Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

Crypto is Fine. The Code is Not.

Blog post from Semgrep

Post Details
Company
Date Published
Author
Diptendu Kar
Word Count
939
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

Every day, new Common Vulnerabilities and Exposures (CVEs) and security advisories emerge, and the Semgrep supply-chain team examines them, identifying patterns in cryptographic advisories. These patterns often reveal that vulnerabilities arise not from the cryptographic math itself but from skipped validation checks in the code, such as improper signature verification and algorithm confusion. This insight led to an extensive analysis of the GitHub Security Advisory (GHSA) dataset, confirming that many cryptographic failures involve code errors, not mathematical ones. A real-world example is CVE-2021-43572, where a FinTech signing library failed to perform a simple range check on ECDSA signature values, allowing attackers to bypass signature verification. This recurring issue highlights the need for focusing on code validation rather than cryptography itself, as many security bugs arise from overlooked input checks. Presentations at BSidesLV and DEF CON 34 emphasize that even without a deep cryptography background, understanding what an attacker can manipulate and applying range checks can prevent these vulnerabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.