P52 · Cryptography Foundations
hashing, HMAC, symmetric & public-key crypto, key exchange
Applied cryptography from the ground up — hashing, HMAC, symmetric modes, Diffie–Hellman and public-key crypto, each built as a toy you understand alongside the attack it defends against.
Cryptography is usually taught as a warning: do not roll your own. That advice is correct for production and useless for understanding, because it leaves you using primitives whose failure modes you have never seen. This pillar takes the other route. You build small, deliberately non-production versions of each primitive — a fingerprint, a keyed fingerprint, a cipher, a key exchange — and you build the attack that breaks the naive version alongside it, so that the rule you eventually follow in production is one you can justify rather than recite.
The order is not arbitrary; each primitive exists because the previous one is not enough. A hash gives you a fingerprint, but anyone can compute it, so it proves nothing about who sent the message — hence HMAC, and with it the constant-time comparison that stops a timing side channel from leaking the answer one byte at a time. HMAC assumes a shared key, and a cipher assumes the same, which raises the obvious question of how two strangers ever get one: Diffie-Hellman answers it in the open, and then fails against a man in the middle, which is precisely the gap certificates are invented to close in P53. Along the way you will see why the mode of a symmetric cipher matters — ECB leaves the outline of the image you encrypted plainly visible — and what authenticated encryption adds that confidentiality alone does not.