Skip to main content
JG is here with you ✨
A04:2025

Cryptographic Failures

Formerly "Sensitive Data Exposure"

Encryption Focus

What are Cryptographic Failures?

Cryptographic failures occur when sensitive data is not adequately protected. This includes using weak algorithms, hardcoded keys, deprecated protocols, and improper key management.

Formerly "Sensitive Data Exposure"MD5, SHA-1 DeprecatedTLS 1.0/1.1 Deprecated

Weak Hashing

Using MD5, SHA-1, or unsalted hashes for passwords

Examples: MD5, SHA-1, plain SHA-256

Hardcoded Secrets

API keys, passwords, and tokens in source code

Examples: AWS keys, JWT secrets

Weak TLS

Deprecated protocols and cipher suites

Examples: TLS 1.0, RC4, 3DES

Insecure Random

Using Math.random() for security purposes

Examples: Predictable tokens, IVs

ECB Mode

Using encryption modes that leak patterns

Examples: AES-ECB reveals patterns

Missing Encryption

Transmitting or storing sensitive data in plaintext

Examples: HTTP, unencrypted DBs

Hash Algorithm Security Status

AlgorithmBitsCrack TimeStatusNotes
MD5128< 1 secondDEPRECATEDCollision attacks proven since 2004. Never use for security.
SHA-1160~$45,000 (cloud)DEPRECATEDSHAttered attack (2017) broke SHA-1. Deprecated by NIST.
SHA-256256~10^50 yearsSECUREPart of SHA-2 family. Currently secure for most applications.
SHA-384384~10^75 yearsSECURESHA-2 variant with larger output. Good for high-security needs.
SHA-512512~10^100 yearsSECUREStrongest SHA-2 variant. Recommended for long-term security.
SHA-3-256256~10^50 yearsSECUREKeccak-based. Different design than SHA-2, quantum-resistant properties.
bcrypt184Configurable (slow)SECUREPassword hashing with adaptive cost. Recommended for passwords.
Argon2id256Memory-hardSECUREWinner of PHC. Best choice for password hashing. Memory-hard.

Related CWE Entries

Built by an OWASP Member • Part of the OWASP Web Security Lab Series

Open to AI-Focused Roles

AI Sales • AI Strategy • AI Success • Creative Tech • Toronto / Remote

Let's connect →
Terms of ServiceLicense AgreementPrivacy Policy
Copyright © 2026 JMFG. All rights reserved.