all projects

NUS · CS4236 Cryptography in Practice · Aug 2026 – now

EduCrypto

I got into security because CTFs sounded fun. I still haven't done one, but I took CS2107, got an A, and liked it enough to make cybersecurity one of my specialisations, which is how I ended up in CS4236. The course was recently redesigned to be about using cryptography correctly in real systems rather than proving theorems, and the whole semester is built around one library, educrypto, that I add to every week.

Python · pytest · Flask · cryptography[ private until the course ends, by course policy ]

01How each week works

Each week the course publishes a feature request with the API and how it should behave, a public pytest suite, and a small Flask service that uses the library with a vulnerability in it. I implement the feature in educrypto until the tests pass, then write the attack that breaks into the service. The bug is never in the maths itself. It's in how the cryptography is used: a reused key, a setting left at an unsafe default, a ciphertext nobody checks.

02So far

We're still on symmetric-key cryptography, where both sides share the same key. The library has encoding and the one-time pad, a block cipher (a configurable substitution-permutation network), and block cipher modes. The attack there was on CBC run with a fixed key and IV, where the first block of ciphertext gave away which message had been encrypted.

Then MACs. One I remember is a forgery where the server's MAC didn't mix the secret key in properly, so it was effectively a known hash, and I could change a message and make a valid tag for it myself. Most recently, hash functions built three ways (Davies-Meyer, Merkle-Damgård and a sponge), with collisions found for both targets.

Public-key cryptography comes next: RSA, Diffie-Hellman, El Gamal and digital signatures, each with its own attack, and then how these fit together in real protocols.