Sitelet https://github.com/systemslibrarian/crypto-lab
Skip to content

About

Crypto Lab is a free, browser-based cryptography teaching collection: interactive demonstrations spanning classical cryptography, modern protocols, cryptanalysis, privacy technologies and post-quantum cryptography, built on real primitives and organized into guided learning paths for self-learners and course modules with worksheets for instructors.

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Repository files navigation

Crypto Lab

DOI 🥇 Crypto Lab · 2026 Cybersecurity Excellence Awards — Gold Winner

Teaching a course? → Course modules for instructors

Browser-based cryptography demos — no backends, no accounts, just the math.*

* ⚡ One deliberate exception: Blind Oracle runs a live Rust/TFHE-rs server to demonstrate real fully homomorphic encryption — its evaluation key cannot decrypt, and the browser keeps the result verdict local.

A curated collection of single-concept cryptography demonstrations. Each one isolates a real primitive or protocol and makes it interactive in the browser. Classic algorithms, post-quantum schemes, zero-knowledge proofs — all grounded in real specifications, not toy reimplementations.

Live → https://crypto-lab.systemslibrarian.dev/


Learning Paths

Curated, ordered journeys through the catalog. Pick one on the live site and follow it step by step.

Path Focus Journey
Start Here For a first visit, with no cryptography assumed: ciphers you can do on paper, then the fingerprint, where keys come from, public and private keys, agreeing on a secret in the open, the signature, the padlock, the password and the quantum clock. Thirteen steps, every one a Beginner lab -- no maths beyond arithmetic. One more is planned, on who can read your messages, and will be added when that lab lands. Dead Sea Cipher → Vigenère Break → Enigma Forge → Hash Zoo → Good Randomness → Locks and Keys → Agreeing in Public → Ed25519 Forge → HTTPS Padlock → Chain of Trust → Bcrypt Forge → What Is PQC → Harvest Timeline
Developer A builder's journey — from primitives to the protocols you actually ship. Babel Hash → AES Modes → KDF Chain → Educational RSA → RSA Forge → Point Arithmetic → Curve Lens → Signed Bytes → DH MITM → X3DH Wire → Noise Pipe → OPAQUE Gate → WebAuthn → SSH Handshake → TLS Handshake → PQ TLS Handshake
Cryptanalyst Mathematical attacks exploit structure and statistics; oracles exploit response differences; side channels measure timing or power; faults alter computation. Follow each from classical ciphers to PQC. Dead Sea Cipher → Biham Lens → Matsui Line → Padding Oracle → Timing Oracle → Power Trace → Masked Core → Salamander → Nonce Collision → Entropy Collapse → Nonce Lattice → Frozen Heart → KyberSlash → Lattice Fault
Post-Quantum A focused track on PQ KEMs, signatures, hybrids, and migration. PQ Families → Kyber Vault → KEM Trap → Dilithium Seal → MAYO Seal → Hybrid Wire → Hybrid PQC → Downgrade Wire → PQ TLS Handshake → PQ Rotation → Harvest Timeline
Key Exchange How two parties agree on a secret — classical ECDH to hybrid post-quantum handshakes. Key Exchange → Curve Lens → DH MITM → X3DH Wire → Ratchet Wire → Noise Pipe → OPAQUE Gate → TLS Handshake → Kyber Vault → Hybrid Wire → PQ TLS Handshake

All Demos

Grouped the way the live catalog groups them, in the same order.

Foundations

Demo Description Source Primitives
Phantom Vault Derive any password from a master passphrase using HMAC-DRBG. Nothing stored, nothing synced, nothing left behind to breach. crypto-lab-phantom-vault PBKDF2-SHA-256 · HMAC-DRBG · Rejection Sampling
DRBG Arena HMAC_DRBG, CTR_DRBG, and Hash_DRBG with state visualizers, seeding, reseeding, and live NIST SP 800-22 statistical tests. The correct-case companion to Corrupted Oracle. crypto-lab-drbg-arena HMAC_DRBG · CTR_DRBG · Hash_DRBG · NIST SP 800-90A
Shamir Gate Split a secret into shares using Shamir's Secret Sharing and reconstruct with any qualified threshold subset. Polynomial interpolation made tangible. crypto-lab-shamir-gate Shamir SSS · Lagrange Interpolation · GF(p)
Babel Hash SHA-256, SHA3-256, and BLAKE3 side by side with live avalanche visualization, length extension attack demo, and HMAC defense. crypto-lab-babel-hash SHA-256 · SHA3-256 · BLAKE3 · HMAC
Curve Lens Point addition, scalar multiplication, and live ECDH across P-256, Curve25519, secp256k1, and brainpoolP256r1, whose RFC 5639 seeds it recomputes from π and e. P-256's seed has no published derivation. crypto-lab-curve-lens brainpoolP256r1 · Curve25519 · ECDH · P-256
Point Arithmetic Drag P and Q to see the chord-and-tangent group law, flip ℝ↔𝔽ₚ to run the identical exact arithmetic, then step double-and-add and feel why the ECDLP is hard. crypto-lab-ec-point-arithmetic Group Law · Chord-and-Tangent · Scalar Mult · secp256k1
MAC Race HMAC, CMAC, Poly1305, and GHASH compared with live length extension attack, timing attack, and nonce reuse demonstrations. Real WebCrypto operations. crypto-lab-mac-race HMAC · CMAC · Poly1305 · GHASH
KDF Chain HKDF, PBKDF2, scrypt, and Argon2id compared side by side with live parameter tuning, real timing measurements, and a KDF decision tree. crypto-lab-kdf-chain HKDF · PBKDF2 · scrypt · Argon2id
Hash Zoo SHA-256 vs SHA3-256 vs BLAKE3 internals — live avalanche analysis, Merkle-Damgård/sponge/tree construction diagrams, and timing benchmarks. crypto-lab-hash-zoo SHA-256 · SHA3-256 · BLAKE3 · Merkle-Damgård
World Hashes SM3 (China), Streebog (Russia), and Kupyna (Ukraine) alongside SHA-256 and SHA-3. Five-way simultaneous hashing, avalanche analysis, and cryptographic sovereignty context. crypto-lab-world-hashes SM3 · Streebog · Kupyna · SHA-256
KDF Arena Live timing and memory comparison of HKDF, PBKDF2, scrypt, and Argon2id with adjustable cost parameters and bar chart visualization. crypto-lab-kdf-arena HKDF · PBKDF2 · scrypt · Argon2id
Poly1305 MAC Polynomial evaluation over GF(2¹³⁰−5), constant-time tag verification, key-reuse attack visualizer, and Polynomial Stepper. crypto-lab-poly1305-mac Poly1305 · GF(2¹³⁰−5) · Key-Reuse Attack · Polynomial Stepper
Merkle Vault The structural view: draw a tree up to 16 leaves with real SHA-256, walk one proof climb level by level, then mount a second-preimage attack and an append-only consistency check on the tree you built. crypto-lab-merkle-vault SHA-256 · Merkle Tree · Inclusion Proofs · Certificate Transparency
Bcrypt Forge Bcrypt anatomy, cost factor benchmarking, timing-safe verification, and a real-world breach simulation. The workhorse password hash, dissected. crypto-lab-bcrypt-forge bcrypt · Blowfish · Cost Factor · Timing-Safe
Commit Gate Hash commitments and Pedersen commitments — binding, hiding, sealed-bid auction, and homomorphic addition. The primitive beneath ZKPs, MPC, and VSS. crypto-lab-commit-gate Hash Commitment · Pedersen · Binding & Hiding · Homomorphic
VRF Gate ECVRF prove/verify, Wesolowski VDF repeated squaring, and a RANDAO-plus-VDF beacon simulation that shows how verifiable randomness resists last-reveal manipulation. crypto-lab-vrf-gate ECVRF P-256 · Wesolowski VDF · RANDAO · RFC 9381
OTP Vault One-time pad encryption with provable perfect secrecy, then the two-time-pad break: XOR two ciphertexts under a reused key and crib-drag to recover both plaintexts. crypto-lab-otp-vault One-Time Pad · Perfect Secrecy · Two-Time Pad · Crib Dragging
Collision Vault Verify real published MD5 and SHA-1 collision pairs — SHAttered, identical-prefix, chosen-prefix — live in the browser, then watch SHA-256 and SHA-3 resist the same attack. crypto-lab-collision-vault MD5 · SHA-1 · SHAttered · Chosen-Prefix Collision
Merkle Proofs The proof-semantics view: what an inclusion proof does and does not establish — RFC 9162 index verification, a pinned real Certificate Transparency entry, and the RFC 6962 and CVE-2012-2459 attacks. crypto-lab-merkle-proofs SHA-256 · Merkle Proof · RFC 6962 · CVE-2012-2459
Time-Lock Puzzle Seal a message that only sequential squaring can open, then reveal the creator's instant trapdoor that collapses the delay. Real BigInt and AES-256-GCM. No backend. crypto-lab-time-lock-puzzle RSW · Sequential Squaring · AES-256-GCM · Trapdoor
VDF Repeated modular squaring in an RSA group with a Wesolowski short proof — watch sequential work accrue one squaring at a time, confirm parallel workers don't help, then verify instantly and reveal the trapdoor. crypto-lab-vdf VDF · Wesolowski · Modular Squaring · Randomness Beacon
Quantum Entropy A biased beam-splitter QRNG, Shannon vs min-entropy on the same stream, von Neumann debiasing, and a real Toeplitz extractor with Leftover Hash Lemma accounting and NIST SP 800-90B health tests. crypto-lab-quantum-entropy QRNG · Min-Entropy · Toeplitz Extractor · SP 800-90B
Accumulator One fixed-size digest commits to a growing set. Prove a certificate is in it — or, the hard part, that it is not — with a short witness, then forge one with the trapdoor. crypto-lab-accumulator RSA Accumulator · Non-Membership Proofs · Strong RSA · Certificate Revocation
Beacon Lock Lock a ciphertext to a future drand round and let the beacon's BLS signature be the decryption key — identity-based encryption with a clock in place of an authority. crypto-lab-beacon-lock drand quicknet · Boneh-Franklin IBE · BLS12-381 · AES-256-GCM
KMAC Gate SHA3-256, SHAKE, cSHAKE and KMAC driven by one hand-rolled Keccak-f[1600] permutation — step the sponge block by block, then tamper with a signed message and watch the real verifier reject it. crypto-lab-kmac-gate Keccak-f[1600] · SHAKE128/256 · cSHAKE128/256 · KMAC128/256
Split Point Secret-share a function, not a value: two DPF keys each evaluate to shares of one-at-α, zero everywhere else. Two non-colluding servers fold 65,536 records and neither learns which one you read. crypto-lab-split-point DPF · 2-Server PIR · AES-128-CTR · FSS
Fold Gate Combining two satisfying R1CS instances leaves a computable cross term; relax the system with a slack scalar and an error vector to absorb it, and one folded instance stands in for all of them. crypto-lab-fold-gate Nova NIFS · Relaxed R1CS · Pedersen Commitment · ristretto255
Hidden Bit Run the game: a challenger hides one bit, an adversary guesses. A rising advantage proves a scheme broken; a flat one proves only that these adversaries failed — which is why security needs a reduction. crypto-lab-hidden-bit IND-CPA · EUF-CMA · PRP/PRF Switching · DDH Reduction
Drift Key Turn a noisy reading that never repeats into the same key every time: a code-offset secure sketch over hand-built BCH codes, HKDF-SHA-256, and the exact entropy the public helper data costs. crypto-lab-drift-key Fuzzy Extractor · Code-Offset Sketch · BCH · HKDF-SHA-256
Noise to Numbers NIST SP 800-90B min-entropy from pinned runs of the real assessment tool: a modelled Infinite Noise TRNG scores 0.37 bits per bit, a SHA-256 counter scores 0.92. Entropy belongs to the source, not the bytes. crypto-lab-noise-to-numbers SP 800-90B · Min-Entropy · Keccak-f[1600] · Modelled Noise Source
Pulse Chain Recompute real NIST Beacon 2.0 pulses byte by byte, walk their SHA-512 hash chain and skiplist, verify drand rounds with a BLS12-381 pairing, and see what no check proves: whether the operator knew first. crypto-lab-pulse-chain NIST Beacon 2.0 · drand · BLS12-381 · SHA-512
Good Randomness Two 32-byte keys pass the same look-random checks — one from the browser’s generator, one from a ChaCha20 stream started at a four-digit PIN. Then the second is rebuilt by counting to ten thousand, while every check still reports success. crypto-lab-good-randomness ChaCha20 · CSPRNG · Seed Recovery · WebCrypto

Symmetric Encryption

Demo Description Source Primitives
Air Stream Generate 128-EEA1, 128-EEA2 and 128-EEA3 keystream from one key, COUNT, bearer and direction, and check each against the test vectors in its own specification. crypto-lab-air-stream SNOW 3G · ZUC · AES-CTR · 3GPP
Shadow Vault One container, two passphrases, two messages. A practical demonstration of plausible deniability, forensic ambiguity, and browser-first UX around serious primitives. crypto-lab-shadow-vault Argon2id · ChaCha20-Poly1305 · SHA-256
Iron Serpent The Serpent block cipher — AES finalist with a deeper security margin. Avalanche analysis, a security-margin (round-count) view, and side-by-side AES comparison. crypto-lab-iron-serpent Serpent · AES-256 · SPN
World Ciphers Camellia (Japan), ARIA (South Korea), SM4 (China), and Kuznyechik (Russia) side by side with AES. Encrypt/decrypt playgrounds, S-box analysis, and geopolitical compliance context. crypto-lab-world-ciphers Camellia · ARIA · SM4 · Kuznyechik
AES Modes ECB, CBC, CTR, GCM, and CCM with live padding oracle attack. Real WebCrypto operations, ECB penguin visualization, and authenticated encryption comparison. crypto-lab-aes-modes AES · AES-GCM · AES-CBC · Authenticated Encryption
Format Ward FF1 and FF3-1 tokenization of credit cards, SSNs, and phone numbers — with the linear cryptanalysis that got FF3-1 cut from NIST's draft revision. crypto-lab-format-ward FF1 · FF3-1 · AES-256 · Tokenization
ChaCha20 Stream Quarter-round stepper, keystream visualizer, nonce reuse attack demo, and encrypt/decrypt playground. ARX design, no AES-NI required. crypto-lab-chacha20-stream ChaCha20 · ARX · Nonce Reuse · Keystream
AEGIS Gate AEGIS-256 as described in CFRG Informational RFC 10032, with AES round-function state updates, six-register sponge flow, tag derivation, and RFC test-vector verification in the browser. crypto-lab-aegis-gate AEGIS-256 · AES Round Function · 6-State Sponge · Test Vectors
Ascon NIST's lightweight cryptography standard with Ascon-AEAD128, Ascon-Hash256, avalanche analysis, and side-by-side comparison against AES-GCM and ChaCha20-Poly1305. crypto-lab-ascon Ascon-AEAD128 · Ascon-Hash256 · Lightweight Crypto · IoT
Stream Ward Splitting a large file into individually authenticated segments fixes the memory ceiling and breaks ordering — reorder, drop or truncate the frames and every tag still verifies until a chain state binds them. crypto-lab-stream-ward XChaCha20-Poly1305 · secretstream · SHA-256 Chaining · Truncation Attack
Feistel Forge Real DES stepped round by round, where the round function need not be invertible — and DES's is not. Then double DES falls to meet-in-the-middle, and a 64-bit block collides at the birthday bound. crypto-lab-feistel-forge DES · Feistel Network · Meet-in-the-Middle · Sweet32
Sector Vault XTS-AES is what full-disk encryption actually uses. Flip a bit, copy a block, restore yesterday's sector — every read returns plaintext and raises nothing, because the mode has nothing to raise it with. crypto-lab-sector-vault XTS-AES · GF(2^128) · Ciphertext Stealing · AES-GCM
Sleeve Check GOST published a 256-byte S-box as a bare table. It falls out of four small constants and field arithmetic — evidence about how it was designed, which is not by itself an attack. crypto-lab-sleeve-check Kuznyechik · Streebog · TKlog · AES S-Box
MGM Mode MGM, the GOST AEAD mode (RFC 9058), over Magma and Kuznyechik: a distinct authentication coefficient per block against GCM's single H, every RFC test value checked, nonce reuse, and why 64-bit blocks re-key sooner. crypto-lab-mgm-mode MGM · Magma · Kuznyechik · RFC 9058

Public-Key & Signatures

Demo Description Source Primitives
SM2 Forge Sign and encrypt under GB/T 32918 SM2, read the identity digest that precedes every signature, compare both deployed ciphertext orders, then recover a key from a reused nonce. crypto-lab-sm2-forge SM2 · SM3 · Nonce Reuse · RFC 8998
Iron Letter ECIES P-256 and RSA-OAEP compared side by side with live timing, key-size tradeoffs, and a simple sealed-letter mental model. crypto-lab-iron-letter ECIES P-256 · RSA-OAEP · AES-256-GCM
SPHINCS+ Ledger Stateless hash-based signatures (SLH-DSA) in the browser. A post-quantum signing scheme that relies only on the security of hash functions. crypto-lab-sphincs-ledger SLH-DSA · FIPS 205 · SPHINCS+ · SHA-256 · WOTS+
Educational RSA Step-by-step RSA on real small numbers — key generation, encryption, decryption, and signatures — then watch a weak key get factored in milliseconds while a 2048-bit key holds. Real BigInt math, no backend. crypto-lab-rsa-educational RSA · Key Generation · Modular Exponentiation · OAEP
RSA Forge Textbook RSA, OAEP, PSS signatures, and live attacks including small exponent and Bleichenbacher PKCS#1 v1.5 padding oracle. Real WebCrypto operations. crypto-lab-rsa-forge RSA · OAEP · PSS · PKCS#1
Ed25519 Forge Keypair generation, signing, and signature verification — deterministic nonces, tamper detection, the ZIP215 cofactor pitfall, and 64-byte compact signatures. crypto-lab-ed25519-forge Ed25519 · EdDSA · Deterministic Nonces · ZIP215 · Cofactor
LMS Ledger LMS/HSS stateful hash-based signatures (NIST SP 800-208) — LM-OTS key state grid, one-time key reuse attack with real forgery demo, and CNSA 2.0 firmware signing context. crypto-lab-lms-ledger LMS · HSS · LM-OTS · NIST SP 800-208
Pairing Gate BLS12-381 bilinear pairing — BLS signature sign/verify with real @noble/curves arithmetic, signature aggregation visualizer (up to 100 signers → 1 proof), and rogue key attack demo. Powers Ethereum 2.0 and Zcash. crypto-lab-pairing-gate BLS12-381 · BLS Signatures · Signature Aggregation · Rogue Key Attack
Blind Sign Chaum RSA blind signatures and Schnorr EC blind signatures — anonymous e-cash, private voting, and unlinkability proofs. The signer signs without seeing the message. crypto-lab-blind-sign Chaum RSA · Schnorr EC · e-Cash · Unlinkability
Ring Sign LSAG ring signatures — key image linkability, double-spend detection, group signatures with manager opening, and Monero transaction privacy. Sign as one-of-many without revealing which. crypto-lab-ring-sign LSAG · Key Image · Group Signatures · Monero
Curve448 X448 key exchange and Ed448 signatures side by side with Curve25519 and Ed25519, covering the 224-bit security tier for long-lived keys. crypto-lab-curve448 X448 · Ed448 · RFC 7748 · RFC 8032
ECDSA Forge ECDSA on secp256k1 and P-256 with sign/verify workflows, RFC 6979 deterministic nonces, and the classic nonce-reuse private-key recovery attack. crypto-lab-ecdsa-forge ECDSA · secp256k1 · RFC 6979 · Nonce Reuse
Schnorr Forge Real BIP-340 Schnorr on secp256k1 with sign/verify, the step-by-step signing equation, nonce-reuse private-key recovery, and the linearity behind multisig and threshold signing. crypto-lab-schnorr-forge BIP-340 · secp256k1 · Nonce Reuse · Aggregation
ElGamal Plain Taher ElGamal's 1985 scheme with fresh ephemeral randomness, multiplicative homomorphism, and ciphertext rerandomization across toy and RFC 3526 groups. crypto-lab-elgamal-plain ElGamal · RFC 3526 Group 14 · Homomorphism · Re-randomization
IBE Gate Boneh-Franklin identity-based encryption on BLS12-381 with setup, private-key extraction, encrypt/decrypt flow, and an honest look at the escrow tradeoff. crypto-lab-ibe-gate Boneh-Franklin · BLS12-381 · Identity-Based Encryption · Key Escrow
LMS/XMSS State-managed hash-based signatures with LM-OTS, Merkle trees, and hierarchical composition, showing where LMS, HSS, and XMSS fit in practice. crypto-lab-lms-xmss LMS · LM-OTS · HSS · NIST SP 800-208
Jevil A hash-based few-time signature scheme over the Goldilocks field using Lagrange interpolation — bounded-use signing with reusable verification keys. crypto-lab-jevil Jevil · Hash-Based · Goldilocks Field · Lagrange Interpolation
Bitcoin Wallet Bitcoin wallet pipeline in the browser — secp256k1 keys to P2PKH and P2WPKH addresses via HASH160, plus BIP-39 mnemonics, PBKDF2 seed stretching, and BIP-32 hardened child derivation. crypto-lab-bitcoin-wallet secp256k1 · BIP-32 · BIP-39 · Bech32
Bitcoin Script Step a real P2PKH spend through the Script stack machine — valid, wrong-key, forged-signature, and tampered scenarios, with real secp256k1 and HASH160. No backend. crypto-lab-bitcoin-script secp256k1 · P2PKH · ECDSA · Stack Machine
Signed Bytes Real Ed25519 over JSON — a signature binds an exact byte string, never the parsed meaning. Break key order, Unicode, and duplicate keys, then watch JCS canonicalization fix some and refuse others. crypto-lab-signed-bytes Ed25519 · JCS RFC 8785 · Parser Differential · Unicode NFC
Token Tell Runs the real SynthID-Text keyed detector over watermarked text, then signs the same words with ECDSA P-256: change only the key and the statistical evidence vanishes; change one byte and verification fails outright. crypto-lab-token-tell SynthID-Text · Tournament Sampling · ECDSA P-256 · C2PA Manifest
Rekey Relay A semi-trusted relay turns Alice's ciphertext into Bob's without ever holding the plaintext. In BBS98, the scheme everyone starts with, the relay and Bob recover Alice's private key in one modular division. crypto-lab-rekey-relay BBS98 · AFGH · BLS12-381 · Re-Encryption Key
Attribute Gate Encrypt to a policy instead of to a person. Then splice two real keys whose attributes only jointly satisfy that policy, run the genuine decryption, and watch the term that refuses to cancel. crypto-lab-attribute-gate FAME CP-ABE · BLS12-381 · Access Policy · Collusion Resistance
SM9 Forge Extract an identity key by inverting in the exponent rather than hashing to a curve, run SM9’s signature, key exchange and encryption against the standard’s own worked examples, and see why two implementations agreeing doesn’t prove either followed the spec. crypto-lab-sm9-forge SM9 · Identity-Based · R-ate Pairing · BN256 · Key Escrow · Nonce Reuse
Adaptor Gate One click turns a pre-signature the real BIP-340 verifier rejects into a valid signature, then subtracts the two to read the secret back out — the fact that atomic swaps and PTLC routing are both built on. crypto-lab-adaptor-gate BIP-340 · secp256k1 · Atomic Swap · PTLC
Function Key Issue a key that answers one question about an encrypted vector — its weighted sum — and nothing else. Then issue keys one at a time and watch the set of possible plaintexts shrink, until one more key hands over the master secret. crypto-lab-function-key ABDP15 IPFE · ristretto255 · Baby-Step Giant-Step · Key Collusion
Locks and Keys A padlock anyone may close and only you can open — real RSA-OAEP and RSA-PSS on a 2048-bit pair, with the wrong key failing on purpose and the same pair doing its other job, signing. No maths on screen. crypto-lab-locks-and-keys RSA-OAEP · RSA-PSS · Public-Key Encryption · WebCrypto
Vector Gate Switch off Ed25519's required scalar-range check and watch the verifier accept a signature nobody signed, while all five RFC vectors still pass — then ask what passing them proved. crypto-lab-vector-gate Ed25519 · RFC 8032 · Wycheproof Case · Evidence Scope

Key Exchange & Protocols

Demo Description Source Primitives
Ratchet Wire A live walkthrough of the Double Ratchet protocol powering Signal-style messaging, with per-message key derivation and forward secrecy guarantees. crypto-lab-ratchet-wire Double Ratchet · X25519 · HKDF · AES-256-GCM
Hybrid Wire X25519 + ML-KEM-768 hybrid post-quantum key exchange as deployed in Chrome 131+ and Cloudflare. Chrome 124 shipped the Kyber draft, not ML-KEM. Six-step handshake visualization and encrypted chat. crypto-lab-hybrid-wire X25519 · ML-KEM-768 · HKDF-SHA256 · AES-256-GCM
X3DH Wire The asynchronous handshake behind Signal. Real X25519 arithmetic, four DH operations, and HKDF-SHA-256 key derivation — no backends, no simulated math. crypto-lab-x3dh-wire X3DH · X25519 · HKDF-SHA-256 · Signal Protocol
Noise Pipe NN, XX, IK, and IKpsk2 handshake patterns with real X25519 arithmetic, live transport encryption, and a WireGuard deep dive. crypto-lab-noise-pipe X25519 · HKDF · WireGuard · Handshake Patterns
PKI Chain X.509 certificate chains, trust store validation, CA compromise cascades, Certificate Transparency with Merkle inclusion proofs, and post-quantum migration to ML-DSA. crypto-lab-pki-chain X.509 · Certificate Transparency · CA Compromise · ML-DSA Sizes Only
OPAQUE Gate RFC 9807 OPAQUE aPAKE with live OPRF blind/evaluate/unblind flow, credential-envelope handling, 3DH mutual authentication, and server-breach simulation showing the password never reaches the server. crypto-lab-opaque-gate OPAQUE · OPRF · 3DH · HKDF
Envelope KMS RFC 3394/5649 AES key wrap, DEK/KEK hierarchy, KMS-style key rotation, re-wrap without plaintext exposure, and a hash-chained audit log — the architecture behind AWS KMS and Google Cloud KMS. crypto-lab-envelope-kms RFC 3394 · AES Key Wrap · DEK/KEK · Key Rotation
Kerberos v5 RFC 4120 Kerberos v5 — Needham-Schroeder origins, Lowe attack, full AS/TGS/AP exchange flow, AES-256-CTS-HMAC-SHA1-96 ticket encryption, and clock-skew replay defense. crypto-lab-kerberos RFC 4120 · Needham-Schroeder · Lowe Attack · AES-256-CTS
MLS Group RFC 9420 Messaging Layer Security — TreeKEM ratchet tree, epoch key schedule, member add/remove/update operations, and group application messaging with forward secrecy guarantees. crypto-lab-mls-group MLS (RFC 9420) · TreeKEM · Epoch Key Schedule · Forward Secrecy
Key Exchange A walkthrough of key exchange across history and protocol families — from Diffie-Hellman to modern hybrid post-quantum handshakes, with shared assumptions and threat models per era. crypto-lab-key-exchange Diffie-Hellman · ECDH · X25519 · ML-KEM
Web of Trust A PGP-style trust graph — sign each other's keys, walk introduction chains, observe how trust flows (and breaks) without a central authority. crypto-lab-web-of-trust PGP · OpenPGP · GnuPG · Key Signing · Trust Graph
WebAuthn Passwordless authentication via FIDO2 / WebAuthn — assertion verification, origin binding, signature counters, and the journey from passwords to passkeys. crypto-lab-webauthn WebAuthn · FIDO2 · Passkeys · Assertion
SSH Handshake SSH transport-layer handshake and TOFU host-key pinning — ephemeral X25519 / ECDH, Ed25519 signatures over the exchange hash, and known_hosts change detection across StrictHostKeyChecking modes. crypto-lab-ssh-handshake X25519 · Ed25519 · TOFU · known_hosts
DH MITM Interactive Diffie-Hellman key exchange, then a live man-in-the-middle attack on the unauthenticated channel that shows why raw DH needs authentication. Real modular arithmetic. No backend. crypto-lab-diffie-hellman-mitm Diffie-Hellman · Modular Arithmetic · MITM · Key Exchange
PAKE Gate Tour SRP-6a, J-PAKE, CPace, and Dragonfly (RFC 7664) side by side — a shared key forms from a low-entropy password that never crosses the wire, plus a server-breach toggle and the Dragonblood side-channel. crypto-lab-pake-gate SRP-6a · J-PAKE · CPace · Dragonfly
TLS Handshake Step through X25519 key exchange, Ed25519 authentication, the HKDF key schedule, and AES-GCM records, with a MITM attack that gets blocked. Real WebCrypto. No backend. crypto-lab-tls-handshake TLS 1.3 · X25519 · Ed25519 · AES-GCM
Chain of Trust X.509 path building vs RFC 5280 validation on a real cross-signed ECDSA hierarchy — build chains yourself, watch a naive builder fail a valid leaf, and see valid signatures rejected. crypto-lab-chain-of-trust X.509 · RFC 5280 · ECDSA P-256 · nameConstraints
HPKE Envelope RFC 9180 with every stage exposed — a KEM, a KDF, and an AEAD composed into one scheme; edit the info string or AAD and watch the real AEAD reject. crypto-lab-hpke-envelope DHKEM X25519 · HKDF-SHA256 · AES-GCM · RFC 9180
Blind Hello TLS 1.3 encrypts everything except the hostname it announces first — seal the ClientHello with real HPKE and see exactly what ECH hides, what it can't, and why it needs encrypted DNS. crypto-lab-blind-hello TLS 1.3 · ECH · HPKE · SNI
Key Mirror A key directory that lies to one user and tells the truth to another — then the append-only Merkle log, consistency proofs, and gossip that make the lie detectable. crypto-lab-key-mirror Merkle Tree · VRF · Ed25519 · KEYTRANS
SPAKE Gate SPAKE2 and SPAKE2+ on the same password, side by side — indistinguishable until the server database leaks, then one impersonation costs nothing and the other forces an offline crack. crypto-lab-spake-gate SPAKE2 · SPAKE2+ · P-256 · PAKE
DNSSEC Chain The PKI that has to sign statements about names which do not exist. Validate a real captured chain from the IANA anchor, then walk an NSEC3 zone the denial proofs gave away. crypto-lab-dnssec-chain DNSSEC · NSEC3 · RRSIG · Zone Walking
Attestation Gate Measured boot into PCRs, a real TPMS_ATTEST quote, a verifier with reference values — then run something outside the measured set after the last measurement and watch every check pass. crypto-lab-attestation-gate TPM 2.0 · TPMS_ATTEST · RATS · Measured Boot
PQXDH Wire One ML-KEM secret added to the X3DH transcript is what survives a future curve break. The prekey signature and the ratchet after it are untouched, so Bob can still be impersonated with every check green. crypto-lab-pqxdh-wire X25519 · ML-KEM-1024 · HKDF-SHA-512 · Ed25519
Ghost Commit Commit an API key, delete it two commits later, and it keeps its name and its contents forever — git adds objects, it never edits them. Then an entropy scanner finds it in seconds. crypto-lab-ghost-commit Git Object Model · SHA-1 / SHA-256 · Shannon Entropy · Secret Scanning
HTTPS Padlock Takes apart a certificate a real site presented, lets you break each of its four checks in turn, then shows a flawless certificate for a lookalike domain that passes every one. Reads captured certificates; it never connects to a site. crypto-lab-https-padlock X.509 · ECDSA P-256 · RFC 5280 Subset · ClientHello Bytes Only
Agreeing in Public The paint-mixing picture, then one real X25519 exchange with both sides’ secrets compared byte for byte — and a stranger who answers in Bob’s place while every check on the page still passes. No modulus, no exponent. crypto-lab-agreeing-in-public X25519 · RFC 7748 · Key Agreement · No Authentication

Privacy & Advanced

Demo Description Source Primitives
ZK Proof Lab Six exhibits from Ali Baba cave to zk-SNARK intuition, with real Schnorr arithmetic, commitments, and replayable transcripts instead of vague metaphors. crypto-lab-zk-proof-lab Schnorr · SHA-256 Commitments · Fiat-Shamir · zk-SNARK
STARK Tower AIR constraints, FRI polynomial commitments, and end-to-end Fibonacci proof. No trusted setup, post-quantum secure. The protocol behind StarkNet, StarkEx, and Risc Zero. crypto-lab-stark-tower zk-STARK · AIR Constraints · FRI · Post-Quantum
SNARK Arena Groth16 vs PLONK — trusted setup ceremonies, proof size comparison, the toxic waste problem, and production deployments in Zcash, Polygon zkEVM, WorldID, and zkLogin. crypto-lab-snark-arena Groth16 · PLONK · Trusted Setup · zk-SNARK
Blind Oracle A server adds encrypted values with TFHE-rs while the decryption key stays in your browser. See why a client must keep decryption-error feedback private. crypto-lab-blind-oracle FHE · TFHE-rs · Rust · Encrypted Compute
CKKS Lab Approximate FHE for encrypted floating-point arithmetic, homomorphic neural network inference, rescaling, and the complete FHE trilogy (TFHE + BGV/BFV + CKKS). crypto-lab-ckks-lab CKKS · RLWE · Approximate FHE · Encrypted Inference
FHE Arena BGV/BFV integer FHE — homomorphic addition and multiplication, live noise budget visualizer, relinearization, SIMD batching, and real-world deployments in private genomics and encrypted databases. crypto-lab-fhe-arena BGV/BFV · RLWE · Noise Budget · SIMD Batching
Patron Shield Information-theoretic private information retrieval applied to catalog privacy. A direct bridge from library ethics to concrete mathematical guarantees. crypto-lab-patron-shield IT-PIR · XOR Secret Sharing · Chor et al. 1995
VSS Gate Feldman VSS and Pedersen VSS — verifiable secret sharing with live cheating dealer detection, commitment verification, and the layer beneath FROST and threshold wallets. crypto-lab-vss-gate Feldman VSS · Pedersen VSS · Commitment Verification · Cheating Detection
DKG Gate Pedersen/GJKR dealerless key generation — n parties Feldman-deal to each other, public complaints disqualify cheating dealers, and the sharings sum into one t-of-n key nobody ever held. Includes the rushing-adversary bias attack and its fix. crypto-lab-dkg-gate Pedersen DKG · GJKR 1999 · Feldman VSS · ristretto255
Garbled Gate Yao’s Garbled Circuits — gate-by-gate garbling, oblivious transfer for input wires, and the Millionaire’s Problem solved end-to-end. The foundational two-party MPC protocol. crypto-lab-garbled-gate Garbled Circuits · Oblivious Transfer · Free XOR · Two-Party MPC
Silent Tally Five hospitals compute a combined enrollment total without revealing any individual counts, demonstrating additive-homomorphic MPC in the browser. crypto-lab-silent-tally Shamir SSS · GF(2⁶¹−1) · Lagrange Interpolation · Additive Homomorphism
FROST Threshold A browser-based FROST (RFC 9591) walkthrough where any qualified signer subset can produce one standard Ed25519 signature without key reassembly. crypto-lab-frost-threshold FROST (RFC 9591) · Ed25519 · Nonce Commitments · VSS Commitments
OT Gate 1-of-2 Oblivious Transfer using the Simplest OT protocol (Chou-Orlandi 2015) over Curve25519 with real Edwards25519 group arithmetic and AES-256-GCM encryption. Foundational primitive for secure MPC. crypto-lab-ot-gate Simplest OT · Chou-Orlandi 2015 · Edwards25519 · AES-256-GCM
Oblivious Shelf 2-server XOR Private Information Retrieval (Chor et al. 1995) — a patron retrieves any book from a 16-item catalog without the server learning which one was requested. Step-by-step query walkthrough and privacy audit. crypto-lab-oblivious-shelf XOR PIR · Chor et al. 1995 · 2-Server PIR · Privacy Audit
GG20 Wallet GG20 threshold ECDSA — Paillier encryption, distributed key generation, and joint signing without any party holding the full private key. The protocol behind Fireblocks and Coinbase MPC. crypto-lab-gg20-wallet GG20 · Paillier · secp256k1 · Distributed Key Generation
Threshold Decrypt ElGamal over P-256 — distributed key generation, verifiable partial decryptions with NIZK proofs, and t-of-n combination without any party holding the full private key. crypto-lab-threshold-decrypt ElGamal · P-256 · NIZK Proofs · t-of-n
ORAM Vault A Path ORAM walkthrough with tree buckets, stash growth, position-map updates, and adversary-view visualization for cloud access-pattern hiding. crypto-lab-oram-vault Path ORAM · Position Map · Stash · Access Patterns
Paillier Gate Paillier's additive homomorphic cryptosystem with encrypt/decrypt, tallying without decryption, and direct links to voting systems and GG20 threshold ECDSA. crypto-lab-paillier-gate Paillier · Additive HE · Private Voting · Aggregation
PSI Gate Classic DH-PSI over ristretto255 with RFC 9380 hash-to-curve, showing how two parties learn their overlap (and each other's set size) and nothing more. crypto-lab-psi-gate DH-PSI · ristretto255 · Hash-to-Curve · Contact Discovery
Bulletproofs ZK range proofs using Bulletproofs on ristretto255 — 64-bit Pedersen commitments, aggregate proofs over multiple ranges, the inner-product argument, and a tamper-rejection demo. crypto-lab-bulletproofs Bulletproofs · ristretto255 · Range Proofs · Inner-Product Argument
ZK Arena A side-by-side comparison playground for zk-SNARK and zk-STARK proof systems — setup phases, proving overhead, verification cost, and the tradeoff space between Groth16, PLONK, and STARKs. crypto-lab-zk-arena zk-SNARK · zk-STARK · Proof Systems · Comparison
Shamir vs FROST Compare Shamir secret sharing against FROST signatures side by side — watch Shamir reassemble the key in memory while FROST signs without it ever existing. Real GF(256) and Ed25519. No backend. crypto-lab-shamir-vs-frost Shamir SSS · FROST · Ed25519 · GF(256)
Blind Relay Oblivious HTTP splits knowledge between a relay that sees your address and a gateway that sees your request — flip the collusion toggle and watch the guarantee evaporate. crypto-lab-blind-relay OHTTP · HPKE · Binary HTTP · RFC 9458
Reshare Circle Refresh threshold shares into a new epoch: every old share becomes garbage, the public key never changes, and the secret is never reconstructed along the way. crypto-lab-reshare-circle Shamir · Feldman VSS · HJKY 1995 · Mobile Adversary
Credential Veil BBS+ selective disclosure over BLS12-381 — the issuer signs six fields once; the holder reveals any subset, unlinkably every time, and proves over-18 without a birth date. crypto-lab-credential-veil BBS+ · Selective Disclosure · Unlinkability · Range Proof
SPDZ Forge SPDZ over F_p (2^61−1) — additive shares, Beaver triples, and information-theoretic MACs. Tamper with a share and semi-honest MPC swallows the lie while SPDZ aborts, even with a dishonest majority. crypto-lab-spdz-forge SPDZ · Beaver Triples · SPDZ MACs · Dishonest Majority
Traitor Trace Naor-Naor-Lotspiech subset-cover over a 16-leaf tree — one ciphertext for all subscribers, revoke a member without rekeying anyone, and trace a leaked decoder back to its builder. Real AES-256-GCM. crypto-lab-traitor-trace NNL Subset-Cover · Broadcast Encryption · Traitor Tracing · AES-256-GCM
Icy DVRF A t-of-n distributed VRF: partial evaluations proven with Chaum-Pedersen DLEQ under one shared challenge, aggregating to a constant-size 128-byte proof whether three parties contribute or three hundred. crypto-lab-icy-dvrf DVRF · Chaum-Pedersen DLEQ · ristretto255 · FROST Nonces
MuSig Gate n signers aggregate their public keys into one key and their nonces into one nonce, yielding a single Schnorr signature indistinguishable from a lone signer's — plus three live forgeries BIP-327 defeats. crypto-lab-musig-gate MuSig2 · BIP-327 · secp256k1 · Wagner & ROS
Card Trick den Boer's five-card trick — two players compute the AND of their secret bits from a shuffle alone, with security no amount of computing power can buy through. crypto-lab-card-trick den Boer 1989 · Five-Card Trick · Information-Theoretic · Two-Party AND
DP Noise Real Laplace and Gaussian mechanisms over a twelve-person payroll — watch two databases differing by one person become indistinguishable, then watch averaging take the truth back once the budget is spent. crypto-lab-dp-noise Laplace Mechanism · Gaussian Mechanism · ε-δ Budget · Composition
Search Vault An encrypted inverted index the server searches without a key — then the count and IKK leakage-abuse attacks turn the access pattern it observed back into your queries. crypto-lab-search-vault SSE · HMAC-SHA-256 · AES-256-GCM · Leakage Abuse
Shelf Oracle Classic PIR needs two servers that never collude. This needs one, under RLWE. Watch the noise budget fall as the server folds in every record — it cannot see which one you asked for. crypto-lab-shelf-oracle BFV · RLWE · Single-Server PIR · Noise Budget
Polynomial Forge One polynomial committed three ways — KZG, IPA, FRI — then the failure nothing else teaches: omit the degree bound and every cryptographic check still passes while the low-degree claim is gone. crypto-lab-polynomial-forge KZG · IPA · FRI · Degree Bound
Sphinx Mix Peel a real Sphinx packet across three mixes — per-hop blinding, a header that never changes length. Then trace one sender end to end on a quiet network with every cryptographic check green. crypto-lab-sphinx-mix Sphinx · ristretto255 · LIONESS · Traffic Analysis
Privacy Pass A token proves the issuer authorised someone without anyone — issuer, origin, or the two colluding — learning who. Remove the client's blind and nothing on the wire changes; the guarantee is simply gone. crypto-lab-privacy-pass VOPRF P-384 · DLEQ Proof · RFC 9578 · Hash-to-Curve
Order Leak A column you can still sort or match on has already published the shape of its answers. Equality, order and a public distribution hand back the plaintext cell by cell — the key is never touched. crypto-lab-order-leak AES-GCM-SIV · BCLO OPE · CLWW ORE · Inference Attacks
Proof Tally Secret sharing hides a measurement and will happily add a lie to the total. A fully linear proof carried in the same shares lets two aggregators reject a malformed report neither of them can read. crypto-lab-proof-tally Prio3 · Fully Linear PCP · Field64 · TurboSHAKE128

Post-Quantum

Demo Description Source Primitives
Quantum Vault KpqC Threshold short-secret encryption using secret sharing and Korean post-quantum cryptography, compiled to WASM for direct browser use. crypto-lab-quantum-vault-kpqc AES-256-GCM · Shamir SSS · SMAUG-T · HAETAE
KpqC Pair Historical AIM2-based AIMer signing, with a reported public-key-only forgery vulnerability (ePrint 2026/2235, September 28, 2026), beside NTRU+ from the older NTRU line. Honest round trips do not establish signature security. crypto-lab-kpqc-pair AIMer · NTRU+ · KpqC · Lattice
TC26 Pair Two TC26 post-quantum signature proposals side by side: code-based Shipovnik and stateless hash-based Hypericum, both built over Streebog. crypto-lab-tc26-pair Shipovnik · Hypericum · Streebog · Hash-Based
BB84 Quantum key distribution with photon polarization, basis sifting, QBER eavesdropper detection, and privacy amplification before AES-256-GCM message encryption. crypto-lab-bb84 Photon Polarization · Basis Sifting · QBER · Privacy Amplification
Shor Modular period finding with QFT and continued fractions to recover integer factors, showing why RSA, ECC, and Diffie-Hellman must migrate to post-quantum alternatives. crypto-lab-shor Shor's Algorithm · Period Finding · QFT · RSA Factorization
Grover Amplitude amplification and oracle phase kickback for symmetric-key search, with live probability oscillation and concrete key-size impact (AES-128 to AES-256). crypto-lab-grover Grover's Algorithm · Amplitude Amplification · Phase Kickback · AES Key Search
Dilithium Seal CRYSTALS-Dilithium (ML-DSA) digital signatures in the browser. Generate lattice-based key pairs, sign documents, and verify — all post-quantum safe. crypto-lab-dilithium-seal ML-DSA · FIPS 204 · CRYSTALS-Dilithium · Lattice
Kyber Vault CRYSTALS-Kyber (ML-KEM) key encapsulation in the browser. Encapsulate, decapsulate, and compare lattice-based key exchange against classical ECDH. crypto-lab-kyber-vault ML-KEM · FIPS 203 · CRYSTALS-Kyber · Lattice · AES-256-GCM
McEliece Gate The oldest post-quantum KEM (1978). Binary Goppa codes, visceral 261KB public key visualization, and four-way comparison against ML-KEM, BIKE, and HQC. crypto-lab-mceliece-gate Classic McEliece · Goppa Codes · Post-Quantum
Frodo Vault Conservative post-quantum KEM using plain LWE with no ring structure. LWE from first principles, error distribution, and side-by-side comparison against ML-KEM. crypto-lab-frodo-vault FrodoKEM · LWE · Lattice · Post-Quantum
BIKE Vault Code-based post-quantum KEM using QC-MDPC codes, Black-Gray-Flip decoding, and side-by-side comparison against ML-KEM. NIST Round 4 alternate candidate. crypto-lab-bike-vault BIKE · QC-MDPC · Post-Quantum · KEM
HQC Vault Hamming Quasi-Cyclic post-quantum KEM with Reed-Muller/Reed-Solomon decoding, and three-way comparison against BIKE and ML-KEM. crypto-lab-hqc-vault HQC · Reed-Muller · Reed-Solomon · Post-Quantum
Falcon Seal Compact NTRU lattice signatures with Fast Fourier Sampling, side-by-side comparison against ML-DSA and SLH-DSA, and implementation security warnings. crypto-lab-falcon-seal Falcon · FN-DSA · NTRU · FFT Sampling · Post-Quantum
Harvest Vault Why harvested traffic is already lost: capture a real key exchange, upgrade to post-quantum afterwards, and watch the recording stay just as readable. Mosca's theorem applied to what you already sent. crypto-lab-harvest-vault HNDL · Mosca's Theorem · Q-Day Timeline · PQC Migration
Isogeny Gate Elliptic-curve isogenies with a toy CSIDH over GF(419), supersingular graph walks, the Castryck-Decru break of SIDH, and the surviving branches of the field in SQIsign. crypto-lab-isogeny-gate SIDH · CSIDH · SQIsign · Castryck-Decru
MPCitH Sign Post-quantum signatures from MPC-in-the-Head with additive secret sharing, SHA-256 commitments, Merkle proofs, Fiat-Shamir, and hidden-view challenges over a toy PERK-style witness. crypto-lab-mpcith-sign MPC-in-the-Head · Fiat-Shamir · SHA-256 Commitments · Merkle Proofs
Dilithium Reject An ML-DSA rejection-sampling lab with live acceptance histograms, rejection-reason breakdowns, and the signing-time tradeoff that keeps lattice signatures secure. crypto-lab-dilithium-reject ML-DSA · Rejection Sampling · FIPS 204 · Timing Tradeoffs
Harvest Timeline The planning half of harvest-now-decrypt-later: which assets in a fleet cross a CRQC, what each year of delay costs, and what a migration actually reaches when you execute one. crypto-lab-harvest-timeline Mosca Inequality · CRQC Scenarios · Cost of Delay · PQC Migration
HAWK An educational HAWK lab covering integer-only lattice signatures, discrete Gaussian sampling over Z, and the July 2026 key-recovery attack that led to HAWK's withdrawal from NIST's additional-signatures process. crypto-lab-hawk HAWK · Lattice Signatures · Gaussian Sampling · Withdrawn July 2026
Hybrid Sign Ed25519 plus ML-DSA-65 hybrid signatures per the IETF LAMPS composite-signature draft, framed as defense in depth for long-lived authenticity. crypto-lab-hybrid-sign Ed25519 · ML-DSA-65 · Composite Signatures · IETF LAMPS
NTRU Classic The original 1996 NTRU lattice cryptosystem with polynomial-ring arithmetic from scratch and the historical path from classic NTRU to modern post-quantum design. crypto-lab-ntru-classic NTRU · Polynomial Rings · Lattice · EESS#1
PQ Rotation A post-quantum migration planner for hybrid certificates, multi-jurisdiction timelines, rolling key rotation, canary deployment, and rollback strategy. crypto-lab-pq-rotation Hybrid X.509 · CNSA 2.0 · Key Rotation · Migration Planner
PQ TLS Handshake TLS 1.3 with the X25519MLKEM768 hybrid handshake, including byte-level framing, full key schedule derivation, and comparison against classical X25519. crypto-lab-pq-tls-handshake TLS 1.3 · X25519MLKEM768 · Key Schedule · Hybrid PQC
Scloud+ Vault China's conservative LWE-based KEM with ternary secrets, BW32 lattice coding, and a faithful but simplified browser model of the ePrint 2024/1306 design. crypto-lab-scloud-vault Scloud+ · LWE KEM · BW32 Coding · Ternary Secrets
Threshold ML-DSA A two-party demo of distributed post-quantum signing that produces real FIPS 204 ML-DSA signatures; key-non-reconstruction is illustrated, not enforced. crypto-lab-threshold-mldsa Threshold ML-DSA · Distributed Signing · Two-Party · Post-Quantum
PQ Families A guided tour of the five post-quantum problem families — lattice, code-based, hash-based, multivariate, and isogeny — with the assumptions, history, and standardization status of each. crypto-lab-pq-families Lattice · Code-Based · Hash-Based · Multivariate · Isogeny
E91 Ekert's entanglement-based QKD: measure entangled pairs, run the CHSH Bell test, and derive a key from aligned bases. |S|≈2.83 proves security; an eavesdropper drags it toward the classical bound, so the key is discarded. crypto-lab-e91 E91 · Entanglement · CHSH Bell Test · QKD
Hybrid Guide A guide to hybrid post-quantum key exchange — a KEM combiner pairs X25519 with ML-KEM-768 so the session key holds as long as either half survives. Break each component to see the hedge. crypto-lab-hybrid-guide KEM Combiner · X25519 · ML-KEM-768 · X-Wing
Multivariate UOV A real Unbalanced Oil-and-Vinegar scheme over GF(256) signs and verifies in the browser, showing how fixing the vinegar variables turns the MQ trapdoor into a linear solve — plus the 2022 Beullens attack that broke Rainbow. crypto-lab-multivariate UOV · GF(256) · MQ Problem · Beullens Attack
MAYO Seal Runs real MAYO keygen, signing, and verification over GF(16), stepping through the moment an oil space too small to invert becomes solvable once k copies of the map are whipped together. crypto-lab-mayo-seal MAYO · GF(16) · Whipping · NIST On-Ramp
Hybrid PQC Compare classical, post-quantum, and hybrid key exchange and signatures side by side, then break one half and watch the hybrid survive. Real X25519, ML-KEM-768, Ed25519, ML-DSA-65. No backend. crypto-lab-hybrid-pqc X25519 · ML-KEM-768 · Ed25519 · ML-DSA-65
KEM Trap Real ML-KEM-768 decapsulation never fails loudly — flip a ciphertext bit and watch a caller that drops the return code or skips key confirmation turn implicit rejection into an oracle. crypto-lab-kem-trap ML-KEM-768 · FIPS 203 · FO Transform · Implicit Rejection
Isogeny Atlas A real supersingular isogeny graph over GF(431²), computed live from the modular polynomials, with the seven open problems of isogeny crypto drawn as paths, cycles, and endomorphisms. crypto-lab-isogeny-atlas Isogeny Graphs · Modular Polynomials · Endomorphism Rings · CGL Hash
Lattice Gentle The lattice picture underneath ML-KEM and ML-DSA: drag basis vectors through SVP and CVP, step Gauss and LLL, then run toy Kyber and Dilithium end to end. crypto-lab-lattice-gentle SVP & CVP · LLL · LWE & SIS · toy ML-KEM/ML-DSA
Simon's Period Exact statevector Simon's algorithm recovering a hidden XOR period in O(n) queries, then using it to predict an Even-Mansour ciphertext and forge a CBC-MAC tag. crypto-lab-simon-period Simon's Algorithm · Period Finding · Even-Mansour · CBC-MAC Forgery
Lattice Builder Two dials straighten a scrambled lattice until its shortest vector is readable by eye. Then guess seven of a real Module-LWE key's eight coefficients and the error left over is no smaller than guessing none. crypto-lab-lattice-builder SVP · Module-LWE · ML-KEM (FIPS 203) · Babai Rounding
Point Ledger Quantum resource estimates for secp256k1, a classical multiplication dialog, and where fuzz-test evidence stops supporting a Fiat-Shamir soundness claim. crypto-lab-point-ledger secp256k1 · Shor Estimates · Fiat-Shamir · Fuzz Evidence
PQ Chooser Set what constrains you and get a shortlist of two or three post-quantum schemes to investigate, built from sizes it derives by running the real algorithms in your browser rather than quoting a table. crypto-lab-pq-chooser Derived Sizes · FIPS 203/204/205 · Live Benchmark · TLS Wire Cost
What Is PQC Runs a real ML-KEM-768 exchange beside a real X25519 one in matching panels, so the only measurable difference is size — 2,272 bytes on the wire instead of 64. Not stronger: a different hard problem. crypto-lab-what-is-pqc ML-KEM-768 · X25519 · FIPS 203 · Size, Not Strength

Cryptanalysis

Demo Description Source Primitives
Corrupted Oracle A live Dual_EC_DRBG backdoor demo showing state recovery and future-output prediction while standard statistical tests still appear clean. crypto-lab-corrupted-oracle Dual_EC_DRBG · HMAC-DRBG · ChaCha20-DRBG · P-256
Misty Lens Run MISTY1 and KASUMI side by side, map the design changes between them, and execute the seven-round related-key sandwich distinguisher in the page. crypto-lab-misty-lens MISTY1 · KASUMI · Related-Key · Feistel
Export Grade Run real TETRA TEA1, trace its 80-bit key into a 32-bit working register, recover that register in a browser-sized window, then extrapolate the rate your own browser measured out to 2^80 and 2^128 and set it beside the published attacks on full-round AES. crypto-lab-export-grade TEA1 · TETRA · Key Reduction · Brute Force · Cost Extrapolation · vs. AES
Model Breach A HiAE threat-model case study showing candidate enumeration, MITM state recovery, and guess-and-determine attacks when assumptions drift from deployment reality. crypto-lab-model-breach Threat Modeling · Candidate Enumeration · MITM Recovery · Guess-and-Determine
Biham Lens A live differential cryptanalysis attack on a toy SPN cipher — the technique co-invented by Biham and Shamir that broke reduced-round DES. DDT visualization and last-round key recovery. crypto-lab-biham-lens Differential Cryptanalysis · SPN · DDT · Chosen-Plaintext
Downgrade Wire Strip X25519MLKEM768 from a TLS 1.3 ClientHello and watch two PQ-capable endpoints agree on classical X25519 — then turn on the Finished MAC and watch transcript binding abort the same strip. crypto-lab-downgrade-wire TLS 1.3 · Transcript Binding · X25519MLKEM768 · Downgrade
Padding Oracle Full Vaudenay 2002 chosen-ciphertext attack with real AES-CBC, byte-by-byte plaintext recovery, and coverage of ASP.NET, Lucky Thirteen, and POODLE. crypto-lab-padding-oracle AES-CBC · PKCS#7 · Vaudenay 2002 · POODLE
Timing Oracle String comparison leakage, HMAC verification timing, RSA private key bit leakage, and cache-timing attacks with real performance.now() measurements. crypto-lab-timing-oracle Timing Attack · HMAC · RSA · Cache-Timing
Nonce Guard AES-GCM vs AES-GCM-SIV comparison — live nonce reuse attack showing keystream XOR recovery and GHASH key extraction, synthetic IV construction, and misuse-resistance comparison. RFC 8452. crypto-lab-nonce-guard AES-GCM · AES-GCM-SIV · RFC 8452 · Synthetic IV
Protocol Compose MAC-then-Encrypt vs Encrypt-then-MAC, padding oracle attack, CRIME, and the composition failures that drove TLS 1.3. Safe primitives composed unsafely break everything. crypto-lab-protocol-compose MAC-then-Encrypt · Encrypt-then-MAC · CRIME · TLS 1.3
Lattice Fault Implementation attacks on lattice PQC: NTT power leakage, rejection-sampling fault bypass, KyberSlash timing, and a loop-abort fault that recovers a whole ML-DSA secret from one signature. The math survives; sloppy implementations do not. crypto-lab-lattice-fault ML-KEM · ML-DSA · KyberSlash · Fault Injection
LLL Break Step-by-step LLL and BKZ lattice reduction with Gram-Schmidt views, Lovasz condition checks, and a toy LWE primal attack that shows why Kyber-sized parameters do not fall the same way. crypto-lab-lll-break LLL · BKZ · Gram-Schmidt · Toy LWE
HQC Timing Break A full-decryption oracle on HQC, where compiler rewrites reintroduce cache timing into constant-time source. Substitutes a repetition code for HQC's Reed-Muller inner code so the soft-decoding step stays legible. crypto-lab-hqc-timing-break vs. HQC · Cache Timing · Soft-ISD · Repetition Stand-In
KyberSlash A KyberSlash timing-attack lab for ML-KEM, covering secret-dependent division, vulnerable compression paths, the Barrett-reduction fix, and live attack simulation. crypto-lab-kyberslash ML-KEM · KyberSlash · Timing Attack · Barrett Reduction
Nonce Lattice ECDSA nonce-bias lattice attack on secp256k1 and P-256 — Hidden Number Problem construction, in-browser LLL reduction, and byte-for-byte private-key recovery from biased nonces. crypto-lab-nonce-lattice ECDSA · Hidden Number Problem · LLL Reduction · secp256k1
Ciphertext Mirror An ML-KEM side-channel walkthrough — manipulating ciphertexts through the Fujisaki-Okamoto transform, LDPC decoder behavior, and NTT blinding countermeasures. crypto-lab-ciphertext-mirror ML-KEM · FO Transform · LDPC Decoder · NTT Blinding
HQC Timing The 2020 timing attack on HQC's BCH decoder — the parameterization predating today's Reed-Muller/Reed-Solomon — reproduced with a modelled decode time rather than a real decoder, then silenced by constant-time. crypto-lab-hqc-timing vs. HQC · Wafo-Tapa 2020 · Timing Oracle · Modelled Decode Time
JWT Forge Paste or generate a JWT, tamper with claims, and swap algorithms to watch alg:none and HS/RS key-confusion attacks succeed against a vulnerable verifier and fail against a correct one. crypto-lab-jwt-forge JWT · JWS · alg:none · HS/RS Key Confusion
LWE Hints Counts how many leakage hints collapse an LWE lattice problem on sparse ternary secrets, then recovers a toy secret from real hints and tests the Gaussian assumption against sampled data. ePrint 2026/1081. crypto-lab-lwe-hints LWE · Sparse Ternary Secrets · Approximate Hints · Lattice
Syndrome Drain How code-based KEMs erode below NIST Level 1 when one public key derives many session keys — run a toy decode-one-of-many search and watch the measured work fall as √D, then compute when to rotate keys. crypto-lab-syndrome-drain DOOM · Syndrome Decoding · vs. Code-Based KEMs · May & Sá Diogo 2026
Broken Trust Leak one bit of ML-DSA's per-signature masking randomness and the secret subkey becomes the bottom of a hill you can roll down — no lattice reduction. Watch a toy version descend beside real-scale numbers from ePrint 2026/472. crypto-lab-broken-trust vs. ML-DSA · Bit Leakage · Hill-Climbing · Toy-Scale Only
Timing Side-Channel Recover a hidden secret one byte at a time from an early-exit comparison, then watch a constant-time compare flatten the leak. Real performance.now() measurements. No backend. crypto-lab-timing-sidechannel Timing Attack · Constant-Time · Side-Channel · Secret Compare
Time Trust Real Ed25519, HMAC, and X.509 verification driven by one movable clock — drag NOW and watch certificates, JWTs, TOTP codes, and replay caches change their verdicts about bytes that never change. crypto-lab-time-trust Ed25519 · X.509 · JWT · TOTP
Nonce Collision Reuse one nonce under one key across AES-CTR, AES-GCM, ChaCha20-Poly1305, and AES-CBC — crib-drag plaintext out of XOR'd ciphertexts and forge tags the real verifiers accept. crypto-lab-nonce-collision AES-GCM · ChaCha20-Poly1305 · Forbidden Attack · Crib Dragging
Entropy Collapse Restore two copies of a VM snapshot and watch an honest, standards-conformant HMAC_DRBG emit identical session keys from both — the seed, not the generator, is the whole game. crypto-lab-entropy-collapse HMAC_DRBG · Seed Provenance · VM Cloning · Nonce Reuse
Salamander Build one AES-GCM ciphertext that decrypts to two different valid plaintexts under two different keys — both tags verify, because AEAD never promised they couldn't. crypto-lab-salamander AES-GCM · GHASH · GF(2¹²⁸) · Message Franking
Frozen Heart Forge a Schnorr zero-knowledge proof the real verifier accepts — because the Fiat-Shamir challenge hash left one transcript field out of its input. crypto-lab-frozen-heart Fiat-Shamir · Schnorr · ristretto255 · NIZK
Power Trace Recover an AES-128 key byte from power consumption alone. The cipher is correct and constant-time, yet CPA and DPA walk the key out through the power rail. Simulated traces, real statistics. crypto-lab-power-trace CPA · DPA · AES-128 · Hamming Weight
Protocol Checker A Dolev-Yao symbolic model checker that rediscovers Lowe's attack on Needham-Schroeder live — found by searching, not by being told — then closes the seventeen-year-old flaw in one edit. crypto-lab-protocol-checker Dolev-Yao · Symbolic Model · Needham-Schroeder · Unification
Syndrome Hints A real information-set-decoding attack on syndrome decoding over F₂ — feed it leaked side-channel hints and watch the work factor slide from exponential toward polynomial. crypto-lab-syndrome-hints Hint-ISD · Prange · Stern · Syndrome Decoding
Encrochat A real Double Ratchet exchange with a genuinely opaque wire, then a modelled endpoint implant reads the plaintext anyway. The cryptography held; it did not matter. crypto-lab-encrochat Double Ratchet · X25519 · AES-256-GCM · Endpoint Implant
Ablation Wire The 1942 Navajo code-talker stack rebuilt on modern primitives, with every layer independently switchable — turn one off and discover which was actually load-bearing. crypto-lab-ablation-wire X-Wing KEM · AES-256-GCM · Transcript Binding · Rust/WASM
Matsui Line Matsui's Algorithm 2 against the same toy SPN Biham Lens attacks — count the bias in real known-plaintext traffic, watch one subkey candidate separate, then watch the piling-up lemma's prediction miss. crypto-lab-matsui-line Linear Cryptanalysis · LAT · Piling-Up Lemma · Known-Plaintext
Context Ward Seals an agent's context window into a SHA-256 hash chain with role-separated HMAC seals and Ed25519 tool attestations, then shows injected content passing every check while the agent is compromised anyway. crypto-lab-context-ward SHA-256 Chain · HMAC-SHA-256 · HKDF · Ed25519
Masked Core First-order Boolean masking flattens the CPA that Power Trace runs — so combine two samples instead of one and the key byte comes back. Masking is a price, not a wall, and this measures it. crypto-lab-masked-core Boolean Masking · Second-Order CPA · AES-128 · Centered Product
GGH Trapdoor A lattice trapdoor is just a good basis: one lattice, two bases, and only the short one decrypts. Then two attacks read the secret off the shape of GGH's own randomness. crypto-lab-ggh-trapdoor GGH · Babai Round-Off · LLL · Nguyen-Regev
Factor Forge Seven classical factoring methods on a real BigInt N, each waiting for a different mistake in key generation. Obey every RSA rule and rho and ECM still finish; only size stops them. crypto-lab-factor-forge Pollard Rho · Lenstra ECM · Quadratic Sieve · Fermat
Glass Box Chow-style white-box AES-128 built from your key as 2,032 encoded lookup tables, then attacked twice: differential computation analysis pulls the key from execution traces, and BGE step A1 strips the table encodings. crypto-lab-glass-box White-Box AES · Chow 2002 · DCA · BGE Attack
Return Path Impossible differentials and the boomerang attack on the same toy SPN as Biham Lens, with DDT and BCT tables computed live, an adaptive chosen-ciphertext oracle, and a one-way-impossible crossing every round trip closes. crypto-lab-return-path Impossible Differential · Boomerang Attack · BCT · Toy SPN

Historical & Steganography

Demo Description Source Primitives
Dead Sea Cipher Substitution and polyalphabetic ciphers from Atbash to Vigenère, through to modern AES-256-GCM. Encode, decode, and explore classical cryptanalysis. crypto-lab-dead-sea-cipher Substitution · Vigenère · Atbash
Stego Suite LSB substitution, DCT-domain hiding, and adaptive embedding with live chi-squared steganalysis. Hide the message, not just the content. crypto-lab-stego-suite LSB · DCT · Adaptive Embedding · Chi-Squared Steganalysis
J-UNIWARD JPEG steganography via Universal Wavelet Relative Distortion — adaptive DCT coefficient embedding that minimizes wavelet-domain detectability. The state-of-the-art in content-adaptive JPEG steganography. crypto-lab-j-uniward J-UNIWARD · DCT · Wavelet Distortion · Adaptive Embedding
Enigma Forge Full mechanical Enigma — rotors with double-stepping, plugboard, and reflector — plus the crib-based Bombe break that exploits the flaw that no letter ever maps to itself. crypto-lab-enigma-forge Enigma · Rotors · Plugboard · Bombe
Vigenère Break Encrypt and decrypt with a repeating-key Vigenère cipher, then recover the key length with Kasiski examination and the index of coincidence and solve each column by frequency analysis. crypto-lab-vigenere-break Vigenère · Kasiski Examination · Index of Coincidence · Frequency Analysis
Regex Veil — FTE Compiles a regex to a minimal DFA, counts its length-n language exactly, and enciphers real AES-CTR bytes into that slice with FF1 — output a DPI rule accepts, plus the substitution attack proving nothing is authenticated. crypto-lab-fte FF1 · DFA Ranking · Cycle Walking · AES-256-CTR
Covert Channel Studio The same bits moved eleven ways — DNS labels, ICMP echoes, inter-arrival gaps, packet order, cache lines — each scored by a cited detector. Then a warden closes several channels while their anomaly score falls, leaving no record. crypto-lab-covert-channel-studio Storage & Timing · Protocol Hopping · Flush+Reload · Active Warden

Related Projects

These sit outside the browser-demo scope of Crypto Lab but belong to the same collection:

  • Crypto Compare — Algorithm reference covering NIST and PQ-Safe standards.
  • Cipher Museum — An interactive museum spanning 3,900 years of cryptographic history. Thirteen halls, 140 exhibits, live encryption demos, and cryptanalysis labs.
  • Meow Decoder — Secure optical air-gap file transfer via QR-code GIFs. AES-256-GCM + Argon2id + ML-KEM-1024 + fountain codes. Python + Rust.
  • Snow 2 — A modern Rust reimplementation of SNOW with AEAD support, Argon2id-derived keys, and steganographic output options.

About

Each demo is self-contained: one concept, one repository, full source. Documentation and threat models are included where the attack surface warrants it.

Built by Paul Clark — IT Librarian & Systems Analyst.

Citing

If you use Crypto Lab in teaching or research, please cite it via the "Cite this repository" button in the sidebar (APA and BibTeX), or the Zenodo record.


So whether you eat or drink or whatever you do, do it all for the glory of God. — 1 Corinthians 10:31


Maintaining the fleet

For contributors. Each Crypto Lab demo is its own repository and its own site, so the things that go wrong go wrong quietly: a lab can be live with no card here, or serving a build older than its own main, while every file-in-this-repo check stays green. These tools each exist because one of those happened.

What each watch is responsible for

Two different questions are being asked here, and neither answers the other's.

The scheduled research watch below asks did the outside world change? — new cryptanalysis, errata, a withdrawal, a standards decision, a shift in deployment guidance. It reads primary sources, works out which labs a finding touches by inspecting what those labs actually contain rather than going by their titles, and reports what it found. It never edits a repository.

The tools in the table that follows ask did this fleet drift from itself? — a lab live with no card here, a site serving a build older than its own main, a card claiming an algorithm its source does not implement, a worksheet naming a control its exhibit no longer has, a module page publishing a defect note that stopped being true.

A finding from one is not evidence about the other. A lab can be perfectly self-consistent and describe a standard withdrawn last week; it can be current with the literature and serving a stale build. Green here means the fleet agrees with itself, and nothing more than that.

Neither asks whether the demonstrations teach well — whether a student who works through an exhibit comes away understanding the thing it was built to show. That needs an instructor, not a checker, and nothing in this section is a substitute for one.

Scheduled research watch

A ChatGPT scheduled task checks Crypto Lab research daily. It uses this catalog's current default branch to discover the labs, checks primary research and standards sources, and reports a finding only when a specific repository has a new, actionable gap. It does not edit repositories; a maintainer reviews and applies any suggested change. This watch is separate from the repository's CI checks below.

The task's prompt as of September 27, 2026 is reproduced verbatim below. The reproduction may lag the task: the scheduled task lives in ChatGPT, nothing here can read it, and no check compares the two — so treat the block as what the prompt said on that date rather than as what is running now. Its opening says “Weekly” and asks for an eight-day lookback, while the task's actual schedule is daily; the overlap helps catch later substantiation and revisions.

Weekly Crypto Lab watch. Lookback window: developments dated in the last 8 days (overlap is intentional).

CATALOG: Use the current default branch of https://github.com/systemslibrarian/crypto-lab as the dynamic catalog of all linked lab repositories and their topics. Include the catalog itself and any newly added labs.

STEP 1 — SCAN: Search for newly published or newly substantiated cryptanalysis, errata, withdrawals, standards decisions (drafts, finals, deprecations), and deployment guidance within the window. Check original papers, IACR ePrint, NIST (FIPS/SP/IR, PQC announcements), IETF/IRTF/CFRG, other relevant standards bodies, and researcher disclosures. News may supply leads, but verify every technical claim against a primary source.

STEP 2 — TRIAGE: Keep only developments that could materially affect a covered primitive, protocol, attack demonstration, parameter choice, or research/status claim. For each, classify it as: demonstrated result, extrapolation, attack-model-conditional, preprint, withdrawn, or final standard.

STEP 3 — MATCH: Only for developments that survive triage, identify every potentially affected lab from its actual contents (README, code, UI text, learning materials), not just the catalog tags. Inspect each affected repo's current default branch and its catalog card before judging an update necessary. If the repo already reflects the development (check content and recent commits), suppress it.

OUTPUT — only for specific, new, actionable gaps, one entry each:
- Severity: Critical (now factually wrong or insecure) / Correction (outdated status or claim) / Enhancement (worth adding)
- Repo(s) and file/section
- What is now inaccurate or missing
- Primary source with date and link
- Suggested concise change
- Meaningful test, if any
Include the catalog when its own cards or learning materials need correction. Sort by severity.

If nothing is actionable, reply with exactly one line: "Crypto Lab watch: no actionable changes this week." Do not modify, open PRs against, or merge any repository.

The table is generated from the tools themselves — the command from each tool's Run: line, the failure from its Prevents: line, and the cadence from the workflow job that runs it. Do not edit it by hand; run node tools/tools-sync.js.

Tool What it prevents When it runs
node tools/catalog-evidence.js verify the catalog asserting a lab implements an algorithm its source does not weekly; selftest only: every PR and push
node tools/catalog-recall.js the chip rule being promoted to a failing check on a judgement call rather than a measurement weekly
node tools/catalog-sync.js check the algorithm index drifting from the cards, a card claiming an algorithm with no evidence behind it, and a chip the vocabulary cannot name passing as clean every PR and push
node tools/clone-guard-proof.js a generator silently deriving this repo's tracked files from another lane's uncommitted work every PR and push
node tools/concept-sync.js check the gap list answering “is anything missing?” wrongly because a demo was never filed under a concept manual
node tools/corpus-freshness.js a corpus entry going on describing a lab that has since changed underneath it, with every other checker green manual; selftest only: every PR and push
node tools/corpus-sync.js check a demo staying invisible to the crypto-counsel chatbot because its corpus entry was never added manual
node tools/deploy-sync.js check a lab serving a build older than its own main, with nothing anywhere going red weekly; selftest only: every PR and push
node tools/depth-audit.js check a depth ranking resting on dimensions nobody re-derived, and a coverage figure that ages into a claim manual
node tools/dispatch-census.js check a lab dropping out of the dispatch checkers’ denominator without the count going red manual
node tools/dispatch-claims.js check the canonical dispatch paragraph asserting something the fleet’s own YAML no longer supports manual
node tools/dispatch-comment-sync.js check the paragraph explaining why the dispatch exists drifting into many wordings, or being deleted with the line it defends manual
node tools/dispatch-proof.js the dispatch work’s claims being trusted without re-running the evidence behind them manual
node tools/dispatch-sync.js check a merged bump whose deploy dispatch can fail, print nothing and exit 0, leaving the live site on the old build weekly
node tools/evidence-shape-proof.js a variable name, a constant, an import path or a drawing function crediting a lab with an algorithm it does not implement every PR and push
node tools/fleet-check.js a whole-fleet failure sitting unnoticed because the checker that would catch it is only run by hand weekly
node tools/fleet-sync.js check a lab going live with no card, which every catalog checker then reads as consistent rather than missing weekly; selftest only: every PR and push
node tools/gate-sync.js check a Dependabot bump clearing a lighter gate than the deploy runs, merging itself, then failing where no pull request is watching weekly; selftest only: every PR and push
node tools/lab-dates.js check a card's displayed dates drifting from the repository they describe, or a package bump reading as a content update weekly; selftest only: every PR and push
node tools/level-sync.js check a card shipping with no audience level, or LEVELS-REVIEW.md disagreeing with the levels the page actually filters on manual
node tools/port-sync.js check two labs sharing a Playwright port, where a local run silently tests whatever is already listening manual; selftest only: every PR and push
node tools/protection-census.js reading a 404 from the classic protection endpoint as unprotected when a ruleset is protecting the branch manual
node tools/readme-sync.js check this README’s tables drifting from the cards they are generated from every PR and push
node tools/teach-build.js check a generated teach page drifting from its source, and a hardcoded catalog count going stale every PR and push
node tools/teach-drift.js a worksheet naming a control its live exhibit no longer has daily
node tools/teach-issues.js a module page publishing a defect note about a lab that stopped being true daily
node tools/teach-layout.js a teach page scrolling sideways, overflowing its container, or crushing prose into a column every PR and push
node tools/teach-observe.js <exhibit url> a privacy note on a module page describing contacts the exhibit no longer makes manual
node tools/test-invocation.js a lab carrying a full test suite that CI never executes, which reads as clean everywhere because nothing reports a test that was never attempted manual
node tools/theme-sync.js check a lab drifting off its single pinned theme, or a removed theme toggle coming back weekly
node tools/tools-sync.js check this list drifting from the tools it describes every PR and push

13 of these 31 listed commands run only when someone runs them. The rest run in CI, on the cadence shown. Selftest-only runs exercise fixtures, not the live fleet. A checker nobody runs reports nothing, which is the failure every one of these was written after.

Not listed above: catalog-structure-check.js, catalog-vocab.js, clone-source.js, depth-audit-report.js, dispatch-mutations.js, render-registry.mjs, render-verification.mjs, sibling-labs.js, transform.mjs, validate-manifest.mjs — support code, fixtures, and one-off rewriters kept as the precise record of what was done to the fleet rather than as things to run.

This table lists the tools git tracks. Anything untracked in tools/ is work in progress rather than fleet machinery, and is absent here for that reason rather than because nothing else exists.

About

Crypto Lab is a free, browser-based cryptography teaching collection: interactive demonstrations spanning classical cryptography, modern protocols, cryptanalysis, privacy technologies and post-quantum cryptography, built on real primitives and organized into guided learning paths for self-learners and course modules with worksheets for instructors.

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages