5 - Cryptography
Lesson 5.1 Cryptography Basics
Overview
Cryptography—also referred to as cryptology—is the science of protecting data by transforming it into a format that cannot be understood by unauthorized users. At the core of secure communication, cryptography ensures that information remains confidential, unaltered, and verifiable. In this lesson, you’ll explore the fundamental concepts and components of cryptography, from ancient techniques like the Caesar Cipher to modern digital encryption and hashing systems.
Understanding these foundational ideas is essential for any cybersecurity professional responsible for safeguarding data in transit, at rest, and in use.
Key Terms / Concepts
Plaintext: Readable or recognizable information before encryption
Ciphertext: Unreadable or unrecognizable data after encryption
Encryption: The process of converting plaintext to ciphertext
Decryption: The process of converting ciphertext back to plaintext
Encryption Algorithm / Cipher: A mathematical formula used to perform encryption
Key: A secret value used in the encryption and decryption process
Hash: A one-way transformation that converts data into a fixed-size output
Message Digest: The resulting output from a hashing algorithm
Confusion: Complicates the relationship between plaintext and key
Diffusion: Spreads out the influence of plaintext over the ciphertext
Entropy: Measure of randomness used in key generation
Transparency: The practice of open-sourcing encryption algorithms for trustworthiness
Reflection Prompt
Think about the digital services you use daily—email, online banking, messaging apps. How does cryptography protect your private messages and transactions behind the scenes? What might happen if encryption didn’t exist?
Detailed Concepts
What is Cryptography?
Cryptography is the science and practice of securing information by converting it into an unreadable format (ciphertext) using mathematical algorithms and secret keys. Only those with the right key can reverse the process (decrypt) and read the original message (plaintext).
Goals of Cryptography
Confidentiality: Only intended parties can access the information
Integrity: Information has not been altered
Authentication: Verifies identities involved in communication
Non-Repudiation: Ensures that someone cannot deny their actions
These goals align with the CIA Triad: Confidentiality, Integrity, and Availability (with cryptography supporting the first two heavily).
Historical Perspective: Classical Ciphers
Caesar Cipher
Shifts each letter in a message a set number of positions in the alphabet
Example: Shift right by 2 → A becomes C
Key = 2; Algorithm = shift
Symmetric encryption – same key used to encrypt and decrypt
Substitution Cipher
Replaces each character with another (more complex than Caesar)
Vulnerable to frequency analysis
Polyalphabetic Cipher (Vigenère Cipher)
Uses multiple substitution alphabets to strengthen security
Enigma machine: WWII mechanical encryption
Other Methods
Vernam Cipher / One-Time Pad: Uses a random key the same length as the message
Unbreakable if: key is truly random, used only once, and kept secret
Practical issues: key distribution and management
Transposition & Book Ciphers: Rearranging letters or using shared book references
Digital Cryptography – Core Components
Method | Description |
|---|---|
Symmetric Encryption | One key used for both encryption and decryption (e.g., AES) |
Asymmetric Encryption | Uses a pair of keys: public and private (e.g., RSA) |
Hashing | One-way transformation that ensures data integrity |
Applications of Cryptography
Transport Encryption: Secures data as it travels across networks (e.g., HTTPS)
Storage Encryption: Protects data saved on disk or in the cloud
Memory Encryption: Shields active data in RAM from snooping
API Security: Ensures safe app-to-app communication
Software Obfuscation: Protects source code from reverse engineering
Non-Repudiation: Prevents users from denying they sent or received data
Key Exchange: Ensures secure transmission of encryption keys
Cryptographic Principles from Claude Shannon (1949)
The secrecy should match the required effort
Algorithms should not rely on obscurity
Encryption process should be simple to implement
Errors should not affect the rest of the message
Ciphertext should not be larger than plaintext
Simplified Summary
Cryptography protects data by turning readable text into unreadable code
It uses keys and algorithms to encrypt and decrypt information
Classical techniques like Caesar Cipher laid the foundation for digital encryption
Hashing checks integrity, while encryption ensures confidentiality
Cryptographic methods are essential for secure communication, data protection, and authentication
Real-World Analogies
Encryption: Like locking a letter in a safe—only those with the key can open it
Hashing: Like fingerprinting a file—if the file changes, its fingerprint changes
Caesar Cipher: Like rotating the alphabet to hide your message
Symmetric vs Asymmetric: Like using one key for both locking and unlocking (symmetric), vs using a padlock (public key) and a private key only you hold
Lesson 5.2 Symmetric Key Cryptography
Overview
Symmetric key cryptography, also called secret-key or private-key cryptography, is one of the foundational methods for encrypting data. It uses the same key for both encryption and decryption, making it fast and efficient. However, secure key exchange and key management remain significant challenges. This lesson explores the core algorithms, operations modes, and applications of symmetric encryption, including block and stream cipher methods and message authentication codes (MACs).
Understanding symmetric cryptography is essential for professionals securing communications, files, and systems.
Key Terms / Concepts
Symmetric Encryption: Encryption using the same key to both encrypt and decrypt
Block Cipher: Encrypts fixed-size chunks of data (e.g., AES, 3DES)
Stream Cipher: Encrypts data one bit or byte at a time using a keystream
Initialization Vector (IV): A random value used with a key for added uniqueness
ECB/CBC/CTR/GCM: Block cipher operation modes
Message Authentication Code (MAC): Verifies message authenticity and integrity
HMAC/CMAC: Hash- or cipher-based MAC algorithms
Session Key: A symmetric key used for a single session
Key Exchange: Process of securely sharing encryption keys
XOR (Exclusive OR): Logical operator used in encryption processes
Reflection Prompt
Consider messaging apps like WhatsApp or Signal. They encrypt your messages using symmetric keys for speed. What challenges would arise if the encryption key were intercepted or reused?
Detailed Concepts
What Is Symmetric Key Cryptography?
Symmetric encryption uses one key to both encrypt and decrypt data. It’s efficient, making it ideal for large volumes of data and real-time applications. Two main types:
Block ciphers: Encrypt data in fixed-size chunks
Stream ciphers: Encrypt data one bit/byte at a time with a keystream
Key Algorithms in Symmetric Encryption
Algorithm | Description |
|---|---|
DES | 56-bit key, outdated, first cracked in 1997 |
3DES | |
AES | Most widely used today; 128, 192, or 256-bit keys |
Blowfish / Twofish | Flexible, secure alternatives |
RC5 | Part of the Rivest Cipher family; variable block/key sizes |
Salsa20 | Modern, efficient stream cipher |
IDEA | Known for strong encryption, less common today |
AES Encryption Process (Simplified)
Key Expansion: Original key expanded into multiple round keys
Initial Round: XOR plaintext with initial key
Main Rounds (9, 11, 13 rounds depending on key length):
SubBytes
ShiftRows
MixColumns
AddRoundKey
Final Round: Like previous rounds, but skips MixColumns
AES processes a 4x4 matrix of bytes (the “state”) and uses the XOR operator to mix the key with data.
Block Cipher Modes of Operation
Semantically Secure Modes
ECB (Electronic Codebook): Same key on every block; insecure
CBC (Cipher Block Chaining): Chains blocks using IV and previous ciphertext
CTR (Counter Mode): Encrypts blocks using incrementing counter as IV
Authenticated Modes
GCM (Galois/Counter Mode): Combines CTR with integrity checks
CCM: Combines CTR and CBC-MAC
EtM (Encrypt-then-MAC): Encrypts then authenticates
AEAD (Authenticated Encryption with Associated Data): Encrypts while authenticating headers and payload
IVs must be unique per session. CBC improves security over ECB by chaining ciphertext.
Message Authentication Codes (MAC)
A MAC ensures data integrity and verifies the sender's identity.
Generation: Sender runs the message through a MAC algorithm (e.g., HMAC with SHA-256) using a shared key
Verification: Receiver does the same and compares the result
MAC Type | Description |
|---|---|
HMAC | Uses hash functions (e.g., SHA-256) |
CMAC | Uses block ciphers (e.g., AES) |
Stream Ciphers
Encrypts data bit-by-bit using a pseudorandom keystream
Common in real-time applications (e.g., streaming, VoIP)
Examples: RC4 (deprecated), Salsa20
Fast and efficient, but key reuse leads to major vulnerabilities
Stream ciphers are symmetric, ideal for applications requiring speed but challenging for secure key management.
Block vs Stream Cipher Comparison
Feature | Block Cipher | Stream Cipher |
|---|---|---|
Data Size | Fixed blocks | Bit or byte stream |
Speed | Slightly slower | Faster |
Security | More robust modes | Vulnerable to key reuse |
Examples | AES, DES | RC4, Salsa20 |
Key Lifecycle and Exchange
Keys must be rotated frequently (session-based)
Two key exchange methods:
In-band (e.g., Diffie-Hellman)
Out-of-band (e.g., USB, secure meeting)
Secure key exchange is one of symmetric encryption’s biggest challenges.
Issues and Considerations
Storage: Where and how to keep keys secure
Exchange: How to share keys without interception
Algorithm Selection: Choose based on:
Supported protocols
Industry standards
Performance requirements
A 128-bit AES key has 3.4×10³⁸ combinations—strong, but useless if stored or transmitted insecurely.
Simplified Summary
Symmetric encryption uses the same key to encrypt and decrypt
It's fast and efficient, suitable for large volumes of data
Block ciphers work on chunks; stream ciphers on continuous bits
Secure key exchange and frequent rotation are essential
AES is the current gold standard in symmetric encryption
Real-World Analogies
Symmetric Encryption: Like using the same house key to lock and unlock your front door
AES Process: Like a complex recipe where steps repeat based on how spicy (secure) you want your dish
CBC Mode: Like a chain—each link depends on the last
Stream Cipher: Like a walkie-talkie where every word gets encrypted live
Lesson 5.3 Asymmetric Key Cryptography
Overview
Asymmetric key cryptography, also known as public-key cryptography, revolutionized secure communication by removing the need for shared secrets. Introduced by Diffie and Hellman in 1976, it relies on two mathematically related keys: a public key for encryption and a private key for decryption. While computationally more intensive than symmetric cryptography, it solves critical problems like secure key exchange and digital signatures.
This lesson explores asymmetric cryptography, its algorithms, practical use cases, and emerging concerns like quantum threats.
Key Terms / Concepts
Asymmetric Encryption: Uses a pair of keys—one public, one private
Public Key: Shared freely, used to encrypt or verify
Private Key: Kept secret, used to decrypt or sign
RSA: A foundational asymmetric encryption algorithm
DSA/ECDSA: Digital signature algorithms
Elliptic Curve Cryptography (ECC): Efficient public-key algorithm
Diffie-Hellman (DH): A method for secure key exchange
FIPS 140-3: U.S. cryptographic module validation standard
Post-Quantum Cryptography (PQC): Encryption designed to resist quantum attacks
Reflection Prompt
When you visit a secure website (https), how do you know you're really talking to the right server and not an attacker? Think about how asymmetric cryptography might play a role in that trust.
Detailed Concepts
What Is Asymmetric Cryptography?
Asymmetric encryption uses two keys:
A public key that can be distributed to anyone
A private key that is kept secret by the owner
If someone encrypts data with your public key, only you can decrypt it using your private key.
Invented in 1976 by Diffie and Hellman for digital signatures
How It Works – Example Flow
Bob generates a public/private key pair
He shares his public key with Alice
Alice encrypts a message using Bob’s public key
Only Bob can decrypt it using his private key
Secure communication without exchanging a shared key beforehand
ALICE
BOB
Limitation: While Alice knows only Bob can read the message, Bob cannot confirm Alice’s identity.
Why It Matters
Solves Key Exchange Problems
Enables Digital Signatures
Powers TLS/SSL (HTTPS), secure email, VPN authentication
Asymmetric encryption is slower than symmetric encryption and uses much longer keys to achieve similar security levels.
Major Asymmetric Algorithms
Algorithm | Purpose | Notes |
|---|---|---|
RSA | Encryption & signatures | Based on two large primes |
DSA | Digital signatures only | Government-backed standard |
ECC | Encryption & signatures | Efficient with smaller keys |
ECDSA | ECC-based signature algorithm | Used in cryptocurrency (e.g., Bitcoin) |
Diffie-Hellman (DH) | Key exchange | Not for direct encryption |
Cryptographic Modules
A cryptographic module is a validated component (software or hardware) that implements cryptographic functions
Must meet standards like FIPS 140-3, validated by NIST
Federal agencies are required to use validated modules
Enterprises often follow suit for compliance and assurance
Quantum Cryptography Threat
Quantum computers pose a threat to asymmetric encryption because:
They can solve problems (like factoring large primes) much faster
This could break algorithms like RSA and ECC
Symmetric encryption is less impacted by quantum computing.
Quantum-Safe Cryptography
Post-Quantum Cryptography (PQC) is the term for new algorithms designed to resist quantum attacks
NIST is standardizing quantum-resistant algorithms
As of December 2024, ~30.7% of Internet-based asymmetric cryptography was post-quantum
Term | Meaning |
|---|---|
Quantum Safe | Algorithms immune to quantum computer attacks |
PQC | May refer to algorithms or broader quantum-era cryptography |
Lattice-based / Code-based Crypto | Types of quantum-safe systems being studied |
Simplified Summary
Asymmetric encryption uses a public and private key pair
Enables secure key exchange and digital signatures
Algorithms include RSA, ECC, and DSA
Slower than symmetric encryption but ideal for authentication
Quantum computing threatens current algorithms, pushing us toward post-quantum cryptography
Real-World Analogies
Public Key: Like a locked mailbox—anyone can drop in a letter, but only you (with the key) can open it
Digital Signature: Like a notarized document—it proves you authored it
Quantum Threat: Like someone inventing a universal master key—forcing us to redesign locks
Lesson 5.4 Cryptographic Hashing
Overview
Cryptographic hashing is the process of transforming data into a fixed-length output using a one-way mathematical function. Even a single-bit change in the input data results in a drastically different output. These hashes are crucial in cybersecurity for validating data integrity, securely storing passwords, and supporting encryption processes.
Unlike encryption, hashing is irreversible—there’s no way to recover the original input from the hash. This lesson covers how hashing works, key algorithms, and why it's fundamental to modern security systems.
Key Terms / Concepts
Hash Function: One-way function that converts data into a fixed-length output
Message Digest: The resulting value from a hash function
Checksum: A basic type of hash used for detecting errors
Avalanche Effect: A small change in input causes a large change in output
Deterministic: The same input always produces the same output
Collision Resistance: It is difficult to find two different inputs that result in the same hash
Cryptographic Hash Function: A secure form of hashing used in security applications
Non-Cryptographic Hash: Used in databases or indexing, not for security
Password Hashing: Converting passwords into irreversible hashes for storage
Reflection Prompt
If someone modifies a file on your system, how could you tell it’s been changed without checking every line of content? Think about how hashes might help verify file integrity.
Detailed Concepts
What Is Cryptographic Hashing?
A hash is a fixed-length representation of data
The process is one-way: you cannot go backward from the hash to the original data
Even a tiny change in the input drastically changes the hash output (avalanche effect)
Basic types:
Check Digit: 1-digit validation
Checksum: Simple integrity check
Message Digest: Secure hash output used in cryptography
Applications of Cryptographic Hashing
Application | Purpose |
|---|---|
Data Integrity | Ensures a file or message wasn’t altered during transmission |
Password Storage | Stores passwords as hashes instead of plaintext |
Key Generation | Provides randomness for generating cryptographic keys |
Digital Signatures | Uses hash of the message before signing |
Blockchain | Each block includes a hash of its contents and the previous block |
Hashes are used anywhere you want to detect tampering or verify identity without revealing the original data.
Popular Hash Algorithms
Algorithm | Notes |
|---|---|
MD5 | Fast but vulnerable to collisions; obsolete |
SHA-1 | Better than MD5, but also now considered insecure |
SHA-2 (SHA-256, SHA-512) | Modern standard, used widely |
SHA-3 | Successor to SHA-2; not yet widely adopted |
RIPEMD | Used in OpenSSL and some crypto systems; European standard |
Key Benefits and Requirements
A cryptographic hash must be:
Deterministic: Same input → same output
Efficient: Fast to compute
Irreversible: Cannot derive original data from hash
Collision-Resistant: Hard to find two inputs that hash to same value
Avalanche-Prone: Small input changes → vastly different output
Avalanche Effect Example
Changing one bit in a document might change the entire hash:
Input | Hash Output (SHA-256) |
|---|---|
"Password1" |
|
"Password2" |
|
This unpredictability is what makes hashing secure and effective for authentication and integrity checks.
Simplified Summary
A cryptographic hash transforms data into a secure fingerprint
Hashing is irreversible, unlike encryption
Widely used in data integrity, password protection, and digital signatures
Secure hashes exhibit the avalanche effect and resist collisions
Real-World Analogies
Hashing a file is like sealing it in a tamper-proof envelope; if anything inside changes, the seal no longer matches
Password hashing is like storing someone’s fingerprint rather than their face—you can verify them without knowing exactly what they look like
Avalanche effect is like dropping one grain of sand that causes a massive avalanche—small input, big impact
Lesson 5.5 Cryptographic Applications
Overview
Now that you understand the core components of cryptography—symmetric encryption, asymmetric encryption, and hashing—this lesson ties those pieces together by showing how they are used in real-world security systems. Cryptographic applications power secure communications, user authentication, digital validation, and blockchain technology. These applications are foundational to digital trust, privacy, and integrity in today's interconnected systems.
By seeing how these methods work in practice, you’ll better appreciate the essential role cryptography plays in everything from signing into websites to securing international finance.
Key Terms / Concepts
Key Exchange: The secure transfer of cryptographic keys between parties
Authentication: Verifying the identity of a user or system
Digital Signature: Confirms the authenticity and integrity of a message
PKI (Public Key Infrastructure): A framework for managing digital certificates and public-key encryption
Blockchain: Distributed ledger secured by cryptographic hashes and consensus protocols
Checksum / Hash Validation: Verifies that a downloaded or transferred file has not been altered
Reflection Prompt
Think about the last time you downloaded a file or logged into a secure website. How did you know the file wasn’t altered or that the site was authentic? Which cryptographic tools might have been working behind the scenes?
Detailed Concepts
What We Know So Far
Concept | Key Properties |
|---|---|
Symmetric Key Cryptography | Uses one shared key for both encryption and decryption. It's fast but key exchange is a challenge. |
Asymmetric Key Cryptography | Uses a public/private key pair. Slower but ideal for authentication and key exchange. |
Cryptographic Hashing | One-way transformation used for integrity verification; not reversible. |
Key Cryptographic Applications
1. Secure Key Exchange
Cryptography enables two parties to securely exchange encryption keys over an insecure channel.
Diffie-Hellman and asymmetric encryption enable secure sharing without pre-established trust
Essential for establishing session keys in symmetric encryption
2. Identity and Access Management (IAM)
Cryptography helps verify users and control access to systems.
Passwords are stored using hashing (e.g., bcrypt, SHA-256)
Digital certificates are used for multi-factor authentication
Public key encryption ensures credential confidentiality
3. File Integrity Verification
When downloading a file, cryptographic hash values are often provided.
Hashes like SHA-256 allow users to verify that the file hasn’t been modified
If the hash value matches, the file is confirmed to be authentic and unaltered
4. Digital Signatures
Digital signatures confirm both integrity and authenticity of data or communications.
The sender hashes the message and encrypts the hash with their private key
The recipient decrypts it with the sender’s public key and compares the hash
Used in secure emails, software signing, and contracts
5. Blockchain and Distributed Ledgers
Each block in a blockchain contains:
A hash of the previous block
A list of transactions and a timestamp
A new hash computed over the current block
This creates a chain of trust. Any tampering changes the hashes, invalidating the chain.
Bitcoin and Ethereum rely on cryptographic hashing and digital signatures
6. Public Key Infrastructure (PKI)
PKI supports the management of digital certificates and key pairs.
Maintains a trusted certificate authority (CA)
Verifies identities of users or systems
Underpins SSL/TLS, secure email, and more
Without PKI, the internet would not be trusted or secure
Simplified Summary
Key Exchange: Securely shares keys using asymmetric encryption
Authentication: Validates users with passwords, certificates, and hashes
Digital Signatures: Confirms who sent a message and that it hasn’t changed
File Integrity: Uses hashes to check if files have been tampered with
Blockchain: Uses chained hashes and cryptographic proofs to record data
PKI: Manages trust and encryption on the internet
Real-World Analogies
Digital Signature: Like notarizing a document—proves who signed it and that it wasn’t altered
Hash Validation: Like sealing a jar—if the seal is broken, you know it was tampered with
Blockchain: Like a tamper-evident ledger—each page includes a summary of the previous page
Lesson 5.6 Secure Key Exchange
Overview
Secure key exchange is a foundational requirement in modern cryptographic systems. While symmetric encryption is fast and efficient, it requires both parties to share a secret key—posing a challenge when communicating over insecure networks. This is where asymmetric methods like the Diffie-Hellman Key Exchange come into play.
This lesson focuses on the key exchange problem and introduces you to one of the oldest and most enduring solutions: the Diffie-Hellman protocol. You'll learn how it works and why it's still vital in today's security protocols.
Key Terms / Concepts
Key Exchange: The secure sharing of cryptographic keys between parties
Symmetric Key: A single key used for both encryption and decryption
Diffie-Hellman Key Exchange (DHKE): Protocol for secure key exchange over a public channel
Public Parameters: Agreed-upon numbers used by both parties
Prime Number (p): A large prime number used in DH calculations
Generator (g): A base number used in key generation
Modulus Operation: A mathematical function used to limit the size of results
Reflection Prompt
If two people want to exchange a secret note across a public classroom, how could they agree on a code without everyone else overhearing? What if they each had a trick that allowed them to share a secret using only numbers and colors?
Detailed Concepts
The Key Exchange Problem
Symmetric encryption is fast but requires a shared key
Physically exchanging keys is not always possible or safe
Diffie-Hellman allows secure key exchange even over insecure networks
Diffie-Hellman Key Exchange
First proposed in 1976 by Whitfield Diffie and Martin Hellman
Allows two parties to establish a shared secret without sharing private values
Supports symmetric encryption by generating a shared key
Paint-Mixing Analogy
A simplified way to understand Diffie-Hellman:
Alice and Bob agree on a base color (public value)
Each chooses a secret color (private value)
They mix their secret with the base color and share the mixture
Each then mixes the received color with their own secret color
Both end up with the same mixed color, which becomes their shared secret key
Even if an attacker sees the shared mixes, they can’t easily reverse-engineer the secret components.
Number Analogy – Step-by-Step
Step 1: Public Agreement
Choose a large prime number (p) and a base (g)
These values are publicly known
Step 2: Secret Selection
Alice chooses a secret number a
Bob chooses a secret number b
Step 3: Public Key Generation
Alice computes A = g^a mod p
Bob computes B = g^b mod p
They share A and B with each other
Step 4: Shared Secret Calculation
Alice computes S = B^a mod p
Bob computes S = A^b mod p
Both arrive at the same shared secret (S)
Why Is It Secure?
Even though g, p, A, and B are public, an attacker cannot easily compute S without knowing a or b
This problem is known as the Discrete Logarithm Problem—hard to reverse
The security of Diffie-Hellman relies on the difficulty of solving large modular exponentiation problems.
Visual Summary
Step | Alice | Bob |
|---|---|---|
Choose Secret | a | b |
Compute Public Key | A = g^a mod p | B = g^b mod p |
Exchange Keys | ← A → | ← B → |
Compute Shared Key | S = B^a mod p | S = A^b mod p |
Simplified Summary
Key exchange is required for symmetric encryption to function securely
Diffie-Hellman enables this over public channels
It uses prime numbers and modular math to generate a shared secret
Attacks are difficult due to the complexity of reverse-engineering exponents
Real-World Analogies
Paint-Mixing: You and a friend each mix paint in secret, but end up with the same final color without revealing your ingredients
Number Locks: You both set a dial to a secret position, exchange dial readings, then apply your own secret again and get the same lock code
Lesson 5.7 Passwords and Hashing
Overview
Passwords are the most common form of authentication, and securely storing them is a critical cybersecurity function. Storing passwords as plain text would be a massive security risk—so modern systems use hashing algorithms to store a secure representation of the password. This lesson covers how password hashing works, the role of salts and peppers, and modern password storage algorithms such as bcrypt and PBKDF2.
By the end of this lesson, you'll understand how operating systems store passwords securely and the techniques used to resist cracking attacks.
Key Terms / Concepts
Password Hashing: Irreversible process of converting a password into a hash
Salt: A unique value added to a password before hashing
Pepper: A hidden value added to strengthen password hashing
Rainbow Table: A precomputed list of hashes used to reverse simple hashed passwords
bcrypt / PBKDF2 / scrypt / Argon2: Modern password hashing algorithms
NTLM: Legacy Microsoft password hashing method
Reflection Prompt
Think about the passwords you’ve created online. What would happen if a site got hacked and stored your passwords in plain text? How does hashing protect you—and what risks still remain?
Detailed Concepts
How Password Hashing Works
User enters password to log in
The system hashes the password using a secure hash function
It compares the resulting hash to the stored hash in the password database
If they match, access is granted
Important: The system never stores or transmits the actual password—only its hash.
Example: Traditional UNIX Systems
Early Linux systems stored password hashes in /etc/passwd
These were readable by all users
Vulnerable to rainbow table attacks—a technique that compares known hash outputs to precomputed tables of password hashes
A line from a Linux Passwd file
mark:x:1001:1001:mark,,,:/home/mark:/bin/bash
[--] - [--] [--] [-----] [--------] [--------]
| | | | | | |
| | | | | | +-> 7. Login shell
| | | | | +----------> 6. Home directory
| | | | +--------------------> 5. GECOS
| | | +--------------------------> 4. GID
| | +-------------------------------> 3. UID
| +-----------------------------------> 2. Password
+----------------------------------------> 1. UsernameSalting and Peppering Passwords
Salt
A random, unique value added to each password before hashing
Stored alongside the hash in plaintext
Prevents the use of a single rainbow table against multiple passwords
Pepper
A secret value, not stored with the hash
Introduced in NIST's 2017 password guidelines
Makes it harder to reverse-engineer individual hashes, even if the salt is known
Modern Password Storage Algorithms
NTLM (NT LAN Manager)
Used by older Windows systems
Relies on MD5, which is now broken
No longer recommended; deprecated in Windows Server 2025
bcrypt
Built on the Blowfish algorithm
Uses a 128-bit salt and produces a 184-bit hash
Supports key stretching to slow brute-force attacks
PBKDF2 (Password-Based Key Derivation Function 2)
IETF standard created by RSA
Combines passwords with salt and HMAC
Slower and more customizable than bcrypt, but generally weaker
Still used in some enterprise applications
Other Secure Hashing Algorithms
Algorithm | Notes |
|---|---|
scrypt | Builds on bcrypt with increased memory-hardness; good for defending against ASICs |
Argon2 | Winner of the Password Hashing Competition; supports multiple modes of resistance (time, memory, parallelism) |
SHA-based Hashing | Avoid using SHA-1 or MD5 for password hashing due to known collisions |
bcrypt, scrypt, and Argon2 are recommended for new systems requiring strong password protection.
Simplified Summary
Passwords are stored as hashes, not plaintext
Salt is used to make each hash unique and resist rainbow table attacks
Pepper adds a hidden security layer
Modern systems use bcrypt, PBKDF2, scrypt, or Argon2 for secure password storage
Legacy algorithms like NTLM should no longer be used
Real-World Analogies
Hashing a password is like shredding a document—you can verify what was shredded by its pieces, but you can’t put it back together easily
Salt is like adding a drop of unique ink to each paper before shredding—it ensures no two documents look the same
Pepper is a secret trick you never reveal—only you know how you shredded the document
Lesson 5.8 File Validation and Hashing
Overview
In cybersecurity, ensuring the integrity and authenticity of downloaded files is critical. A malicious actor could tamper with a file during transmission or replace it entirely. File validation through cryptographic hashing provides a reliable way to verify that a file is authentic and unmodified. This lesson explores how hash functions, checksums, and digital signatures help users and systems confirm file integrity, especially during downloads and software installations.
Key Terms / Concepts
File Validation: Verifying that a downloaded or transferred file has not been altered
Hash/Checksum: A fixed-length representation of a file’s contents
SHA-256 / MD5 / SHA-1: Common hashing algorithms used for file integrity
Digital Signature: A cryptographic mechanism used to verify the source and integrity of a file
PGP (Pretty Good Privacy): Encryption tool used to sign and verify files
Automated Verification: System-level processes that verify files automatically during download or installation
Reflection Prompt
When you download a software installer or update, how do you know it hasn’t been tampered with? Why might verifying the file’s hash or signature be important?
Detailed Concepts
Why File Validation Matters
Imagine downloading a program from a public website. Without file validation:
You could install malware instead of the intended software
A corrupted download might result in data loss or application failure
File validation ensures the file has not been modified or corrupted in transit.
How File Validation Works
Publisher creates a hash of the original file (e.g., using SHA-256)
The hash is posted alongside the download
You download the file and then run the same hash algorithm on it
Compare the two hashes
If they match → File is valid
If not → File may be corrupted or tampered with
Checksums & Hashes
Checksum is often used interchangeably with hash
Common formats: MD5, SHA-1, SHA-256, SHA-512
Example:
Publisher posts:
SHA256: 3a5f8c...You compute your own hash of the downloaded file
If it matches, the file hasn’t changed
Digital Signatures
Some files are digitally signed using tools like PGP
The signature confirms both:
The origin (it came from a trusted source)
The integrity (it hasn’t been altered)
Used in:
Secure software distribution
Open-source repositories (e.g., GitHub, SourceForge)
Operating system update files
Digital signatures go one step beyond hash comparison—they verify who created the file.
Automated File Verification
Modern systems often validate files without user intervention:
Package Managers (e.g., apt, yum, Homebrew) automatically verify software before installation
Web browsers check file headers and hashes
Operating systems block execution if a file fails integrity checks or lacks a trusted signature
Browser & OS Protections
Browsers may block or warn about:
Files with invalid or missing digital signatures
Files commonly flagged as malicious
OS-level protections include:
Windows SmartScreen
Gatekeeper (macOS)
Antivirus hash scanning before opening a file
Simplified Summary
File validation ensures downloaded files are safe and unchanged
Users verify hashes or digital signatures to confirm file authenticity
Automated systems often perform this verification silently in the background
Common algorithms include SHA-256 and MD5 (though MD5 is less secure)
Real-World Analogies
Hash Check: Like checking a barcode—you know the item is correct if the code matches
Digital Signature: Like a tamper-proof seal on a bottle—if it’s broken, the product may have been altered
Automated Validation: Like airport luggage scanners that check for contraband without you doing anything
Lesson 5.9 Digital Signatures and Public Key Infrastructure (PKI)
Overview
Digital signatures are essential for verifying the authenticity and integrity of digital communications. Paired with a trusted infrastructure for issuing and managing public keys—known as Public Key Infrastructure (PKI)—they help establish trust in digital environments. This lesson explores how digital signatures work, the role of digital certificates, and how PKI supports secure communications, user authentication, and system validation.
Key Terms / Concepts
Digital Signature: Encrypted hash proving message origin and integrity
Public Key Infrastructure (PKI): Framework for managing digital certificates
Certificate Authority (CA): Entity that issues and verifies digital certificates
Digital Certificate: Verifies a public key’s association with an entity
CSR (Certificate Signing Request): Request submitted to a CA to issue a certificate
CRL (Certificate Revocation List): List of revoked certificates
OCSP (Online Certificate Status Protocol): Checks certificate status in real time
S/MIME / Code Signing / SAN / Wildcard / EV Certificates: Specialized certificate types
Reflection Prompt
Think about secure websites, encrypted emails, or downloaded software. How do you know that what you're seeing is legitimate and came from a trusted source?
Detailed Concepts
Digital Signature Process
Hashing the Message
The sender creates a hash of the message (e.g., SHA-256)Signing the Hash
The hash is encrypted with the sender’s private key, creating a digital signatureTransmitting Message + Signature
Both the message and signature are sent to the recipient
Verification
Recipient decrypts the signature using the sender’s public key
Recipient hashes the received message
If the two hashes match, the message is authentic and unaltered
The Trust Problem
How does the recipient know the public key really belongs to the sender?
What if someone is impersonating the sender?
That’s where digital certificates come in
Digital Certificates
A digital certificate is a signed file that proves:
The identity of the certificate holder
The authenticity of the public key
The certificate’s usage and expiration
Components Include:
Public Key
Owner’s identity
Hash of the key
Validity period
Intended key usage
CA’s digital signature(s)
Certificate Trust Models
Model | Description |
|---|---|
Self-Signed | The owner signs their own certificate. Not inherently trustworthy |
PKI-Based | A CA verifies and signs the certificate |
Web of Trust | Others (peers) sign and vouch for your identity in a decentralized model |
Certificate Authorities (CAs)
Issue, verify, and revoke certificates
Follow a Certificate Practice Statement (CPS) that outlines rules for verification, issuance, and revocation
Work with Registration Authorities (RAs) for identity validation
Root Certificates and Registration Authorities
Root Certificate: Self-signed and used to sign other certificates
RA: Confirms the identity of applicants and forwards info to CA
Public Certificate Authorities and internal enterprise CAs both play roles
Certificate Generation Process
User generates a key pair
Submits a CSR to the CA
CA or RA verifies identity
CA signs and issues the certificate
Certificate is deployed for use
PKI Lifecycle Overview
Stage | Description |
|---|---|
Request | Entity submits a CSR to the CA |
Issuance | CA verifies and issues certificate |
Deployment | Installed on servers, users, etc. |
Monitoring | Track expiration and revocation status |
Renewal | Issued again before expiration |
Revocation | Marked as invalid due to compromise or retirement |
Expiration | Certificate is removed from use |
Certificate Revocation
Method | Description |
|---|---|
CRL | Downloadable list of revoked certificates |
OCSP | Real-time protocol to verify certificate status via CA |
Types of Digital Certificates
Type | Purpose |
|---|---|
Domain Validation (DV) | Validates ownership of a domain |
User/Machine Auth | For identity and system validation |
Email (S/MIME) | Encrypts/signs emails |
Code Signing | Verifies software authenticity |
SAN / Wildcard | Supports multiple domains/subdomains |
EV | Extended validation for high-assurance identity |
Qualified | Issued by a QTSP for legal compliance |
Certificate Expiration
Applications may warn, allow manual override, or block expired certificates
Expired certificates must be renewed, often via a streamlined version of original request
Certificate Protection and Key Recovery
Trusted root certs don’t hold secrets but shouldn’t be modified without permission
Private keys should never be exposed—store them securely
Some systems support key recovery, separate backup, or hardware key storage modules
Simplified Summary
Digital signatures prove identity and integrity using public/private keys
PKI enables global trust with certificates issued by Certificate Authorities
Certificates validate public keys and can be revoked, renewed, or monitored
Trust models range from self-signed to enterprise-wide PKI
Certificate lifecycle includes creation, issuance, monitoring, and expiration
Real-World Analogies
Digital Signature: Like a handwritten signature and wax seal combined
CA: Like a notary public verifying your ID before letting you sign a legal document
CRL/OCSP: Like a background check database ensuring a license or credential hasn’t been revoked
Lesson 5.10 PKI Applications
Overview
Public Key Infrastructure (PKI) is the backbone of modern digital trust. Its applications span from secure websites and encrypted emails to software validation and internal organizational security. This lesson highlights key PKI applications including the TLS handshake, digital certificates for software, and email security. You’ll also learn about the role of self-signed certificates and the differences between internal and public trust models.
Key Terms / Concepts
TLS (Transport Layer Security): Protocol securing internet communication
Certificate Authority (CA): Issues and validates digital certificates
Digital Certificate: Proves the identity of a server, user, or device
S/MIME: Email encryption and signature protocol
Code Signing: Verifies software authenticity and integrity
Self-Signed Certificate: Certificate not issued by a CA—trusted internally only
Wildcard / SAN / EV Certificates: Types of TLS certificates with varying scopes and validation levels
Reflection Prompt
When visiting a secure website or downloading an application, what tells your device or browser that it's safe to proceed? What role do certificates and PKI play in that decision?
Detailed Concepts
TLS Certificates and Applications
TLS certificates are used to encrypt communications between browsers and websites. These certificates:
Are issued to a domain, server, or device
Help authenticate identity and secure data
May contain organizational information, including:
Subject name
Validity period
Intended usage (e.g., encryption or authentication)
Types of TLS Certificates:
Type | Description |
|---|---|
Domain Validation | Verifies domain ownership |
Wildcard | Covers multiple subdomains |
Subject Alternative Name (SAN) | Supports multiple domain names |
Extended Validation (EV) | Highest level of identity verification |
TLS Handshake Process
The TLS handshake sets up a secure communication channel between client and server.
Step 1: Client Hello
Client sends supported TLS versions, cipher suites, and a random value
Step 2: Server Hello
Server responds with selected options, another random value, and its digital certificate
Step 3: Certificate Validation
Client checks if certificate is valid and trusted
Step 4: Server Hello Done
Indicates server is finished sending preliminary information
Step 5: Key Exchange
RSA: Client encrypts a pre-master secret with server’s public key
Diffie-Hellman: Both parties compute a shared key collaboratively
Step 6: Key Generation
Client and server generate symmetric session keys
Step 7: Cipher Exchange
Client and server exchange cipher specs and finalize encryption settings
Step 8: Secure Communication Begins
Data is encrypted with shared key
Messages include integrity mechanisms like HMAC
TLS Summary
Authentication: Server identity is verified
Encryption: Session key encrypts data
Integrity: HMAC prevents message tampering
Code Signing Certificates
Used by software developers to:
Sign apps, scripts, or installers
Prove code hasn’t been modified after signing
Provide users with confidence in software origin
Unsigned or self-signed downloads usually trigger security warnings.
Email Certificates – S/MIME
Encrypt and sign emails
Primarily used internally within organizations
Ensures:
Sender authenticity
Message confidentiality
Message integrity
Rarely used in public consumer email services.
Self-Signed Certificates
Created without a CA
Used for internal services or testing
Browsers and OSs do not trust them by default
Advantage | Risk |
|---|---|
Free and easy | No external validation |
Useful internally | Users may ignore warnings on real threats |
Simplified Summary
PKI is used in web browsing (TLS/SSL), software distribution (code signing), and secure messaging (S/MIME)
TLS handshake securely negotiates a session between a client and server
Certificates can be publicly trusted or self-signed depending on usage
Without proper validation, data and identities are vulnerable to attack
Real-World Analogies
TLS Handshake: Like exchanging IDs and agreeing on a secret handshake before speaking in a secure room
Code Signing: Like sealing a document with a wax seal—if the seal’s intact, the document is authentic
Self-Signed Certs: Like writing your own ID badge—it works in your building, but not in public
Lesson 5.11 Symmetric Key Applications
Overview
Symmetric key encryption is widely used for securing stored data—commonly referred to as data at rest. Operating systems, databases, and applications all leverage symmetric encryption to protect sensitive information from unauthorized access, especially in cases of theft or system compromise. In this lesson, we’ll explore real-world applications of symmetric encryption, including Windows BitLocker, the Encrypting File System (EFS), and database encryption techniques.
Key Terms / Concepts
Data at Rest Encryption: Protecting stored (inactive) data using encryption
BitLocker: Full-volume encryption in Windows
Encrypting File System (EFS): File- and folder-level encryption
FEK (File Encryption Key): Temporary key used to encrypt file contents
TPM (Trusted Platform Module): Secure hardware for storing keys
Transparent Encryption: Encrypts without user interaction
Column-Level Encryption: Secures specific fields within a database
Data Recovery Agent (DRA): Backup user account for decryption
Reflection Prompt
Consider your laptop getting lost or stolen—how could encryption prevent your sensitive data from falling into the wrong hands? What are the advantages and limitations of encrypting individual files versus the entire disk?
Detailed Concepts
Data at Rest Encryption
Symmetric encryption is commonly used to protect stored data. Key examples include:
1. Windows BitLocker
Encrypts the entire disk volume
Helps prevent unauthorized access when a system is lost or stolen
Prevents users from removing disks and reading them on other devices
Uses AES with CBC mode and stores the key on the TPM chip
Recovery options:
Offline recovery key
Data Recovery Agent (DRA)
Introduced in 2007, BitLocker is now available in Windows 11 Home (not supported in previous Home editions)
Linux Equivalents:
dm-crypt, LUKS (Linux Unified Key Setup)
2. Windows Encrypting File System (EFS)
Encrypts individual files or folders on NTFS volumes
Supported on all Windows editions except Home
Allows users to share encrypted files by adding other users’ public keys
Encryption Process:
Step | Action |
|---|---|
1 | System creates a File Encryption Key (FEK) |
2 | FEK encrypts file contents with AES |
3 | FEK is encrypted with user's public key |
4 | Encrypted FEK is stored with the file |
Decryption Process:
Step | Action |
|---|---|
1 | User's private key decrypts the FEK |
2 | FEK decrypts the file |
Linux Equivalents:
EncFS, Tomb, VeraCrypt
3. EFS Data Recovery Agent (DRA)
An alternate account that can decrypt files
Used to be the administrator by default
No longer set automatically—must be defined in:
Group Policy (local)
Active Directory (domain)
Good practice: configure a DRA for file recovery and backup key storage securely.
Database Encryption Techniques
Databases also use symmetric encryption for data at rest:
Type | Description |
|---|---|
Transparent Encryption | Encrypts and decrypts data automatically without user interaction |
Column-Level Encryption | Encrypts specific sensitive fields (e.g., SSNs or credit cards); complex to manage |
Application-Level Encryption | Managed by the app itself; offers flexibility but shifts responsibility to developers |
Simplified Summary
BitLocker encrypts entire disks to protect against physical theft
EFS encrypts individual files using a FEK + public key method
Databases use transparent or column-level encryption for sensitive data
Recovery methods include Data Recovery Agents and key backup
Linux and open-source equivalents exist for all major Windows encryption tools
Real-World Analogies
BitLocker: Like putting your entire laptop in a safe that only you can open
EFS: Like locking individual drawers in your file cabinet
Column-Level Encryption: Like redacting sensitive fields in a document while leaving the rest visible
TPM: Like a vault inside your computer that stores the encryption key
Lesson 5.12 Encryption Packages
Overview
Encryption packages bundle together tools and protocols that support secure communication, file protection, and certificate management. This lesson focuses on three widely used encryption packages: Pretty Good Privacy (PGP), GNU Privacy Guard (GPG), and OpenSSL. Each serves a unique role in modern cybersecurity, from encrypting email to powering secure websites.
These tools demonstrate how encryption is implemented and maintained across platforms and applications, and they often form the foundation of real-world encryption strategies.
Key Terms / Concepts
PGP (Pretty Good Privacy): Early hybrid encryption tool for secure email and files
GPG (GNU Privacy Guard): Open-source replacement for PGP
OpenSSL: Software library supporting SSL/TLS and encryption protocols
Web of Trust: Peer-based trust model used by early PGP
Hybrid Cryptographic Model: Combines symmetric and asymmetric encryption
X.509 Certificates: Digital certificates used to verify identity and support encrypted communication
Reflection Prompt
Have you ever sent or received a secure email, or visited a website with a padlock icon? What tools or encryption packages made that possible?
Detailed Concepts
Pretty Good Privacy (PGP)
Created in 1991, before encryption was built into most systems
Designed for email and file encryption
Uses a hybrid cryptographic model:
Encrypts the message with a symmetric key
Encrypts the symmetric key with the recipient’s public key
Original PGP Features:
Personal web of trust for public key validation
Used for:
Secure email communication
File encryption
Disk encryption
PGP became commercialized in 1997. While still used, its core ideas were adopted by modern systems.
GNU Privacy Guard (GPG)
Open-source implementation of PGP
Released in 1999
Command-line utility (but often used through graphical interfaces)
Key Features:
Free and open-source
Cross-platform (Linux, macOS, Windows)
Hybrid encryption
Compatible with email clients, file systems, and automation tools
GPG is widely used in open-source communities, DevOps workflows, and secure file sharing.
OpenSSL
A robust, open-source software library for implementing SSL/TLS and cryptographic functions
Powers HTTPS websites, VPNs, and secure application protocols
Common Use Cases:
Encrypting web traffic (TLS)
Creating and managing X.509 certificates
Performing encryption, decryption, hashing, and digital signatures
Generating and verifying CSRs (Certificate Signing Requests)
Why It’s Important:
Installed by default on many Linux systems
Widely adopted in secure web services and infrastructure
OpenSSL powers a large portion of the encrypted internet
OpenSSL Capabilities
Feature | Description |
|---|---|
Cryptographic Functions | AES, RSA, SHA, and other encryption and hashing algorithms |
Certificate Management | Create, sign, revoke, and validate digital certificates |
Cross-Platform | Supports Windows, Linux, and macOS environments |
Automation Ready | Easily scripted in DevOps, CI/CD, and security pipelines |
Simplified Summary
PGP: Early secure messaging tool that used asymmetric encryption and web of trust
GPG: Free and open version of PGP used across platforms and tools
OpenSSL: The most widely used encryption library for securing network communication, particularly via TLS
Real-World Analogies
PGP: Like mailing a letter in a locked box and sharing the key with a friend
GPG: Like an open-source version of that locked box—available to anyone, but still secure
OpenSSL: Like the plumbing behind every secure website, email, and VPN—it’s hidden but critical
Lesson 5.13 Cryptanalytic Attacks
Overview
Cryptanalytic attacks target the design or implementation of encryption systems in an attempt to reveal secret information—especially the encryption key—without authorized access. These attacks are essential to study because they highlight the potential weaknesses in even the strongest cryptographic systems. Understanding these methods is crucial for anticipating vulnerabilities and strengthening system security.
This lesson introduces the major types of cryptanalytic attacks, including brute force, side-channel, timing, and hash manipulation techniques.
Key Terms / Concepts
Brute Force Attack: Tries every possible key combination
Ciphertext-Only Attack: Relies solely on intercepted ciphertext
Known Plaintext Attack: Involves matching known plaintext and ciphertext
Side-Channel Attack: Uses physical observations (timing, light, etc.)
Fault Injection: Introduces errors to observe system behavior
Pass-the-Hash (PtH): Exploits hashed credentials instead of passwords
Rainbow Tables: Precomputed hashes used to reverse password hashes
Kerberos Exploitation: Targets weaknesses in SSO (Single Sign-On) systems
Reflection Prompt
If an attacker can’t crack the encryption directly, what other ways might they attempt to extract secret data? How might observing how a system behaves give them clues?
Detailed Concepts
What Are Cryptanalytic Attacks?
Cryptanalytic attacks aim to exploit:
Mathematical weaknesses in the encryption algorithm
Implementation flaws in how encryption is deployed
Human errors in key management or usage
These attacks do not necessarily require physical access to the system—they can often be performed remotely or with passive observation.
Common Cryptanalytic Attack Methods
Brute Force
Tries every possible key until the correct one is found
Effective only against weak encryption or short keys
Requires massive computational power and time
Ciphertext-Only Attack
Attacker only has intercepted ciphertext
Uses:
Frequency analysis
Statistical methods
Guesswork and brute force
Known Plaintext Attack
Attacker has both:
Plaintext (original message)
Corresponding ciphertext
Goal: Determine the encryption key
Implementation and Side-Channel Attacks
Implementation Attack
Exploits how the system is used—not the encryption itself
Example: Poor key storage, misconfigured crypto libraries
Side-Channel Attack
Observes physical or operational characteristics:
Power consumption
Electromagnetic leaks
Sound or timing
Chosen Ciphertext Attack
Attacker provides the victim with a crafted ciphertext
Observes the resulting plaintext
Goal: Infer key or decryption method
Fault Injection
A more active version of a side-channel attack
Techniques:
Power surges
Overclocking
Heating or cooling the system
Induces errors that reveal internal behavior or key bits
Timing Attack
Measures how long the system takes to encrypt/decrypt
Can reveal:
Key length
Algorithm type
Pattern of operation
Man-in-the-Middle (MITM) Attack
Attacker intercepts communication between sender and recipient
Modifies, captures, or relays data while both parties think they are talking directly
Can defeat:
Key exchanges (e.g., Diffie-Hellman without authentication)
SSL/TLS if not properly validated
Modern Cryptanalytic Techniques
Pass-the-Hash (PtH)
Exploits password hashes, not the passwords themselves
Used in Windows systems
Attacker obtains a stored NTLM or Kerberos hash and reuses it to authenticate
Kerberos Exploitation
In Single Sign-On (SSO) environments
If one system or token is compromised, all connected services may be accessible
Examples:
Ticket reuse
Session hijacking
Rainbow Table Attacks
Uses precomputed hashes of common passwords
Attacker compares hashes from a password file to the table
Fast and effective if passwords aren’t salted
Simplified Summary
Cryptanalytic attacks expose flaws in encryption systems or their use
They include brute force, side-channel, timing, and hash-based attacks
Attackers don’t need the password—they may use hashes or environmental cues
Defense depends on strong algorithms, secure key handling, and updated systems
Real-World Analogies
Brute Force: Like trying every combination on a padlock
Side-Channel: Like guessing a PIN based on which buttons are worn out
Pass-the-Hash: Like using a photo of a signature to forge a check
Rainbow Table: Like using a cheat sheet of known answers instead of guessing