About this interactive
When Susan sends David an important message, a legal document for example, David wants to know two things: that it has not changed (integrity) and that it really came from Susan (authenticity). A digital signature gives him both.
Susan hashes the document to make a fingerprint, then signs that hash with her private key. She sends the document and the signature to David, along with her digital certificate, which carries her public key.
David runs the document through the same hashing algorithm to get his own fingerprint. He then uses Susan's public key to check her signature against that fingerprint. If it verifies, the document has not changed since she signed it, and it was signed with the private key that matches her public key.
The video describes signing as encrypting the hash with the private key, and checking as decrypting it with the public key. That is a common way to picture RSA signatures, but signing is not encryption: nothing is made secret, and algorithms such as ECDSA sign without encrypting anything. The private key signs; the public key verifies.
The check is only as good as the public key. If anyone could hand David a key and call it Susan's, a valid signature would prove nothing about Susan. So David relies on public key infrastructure: a certificate authority both sides trust has validated that the certificate, and the public key in it, belong to Susan.
A signature does not hide the document. The document travels as it is, readable by anyone who intercepts it.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →