Propose a Cryptographic Target State for a Checkout Stack
Overview
What this challenge is about.
Propose a Cryptographic Target State for a Checkout Stack. Intermediate challenge in design. Designing real products under real constraints, earn a blockchai...
The Brief
What you'll do, and what you'll demonstrate.
Design a defensible modern cryptographic target state for the checkout stack and a prioritized migration path that satisfies PCI DSS SAQ A-EP, auditing every current choice against best practice.
This is not a design exercise. It is the work a product designer does between a brief and a shipped interface. That distinction matters to every hiring manager who has seen candidates redesign Spotify's homepage and none who have worked under real product constraints.
When you finish, you will have something most graduates do not: a real-world deliverable, verified by Ewance, that you can show to a hiring manager and say "I did this. Here is the proof."
Earning criteria — what you'll demonstrate
- Inventory every cryptographic touchpoint in a payment-facing web stack from documentation alone
- Calibrate severity for weak primitives (RSA-1024, SHA-1, CBC modes) with defensible, evidence-backed reasoning
- Design modern cryptographic replacements with concrete, low-risk migration steps
- Map cryptographic controls to specific PCI DSS SAQ A-EP requirements
- Communicate technical risk and remediation cost to both engineers and finance stakeholders
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Cryptography
Apply cryptography to solve real industry problems and demonstrate production-level capability.
- Tls
Apply tls to solve real industry problems and demonstrate production-level capability.
- Pci Dss
Apply pci dss to solve real industry problems and demonstrate production-level capability.
- Secure Design
Apply secure design to solve real industry problems and demonstrate production-level capability.
- Risk Assessment
Apply risk assessment to solve real industry problems and demonstrate production-level capability.
- Documentation
Apply documentation to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Application Security Engineer
Auditing TLS, cookie signing, and column encryption in a real web stack mirrors the daily work of hardening application cryptography. You practice turning configuration evidence into defensible secure-design recommendations engineering teams can ship.
This challenge sharpens
- cryptography
- tls
- secure-design
Security Compliance Analyst
Mapping findings to PCI DSS requirements and writing a CFO-ready summary is the core of compliance work. You learn to translate cryptographic risk into requirement-traceable evidence and prioritized remediation that auditors and executives both accept.
This challenge sharpens
- pci-dss
- risk-assessment
- documentation
Security Architect
Designing a coherent cryptographic target state and a phased migration across a payment stack is foundational architecture work. You practice balancing modern primitives, feasibility, and business impact into a single defensible plan.
This challenge sharpens
- secure-design
- cryptography
- risk-assessment