Skip to content

Encryption & TLS

Encryption scrambles data so only authorized parties can read it. TLS (Transport Layer Security) encrypts data in transit between client and server.


TypeWhat It ProtectsExamples
In TransitData moving over the networkHTTPS (TLS), VPN, SSH
At RestData stored on diskDatabase encryption, file encryption

Both are needed. Encrypting the database doesn’t help if someone intercepts the API response.


sequenceDiagram
participant Client as 📱 Browser
participant Server as 🖥️ Server
Client->>Server: ClientHello (supported TLS versions, ciphers)
Server->>Client: ServerHello (chosen TLS version, cipher, certificate)
Client->>Client: Verify certificate (CA signature check)
Client->>Server: Pre-master secret (encrypted with server's public key)
Client->>Server: ✅ Finished (encrypted)
Server->>Client: ✅ Finished (encrypted)
Note over Client,Server: 🔒 Secure symmetric encryption established

What TLS provides:

  • Authentication — you’re talking to the real server (not an imposter)
  • Encryption — no one can read the data in transit
  • Integrity — data hasn’t been tampered with

AspectHTTPHTTPS
EncryptionNone (plain text)Full (TLS)
Port80443
PerformanceFaster (no handshake)Slightly slower (TLS overhead)
SEOPenalized by GooglePreferred by Google
Trust❌ Anyone can intercept✅ Verified by CA
Typical overhead—~5-10% CPU, one extra round trip

In practice, you don’t do TLS in your application code. You terminate TLS at a reverse proxy (Nginx, ELB, CloudFront):

flowchart LR
Client["📱 Client"] -->|"🔒 HTTPS"| LB["Load Balancer<br/>(TLS Termination)"]
LB -->|"🔓 HTTP (internal)"| App["App Server"]
LB -->|"🔓 HTTP (internal)"| Cache["Cache"]
style Client fill:#7c3aed,color:#fff
style LB fill:#059669,color:#fff
style App fill:#6366f1,color:#fff

  • TLS adds CPU overhead (encryption) and one round trip (handshake).
  • Use TLS termination at the load balancer — app servers get plain HTTP internally.
  • Certificate management is operational overhead (use Let’s Encrypt for free automated certs).
  • Never send sensitive data (passwords, tokens) without TLS.

  • Encryption at rest = data is scrambled on disk (database encryption).
  • Encryption in transit = data is scrambled while traveling (HTTPS/TLS).
  • TLS handshake verifies the server’s identity and establishes encryption.
  • Always use HTTPS. Terminate TLS at the load balancer, not the app server.