Computer Networks · Module 8 — Network Security & Wireless Basics
Encryption basics and certificates
Symmetric encryption uses one key to lock and unlock. Fast, good for bulk data. But both sides need the same key, and sending it over an untrusted network defeats the point.
Sign in to track your score
Encryption makes Aisha's traffic unreadable. But unreadable to whom? If she is talking to an impostor, perfect encryption just means she is confiding in the wrong person very securely.
Why & what
Why there are two kinds of encryption.
Symmetric encryption uses one key to lock and unlock. Fast, good for bulk data. But both sides need the same key, and sending it over an untrusted network defeats the point.
Asymmetric encryption uses a key pair. Anything locked with the public key opens only with the matching private key, so the public key can be handed to anyone. That solves the sharing problem, but it is slow.
Real systems use both. HTTPS uses asymmetric briefly, only to agree a shared symmetric key, then switches to symmetric for the data.
Why certificates are needed. Asymmetric encryption proves someone holds a private key. It does not prove who they are.
A certificate binds a public key to a domain name, signed by a Certificate Authority (CA) that browsers already trust. The signature says: this public key really does belong to college.edu. An attacker cannot get a CA to sign a certificate for a domain they do not control, so Aisha's browser warns her.
How it works
- Aisha's browser connects and the TLS handshake begins.
- The server sends its certificate: public key, domain, and the CA's signature.
- The browser checks that signature against the CA list it ships with, that the name matches, and that it has not expired.
- If it passes, both sides use asymmetric encryption to agree a shared symmetric key.
- Everything after that uses the fast symmetric key.

Common confusion
Students think the padlock icon means a website is safe. Actually, it only means the connection is encrypted and the certificate matches the name.
A scam site can get a valid certificate for its own domain in minutes, and the padlock then looks identical to a real bank's. It guarantees two things: nobody is reading this in transit, and you are connected to the domain in the address bar. It says nothing about whether that domain deserves trust. Encryption protects the channel, not the other end of it.
Interview angle
Asked as: "Difference between symmetric and asymmetric encryption?" and "What is a digital certificate?"
Model answer:
Symmetric encryption uses one shared key to encrypt and decrypt. It is fast, but distributing the key securely is the hard part. Asymmetric uses a public and private key pair — anything encrypted with the public key opens only with the private one, so the public key can be shared openly. It is much slower. HTTPS uses both: asymmetric during the TLS handshake to agree a session key, then symmetric for the data. A certificate binds a public key to a domain and is signed by a CA the browser trusts. That is what stops a man-in-the-middle substituting their own key — they cannot get a trusted CA to sign for a domain they do not control.
- 1.
Symmetric encryption's main weakness is
- 2.
In asymmetric encryption, what may be shared freely?
- 3.
What does a certificate prove?
- 4.
Why does HTTPS use both kinds of encryption?