The Cyber Threat Perspective
The Cyber Threat Perspective
SecurIT360
Episode 190 | OWASP Top 10 Part 4: Cryptographic Failures
22 minutes Posted Jul 31, 2026 at 5:00 pm.
Intro — why A04 is our least favorite OWASP category
Most crypto findings aren't practically exploitable
Hygiene risk vs. brand reputational risk
Security Scorecard and BitSight: do these scores matter?
Low-hanging fruit vs. material risk — a pen tester's view
Perfect score, terrible password policy, no MFA
Why a 16-year-old vulnerability is a hygiene failure
What else aren't they fixing?
The two halves of A04: data in transit and data at rest
What is a JSON Web Token (JWT)?
Pen test story: decoding the JWT and spotting the role claim
The exposed config backup and the leaked signing secret
Re-signing the token and escalating to administrator
MD5, SHA-1, and what to use instead (Argon2, scrypt)
The coffee shop scenario: what SWEET32 actually requires
250 GB of traffic and zero documented exploits in the wild
What you should actually care about
Quantum computing: theoretical today, maybe not tomorrow
Wrap-up and what's next (A05)
0:00
22:37
Download MP3
Show notes
Most cryptographic findings on your vulnerability report will never be exploited by a real attacker. So why do they keep showing up — and why should you still fix them? In this episode of the Cyber Threat Perspective, Brad Causey and Jordan Natter break down OWASP Top 10 A04: Cryptographic Failures — the entry they openly call their least favorite on the list. They explain why SWEET32, BEAST, and the other scary-sounding named TLS vulnerabilities almost never translate into real-world compro...