History

Four thousand years of secrets

From an Egyptian scribe's odd hieroglyphs to the post-quantum standards of 2024: the ciphers, the breaks and the people. Filter by chapter to follow one thread.

c. 1900 BC – AD 799

Antiquity

Unusual signs, transposition with a staff, and the shift that carries Caesar's name.

  1. c. 1900 BC

    Unusual hieroglyphs at Menet Khufu

    An Egyptian scribe

    A tomb inscription replaces standard hieroglyphs with rare ones, the oldest known deliberate transformation of writing.

    Read chapter 01 · Classical ciphers →
  2. c. 1500 BC

    A secret glaze recipe

    A Mesopotamian potter

    A clay tablet hides a recipe for pottery glaze by writing words with uncommon cuneiform signs: a trade secret, encrypted.

    Read chapter 01 · Classical ciphers →
  3. c. 500 BC

    The scytale

    Spartan generals

    A strip of leather wound around a staff: a transposition cipher whose key is the staff's thickness.

    Read chapter 01 · Classical ciphers →
  4. c. 50 BC

    Caesar's cipher

    Julius Caesar

    Suetonius records that Caesar replaced each letter by the one three places further on.

    Read chapter 01 · Classical ciphers →

800 – 1499

Baghdad and the Renaissance

Arab scholars invent cryptanalysis; Italian courts answer with many alphabets.

  1. c. 850

    Frequency analysis

    al-Kindi

    In Baghdad, the first written description of cryptanalysis by counting letters. Rediscovered in an Istanbul archive in 1987.

    Read chapter 01 · Classical ciphers →
  2. 1467

    The cipher disk

    Leon Battista Alberti

    Two concentric alphabets that can turn: the first polyalphabetic cipher, and the ancestor of every rotor machine.

    Read chapter 01 · Classical ciphers →

1500 – 1899

Black chambers and indecipherable ciphers

Every European court reads its neighbours' mail; Vigenère resists for three centuries.

  1. 1553

    The keyword cipher

    Giovan Battista Bellaso

    A repeating keyword chooses the shift of each letter. History will credit it to Blaise de Vigenère.

    Read chapter 01 · Classical ciphers →
  2. 1587

    Mary Stuart is executed

    Thomas Phelippes

    Walsingham's cryptanalyst reads Mary's letters to the Babington plotters; the decrypts are the evidence at her trial.

    Read chapter 01 · Classical ciphers →
  3. 1854

    Playfair, and Vigenère broken

    Charles Wheatstone, Charles Babbage

    Wheatstone invents the digraph cipher named after Lord Playfair; Babbage breaks Vigenère but does not publish.

    Read chapter 01 · Classical ciphers →
  4. 1863

    Kasiski's examination

    Friedrich Kasiski

    Distances between repeated fragments reveal the length of a Vigenère key. The indecipherable cipher falls in public.

    Read chapter 01 · Classical ciphers →
  5. 1882

    The first one-time pad

    Frank Miller

    A Californian banker publishes a telegraph code with random additives used once. Forgotten until 2011.

    Read chapter 03 · Perfect secrecy →
  6. 1883

    Kerckhoffs's principle

    Auguste Kerckhoffs

    “La cryptographie militaire”: a cipher must stay secure even if the enemy knows everything about it except the key.

1900 – 1945

Machines and world wars

Radio makes every message public; rotor machines and the people who broke them decide battles.

  1. 1917

    The Zimmermann telegram

    Room 40

    British codebreakers read a German offer of alliance to Mexico; its publication helps bring the United States into the First World War.

  2. 1917

    Vernam's teleprinter cipher

    Gilbert Vernam, Joseph Mauborgne

    Key tape combined bit by bit with the message. Used once and truly random, it becomes the one-time pad.

    Read chapter 03 · Perfect secrecy →
  3. 1918

    Enigma is patented

    Arthur Scherbius

    A rotor machine for businesses; the German navy adopts it in 1926 and the army in 1928.

    Read chapter 02 · Enigma →
  4. 1922

    The index of coincidence

    William Friedman

    Statistics replaces guesswork: the probability that two letters agree measures how polyalphabetic a ciphertext is.

    Read chapter 01 · Classical ciphers →
  5. 1932

    Rejewski breaks Enigma

    Marian Rejewski

    Permutation theory and the doubled message key let the Polish Cipher Bureau reconstruct the rotors and read German traffic.

    Read chapter 02 · Enigma →
  6. 1939

    The Pyry meeting

    Rejewski, Różycki, Zygalski

    Five weeks before the invasion, the Poles give their British and French allies their methods and two Enigma replicas.

    Read chapter 02 · Enigma →
  7. 1940

    The bombe

    Alan Turing, Gordon Welchman

    At Bletchley Park, electromechanical machines test rotor settings against cribs. Ultra intelligence follows.

    Read chapter 02 · Enigma →
  8. 1943

    Venona begins

    US Signal Intelligence Service

    Soviet one-time pads printed twice let American analysts read thousands of messages and expose atomic spies.

    Read chapter 03 · Perfect secrecy →
  9. 1944

    Colossus

    Tommy Flowers, Bill Tutte

    The first programmable electronic digital computer attacks the Lorenz cipher of the German high command.

    Read chapter 02 · Enigma →

1946 – 1975

Information theory and the computer

Shannon turns secrecy into mathematics; IBM brings cryptography to banks; DES is born.

  1. 1949

    Communication Theory of Secrecy Systems

    Claude Shannon

    Perfect secrecy, unicity distance, confusion and diffusion: cryptography becomes a branch of mathematics.

    Read chapter 03 · Perfect secrecy →
  2. 1970

    Non-secret encryption

    James Ellis

    At GCHQ, Ellis shows that public-key encryption is possible in principle. Kept secret until 1997.

    Read chapter 08 · Public-key cryptography →
  3. 1973

    Lucifer and the Feistel network

    Horst Feistel

    IBM's cipher for banks, built from rounds that need not be invertible. Clifford Cocks finds RSA at GCHQ the same year, in secret.

    Read chapter 04 · Block ciphers →

1976 – 2000

The public-key revolution

Keys that can be published, signatures, and the first battles over who may use strong cryptography.

  1. 1976

    New Directions in Cryptography

    Whitfield Diffie, Martin Hellman

    Two strangers agree on a secret in public. Ralph Merkle's puzzles had shown the way.

    Read chapter 08 · Public-key cryptography →
  2. 1977

    DES

    IBM, NBS, NSA

    The first public encryption standard: 64-bit blocks, a 56-bit key and S-boxes hardened against an attack nobody else knew.

    Read chapter 04 · Block ciphers →
  3. 1977

    RSA

    Ron Rivest, Adi Shamir, Leonard Adleman

    A public-key cipher and signature scheme based on the difficulty of factoring. Martin Gardner's column challenges readers to break RSA-129.

    Read chapter 08 · Public-key cryptography →
  4. 1979

    Password hashing with salt

    Robert Morris, Ken Thompson

    Unix stores salted, iterated DES-based hashes of passwords, never the passwords themselves.

    Read chapter 07 · Passwords →
  5. 1979

    Merkle–Damgård

    Ralph Merkle

    Iterating a compression function: the construction of MD5, SHA-1 and SHA-2 (proved secure by Damgård in 1989).

    Read chapter 06 · Hash functions →
  6. 1985

    Elliptic-curve cryptography

    Neal Koblitz, Victor Miller

    The same protocols in the group of points of a curve, with much shorter keys.

    Read chapter 09 · Elliptic curves →
  7. 1990

    Differential cryptanalysis

    Eli Biham, Adi Shamir

    Following differences through the rounds breaks many ciphers, but not DES, whose designers had known it since 1974.

    Read chapter 04 · Block ciphers →
  8. 1991

    PGP

    Phil Zimmermann

    Pretty Good Privacy brings RSA to everyone's e-mail; the US government investigates its author for exporting munitions.

    Read chapter 08 · Public-key cryptography →
  9. 1992

    MD5

    Ron Rivest

    A 128-bit hash that becomes ubiquitous. Collisions are found in 2004.

    Read chapter 06 · Hash functions →
  10. 1993

    Blowfish and linear cryptanalysis

    Bruce Schneier, Mitsuru Matsui

    A free alternative to DES, and a new attack that breaks DES with 2⁴³ known plaintexts.

    Read chapter 04 · Block ciphers →
  11. 1994

    Shor's algorithm

    Peter Shor

    A quantum computer could factor and compute discrete logarithms in polynomial time, breaking RSA and elliptic curves.

    Read chapter 10 · Post-quantum cryptography →
  12. 1996

    HMAC

    Mihir Bellare, Ran Canetti, Hugo Krawczyk

    A keyed hash with a security proof, immune to length extension. Lov Grover finds quantum search the same year.

    Read chapter 06 · Hash functions →
  13. 1998

    Deep Crack

    Electronic Frontier Foundation

    A $250,000 machine finds a DES key in 56 hours: the 56-bit key is officially too short.

    Read chapter 04 · Block ciphers →
  14. 1999

    bcrypt

    Niels Provos, David Mazières

    Blowfish's slow key setup, repeated 2^cost times, becomes OpenBSD's password hash.

    Read chapter 07 · Passwords →

2001 – today

Cryptography everywhere

Open competitions, broken hashes, encrypted-by-default Internet, and the race against quantum computers.

  1. 2001

    AES

    Joan Daemen, Vincent Rijmen

    Rijndael wins NIST's open competition and becomes the Advanced Encryption Standard, FIPS 197.

    Read chapter 04 · Block ciphers →
  2. 2002

    Padding oracles

    Serge Vaudenay

    A server that reveals whether padding is valid lets an attacker decrypt CBC ciphertexts byte by byte.

    Read chapter 05 · Modes of operation →
  3. 2004

    MD5 collisions; GCM

    Xiaoyun Wang; David McGrew, John Viega

    Wang's team finds collisions in MD5 in hours. The same year, Galois/Counter Mode is proposed.

    Read chapter 06 · Hash functions →
  4. 2005

    Learning with errors

    Oded Regev

    A noisy linear-algebra problem as hard as worst-case lattice problems: the basis of ML-KEM and ML-DSA.

    Read chapter 10 · Post-quantum cryptography →
  5. 2006

    Curve25519

    Daniel J. Bernstein

    A curve designed so that the simple, fast implementation is also the safe one. Its key exchange, X25519, becomes the Internet's default.

    Read chapter 09 · Elliptic curves →
  6. 2008

    ChaCha

    Daniel J. Bernstein

    An add-rotate-xor stream cipher, fast and constant-time in software; with Poly1305 it becomes a standard AEAD.

    Read chapter 05 · Modes of operation →
  7. 2009

    scrypt

    Colin Percival

    The first widely used memory-hard password hash. RockYou leaks 32 million plaintext passwords the same year.

    Read chapter 07 · Passwords →
  8. 2010

    Sony's ECDSA nonce

    fail0verflow

    The PlayStation 3 signs with the same nonce every time, which reveals Sony's private key.

    Read chapter 09 · Elliptic curves →
  9. 2011

    Ed25519

    Bernstein, Duif, Lange, Schwabe, Yang

    Deterministic, fast elliptic-curve signatures with no random nonce to get wrong.

    Read chapter 09 · Elliptic curves →
  10. 2013

    Snowden and Dual_EC_DRBG

    Edward Snowden

    Leaked documents confirm an NSA back door in a standardised random number generator and push the web towards encryption by default.

    Read chapter 09 · Elliptic curves →
  11. 2015

    SHA-3 and Argon2

    Keccak team; Biryukov, Dinu, Khovratovich

    The sponge construction becomes FIPS 202; Argon2 wins the Password Hashing Competition.

    Read chapter 06 · Hash functions →
  12. 2016

    NIST's post-quantum competition

    NIST

    82 candidates for replacing RSA and elliptic curves enter eight years of public attack.

    Read chapter 10 · Post-quantum cryptography →
  13. 2017

    SHAttered

    Google, CWI Amsterdam

    Two different PDF files with the same SHA-1, after 9 quintillion SHA-1 computations.

    Read chapter 06 · Hash functions →
  14. 2018

    TLS 1.3

    IETF

    Only authenticated encryption (AES-GCM, ChaCha20-Poly1305) and forward-secret key exchange remain.

    Read chapter 05 · Modes of operation →
  15. 2022

    SIKE broken

    Wouter Castryck, Thomas Decru

    An isogeny-based finalist falls in an hour on a laptop. NIST selects Kyber and Dilithium.

    Read chapter 10 · Post-quantum cryptography →
  16. 2024

    ML-KEM, ML-DSA, SLH-DSA

    NIST

    FIPS 203, 204 and 205: the first post-quantum standards. Browsers, Signal and iMessage already use hybrid key exchange.

    Read chapter 10 · Post-quantum cryptography →
  17. 2025

    Post-quantum by default

    OpenSSH, Cloudflare and others

    OpenSSH 10 makes ML-KEM hybrid key exchange its default; a large share of web traffic is already post-quantum.

    Read chapter 10 · Post-quantum cryptography →