2026-10-01
| Concept | Question | Example |
|---|---|---|
| Authentication | Who are you? | Logging in with a password |
| Authorization | What can you do? | Admin vs. regular user permissions |
Note
These are often confused. Authentication proves identity. Authorization grants access. They are not the same thing.
Authentication: Showing your ID at the door.
Authorization: Being allowed into the VIP section.
You can be authenticated (ID is valid) but not authorized (not on the VIP list).
Users are terrible at passwords:
123456, password, pet names, birthdaysThe most common password in 2023 was still 123456.
| Attack | How it works |
|---|---|
| Phishing | Trick the user into entering their password on a fake site |
| Brute force | Try every possible combination |
| Credential stuffing | Use leaked passwords from other breaches |
| Shoulder surfing | Physically watch someone type |
| Data breaches | Steal the password database directly |
\[\text{Keyspace} = (\text{character set size})^{\text{password length}}\]
| Password type | Keyspace | Time to brute force 1 |
|---|---|---|
| 8 lowercase letters | \(26^8 \approx 200\) billion | Minutes |
| 8 mixed + symbols | \(95^8 \approx 6.6\) quadrillion | Days |
| 12 mixed + symbols | \(95^{12} \approx 5.4 \times 10^{23}\) | Millions of years |
Takeaway: Length wins. Every character you add multiplies the keyspace.
People have wanted to send secret messages for thousands of years.
Caesar Cipher (~50 BC): Shift each letter by a fixed number.
Enigma Machine (1920s–1940s): Electromechanical rotor cipher used by Nazi Germany. Far more complex, but built on the same idea.

Every cipher from Caesar to Enigma shares the same problem:
Both sides need the same key.
This is the key distribution problem.
For symmetric encryption to work, you had to meet your friend in a dark alley and agree on the secret key without anyone watching.
This worked for militaries. They had couriers, diplomatic pouches, locked briefcases.
But then the internet happened.
You send your credit card number to Amazon every day.
You never met Jeff Bezos in a parking garage to exchange a secret key.
So how does that work?
This is the question that Diffie, Hellman, and RSA set out to answer.
Diffie-Hellman (1976) and RSA (1977) solved the key distribution problem.
The idea:
You publish your public key to the world. Anyone can send you a secret message. Only you can read it.
Fun fact
GCHQ (the UK’s intelligence agency) discovered the same idea in 1973 (four years earlier). But it was classified, so Diffie, Hellman, and RSA got the credit.
A one-way function is easy to compute forward, but practically impossible to reverse.
RSA relies on this. Your public key is derived from two huge primes multiplied together (hundreds of digits). Recovering those primes from the product is computationally infeasible.
Why “computationally infeasible” and not “truly impossible”?
Because no one has proven that one-way functions can’t be reversed efficiently.
This is the P vs NP problem: one of the seven Millennium Prize Problems (worth $1,000,000).
Most computer scientists believe P ≠ NP. But nobody has proven it.
Your password arrived safely.
Now the server needs to store it. But not with encryption. If someone steals the database and the key, they can decrypt everything.
We need something one-way: a function that verifies “is this the right password?” without ever being able to recover the original.
That’s hashing.
Real companies. Real breaches. Real incompetence.
| Company | Year | What they did wrong |
|---|---|---|
| RockYou | 2009 | Stored 32 million passwords in plaintext |
| 2012 | Used unsalted SHA-1 hashes, 6.5M cracked | |
| Adobe | 2013 | Used reversible encryption, 153M exposed |
These were not small startups. These were companies with millions of users.
If you hash passwords without a salt:
cat123 = same hashThis is a rainbow table: a massive lookup table of password-hash mappings.
Hashing without salt is barely better than plaintext.
A salt is a random value generated per user, prepended to the password before hashing.
Same password, different salt = different hash.
Rainbow tables become useless; the attacker would need a separate table for every possible salt.
bcrypt is designed to be slow on purpose.
If a system requires both a password AND a security question to log in, is that Multi-Factor Authentication?
No.
Both are “something you know.” That’s two methods, one factor.
MFA requires methods from different factor
| Factor | What it means |
|---|---|
| Something you know | Information you’ve memorized |
| Something you have | A physical object you possess |
| Something you are | A biometric trait unique to you |
Multi-Factor Authentication = combining two or more of these different factors.
Two methods, same factor (NOT MFA):
Two different factors (MFA):
The categories matter more than the count.
