28 câu hỏi từ primitive đến production
1. Base64 có bảo mật dữ liệu không?
Không, chỉ encoding và decode công khai. Follow-up: Base64 thường xuất hiện ở đâu trong key/token format?
2. Hash có phải mã hóa một chiều?
Không nên gọi vậy: hash không có key/decrypt và dùng cho digest. Follow-up: preimage khác collision?
3. SHA-256 dùng lưu password được không?
Không; quá nhanh trước offline guessing. Dùng Argon2id/scrypt/bcrypt/PBKDF2 với salt và cost. Follow-up: chọn cost thế nào?
4. Salt có cần bí mật?
Không; cần random/unique mỗi password để phá rainbow table và duplicate hash. Follow-up: pepper khác gì?
5. HMAC khác hash?
HMAC có secret key nên xác thực integrity và nguồn sở hữu key; hash thường không. Follow-up: vì sao không dùng hash(key||message)?
6. MD5/SHA-1 còn dùng lúc nào?
Có thể làm non-security checksum trong context rõ, không dùng cho chữ ký/collision-sensitive security. Follow-up: attacker lợi dụng collision thế nào?
7. Symmetric encryption là gì?
Cùng secret key encrypt/decrypt; nhanh nhưng phân phối và bảo vệ key khó. Follow-up: multi-tenant key hierarchy?
8. AES là mode hay cipher?
AES là block cipher; GCM/CBC/CTR là mode/construction. Follow-up: vì sao ECB lộ pattern?
9. AEAD cung cấp gì?
Confidentiality và integrity/authenticity của ciphertext, cộng AAD. Follow-up: AAD nên chứa gì?
10. Nonce có phải secret?
Thường không, nhưng phải đáp ứng uniqueness/randomness theo algorithm. Follow-up: GCM nonce reuse gây gì?
11. Authentication tag fail thì làm gì?
Reject toàn bộ, không dùng plaintext và không trả oracle chi tiết. Follow-up: log thế nào an toàn?
12. Fernet là gì?
Authenticated symmetric token recipe của Python cryptography, AES-CBC + HMAC, timestamp/versioned. Follow-up: metadata nào bị lộ?
13. Fernet có dùng hash password?
Không; Fernet decrypt được bằng key, password verification cần password KDF. Follow-up: nếu muốn derive Fernet key từ password?
14. MultiFernet rotation hoạt động sao?
Encrypt key đầu, decrypt thử danh sách; rotate re-encrypt token bằng primary mới. Follow-up: khi nào bỏ old key?
15. RSA mã hóa file lớn trực tiếp được không?
Không; giới hạn message và chậm. Dùng hybrid: AEAD cho data, RSA-OAEP wrap DEK. Follow-up: envelope chứa field nào?
16. OAEP để làm gì?
Padding randomized an toàn hơn cho RSA encryption; textbook RSA deterministic/insecure. Follow-up: hash/MGF parameters phải tương thích thế nào?
17. Public key có cần bí mật?
Không, nhưng cần xác thực đúng owner để tránh key substitution. Follow-up: certificate giải quyết phần nào?
18. Digital signature có mã hóa message?
Không; cung cấp integrity/authenticity, content vẫn đọc được. Follow-up: encrypt-then-sign hay sign-then-encrypt?
19. RSA-PSS khác RSA-OAEP?
PSS cho signature, OAEP cho encryption. Follow-up: PKCS#1 v1.5 legacy risks?
20. Signed JWT có bí mật không?
Không; JWS payload thường chỉ Base64URL. Confidentiality cần JWE hoặc channel/storage control. Follow-up: nên đặt PII trong token?
21. Certificate validation gồm gì?
Chain/trust anchor, hostname, validity, constraints/EKU và revocation policy. Follow-up: pinning rotation caveat?
22. KMS khác secret manager?
KMS quản cryptographic keys/operations; secret manager quản secret values/lifecycle, thường dùng KMS bên dưới. Follow-up: envelope encryption giảm KMS calls sao?
23. KEK và DEK khác gì?
DEK mã hóa data; KEK wrap/protect DEK. Follow-up: rotate KEK có cần re-encrypt data?
24. Key ID có bí mật không?
Thường không; là routing/version metadata, nhưng vẫn tránh lộ topology không cần thiết. Follow-up: thiếu key ID gây rotation issue gì?
25. Key rotation không downtime thiết kế sao?
New-write bằng primary mới, dual-read old/new, migrate/rewrap có metrics rồi retire old. Follow-up: rollback?
26. Constant-time comparison cần ở đâu?
MAC/tag/password verifier/signature-adjacent secrets để giảm timing leakage. Follow-up: network noise có loại bỏ risk?
27. Có nên tự thiết kế crypto protocol?
Hầu như không; dùng vetted library/construction/protocol và test vectors. Follow-up: review checklist cho library choice?
28. Crypto failure production điều tra sao?
Xác định algorithm/version/key ID/provider, encoding, nonce/AAD, clock, rotation state và exact error class; không log key/plaintext. Follow-up: evidence nào tái lập an toàn?