DEV Community

Basstardd
Basstardd

Posted on

The year cryptographers got nervous

I think cryptography is the most modest discipline in the world. It literally provides the means that keep the modern world together. Yet it is rarely publicly recognized. Cryptographers are basically a bunch of math geeks applying math to build cryptographic primitives that ensure three basic properties of any digital communication: confidentiality (the message stays private, aka encryption), integrity (nobody tampered with it, our beloved hash algorithms combined with MACs, think the token your app hands you after login, or signatures), and authenticity (we know who sent it, digital signatures, which give integrity for free as well). They use math to make primitives, combine primitives into schemes (asymmetric aka public-key cryptography), and schemes into protocols (again our beloved HTTPS, for example).

Cryptographers sat at the top of the digital world doing their academic stuff, publishing papers and talking at conferences. Once the community verified the math, results trickled down to our world of programmers, code and infrastructure, giving our programs all the nice properties we love: privacy, security for end users and our databases.

For a long time they sat there tranquilos, drinking sangria and feeling safe and relaxed from intrusions by outside world. After all, they have math proofs on their side! A cryptographic proof says “if problem X is hard, this scheme is secure”. Whether X is actually hard was never proven. It was assumed, because nobody had found a shortcut or had enough compute power to brute-force it. Classical cryptography always relied on two things: the real amount of compute on Earth (you cannot brute-force this key, so it is practically safe), and the hope that nobody finds an algorithmic shortcut. Banks were fine with this. Shortcuts came rarely, cryptographers are well-informed people, they were the first to know and reacted swiftly. Probability not zero, but something banks and the rest of the world could live with.

This kept cryptographers, banks and the rest of the world relaxed for quite some time. Until recently.

The first reason to worry was initially a computer science fringe field called quantum computing. Once considered not so promising, it is becoming a new platform for humans to compute. Not incrementally more powerful, but many orders of magnitude more powerful for specific problems. And the problems where it shines the most, factoring and discrete logarithms, are exactly the ones our beloved public-key cryptography is built on. Remember how we defined “practically safe”? Cannot be brute-forced with available compute. Now you see why cryptographers got a bit nervous. With quantum computing, compute becomes abundant and the practical guarantee cryptographers relied on potentially does not hold any more.

But cryptographers are diligent people! They like problems, and they built a whole new field named post-quantum cryptography. Math-based algorithms that survive attacks from, you guess, quantum computers. A thriving field with many new schemes already developed and some already deployed (your browser has been doing post-quantum key exchange since 2024). They even named the enemy: “Q-day”, the day a quantum computer breaks the first real cryptographic algorithm. The nice part: hashes and symmetric encryption only lose about half their strength to quantum. Our dear hash algorithm will most probably survive.

But then, as if poor cryptographers did not have enough stress, bad news arrived from a totally different direction. In the last weeks AI models from OpenAI and Anthropic produced hundreds of new math results, including disproofs of conjectures everyone took for granted. Now remember the second danger banks thought they could ignore? Algorithmic shortcuts! Shortcuts that let classical compute, mainly GPUs, get the answer much faster than we initially assumed. And this week Justin Drake, Ethereum Foundation researcher, wrote a long post exactly about this. Not as a future threat, but as a call to calmly start planning now. His worry is that AI finds a shortcut through elliptic curves before any quantum computer does. For now nothing is broken, nobody has shown such a shortcut, and he explicitly says do not rush and do not panic.

But cryptography is now challenged from two directions, quantum and AI, and these are not challengers you can just ignore. They challenge the core of the cryptography business: confidentiality, authenticity and integrity, without which our modern world literally cannot exist.

If you think I am panicking and overblowing things, think about what you used just today without noticing it is cryptography: HTTPS on every site and every click you send, the bank app you used 15 minutes ago, the Wi-Fi password or actually any password, WhatsApp and Signal messages, the VPN to the office, SSH to the server, every Windows and app update (code signing), your password manager, the login token in every web app you build, the encrypted connection to your database, every git commit signature and every Docker image you pull, etc.. As you can see, a long list of almost everything. Take away public-key cryptography and few other cryptographic primitives and all of that stops the same afternoon. Literally.

So, some shake-up in the very foundation of our digital world and our craft is just about to happen. And when you combine it with the progress and challenges in other fields, the only “reasonable” human behavior is to buy a big box of popcorn, sit in the front row and enjoy this epic change unfolding right in front of our eyes.

Top comments (0)