Cryptographic Hashing and Digital Signatures Questions

Cryptographic hash functions (collision resistance, preimage resistance), message authentication codes, and digital-signature schemes. Covers HMAC, signature verification, and how hashing underpins integrity, commitments, and authentication. Distinct from non-cryptographic hashing used in data structures.

EasyTechnical
52 practiced

Explain what a length-extension attack is for Merkle–Damgård style hash functions (like MD5, SHA-1, SHA-256). Then describe, step-by-step, how an attacker can forge H(key || message || suffix) given only H(key || message) when a naive MAC = H(key || message) is used. (You may reference tools/libraries but sketch the algorithm and why the internal state enables the forgery.)

EasyTechnical
43 practiced

MD5 and SHA-1 are widely considered broken and deprecated. What exactly broke, collision resistance or preimage resistance, and why does that distinction matter? Reference a concrete real-world demonstration if you can, and explain what it means for a system today that still signs certificates or code with one of these algorithms. How would you advise a team still relying on them in production?

HardTechnical
39 practiced

Design an incident response plan for the discovery of a practical collision on a hash algorithm you use across several products. The plan should cover detection, announcement policy, revocation or migration of affected artifacts, coordinating with downstream users, and long-term mitigations.

EasyTechnical
48 practiced

In Python using the 'cryptography' library, write a function sign_message_rsa_pss(private_pem: bytes, message: bytes) -> bytes that computes SHA-256 over the message and returns an RSA-PSS signature. Also provide a short verification snippet showing how to verify the signature. Focus on correct padding parameters and hash selection; you may omit file I/O and error handling boilerplate.

EasyTechnical
47 practiced

You're building a cache-key generator for a CDN, and a teammate suggests reusing the same fast hash function for hashing user passwords too, to keep the codebase simple. How would you respond, and what's the real boundary between a general-purpose hash like MurmurHash and a cryptographic hash function? Give three situations where a non-cryptographic hash is perfectly fine and three where using one would be a serious mistake.

Unlock Full Question Bank

Get access to all 35 Cryptographic Hashing and Digital Signatures interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.