7 ms·
The Matasano Crypto Challenges
- Osmium 12y agoI only did the first two, which I hear are pretty trivial in comparison to the later ones, but I still had a great time and learned a hell of a lot in the process. Definitely highly recommended even if it's just for fun or out of idle curiosity, and no prior knowledge required. Looking forward to reading some 'proper' solutions now...
- sweis 12y agoThese are great challenges for learning crypto. They've provided solutions in 10 different languages.
- andrewjkerr 12y agoI've only been able to find working pages for the C++ solutions, but hopefully the rest will be added soon.
- tptacek 12y agoOops, the C++ stuff shouldn't be there yet. They will be there tomorrow.
- andrewjkerr 12y agoAh, that's good to know!
- rikacomet 12y agowhat about Perl?.. the other languages are mentioned in the side links at least :(
- tptacek 12y agoWe have solutions in Perl, but nobody that has submitted them has given us permission to share them. But we'll reach out and ask.
- sgdread 12y agoIt was a really nice adventure to complete all the 6 sets. Learned lots of useful stuff. My great thanks to tptacek and the team who prepared such a nice hands-on crypto class. P.S. 7th set is insane (in a good way).
- tptacek 12y agoThe 8th set ends in an elliptic curve attack that (a) is useful in the real world and (b) only one person I know has been able to implement. It is amazing.
- fierycatnet 12y agoSomething isn't right. Not Found http://cryptopals.com/sets/1/challenges/1/ruby http://cryptopals.com/sets/1/challenges/1/ruby
- meowface 12y agoThey haven't actually posted the solutions yet, I believe.
- krankin1 12y agotry running this in ruby: ['49276d206b696c6c696e6720796f757220627261696e206c696b65206120706f69736f6e6f7573206d757368726f6f6d'].pack('H*') --interesting string output for challenge 1.
- dmitris 12y agoGave me a bigger jolt than the morning coffee - here's a spoiler in Go: http://play.golang.org/p/YBfxhjvsOB http://play.golang.org/p/YBfxhjvsOB
- tptacek 12y agoThe solutions aren't up yet, so you have a very little bit of time in which to solve them before they're spoiled for you. Ruby should go up Wednesday. Tomorrow I know Python and C++ go up, and hopefully Haskell.
- peteretep 12y agoRandom meditation: I worked through a lot of the early exercises in Haskell, and partly to learn Haskell. I did a lot of things a "silly" way - didn't use the Vector libraries at all, for example. I learned a lot from doing that, and I wonder if a shiny set of Haskell examples using half of Hackage would provide the same learning experience. Also: do you have a set of Perl examples? If not, I'd be happy to put them together.
- radicality 12y agoOh, these links are for the solutions? I thought that clicking on a language should take me to a code submission page for that language where my submission will be judged against different test cases.
- csdrane 12y agoAlso by Matasano, and tons of fun: https://microcorruption.com https://microcorruption.com In-browser reverse engineering game.
- a473152 12y agoI find using a browser to do this type of tasks intensely frustrating.
- tptacek 12y agoYou don't need to use a browser; there's a simple JSON RPC interface.
- showdead 12y agoThat doesn't really do much for those of us with backgrounds that do not include Javascript / web development. Such as embedded processors, just to use an example that might be exactly the type of people who would find this challenge extra interesting. Full disclosure: I did several of these, but the browser issue is probably what kept me from doing more. It did not run in my (admittedly outdated) browser of choice, so I had to do some Chrome wrangling, which was the opposite of fun.
- tptacek 12y agoWhat Javascript are you talking about? Anything the browser interface can do, you can do directly with raw HTTP calls. The Rails front-end is actually just a thin proxy around a JSON RPC interface exposed by the Golang emulator itself. If your point is "that's not helpful for people who don't know how to use HTTP and JSON", I'm at a loss, because the problems Microcorruption wants you to solve are much, much harder than HTTP.
- a473152 12y agoHarder, but simpler (less complex). Wargames like SmashTheStack give you a Linux shell - it's much more fun this way. Just so you know, I ragequit microcorruption after three levels. Like the poster above, I know nothing about web development and have no intention of learning. The crypto challenge was really great though, thank you for that!
- aye 12y agoThanks for bringing this back! I've been wanting to study crypto, and I usually enjoy @tpacek's comments on this site.
- elwell 12y agoWould like to see real-world-ish Clojure crypto concerns.
- tptacek 12y agoYou mean solutions in Clojure? We got 'em. Or do you mean "crypto issues specific to Clojure"? What would those be?
- elwell 12y ago> You mean solutions in Clojure? We got 'em. Great, I'm interested. > Or do you mean "crypto issues specific to Clojure"? What would those be? Ah, I see now that these challenges are more of the language-agnostic type, rather than a demo of platform quirks. I suppose that negates my previous comment. Thanks for posting the challenges!
- Vivtek 12y agoIncredibly good news! I emailed earlier this year and got no response, and I was afraid the whole thing had gone away. It's like Christmas in August!
- calvins 12y agoI emailed twice in the last year (many months apart) and got no response either.
- weavie 12y agoI think they were massively overwhelmed with the response to the challenges. They were handling all the responses manually. It's great to see that they have made things more scalable and just put them up for everyone. It gives me a lot of faith in humanity when people share their knowledge and expertise so altruistically. Really looking forward to going through these. Thanks guys.
- yuhong 12y agoOn http://cryptopals.com/sets/4/challenges/31 http://cryptopals.com/sets/4/challenges/31 , I'd just make it return the offset of the first byte that don't match to simulate the information that a timing leak would reveal.
- Coincoin 12y agoOh, I made it return the whole thing since the timing attack would have leaked it anyway.
- goodvibes 12y agoAll cryptography is broken before implementation so, it really only looks like a compression mechanism for now.
- lelf 12y agoWill it be some more than implement & compare with the provided solution?
- mostafah 12y agoA more comprehensive test data would be awesome.
- deleted 12y ago[deleted]
- hobs 12y agoEaster egg spooked me: "I'm killing your brain like a poisonous mushroom"
- georgemcbay 12y agoThat's a line from the song "Ice, Ice, Baby" by Vanilla Ice. So it is no wonder it spooked you. I did a couple of the matasano challenges in the past and there were a lot of music lyrics strewn all over the place.
- fasteo 12y agoOut of context, but I couldn´t resist. "Matasano" is one of my favorite words in Spanish, not for its meaning, but for how it sounds. Anyway, here is the meaning: mata=kill sano=healthy So, literally it means to "kill the healthy" and it is used to refer to doctors, usually in colloquially, rather than pejorative, terms. Sorry for the interlude.
- tptacek 12y agohttps://news.ycombinator.com/item?id=4684599#up_4684845 https://news.ycombinator.com/item?id=4684599#up_4684845
- fasteo 12y agoIt´s good to know semantic differences between Spanish speaking countries. Here, talking from the south of Spain, matasano rarely refers to the "quackery" sense.
- fasteo 12y agoThinking about this, Matasano turns out to be a rather good name for your company. After all, your services are about trying to "kill the healthy" system, so to speak.
- tptacek 12y agoThat's how we rationalized it. :)
- juanuys 12y ago404 on http://cryptopals.com/sets/1/challenges/1/python http://cryptopals.com/sets/1/challenges/1/python
- kelnos 12y agoIf you actually read the big red warning on the main page, it notes that many pages are incomplete and some stuff isn't up yet.
- candeira 12y agoWhat textbook would be recommended for someone wanting not only to accept the challenge, but also to get some theory under their belt at the same time?
- tptacek 12y agoI'd recommend the Boneh Coursera class.
- mattstreet 12y agoSo I don't know what textbook to suggest but are you aware of: https://www.coursera.org/course/crypto https://www.coursera.org/course/crypto I've heard it's pretty good.
- mikevm 12y agoIf you're looking for a textbook, this one is pretty good: http://www.amazon.com/Introduction-Modern-Cryptography-Principles-Protocols/dp/1584885513 http://www.amazon.com/Introduction-Modern-Cryptography-Princ...
- cryptbe 12y agoIf you want to learn the math, check out http://www.amazon.com/Introduction-Mathematical-Cryptography-Undergraduate-Mathematics/dp/0387779930 http://www.amazon.com/Introduction-Mathematical-Cryptography....
- tptacek 12y agoI like this book a lot, but you won't need any of this math until set 8. I spent a lot of term learning things like lattice basis reduction algorithms (I used Strang's linear algebra book and MIT lectures) only to discover that there really isn't a whole lot that requires you to break out linear algebra in day-to-day cryptography. In particular: virtually all of block cipher crypto and message authentication relies on straightforward math. (It would be different if our challenges covered poly MACs, but we don't have good examples of common flaws in poly MAC implementations).
- cpach 12y agoGreat that the challenges are up! Feel free to join #cryptopals on Freenode :)
- joereggan190 12y agohttp://www.la15th.com/roihodson/_watch_manchester_united_vs_valencia_live_stream_highlights_online_full_match http://www.la15th.com/roihodson/_watch_manchester_united_vs_...
- wnevets 12y agoI still havent finished the first email
- showdead 12y agoGlad to see that this was not dropped! I did notice that matasano.com/articles/crypto-challenges/ has been returning a 404 for the past month or two. Will there be a way to automatically submit / advance, for those of us that would like to do them without encountering spoilers?
- jonahx 12y agoOnce solutions are up, will there a be a way to test your answer against solution without actually viewing the solution, as there is on project euler?
- nialo 12y agoI would expect probably not, but my experience with these is that it's generally pretty obvious when one has a correct solution. (except for the one problem in set 5 where they computed the hash of the ascii string representing the solution and I computed the hash of the actual number)
- andrewparker 12y agoA good complement to this set of challenges is Dan Boneh's Crypto class on Coursera. The coursera class is more theory-driven, whereas these challenges are more practical... they mix well. https://www.coursera.org/course/crypto https://www.coursera.org/course/crypto
- bradleyjg 12y agoI just finished Cryto I and immediately signed up for Cryto II. Very well done online class.
- Rangi42 12y agoI'm stuck on set 1 challenge 4, detecting single-character XOR. I know how the cipher works, having solved challenge 3, but when I brute-forced all 327 hex strings in their challenge data with each of the 256 possible one-byte keys, none of them deciphered to anything like English. I suspect a typo in their data, since one line -- 1c3df1135321a8e9241a5607f8305d571aa546001e3254555a11511924 -- actually has 58 hex digits, not 60. Has anyone else run into this problem? Edit: Of course I would solve this right after a post saying I can't. I was only looking at the (string, key) pairs which deciphered to all-printable plain text, but forgot that \r, \n, and \t count as printable ASCII characters.
- wtbob 12y agoI'll probably always regret not getting further into these than I did (life intruded, and then the psychic debt of being late disincentivised me from returning to them). One of these days I really do intend to finish 'em. Thanks for crafting them, and thanks for posing them. Hopefully you guys got some great new hires out of it!
- mostlybadfly 12y agoGot through the first 4 of set 1. This was emailed challenges though from a while ago. I'll check this out now.