Encryption in Transit - Protecting Data on the Wire
About 2 min read
Encryption in Transit is a technique that encrypts data flowing over a network to prevent eavesdropping and tampering. TLS (Transport Layer Security) is the representative protocol, used to protect all kinds of network communication such as HTTPS communication, sending and receiving email, and VPN tunnels. TLS 1.3, the latest version, was standardized as RFC 8446 in August 2018, reducing the number of handshake round trips and removing legacy cipher suites.
Real-World Use Cases
For example, a system might protect external communication with HTTPS while leaving internal communication between microservices in plaintext. In that state, anyone who gets inside the same network can read the internal traffic as it is, so a common countermeasure is to use a service mesh (such as Istio) to apply mTLS to service-to-service communication as well, automating authentication and encryption at the platform layer instead of leaving it to each application.
Encryption-in-Transit Flow
The Difference from Encryption at Rest
Whereas encryption at rest protects data stored on disks and databases, encryption in transit protects data while it moves from sender to receiver. The two are complementary, and either one alone is insufficient. For example, even if your database is encrypted, if communication with the application server is in plaintext, the data could be intercepted through a man-in-the-middle attack.
Major Protocols and Implementations
TLS 1.3, the latest version defined in RFC 8446, reduces the number of handshake round trips and balances security with speed. SSH encrypts server-management communication, and IPsec provides network-layer encryption over VPN tunnels. In cloud environments, designs that also apply mTLS (mutual TLS authentication) to inter-service communication are recommended. On public Wi-Fi, encryption in transit is especially important, and combining it with a VPN can also protect unencrypted communication.
Operational Tips
TLS certificates have an expiry date, and forgetting to renew one makes browsers display a warning that leaves the service effectively unusable. Use Let's Encrypt's auto-renewal or certificate-management tools to prevent expiration. In addition, TLS 1.0/1.1 have known vulnerabilities and were formally deprecated by the IETF in RFC 8996 (March 2021), so they need to be disabled. Combining a strong random password with encryption in transit keeps your credentials from travelling across the network in plaintext.
Was this article helpful?