01What cryptography buys you
Networks are shared, observable, and hostile by default. Anyone on the path can read, copy, alter, replay, or inject traffic. Cryptography does not stop them from touching the bits; it makes reading useless and tampering detectable.
| Goal | Primitive | Question it answers |
|---|---|---|
| confidentiality | Encryption (symmetric or asymmetric) | Can an eavesdropper understand this? |
| integrity | Hash, MAC, authenticated encryption | Was this changed in transit? |
| authenticity | MAC, digital signature, certificate | Did this really come from who it claims? |
| non-repudiation | Digital signature | Can the sender later deny sending it? |
Notice what is missing: availability. Encryption protects data, not uptime. Ransomware is, ironically, encryption used against you.
- CyberChef — browser sandbox for encoding, hashing, and encrypting
- CrypTool — visual cryptography learning suite
- Dan Boneh — Cryptography I (Stanford, free to audit)
02Symmetric encryption
One secret key both locks and unlocks. Symmetric ciphers are fast enough to encrypt gigabits per second on commodity CPUs, especially with hardware AES instructions, which makes them the workhorse for all bulk data: disks, VPN tunnels, and the body of every TLS session.
Modes matter as much as the cipher
AES encrypts one 128-bit block. A mode of operation decides how to chain blocks for longer messages, and choosing badly leaks information even with a perfect cipher.
ECB
Each block independent. Identical plaintext blocks yield identical ciphertext, so patterns show through. Never use.
CBC / CTR
Hide patterns but provide no integrity on their own; an attacker can flip bits undetected without a separate MAC.
GCM / ChaCha20-Poly1305
Authenticated encryption (AEAD): confidentiality and tamper detection in one step. The modern default and the only kind TLS 1.3 allows.
- FIPS 197 — the AES standard
- OWASP Cryptographic Storage Cheat Sheet
- Bellare, M. & Namprempre, C. (2000). Authenticated encryption: relations among notions and analysis of the generic composition paradigm. ASIACRYPT.
03The key distribution problem
If every pair of parties needs its own shared secret, the number of keys grows quadratically: n(n−1)/2. And each key must somehow be delivered over a channel that is not yet secure, which is exactly the thing you were trying to build.
Before 1976 the answers were couriers, pre-loaded devices, and trusted key-distribution centers (the model Kerberos still uses). Public-key cryptography broke the trap.
04Asymmetric (public-key) cryptography
Each party owns a mathematically linked pair: a public key anyone may hold, and a private key that never leaves its owner. What one key does, only the other can undo. Security rests on problems that are easy one way and infeasible in reverse:
RSA
Multiplying two large primes is trivial; factoring the product back is not. Typical keys: 2048–4096 bits.
Elliptic curves (ECC)
Discrete logarithm on a curve. A 256-bit ECC key matches roughly 3072-bit RSA, so it is smaller and faster.
Diffie–Hellman
Not encryption at all: two strangers derive the same secret over a public channel. The basis of modern key exchange.
The price is speed: public-key operations are orders of magnitude slower than AES. So real systems use them sparingly, just long enough to agree on a symmetric key, which is the hybrid pattern behind TLS, SSH, IPsec, and Signal.
Diffie–Hellman alone does not tell you who you agreed with. A man-in-the-middle can run two exchanges and sit between you. That gap is filled by signatures and certificates.
- OpenSSL genpkey — generate RSA and EC key pairs
- Diffie, W. & Hellman, M. (1976). New directions in cryptography. IEEE Trans. Information Theory, 22(6).
- Rivest, R., Shamir, A. & Adleman, L. (1978). A method for obtaining digital signatures and public-key cryptosystems. CACM, 21(2).
05Hashes, MACs, and signatures
Three tools for integrity, each proving a little more than the last. They are often confused with each other and with encoding.
| Operation | Reversible? | Needs a key? | Purpose |
|---|---|---|---|
| Encoding (Base64, hex) | Yes, by anyone | No | Format conversion. Zero security. |
| Hashing (SHA-256) | No | No | Fingerprint / integrity |
| Encryption (AES, RSA) | Yes, with key | Yes | Confidentiality |
- NIST hash function standards (SHA-2, SHA-3)
- SHAttered — the first practical SHA-1 collision, and why SHA-1 is retired
06PKI and certificates
A public key is just a number. A certificate binds that number to an identity (a domain name, a person, a device) and is signed by a Certificate Authority the verifier already trusts. Browsers and operating systems ship with a few hundred root CA keys; everything else chains back to them.
Revocation is the weak spot: CRLs are large and stale, OCSP leaks browsing to the CA and often fails open. The industry response has been short-lived certificates (90 days and shrinking) issued automatically via ACME.
- Let's Encrypt — how ACME issuance works
- crt.sh — search Certificate Transparency logs for any domain
- Laurie, B. (2014). Certificate transparency. CACM, 57(10).
- Clark, J. & van Oorschot, P. (2013). SoK: SSL and HTTPS — revisiting past challenges and evaluating certificate trust model enhancements. IEEE S&P.
07TLS: everything combined
TLS is the hybrid pattern made concrete. An ephemeral Diffie–Hellman exchange creates fresh shared secrets, a certificate plus signature proves the server's identity, and an AEAD cipher protects the actual traffic. TLS 1.3 does all of that in a single round trip.
Forward secrecy
Session keys come from throwaway DH keys, so stealing the server's long-term key later cannot decrypt recorded past traffic. Mandatory in TLS 1.3.
Cipher suite
The negotiated bundle of key exchange, authentication, bulk cipher, and hash. TLS 1.3 cut the menu to five AEAD suites.
What TLS does not hide
IP addresses, timing, sizes, and usually the server name (SNI). Encrypted Client Hello (ECH) is closing that last gap.
- The Illustrated TLS 1.3 Connection — every byte explained
- Wireshark TLS wiki — capturing and decrypting handshakes
- Qualys SSL Labs server test · Mozilla SSL configuration generator
- RFC 8446 — TLS 1.3
- Cremers, C. et al. (2017). A comprehensive symbolic analysis of TLS 1.3. ACM CCS.
08Key management
Strong algorithms are the easy part. Most real cryptographic failures are key-handling failures.
- NIST SP 800-57 Part 1 Rev. 5 — Recommendation for Key Management
- OWASP Key Management Cheat Sheet
- Heninger, N. et al. (2012). Mining your Ps and Qs: detection of widespread weak keys in network devices. USENIX Security.
09When it goes wrong
DigiNotar (2011)
A breached Dutch CA issued fraudulent certificates, including one for Google, used to intercept users' traffic. Every browser distrusted the CA and it went bankrupt. Lesson: trust is only as strong as the weakest CA, which drove Certificate Transparency.
Heartbleed (2014)
A missing bounds check in OpenSSL's heartbeat extension let anyone read server memory, including private keys. The math was fine; the implementation was not.
Logjam (2015)
Many servers shared the same small Diffie–Hellman groups and still accepted export-grade parameters, enabling downgrade and precomputation attacks.
Common misconceptions
- Durumeric, Z. et al. (2014). The matter of Heartbleed. ACM IMC.
- Adrian, D. et al. (2015). Imperfect forward secrecy: how Diffie–Hellman fails in practice. ACM CCS.
- Cohn-Gordon, K. et al. (2017). A formal security analysis of the Signal messaging protocol. IEEE EuroS&P.
10Looking ahead: post-quantum
A large enough quantum computer running Shor's algorithm would break RSA, Diffie–Hellman, and ECC outright. Symmetric ciphers and hashes survive with larger sizes (AES-256). Because adversaries can harvest now, decrypt later, migration is already underway.
| Standard | Replaces | Basis |
|---|---|---|
| FIPS 203 · ML-KEM (Kyber) | DH / RSA key exchange | Module lattices |
| FIPS 204 · ML-DSA (Dilithium) | RSA / ECDSA signatures | Module lattices |
| FIPS 205 · SLH-DSA (SPHINCS+) | Signatures (conservative backup) | Hash functions only |
Major browsers and CDNs already negotiate hybrid key exchange (classical X25519 plus ML-KEM), so a session stays safe if either one holds.
- NIST Post-Quantum Cryptography project · FIPS 203
- Shor, P. (1997). Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Computing, 26(5).
- Bernstein, D. & Lange, T. (2017). Post-quantum cryptography. Nature, 549.
—References
Peer-reviewed
- Adrian, D. et al. (2015). Imperfect forward secrecy. ACM CCS. doi:10.1145/2810103.2813707
- Bellare, M. & Namprempre, C. (2000). Authenticated encryption. ASIACRYPT. doi:10.1007/3-540-44448-3_41
- Bernstein, D. & Lange, T. (2017). Post-quantum cryptography. Nature, 549. doi:10.1038/nature23668
- Clark, J. & van Oorschot, P. (2013). SoK: SSL and HTTPS. IEEE S&P. doi:10.1109/SP.2013.41
- Cohn-Gordon, K. et al. (2017). A formal security analysis of the Signal messaging protocol. IEEE EuroS&P. doi:10.1109/EuroSP.2017.27
- Cremers, C. et al. (2017). A comprehensive symbolic analysis of TLS 1.3. ACM CCS. doi:10.1145/3133956.3134063
- Diffie, W. & Hellman, M. (1976). New directions in cryptography. IEEE Trans. IT, 22(6). doi:10.1109/TIT.1976.1055638
- Durumeric, Z. et al. (2014). The matter of Heartbleed. ACM IMC. doi:10.1145/2663716.2663755
- Heninger, N. et al. (2012). Mining your Ps and Qs. USENIX Security. usenix.org
- Laurie, B. (2014). Certificate transparency. CACM, 57(10). doi:10.1145/2659897
- Rivest, R., Shamir, A. & Adleman, L. (1978). A method for obtaining digital signatures and public-key cryptosystems. CACM, 21(2). doi:10.1145/359340.359342
- Shor, P. (1997). Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput., 26(5). doi:10.1137/S0097539795293172