Loading
0x50Lesson 6 of 13

Crack a cipher, trust a hash

Break a Caesar cipher with frequency analysis, then see what makes modern hashes different.

22 min 5-question quiz 2 code exercises
By the end of this lesson you can
  • Break a substitution cipher using letter frequencies
  • Explain Kerckhoffs’s principle and why we don’t invent our own crypto
  • Use hashes to detect tampering, and know which are broken

Julius Caesar reportedly hid messages by shifting every letter three places: A→D, B→E… The shift is the key. It looks like gibberish, but there are only 25 useful keys - and even without trying them all, the text gives itself away: in English, E, T and A are the most common letters, so the most common letter in the ciphertext is probably one of them.

That trick, frequency analysis, was described by the Arab scholar al-Kindi in the 9th century. It breaks every simple substitution cipher.

Try it

Crack the intercepted message

Turn the wheel until the amber pattern (English) lines up with the blue one (the message), and the text becomes readable.

Intercepted message

Wkh vhuyhu urrp grru frgh lv vhyhq iru wzr hljkw. Fkdqjh lw diwhu wkh dxglw dqg whoo qr rqh.

Decrypted with shift 0

Wkh vhuyhu urrp grru frgh lv vhyhq iru wzr hljkw. Fkdqjh lw diwhu wkh dxglw dqg whoo qr rqh.

A→A
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z

Blue: letters in the message. Amber: typical English, moved by your shift. When the patterns line up, you’ve found the key.

Modern ciphers like AES are designed so ciphertext looks random and no pattern leaks. They follow Kerckhoffs’s principle: a system should stay secure even if everything about it except the key is public. That’s why the rule is don’t roll your own crypto - use well-reviewed algorithms and libraries, because secret, homemade schemes are almost always breakable.

Hashes: fingerprints for data

A cryptographic hash like SHA-256 turns any input into a fixed-size fingerprint (256 bits). Good hashes are:

  • deterministic - the same input always gives the same hash;
  • one-way - you can’t work back from the hash to the input;
  • collision-resistant - you can’t find two inputs with the same hash;
  • full of avalanche - change one bit of input and about half the output bits flip.

That’s how software downloads, Git commits and package lockfiles detect tampering. MD5 and SHA-1 are broken (collisions have been produced), so use SHA-256 or newer.

Try it

Hash explorer

Change one character in either text and count the flipped bits. Then make both texts identical and type a salt: the hashes change completely. Give every user a different salt, and identical passwords no longer share a hash.

SHA-256 of text 1

76aecfa667ee3b408c6cb64eaeca752a910330b17bc22981e77b86fcd914be7b

SHA-256 of text 2

9250560fd497ba42f5134ca5d3848e5a239e8dd7a85ac48bf155148d9975de4e

135 of 256 bits differ (53%).

Change one character and about half the bits flip - the “avalanche effect”. Highlighted digits differ between the two hashes.

Key takeaways

  • Simple substitution ciphers leak letter frequencies; frequency analysis breaks them.

  • Use public, well-reviewed algorithms - security should rest only on the key.

  • Hashes are one-way fingerprints that reveal tampering; avoid MD5 and SHA-1.

Lesson quiz

5 questions · pass with 4 correct · up to 50 XP

Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.

Practice: write Python

Write Python in the editor and run it against sample inputs. Python runs locally in your browser using a WebAssembly runtime.

Exercise 1

Crack a Caesar cipher automatically

+25 XP

Read a ciphertext line. For each shift 0-25, decrypt it and score the result by adding up FREQUENCY[letter] for every letter. Print shift N: PLAINTEXT for the best-scoring shift (the smallest shift if tied).

  • Shift 11
  • Shift 19
main.py
Loading editor…

Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.

Exercise 2

Verify a download

+25 XP

The first line is the publisher’s SHA-256 checksum. The second line is the downloaded content. Print OK if the SHA-256 of the content (UTF-8) matches, otherwise TAMPERED: got plus the first 12 hex digits of the actual hash.

  • Genuine
  • One extra character
main.py
Loading editor…

Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.

Questions about this lesson

Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.

Loading posts…

Did you like the lesson? 😆👍
Consider a donation to support our work: