Security

Crypto Visualizer

A cryptography visualizer lets you watch the three primitives behind every secure connection work on your own input: a hash that changes completely when one character changes, a symmetric cipher that needs the same key to unlock, and an asymmetric pair where a public key encrypts and only the private key decrypts.

Last reviewed by the Radiatus Cloud team

Cryptography Concepts Visualizer

Interactive demos to understand the core pillars of cryptography: Hashing, Symmetric Encryption, and Asymmetric Encryption.

1. Hashing (One-Way Fingerprint)

Hashing transforms any input into a fixed-size string. A tiny change in input creates a completely different output (Avalanche Effect).

...

2. Symmetric Encryption (Shared Secret)

The SAME key is used to lock and unlock the message. Fast, but key distribution is hard.

3. Asymmetric Encryption (Public/Private Key)

Alice uses Bob's Public Key to encrypt. Only Bob's Private Key can decrypt.

(Public Key will appear here)

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Hashing and the avalanche effect

Type in the first box and the SHA-256 digest updates on every keystroke. Change one character and the tool counts how many of the 64 hex digits changed; it is usually around 32, half of them, which is the avalanche property a hash needs. The digest is always 256 bits regardless of input length, and it cannot be reversed, which is why systems store hashes of passwords rather than passwords. For password storage specifically, use a slow hash such as bcrypt or Argon2, not raw SHA-256.

Symmetric encryption with a derived key

The second section runs AES-256 in GCM mode. Your passphrase is not used directly as the key; it is stretched through PBKDF2 with 100,000 iterations of SHA-256 and a random 16-byte salt into a 256-bit key. A random 12-byte IV is generated for every encryption, so encrypting the same message twice produces different ciphertext. GCM appends a 16-byte authentication tag, and the demo proves the point by trying to decrypt with a passphrase one character longer: the tag fails to verify and decryption is refused rather than returning garbage.

Asymmetric encryption with RSA-OAEP

Bob's button generates a real 2048-bit RSA key pair. The public key is shown in PEM form; the private key stays in memory and is never displayed. Alice encrypts with the public key, and only the private key can recover the message. RSA-OAEP with a 2048-bit key and SHA-256 can encrypt at most 190 bytes at once, and the tool says so if you exceed it. That limit is why TLS and PGP use RSA or elliptic curves only to agree on an AES key, then encrypt the actual data with AES.

How the three fit together in TLS

  • Asymmetric cryptography authenticates the server and establishes a shared secret.
  • Symmetric cryptography, usually AES-GCM or ChaCha20-Poly1305, encrypts the traffic because it is hundreds of times faster.
  • Hashing, inside HMAC and signatures, proves nothing was altered in transit.

Everything here uses the browser's native Web Crypto implementation, the same code that handles HTTPS, and no key or message leaves the page.

Related tools

  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • AES Text Encryption — Encrypt and decrypt text with AES-256-GCM using a password (PBKDF2 key derivation), entirely in your browser. Strong, standard cryptography with zero uploads.
  • RSA Key Generator — Generate RSA public and private key pairs.
  • HMAC Generator — Generate HMAC signatures with SHA-256 and other algorithms, and use them correctly.

Frequently Asked Questions

Is the AES encryption real or a demonstration?

Real. It calls crypto.subtle.encrypt with AES-GCM and a key derived by PBKDF2. The ciphertext shown would decrypt correctly in any other AES-GCM implementation given the same salt, IV and passphrase.

Why does the same message produce different ciphertext each time?

A fresh random IV and salt are generated for every encryption. Reusing an IV with the same key in GCM mode is a serious flaw that leaks the XOR of the two messages, so correct implementations never do it.

Why can RSA only encrypt 190 bytes?

RSA operates on a number smaller than its modulus, and OAEP padding with SHA-256 consumes 66 bytes of the 256-byte block. Real protocols encrypt a short symmetric key with RSA and use that key for the message.

Can I recover the private key from the page?

No. It is held in a non-extractable CryptoKey object in memory and discarded when you leave. The public key is shown because that is what public keys are for.

Is SHA-256 suitable for storing passwords?

No. It is fast by design, so an attacker with a leaked hash list can test billions of guesses per second on a GPU. Use bcrypt, scrypt or Argon2, which are deliberately slow and salted.

Privacy & Security

Processed locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.