1
CS 161, Summer 2026 @ UC Berkeley
Slides credit: Nick Weaver, Nicholas Ngai, Peyrin Kao, Henry Corrigan-Gibbs, Jonah Bedouch
Cryptography Implementation Bugs
Lecture 19 (Transport 7)
Today: Cryptographic Implementation Bugs
Most common source of crypto bugs: Implementation.
This lecture will show many real-world examples.
Measuring Randomness
Lecture 19, CS 161, Summer 2026
Randomness
Side Channels
Nothing-Up-My-Sleeve Numbers
Snake Oil Cryptography
Randomness is Essential
Cryptographic schemes assume access to random values.
If an attacker can predict a random number, things can catastrophically fail.
What is Randomness?
For cryptography: "Sample uniformly at random."
Notice: Randomness is not a property of the value, it's a property of the method used to generate the value.
Measuring Randomness: Entropy
Entropy is a measure of uncertainty, i.e. how unpredictable outcomes are.
Randomness Is Hard To Measure
Measuring entropy/randomness is hard, because:
Sampling Algorithm
H(time_of_day)
9f42b057444dcdbfcaa4b6f34b527e58871e0532480f933abac0bb018c7b8f2d
b51f2044c51e11fddcd26fbe786c4f82e3db220b2ab8b79705abec08bebd0509
a2d2fde7f469b706ea8d26a6121b00045c847e17612ba80ca1a56cdcbcc6653a
Unique every time, looks totally random!
Super easy for an attacker to guess…
Bad Randomness is a Real Problem
If you generate keys with bad randomness, an attacker may be able to recover them!�Example:
Some schemes fail completely when randomness is reused. �Example:
Generating Randomness
Lecture 19, CS 161, Summer 2026
Randomness
Side Channels
Nothing-Up-My-Sleeve Numbers
Snake Oil Cryptography
True Randomness
True randomness comes from physical phenomena (hardware, not software).
Common sources of randomness:
Problem: Hardware randomness is expensive and slow.
Exotic entropy source: Cloudflare has a video stream of a wall of lava lamps.
CPU�Clock
Mouse Wiggle
Key Presses
Random Circuit
Hardware
Software Randomness with PRNGs
To make randomness cheap/fast:
CPU�Clock
Mouse Wiggle
Key Presses
Random Circuit
Hash
Seed
OS's PRNG
Pseudorandom Output
Hardware
Operating System (OS)
Pseudorandom Number Generators (PRNGs)
PRNGs use a little bit of true randomness to generate a lot of random-looking output.
A PRNG should be seeded with all available sources of entropy.
Reseeding can be used to add even more entropy as it becomes available.
Pseudorandom Number Generator (PRNG) : {0,1}k → {0,1}* | |
Inputs: | k-bit seed |
Output: | Arbitrary-length random output |
Properties: |
|
Many PRNGs also support reseeding. (Not shown in this definition.)
CTR-DRBG
An example of a PRNG: CTR-DRBG, based on CTR mode!
0
AES Enc
E(Seed, 0)
Seed
1
AES Enc
E(Seed, 1)
Seed
2
AES Enc
E(Seed, 2)
Seed
As-good-as-random bits
…
"Deterministic Random Bit Generator," another term for PRNGs.
Software Randomness with PRNGs
To access randomness, the application has to ask the operating system (using a syscall).
Solution:
CPU�Clock
Mouse Wiggle
Key Presses
Random Circuit
Hash
Seed
OS's PRNG
Pseudorandom Output
Hardware
Operating System (OS)
Application's PRNG
Cryptographic Secrets
Application
Breaking Randomness
Lecture 19, CS 161, Summer 2026
Randomness
Side Channels
Nothing-Up-My-Sleeve Numbers
Snake Oil Cryptography
Breaking Randomness at Hardware-Level
At the hardware level, weak sources of entropy can be guessed.
Example: Network routers (2008).
Fixes: Use more diverse sources of randomness, wait longer to gather more entropy.
Researchers recovered 0.5% of private keys for TLS hosts!
CPU�Clock
Mouse Wiggle
Key Presses
Random Circuit
Hash
Seed
OS's PRNG
Pseudorandom Output
Hardware
Operating System (OS)
Application's PRNG
Cryptographic Secrets
Application
Breaking Randomness at OS-Level
At the OS level, seed reuse can occur.
Example: VMs.
A similar problem exists at the application layer when using fork() to clone processes.
Hash
Seed
OS's PRNG
Pseudorandom Output
Operating System (OS)
CPU�Clock
Mouse Wiggle
Key Presses
Random Circuit
Hardware
Application's PRNG
Cryptographic Secrets
Application
Breaking Randomness at Application-Level (1/3): Insufficient Randomness
At the application level, it's possible for a bug to prevent randomness from ever reaching the PRNG.
Example: OpenSSL on Debian (2008).
Fix: Don't touch crypto code if you don't know what it does.
Hash
Seed
OS's PRNG
Pseudorandom Output
Operating System (OS)
CPU�Clock
Mouse Wiggle
Key Presses
Random Circuit
Hardware
Application's PRNG
Cryptographic Secrets
Application
Breaking Randomness at Application-Level (2/3): Bad PRNG
At the application level, it's possible to use a completely insecure PRNG.
Not all PRNGs are cryptographic PRNGs!
Example: Slot machine hacking (2017).
Hash
Seed
OS's PRNG
Pseudorandom Output
Operating System (OS)
CPU�Clock
Mouse Wiggle
Key Presses
Random Circuit
Hardware
Application's PRNG
Cryptographic Secrets
Application
[Not in scope] Try This At Home?
🤑
Breaking Randomness at Application-Level (3/3): PRNG Output Misuse
At the application layer, you can use secure randomness wrong, e.g. not using random IVs.
Example: Sony PlayStation 3 (2010).
Hash
Seed
OS's PRNG
Pseudorandom Output
Operating System (OS)
CPU�Clock
Mouse Wiggle
Key Presses
Random Circuit
Hardware
Application's PRNG
Cryptographic Secrets
Application
The key was burned into hardware, so Sony couldn't change it.
Recall: ECDSA with a fixed nonce leaks the key!
There's More Where That Came From
Randomness bugs are very common.
CVE stands for "Common Vulnerabilities and Exposures," a public database maintained by security researchers.
Side Channels
Lecture 19, CS 161, Summer 2026
Randomness
Side Channels
Nothing-Up-My-Sleeve Numbers
Snake Oil Cryptography
Side Channels
Side channels: Information about the plaintext revealed as a result of the implementation of the scheme, not the scheme itself.
While a scheme runs, an attacker could observe:
More on side channels when we discuss isolation.
Nothing Up My Sleeve Numbers
Lecture 19, CS 161, Summer 2026
Randomness
Side Channels
Nothing-Up-My-Sleeve Numbers
Snake Oil Cryptography
Public Constants in Cryptography
Cryptography uses a lot of public constants:
Usually, any value works, but the designer needs to choose some constant.
Dual EC DRBG: Something Up Their Sleeves
DUAL_EC_DRBG was a NSA-proposed PRNG added to NIST standards in 2006.
It had many problems from the start — it wasn't even a good PRNG!
After a while, security researchers noticed something…
Theory: NSA proposed the scheme on purpose to learn secret keys.
In general, a backdoor is an undocumented method of bypassing cryptography schemes (such as the relationship in this scheme).`
And used their influence to add the scheme to the standards, so that developers would use it by default.
DES: Something Up Their Sleeves...Maybe?
Mysterious public parameters can cast doubt, even when a design is solid.
Example: DES was the block cipher standard before AES.
Moral of the Story: Nothing-Up-My-Sleeve Numbers
Good systems should transparently describe how public parameters are generated:
Snake Oil Cryptography
Lecture 19, CS 161, Summer 2026
Randomness
Side Channels
Nothing-Up-My-Sleeve Numbers
Snake Oil Cryptography
Snake Oil
Snake oil: Fraudulent "cure-all" medicines sold in the 1700s and 1800s.
Snake oil cryptography: Useless security products sold to uninformed buyers.
Signs of Snake Oil Cryptography (1/2)
Amazingly long key lengths.
New algorithms and wild protocols.
NSA = National Security Agency, part of the US government.
Signs of Snake Oil Cryptography (2/2)
Fancy-sounding technical buzzwords.
"One time pads."
Rigged "cracking contests."
Snake Oil Cryptography Example: Nick Weaver vs. Crown-Sterling (1/2)
Buzzwords, wild new math, and rolling your own crypto are all signs of snake oil.
| |
Alleged "snake oil" crypto company sues over boos at Black Hat | |
Sean Gallagher | August 23, 2019 |
Grant's presentation, entitled "Discovery of Quasi-Prime Numbers: What Does this Mean for Encryption," was based on a paper called "Accurate and Infinite Prime Prediction from a Novel Quasi-PrimeAnalytical Methodology." That work was published in March of 2019 through Cornell University's arXiv.org by Grant's co-author Talal Ghannam—a physicist who has self-published a book called The Mystery of Numbers: Revealed through their Digital Root as well as a comic book called The Chronicles of Maroof the Knight: The Byzantine. The paper, a slim five pages, focuses on the use of digital root analysis (a type of calculation that has been used in occult numerology) to rapidly identify prime numbers and a sort of multiplication table for factoring primes. | |
Snake Oil Cryptography Example: Nick Weaver vs. Crown-Sterling (2/2)
| |
Medicine show: Crown Sterling demos 256-bit RSA key-cracking at private event | |
Sean Gallagher | September 20, 2019 |
Nicholas Weaver, lecturer at the University of California Berkeley's Department of Electrical Engineering and Computer Sciences, reacted to Grant's latest demonstration with this statement to Ars: It was previously an open question whether Mr Grant was a fraud or just delusional. His new press release now makes me certain he is a deliberate fraud. He received a lot of feedback from cryptographers, both polite and rude, so showing this level of continued ignorance is willful at this point. His video starts with the ridiculously false notion that factoring is all there is for public key. He then insists that breaking a 256 bit RSA key or even a 512b key is somehow revolutionary. It's not. Professor [Nadia] Heninger at UCSD, as part of her work on the FREAK attack, showed that factoring a 512 bit key is easily accomplished with less than $100 of computing time in 2015. His further suggesting that breaking 512-bit breaks RSA is also ridiculous on its face. Modern RSA is usually 2048 bits or higher, and there is a near-exponential increase in the difficulty of factoring with the number of bits. At this point I have to conclude he is an outright fraud, and the most likely explanation is he's looking to raise investment from ignorant accredited investors. And now I wonder how many other companies he's started are effectively fraudulent. | |