Case 069705 · Cryptography · L2 Practitioner
Digital Signatures and MACs
Practise as: Explain it
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- A signature is made with a private key over a hash of the message and verified with the public key.
- Signatures give integrity, authenticity and non-repudiation; a MAC (HMAC) gives integrity but shared-key only.
- Common schemes: RSA-PSS, ECDSA (P-256) and Ed25519; Ed25519 is deterministic, avoiding nonce-reuse failures.
- ECDSA nonce reuse leaks the private key, as in the 2010 Sony PS3 signing key compromise.
If the interviewer pushes back
- Why is RSA PKCS#1 v1.5 signature verification historically error-prone (e.g. Bleichenbacher 2006 forgeries)?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.