Cryptographic Implementation Security Questions

Security of cryptography as actually implemented in code, where a correct algorithm still fails through misuse, side-channel leakage, or faulty error handling. Covers cryptographic API misuse patterns (nonce and IV reuse, ECB mode, hardcoded secrets, unauthenticated ciphertext, algorithm confusion), timing and cache side-channels, constant-time coding techniques (masking, blinding, formal constant-time verification), physical side-channel and fault-injection attacks and their countermeasures (power analysis, electromagnetic leakage, voltage and laser glitching), padding-oracle and other implementation-level cryptanalytic attacks (Bleichenbacher, CBC padding oracles, nonce-reuse key recovery), cryptographic failure-mode handling, and implementation auditing (code review checklists, static and dynamic misuse detectors, fuzzing). Assumes the algorithm, key, and RNG have already been selected: distinct from choosing and provisioning primitives, key derivation, and random number generation (applied cryptography and key management) and from encryption-at-rest and in-transit architecture (data protection and encryption).

EasyTechnical
49 practiced

Explain how error messages and exception handling in cryptographic flows can leak sensitive information (for example, enabling padding oracles or revealing distinct error types). Provide practical error-handling and logging strategies that avoid leaking secrets while preserving enough diagnostic information for developers and operators.

MediumTechnical
59 practiced

A token service reuses a per-user HMAC key to sign both session tokens and password reset links. Identify cryptographic and protocol weaknesses arising from key reuse across different purposes and propose a secure key separation strategy and migration plan that preserves backward compatibility where possible.

HardSystem Design
53 practiced

Design a secure file-encryption scheme for arbitrarily large files that supports streaming, random access reads, integrity, and efficient key rotation. Specify algorithms/modes (AEAD), chunking and per-chunk nonce derivation strategy, metadata authentication, and how to rotate keys for existing files without decrypting every file immediately.

MediumTechnical
66 practiced

Given the following pseudocode for decrypting AES-CBC messages, identify the vulnerability that creates a padding oracle and rewrite the control flow to avoid leaking padding errors. Explain why your changes are safe and suggest an AEAD-based alternative.

pseudocode snippet: def decrypt(ciphertext, key, iv): plaintext = aes_cbc_decrypt(ciphertext, key, iv) try: unpadded = pkcs7_unpad(plaintext) except PaddingError: return 'padding error' if not verify_hmac(unpadded): return 'mac error' return unpadded

MediumSystem Design
54 practiced

Design a secure password-reset token mechanism for a web application. Include token generation (entropy length), storage (hashing vs plaintext), expiry and single-use enforcement, rate-limiting, and defenses against token prediction, reuse, and abuse. Also describe how you would log and monitor reset flows for abuse without leaking sensitive information.

Unlock Full Question Bank

Get access to all 10 Cryptographic Implementation Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.