Encrypting Data - CompTIA Security+ SY0-701 - 1.4 — Transcript
Full transcript
- 0:02if you need to protect data that you're
- 0:03storing on an SSD a hard drive or any
- 0:06other type of storage device then you'll
- 0:08need to work on encrypting all of this
- 0:10stored data sometimes you'll hear this
- 0:12referred to as encrypting data at rest
- 0:15this includes not just individual files
- 0:17that you might have on these storage
- 0:19devices but in some cases everything
- 0:22that's on the storage devices using full
- 0:24dis or volume level encryption in the
- 0:26Windows operating system you may be
- 0:28using bit Locker to Lish this if you're
- 0:31using Macos you may be using file Vault
- 0:34and other operating systems have other
- 0:36ways for encrypting everything on a
- 0:38single volume you might also need to
- 0:40encrypt a single file that is on a
- 0:42system and not the entire volume in
- 0:45Windows you can use EFS this stands for
- 0:47the encrypting file system it's a file
- 0:50level encryption that's built into the
- 0:51NTFS file system and if you're using Mac
- 0:54OS Linux or even Windows there are many
- 0:57third-party utilities that can perform a
- 0:59a similar function in Windows you would
- 1:02look at the properties of a file or
- 1:03folder and inside the advanced
- 1:05attributes you can select encrypt
- 1:08contents to secure data to enable
- 1:11EFS a lot of the data that we use online
- 1:14is stored in a database and of course
- 1:16there are different techniques to be
- 1:18able to protect the data that's inside
- 1:20of these database files for example you
- 1:23may be able to configure transparent
- 1:25encryption this uses a symmetric key to
- 1:28encrypt everything that might be in that
- 1:30database and you would need to perform
- 1:32an encryption or decryption of that data
- 1:35each time the information is pulled from
- 1:37the database some of the information in
- 1:39your database might not be private or
- 1:41sensitive so you might have some data
- 1:43inside of the database that is protected
- 1:46or encrypted and other data which is
- 1:48still available in plain text here's an
- 1:51example of a table inside of a database
- 1:54this is an employee database that has
- 1:56employee ID numbers first names last
- 1:59names names and Social Security numbers
- 2:02of course you could encrypt the entire
- 2:04database by applying a symmetric key so
- 2:07that all of this data is now encrypted
- 2:09and you can see we have no idea what
- 2:12part of this may have anything to do
- 2:14with an employees name their ID number
- 2:16or their social security number but of
- 2:19course there's overhead involved in
- 2:21being able to view this information and
- 2:23every time we need to search through the
- 2:25entire database we would effectively
- 2:27need to decrypt all of the data Within
- 2:29that single database one way to avoid
- 2:32some of that overhead is to only encrypt
- 2:34a certain type of data in the database
- 2:37in this example we're performing column
- 2:39level encryption where the employee ID
- 2:42the first name and the last name are all
- 2:44displayed in plain text and if you
- 2:46needed to search for a name or search
- 2:48for an ID you can perform this very
- 2:50quickly without having to decrypt any
- 2:52other type of data but if you needed
- 2:54access to a person's social security
- 2:56number you would either need to decrypt
- 2:58the entire column or that single record
- 3:00to be able to gain access to that
- 3:02data another common place to perform
- 3:05this encryption is when we're sending
- 3:07data across the network we want to be
- 3:09sure that everything we're sending
- 3:10between two devices is protected and if
- 3:12someone does tap into this connection
- 3:14and view that data they wouldn't be able
- 3:16to make sense of any of those details
- 3:19for example you're probably using a
- 3:20browser right now to watch this video
- 3:22and all of the communication that's
- 3:24taking place in your browser is most
- 3:26likely using https which means that
- 3:28everything Travers ing the network is
- 3:30encrypted if you need to connect
- 3:32different sites to each other or need to
- 3:34connect individuals for remote access we
- 3:37commonly would use a VPN to provide this
- 3:39encryption this stands for virtual
- 3:41private Network and it effectively
- 3:43creates an encrypted tunnel where you
- 3:45can send all information into the tunnel
- 3:47to the other side and anything within
- 3:49that tunnel is going to be encrypted
- 3:52this is commonly used with client-based
- 3:54vpns using SSL or TLS and if you're
- 3:57connecting two sites together we
- 3:59commonly we use use IPC to provide that
- 4:01VPN
- 4:02connectivity to be able to have a
- 4:05successful encryption and decryption
- 4:07both sides must be using the same
- 4:09encryption algorithms this is the
- 4:11formula that's used to not only provide
- 4:14the encryption process but it also
- 4:16provides you with the way to decrypt
- 4:18that data on the other side generally
- 4:21both sides would agree from the very
- 4:23beginning to use one or more encryption
- 4:25algorithms so that both sides know
- 4:28exactly what to expect when information
- 4:30is received many times the enduser
- 4:33doesn't see the details of the
- 4:34algorithms that are being used but they
- 4:36know that they're using a particular
- 4:38application and they want to be sure the
- 4:40person on the other side is using a
- 4:42similar application so that the
- 4:43encryption and decryption processes will
- 4:46be compatible there are obviously
- 4:48advantages and disadvantages depending
- 4:50on what encryption algorithm you're
- 4:51using some algorithms have a better
- 4:54security level some work faster than
- 4:56others some have a more complex method
- 4:58for implement mation but once both sides
- 5:01agrees on the application that will be
- 5:03used for encryption and decryption
- 5:05everything else generally takes care of
- 5:07itself automatically usually the
- 5:09Security administrator will have a
- 5:11pretty good idea of what the
- 5:13requirements are for the users and
- 5:15they'll make sure that the proper
- 5:16encryption algorithms are used here's a
- 5:19good example of why it's so important
- 5:21that both parties in a conversation are
- 5:23using the same encryption algorithm
- 5:25these are very broad comparisons between
- 5:27the desk encryption algorithm and the
- 5:29AES encryption algorithm these stand for
- 5:32the data encryption standard and the
- 5:34advanced encryption standard you do not
- 5:37need to know the specifics of these
- 5:39block diagrams for the Security Plus
- 5:41exam but you can visually see that there
- 5:44are quite a few differences between both
- 5:46of these algorithms the desk encryption
- 5:48algorithm has five different steps which
- 5:50include breaking up the data into a left
- 5:52plane text and right plain text to
- 5:55finally come up with a 64-bit Cipher
- 5:57text you can see that AES Works a little
- 5:59a little bit differently where you take
- 6:00a plain text and a secret key add it to
- 6:02a cipher and finally get the cipher text
- 6:05there are also different versions of AES
- 6:08that can produce different levels of
- 6:09output you obviously would not be able
- 6:12to encrypt with desks and somehow
- 6:14decrypt with AES you have to be sure
- 6:16that you're using compatible encryption
- 6:19and decryption algorithms on both sides
- 6:21of the
- 6:22conversation here's another interesting
- 6:24part about encryption algorithms is we
- 6:26know exactly how they work the
- 6:28algorithms themselves are usually public
- 6:31you can read the code or look through
- 6:32the math and see exactly the process
- 6:35that occurs the algorithm is usually a
- 6:37very well-known thing in fact it makes
- 6:39the algorithm more trustworthy because
- 6:41we can see the math and the process
- 6:43that's used to create the encryption the
- 6:46one major piece of information that we
- 6:47don't have is the key and although we
- 6:50know how the algorithm works we still
- 6:52are not able to reverse engineer
- 6:54anything unless we have that key this is
- 6:57very similar to the way that a door lock
- 6:59operates we know how door locks work we
- 7:02know how to manufacture door locks we
- 7:05know what happens inside of a door lock
- 7:07when you put a key in but just knowing
- 7:09that information doesn't somehow allow
- 7:11you access through a lock door you have
- 7:14to have the proper key just as you do
- 7:16with encryption and decryption that key
- 7:20helps determine the final output if
- 7:22you're encrypting data or hashing data
- 7:24or creating a digital signature it's all
- 7:26based around that key and even though we
- 7:28have the algorithm and understand
- 7:30everything about the math you still need
- 7:32the key to be able to gain access to the
- 7:35data this is why we always tell you to
- 7:37keep those private Keys private if
- 7:40somebody gains access to your key
- 7:41they're able to use it on your door lock
- 7:43and now they have access to all of your
- 7:46data like anything else your encryption
- 7:48and decryption keys are subject to Brute
- 7:51Force attacks which means that an
- 7:53attacker could go through every possible
- 7:55permeation to be able to determine what
- 7:57a public or private key might be we can
- 8:00effectively prevent these Brute Force
- 8:02attacks from being successful by
- 8:04creating a very very long key in the
- 8:07world of encryption a symmetric key of
- 8:09128 bits or larger would be very common
- 8:12and today would be very protected as
- 8:15time goes on and our processors become
- 8:16more powerful and we're able to tie many
- 8:19different processors together we may
- 8:21increase the size of our keys to make
- 8:23them that much more difficult to Brute
- 8:26Force this extension of the key links
- 8:28also applies to asymmetric encryption as
- 8:30well even though an asymmetric key
- 8:32involves complex mathematics surrounding
- 8:34very large prime numbers an attacker can
- 8:37still perform a brute force and it's not
- 8:39uncommon to see asymmetric keys that
- 8:41have a key length of 372 bits or even
- 8:45larger this means as time goes on we may
- 8:48have to create larger and larger Keys
- 8:50just to keep up with the changes in
- 8:52technology but there are some other
- 8:54things we can do to make our existing
- 8:56keys that much more secure and and one
- 8:59of the ways to do that is to perform the
- 9:01encryption process multiple times on the
- 9:04single type of data for example you may
- 9:07want to Hash a password then hash the
- 9:09hash of that password then hash the hash
- 9:12of the hash of that password and so on
- 9:14this is referred to as key stretching or
- 9:17key strengthening this means if someone
- 9:19wanted to Brute Force some data that's
- 9:21been encrypted multiple times using this
- 9:24key stretching method that they would
- 9:26need to decrypt multiple times to see if
- 9:29their brute force was successful and
- 9:31this adds an additional overhead and
- 9:33certainly would create more time during
- 9:35the Brute Force
- 9:46process
About this transcript
This page contains the full transcript of Encrypting Data - CompTIA Security+ SY0-701 - 1.4 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 1,736 words across 257 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.