The Hidden Locks of the Internet: Everyday Cryptography

The Hidden Locks of the Internet: Everyday Cryptography

Every time we unlock a phone, refresh a bank balance, or send a private message, an invisible lock clicks shut somewhere on the internet. That lock is not made of metal; it is made of mathematics. We rarely see it, yet it stands between our money and thieves, our conversations and eavesdroppers, our records and forgers.

Cryptography is the science and engineering of these hidden locks. It turns readable information into scrambled data that looks like nonsense to anyone who does not hold the right key. It also lets us prove who wrote a message, detect if something has been tampered with, and agree on secrets with people we have never met.

Understanding cryptography does not require a math degree. At its core, it is about clever ways to use big numbers, randomness, and one-way processes so that some actions are easy to do but practically impossible to undo. Those ideas have stayed remarkably stable, even as individual apps and technologies have come and gone.

Grasping these principles gives us a clearer sense of what really keeps digital life private and trustworthy—and where its limits lie.

Locks, Secrets, and the Language of Numbers

Traditional locks and keys work because:
  • Locks are easy to close with a key.
  • Locks are very hard to open without the matching key.

Cryptographic systems aim for the same pattern:
  • Scrambling information (encrypting) is easy with a key.
  • Unscrambling it (decrypting) is easy with the right key.
  • Unscrambling it without that key should be so difficult that, even with all the computers in the world, it would take longer than the age of the universe.

To reach that gap between “easy” and “effectively impossible,” cryptography leans on:
  • Very large numbers, typically hundreds or thousands of bits long.
  • Mathematical problems that are easy in one direction and extremely hard in the reverse.
  • Careful randomness to avoid patterns an attacker could exploit.

The remarkable part is that the underlying math is public. Anyone can read how the locks work. Security comes not from secrecy of the design, but from the sheer difficulty of breaking the math without the keys.

A Short History of Modern Cryptography

People have hidden messages for thousands of years.
  • Ancient ciphers, like shifting letters in the alphabet, relied on simple patterns.
  • For centuries, spies and generals used hand ciphers and codebooks that could be broken with enough patience.

The 20th century brought a turning point:
  • During World War II, machines like the German Enigma were used to automate complex ciphers.
  • Allied efforts to break Enigma and other codes spurred the development of early computers and formal methods for analyzing ciphers.

After the war, governments treated strong cryptography as a strategic secret and often tried to control its use. Over time, several big shifts opened it up:
  • In the 1970s, researchers developed the Data Encryption Standard (DES), a widely used public cipher.
  • Around the same period, the concept of public-key cryptography emerged, starting a revolution.
  • Academic and private-sector cryptographers began publishing open algorithms and proofs, turning cryptography into a mature scientific field.

Today, the building blocks that protect national secrets also protect routine web browsing and everyday conversations. The same ideas scale from a family group chat to a diplomatic cable.

Symmetric Keys: The Oldest Kind of Secret Lock

The most basic form of encryption is symmetric-key cryptography.
  • The same secret key is used to lock (encrypt) and unlock (decrypt).
  • Anyone with the key can both read and change the protected data.

It is like a shared safe combination: if two people both know the combination, either can open the safe.

Symmetric ciphers turn readable text into scrambled data using a combination of substitution, permutation, and other operations tied to the secret key. Modern symmetric algorithms, such as widely adopted block ciphers, are designed so that:
  • Without the key, trying every possible key (brute force) would be hopelessly slow.
  • No shortcut is known that would be faster than trying an enormous number of keys.

Symmetric encryption is extremely fast, which makes it ideal for:
  • Encrypting large files.
  • Protecting data stored on devices.
  • Securing most of the actual content flowing over secure web connections.

There is one big challenge: how do two people who have never met agree on a shared secret key in the first place, especially over an insecure network?

That question leads directly to public-key cryptography.

Public-Key Cryptography: Sharing Locks in Public

Public-key cryptography, also called asymmetric cryptography, was a breakthrough idea.

Instead of one key shared by both sides, each person has a pair of keys:
  • A public key that can be shared with anyone.
  • A private key that is kept secret.

The keys are mathematically linked. The system is designed so that:
  • Data encrypted with a public key can only be decrypted with the matching private key.
  • Data encrypted with the private key can be checked with the public key, proving that it came from the private key holder.

This enables a few powerful abilities.

Secure communication with strangers

If we have someone’s public key, we can:
  • Encrypt a message with their public key.
  • Send the encrypted message over any channel (even if it is being monitored).
  • Only the person with the matching private key can decrypt and read it.

This solves the “key exchange” problem: we can set up a shared secret with someone without needing a secret channel ahead of time.

Authenticity and signatures

Because the keys are linked in one direction, if something fits a person’s public key in the right way, we can be confident it came from their private key. This is the basis for digital signatures, used to verify software updates, legal agreements, and more.

Public-key operations are slower than symmetric encryption, so secure systems typically:
  • Use public-key cryptography to set up a shared symmetric key.
  • Then use that symmetric key for the bulk of the communication.

This blended approach combines the convenience of public keys with the speed of symmetric ciphers.

Why Prime Numbers Matter So Much

Many public-key systems rely on properties of prime numbers—numbers greater than 1 that have no divisors other than 1 and themselves (such as 2, 3, 5, 7, 11, and so on).

One widely used public-key method is built around a simple-to-state idea:
  • It is easy to multiply two large prime numbers together.
  • It is extremely hard to start from the product and figure out which primes were multiplied.

For example, multiplying two 300-digit primes is straightforward for a computer. But finding those two primes from the resulting 600-digit number appears to require an amount of work that grows explosively with the number of digits.

This imbalance is exactly what cryptographers want:
  • People generating keys pick large random primes and multiply them.
  • The product, along with some additional values, becomes part of the public key.
  • The original primes are kept private and form part of the private key.
  • Anyone can see the public key, but no one is expected to realistically recover the primes from it.

Other public-key systems use related “hard” problems, such as the difficulty of certain equations on elliptic curves. The common thread is the same: one direction is easy; the reverse direction is believed to be infeasible with any non-quantum computer.

Digital Signatures: Proving Who Wrote What

Digital signatures are the cryptographic analog of handwritten signatures, but with stronger guarantees.

A basic digital signature scheme works in three steps.
  1. Key generation
    • A signer generates a pair of keys: one public, one private.
    • The public key can be widely shared; the private key must be protected.
  2. Signing
    • To sign a message, the signer runs a signing algorithm that uses:
      • The message (or, more commonly, a hash of the message).
      • The private key.
    • The result is a signature: a short string of data.
  3. Verification
    • Anyone with the public key can run a verification algorithm that checks:
      • The message.
      • The signature.
      • The public key.
    • If the check passes, the verifier knows:
      • The signature could only have been created by someone with the private key.
      • The message has not been changed since it was signed.


Three main properties make digital signatures valuable:
  • Authenticity: The signer is who they claim to be, assuming the private key is truly theirs.
  • Integrity: If any bit of the signed message changes, the signature check fails.
  • Non-repudiation (with context): Once a signature is attached and verified, it becomes hard for the signer to plausibly deny creating it.

Digital signatures underpin:
  • Software and operating system updates.
  • Secure connections to websites (certificates).
  • Electronic contracts and legal agreements.
  • Package managers and app stores.

When a phone, computer, or browser warns that software or a website certificate is not trusted, it is usually because a signature is missing, invalid, or tied to an unrecognized key.

Hash Functions: Digital Fingerprints for Data

Cryptographic hash functions are tools that turn data of any length into fixed-size “fingerprints.”

Given any input, a cryptographic hash function:
  • Produces a fixed-size output (for example, 256 bits).
  • Always produces the same output for the same input.
  • Produces outputs that appear random and unrelated for different inputs.

To be considered secure, a hash function must make certain tasks effectively impossible:
  • Given an output, finding any input that produces that output (preimage resistance).
  • Given one input, finding a different input with the same output (second-preimage resistance).
  • Finding any two different inputs that produce the same output (collision resistance).

Because the outputs are fixed-length, there must mathematically be many different inputs that yield the same hash. The security comes from making it computationally impractical to find any of those collisions on purpose.

Hash functions are used in many crucial ways:
  • Storing passwords securely (by hashing them and storing the hash, not the password itself).
  • Checking file integrity: if a downloaded file’s hash matches a trusted value, it almost certainly has not been altered.
  • Forming the backbone of many digital signature schemes (signing the hash of a message, not the full message).
  • Building more complex cryptographic constructions like message authentication codes and commitment schemes.

Thinking of hashes as digital fingerprints is helpful: they are short, unique-looking summaries that let us tell if something has changed, even if we never see the content directly.

How Cryptography Protects Daily Life

Cryptography is woven into daily routines in ways that are easy to overlook.

Web browsing and HTTPS

When a browser connects to a website with “https” in the address bar and shows a lock icon:
  • The browser and the server perform a key agreement using public-key cryptography.
  • They agree on a shared symmetric key known only to them.
  • All data exchanged (pages, login forms, cookies) is encrypted with that symmetric key.

Certificates issued by trusted authorities, along with digital signatures, help the browser verify that it is talking to the genuine website, not an imposter.

Messaging apps and end-to-end encryption

Many messaging platforms use end-to-end encryption:
  • Each device has its own set of cryptographic keys.
  • Messages are encrypted in a way that only the sender’s and recipient’s devices can decrypt.
  • The service provider sees only encrypted data, not the content.

Under the hood, this typically combines:
  • Public-key cryptography to establish shared secrets between devices.
  • Symmetric encryption for the message content.
  • Hash functions and additional techniques to authenticate messages and prevent tampering.

Online banking and payments

When we log into a bank account or send money online, cryptography plays several roles:
  • HTTPS protects the session between device and bank servers.
  • Strong authentication methods (such as one-time codes or security keys) reduce the risk of account takeover.
  • Digital signatures and cryptographic checks help verify that transaction requests are authentic and unaltered.

The goal is to make it drastically easier for a legitimate customer to access their accounts than for an attacker to impersonate them.

Software updates and app stores

Operating systems and app stores rely heavily on cryptography to keep updates safe:
  • Developers sign application packages with private keys.
  • Devices store corresponding public keys or certificates.
  • Before installing or updating software, the device verifies the signature.

If an attacker tries to slip in modified software, the signature check fails, and the device can refuse to install it or warn the user.

Data at rest: phones, laptops, and backups

Full-disk encryption and encrypted backups protect data if a device is lost or stolen:
  • A symmetric key encrypts the data stored on the device or in the backup.
  • That key is often derived from a password, passphrase, or hardware module in the device.
  • Without the key, the raw storage looks like random data.

This type of protection limits damage when physical security fails.

Limits of Cryptography: What It Cannot Do

Cryptography is powerful, but it is not magic. Several important limits often get overlooked.
  • It cannot protect data that is already exposed. If a device is infected with malware that records keystrokes or screenshots, encryption of the network traffic will not keep that captured information safe.
  • It does not solve bad passwords. If we use weak or reused passwords, an attacker may simply log in as us, bypassing the need to break the underlying cryptography.
  • It cannot guarantee honest behavior. Digital signatures and certificates can verify identities and integrity, but they cannot ensure that the person or organization behind a key behaves ethically.
  • It can be undermined by poor implementation. Even strong algorithms can be weakened by programming mistakes, side-channel leaks (like timing measurements), or insecure random number generators.
  • It often cannot hide metadata. Even when content is encrypted, outside observers may still infer who is talking to whom, how often, and when.

Recognizing these boundaries helps us appreciate what cryptography does well and where other safeguards—like secure software design, legal protections, and personal security habits—must fill in.

The Coming Challenge of Quantum Computers

Most widely deployed public-key systems today rely on problems such as:
  • Factoring large numbers into primes.
  • Solving certain types of discrete logarithm problems, including on elliptic curves.

Quantum computing introduces a new wrinkle. A quantum algorithm known as Shor’s algorithm, if run on a sufficiently powerful quantum computer, could solve these problems efficiently. That would undermine:
  • Many popular public-key encryption schemes.
  • Most widely used digital signature systems based on these problems.

Symmetric encryption and hash functions are affected differently:
  • A quantum algorithm called Grover’s algorithm could speed up brute-force searches.
  • This does not completely break symmetric systems, but it effectively reduces their security level.
  • Using longer keys and larger hash outputs can compensate for this effect.

Researchers are actively developing “post-quantum” cryptography:
  • New public-key schemes based on problems believed to resist quantum attacks, such as lattice-based or code-based problems.
  • Standardization efforts to identify and vet candidates for broad use.
  • Transition plans so that protocols and software can eventually move to quantum-resistant options.

One subtle but important issue is “harvest now, decrypt later”:
  • Encrypted communications recorded today might be stored by an adversary.
  • If that adversary gains access to a powerful quantum computer in the future, they could try to decrypt those recordings.
  • Highly sensitive data that must remain secret for many years may need protection with quantum-resistant methods sooner rather than later.

The core ideas of one-way functions, key separation, and strong randomness remain relevant in a post-quantum world, even if some specific algorithms must change.

How We Can Stay Safe in a Cryptographic World

Most of us will never design cryptographic algorithms, but understanding the basics lets us make smarter choices.

Here are practical ways to benefit from the locks we already have:
  • Prefer end-to-end encrypted options when privacy matters. For messaging, choose platforms that clearly document how keys are handled and whether even the provider can read content.
  • Watch for HTTPS and certificate warnings. If a browser warns that a connection is not secure or a certificate is invalid, take it seriously—especially on login or payment pages.
  • Use strong, unique passwords and a password manager. Cryptography can only do so much if passwords are weak or reused across sites.
  • Enable two-factor authentication. This adds an extra layer beyond passwords, often using cryptographic techniques such as one-time codes or physical security keys.
  • Keep devices and software up to date. Many updates patch security flaws that could otherwise allow attackers to bypass cryptographic protections.
  • Encrypt devices and backups. Turn on full-disk encryption on phones and computers, and ensure backups are encrypted as well.
  • Be cautious with public Wi‑Fi. Even with HTTPS, misconfigured apps or legacy sites can leak information. A reputable virtual private network (VPN) can add an extra layer of encryption in some situations, though it does not replace other protections.

Fundamentally, cryptography is a tool. Its strength in practice depends on how it is used, implemented, and combined with other security measures.

Key Terms at a Glance

  • Plaintext: Original, readable information before encryption.
  • Ciphertext: Scrambled output produced by encryption, unintelligible without the key.
  • Key: A piece of information (often a long number) that controls the behavior of a cryptographic algorithm.
  • Symmetric key: A key used for both encryption and decryption in the same scheme.
  • Public key: The part of a key pair that can be shared openly and is used for encryption or signature verification.
  • Private key: The secret part of a key pair, used for decryption or signing; must be protected.
  • Encryption: The process of turning plaintext into ciphertext using a key.
  • Decryption: The process of turning ciphertext back into plaintext with the appropriate key.
  • Digital signature: A cryptographic value that proves a message was created by a specific private key holder and has not been altered.
  • Hash function: A function that turns data into a fixed-size output in a way that is easy to compute but hard to reverse or collide.
  • Certificate: A digitally signed document that binds a public key to an identity (such as a website or organization).
  • Key exchange: A technique that allows parties to agree on a shared secret key over an insecure channel.
  • End-to-end encryption: An arrangement in which only the communicating devices can decrypt messages, excluding even the service provider.
  • Post-quantum cryptography: Cryptographic algorithms designed to remain secure even if large-scale quantum computers become available.

Modern life runs on countless silent agreements between those who send, receive, and store information. Cryptography provides the language for those agreements, encoded in numbers too large for any of us to fathom yet reliable enough to trust every day. Understanding the locks does not just satisfy curiosity; it helps us make better choices about where and how we place that trust.

Comments:

Comments are currently disabled.

About

Altus BlogAltus Blog delivers expert analysis and deep dives on the world's most compelling subjects.

Categories

Follow