Posts

Showing posts with the label Cryptography

Key Rotation: How Often, and How Not to Break Everything

Key rotation replaces a cryptographic key with a new one. The reasons are straightforward; the reason it goes wrong is that a key is rarely in only one place, and rotating it without knowing where they all are causes an outage. Why rotate at all Limiting exposure. A key compromised at some unknown point protects everything it ever encrypted. Rotating bounds that window — material encrypted under a retired key is unaffected by compromise of the current one, and vice versa. Cryptoperiod limits. Every key has a usable lifetime based on how much data it protects and how much cryptanalysis it is exposed to. Some modes have hard limits on data volume under a single key. Personnel change. Where a human ever held or could have held the key material, rotation on departure is the only way to revoke that knowledge. Compliance. Several frameworks mandate defined cryptoperiods, and an auditor will ask for evidence of rotation rather than a policy stating it happens. Practice. The u...

Forward Secrecy and Harvest-Now-Decrypt-Later

Forward secrecy means that compromising a long-term private key does not reveal past sessions. Each session's key is generated fresh and destroyed afterwards, so an attacker who obtains the server's key next year cannot decrypt the traffic they recorded this year. The problem it solves Older TLS used the server's RSA key directly for key transport: the client generated a session key, encrypted it with the server's public key, and sent it. Anyone holding the server's private key could decrypt that message and recover the session key. So an attacker recording traffic today and obtaining the private key later — through a breach, a subpoena, a departing administrator, or a flaw in the key's generation — could decrypt everything retroactively. One key compromise exposed years of sessions. Ephemeral key exchange removes that. The session key is derived through a fresh Diffie-Hellman exchange, the private values are discarded when the session ends, and the server...

PGP and GPG: The Web of Trust and Why Email Encryption Stayed Niche

PGP is a hybrid cryptosystem for encrypting and signing files and messages, and GPG is its widely used free implementation. Technically it has aged well; as an email encryption scheme it never achieved broad adoption, and the reasons are instructive about usability as a security property. How the hybrid scheme works PGP does not encrypt a message with the recipient's public key directly — asymmetric operations are far too slow for bulk data. Instead it generates a random symmetric session key, encrypts the message with that, then encrypts the session key with each recipient's public key and attaches the results. Each recipient uses their private key to recover the session key, and the session key to read the message. This is the same pattern TLS uses and the standard arrangement described under asymmetric encryption : asymmetric for key establishment, symmetric for the data. It is also why adding a recipient is cheap — one more encrypted copy of a small key rather than ...

DTLS vs TLS: Why UDP Needs a Different Handshake

Image
TLS assumes the transport beneath it is reliable and ordered. TCP guarantees both, so TLS can treat its handshake as a conversation where nothing is lost and nothing arrives out of sequence. Take that guarantee away and TLS breaks outright — not because the cryptography fails, but because the protocol has no way to recover from a dropped message. DTLS is TLS adapted to run over UDP. Same cipher suites, same certificates, same security guarantees; different plumbing. Why UDP Needs Anything Different Three problems appear the moment you remove TCP. Messages get lost. TLS would simply stall. DTLS adds its own retransmission timer for handshake messages, so a lost ServerHello is resent rather than hanging the connection. Messages arrive out of order. DTLS numbers each handshake message with an explicit sequence number so the receiver can reassemble them correctly. Records cannot depend on each other. In TLS, the stream cipher state carries across records. DTLS makes eac...

TLS Proxies: How Interception Works and What It Breaks

A TLS proxy terminates an encrypted session, inspects the plaintext, and establishes a second encrypted session to the real destination. Two connections instead of one, with the proxy holding the cleartext in the middle. It is, mechanically, a machine-in-the-middle — performed deliberately, with a trust relationship that makes the client accept it. Forward and reverse A forward proxy sits between your users and the internet. Clients are configured to trust a certificate authority you control, so when the proxy generates a certificate for whatever site the user requested, the browser accepts it. This is the deployment behind enterprise web inspection, and it is how a secure web gateway sees content at all. A reverse proxy sits in front of your own servers. It holds the real certificate for your domain, terminates client sessions, inspects and filters, then forwards to backend servers — often unencrypted inside a trusted network, though re-encrypting is better practice....

Code Signing: Certificates, Timestamping, and What a Signature Proves

Code signing attaches a digital signature to software so a recipient can confirm who published it and that it has not been altered since. It is the mechanism behind every "verified publisher" prompt and every silently accepted driver installation. What it proves is narrower than most people assume, and that gap is where the exam questions live. The mechanics The publisher hashes the software and encrypts the hash with their private key. That signature, along with the signing certificate, travels with the file. On the receiving side, the system hashes the file, decrypts the signature using the public key from the certificate, and compares. A match means the file is byte-for-byte what was signed. The certificate itself is validated up the chain to a trusted root, and revocation is checked. Signature valid plus chain valid plus certificate not revoked equals a trusted install; any failure produces a warning or a refusal depending on the platform's policy. Certificate au...

FIPS 140-3: What Validation Covers, and What It Does Not

FIPS 140-3 is the US and Canadian standard for cryptographic modules, and validation against it is mandatory for federal systems and increasingly demanded in regulated sectors. It certifies the module — the hardware or software boundary performing cryptography — not the product containing it, and the distinction is where most confusion lives. The four security levels Level 1 requires approved algorithms and correct implementation, with no physical security requirements. A software cryptographic library running on a general-purpose computer is typically Level 1, and this covers the large majority of validations. Level 2 adds tamper evidence — seals or coatings that show if the module was opened — and role-based authentication. Level 3 adds tamper resistance and response: the module actively detects intrusion and zeroises its keys when it happens. It also requires identity-based authentication and physical or logical separation of the interfaces carrying ...

TLS Configuration: Protocol Versions, Cipher Suites and What to Disable

TLS configuration is one of the few security tasks where the correct answer is short, well documented and still frequently got wrong — usually because a server was configured years ago and nobody revisited it. Protocol versions SSL 2.0 and 3.0 are long dead and must be disabled. TLS 1.0 and 1.1 are deprecated, removed from browsers, and disallowed by most compliance regimes. TLS 1.2 remains widely required for compatibility and is acceptable when configured with modern cipher suites. TLS 1.3 is the current version and is a substantial simplification: it removes every weak option rather than making them configurable, mandates forward secrecy, encrypts more of the handshake, and completes in fewer round trips. That design decision is the interesting one. TLS 1.2 is secure if configured correctly , and most vulnerabilities of the last decade exploited options it permitted. TLS 1.3 removes the ability to configure it wrongly, which is a stronger guarantee than documentation. ...

PKI Structure: Root CAs, Intermediates, and What a CA Compromise Means

A certificate is only meaningful because something you already trust vouches for it. Public key infrastructure is the arrangement of who vouches for whom, and its structure is designed around one assumption: that a signing key will eventually be compromised, and the damage must be survivable. Why roots sign intermediates rather than end entities A root certificate authority's private key is the anchor of trust for everything beneath it, and its public certificate is embedded in operating systems and browsers. It cannot be revoked in any practical sense — revoking it means every device with it in its trust store must be updated, which for a widely distributed root is effectively impossible. So the root key is kept offline , in hardware, under multi-person control, brought out rarely and ceremonially. It signs a small number of intermediate certificates and nothing else. Intermediates do the day-to-day issuing. They are online, they are exposed, and — crucially — th...

Blockchain for the Security Exam: Immutability, Consensus and Real Limits

A blockchain is an append-only ledger replicated across many participants, where each block contains a cryptographic hash of the one before it. That chaining is the whole mechanism: change any historical record and every subsequent hash no longer matches, so tampering is immediately detectable. Note the word. Tamper-evident , not tamper-proof. Nothing prevents someone altering their own copy; the design guarantees that everyone else can tell. What a Block Holds The hash of the previous block — the link in the chain. A timestamp. The transactions or data records. A Merkle root, a single hash summarizing all transactions in the block, which allows verifying that one transaction is included without downloading the rest. A nonce, where the consensus mechanism requires one. The security rests entirely on the collision resistance of the hash function. This is the same dependency that makes deprecated algorithms dangerous elsewhere — see cryptographic vulnerabilities ...

Secure Enclaves and Confidential Computing: Protecting Data in Use

Encryption protects data at rest and data in transit. Data in use — loaded into memory so a processor can work on it — has traditionally been unprotected, readable by the operating system, the hypervisor, and anyone with sufficient privilege on the machine. Confidential computing is the attempt to close that third state. The threat model The question is who you are protecting against, and the answer here is unusual: the infrastructure operator . In a cloud environment your workload runs on someone else's hardware, under their hypervisor, administered by their staff. Conventional controls protect you from other tenants and from external attackers; they do not protect you from a compromised hypervisor or a malicious administrator, because those sit beneath your operating system. Secure enclaves shrink the trusted computing base to the processor itself. Memory belonging to the enclave is encrypted by the hardware, with keys the processor holds and the operating system nev...

TPM: Measured Boot, Key Sealing, and What the Chip Actually Does

A Trusted Platform Module is a small dedicated chip — or a firmware equivalent — that stores keys and records what the system loaded as it started. It does not encrypt your disk or run your applications. It holds secrets in a place software cannot read them, and it attests to the state of the machine, and everything useful follows from those two capabilities. Platform Configuration Registers The mechanism behind measured boot, and the concept worth understanding properly. As the system starts, each stage measures the next before handing control to it — hashing the firmware, the boot loader, the kernel and its configuration — and extends the result into a Platform Configuration Register. Extending means the new value is combined with the existing one and the result stored, so a register accumulates a hash chain of everything measured into it. That chain cannot be rewound or set to an arbitrary value. Software can extend a register; it cannot reset one, and t...

IPsec Transport vs Tunnel Mode: AH, ESP, and Where Each Belongs

IPsec secures traffic at the network layer, which means it protects everything above it without any application needing to know. Two choices define any deployment: which mode — transport or tunnel — and which protocol — AH or ESP. The exam tests both, and the combinations behave quite differently. Transport mode Transport mode protects the payload of the original IP packet and leaves the original header in place. Source and destination addresses stay visible, and the packet routes exactly as it would have. That makes it appropriate for end-to-end protection between two hosts that are already routable to each other: a management workstation to a server, a server to a database, or host-to-host policies inside a data center. There is no encapsulation overhead beyond the IPsec header itself, so it is the more efficient of the two. Its limitation follows from the same property. Because the original addresses are exposed, transport mode provides no topology hiding, a...

VPN Protocols Compared: IPsec, WireGuard, TLS-Based and MACsec

Four ways to encrypt traffic between systems, operating at different layers with different trade-offs. Choosing between them is mostly about where the encryption boundary sits and what has to pass through in between. IPsec Network layer, so it protects everything above it without applications knowing. Two modes — transport for host to host, tunnel for gateway to gateway — and ESP as the protocol providing confidentiality and integrity, as covered under IPsec transport and tunnel mode . Its strengths are ubiquity and interoperability: every serious network device supports it, and it is the default for site-to-site connectivity between different vendors' equipment. Its weaknesses are complexity and traversal. The configuration surface is large — two negotiation phases, many algorithm choices, traffic selectors that must mirror — which is why the failures under VPN troubleshooting are so common. And ESP is IP protocol 50 rather than a port, so it needs NAT tra...

Key Derivation Functions: Turning a Password or a Secret Into Keys

A key derivation function turns input material into cryptographic keys. There are two distinct jobs, they have different requirements, and using the function designed for one to do the other is a recurring mistake worth understanding. Two different problems Deriving a key from a password. The input is low-entropy — a human chose it — so the function must be deliberately slow to make guessing expensive. This is key stretching, and it is what PBKDF2, bcrypt, scrypt and Argon2 do. Deriving keys from an existing high-entropy secret. The input is already strong — a shared secret from a key exchange, a master key, random bytes — so slowness serves no purpose and would only cost performance. The function must distribute the input's entropy evenly and produce independent outputs. This is what HKDF does. The distinction to hold: slowness is a defence against guessing, and it is pointless when there is nothing to guess. Running a shared secret from a Diffie-Hellma...

Password Hashing and Offline Cracking: Why Work Factor Beats Complexity

Offline password cracking is what happens after a breach. The attacker has the hashes and no longer has to talk to your service, so rate limiting, lockout and monitoring are all irrelevant. What remains is arithmetic: how many guesses per second the attacker can make, and how many guesses your passwords require. Why hashing, and why that is not enough Storing passwords hashed means a breach does not immediately reveal them. Hashes are one-way, so the attacker must guess a candidate, hash it, and compare. The problem is speed. General-purpose hash functions were designed to be fast, which is exactly wrong here — a modern GPU computes billions of fast-hash guesses per second, and dedicated hardware does far more. Against that rate, any password a human chose and can remember falls quickly. So a password hash function needs to be deliberately slow, and slow in a way that does not help the attacker more than the defender. Salting A salt is a unique random value stored alongsid...

Certificate Lifecycle for Device Identity: Enrolment, Renewal and Revocation

Certificate-based authentication is the strongest option for network access because there is no password to phish, steal or spray. It is also the option most deployments avoid, and the reason is never the cryptography — it is the operational lifecycle. Getting certificates onto thousands of devices, renewing them before they expire, and revoking them when a device is lost is the entire difficulty. Why certificates beat passwords here With 802.1X using EAP-TLS, both the client and the authentication server present certificates and each validates the other. The private key never leaves the device, so there is nothing an attacker can capture from the exchange and crack offline. It also closes the failure described under evil twin attacks . With tunnelled password methods, a client that skips server certificate validation hands its credentials to a rogue access point. With mutual certificate authentication there is no credential to hand over, and the client's own validation of th...

Side-Channel Attacks Explained: Timing, Power and Cache for SecurityX

A side-channel attack extracts secrets from the physical or behavioural characteristics of a system rather than from a flaw in its algorithm. The cryptography can be mathematically sound and still leak, because implementations run on real hardware that takes time, draws power and emits radiation. The channels Timing. Operations take different lengths of time depending on the data. A comparison that returns as soon as it finds a mismatched byte reveals how many bytes were correct. Repeated measurement recovers the secret one byte at a time. Power analysis. Power draw varies with the operation and the data. Simple power analysis reads the trace directly; differential power analysis uses statistics across many traces to extract keys even from noisy measurements. Relevant to smart cards, hardware security modules and embedded devices. Electromagnetic. Circuits radiate, and the emissions correlate with what they are processing. The defensive discipline against this is TEMPEST , cov...