What is encryption? A plain-English guide
Encryption protects your UPI payments, WhatsApp chats and course videos. Here's how it works, what keys do, and what encryption can and can't protect.
On this page 16 sections
- Encryption in one sentence
- A simple example: the shifted alphabet
- The key is the secret, not the method
- Two families of encryption
- Symmetric encryption: one shared key
- Asymmetric encryption: a pair of keys
- Where encryption protects you
- In transit
- At rest
- End to end
- What encryption does not do
- Encryption, hashing and encoding are different things
- Keys are where things usually go wrong
- Why this matters for education businesses
- Key takeaways
- Frequently asked questions
Encryption turns readable data into scrambled ciphertext that only someone holding the right key can turn back into the original. It quietly protects your UPI payments, WhatsApp chats and course logins, both while data travels and where it is stored. What it can't do is protect what is shown on a screen, or stop someone with legitimate access from copying it.
This guide explains how encryption works, where it protects you and, just as importantly, where it doesn't. No maths required.
Encryption in one sentence
Encryption turns readable information into scrambled data that only someone holding the right key can turn back into its original form.
A few terms make the rest of this guide easier:
- Plaintext is the original, readable data: a message, a file, a video.
- Ciphertext is the scrambled version. To anyone without the key, it looks like random noise.
- The algorithm, also called a cipher, is the recipe for scrambling and unscrambling.
- The key is a secret value that controls the recipe. Same recipe, different key, completely different ciphertext.
Turning plaintext into ciphertext is encryption; turning it back is decryption. In short:
plaintext + key → encrypt → ciphertext
ciphertext + key → decrypt → plaintext
A simple example: the shifted alphabet
One of the oldest known ciphers, traditionally credited to Julius Caesar, shifts every letter forward by a fixed number of places. With a shift of three, A becomes D, B becomes E, and so on. The word UPSC becomes XSVF.
Here the algorithm is "shift each letter forward" and the key is "3". Anyone who knows both can reverse it. The weaknesses are obvious. There are only 25 useful shifts, so an attacker can try them all in a minute. Patterns survive too: whichever letter is most common in the message becomes the most common letter in the ciphertext, just under a different name.
Modern encryption follows the same basic idea, an algorithm plus a secret key, with two big differences. The number of possible keys is so large that trying them all is physically impossible, and the scrambling is so thorough that no patterns from the original survive.
The key is the secret, not the method
You might assume the safest encryption is the one nobody knows about. Cryptographers believe the opposite. In the 1880s, the Dutch cryptographer Auguste Kerckhoffs argued that a system should stay secure even if everything about it except the key is public. That principle still guides the field.
The algorithms that protect banks, governments and messaging apps today, such as AES, are fully published. Researchers around the world have spent decades trying to break them, and their survival is exactly why they are trusted. Think of a good lock: its design can be printed in a catalogue, and it still won't open without your key.
The practical lesson: be wary of any product whose security depends on a secret, home-made cipher rather than a published, well-studied one. Home-made algorithms are almost always weaker than the standards.
Two families of encryption
Symmetric encryption: one shared key
The same key locks and unlocks the data. Symmetric encryption is fast enough to protect entire disk drives and live video streams, so it does most of the heavy lifting. AES is the best-known example. The catch is getting the key safely to the other person in the first place.
Asymmetric encryption: a pair of keys
Each person or server has two mathematically linked keys. The public key can be shared with anyone; the private key never leaves its owner. Data locked with the public key can only be unlocked with the matching private key. RSA and elliptic-curve cryptography are the common examples. Asymmetric encryption solves the key-sharing problem, but it is much slower.
In practice, most systems use both: asymmetric cryptography to agree on a secret key, then symmetric encryption for the actual data. Our guide to symmetric vs asymmetric encryption explains how that partnership works.
Where encryption protects you
Encryption shows up in three main places, and each protects against something different.
In transit
Data moving across a network, say from your phone to a server, can be encrypted in transit. This is what HTTPS does. It stops anyone along the way, such as whoever runs the Wi-Fi in a PG hostel, a café or a self-study library, from reading or altering what you send.
At rest
Data sitting on a disk, in a database or in a backup can be encrypted at rest. Most modern phones encrypt their storage by default, and laptops offer tools like BitLocker and FileVault. If a device is lost or a backup drive is stolen, the data stays unreadable without the key.
End to end
With end-to-end encryption, only the sender's and recipient's devices hold the keys. The service in the middle carries the messages but cannot read them. WhatsApp and Signal work this way. Compare that with ordinary in-transit encryption, where the connection is protected but the service itself can read the data once it arrives.
What encryption does not do
Encryption is powerful, but it is not a force field. It has clear limits:
- It doesn't hide everything. Even when content is encrypted, metadata such as who contacted whom, when, and how much data moved is often visible.
- It can't protect data after decryption. Anything shown on a screen can be photographed or recorded. This is the core reason video piracy survives even strong encryption.
- It is only as strong as the key. If a key is derived from a weak password, attackers guess the password rather than attack the cipher.
- It doesn't stop authorised people. Someone with legitimate access can still copy, forward or misuse whatever they can see.
Encryption, hashing and encoding are different things
These three terms are often mixed up, even by technical teams.
| Aspect | Encryption | Hashing | Encoding |
|---|---|---|---|
| Reversible? | Yes, with the key | No, it is one-way | Yes, by anyone |
| Purpose | Keep data secret | Create a fingerprint to verify data or store passwords | Change the format of data so systems can handle it |
| Examples | AES, ChaCha20 | SHA-256; bcrypt and Argon2 for passwords | Base64, URL encoding |
Two practical consequences follow. First, Base64 is not security: anyone can decode it in seconds. Second, passwords should never be stored encrypted, let alone as plain text. They should be hashed with a slow, salted algorithm designed for passwords. If a website can email you your old password, it is storing it in a reversible form, and that is a warning sign. Our guide to encoding vs encryption vs hashing goes further.
Keys are where things usually go wrong
Well-established algorithms are rarely the weak point. Key handling is. Common mistakes include:
- hard-coding keys inside a mobile app, where anyone who unpacks the app can find them;
- committing keys to a code repository, sometimes a public one;
- storing keys on the same server, or in the same database, as the data they protect;
- never rotating keys, so a single leak exposes years of data.
It's the digital equivalent of buying the best safe on the market and taping the key to its door. Mature teams keep keys in dedicated key-management services or hardware security modules, limit who and what can use them, and rotate them on a schedule.
Why this matters for education businesses
A coaching institute handles more sensitive data than it might think: students' names, phone numbers and addresses, payment records, sometimes identity documents, and paid course content that took years to build. Encryption in transit and at rest is now a baseline expectation, not a premium feature.
In India it is becoming a legal expectation as well. The Digital Personal Data Protection Rules, 2025 list encryption, alongside obfuscation, masking and tokenisation, among the minimum security safeguards expected of organisations that handle personal data. Most of the Rules' obligations, including these safeguards, take effect in May 2027; our DPDP compliance checklist covers the rest. This article is general information, not legal advice.
For paid video, encryption is the starting point rather than the finish line. It protects lectures on their way to a student's device, but once a lecture is decrypted and playing, it can be recorded or filmed like anything else on a screen. Our guide to how encrypted data gets exposed covers the routes attackers take instead of breaking the cipher.
Key takeaways
- Encryption scrambles data so that only someone with the right key can read it.
- Trusted algorithms are public; the security lies in keeping the key secret.
- Symmetric encryption is fast; asymmetric encryption solves key sharing. Real systems use both.
- Know which protection you have: in transit, at rest or end to end.
- Encryption can't protect what is shown on a screen, and it is only as strong as your key management.
Encryption is less mysterious than it looks: a public recipe, a secret key and a lot of careful engineering around them. Knowing the basics helps you ask better questions of any app, vendor or platform that promises your data is "encrypted". Encrypted where, with what, and who holds the keys?
Frequently asked questions
What is encryption in simple words?
Encryption is a way of scrambling information so that only someone with the right key can read it. The scrambling follows a published recipe, called an algorithm, and a secret key controls the result. Without the key, the scrambled data looks like random noise. With it, the original message, file or video comes back exactly as it was.
What are the two main types of encryption?
Symmetric encryption uses one shared secret key to lock and unlock data; it is fast, and AES is the standard example. Asymmetric encryption uses a pair of keys, a public key anyone can use and a private key only the owner holds; RSA and elliptic-curve cryptography are examples. Most real systems, including HTTPS, use both together.
What is the difference between encryption and hashing?
Encryption is reversible: anyone with the right key can turn the ciphertext back into the original data. Hashing is one-way: it produces a fixed-length fingerprint that can't be turned back into the input. Encryption keeps data secret, while hashing verifies data and protects stored passwords, which should always be hashed with a slow, salted algorithm rather than encrypted.
Can encrypted data be hacked?
Modern encryption used properly isn't broken by guessing keys. Encrypted data is exposed in other ways: a weak password behind the key, a key left in an app or a code repository, a buggy implementation, or an attack on a device after the data has been decrypted. That is why key handling and device security matter as much as the algorithm.