Habr•September 28, 2026•🇷🇺Translated from Russian

CryptoLab: Interactive Educational Platform Turns Cryptographic Protocols Course into Hands-On Alice, Bob and Mallory Experiments

CryptoLab is an educational testbed created to transform traditional cryptographic protocols laboratory work into interactive experiments featuring Alice, Bob, and Mallory. Instead of simply calling encrypt and decrypt functions, students now place an active adversary between sender and receiver to observe real protocol behavior under attack.

The first laboratory centers on the model Alice → Mallory → Bob, where Alice acts as the client, Bob as the server, and Mallory controls the communication channel. Mallory can INSPECT, MODIFY, DROP, or REPLAY packets. In normal operation the packet passes unchanged; once students assume the Mallory role they begin tampering to see concrete results.

Key Experiments in the First Lab

One experiment shows what happens when Mallory alters ciphertext protected by AES-GCM. Because AEAD is used correctly, any modification causes the authentication tag check to fail, resulting in immediate rejection rather than partial plaintext delivery. This demonstrates the principle that AEAD decryption must return either valid plaintext or failure, never forwarding data to application logic before authentication succeeds.

A second experiment covers replay attacks. Students capture a fully valid packet containing a correct authentication tag and nonce, then resend it. Without replay protection the server accepts the duplicate because the cryptographic primitive itself only guarantees authenticity and integrity, not freshness. Enabling replay protection through sequence numbers or a replay cache causes the second copy to be rejected, illustrating that replay defense is a protocol-level property built around the primitive.

Additional covered topics include ciphertext and authentication tag handling, AAD, nonce reuse consequences, CSPRNG versus weak RNG behavior, salt usage, key rotation and revocation, and metadata leakage. The lab supports both interactive sessions and automated scenarios launched via command line, such as ./CryptoLab scenario --lab 1 --name 08_weak_rng, which also serve as regression checks during platform development.

Programming tasks remain part of the course but focus on the correct use of existing libraries rather than implementing algorithms. Students write supporting logic for data preparation, key and parameter handling, protocol message formatting, validation, state management, and error handling in Python 3.10.

The platform is distributed as a ready-to-run application for Windows x64 and macOS Apple Silicon without requiring separate installation of Python or Docker. The first lab has already undergone multiple development iterations and now forms the foundation for a second lab on symmetric encryption modes (ECB, CBC, CTR, GCM), padding oracle attacks, and bit-flipping. Future labs will extend the same testbed to asymmetric cryptography, key exchange, digital signatures, handshake protocols, TLS, and PKI.

Related articles

Habr•Other

From Scanner Overload to Manual Insight: A Bug Bounty Hunter's Journey

A young researcher recounts his transition from automated scanning to thoughtful manual analysis in Bug Bounty programs. After completing a broad information security course covering cryptography, networks, Docker, databases, and OWASP Top 10, he initially approached real-world targets with the same scanner-heavy mindset used in labs. Months of fruitless results led to burnout and a six-month break working in construction. Returning with a new focus, he studied hundreds of public HackerOne reports to understand researcher reasoning and anomaly detection. This shift enabled his first valid, unreported finding and fundamentally changed his methodology. Today the 18-year-old university student balances Bug Bounty with reconnaissance, machine learning, and personal projects while emphasizing deep application understanding over tool volume.

Habr•Other

Bypassing Paid Export on AI 3D Generation Sites via Browser Network Inspection

A detailed walkthrough shows how users can retrieve AI-generated 3D models in GLB format from services that normally require a paid subscription for export. The method relies on opening the browser developer console, filtering network requests for .glb files after model generation completes, and opening the intercepted asset in a new tab. Examples using Tripo3D and Hi3D demonstrate that the generated model and textures are already present on the client side even when the export button remains disabled. Additional steps address compatibility issues with 3ds Max by recommending conversion through gltf.report with Draco compression before import. The technique also covers post-processing in ZBrush for auto-retopology and format conversion to OBJ. The article notes that such workarounds exist because many AI platforms limit free exports while still rendering full models locally.

AntiMalware•Other

National Platform Max Begins Testing Advertising Tools to Monetize User Attention

The Russian national platform Max has started internal testing of new advertising instruments designed to convert user attention into sellable ad inventory. According to the company's press service, the tests are already underway inside the application, although the exact placement, visual format, and eligibility criteria for advertisers remain undisclosed. The move marks a significant shift for the platform, which previously operated without visible commercial advertising. Observers note that Max could become one of the largest domestic digital advertising channels if the tests prove successful. No timeline has been given for a public rollout or for the publication of detailed advertising policies.

Habr•Other

Yandex Drops Earbuds Under X-Ray Microtomography: Detailed Internal Analysis of First AI-Powered TWS Headphones

Engineers used non-destructive X-ray microtomography to examine Yandex Drops, the company's first TWS earbuds featuring the Alice AI voice assistant. The scan revealed an eight-layer HDI PCB, three microphones per earbud arranged in a dual feedforward plus feedback ANC configuration, an 11 mm driver, and a QFN-packaged SoC with NPU. No hardware disconnect point was identified in the microphone signal path within visually accessible traces, connectors, and vias. Battery dimensions, coil windings in the case, and internal flex routing were measured directly from calibrated voxel data. The study also confirmed contact-based charging via spring-loaded claw contacts and a Hall-effect sensor in the case lid. The work demonstrates how industrial micro-CT can support hardware security reviews without destroying the sample.