Cryptographic Hashing and Digital Signatures Questions

Cryptographic hash functions (collision resistance, preimage resistance), message authentication codes, and digital-signature schemes. Covers HMAC, signature verification, and how hashing underpins integrity, commitments, and authentication. Distinct from non-cryptographic hashing used in data structures.

MediumTechnical
41 practiced

Walk through how you'd implement signature verification for a client-server API using JSON Web Signatures (JWS). What are the concrete ways this commonly goes wrong in production code, and how would you guard against algorithm confusion, replay of an old but validly-signed request, and any subtleties around exactly what bytes get hashed and signed?

EasyTechnical
43 practiced

MD5 and SHA-1 are widely considered broken and deprecated. What exactly broke, collision resistance or preimage resistance, and why does that distinction matter? Reference a concrete real-world demonstration if you can, and explain what it means for a system today that still signs certificates or code with one of these algorithms. How would you advise a team still relying on them in production?

MediumTechnical
50 practiced

A service signs messages built by concatenating fields without separators, say user || timestamp || amount. Demonstrate how two different sets of field values could produce the exact same concatenated string (and therefore the same signature), then propose a fix. What would you actually change about how these messages get serialized before signing, and what backward-compatibility issues would your fix create?

EasyTechnical
48 practiced

In Python using the 'cryptography' library, write a function sign_message_rsa_pss(private_pem: bytes, message: bytes) -> bytes that computes SHA-256 over the message and returns an RSA-PSS signature. Also provide a short verification snippet showing how to verify the signature. Focus on correct padding parameters and hash selection; you may omit file I/O and error handling boilerplate.

MediumTechnical
55 practiced

Explain the birthday paradox as it applies to hash collision attacks. Given a hash output of n bits and an attacker capable of 2^30 hash computations per second, estimate the time required to find a collision for a 128-bit hash and a 256-bit hash. Show your calculation steps and discuss practical feasibility.

Unlock Full Question Bank

Get access to all 8 Cryptographic Hashing and Digital Signatures interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.