-to-End EncryptionOnly the communicating users can read the data, not the server.
- Envelope EncryptionEncrypting data with a data key, then encrypting that key with a master key.
- Key Management (KMS)Generating, storing, rotating and controlling access to keys.
Staff
Shape how the whole organization produces and uses data.
Nothing here yet.
Principal
Set data strategy and architecture across the company.
Nothing here yet.
Frontend Engineer track
Junior
Build UI that works, ship small changes safely, ask good questions.
- Base64An encoding of bytes as text; not encryption.
- Don't Roll Your Own CryptoUse vetted libraries; homemade cryptography is almost always broken.
- Encryption in TransitEncrypting data as it travels, with TLS.
- Hashing vs Encryption vs EncodingA one-way fingerprint vs reversible with a key vs just a different format.
Mid-level
Own a feature end to end without hand-holding.
- Cryptographic Hash (SHA-256)A hash where finding collisions is infeasible.
- CryptographyThe math of keeping data secret and verifying it.
- Digital SignatureProving who created data and that it hasn't been changed.
- Public-Key CryptographyA public key encrypts or verifies; a private key decrypts or signs.
- Secure Random NumbersCryptographically secure randomness for tokens and keys.
- Symmetric EncryptionOne shared key both encrypts and decrypts, as with AES.
Senior
Own an app's architecture, performance, and failure modes.
- End-to-End EncryptionOnly the communicating users can read the data, not the server.
Staff
Shape how many teams build, across apps.
Nothing here yet.
Principal
Set technical direction for the organization.
Nothing here yet.