Urgent.News

What's breaking now, across thousands of outlets.

Tech

Client-Side vs. Server-Side Encryption: Architecture, Keys, and Trade-Offs

Client-side and server-side encryption protect data differently. Learn how key ownership determines who can actually access your encrypted information.

Client-Side vs. Server-Side Encryption: Architecture, Keys, and Trade-Offs

Client-side encryption and server-side encryption are two distinct methods of securing data between users' devices and a server. Client-side encryption refers to the process where data is encrypted on the user's device before being sent to the server. This approach is foundational to concepts like end-to-end encryption and zero-knowledge services, providing maximum privacy and control to users.

The data remains in an unreadable ciphertext format while it travels over the internet, and only the intended recipient can decrypt it using their own unique key.

On the other hand, server-side encryption involves encrypting data on the server after it has been received. While this method can provide some level of security, it also means the service provider has access to the decryption key. This could potentially allow them to access the data if they choose to, posing a risk compared to client-side encryption.

The client-side encryption method is widely used in social messaging apps and non-custodial crypto wallets, where users' privacy and security are paramount. It ensures that even if a server is compromised, the attacker is left with meaningless ciphertext, unable to decipher the actual content. However, client-side encryption does come with the burden of key management, as users must securely store their encryption keys to prevent unauthorized access.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Tech

A free, keyless Remote Jobs API I built to stop scraping job boards (5 sources, one call)

Building something that needs to know "which jobs are out there right now" keeps hitting the same wall: every remote job board is a different scrape, a different HTML layout, a different rate limit…

  • Free, keyless Remote Jobs API eliminates scraping need
  • Normalizes remote roles from Remotive, RemoteOK, Jobicy, WeWorkRemotely, Hacker News
  • Single endpoint returns normalized job objects with company, salary, apply URL

How to Extract Tailwind CSS Configs and Figma Tokens from Any Site in 1 Click

Every developer and designer has been there: you stumble upon a beautifully designed website and want to reverse-engineer its design tokens or inspect how its typography, color palette, and utility…

  • Token Inspector tool extracts Tailwind CSS configs and Figma tokens from any website in one click
  • Scans DOM and stylesheets to locate CSS variables and inline SVG elements
  • Operates entirely on client side, ensuring privacy and security

More from Monday 5 October →