Hint from Otto: "Neither of these are encryption. They're formats meant to make data safe to copy and paste — and formats like that can always be reversed, layer by layer, no secret key needed."
What is Base64 (and Hex)?
Base64 is an encoding scheme that represents binary data using only 64 printable characters (A–Z, a–z, 0–9, +, /). Hexadecimal (base16) represents each byte as two characters from 0–9 and a–f. Both are everywhere — in JSON payloads, URLs, color codes, memory dumps — because they make binary-safe data easy to copy, paste, and log.
Why is Treating Encoding as "Security" Dangerous?
Encoding is not encryption. It uses no secret key, and reversing it takes nothing more than a standard decoder — the same one built into every browser and terminal. Storing a password, token, or personal note in Base64 and calling it "protected" gives a false sense of security: anyone who can see the encoded value can decode it in seconds.
How to Actually Protect Sensitive Data?
- Use real encryption (e.g. AES) with a properly managed key when confidentiality matters
- Rely on access controls to decide who gets to see the data at all
- Reserve encoding schemes like Base64 for what they're actually for: safely transporting data
- Never use encoding as a substitute for encryption or access control