# How Encryption Works
It's 1943. A woman at Bletchley Park is staring at five letters that just came through on an Enigma intercept.
She knows somewhere in those letters... there's a convoy route. A submarine position. Maybe the difference between a thousand soldiers living or dying.
The room smells like ink and cigarette smoke. Typewriters clatter in the background. And she's thinking about wheels.
That's what encryption is, really. Wheels within wheels.
Ways of turning meaning into noise... and then—if you have the right key—back into meaning again.
We've been doing this for four thousand years.
Ancient Egyptians in 1900 BCE were already substituting hieroglyphs in tomb inscriptions. Making sure only certain priests could read certain passages. Not military secrets, just... the human impulse to say "this message is not for everyone."
That impulse never went away.
It's the same instinct that makes you close the bathroom door even when you're home alone. Privacy isn't rational. It's fundamental.
Fast forward to 1467.
Leon Battista Alberti—Renaissance man, literally—invents the cipher disk. It's a beautiful object. Two rotating disks with alphabets on them. Spin the outer disk, and suddenly every A becomes a K. Every B becomes an M.
But here's the clever bit: you can change the alignment mid-message.
So the same letter encrypts differently depending on where you are in the text. He called it polyalphabetic substitution. We'd call it the first systematic encryption tool. The thing that made cryptography a discipline... instead of a party trick.
But all of these early methods share a problem.
If I want to send you a secret message, we both need to know the method ahead of time. We need to meet. Agree on the cipher disk settings. Memorize them.
Which is fine if you're two Renaissance princes.
Less fine if you're trying to coordinate a war effort across continents. Or if you're a dissident who's never met your contact... and the government is reading your mail.
So here's the turn.
In 1917, a guy named Gilbert Vernam working at AT&T invents something called the one-time pad. The concept is almost stupidly simple.
Take your message. Take a completely random key that's as long as the message. Combine them. The result is gibberish.
But if you have that exact key, you can reverse it perfectly.
And mathematically—Claude Shannon proved this in 1949—it's unbreakable. Not "really hard to break." Actually unbreakable... if you use the key only once and keep it secret.
Shannon's proof is one of those rare moments where math says "no further."
Not "we haven't found a way yet." Not "it would take too long." Just... no.
There's no amount of computing power, no clever algorithm, no future breakthrough that can crack a properly used one-time pad. It's like asking if there's a way to make a triangle have four sides. The universe says no.
Which sounds perfect... until you hit the problem: you still need to get that key to the other person securely.
You've just moved the problem around.
It's like having the world's best lock on a door, but you have to hand-deliver the key. The Soviets used one-time pads for their most sensitive communications during the Cold War. They'd send couriers with briefcases handcuffed to their wrists, carrying books of random numbers.
One compromise. One captured briefcase. And months of messages became readable.
This is the thing that haunted cryptographers for decades.
How do you share a secret... over a channel that everyone can see?
And this is where it gets strange.
In 1976, two guys at Stanford—Whitfield Diffie and Martin Hellman—had an idea that sounded like it violated common sense.
What if you could have two keys? One that locks. One that unlocks. And what if the locking key could be completely public?
Think about it.
I publish my "public key" in a phone book. You use it to encrypt a message to me. But only my private key—which I never share—can decrypt it.
You can't decrypt it... even though you encrypted it.
Anyone can lock the box. But only I can open it.
When Diffie and Hellman first presented this at a conference, cryptographers literally stood up and said it was impossible. Not impractical. Impossible.
Because for two thousand years, every encryption system in human history had worked the same way: the thing that locks must be the thing that unlocks. Symmetric. A key that opens a door also locks it.
To suggest otherwise felt like claiming you could build a staircase that only goes up.
The math behind this is based on trapdoor functions. Problems that are easy in one direction... and brutally hard in reverse.
Like multiplying two large prime numbers—easy. But taking the result and figuring out which primes made it? That'll take you longer than the universe has existed, if the numbers are big enough.
If you're trying to factor a number that's two thousand digits long using current technology, you're looking at more time than has elapsed since the Big Bang. Every atom in your body will have decayed. The sun will have burned out. And you'll be at point-zero-zero-zero-zero-one percent progress.
A year later, three researchers—Rivest, Shamir, and Adleman—turned this into something you could actually use. RSA encryption.
The story goes they came up with the idea at a Passover Seder. Rivest couldn't sleep. Went home. And by morning had the algorithm written out.
It's what makes secure websites possible. Every time you see that little padlock in your browser, RSA or its descendants are working.
But let's go back to that room at Bletchley Park, because there's a parallel story happening.
The Enigma machine the Germans were using wasn't theoretically unbreakable. It was just really, really hard. It used rotating wheels—those wheels again—to scramble messages. Three wheels, each with twenty-six positions, and the positions changed with every keystroke. The number of possible settings was in the billions.
Alan Turing and his team didn't break it with math alone. They broke it with a combination of math, engineering, psychology... and captured codebooks.
They built machines—actual physical computing machines called "bombes"—to test possibilities faster than humans could. Each bombe was the size of a room. Sounded like a thousand knitting needles clicking at once. And could test thousands of wheel positions per hour.
And they exploited human error.
German operators would sometimes use girlfriend's names as keys. Or they'd start messages the same way every time. "Nothing to report" encrypted the same way every morning... is a gift to a codebreaker.
When they cracked it, when they could read German naval communications... it changed the war. Eisenhower said the intelligence from Bletchley shortened the war by at least two years.
That's not an abstract victory. That's millions of lives.
And here's the thing that haunts me: they couldn't use every piece of intelligence they got. If they acted on every decoded message, the Germans would realize Enigma was broken and change systems.
So sometimes they had to let convoys get attacked. They had to choose which secrets to act on... and which soldiers to save.
Encryption didn't just change the math of war. It changed the moral calculus.
Turing understood something most people miss.
A cryptosystem's strength isn't just about the algorithm. It's about the whole system—the people, the procedures, the physical security of the keys.
A principle that Auguste Kerckhoffs laid out back in 1883: your system should be secure even if the enemy knows everything about it except the key.
Which seems backwards until you think about locks. Everyone knows how a pin-tumbler lock works. You can watch YouTube videos about it. But your front door is still secure... because they don't have your specific key.
Which brings us to 1991.
A guy named Phil Zimmermann sitting in his home office, about to do something that'll make the US government very, very angry.
He's written software called Pretty Good Privacy—PGP—that brings military-grade encryption to regular people. Email encryption. File encryption. All of it using public key cryptography. And he's about to release it for free on the internet.
The government tried to prosecute him. Exporting encryption was legally considered the same as exporting weapons.
Zimmermann's defense was brilliant. He published the source code as a book. Actual printed pages with code on them. Because books are protected by the First Amendment. You can't ban the export of books.
He literally weaponized the fact that software is speech.
The case eventually collapsed, but not before Zimmermann spent years under investigation, watching his savings drain into legal fees.
Whitfield Diffie said it plainly: "The ability to communicate securely is fundamental to a free society."
Zimmermann bet his life on that being true.
That tension never went away. It just got more intense.
Today, over ninety percent of internet traffic is encrypted using something called TLS—Transport Layer Security.
When you log into your bank, buy something online, send a message... it's encrypted. Two-hundred-fifty-six-bit encryption. Which means there are two to the power of two-fifty-six possible keys.
That's more combinations than there are atoms in the observable universe. Not metaphorically. Literally.
The fastest supercomputer on Earth would take billions of years to crack it by trying every possibility. We've built a system where your embarrassing text to your ex is protected by math that would take longer than the age of the universe to break.
But here's the thing that keeps security researchers up at night: quantum computers.
Regular computers think in bits—ones and zeros. Quantum computers think in qubits, which can be both at once.
And certain quantum algorithms—specifically one called Shor's algorithm, published in 1994—can factor large numbers exponentially faster than classical computers.
Which means RSA encryption, the thing protecting most of the internet right now... could become obsolete.
Not tomorrow. Maybe not for twenty years. But it's coming.
And so right now, NIST—the National Institute of Standards and Technology—is finalizing new encryption standards designed to resist quantum attacks. Post-quantum cryptography.
They ran a competition. Cryptographers from around the world submitted algorithms. Some had names like CRYSTALS-Kyber and SPHINCS+. Others broke under analysis. The finalists are being tested against every attack vector anyone can imagine.
The race is on to upgrade the world's security infrastructure before quantum computers are powerful enough to threaten it.
And here's the weird part: some intelligence agencies are already recording encrypted traffic now, betting they'll be able to decrypt it in twenty years when quantum computers exist.
Your secrets today... might not be secret in 2045.
Meanwhile, there's this development called homomorphic encryption that sounds like science fiction.
Imagine you could send your data to a cloud service, have them perform calculations on it, and get results back—all without them ever being able to see what the data actually is. They're computing on encrypted data.
It sounds impossible, but it works. IBM has a working implementation.
You could send your genome to a research lab, have them analyze it for disease markers, and get results—without them ever knowing whose genome it is or what it contains. They're doing math on numbers they can't see.
It's like asking someone to bake you a cake... but they're blindfolded and can't taste any of the ingredients. And somehow the cake still comes out perfect.
And then there's quantum key distribution. Instead of relying on math problems being hard, it relies on the laws of physics.
You send cryptographic keys encoded in photons. If anyone tries to intercept them, the quantum state collapses, and you know you've been compromised.
China launched a satellite in 2016 called Micius that can do quantum key distribution from space. They've had secure video calls between Beijing and Vienna where the security isn't based on math being hard—it's based on the Heisenberg uncertainty principle.
You can't observe a quantum state without changing it. Physics itself becomes the lock.
The thing is, encryption is only as strong as its weakest link. And often that link is human.
People reuse passwords. Companies misconfigure their security certificates. Someone writes down a key on a sticky note.
In 2013, Target got hacked because an HVAC contractor's credentials were stolen. The math was perfect. The system was not. Forty million credit card numbers compromised... because someone in the heating and cooling department clicked a phishing email.
There's a concept in architecture called "desire paths." You know those worn trails across grass where the sidewalk doesn't quite go where people want to walk? Those are desire paths. They show where the design failed to match human behavior.
Security systems have desire paths too.
Every workaround. Every password written on a Post-it. Every time someone clicks "remind me later" on a software update—those are desire paths. They're showing you where the security is too hard, too slow, too annoying to be sustainable.
And attackers know to look for those paths.
So here's what you can do with this.
Next time you send a message, buy something online, log into anything—pause for half a second and think about the fact that there are wheels spinning invisibly. Mathematical wheels that Alberti would recognize. That Turing would appreciate. That are keeping your secrets secret from everyone on Earth... except the person you're sending them to.
You're carrying cryptographic power in your pocket that would have made you the most dangerous person alive in 1943. The Bletchley Park codebreakers would kill for the computational power in your phone.
And maybe ask yourself: what's one thing I'm trusting to encryption that I should actually check?
Is my banking app up to date? Am I reusing the same password everywhere?
Because the beautiful math only works if we do our part. The locks are extraordinary. But we still have to remember to use them.
And here's the thing nobody tells you: every time you use encryption, you're making a political statement.
You're saying that there are parts of your life that don't belong to corporations, to governments, to anyone but you. That privacy isn't about having something to hide. It's about having something to protect.
Your thoughts. Your relationships. The space where you're allowed to be wrong, confused, uncertain... human.
The woman at Bletchley Park staring at Q-X-P-M-L understood that.
She was fighting for the right to have secrets.
We still are.