all modules module 05 · intermediate

Cryptography Essentials

Crypto goes wrong in hilarious ways when people misuse correct math. Learn the categories and the failure modes — not just formulas.

01Encoding vs encryption vs hashing~5 min

Three concepts people constantly confuse:

  • Encoding (Base64, URL-encode, hex): for transport, zero secrecy, trivially reversible. UGFzc3dvcmQxMjM= is not “encrypted” — it’s a free password.
  • Encryption: reversible but requires a key. Without it, ciphertext is noise.
  • Hashing: one-way. Same input always gives same output; you can’t reverse it — only guess inputs and compare (that’s what hash cracking does).

Instant recognition tips: Base64 ends with =/==, charset A–Z a–z 0–9 +/. MD5 = 32 hex chars, SHA-1 = 40, SHA-256 = 64. In CTFs and reports, identifying “this is just base64” instantly is a superpower. The arcade’s Cipher Cracker game drills exactly this instinct.

02Symmetric crypto: one key to rule them all~5 min

Same key encrypts and decrypts: AES, ChaCha20. Fast, used for everything at volume (disk encryption, TLS session data after the handshake).

  • ECB mode penguins: identical plaintext blocks give identical ciphertext blocks — patterns leak. Never ECB.
  • Modern modes (GCM) add an IV/nonce; reusing a nonce with the same key can be catastrophic.
  • The awkward part: how do two strangers share the key without someone watching? That’s the problem asymmetric crypto solves next lesson.

Security+ angle: know that AES-256-GCM is the modern default answer, ECB is the trap answer, and “out-of-band secure key exchange” is the fix for distribution.

03Asymmetric crypto & PKI: who are you again?~6 min

Key pairs: public key encrypts / verifies; private key decrypts / signs. RSA and ECC are the workhorses. Slow, so real systems use hybrid: asymmetric to agree on a symmetric key, then AES for the data.

  • Digital signatures: sign with private key, anyone verifies with public key — authenticity + integrity.
  • Certificates: a CA signs “this public key belongs to shop.example.com”. Browsers trust pre-installed root CAs → chain of trust down to the site cert.
  • PKI failure modes: expired certs, weak algorithms (SHA-1 signatures), and mis-issued certificates (revocation via CRL/OCSP).

Hacker relevance: JWTs are mini-certificates gone rogue when apps accept alg:none or verify with the public key as HMAC secret. And self-signed certs on internal tools train users to click through warnings — an organizational vulnerability no firewall fixes.

04TLS in motion + hashing deep dive~5 min

TLS handshake, simplified: client says hello with supported suites → server presents certificate chain → verified against trusted roots → keys agreed via ECDHE (so past traffic stays safe even if the key leaks later = forward secrecy) → everything flows through AES-GCM.

Hashing in practice: passwords must be stored with slow, salted hashes — bcrypt/scrypt/Argon2 — never MD5/SHA-1 alone (too fast = crackable at scale). Salts kill rainbow tables; slowness kills brute force. File integrity uses fast hashes (SHA-256); signatures use them too.

Spot-the-finding checklist: HTTP login forms, missing HSTS, TLS 1.0/1.1 enabled, MD5 password hashes in a database dump you were authorized to review. All real report material.