Building Software

Engineering Fundamentals for the Agent Era

Contents Section 8, Security

Protecting Data in Transit and at Rest

Mistakes to catch in review

  1. TLS certificate verification disabled in a client to get past an error.

  2. Home-made encryption, a hardcoded key or a reused initialization vector.

  3. An encryption key stored next to the data it protects.

  4. Database exports and backups left unencrypted in a publicly readable storage bucket.

How data moves securely between systems, and how it stays protected where it is stored.

Topics

Encryption in Transit
TLS on every connection, certificate validation, and mutual TLS between services.
Encryption at Rest
Disk, database and field-level encryption, and which threats each one actually addresses.
Key Management
Where keys live, who can use them, envelope encryption and rotation.
Hashing, Signing and MACs
Tools for integrity and authenticity, and when each one is the right choice.
Using Vetted Cryptography
Relying on well-reviewed libraries, algorithms and modes instead of designing cryptography yourself.

You understand it when you can

  • Explain what TLS protects, what it does not, and what certificate validation adds.
  • Choose between hashing, encryption and signing for three stated needs, and justify each choice.
  • Describe envelope encryption and how it allows key rotation without re-encrypting all the data.

Drill

An agent wrote a client for a partner API with certificate verification turned off 'for local testing', and encrypts stored API keys with a key defined as a constant in the same file. Find what an attacker on the network and an attacker who reads the repository can each do.

Start here

Watch

TLS Handshake Explained - Computerphile

Mike Pound, 2020. 17-minute explainer.

Walks through how client and server agree keys and how the certificate proves the server's identity, which shows what you give up by disabling certificate verification.

Watch

Crypto 101

Laurens Van Houtven, 2013. 46-minute talk.

PyCon 2013 introduction that builds from block and stream ciphers to hashes, MACs and key exchange, showing how naive constructions break and why hashing, MACs and encryption each have a separate job.

Read

Real-World Cryptography

David Wong, 2021.

A practitioner's map of which primitive to use for which job (authenticated encryption, MACs, signatures, key exchange, TLS), written for engineers rather than mathematicians.

Serious Cryptography: A Practical Introduction to Modern Encryption

Jean-Philippe Aumasson, 2024, 2nd edition.

Explains authenticated encryption, hash functions, randomness and TLS's strengths and limits in enough depth that you can spot a reused IV or a home-made scheme.

Primary sources