Week 3 — Cryptography Used Correctly (and Misused)
← all weeks · worksheet · slides
Week 3 — Cryptography Used Correctly (and Misused)
OWASP 2025: A04 Cryptographic Failures · CWE: CWE-327, CWE-916, CWE-330
✅ This week — what to do
- Before class — Docker Desktop working (Week 1 Lab 0); skim last week's recap.
- Lecture (120 min) — weekly quiz first (~10 min), then the lecture. Slides:
slides/week03.md. - Lab (180 min) — play this week's game, then complete Worksheet 3 (
worksheet.md, Parts 1–4, incl. Audit the AI + EiPE/Prompt). Kickoff:docker compose up. - Submit — worksheet PDF → Classroom · code → GitHub · weekly quiz → Google Form. (How: SUBMISSION.md.)
- Project — apply this week's lesson to your NoteVault project where it fits.
Time breakdown: AGENDA.md. Grading: see the worksheet rubric.
Objectives
- Distinguish hashing vs encryption vs encoding.
- Store passwords with a vetted KDF (bcrypt/argon2).
- Recognize crypto misuse: ECB, hardcoded keys, weak RNG, MD5/SHA-1.
🔓 Signature game — "Capture the Hash"
- Crack weak hashes: given unsalted MD5 hashes, recover passwords (e.g.
hashcat/johnwith a wordlist). - ECB oracle: observe identical plaintext blocks → identical ciphertext; exploit to leak structure.
- Remediate: rewrite the sample service to use argon2id for passwords and AES-GCM (authenticated) for data, with keys from a secrets manager / env (never hardcoded).
Deliverable
Before/after code + a short note on which CWE each change closes.
References
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
- https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html