Open cardosec

Case 9F9930 · Cryptography · L3 Applied

Why Crypto Implementations Fail

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Most breaks are implementation bugs, not math: Heartbleed (OpenSSL over-read) leaked keys from memory.
  2. Side channels: timing (non constant-time compares), cache attacks, and power analysis on devices.
  3. Bad randomness: Debian OpenSSL 2008 PRNG bug produced only ~32k possible keys per type and size.
  4. Protocol and API misuse: JWT alg=none, ECB mode, hard-coded IVs, disabled certificate validation.
  5. OWASP Top 10:2025 A04 Cryptographic Failures: use vetted libraries (libsodium, Tink) with safe defaults.

If the interviewer pushes back

  • Pick one real CVE in a crypto library and explain the root cause, the exploit, and the fix.

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.