Quick reference for cryptography — algorithm choices, key sizes, password hashing params, and OpenSSL commands.
HashingAESRSATLS
Algorithm Selection (2026)
| Purpose | Use | Avoid |
| Symmetric | AES-256-GCM, ChaCha20-Poly1305 | DES, 3DES, RC4, ECB |
| Key exchange | ECDHE (X25519), hybrid+ML-KEM | Static RSA transport |
| Signatures | Ed25519, RSA-PSS, ML-DSA | PKCS#1 v1.5, DSA |
| Hashing | SHA-256/512, SHA-3 | MD5, SHA-1 |
| Passwords | Argon2id, scrypt, bcrypt | Plain/unsalted hashes |
| Transport | TLS 1.3 | TLS 1.0/1.1, SSLv3 |
Key Size Recommendations
| Algorithm | Minimum (2026) |
| AES | 256-bit (128-bit acceptable) |
| RSA | 3072-bit (2048 legacy min) |
| ECC (ECDSA/ECDH) | 256-bit (P-256 / Curve25519) |
| GCM nonce | 96-bit, unique per key |
| HMAC key | >= hash output size (256-bit) |
| Random tokens | 128-bit+ from a CSPRNG |
Password Hashing Params
| Function | Baseline params (OWASP 2026) |
| Argon2id | m=19456 KiB, t=2, p=1 (tune up) |
| scrypt | N=2^17, r=8, p=1 |
| bcrypt | cost/work factor >= 12 |
| Salt | Unique per password, auto-generated |
OpenSSL Quick Reference
Keys & Certificates
# RSA-3072 private key + public key
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:3072 -out rsa.key
openssl pkey -in rsa.key -pubout -out rsa.pub
# ECC key (P-256) and Ed25519
openssl ecparam -name prime256v1 -genkey -noout -out ec.key
openssl genpkey -algorithm ed25519 -out ed.key
# CSR + self-signed cert (lab)
openssl req -new -key rsa.key -out req.csr
openssl req -x509 -key rsa.key -days 365 -out cert.pem
# Inspect a certificate
openssl x509 -in cert.pem -noout -text
openssl s_client -connect example.com:443 -servername example.com
Sign / Verify / Encrypt
# Sign and verify (RSA-PSS)
openssl dgst -sha256 -sign rsa.key -out sig.bin file.txt
openssl dgst -sha256 -verify rsa.pub -signature sig.bin file.txt
# Symmetric file encryption (AES-256-GCM via enc)
openssl enc -aes-256-cbc -pbkdf2 -salt -in f.txt -out f.enc
openssl enc -d -aes-256-cbc -pbkdf2 -in f.enc -out f.txt
Hashing Snippets
# File digests
sha256sum file # Linux
shasum -a 256 file # macOS
openssl dgst -sha256 file
openssl dgst -sha3-256 file
# HMAC-SHA256
openssl dgst -sha256 -hmac "secret" file
# Secure random
openssl rand -hex 32 # 256-bit token
head -c 32 /dev/urandom | xxd -p
Symmetric vs Asymmetric
| Aspect | Symmetric | Asymmetric |
| Keys | One shared secret | Public + private pair |
| Speed | Fast (bulk data) | Slow |
| Example | AES-GCM, ChaCha20 | RSA, ECC, Ed25519 |
| Key distribution | Hard (must share secret) | Easy (publish public key) |
| Typical role | Encrypt the data | Exchange keys, sign |
Common Pitfalls
- Hardcoded keys/secrets in code or repos.
- Reusing a nonce/IV with the same key (fatal in GCM).
- Using ECB mode or unauthenticated CBC.
- MD5 / SHA-1 for security decisions.
- Fast/unsalted hashes for passwords.
- Weak RNG (
Math.random, rand()) for keys/tokens.
- Rolling your own crypto or protocol.
- Non-constant-time comparison of MACs/tokens.
- No key rotation or crypto-agility plan.