Cryptographic Implementation Security Questions

Security of cryptography as actually implemented in code, where a correct algorithm still fails through misuse, side-channel leakage, or faulty error handling. Covers cryptographic API misuse patterns (nonce and IV reuse, ECB mode, hardcoded secrets, unauthenticated ciphertext, algorithm confusion), timing and cache side-channels, constant-time coding techniques (masking, blinding, formal constant-time verification), physical side-channel and fault-injection attacks and their countermeasures (power analysis, electromagnetic leakage, voltage and laser glitching), padding-oracle and other implementation-level cryptanalytic attacks (Bleichenbacher, CBC padding oracles, nonce-reuse key recovery), cryptographic failure-mode handling, and implementation auditing (code review checklists, static and dynamic misuse detectors, fuzzing). Assumes the algorithm, key, and RNG have already been selected: distinct from choosing and provisioning primitives, key derivation, and random number generation (applied cryptography and key management) and from encryption-at-rest and in-transit architecture (data protection and encryption).

MediumTechnical
99 practiced

An API signs JWT tokens using RS256, but a legacy endpoint accepts tokens with alg set to 'none' or allows algorithm confusion. Explain the vulnerability, outline a proof-of-concept exploit to forge a token accepted by the service, and specify code-level changes and validation checks to permanently fix the issue.

HardTechnical
52 practiced

Discuss unique side-channel and secret management challenges when implementing cryptographic primitives in managed languages like Java, Go or JavaScript. Cover garbage collection, memory pinning, immutable objects, JIT optimizations, escaping to native code, and mitigation strategies for timing and memory-disclosure risks in such environments.

EasyTechnical
67 practiced

Compare physical side channels such as power, electromagnetic and acoustic leakage with microarchitectural channels such as caches and branch predictors. Discuss attacker proximity requirements, instrumentation complexity, typical leakage signals, and typical mitigations for each class.

HardTechnical
54 practiced

Analyze potential side-channel vulnerabilities of ChaCha20-Poly1305 implementations on resource-constrained embedded devices, including cache-timing, branch-timing, and instruction-timing leaks. Propose concrete mitigations at algorithmic and implementation levels (compiler flags, constant-time libraries, assembly implementations) and testing methods to detect leaks.

MediumTechnical
66 practiced

Explain RSA decryption blinding: what attacks it mitigates, how randomized blinding prevents side-channel and fault-injection attacks that target private-key operations (especially CRT-optimized implementations), and outline correct blinding and unblinding steps, RNG requirements, and pitfalls.

Unlock Full Question Bank

Get access to all Cryptographic Implementation Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.