A cypherpunk is any activist advocating widespread use of strong cryptography and privacy-enhancing technologies as a route to social and political change. Originally communicating through the Cypherpunks mailing list, informal groups aimed to achieve privacy and security through proactive use of cryptography. Cypherpunks have been engaged in an active movement since the late 1980s. The cypherpunks were the first to discuss the possibilities of cryptocurrencies.
- 1 History
- 2 Main principles
- 3 Activities
- 4 Noteworthy cypherpunks
- 5 References
- 6 Further reading
- 7 External links
Before the mailing list
Until about the 1970s, cryptography was mainly practiced in secret by military or spy agencies. However, that changed when two publications brought it out of the closet into public awareness: the US government publication of the Data Encryption Standard (DES), a block cipher which became very widely used; and the first publicly available work on public-key cryptography, by Whitfield Diffie and Martin Hellman.
The technical roots of Cypherpunk ideas have been traced back to work by cryptographer David Chaum on topics such as anonymous digital cash and pseudonymous reputation systems, described in his paper "Security without Identification: Transaction Systems to Make Big Brother Obsolete" (1985).
In the late 1980s, these ideas coalesced into something like a movement.
Origin of the term, and the Cypherpunks mailing list
Main article Cypherpunks mailing list
In late 1992, Eric Hughes, Timothy C. May and John Gilmore founded a small group that met monthly at Gilmore's company Cygnus Solutions in the San Francisco Bay Area, and was humorously termed cypherpunks by Jude Milhon at one of the first meetings - derived from cipher and cyberpunk. In November 2006, the word was added to the Oxford English Dictionary.
The Cypherpunks mailing list was started in 1992, and by 1994 had 700 subscribers. At its peak, it was a very active forum with technical discussion ranging over mathematics, cryptography, computer science, political and philosophical discussion, personal arguments and attacks, etc., with some spam thrown in. An email from John Gilmore reports an average of 30 messages a day from December 1, 1996 to March 1, 1999, and suggests that the number was probably higher earlier. The number of subscribers is estimated to have reached 2000 in the year 1997.
The basic ideas can be found in A Cypherpunk's Manifesto (Eric Hughes, 1993): "Privacy is necessary for an open society in the electronic age. ... We cannot expect governments, corporations, or other large, faceless organizations to grant us privacy ... We must defend our own privacy if we expect to have any. ... Cypherpunks write code. We know that someone has to write software to defend privacy, and ... we're going to write it."
Some are or were quite senior people at major hi-tech companies and others are well-known researchers (see list with affiliations below).
The people in this room hope for a world where an individual's informational footprints -- everything from an opinion on abortion to the medical record of an actual abortion -- can be traced only if the individual involved chooses to reveal them; a world where coherent messages shoot around the globe by network and microwave, but intruders and feds trying to pluck them out of the vapor find only gibberish; a world where the tools of prying are transformed into the instruments of privacy.
There is only one way this vision will materialize, and that is by widespread use of cryptography. Is this technologically possible? Definitely. The obstacles are political -- some of the most powerful forces in government are devoted to the control of these tools. In short, there is a war going on between those who would liberate crypto and those who would suppress it. The seemingly innocuous bunch strewn around this conference room represents the vanguard of the pro-crypto forces. Though the battleground seems remote, the stakes are not: The outcome of this struggle may determine the amount of freedom our society will grant us in the 21st century. To the Cypherpunks, freedom is an issue worth some risk.
Later, Levy wrote a book, Crypto: How the Code Rebels Beat the Government – Saving Privacy in the Digital Age, covering the crypto wars of the 1990s in detail. "Code Rebels" in the title is almost synonymous with cypherpunks.
The term cypherpunk is mildly ambiguous. In most contexts it means anyone advocating cryptography as a tool for social change, social impact and expression. However, it can also be used to mean a participant in the Cypherpunks electronic mailing list described below. The two meanings obviously overlap, but they are by no means synonymous.
Privacy of communications
A very basic cypherpunk issue is privacy in communications and data retention. John Gilmore said he wanted "a guarantee -- with physics and mathematics, not with laws -- that we can give ourselves real privacy of personal communications."
Such guarantees require strong cryptography, so cypherpunks are fundamentally opposed to government policies attempting to control the usage or export of cryptography, which remained an issue throughout the late 1990s. The Cypherpunk Manifesto stated "Cypherpunks deplore regulations on cryptography, for encryption is fundamentally a private act."
This was a central issue for many cypherpunks. Most were passionately opposed to various government attempts to limit cryptography — export laws, promotion of limited key length ciphers, and especially escrowed encryption.
Anonymity and pseudonyms
Arguably, the possibility of anonymous speech and publication is vital for an open society, an essential requirement for genuine freedom of speech — this was the position of most cypherpunks. A frequently cited example was that the Federalist Papers were originally published under a pseudonym.
Censorship and monitoring
Questions of censorship and government or police monitoring were also much discussed. Generally, cypherpunks opposed both.
In particular, the US government's Clipper chip scheme for escrowed encryption of telephone conversations (encryption secure against most attackers, but breakable at need by government) was seen as anathema by many on the list. This was an issue that provoked strong opposition and brought many new recruits to the cypherpunk ranks. List participant Matt Blaze found a serious flaw in the scheme, helping to hasten its demise.
Steven Schear createdTemplate:When the warrant canary to thwart the secrecy provisions of court orders and national security letters. Template:Asof, warrant canaries are gaining commercial acceptance.
Hiding the act of hiding
An important set of discussions concerns the use of cryptography in the presence of oppressive authorities. As a result, Cypherpunks have discussed and improved steganographic methods that hide the use of crypto itself, or that allow interrogators to believe that they have forcibly extracted hidden information from a subject. For instance, Rubberhose was a tool that partitioned and intermixed secret data on a drive with fake secret data, each of which accessed via a different password. Interrogators, having extracted a password, are led to believe that they have indeed unlocked the desired secrets, whereas in reality the actual data is still hidden. In other words, even its presence is hidden. Likewise, cypherpunks have also discussed under what conditions encryption may be used without being noticed by network monitoring systems installed by oppressive regimes.
As the Manifesto says, "Cypherpunks write code"; the notion that good ideas need to be implemented, not just discussed, is very much part of the culture of the mailing list. John Gilmore, whose site hosted the original cypherpunks mailing list, wrote: "We are literally in a race between our ability to build and deploy technology, and their ability to build and deploy laws and treaties. Neither side is likely to back down or wise up until it has definitively lost the race."
Anonymous remailers such as the Mixmaster Remailer were almost entirely a cypherpunk development. Among the other projects they have been involved in were PGP for email privacy, FreeS/WAN for opportunistic encryption of the whole net, Off-the-record messaging for privacy in Internet chat, and the Tor project for anonymous web surfing.
In 1998, the Electronic Frontier Foundation, with assistance from the mailing list, built a $200,000 machine that could brute-force a Data Encryption Standard key in a few days. The project demonstrated that DES was, without question, insecure and obsolete, in sharp contrast to the US government's recommendation of the algorithm.
Cypherpunks also participated, along with other experts, in several reports on cryptographic matters.
One such paper was "Minimal Key Lengths for Symmetric Ciphers to Provide Adequate Commercial Security". It suggested 75 bits was the minimum key size to allow an existing cipher to be considered secure and kept in service. At the time, the Data Encryption Standard with 56-bit keys was still a US government standard, mandatory for some applications.
Other papers were critical analysis of government schemes. "The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption", evaluated escrowed encryption proposals. Comments on the Carnivore System Technical Review. looked at an FBI scheme for monitoring email.
Cypherpunks provided significant input to the 1996 National Research Council report on encryption policy, Cryptography's Role In Securing the Information Society (CRISIS). This report, commissioned by the U.S. Congress in 1993, was developed via extensive hearings across the nation from all interested stakeholders, by a committee of talented people. It recommended a gradual relaxation of the existing U.S. government restrictions on encryption. Like many such study reports, its conclusions were largely ignored by policy-makers. Later events such as the final rulings in the cypherpunks lawsuits forced a more complete relaxation of the unconstitutional controls on encryption software.
Cypherpunks have filed a number of lawsuits, mostly suits against the US government alleging that some government action is unconstitutional.
Phil Karn sued the State Department in 1994 over cryptography export controls after they ruled that, while the book Applied Cryptography could legally be exported, a floppy disk containing a verbatim copy of code printed in the book was legally a munition and required an export permit, which they refused to grant. Karn also appeared before both House and Senate committees looking at cryptography issues.
Daniel J. Bernstein, supported by the EFF, also sued over the export restrictions, arguing that preventing publication of cryptographic source code is an unconstitutional restriction on freedom of speech. He won, effectively overturning the export law. See Bernstein v. United States for details.
Peter Junger also sued on similar grounds, and won.
John Gilmore has sued US Attorneys General Ashcroft and Gonzales, arguing that the requirement to present identification documents before boarding a plane is unconstitutional. These suits have not been successful to date.
Cypherpunks encouraged civil disobedience, in particular US law on the export of cryptography. Until 1996, cryptographic code was legally a munition, and until 2000 export required a permit.
- !/bin/perl -sp0777i<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<j]dsj
$/=unpack('H*',$_);$_=`echo 16dio\U$k"SK$/SM$n\EsN0p[lN*1 lK[d2%Sa2/d0$^Ixp"|dc`;s/\W//g;$_=pack('H*',/((..)*)$/) </source>
Vince Cate put up a web page that invited anyone to become an international arms trafficker; every time someone clicked on the form, an export-restricted item — originally PGP, later a copy of Back's program — would be mailed from a US server to one in Anguilla. This gained overwhelming attention. There were options to add your name to a list of such traffickers and to send email to the President of the United States registering your protest.
In Neal Stephenson's novel Cryptonomicon many characters are on the "Secret Admirers" mailing list. This is fairly obviously based on the cypherpunks list, and several well-known cypherpunks are mentioned in the acknowledgements. Much of the plot revolves around cypherpunk ideas; the leading characters are building a data haven which will allow anonymous financial transactions, and the book is full of cryptography. But, according to the author the book's title is — in spite of its similarity — not based on the Cyphernomicon, an online cypherpunk FAQ document.
Cypherpunk achievements would later also be used on the Canadian e-wallet, the MintChip, and the creation of bitcoin. It was an inspiration for CryptoParty decades later to such an extent that the Cypherpunk Manifesto is quoted at the header of its Wiki, and Eric Hughes delivered the keynote address at the Amsterdam CryptoParty on 27 August 2012.
Cypherpunks list participants included many notable computer industry figures. Most were list regulars, although not all would call themselves "cypherpunks". The following is a list of noteworthy cypherpunks and their achievements:
- Jacob Appelbaum: Tor developer, political advocate.
- Julian Assange: WikiLeaks founder, deniable cryptography inventor, journalist, co-author of Underground, author of Cypherpunks: Freedom and the Future of the Internet, member of the International Subversives. Assange has stated that he joined the list in late 1993 or early 1994. An archive of his cypherpunks mailing list posts is at the Mailing List Archives
- Derek Atkins: Computer scientist, computer security expert, and one of the people who factored RSA-129.
- Adam Back: inventor of Hashcash and of NNTP-based Eternity networks, co-founder of Blockstream.
- Jim Bell: author of Assassination Politics.
- Steven Bellovin: Bell Labs researcher, later Columbia professor. Chief Technologist for the US Federal Trade Commission in 2012.
- Matt Blaze: Bell Labs researcher, later professor at University of Pennsylvania; found flaws in the Clipper Chip.
- Eric Blossom: designer of the Starium cryptographically secured mobile phone, founder of the GNU Radio project.
- Jon Callas: technical lead on OpenPGP specification, co-founder and Chief Technical Officer of PGP Corporation, co-founder with Philip Zimmermann of Silent Circle.
- Bram Cohen: creator of BitTorrent.
- Lance Cottrell: the original author of the Mixmaster Remailer software, and founder of Anonymizer.
- Matt Curtin: founder of Interhack Corporation, first faculty advisor of The Ohio State University Open Source Club, and lecturer at The Ohio State University.
- Hugh Daniel (deceased): former Sun Microsystems employee, manager of the FreeS/WAN project (an early and important freeware IPsec implementation).
- Dave Del Torto: PGPv3 volunteer, founding PGP Inc. employee, longtime Cypherpunks physical meeting organizer, co-author of RFC3156 (PGP/MIME) standard, co-founder of IETF OpenPGP Working Group and the CryptoRights Foundation human rights non-profit, HighFire project principal architect.
- Suelette Dreyfus: co-author of Rubberhose, a deniable encryption archive.
- Hal Finney (deceased): cryptographer, main author of PGP 2.0 and the core crypto libraries of later versions of PGP; designer of RPOW.
- Alex Fowler: entrepreneur, advocate, executive, AAAS, EFF, Zero-Knowledge Systems, PwC and Mozilla. Notable contributions include NSF study on Anonymous Communications on the Internet, AAAS Brief in Bernstein case, EFF's DES Cracker Project, Do Not Track, Collusion/Lightbeam Extension, Stopwatching.us campaign
- Randy French (pseudonym of Sandy Sandfort): producer of the first Cypherpunk genre pornographic film, Cryptic Seduction.
- Michael Froomkin*: Distinguished Professor of Law University of Miami School of Law.
- Eva Galperin: Malware researcher and security advocate, Electronic Frontier Foundation activist.
- John Gilmore*: Sun Microsystems' fifth employee, co-founder of the Cypherpunks as well as the Electronic Frontier Foundation, project leader for FreeS/WAN.
- Mike Godwin: Electronic Frontier Foundation lawyer, electronic rights advocate.
- Ian Goldberg*: professor at University of Waterloo, designer of the Off-the-record messaging protocol.
- Rop Gonggrijp: founder of XS4ALL, co-creator of the Cryptophone.
- Sean Hastings: founding CEO of Havenco and co-author of the book God Wants You Dead.
- Johan Helsingius: creator and operator of Penet remailer.
- Nadia Heninger: assistant professor at University of Pennsylvania, security researcher.
- Robert Hettinga: Founder of the International Conference on Financial Cryptography and originator of the idea of Financial cryptography as an applied subset of cryptography.
- Marc Horowitz: author of the first PGP key server.
- Tim Hudson: co-author of SSLeay, the precursor to OpenSSL.
- Eric Hughes: founding member of Cypherpunks, author of A Cypherpunk's Manifesto.
- Isak Johnsson (deceased): Creator of the stealth technology used in Stuxnet, virus author, programmer.
- Peter Junger (deceased): Law professor at Case Western Reserve University.
- Werner Koch: author of GNU Privacy Guard.
- Paul Kocher: president of Cryptography Research, Inc., co-author of the SSL 3.0 protocol.
- Ryan Lackey: co-founder of HavenCo, the world's first data haven.
- Brian LaMacchia: designer of XKMS, research head at Microsoft Research.
- Ben Laurie: founder of The Bunker, core OpenSSL team member, Google engineer.
- Moxie Marlinspike: founder of Open Whisper Systems (developer of Signal), author of the Convergence SSL authenticity system, co-author of the Signal Protocol and the Double Ratchet Algorithm (with Trevor Perrin).
- Morgan Marquis-Boire: researcher, security engineer, privacy activist.
- Timothy C. May: former Assistant Chief Scientist at Intel, author of A Crypto Anarchist Manifesto and the Cyphernomicon, and a Founding member of the Cypherpunks Mailing List.
- Jude Milhon (deceased; a.k.a. "St. Jude"): a Founding Member of the Cypherpunks mailing list, credited with naming the group; co-creator of Mondo 2000 magazine.
- Vincent Moscaritolo: = Founder of Mac Crypto Workshop , Principal Cryptographic Engineer for PGP Corporation, Co Founder of Silent Circle., Co Founder 4th-A Technologies, LLC.
- Julian Oliver: Artist, privacy advocate, critical engineer. Co-founder of Critical Engineering.
- Sameer Parekh: former CEO of C2Net and co-founder of the CryptoRights Foundation human rights non-profit.
- Runa Sandvik: Tor developer, political advocate.
- Len Sassaman (deceased): maintainer of the Mixmaster Remailer software, researcher at Katholieke Universiteit Leuven, and a biopunk.
- Steven Schear: Creator of the warrant canary, street performer protocol, founding member of the International Financial Cryptographer's Association and GNURadio, team member Counterpane, former Director at data security company Cylink and MojoNation, current Vice President at StashCrypto.
- Bruce Schneier*: well-known security author, founder of Counterpane.
- Vipul Ved Prakash: co-founder of Sense/Net, author of Vipul's Razor, founder of Cloudmark.
- Zooko Wilcox-O'Hearn: DigiCash and MojoNation developer, founder of Zcash, co-designer of Tahoe-LAFS.
- Asher Wolf: Founder of Cryptoparty.
- Jillian C. York: Director of International Freedom of Expression at the Electronic Frontier Foundation (EFF).
- John Young: anti-secrecy activist and cofounder of Cryptome.
- Philip Zimmermann: original creator of PGP v1.0 (1991), co-founder of PGP Inc. (1996), co-founder with Jon Callas of Silent Circle.
* indicates someone mentioned in the acknowledgements of Stephenson's Cryptonomicon.
- Arvind Narayanan: What Happened to the Crypto Dream?, Part 1. IEEE Security & Privacy. Volume 11, Issue 2, March–April 2013, pages 75-76, ISSN 1540-7993
- Robert Manne: The Cypherpunk Revolutionary - Julian Assange. The Monthly March, 2011, No. 65
- ResourceShelf » Oxford English Dictionary Updates Some Entries & Adds New Words; Bada-Bing, Cypherpunk, and Wi-Fi Now in the OED
- Please title this page. (Page 2)
- Hughes, Eric (1993), A Cypherpunk's Manifesto
- Levy, Steven (May 1993). "Crypto Rebels". Wired.
- Levy, Steven (2001). Crypto: How the Code Rebels Beat the Government – Saving Privacy in the Digital Age. Penguin. ISBN 0-14-024432-8.
- Timothy C. May (1992), The Crypto Anarchist Manifesto
- May, Timothy C. (September 10, 1994). "The Cyphernomicon: Cypherpunks FAQ and More, Version 0.666". Cypherpunks.to. Retrieved February 28, 2011. as well as Hughes's
- John Gilmore, home page
- Matt Blaze (1994), Protocol failure in the escrowed encryption standard
- "Apple takes strong privacy stance in new report, publishes rare "warrant canary"". Ars Technica.
- Electronic Frontier Foundation (1998), Cracking DES: Secrets of Encryption Research, Wiretap Politics, and Chip Design, Electronic Frontier Foundation, ISBN 1-56592-520-3
- Blaze; Diffie; Rivest; Schneier; Shimomura; Thompson & Wiener (1996). http://www.schneier.com/paper-keylength.html. Missing or empty
- Hal Abelson; Ross Anderson; Steven M. Bellovin; Josh Benaloh; Matt Blaze; Whitfield Diffie; John Gilmore; Peter G. Neumann; Ronald L. Rivest; Jeffrey I. Schiller & Bruce Schneier (1998), The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption
- Steven Bellovin; Matt Blaze; David Farber; Peter Neumann; Eugene Spafford, Comments on the Carnivore System Technical Review
- Kenneth W. Dam; Herbert S. Lin, eds. (1996). Cryptography's Role In Securing the Information Society. Washington, D.C.: National Research Council. p. 688. ISBN 0-309-05475-3. LCCN 96-68943. Archived from the original on September 28, 2011.
- "The Applied Cryptography Case: Only Americans Can Type!".
- Schneier, Bruce (1996). Applied Cryptography (2nd ed.). John Wiley & Sons. ISBN 0-471-11709-9.
- Gilmore v. Gonzales
- Adam Back, export-a-crypto-system sig, web page
- Adam Back, post to cypherpunks list, RSA in six lines of Perl
- Vince Cate, ITAR Civil Disobedience (International Arms Trafficker Training Page)
- Zurko, Marie Ellen (1998-10-07). "Crypto policy costs the US a citizen". Electronic CIPHER: Newsletter of the IEEE Computer Society's TC on Security and Privacy (29). Retrieved 2013-10-11.
- Dawson, Keith (1996-05-05). "Become an international arms trafficker in one click". Tasty Bits from the Technology Front. Archived from the original on 1997-01-16. Retrieved 2013-10-11.
- Neal Stephenson, Cryptonomicon cypher-FAQ, archived from the original on May 28, 2010
-  Archived September 12, 2012, at the Wayback Machine.
- "Warm Party for a Code Group". Wired. September 13, 2002. Archived from the original on March 5, 2009.
- Lopp, Jameson (9 April 2016). "The rise of the cypherpunks". CoinDesk. Retrieved 11 April 2016.
- 'Julian Assange <proff () suburbia ! net>' posts - MARC
- Rodger, Will (30 November 2001). "Cypherpunks RIP". The Register. Retrieved 13 July 2016.
- "Officers - Open Source Club at Ohio State University".
- Orlowski, Andrew. "Alice, Bob and Eve too". The Register.
- Discourse.net | On the fringes of the public sphere
- Franchesci-Bicchierai, Lorenzo (20 September 2014). "Egypt's New Internet Surveillance System Remains Shrouded in Mystery". Retrieved 23 September 2014.
- Hastings, Sean (2007). God Wants You Dead (1st ed.). Vera Verba. ISBN 0979601118.
- Evans, Jon (13 January 2013). "Nadia Heninger Is Watching You". Retrieved 23 September 2014.
- "Visa gravplats". Retrieved 28 April 2015.
- "Meet the virus author:Hackitat". 11 September 2012. Retrieved 28 April 2015.
- Mac Crypto Workshop
- http://criticalengineering.org/en. Missing or empty
- Allnutt, Luke (27 November 2012). "The Woman Behind CryptoParty". Retrieved 23 September 2014.
- "Jillian York". Electronic Frontier Foundation.
- Andy Greenberg: This Machine Kills Secrets: How WikiLeakers, Cypherpunks, and Hacktivists Aim to Free the World's Information. Dutton Adult 2012, ISBN 978-0525953203
- A Cypherpunk's Manifesto written by Eric Hughes
- The Crypto Anarchist Manifesto written by Timothy C. May
- Assange 'The World Tomorrow' — Cypherpunks uncut version
- The Cyphernomicon by Timothy C. May ("Cypherpunks FAQ and More" from 1994)
- Archives of the first eight years of the mailing list (Zipped, 83MB)
- "Warm Party for a Code Group" - Cypherpunks 10 year anniversary (article in Wired)
- Crypto Rebels, Wired Magazine issue 1.02 (May/Jun 1993)
- The Crypto Project, a revitalization of the Cypherpunk movement