Cryptographic Implementation Security Questions

Security of cryptography as actually implemented in code, where a correct algorithm still fails through misuse, side-channel leakage, or faulty error handling. Covers cryptographic API misuse patterns (nonce and IV reuse, ECB mode, hardcoded secrets, unauthenticated ciphertext, algorithm confusion), timing and cache side-channels, constant-time coding techniques (masking, blinding, formal constant-time verification), physical side-channel and fault-injection attacks and their countermeasures (power analysis, electromagnetic leakage, voltage and laser glitching), padding-oracle and other implementation-level cryptanalytic attacks (Bleichenbacher, CBC padding oracles, nonce-reuse key recovery), cryptographic failure-mode handling, and implementation auditing (code review checklists, static and dynamic misuse detectors, fuzzing). Assumes the algorithm, key, and RNG have already been selected: distinct from choosing and provisioning primitives, key derivation, and random number generation (applied cryptography and key management) and from encryption-at-rest and in-transit architecture (data protection and encryption).

HardTechnical
60 practiced

Explain the ROCA-style weak key vulnerability where a flawed key generation algorithm produces RSA moduli with predictable structure that allows factoring. Describe how you would detect such weak keys at scale in a large key repository, what mathematical tests or fingerprints to use, and what mitigation and remediation steps should follow detection.

HardTechnical
51 practiced

Design a scalable instrumentation and alerting system to detect cryptographic misuse and vulnerabilities in production (examples: reused IVs/nonces, weak randomness, deprecated algorithms in use, certificate mis-issuance). Specify telemetry sources, sampling strategy, anomaly-detection heuristics, false-positive reduction, automated mitigation actions, and privacy/data-retention considerations.

HardTechnical
57 practiced

A service has accidentally reused nonces with AES-GCM for a series of messages. As the cryptographer on-call, explain how you would detect the scope of reuse from logs and ciphertexts, immediate mitigation steps to reduce further damage, and a remediation plan including forensics, key rotation, and recovering trust in the system.

HardTechnical
53 practiced

Design an algorithm or pseudocode to analyze web/server logs and network traces to detect possible padding-oracle attacks against an application using AES-CBC with padding. Describe features you would extract (response timing, error codes, repeated ciphertexts), statistical detection methods, methods to reduce false positives, and suggested remediation actions upon detection.

That is every published Cryptographic Implementation Security question for Information Security Analyst so far. Browse the other topics in this category, or practice this one interactively.