Security goals, encoding và randomness

Cryptography chỉ có ý nghĩa sau threat model. Confidentiality giấu nội dung; integrity phát hiện sửa đổi; authenticity chứng minh nguồn. Non-repudiation còn phụ thuộc identity proofing, key custody và audit.

Encoding không phải encryption

Base64, hex và URL encoding chỉ đổi biểu diễn byte để truyền/lưu; ai cũng decode được. Compression và obfuscation cũng không tạo confidentiality.

Randomness

Key, nonce, token và salt phải dùng CSPRNG như Java SecureRandom hoặc Python secrets. Không dùng timestamp, Math.random() hay PRNG mô phỏng cho secret. Entropy thấp làm key space nhỏ dù thuật toán mạnh.

Nguồn

← Mục lụcHash/MAC →