skip to content

Cryptography Concepts

The primitives a developer must choose between — hashing, symmetric and asymmetric encryption, cipher modes, signatures, randomness, password storage and TLS — and the reasoning behind each choice. Interviewers ask at the concept level because the common failures are picking the wrong primitive, not calling it incorrectly.

part ofApplication security & secure codingoverview, primer and where to startread it →
on this pageshow

questions

page 1 of 2

Public-key encryption is usually taught as 'encrypt with the public key, decrypt with the private key'. Give the definition that explains what asymmetric encryption actually solves, and why calling it 'a stronger shared password' is the wrong frame.

level: juniorimportance: must knowfreq 72%

answer

  1. public encrypts, private decrypts
  2. solves distribution, not strength
  3. attacker owns the encryption key
  4. no sender authenticity, no freshness
  5. RSA encrypts / DH agrees / KEM encapsulates

basics

~20 s

A linked key pair: the public key only encrypts and may be published, the private key alone decrypts. It removes the need for a pre-shared secret, so it solves key distribution, not strength. A ciphertext still proves nothing about who produced it.

solid answer

~40 s

Symmetric encryption requires both sides to already share a secret, which requires a confidential channel you do not yet have. Asymmetric encryption breaks that circularity with a trapdoor one-way function: the public key can be published and still only enables encryption; only the private key reverses it. It is not a better password. Per bit it is weaker, and it is slow and size-limited, which is why it is used to establish a symmetric key rather than to carry data. It also buys less than people assume. Because anyone holds the encryption key, a ciphertext carries no evidence of sender, no freshness (an old ciphertext replays fine), and no protection if you encrypted to the wrong public key. Secrecy of distribution became authenticity of distribution: you still have to know the key is theirs.

go deeper

for a junior

Recall the pair, which half is published, and that it removes the pre-shared-secret requirement.

for a middle

Add why the primitive is slow and bounded, and that a ciphertext gives confidentiality only - no origin, no freshness.

for a senior

Frame it as converting a secrecy problem into an authenticity problem, and distinguish direct encryption from key agreement and encapsulation.

for a principal

Reason about where the residual trust decision lives in the system and what recorded ciphertext is worth to an attacker who later obtains the private key.

## The circular problem it breaks Symmetric encryption needs the same secret at both ends, so agreeing on it needs an already-confidential channel, which is what you were trying to build. It also scales as n(n-1)/2 pairwise keys. Asymmetric encryption removes the prerequisite: publish one half of a key pair and anyone can send you confidential data with no prior contact. ## The asymmetry itself The pair is generated together and linked by a hard mathematical problem (factoring, discrete logarithms). The direction that uses the public key is easy; reversing it without the private key is believed infeasible, and the private key is not derivable from the public key in practical time. That one-way structure is the whole mechanism. ## The threat-model consequence of 'public' The attacker owns the encryption key. Any attack that only requires encrypting is therefore free and offline: no interaction with you, no rate limit, no log entry. That single fact drives everything else, including why raw unpadded encryption is unsafe and why encrypting a low-entropy value is dangerous. ## What it does not provide - **Sender authenticity.** Anyone can encrypt to your public key, so 'it decrypted cleanly' means only that it was encrypted to you. - **Freshness.** Recording and replaying an old ciphertext works; nothing in the primitive binds a message to a moment. - **Forward secrecy** when a long-lived key pair is the only thing protecting recorded traffic. - **The trust decision.** Encrypting to an attacker's public key is flawless encryption to the wrong person, and it fails silently. ## Three families that diverge on what 'asymmetric encryption' even means RSA is a genuine trapdoor permutation: it encrypts a bounded message directly. Diffie-Hellman and its elliptic-curve form encrypt nothing at all; both sides derive a shared secret from each other's public values, so it is key agreement. Post-quantum designs such as ML-KEM are key-encapsulation mechanisms: they produce a random key plus a ciphertext that carries it. Only the first is literally 'encrypt a message with a public key'; the other two exist to hand you a symmetric key. So the sentence 'we encrypt with public-key crypto' almost always means 'we asymmetrically establish a symmetric key'. ## The invariant Anyone may hold the ability to encrypt; only the private-key holder may decrypt. Confidentiality is therefore a property of two things: who controls the private key, and whether you bound the right public key to the right identity.

  • If a message decrypts successfully with your private key, what have you actually learned?
    Only that someone encrypted it to your public key, which everybody can do. You have learned nothing about the sender's identity, nothing about when it was created, and nothing about whether it is the original message rather than a replay of an older one. Any claim of origin inside the plaintext is unauthenticated text.
  • Why is a key pair not simply 'two passwords'?
    A password is a shared secret: both sides hold the same value, so either can perform either operation, and disclosure to one party is disclosure to all. A key pair is deliberately unequal - one half is safe to publish because it only permits the easy direction. That inequality is what removes the need for a secure setup channel, and it is also why the two halves cannot be swapped when reasoning about risk.

saying these in an interview costs you the question

  • Saying asymmetric encryption is 'more secure' than symmetric rather than differently scoped; per bit it is weaker and far slower.
  • Claiming a successfully decrypted message proves who sent it.
  • Assuming the public key must be kept secret, or that publishing it weakens the pair.
  • Believing key distribution is now solved, when the residual problem is proving a public key belongs to the intended party.

context

open as a page

Why is Electronic Codebook (ECB) mode considered unusable for general-purpose encryption, and what property must any acceptable mode have that ECB lacks?

level: juniorimportance: must knowfreq 62%

basics

~20 s

ECB encrypts each block independently with no randomization, so identical plaintext blocks give identical ciphertext blocks — it leaks structure, repetition and equality, and blocks can be reordered or spliced. Any usable mode must be randomized: same plaintext, different ciphertext each time.

open as a page

A candidate defines a digital signature as "encrypting the hash with your private key". Give a definition that also holds for signature schemes involving no encryption at all, and state precisely which security property a signature provides that a shared-key message authentication code (MAC) cannot.

level: juniorimportance: must knowfreq 65%

basics

~20 s

Signing runs the message and a private key through a signing algorithm to produce a value anyone can check with the matching public key. It gives integrity and origin authenticity. A shared-key MAC gives both too, but not non-repudiation: either key holder could have produced the tag.

open as a page

A team exports a customer table to an analytics partner and replaces the email column with its SHA-256 digest, reporting that the export is now "anonymised" and safe to share. Explain what a digest of a personal identifier actually gives you, how hashing differs from encryption and from encoding such as Base64, and what you would do instead.

level: juniorimportance: must knowfreq 68%

basics

~20 s

Hashing is unkeyed and deterministic, so a hashed identifier is a stable pseudonym, not anonymous data: it still singles out people and joins across datasets, and small identifier spaces enumerate. Encryption is keyed and reversible; encoding is neither and protects nothing.

open as a page

A team stores user passwords as SHA-256 digests and argues that SHA-256 is cryptographically strong and irreversible. Explain why that reasoning is wrong for passwords, and what property a password-storage function must have instead.

level: juniorimportance: must knowfreq 82%

basics

~20 s

Passwords are low-entropy, so nobody inverts the hash — they guess candidates and hash them. A general-purpose hash is designed to be fast, so an attacker tests billions of guesses per second. A password function must be deliberately slow and hardware-hostile, with a per-user salt and a tunable cost.

open as a page

Symmetric encryption is usually described as 'the same key encrypts and decrypts'. Give the definition an engineer should actually work from: what security property it provides, what it does not provide, and why a block cipher such as AES is not by itself an encryption scheme.

level: juniorimportance: must knowfreq 76%

basics

~20 s

One secret shared by both sides; security rests on the key alone, never on hiding the algorithm. AES by itself is a keyed permutation on one fixed block, so a usable scheme adds length handling and per-message randomisation. It gives confidentiality only, not integrity or authenticity.

open as a page

What exactly does Transport Layer Security guarantee, against which attacker, and what does it deliberately not protect? Answer in terms of security properties rather than a list of handshake steps.

level: juniorimportance: must knowfreq 78%

basics

~20 s

Against an attacker who controls the network path, TLS gives confidentiality, integrity, ordering within the connection, and authenticity of the peer - the last one carries the rest. It protects the channel, not the endpoints, the metadata, or stored data.

open as a page

Why is a 4 MB file never encrypted directly under an RSA public key, and what does the standard hybrid (envelope) construction do instead? Derive the size limit rather than quoting a number.

level: middleimportance: must knowfreq 60%

basics

~20 s

RSA encrypts one integer smaller than the modulus, minus padding overhead - a couple of hundred bytes - and there is no chaining mode to extend it. So generate a random symmetric key, encrypt the bulk with it, and use the public key only to wrap that key.

open as a page

Encryption is usually described as "nobody else can read it." Give the definition of what a block-cipher mode of operation actually guarantees, and explain why a ciphertext an attacker can modify in a predictable way is insecure even when they can never read it.

level: middleimportance: must knowfreq 60%

basics

~20 s

A mode gives confidentiality only — it hides content, not length and not authenticity. Unauthenticated ciphertext is malleable: an attacker can flip plaintext bits blindly. Authenticated encryption adds a tag, so any modified ciphertext is rejected instead of decrypted.

open as a page

Signature schemes hash the message before signing it. Beyond "the message might be large", what does that hash contribute to the security argument, and what goes wrong when the hash is weak or when signer and verifier disagree about exactly which bytes were covered?

level: middleimportance: must knowfreq 50%

basics

~20 s

The digest maps arbitrary input into the primitive's fixed domain, and unforgeability then rests on collision resistance: a collision means one signature is valid for two messages. Separately, a signature covers exact bytes, so any normalisation gap lets the verifier authenticate one thing and the application consume another.

open as a page

Cryptographic hash functions are usually summarised as "one-way". State the security properties a hash function is actually supposed to provide, and explain why knowing a function is one-way still does not tell you whether a particular use of it is safe.

level: middleimportance: must knowfreq 72%

basics

~20 s

Three properties: preimage resistance (given a digest, find any input producing it), second-preimage resistance (given one input, find a different one with the same digest), and collision resistance (find any two inputs that collide). Each use depends on a different one; "one-way" names only the first.

open as a page

In password storage, a per-user salt, a secret "pepper", and the work factor of the key-derivation function are three separate mechanisms. Explain what attack each one defeats, which of them still helps after a full database dump, and how the pepper must be constructed if you ever want to rotate the secret.

level: middleimportance: must knowfreq 62%

basics

~20 s

Salt is unique and public: it kills precomputed tables and stops one guess testing every account. Work factor makes each guess expensive — the only thing that still helps once the attacker holds everything. Pepper is a secret key stored outside the database; it defeats database-only theft, and it is rotatable only if applied as a reversible keyed layer.

open as a page

Secure randomness is usually taught as a rule: "use the cryptographic random generator, not the ordinary one." Give the definition behind the rule — what makes a generator cryptographically secure, why a generator can pass every statistical randomness test and still be useless for keys and tokens, and what property you are actually buying.

level: middleimportance: must knowfreq 62%

basics

~20 s

Ordinary generators are designed for good distribution; cryptographic ones are designed for unpredictability. The question is never whether output looks random, but whether an attacker who has seen past output can predict the next one or recover the internal state. Statistical tests cannot answer that.

open as a page

You have to specify a password-reset token: the number of bits behind it, and how those bits are turned into the characters that appear in the emailed link. Explain how you size the value, why the character alphabet changes the answer, and what goes wrong when random bytes are mapped into an alphabet by simple remainder arithmetic.

level: middleimportance: must knowfreq 55%

basics

~20 s

Size by entropy bits, not by string length: aim for 128 bits of generator output. Encoding only changes how many characters carry those bits — hex gives 4 per character, base64 gives 6. Mapping bytes with a plain remainder skews the alphabet; use rejection sampling.

open as a page

A client makes a TLS connection and receives a certificate. List what it must verify before it can claim it is talking to the intended server, and explain why 'the certificate chained to a trusted root' is not sufficient on its own.

level: middleimportance: must knowfreq 68%

basics

~20 s

Verify the chain to a trusted root with its constraints, the validity dates, revocation status, proof that the peer holds the private key, and - decisively - that the hostname you intended matches the certificate's subject alternative names. Chaining alone proves only that some CA issued it, to someone.

open as a page

Explain how a TLS handshake turns an untrusted network into an authenticated confidential channel: which job the public-key operations do, which job the symmetric keys do, and what forward secrecy means for a connection recorded today and attacked years later.

level: middleimportance: must knowfreq 70%

basics

~20 s

Ephemeral key agreement produces a shared secret neither side transmitted; a signature with the certificate's private key binds that agreement to a named identity; symmetric keys derived from it protect records. Discarding the ephemeral values afterwards gives forward secrecy.

open as a page

State the contract an initialization vector or nonce must satisfy in CBC-style and counter-style encryption modes, and describe exactly what an attacker gains when the same nonce is reused under the same key.

level: seniorimportance: must knowfreq 48%

basics

~20 s

CBC needs an IV that is unique and unpredictable. Counter-style modes need only uniqueness, but absolutely: reuse XORs two plaintexts together, and in a Galois-tag mode it also leaks the authentication subkey, letting the attacker forge any message under that key.

open as a page

A signature verification call returns true. Enumerate precisely what that proves and what it does not, and describe the verification mistakes that make a "valid" signature meaningless.

level: seniorimportance: must knowfreq 55%

basics

~20 s

It proves only that these exact bytes were signed by whoever holds the private key matching the public key you chose. Not who that is, not when, not for whom, not that the key is still valid. The classic bypasses: taking the algorithm or the key identity from the message itself.

open as a page

MD5 and SHA-1 are routinely called "broken". State precisely which property fails, explain why a system that compares an attacker-supplied artifact against an attacker-influenced digest fails immediately while a keyed construction over the same function does not, and say what you would tell a team that answers "we only use MD5 as a cache key".

level: seniorimportance: must knowfreq 55%

basics

~20 s

Their collision resistance is destroyed; their preimage resistance is essentially intact. So uses where the adversary chooses both inputs — signing, deduplication, approval lists — fail now, while uses that require matching a fixed unknown value do not. Brokenness is a statement about a property, never about an algorithm in the abstract.

open as a page

Hundreds of service pairs each need a shared secret before they can exchange encrypted data. Describe the key-distribution problem this creates, the structural ways systems escape it, and why a key hierarchy is preferred over handing every component the same long-lived key.

level: seniorimportance: must knowfreq 55%

basics

~20 s

Pairwise secrets scale as n(n-1)/2 and need an already-secure channel to bootstrap. Systems escape via pre-shared keys, authenticated key agreement, or a central key authority, then use a hierarchy: a protected root key wraps per-object data keys.

open as a page

Asymmetric encryption is credited with solving key distribution. What problem does it leave behind, and for a system that must encrypt data to many recipients, how would you decide how public keys are trusted and how long a private key may live?

level: principalimportance: must knowfreq 40%

basics

~20 s

It converts secrecy of distribution into authenticity of distribution: you must prove a public key belongs to the intended party, and encrypting to the wrong one fails silently. Key lifetime is driven by blast radius - a static wrapping key leaked later exposes everything ever wrapped under it.

open as a page

A colleague argues that a 256-bit elliptic-curve key must be far weaker than a 2048-bit RSA key because 256 is much smaller than 2048. Explain what is wrong with comparing key lengths across algorithm families, and how you would reason about a key pair's security margin instead.

level: middleimportance: should knowfreq 45%

basics

~20 s

Compare work factor, not key length. Best-known attacks differ per family: exhaustive search for symmetric keys, sub-exponential sieving for RSA, square-root generic attacks for curves. Roughly, 128-bit security means AES-128, RSA-3072 or a 256-bit curve.

open as a page

Encryption keys, initialisation vectors, nonces, password salts and session identifiers are all commonly produced by "generate some random bytes." For each of these, state which property the consumer actually requires — unpredictability, uniqueness, or both — and explain what concretely breaks when the wrong property is supplied.

level: middleimportance: should knowfreq 45%

basics

~20 s

Randomness is a means, not the requirement. Keys and tokens need unpredictability. Nonces need uniqueness — a counter is often better. Salts need uniqueness, not secrecy. Some IVs need unpredictability too. Naming the required property tells you which generator, and how many bits.

open as a page

Why is textbook RSA - treating the message as an integer and raising it to the public exponent modulo n with no padding - insecure even when nobody can factor the modulus? Name the property that randomized padding restores.

level: seniorimportance: should knowfreq 34%

basics

~20 s

Because the attacker holds the encryption key. Unpadded encryption is deterministic, so any low-entropy plaintext can be guessed and encrypted offline until the ciphertext matches. Randomized padding restores semantic security: the same message encrypts to unlinkable ciphertexts.

open as a page

A service decrypts attacker-supplied ciphertext and returns one error for "bad padding" and a different one for "bad content." Explain the general class of attack this enables, and state the ordering rule for encryption and authentication that prevents it.

level: seniorimportance: should knowfreq 42%

basics

~20 s

Any behaviour that differs based on decrypted bytes turns the service into a decryption oracle; a padding check leaks enough to recover plaintext byte by byte without the key. Fix: authenticate the ciphertext and reject before decrypting — encrypt-then-MAC, or an authenticated mode.

open as a page

Why should a digest or authentication tag be compared using a constant-time comparison rather than an ordinary equality check, and when does it genuinely not matter?

level: seniorimportance: should knowfreq 42%

basics

~20 s

An early-exit comparison takes longer the more leading bytes match, so its runtime leaks how close a guess was. That turns an infeasible offline forgery search into a byte-at-a-time online search. It stops mattering only when both compared values are already public to the attacker.

open as a page

A service authenticates messages by transmitting the message together with SHA-256(secret || message). Explain the structural weakness in that construction, and state the general rule for when a bare hash actually gives you integrity.

level: seniorimportance: should knowfreq 45%

basics

~20 s

SHA-256 is a Merkle–Damgård chain whose output is its full internal state, so an attacker who knows the digest and the secret's length can append data and compute a valid digest without the secret. More fundamentally, a bare hash gives integrity only against a digest obtained over a channel the attacker cannot rewrite.

open as a page

Compare bcrypt, scrypt, Argon2 and PBKDF2 as password-storage functions. On what axes do they actually differ, and how would you choose and parameterise one for a service handling heavy login traffic?

level: seniorimportance: should knowfreq 52%

basics

~20 s

They differ in what resource they force the attacker to spend. PBKDF2 costs only iterations of a fast hash, so specialised hardware wins; bcrypt costs a modest fixed memory footprint; scrypt and Argon2 let you demand large tunable memory, which is what neutralises massively parallel hardware. Parameters come from a measured latency budget at peak concurrency.

open as a page

Verifying a submitted password against a stored value looks trivial, yet several failures cluster there — timing side channels, account enumeration, denial of service, and inconsistent handling of the submitted string. Walk through what a correct verification path must do.

level: seniorimportance: should knowfreq 46%

basics

~20 s

Compare derived values in constant time; do the same amount of work for an unknown user as for a known one, using a dummy record, and return an identical response; normalise and length-bound the submitted string consistently; rate-limit because each verification is expensive; and never log or echo the credential.

open as a page

A cryptographically secure generator is still deterministic once it is seeded. Explain where the initial entropy comes from, what "weak entropy" concretely means, and how two machines running correct code with a correct generator can end up emitting identical keys.

level: seniorimportance: should knowfreq 35%

basics

~20 s

A secure generator expands a seed; it does not create unpredictability. If the seed is guessable or duplicated, so is every output. Duplication happens at first boot before the entropy pool fills, on process fork, on VM snapshot restore, and in cloned machine images.

open as a page

showing 1–30 of 37