contentintech

Cryptography Cheatsheet

Quick reference for cryptography — algorithm choices, key sizes, password hashing params, and OpenSSL commands.

HashingAESRSATLS
NotesCheatsheet

Algorithm Selection (2026)

PurposeUseAvoid
SymmetricAES-256-GCM, ChaCha20-Poly1305DES, 3DES, RC4, ECB
Key exchangeECDHE (X25519), hybrid+ML-KEMStatic RSA transport
SignaturesEd25519, RSA-PSS, ML-DSAPKCS#1 v1.5, DSA
HashingSHA-256/512, SHA-3MD5, SHA-1
PasswordsArgon2id, scrypt, bcryptPlain/unsalted hashes
TransportTLS 1.3TLS 1.0/1.1, SSLv3

Key Size Recommendations

AlgorithmMinimum (2026)
AES256-bit (128-bit acceptable)
RSA3072-bit (2048 legacy min)
ECC (ECDSA/ECDH)256-bit (P-256 / Curve25519)
GCM nonce96-bit, unique per key
HMAC key>= hash output size (256-bit)
Random tokens128-bit+ from a CSPRNG

Password Hashing Params

FunctionBaseline params (OWASP 2026)
Argon2idm=19456 KiB, t=2, p=1 (tune up)
scryptN=2^17, r=8, p=1
bcryptcost/work factor >= 12
SaltUnique per password, auto-generated

OpenSSL Quick Reference

Keys & Certificates

# RSA-3072 private key + public key
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:3072 -out rsa.key
openssl pkey -in rsa.key -pubout -out rsa.pub

# ECC key (P-256) and Ed25519
openssl ecparam -name prime256v1 -genkey -noout -out ec.key
openssl genpkey -algorithm ed25519 -out ed.key

# CSR + self-signed cert (lab)
openssl req -new -key rsa.key -out req.csr
openssl req -x509 -key rsa.key -days 365 -out cert.pem

# Inspect a certificate
openssl x509 -in cert.pem -noout -text
openssl s_client -connect example.com:443 -servername example.com

Sign / Verify / Encrypt

# Sign and verify (RSA-PSS)
openssl dgst -sha256 -sign rsa.key -out sig.bin file.txt
openssl dgst -sha256 -verify rsa.pub -signature sig.bin file.txt

# Symmetric file encryption (AES-256-GCM via enc)
openssl enc -aes-256-cbc -pbkdf2 -salt -in f.txt -out f.enc
openssl enc -d -aes-256-cbc -pbkdf2 -in f.enc -out f.txt

Hashing Snippets

# File digests
sha256sum file            # Linux
shasum -a 256 file        # macOS
openssl dgst -sha256 file
openssl dgst -sha3-256 file

# HMAC-SHA256
openssl dgst -sha256 -hmac "secret" file

# Secure random
openssl rand -hex 32                      # 256-bit token
head -c 32 /dev/urandom | xxd -p

Symmetric vs Asymmetric

AspectSymmetricAsymmetric
KeysOne shared secretPublic + private pair
SpeedFast (bulk data)Slow
ExampleAES-GCM, ChaCha20RSA, ECC, Ed25519
Key distributionHard (must share secret)Easy (publish public key)
Typical roleEncrypt the dataExchange keys, sign

Common Pitfalls

  1. Hardcoded keys/secrets in code or repos.
  2. Reusing a nonce/IV with the same key (fatal in GCM).
  3. Using ECB mode or unauthenticated CBC.
  4. MD5 / SHA-1 for security decisions.
  5. Fast/unsalted hashes for passwords.
  6. Weak RNG (Math.random, rand()) for keys/tokens.
  7. Rolling your own crypto or protocol.
  8. Non-constant-time comparison of MACs/tokens.
  9. No key rotation or crypto-agility plan.

Section navigation