Open cardosec

Case B62FD8 · Cryptography · L1 Foundations

Symmetric vs Asymmetric Crypto

Practise as: Explain it · Interview

Interview questionExplain symmetric versus asymmetric encryption and why real protocols use both.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Symmetric (AES, ChaCha20) uses one shared key; fast, hardware-accelerated (AES-NI), but key distribution is hard.
  2. Asymmetric (RSA, ECC) uses a public/private pair; enables key exchange and signatures without a pre-shared secret.
  3. Asymmetric ops are orders of magnitude slower, so protocols use hybrid encryption: exchange a key, then use AES.
  4. Key sizes differ: AES-128 is roughly comparable to RSA-3072 or a 256-bit elliptic curve (P-256, X25519).
  5. Use AEAD modes (AES-GCM, ChaCha20-Poly1305) so ciphertext is authenticated, not just encrypted.

If the interviewer pushes back

  • What happens to AES-GCM security if a nonce is ever reused under the same key?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.