REDMARK FORGE SANDBOX
Protect · Derive · Verify

Cryptography Lab

AES-GCM text and file encryption, PBKDF2 key derivation, cryptographic hashes, HMAC, random bytes and encoding conversion.

Browser-local: your data is processed in this tab, not uploaded by these tools. Experimental results are educational; validate security-critical or forensic conclusions independently.

01 · AES-GCM text encryption

AES-256-GCM + PBKDF2-SHA-256; salt, IV and iteration count travel in the package.

Keep passphrases separate from ciphertext.

02 · File encryption

Encrypt any file into an authenticated package; decrypt back to a downloaded file.

File limit 100 MiB.

03 · Hash & HMAC

SHA-256/384/512 digests and keyed HMAC-SHA-256.

Results appear here.

04 · Randomness & encoding

Secure random bytes via Web Crypto; UTF-8, hex and Base64 conversion.

Output appears here.

05 · Password & passphrase generator, strength meter

Unbiased CSPRNG generation (rejection sampling) and an entropy estimate that penalises common passwords, repeats and keyboard/sequence patterns.

Strength analysis appears here.

06 · Key-derivation lab (PBKDF2 · HKDF · scrypt)

Derive keys with adjustable cost, benchmark this browser and see what the cost means for an attacker. scrypt is memory-hard (pure JS, verified against RFC 7914).

Derived key and timing appear here. For scrypt, "Iterations / N" is the exponent k (N = 2^k, typically 14).

07 · Public-key lab (RSA-OAEP · ECDSA · ECDH · Ed25519)

Generate keys, export/import PEM, encrypt, sign, verify, agree on a shared secret, and encrypt whole files to a public key (hybrid RSA + AES-256-GCM).

|
Generate a key pair to begin. Private keys never leave this page.

08 · Extended hashes & checksums

MD5, SHA-1, SHA-3 (224–512), CRC-32, Adler-32 and a hash-type identifier. MD5/SHA-1 are broken for security; shown for compatibility.

Digests appear here.

09 · Encodings, classical ciphers & auto-decode

Base32, Base58, Base64URL, URL, binary, ROT13, Atbash, Caesar (with brute force), Vigenère, XOR, and a "magic" decoder that tries common encodings on its own.

Output appears here.

10 · TOTP / HOTP (RFC 6238 / 4226)

Time-based and counter-based one-time passwords. Compatible with authenticator apps; validated against RFC test vectors.

Codes appear here and refresh every second while this panel is active.

11 · JWT inspector & verifier

Decode header and claims, check exp/nbf/iat, flag risky algorithms, and verify HS256/384/512 with a secret or RS/ES256/384/512 with a public key PEM.

Decoded token appears here. Nothing is sent anywhere.

12 · X.509 / PEM / ASN.1 inspector

Paste a PEM (certificate, CSR, key) or load a DER file. Shows subject, issuer, validity, SANs, key type, fingerprints and a generic ASN.1 tree.

Certificate fields and ASN.1 tree appear here.

13 · Shamir secret sharing

Split a secret into n shares so that any k recover it and fewer than k reveal nothing (GF(2⁸), per-byte polynomials).

Share format: RFS1-k-index-hex.

14 · AES modes & tamper lab

Encrypt with GCM, CBC or CTR, then flip one ciphertext bit and see what happens: GCM rejects it, CBC garbles a block, CTR silently changes exactly one plaintext bit.

Results appear here. Fresh random key and IV on every run.