Skip to main content

Back online

Concept Explainer

The Math That Keeps Your Secrets Safe

Every password, bank transaction, and private message relies on one mathematical trick. Learn how it works in plain language.

15:53 listenAudio + TranscriptUpdated Feb 2026
Listen to the Episode
0:000:00

Explore this idea

Think through the math that keeps your secrets safe with AI...

Free account · 30 seconds to start

Want to explore this idea without listening first?

Want a deep dive on a different topic?

Full Transcript

# How Encryption Works

It's 1943. A woman at Bletchley Park is staring at five letters that just came through on an Enigma intercept.

Q-X-P-M-L.

She knows somewhere in those letters... there's a convoy route. A submarine position. Maybe the difference between a thousand soldiers living or dying.

The room smells like ink and cigarette smoke. Typewriters clatter in the background. And she's thinking about wheels.

That's what encryption is, really. Wheels within wheels.

Ways of turning meaning into noise... and then—if you have the right key—back into meaning again.

We've been doing this for four thousand years.

Ancient Egyptians in 1900 BCE were already substituting hieroglyphs in tomb inscriptions. Making sure only certain priests could read certain passages. Not military secrets, just... the human impulse to say "this message is not for everyone."

That impulse never went away.

It's the same instinct that makes you close the bathroom door even when you're home alone. Privacy isn't rational. It's fundamental.

Fast forward to 1467.

Leon Battista Alberti—Renaissance man, literally—invents the cipher disk. It's a beautiful object. Two rotating disks with alphabets on them. Spin the outer disk, and suddenly every A becomes a K. Every B becomes an M.

But here's the clever bit: you can change the alignment mid-message.

So the same letter encrypts differently depending on where you are in the text. He called it polyalphabetic substitution. We'd call it the first systematic encryption tool. The thing that made cryptography a discipline... instead of a party trick.

But all of these early methods share a problem.

If I want to send you a secret message, we both need to know the method ahead of time. We need to meet. Agree on the cipher disk settings. Memorize them.

Which is fine if you're two Renaissance princes.

Less fine if you're trying to coordinate a war effort across continents. Or if you're a dissident who's never met your contact... and the government is reading your mail.

So here's the turn.

In 1917, a guy named Gilbert Vernam working at AT&T invents something called the one-time pad. The concept is almost stupidly simple.

Take your message. Take a completely random key that's as long as the message. Combine them. The result is gibberish.

But if you have that exact key, you can reverse it perfectly.

And mathematically—Claude Shannon proved this in 1949—it's unbreakable. Not "really hard to break." Actually unbreakable... if you use the key only once and keep it secret.

Shannon's proof is one of those rare moments where math says "no further."

Not "we haven't found a way yet." Not "it would take too long." Just... no.

There's no amount of computing power, no clever algorithm, no future breakthrough that can crack a properly used one-time pad. It's like asking if there's a way to make a triangle have four sides. The universe says no.

Which sounds perfect... until you hit the problem: you still need to get that key to the other person securely.

You've just moved the problem around.

Frequently asked questions

How can someone encrypt a message they can't decrypt themselves?
Public key cryptography, invented by Diffie and Hellman in 1976, uses two keys: a public one that locks and a private one that unlocks. Anyone can encrypt a message with your public key, but only your private key opens it.
Why isn't the unbreakable one-time pad used for everything?
Shannon proved in 1949 that a properly used one-time pad can't be broken by any amount of computing power. But you still have to deliver the key securely—the Soviets used couriers with briefcases handcuffed to their wrists, and one capture exposed months of messages.
Will quantum computers break the encryption protecting the internet?
Shor's algorithm, published in 1994, can factor large numbers exponentially faster than classical computers, which could make RSA obsolete—maybe in twenty years. NIST is finalizing post-quantum standards, with finalists like CRYSTALS-Kyber and SPHINCS+.
If encryption is so strong, how do big companies still get hacked?
The weakest link is usually human, not mathematical. Target lost forty million credit card numbers in 2013 because an HVAC contractor's credentials were stolen through a phishing email—the math was perfect, the system was not.
Should encryption algorithms be kept secret from attackers?
No. Auguste Kerckhoffs laid out in 1883 that a system should stay secure even if the enemy knows everything about it except the key. Everyone knows how a pin-tumbler lock works, but your door is still secure without your specific key.
What can I actually do to make encryption work for me?
The transcript suggests two checks: make sure your banking app is up to date, and stop reusing the same password everywhere. Workarounds like passwords on Post-its are "desire paths" that attackers know to look for.
MindCast — Audio learning that helps you think clearly