Not That Secure after All: Cryptography in a Connected World

Join Our Community of Science Lovers!

This article was published in Scientific American’s former blog network and reflects the views of the author, not necessarily those of Scientific American


You're not going to like hearing this: The arsenal of mental and physical resources out there right now could easily bring down our cyber-security system, which protects the trivial, such as e-mails, to the critical, think banking system. The only reason it hasn't happened yet: the intent hasn't been there.

It was on this quite grave note that the session, "Keeping Secrets: Cryptography in a Connected World," ended June 4 at the World Science Festival. But the lively panelists, often in disagreement with one another, seemed to be unanimously content with this assertion. It was raised first by Brian Snow, who previously worked at the National Security Agency, creating and managing their Secure Systems Design division. In other words, he would know.


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


The problem isn't so much encryption, which are mainly algorithms and extremely laborious math problems that act as padlocks to protect data. There are of course some difficulties: it is hard to build a system that will be secure in the future, as programmers must try to project how smart and resourceful future mathematicians and hackers might be.

The main problem is what Snow and fellow panelist Orr Dunkelman, a cryptanalysist (i.e. breaking ciphers and then analyzing them to see how secure they are), call the human factor. That is, to paraphrase Dunkelman, the problem with ciphers designed to enforce cybersecurity is not in the algorithms or encryption systems necessarily, but in their implementation by humans—we are the erratic and unpredictable flaw in most cybersecurity systems. An example came from journalist and BBC Science producer Simon Singh: when he wrote his book on the history of encryption, he included a handful of mathematical encryption puzzles for readers to break; the last one, which should have been the hardest puzzle, was in fact ridiculously easy because when Singh wrote it, he used the wrong cipher. Human factor.

But maybe that's just fine. Tal Rabin, a researcher in cryptography at I.B.M., made the point that maybe we don't want to be overly secure. Why would she want the same level of cybersecurity for her emails as with our nuclear system? People don't want overly secure systems for everything; it would come with too high a personal and monetary cost. And some people just don't care. Rabin and Dunkelman seemed to be fine with this, but Snow was visibly irked by this type of cognitive dissonance—the carelessness or inability of people to understand cybersecurity and how it works (or doesn't).

Snow's only comfort seemed to be that in the military, systems that are built and always tested and retested, to ensure that the cryptography used in the field is a trustworthy padlock. In commercial sectors, time and money are scarce, so what you get is by no means quite as secure. For instance, the new key fobs that automatically open the doors on new cars. These keys rely on a radio transmission between the key and the car; but it's not a secure transmission—in fact Snow shared with us one way of getting around this and getting into any car that opens with a key fob.

We have come quite a long way from from the 1940s and 50s when math was first used by cryptographers as a way to hide information. But the leaps made still don't completely protect our information, ranging from Facebook pages to government and military communications. Should we trust the security of cloud computing? Will online voting ever be a secure option? These questions lingered at the end of Saturday's session.

Image credit: Pacific Northwest National Laboratory

Subscribe to Support Independent Journalism

Great science journalism requires human expertise, time, effort and creativity. And it costs money. That’s why I and the journalists here at Scientific American hope you’ll join our community.

When you subscribe, you are supporting staff and freelance journalists who are passionate about telling science stories that are true, important and compelling. Our editors and reporters are often experts in their fields, which means they understand the nuances of big discoveries and can untangle the breakthroughs from the hype. With a subscription, you are also supporting rigorous fact-checking to ensure the words we publish are precise and accurate. And you’re supporting original illustrations, graphics and photos that bring you closer to an advanced laboratory, an ice sheet in Antarctica or a space mission in orbit. You’re helping us craft other types of high-quality journalism as well: Our newsletters are carefully written, edited and curated by staffers you have or will come to know and love. Our Science Quickly podcast is based on original reporting, collaboration with editors and scientists and exacting production.

Subscriptions keep this engine running so we can continue to deliver thoughtful, rigorous and independent science journalism to you. In an era of viral misinformation, this work is crucial. If you value what we do, I hope you’ll consider joining us as a subscriber

Thank you,

Jeanna Bryner, Editor in Chief, Scientific American

Subscribe