Cryptographic Implementation Security Questions

Security of cryptography as actually implemented in code, where a correct algorithm still fails through misuse, side-channel leakage, or faulty error handling. Covers cryptographic API misuse patterns (nonce and IV reuse, ECB mode, hardcoded secrets, unauthenticated ciphertext, algorithm confusion), timing and cache side-channels, constant-time coding techniques (masking, blinding, formal constant-time verification), physical side-channel and fault-injection attacks and their countermeasures (power analysis, electromagnetic leakage, voltage and laser glitching), padding-oracle and other implementation-level cryptanalytic attacks (Bleichenbacher, CBC padding oracles, nonce-reuse key recovery), cryptographic failure-mode handling, and implementation auditing (code review checklists, static and dynamic misuse detectors, fuzzing). Assumes the algorithm, key, and RNG have already been selected: distinct from choosing and provisioning primitives, key derivation, and random number generation (applied cryptography and key management) and from encryption-at-rest and in-transit architecture (data protection and encryption).

HardTechnical
52 practiced

Show how a chosen-ciphertext attack could be mounted against an RSA-OAEP implementation that leaks validation errors or timing differences during OAEP decoding. Describe attack steps, necessary leakage model, and mitigations both at the protocol level and implementation level to restore OAEP's intended security.

MediumTechnical
99 practiced

An API signs JWT tokens using RS256, but a legacy endpoint accepts tokens with alg set to 'none' or allows algorithm confusion. Explain the vulnerability, outline a proof-of-concept exploit to forge a token accepted by the service, and specify code-level changes and validation checks to permanently fix the issue.

HardTechnical
57 practiced

You are evaluating a software AES implementation that uses precomputed T-tables. An attacker can execute victim code on the same CPU and measure cache access timing with a high-resolution timer. Describe the end-to-end cache-timing attack to recover AES key bytes: how to collect traces, which statistical methods to apply, how to construct key rankings, and which software or hardware mitigations are effective.

HardTechnical
65 practiced

Design an experiment to detect cache-based side-channel leakage from a cryptographic routine running on a shared cloud host. Define the attacker model (co-residency, privileges), measurements you would collect (timing, cache-probing traces), statistical analysis to detect leakage, and mitigation steps to harden the routine if leakage is confirmed.

HardTechnical
48 practiced

You ran fixed versus random t-test leakage experiments and received p-values around 0.03 in some time intervals and around 0.2 in others. Explain how to interpret these results in terms of leakage presence, and outline next investigative steps. Discuss multiple testing corrections, measurement noise, and how to quantify practical leakage strength.

Unlock Full Question Bank

Get access to all 8 Cryptographic Implementation Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.