Why It Matters
Half the "encrypted" text in CTFs is just encoded. Confusing these three costs hours. Learn the difference once.
1. Encoding — NOT security
Purpose: represent data in another format (transport/compatibility), not hide it.
Reversible without a key — anyone decodes.
- Base64 SGVsbG8=, Base32 (A–Z, 2–7), Hex 48656c6c6f, URL %20.
"Encrypted" with no mention of a key → probably just encoding.
2. Encryption — reversible WITH A KEY
Hide data so only the key holder can read it. - Symmetric (one key): AES, ChaCha20. Asymmetric (key pair): RSA, ECC.
3. Hashing — ONE-WAY
A fixed-length fingerprint you cannot reverse. SHA-256 for integrity; bcrypt/argon2 for passwords (intentionally slow); MD5/SHA-1 are broken.
How are hashes "cracked"? Not reversed — guessed: hash dictionary words and compare (hashcat/john). That's why salting and slow algorithms matter.
Cheat sheet
| Key? | Reversible? | Example | |
|---|---|---|---|
| Encoding | no | yes, by anyone | Base64, Hex |
| Encryption | yes | yes, with key | AES, RSA |
| Hashing | no | no | SHA-256, bcrypt |
Practice: the Base32, ROT47, XOR, Atbash labs.