Open cardosec

Case 069705 · Cryptography · L2 Practitioner

Digital Signatures and MACs

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. A signature is made with a private key over a hash of the message and verified with the public key.
  2. Signatures give integrity, authenticity and non-repudiation; a MAC (HMAC) gives integrity but shared-key only.
  3. Common schemes: RSA-PSS, ECDSA (P-256) and Ed25519; Ed25519 is deterministic, avoiding nonce-reuse failures.
  4. ECDSA nonce reuse leaks the private key, as in the 2010 Sony PS3 signing key compromise.

If the interviewer pushes back

  • Why is RSA PKCS#1 v1.5 signature verification historically error-prone (e.g. Bleichenbacher 2006 forgeries)?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.