18 cards · Foundations, Practitioner, Applied, Advanced, Expert
Cryptography interview questions and practice topics
Applied cryptography: hashing versus encryption, TLS, PKI and certificates, key management, password storage and common implementation mistakes. Explain the maths simply and the failure modes precisely.
Each card is a topic to explain out loud against the clock: 12 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick Cryptography as a focus.
L1 Foundations What it is
L2 Practitioner How it works
- Block Cipher ModesExplain
- Digital Signatures and MACsExplain
- Forward SecrecyWhat is forward secrecy and why does it matter if a server private key is stolen?Explain · Interview
- Password Dump Hits PastebinYour user password hashes have leaked and they are unsalted MD5. Walk me through the response.Incident · Interview
- Salting, bcrypt and Argon2How should an application store user passwords, and why?Explain · Interview
L3 Applied Abuse and defence in real systems
- Cert Chain Breaks at MidnightIncident
- Key Management with KMS and HSMsDeep dive · Explain
- PKI and Certificate ChainsWalk me through how a browser decides to trust a website certificate.Explain · Interview · Deep dive
- Post-Quantum CryptographyWhat does quantum computing break in today's crypto, and how are we migrating?Explain · Interview · Deep dive
- The TLS 1.3 HandshakeExplain the TLS 1.3 handshake and what changed from TLS 1.2.Explain · Interview · Deep dive
- TLS Private Key on GitHubA production TLS private key was committed to a public repo. What do you do?Incident · Interview
- Why Crypto Implementations FailDeep dive
L4 Advanced Edge cases, bypasses, trade-offs
L5 Expert Research-grade, architecture-level
- ECDSA Nonce Bias Key RecoveryYour ECDSA signer leaks a few bits of each nonce through timing. Why is that enough to recover the private key?Explain · Interview
- Group E2EE with MLSHow would you design end-to-end encryption for groups of thousands of members, and how does MLS approach it?Deep dive · Interview
Other domains
Web AppSec · Network · Identity & AD · Cloud · Blue team / DFIR · Malware & intel · Famous breaches · GRC · AI security