SSCP Systems Security Certified PractitionerCryptographyHard
A forensic investigator is examining encrypted files found on a suspect's computer. The files were encrypted using a custom application. The investigator notices that a common attack vector involves guessing a short, predictable passphrase, which then directly acts as the encryption key. What cryptographic vulnerability is being exploited in this scenario?
- ALack of key stretching
- BWeak initialization vector (IV)
- CAbsence of a digital signature
- DInsufficient block size
Show answer & explanationAnswer & explanation
Correct answer: A. Lack of key stretching
This scenario describes a lack of key stretching, where a short, predictable passphrase is directly used as a cryptographic key. Key stretching (like using a PBKDF) is essential to transform weak, human-memorable passwords into strong, unpredictable keys that are computationally expensive to brute-force.
Why the other options are wrong
- B. A weak IV affects confidentiality and uniqueness of ciphertext, but the core issue here is the predictability of the key derived from the passphrase.
- C. Digital signatures provide authenticity and non-repudiation, which are separate concerns from the strength of an encryption key derived from a passphrase.
- D. Insufficient block size is a property of block ciphers, not directly related to the strength or derivation of a key from a passphrase.
Key Stretching
A technique used to increase the strength of a weak key, typically derived from a password or passphrase, by making it computationally more expensive to brute-force or guess.
- Transforms weak passwords into stronger keys.
- Uses iterative hashing or PBKDFs.
- Slows down brute-force attacks significantly.
Memory trick: Stretch the Key, Secure the Secret.