Crypto goes wrong in hilarious ways when people misuse correct math. Learn the categories and the failure modes — not just formulas.
Three concepts people constantly confuse:
UGFzc3dvcmQxMjM= is not “encrypted” — it’s a free password.Instant recognition tips: Base64 ends with =/==, charset A–Z a–z 0–9 +/. MD5 = 32 hex chars, SHA-1 = 40, SHA-256 = 64. In CTFs and reports, identifying “this is just base64” instantly is a superpower. The arcade’s Cipher Cracker game drills exactly this instinct.
Same key encrypts and decrypts: AES, ChaCha20. Fast, used for everything at volume (disk encryption, TLS session data after the handshake).
Security+ angle: know that AES-256-GCM is the modern default answer, ECB is the trap answer, and “out-of-band secure key exchange” is the fix for distribution.
Key pairs: public key encrypts / verifies; private key decrypts / signs. RSA and ECC are the workhorses. Slow, so real systems use hybrid: asymmetric to agree on a symmetric key, then AES for the data.
Hacker relevance: JWTs are mini-certificates gone rogue when apps accept alg:none or verify with the public key as HMAC secret. And self-signed certs on internal tools train users to click through warnings — an organizational vulnerability no firewall fixes.
TLS handshake, simplified: client says hello with supported suites → server presents certificate chain → verified against trusted roots → keys agreed via ECDHE (so past traffic stays safe even if the key leaks later = forward secrecy) → everything flows through AES-GCM.
Hashing in practice: passwords must be stored with slow, salted hashes — bcrypt/scrypt/Argon2 — never MD5/SHA-1 alone (too fast = crackable at scale). Salts kill rainbow tables; slowness kills brute force. File integrity uses fast hashes (SHA-256); signatures use them too.
Spot-the-finding checklist: HTTP login forms, missing HSTS, TLS 1.0/1.1 enabled, MD5 password hashes in a database dump you were authorized to review. All real report material.