Cryptographic Hashing and Digital Signatures Questions

Cryptographic hash functions (collision resistance, preimage resistance), message authentication codes, and digital-signature schemes. Covers HMAC, signature verification, and how hashing underpins integrity, commitments, and authentication. Distinct from non-cryptographic hashing used in data structures.

EasyTechnical
52 practiced

Explain what a length-extension attack is for Merkle–Damgård style hash functions (like MD5, SHA-1, SHA-256). Then describe, step-by-step, how an attacker can forge H(key || message || suffix) given only H(key || message) when a naive MAC = H(key || message) is used. (You may reference tools/libraries but sketch the algorithm and why the internal state enables the forgery.)

MediumTechnical
41 practiced

Walk through how you'd implement signature verification for a client-server API using JSON Web Signatures (JWS). What are the concrete ways this commonly goes wrong in production code, and how would you guard against algorithm confusion, replay of an old but validly-signed request, and any subtleties around exactly what bytes get hashed and signed?

EasyTechnical
47 practiced

You're building a cache-key generator for a CDN, and a teammate suggests reusing the same fast hash function for hashing user passwords too, to keep the codebase simple. How would you respond, and what's the real boundary between a general-purpose hash like MurmurHash and a cryptographic hash function? Give three situations where a non-cryptographic hash is perfectly fine and three where using one would be a serious mistake.

MediumTechnical
74 practiced

Explain why using H(secret || message) as a MAC is insecure when the hash is a Merkle–Damgård construction (e.g., MD5/SHA-1) and describe the length-extension attack. Show the attack idea and then explain how HMAC fixes it, including why HMAC resists length-extension and what properties of the underlying hash it relies on.

EasyTechnical
55 practiced

What is a Merkle tree, and how does a Merkle proof let you verify that a single leaf belongs to a committed root without holding the whole dataset? Name two real-world systems that rely on this structure and explain what they'd lose without it.

Unlock Full Question Bank

Get access to all 19 Cryptographic Hashing and Digital Signatures interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.