Every defence on this page has a specific, understandable reason it works, and understanding why is what turns "use a strong password" from advice you're told into something you can actually calculate for yourself.
The simplest possible cipher: shift every letter along the alphabet by a fixed amount. Type a message and pick a shift.
There are only 25 possible shifts, ever. That means a computer (or even a patient human) can just try every single one and instantly spot which one reads as real English.
This message was encoded with a secret shift. Find it.
A substitution cipher (each letter mapped to a completely different, random letter) has 26! possible keys, brute force genuinely is not realistic here. But English letters are not used equally often, and that pattern survives encryption.
This is exactly the same combinatorics idea from earlier work, applied to something you actually use every day. Pick a password style and watch worst-case crack time explode.
1 billion guesses per second, realistic for modern password-cracking hardware.
This is a real, working cipher, not an analogy. It uses XOR, the same logic gate from earlier, applied byte by byte between your message and a key. Type both in and watch it actually encrypt, then watch the exact same key decrypt it straight back.
Symmetric encryption is fast and simple, but both sides need the identical secret key before they can communicate at all. If you've never met the other person, for example buying something from a website you've never visited before, how do you agree on a secret key over a connection that might itself be intercepted? Sending the key itself would be exactly as risky as sending the unencrypted message. This exact problem is what asymmetric encryption solves.
The toy XOR cipher above uses a short, guessable key. Real symmetric encryption (AES) uses 128 or 256-bit keys instead, using the exact same keyspace idea from the password section: a 256-bit key has 2256 possible values, so large that brute-forcing it would take vastly longer than the age of the universe, even at trillions of guesses per second.
The padlock analogy: imagine an open padlock anyone can snap shut (the public key), but only one specific physical key can open it again (the private key). You can hand out copies of the open padlock to the entire world. Nobody needs a shared secret in advance, they just lock their message with your public padlock, and only you can unlock it.
If you've seen hash tables elsewhere, you've seen a hash function used purely for speed, mapping data to array slots. This is a completely different use of the exact same idea: a one-way function used to protect passwords, where the entire point is that it cannot be reversed. Type something below, this is real SHA-256, computed genuinely in your browser, not a simulation.
| Encryption | Hashing | |
|---|---|---|
| Reversible? | Yes, with the right key (as you saw above) | No, deliberately one-way, there is no key that reverses it |
| Purpose | Protect data in transit or storage, while still needing it back later | Verify something without ever needing the original back, e.g. checking a password is correct without storing it |
| Real example | HTTPS traffic, encrypted files | Password storage, verifying a download hasn't been corrupted or tampered with |
Two users pick the exact same password. Watch what their stored hashes look like, first without a salt, then with one, and this time the salts themselves are genuinely random, generated fresh, not fixed demo values.
A salt is just a random string, generated using a cryptographically secure random number generator (not an ordinary "random" function, which can be predictable), a fresh one for every single password stored, never reused between users. It gets stuck onto the front of the password before hashing, then stored right alongside the resulting hash, in plain view, it isn't secret at all. Its job isn't to hide anything, it's purely to make sure identical passwords never produce identical hashes. Real systems typically use salts of 16 bytes (128 bits) or more, this demo uses a short one purely so it fits on screen.
Attackers don't have to guess your password live. They can precompute the hash of every common password once, then just look up a stolen hash instantly. This table below is real, genuinely precomputed with the same SHA-256 used above.
Cryptography is one layer. Real systems combine several defences, because no single one covers every threat from the previous page.