Case 9F9930 · Cryptography · L3 Applied
Why Crypto Implementations Fail
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Most breaks are implementation bugs, not math: Heartbleed (OpenSSL over-read) leaked keys from memory.
- Side channels: timing (non constant-time compares), cache attacks, and power analysis on devices.
- Bad randomness: Debian OpenSSL 2008 PRNG bug produced only ~32k possible keys per type and size.
- Protocol and API misuse: JWT alg=none, ECB mode, hard-coded IVs, disabled certificate validation.
- OWASP Top 10:2025 A04 Cryptographic Failures: use vetted libraries (libsodium, Tink) with safe defaults.
If the interviewer pushes back
- Pick one real CVE in a crypto library and explain the root cause, the exploit, and the fix.
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.