How it works
Symmetric encryption uses one secret key to lock and unlock. AES-GCM and ChaCha20-Poly1305 are the standard choices, and both also detect tampering. Asymmetric (public-key) encryption uses a pair: anyone can lock data with the public key, but only the matching private key opens it. RSA and elliptic-curve schemes are asymmetric and much slower than symmetric ciphers, so real systems use them to agree on or protect a symmetric key, then encrypt the data itself with that key.
In transit means data moving over a network, protected by TLS (the S in HTTPS), SSH or a VPN. At rest means data sitting on a disk or in a database, protected by disk encryption such as BitLocker or FileVault, or by the storage service; the major cloud storage services encrypt at rest by default. End-to-end encryption, as in Signal and WhatsApp, means only the people talking hold the keys, so even the service in the middle cannot read the messages.
Encryption is only as strong as the handling of its keys. Keys belong in a key management service (such as AWS KMS or Google Cloud KMS) or the OS keychain, never beside the data they protect. Inventing your own cipher, or reusing a nonce with AES-GCM, are classic ways to break otherwise sound encryption.
Encryption vs the alternatives
Related terms
More in Security
Crypto basics