The Peterman Pod - Turing Award Winner: NSA, Public Key Cryptography, Crypto Wars | Martin Hellman
Episode Date: July 6, 2026Martin Hellman is a Turing Award winner who helped to invent public-key cryptography against the NSA's wishes. I interviewed him all about his work and why it broke the law at the time.• My ergo...nomic keyboard project I mentioned, you can follow along here: https://read.compose.llc/• The Kickstarter page for it: https://www.kickstarter.com/projects/ryanlpeterman/compose-simple-ergonomics-beautifully-donePodcast links:• YouTube: https://youtu.be/AZLOETBCQM4• Apple: https://podcasts.apple.com/us/podcast/the-peterman-pod/id1777363835• Transcript: https://www.developing.dev/p/turing-award-winner-nsa-public-keyThank you to this episode's sponsor for supporting my work:• WorkOS: makes your app Enterprise Ready with easy to use APIs to add SSO, SCIM, RBAC, and more in just a few lines of code, check them out at https://workos.com/Timestamps:(00:00) Intro(00:34) Why his work broke the law(08:39) How people did encryption before(18:51) The crypto wars(26:22) The story behind Diffie Hellman key exchange(36:48) Signatures vs key exchange(43:05) RSA patent wars(48:08) Why inventions happen at similar times(50:29) What he worked on after cryptography(57:31) His thoughts on death(59:40) Advice for his younger self(01:00:45) OutroWhere to find Martin:• Wikipedia: https://en.wikipedia.org/wiki/Martin_Hellman• Website: https://ee.stanford.edu/~hellman/Where to find Ryan:• Newsletter: https://www.developing.dev/• X/Twitter: https://x.com/ryanlpeterman• LinkedIn: https://www.linkedin.com/in/ryanlpeterman/• Threads: https://www.threads.com/@ryanlpeterman• Instagram: https://www.instagram.com/ryanlpeterman• TikTok: https://www.tiktok.com/@ryanlpetermanReferenced in this episode:• Martin Hellman's “The Evolution of Public Key Cryptography”: https://www.youtube.com/watch?v=Tev3tVzH91s• Keys Under Doormats: https://cacm.acm.org/opinion/keys-under-doormats/• Cryptography's Role in Securing the Information Society (CRISIS report): https://nap.nationalacademies.org/catalog/5131/cryptographys-role-in-securing-the-information-society• Secure Communications Over Insecure Channels: https://doi.org/10.1145/359460.359473• New Directions in Cryptography: https://doi.org/10.1109/TIT.1976.1055638
Transcript
Discussion (0)
I mean, I wasn't just pissing off NSA.
I was pissing off the Russians.
This is Martin Hellman, a Turing Award winner famous for his contributions to public key cryptography
that the government was against.
I told them, look, if you want to give the papers, that's okay.
But Stanford's not sure they can defend you or it's clear they could defend me.
I could have gotten killed.
So when my colleagues said I was crazy to work in cryptography instead of scaring me off,
it actually attracted me.
The NSA, did they ever try to recruit you?
When I looked at it, I went, oh, shit.
basically because I saw your initial work in cryptography was potentially breaking laws or it was
kind of in this gray area where the NSA was kind of not super happy with your work and there was
some conflict with the government. Could you explain what the field of cryptography was like at the
time and its relationship to the government and how you got into the field?
Cryptography is the study of codes and ciphers for keeping information secret.
When I started to get interested in this area in the, let's see, it was 1968.
I was at IBM research, just after finishing my PhD.
They'd hired Horstice,l, who you may have heard of, who was the father of IBM's work in this area,
and really started the unclassified research in cryptography.
So I started there, and then I realized when I was teaching MIT 69 to 71,
that I might actually be able to do something.
I won't go into the details of that right now.
And I did it in my own time
because I didn't think I was breaking any laws by doing it.
I didn't think anybody could make that case,
but I realized that there was a part of the government,
the National Security Agency,
that would be very concerned about this.
And then it was, as our work really became visible,
that they started saying we were breaking the laws.
And that's when I looked into it more carefully. We got a letter in July, 1977, from a guy who
worked at, we determined he worked at NSA. He wrote from his home address in Maryland, which is a good
indicator that he works at NSA, to the ICCLE, which is the main electrical engineering
professional society, the Institute of Electrical and Electronics Engineers, saying that as an ICCI
member, he was concerned that they were breaking the law by publishing certain papers. He never
mentioned me by name, but I had an article in almost every issue that he mentioned of the
R2E transactions. And the R2EA wrote back to him, copying me. They didn't copy me as Martin
Hellman Troublemaker. They copied me as a member of the board of governors of the information
theory group, which was then publishing most of these papers. And so it's a funny thing that when
People start to talk about cryptography.
They talk in code all the time.
NSA was maintaining, I was breaking the law by publishing my papers
in international journals.
The ITAR, the international traffic and arms regulations,
which I'd been unaware of up to that point,
defines anything cryptographic as an implement of war.
And I wasn't exporting an implement of war,
which would you need a license from the State Department.
I was exporting technical data from their perspective
on implements of war.
And so that's why I was breaking the law.
And so I took the letter to Stanford's general counsel at the time, John Schwartz.
He said, if the laws interpreted that broadly, he thinks it was unconstitutional,
but that's only his legal opinion.
It had to be settled in the court of law.
I mean, when you got these warnings, did it deter you at all?
Or what was your immediate reaction?
I kind of fell into this.
At first, Witt and I, with Diffey, and I thought that the 56-bit key size of D.
the data encryption standard was a mistake.
We realized that you could break it with exhaustive search.
Today, the AES, the advanced encryption standard,
has a minimum of 128-bit key size,
which is much, much bigger than a 56-bit key size.
2 to the 128th is much bigger than 2 to the 56.
So we wrote letters, we thought that they'd change it.
It was cheap and easy to change it.
And after six months, we realized that we had a political problem,
technical problem. And then we had to decide whether to back down or not. And we went forward
because at that point I was invested in this. And also, I'm from the Bronx, as I mentioned to you
earlier. And I'm a streetfighter, not with my fists. I got beat up a lot. But I'm a street
fighter with my mouth and my mind. And they picked the wrong person, basically. I wasn't going to
back down. What could have gone wrong? I mean, would they pursue you with lawyers? Or would
Oh, I could have gotten killed.
You could have gotten killed.
Oh, yeah.
Not necessarily by them, but maybe by the GRU, the Russian equivalent.
I mean, I wasn't just pissing off NSA.
I was pissing off the Russians, the Soviets.
Why would they be pissed, though?
Oh, we and the Soviets sold our World War II surplus cryptographic equipment to third world
countries.
We'd rather that they were able to break it, and they'd rather that we were able to break it,
then no one was able to break it.
So my mother called me up.
My mother was still alive.
She died in 1984.
And she called me up and said, what are you doing?
You're going to get yourself killed?
She was really upset.
So, okay, so you get issued the warning
and then you go to the general counselor at Stanford.
Then what happens?
This was July, 1977.
In, I think, October, early October.
Yes, it was October.
There was an I-Triplee symposium
on an information theory at Cornell University.
And I had two papers there, one with Ralph Merkel, who deserves, I believe, a lot of credit for inventing public key cryptography, as you probably know.
And one with Steve Pollack, which really, Steve and I have a paper, which is really the RSA system, except it's mod P instead of mod N.
It's mod A prime number instead of module composite number.
We realized that you could get, you could do it in mod N, but we didn't have public key cryptography then.
Anyway, Steve and Ralph and I had papers, and John Schwartz said that he strongly recommended
that I give the papers instead of the students.
I was going to have the students give the papers.
And so I went to the students, and I told them, look, if you want to give the papers, that's
okay, but Stanford's not sure they can defend you or it's clear they could defend me.
And I feel very comfortable going forward with Stanford's financial resources.
and the students initially bravely said that they would give the papers.
After a week they came back to me, their mothers were beating on them,
like my mother beat on me, and they said, okay, you give the paper.
So when it came time for each of those papers to be given at Cornell,
I went up to the podium, and I said,
I had the student come up with me, and I said,
normally the student would be giving this paper,
but on the advice of counsel, and everyone knew what I was talking about,
I will be giving the paper.
And I want you to consider, in every way but legally, the words coming from my mouth as if they're coming from his.
And so the students got more credit that way than they ever would have if they gave the papers by themselves.
It sounds like you had a lot of opposition at the time. Why did you still pursue it?
Well, my colleagues all told me that I was crazy to work in cryptography, and they had two reasons.
One of which was NSA has a multi-billion-dollar year budget, and they've got a decades head start.
How can you hope to discover something they don't already know?
And my attitude was, I don't care what they know.
It's not available for commercial use.
Even if I only develop things that they know, it doesn't matter.
And yet we develop things that they didn't know about, which is a whole other thing.
Like GCHQ, the British equivalent of NSA, has claimed that they invented public key cryptography a little bit before us.
Not a lot, by the way, just around the same time.
Except they never had anything on digital signatures.
They never had anything that allowed my phone to accept a software update
and to use a secret key to sign it, which Apple has,
and a public key in the phone.
So even if someone takes the phone apart and gets the public key,
that doesn't tell them how to sign future software updates.
And GCHQ had nothing on digital signatures,
only on the privacy aspect.
Prior to the solutions you came up with,
how did people, how did people, you know,
Encrypted data?
Yeah, encrypt their messages.
They didn't.
No, actually, NSA, GCHQ, GRU, all these foreign, the United States and foreign intelligence
services was sucking up huge amounts of unencrypted data.
It was only mining companies and banks that used encryption, and they used very bad encryption.
What about like during wars and stuff, sending messages that they didn't want other, you know,
adversaries to be able to read.
You're talking about military use?
Yeah, yeah, exactly.
Well, that's, that was where the major use had been, was in the military.
And one of the things, I have a talk on the evolution of public key cryptography,
and I start off by saying, I love that people call it revolutionary.
Don't stop saying that.
But by the end of this talk, you wonder why it took us so long rather than how we ever found it.
And they were almost like big arrows pointing, go here, go here, go here.
And one of them was, Witt and I had come up with the idea of a trapdoor cipher.
That was a cipher that was impossible to break unless you knew trapdoor information and went into its design.
We've never been able to develop such a cipher, but we realized that was a possibility.
And that would be a general's dream because he could use it, if he knew the trapdoor information,
he could use it securely against his adversary in the war.
But his adversary, if they captured it, couldn't use it securely because he could use it.
because he knew the trapped or information and could break it.
And from there to public key cryptography is a minor step.
I know there's this famous, I think it's called the Enigma Machine
and Turing was involved in that.
That's some sort of encryption mechanism.
Basically, it's a World War II.
It's the main German field cipher of World War II, the Enigma Machine.
It was gear-based.
And encryption is a special purpose form of computation.
And computation has gotten a hell of a lot better.
We do, I don't know, I'm 80 years old, so it's 16 periods of five years.
We can do about maybe 10 to the 14th.
It's not quite 10 to the 16th times as much computation for a dollar today as we could
when I was born at the end of World War II.
I was born October 45.
So Enigma, what was the primary computing device of World War II?
Gear-based adding machines.
What was the primary encryption device?
Gear-based encryption machines.
Today, we can do not only computation much better, we can do encryption much better.
In that case, it substituted the electricity.
You pressed a letter on a keyboard.
It generated an electrical signal that went through a sequence of rotors, as they're called,
which transformed it into another letter that lit up.
And so you'd set up the key, which rotors to use and what order to put them in and some other things.
and then you type out the message on the keyboard
and you'd read off the enciphered message on the lights.
And Alan Turing, who you pointed out in the imitation game,
which was the major movie of like five years ago,
Alan Turing figured out how to build a primitive form of computer
to break the Enigma machine.
Now, the Germans knew Enigma was breakable.
They never thought that the Allies would build a computer to break it.
And so the Allies were reading German
encrypted messages almost as fast, maybe faster than the Germans were.
And that's what was different.
And as they knew Enigma was breakable, they never realized that they never thought
that we would build a machine like that.
And it's interesting, Alan Turing was hounded to death in the 1950s in spite of his
wartime activities, and this is covered in the imitation game in that movie.
He was hounded to death because of his homosexual tendencies, or more than tendencies.
I mean, he was homosexual.
Today, we wonder how our parents, grandparents,
could have been so uncivilized as to do things like that.
You mentioned in that talk of the history of public key cryptography,
there's these, everything is pointing towards these directions.
What did you mean by that?
Well, I mean, the Trapptor Seifer was pointing us toward public key cryptography.
And yet a Trappedor Seifer makes perfect sense
because almost everything in cryptography involves trapdoors.
People usually think of public key cryptography as a trapdoor cryptographic system.
But even a cryptographic system is a trapdoor.
And this is fundamentally related to a question called p equals np or not in computer science.
Are there any problems that are easily checked that are hard to solve?
That's basically what that means.
And if there's any, if there are any secure cryptographic systems,
then there are problems that easily check
that are hard to solve.
And so, for example, one-way function
is the simplest form of trapdoor.
This is a function that's easy to compute
but hard to invert.
And this figures importantly in cryptography
and blockchains, among other things.
And so we've all taken trapdoor quizzes
where the professor gives you an hour
to solve the problem.
At the end of the hour, he says,
pencils down, papers in.
He says, oh, we have a few minutes remaining,
let me give you the solution
and convince you it's right.
That's a trapdoor quiz problem.
It's a affirmative form.
And there, the professor has in mind
a particular method for solving it
whereas you have many methods.
And a real trapdoor quiz problem
would work like as follows.
The professor would say,
here's a one-way function.
I've generated an X.
Here's the Y that comes out.
you find the X that comes in. After a million years goes by, he says papers, down, pencils in,
he says, oh, by the way, in the few seconds remaining, let me convince you, let me give you the
solution and convince you it's right. What does he do? He takes X. He puts it through the one-way
function. He gets Y, and you know that he had the right value of X, and yet you can never find it.
When I imagine you kind of competing or budding heads with the NSA, I could imagine one solution
for them might be to try to recruit you to their side. Did they ever try to recruit you?
Yes. Early on, before we had public, before we had any good results, I'd go to conferences and I'd
give talks on cryptography, which in hindsight were very primitive. And people with name badges
that said, Department of Defense, which was the simple substitution cipher for NSA, would always ask
me, they explained they were at NSA and they'd love to hire me as a consultant because they needed
new blood. And I said, I'd love to know what you know, but only if I can't, only if I can publish
my papers independently. And he said, of course not. And so that, which I knew was the answer.
And so I never took any classified consulting contracts, etc. Until 1995, there was a National
Research Council Committee called Crisis. It's called the Crisis Report. Cryptography's role in securing
the information society, which comes out as crisis.
And that was about 1995.
And the question was, were U.S. government regulations
helping national security or hurting national security?
We concluded that in many ways they were hurting national security.
And we had a former deputy director of NSA on the committee.
We had a former attorney general on the committee,
Benjamin Civoletti, who had been attorney general under Jimmy Carter.
We had people like me who were privacy advocates,
but who had come around and started to understand how NSA viewed things.
We had Ray Ozzy was on that committee,
who was the chief software architect at Microsoft when Bill Gates retired.
He did Lotus Notes.
And we reached unanimous conclusions.
And one of the most important conclusions we reached
was that the classified briefings,
I did take a classified, I didn't get paid for that,
but I did have a security clearance.
for that and intelligence corns,
which I'd never taken before.
But I was retiring at that point,
and I figured it didn't matter.
And it was important for me to be able to get past the people
who said, if you knew what I knew, you'd think differently.
And there were people in the unclassified briefings
who said, if you knew what we knew, you'd think differently.
But we concluded, and it's in our report,
which you can get free of charge on the National Academy's website,
we had in there that the classified briefings helped fill in details,
but they did not change our fundamental conclusions.
And that was one of the most important conclusions we reached.
And yet people said, if you knew what we knew, you'd think differently,
and yet that was not true.
When they were trying to recruit you,
I imagine it would have been very advantageous for them to classify your work.
Oh, yeah.
I mean, when you turned down their offer,
I imagine they would have had to compensate you handsomely
to kind of go to the dark side.
We never got that far.
Oh, okay.
And by the time we had a fight on our hands,
it was too late.
I mean, basically, I'd committed to see this thing through.
And when I realized that my life might be in danger,
I might go to jail,
although I didn't think about those possibilities.
very much.
And I didn't think they were real, although they may have been.
I felt like I was committed and I couldn't back down.
I mean, what would you do?
I kind of fell into it.
It's like a friend of mine who was a helicopter pilot in Iraq.
He went through ROTC in the late 90s.
He said to pay for his education.
There were no wars.
He said, why is everybody calling me a hero?
When I was doing the research, I kept seeing this mention of first crypto.
wars, what are the crypto wars and how did they play out?
The first crypto war was the one we've been talking about, which occurred in the late 70s,
early 80s, where NSA threatened to throw me in jail.
My life may have been in danger, things like that.
And that was over two things.
It was over the freedom to publish papers in international journals, which has now been
established.
And it was over the key size of DES, which is something that people today know almost nothing
about.
As I mentioned before, it was a 56-bit key size, and Witt and I did a quick calculation
that you could probably break that for $10,000, even with 1976 technology, 1975 technology.
And if we were wrong, Moore's Law would, if we were off by a factor of 10, an order of magnitude,
that would be erased in five years' time because Moore's Law was advancing the state of
computing by an order of magnitude every five years in those days.
So that was the first crypto war.
It was over the freedom to publish and the key size of DES.
The second crypto war, which people don't really remember, was in the 90s and quipper chip
was a big piece of that.
This was the idea that there should be an escrow service, that the government would allow strong
encryption, but it would maintain master keys somewhere.
And if they got a court order that said that they were able to get into it.
to something, they'd be able to do it.
Well, this sounds great, and it was great from certain points of view, but there were problems
with it.
Like in the National Research Council Committee, the Crisis Committee that I talked about, we wasted
a lot of time talking about key escrow.
And then we realized, I may have actually said this, although I think we came to it as a whole.
Look, there are major problems with key escrow.
How's going to work internationally?
Who's going to hold the keys when someone's in France and someone's in the United States or
someone's in Russia and someone's in the United States.
So what we said in the report is we said it very nicely
that we don't see how to solve many of the problems
with key escrow.
And the US government should experiment with it
and if they came up with a solution, come back to us.
And they never did.
That was the second crypto war.
And Clipper Chip was a chip that had a key escrow
built into it, basically.
The third crypto war,
some people may remember, occurred about 10, 15 years ago. It was over things like the San Bernardino
Apple iPhone. There were terrorists who committed acts and they had an Apple iPhone and NSA, the FBI
wanted to break into it. And FBI, not NSA, wanted to break into it. And they asked Apple to
give them the key. Apple does not have a key. Ron Revest is one of the authors of a report.
called Keys Under Doormats.
If you build what they call a backdoor
into a cryptographic system
to allow access,
and that was the third crypto war,
it was really a repeat of the second crypto war,
the key escrow, with a different name.
And it's really putting keys under doormats
because if Apple can recover one key,
they can recover any key,
and they're going to be asked repeatedly,
and there's a danger that if that information gets out there,
that all of Apple's devices become insecure.
So how do you do it?
We don't see how to do it.
It's unfortunate, but there is no way to give access.
I'd love to give access to the U.S. government
when it had legitimate reason for doing it.
I would love to withhold that access from the U.S. government
when it has an illegitimate reason for doing it,
which it sometimes does,
and from the Russian government,
which also would use it illegitimately.
You mentioned the DES,
56 bits was not secure enough.
Why would the government want less bits?
Oh, easy.
The government wanted fewer bits because they didn't want a publicly available standard that they couldn't break.
They figured that there was a crude form of trapdoor that Witt and I made an estimate in 75,
and I refined it when NSA, actually NBS, the National Bureau of Standards,
but it was two guys from NSA that we were always communicating with who had moved over to NBS.
we estimated that two to the 56 is roughly 10 to the 17th power.
That's 100,000 million, million keys.
We estimated that you could build a search chip,
even with 1975 technology,
it would search a million keys per second,
a microsecond per key.
And we then said, you wouldn't just build one of these,
you'd build a million of them.
And now you're searching a million, million keys per second.
And how long does it take to search 100,000 million?
million keys, 100,000 seconds, which is about a day. It's roughly 80,000 seconds. And so we estimated
that the cost of searching a 56-speed key size was roughly $10,000 per solution in 1975. And we were
probably optimistic, but as I said, even a factor of 10 optimism would be erased within five years.
So that's, the crude form of trapdoor was, if I build a machine like that, I can't keep it
fully loaded. I don't have roughly 60 problems a month to keep it fully loaded.
NSA has 60 problems a month to keep it fully loaded. And they have the $20 million to build the
machine. I don't. So that was the crude form of trapdoor. So they would retain access to
privileged information through superior computing resources. Yes. And snoopingness. The problem is
you and I might want to snoop on one problem a year.
How do we do that?
Do we wait a year to get a solution?
No.
We want it quickly.
But then it's sitting idle most of the time and our cost goes way to help.
You know, with modern public key cryptography and we can securely, anyone can
message anyone else and no one can snoop.
But that also includes the bad guys as well.
What do your thoughts on, I guess, the devil's advocate that says, you know,
Why do you need to hide something if you have nothing bad to hide?
Well, if you want to put all your banking information out there in the public,
if you want Apple to sign software updates in ways that bad guys can do,
yeah, there's no problem.
But we do have reasons for being secure.
We don't live in a world where we trust everybody yet.
And so there's a fundamental trade-off.
You cannot make strong encryption and give it only to the good guys
and not to the bad guys.
It's like cars.
If cars had been invented
in the classified literature,
the government might say,
this is great.
We can catch bad guys.
We can fight wars
and we can always win them
because we have tanks,
we have cars,
we have things like that,
and they've got horses.
And now imagine Witt and I invent a car
50 years ago
in the unclassified literature.
They'd be up on arms.
We wouldn't see ambulances.
We wouldn't see commuting.
We wouldn't see vacations
that people could take.
There's a fundamental trade-off.
It's there with cars, and it's there with cryptography as well.
So I wanted to talk about, obviously, the big invention that you had,
the public key cryptography, the Diffie-Helman key exchange algorithm.
What's the story behind you inventing this Diffy-Helman and maybe Merkel key exchange algorithm?
So which showed up on my doorstep, almost literally speaking, in the fall of 19,
He had been traveling around the country.
He'd worked to the AI lab, the artificial intelligence lab here at Stanford, and he'd done some work on cryptography.
He wanted to do more.
They could not support it.
So he took a small, I think, inheritance that he got from his mother, and he traveled around the country.
And if you work in AI, if you're known, there are people that will put you up in their garages and their homes.
They'll feed you even, maybe.
John McCarthy lives up the hill, and Witt was a good friend of him.
his and there was a high school student living in his attic I think who was from Cambridge and I asked
him why he didn't just go to the MIT artificial intelligence lab and he said he didn't like their
politics I don't know what that means so Witt traveled around the country and he when he was at
IBM research a secrecy order had to send it on them just about this time I'd been there a few
months before they told me they couldn't tell me very much they told Witt when he came through the
same thing, but they told him one thing additional. Oh, when you back out at Stanford,
woke up Helman. So he called me in the fall of 74, and we set up maybe a half hour,
an hour meeting max, and it went through the night. They came back here. He and Mary Fisher,
his then-girlfriend now wife, then-wife, she's passed away since then. And we had a real
meeting of the minds. It was amazing. And so Witt and I, and I,
started working together in the fall of 74.
The data encryption standard
came out in March 75.
It was announced.
We came up with the idea
of public key cryptography around then.
And we did not know about Ralph Merkel at the time.
Ralph was an undergraduate
and later a master's student at Berkeley,
the UC Berkeley.
And he came up with half of public key cryptography.
He came up with public key distribution.
And I have his paper
in which he, in the fall of 74,
We didn't know about him then.
He was taking CS244 computer security,
and he had to do a term project,
and he proposes two term projects.
One is the privacy half of public key cryptography,
and the other is something much more mundane.
And I have the professor's handwriting in blue scanned,
I've scanned this across the top,
that idea number two, the mundane idea looks much better
than idea number one,
maybe because his description of idea number one,
is so muddled. But Ralph had major problems. So he drops the course. The professor says,
see me today about this. Ralph, instead of seeing the professor drops the course and goes and does it on his own.
He then submits a paper to the CACM, the communications of the ACM, the primary journal of the ACM.
And it's rejected. I have the rejection letter. Susan Graham, who was the editor who rejected it,
based on a referees report, writes,
it bothers so that there are no references in the paper.
Has no one thought of doing anything like this before?
The answer is no.
Now, he still soon have had references.
Ralph didn't know how to write a paper at that point.
I helped him rewrite the paper and it was later accepted,
but it was actually submitted a little before ours.
So Witt and I came up with public key cryptography.
Ralph came up with public key distribution.
We eventually learned about one another afterward.
And I bring him here in the summer of 76, and I talk to Ralph and I say, have you ever thought of coming to Stanford to do your Ph.D.? And Ralph says, I can't afford it. I said, yes, you can. How much are you making it Berkeley as a TA? And I said, I'd pay you roughly the same as an RA here at Stanford and your tuition would be covered. So he came to Stanford. He did his PhD under my supervision, supposedly, although we really worked together.
Open AI, Anthropic, Cursor, and Versal all use this product to make their lives better.
And the problem it solves is when you're building SaaS or an AI product and you want to sell to other companies, there's all these requirements you need to meet.
There's SSO, there's SCM, there's ARBAC, there's audit logs.
These are all things that take time to integrate but aren't the main focus of your app.
WorkOS is an API layer that lets you meet all of these requirements in just a few lines of
code. So let's say you have a new SaaS product and you want to sell to other companies, WorkOS will
solve all of these critical feature gaps for you. You can check them out at WorkOS.com to learn more
and get started. And I appreciate them for supporting my work and sponsoring this podcast.
It seems like this cryptography space was not so well resourced. I mean, Diffy is kind of going
couch to couch to kind of support himself on this. Ralph's also
kind of doing this in his own,
you know, fully his own initiative
and people aren't really supporting him throughout.
Was that common in cryptography at that time?
Yeah, I told you, all my colleagues,
and it's not an exaggeration,
told me I was crazy to work in cryptography.
And one of their reasons was NSA has a huge budget
and a multi-decade head start.
One of them, Jim O'Meuro,
who passed away about a year or two years ago,
he was a professor at UCLA.
I mentioned him to you earlier.
Jim told me I was crazy, and the best ideas often seem crazy ahead of time.
So I was at Tom Kailat.
Ten years ago, I was at Tom Kailat's 80th birthday celebration.
He won the National Medal of Technology and Science, I think,
given to him by President Obama for his work,
keeping Moore's law going for 10 years,
according to the former dean of engineering at Stanford at the time.
Jim O'Mora is standing six feet away.
I motion him over.
I said, Jim, tell this woman what you told me
when I first started working in cryptography.
and I just won the Turing Award,
the top prize in computer science for that work.
And Jim said, oh, I told Marty he was crazy.
And I knew he would do that
because he'd given me permission to quote him on this.
And the best work often appears crazy a priori.
GPS, which we use daily,
Brad Parkinson, who won the top prize
from the ICCI for that work,
says that the Air Force thought GPS was crazy initially.
high-speed internet access.
I won't go into details there.
And I've spoken to a number of Nobel laureates,
and almost all of them had the same reaction
from people that I did.
One of them, I'll tell you one story,
Lou and Yarrow, who won the Nobel Prize
in Physiology or Medicine, I think in 1998,
told me that the dean of his medical school
came to him and said,
Lou, why are you doing this crazy stuff?
We hired you because you do good work.
Crazy stuff that won them a Nobel Prize.
It makes sense.
But I guess the unique aspect is,
I think a lot of people would receive that pushback
and everyone thinks they're foolish
and they wouldn't go for it.
What is it that gave you the confidence to continue
when everyone was saying this is foolish?
Two reasons.
One is I got beaten up as a crazy.
Christ-Color as a kid. And that's a little bit of a joke, but not totally. As a kid, we moved to an Irish
Catholic neighborhood. I'm Jewish. We moved there when I was four and a half years old. I went to my
parents and I said, I want the pretty tree that the other kids have, the Christmas tree. I want
the presents under the tree. I want to go to the same school as the other kids in the neighborhood,
St. Nicholas of Tolentine Parochial School. I was telling my parents I didn't want to be Jewish.
and so in self-defense I adopted the attitude
of who would want to be like anybody else
that had a very simple answer, me.
I would have given my eye teeth to have been like everybody else
but in time I came to believe my own bullshit
and so when my colleagues said I was
crazy to work in cryptography instead of scaring me off
that actually attracted me.
So that's one reason.
And the other reason
I think it runs in my family.
I have an uncle who in 1940 with his wife, a Jew, took trains across the country with bicycles,
bicycling through national parks.
I mean, who would a crazy person would do that?
I come from a crazy family.
We've done crazy things and this was a crazy thing to do.
When you put out that paper in 1976, what was the problem you were trying to solve or what was
guiding your research direction at that time? Well, it started as trying to develop a theory of
cryptography. And Jim Massey, who was the editor at the time of the IAA Transactions on Information
Theory, of which I was on the board of governors, as I mentioned, Jim said, invited me to write a paper on
that. I mean, this was beginning to get some traction. And I asked if Witt could be included.
And he said, absolutely.
And so Witt and I were working on this paper.
We had several drafts.
And then in May 76, I come up with now Diffy-Helman Key Exchange.
And I include that, I throw that into a paper I'm giving in June 76 a month later
at the ICCI Symposium on Information Theory in Ronaby, Sweden.
Jim Massey's there, of course.
And he says, you get that into the paper.
I'll have it out in the November issue, which he did.
Now, the November issue, Witt has found.
of pointing out did not come out until February, 1977 was usually late. But that's how it worked.
And Ralph, unfortunately, as I said, had his idea rejected, his paper rejected. And so his paper
did not appear until 1978, even though it was submitted slightly before ours.
I see. I think in this conversation you mentioned key exchange, also signatures.
it seems like there's these components of a full cryptographic system.
Could you explain each of these?
Key exchange is how do you and your bank exchange a key
to protect your banking transactions,
to use a modern example,
with somebody listening in on the Internet,
and so use public key cryptography to do that.
Ralph had a puzzle method, Ralph Merkel,
had a puzzle method where he generated a C,
sequence of puzzles and you solved, your bank would solve one of them and it would then use
that key and you could quickly tell which key it was using.
But somebody else had to solve half the puzzles on average before it could do it.
And so it took a lot more effort on the part of an opponent.
I'll explain Diffy-Hellman key exchange very briefly and that is only key exchange.
It's not yet signatures.
You and I want to exchange physical messages.
I want to write them out to you and pass them to you,
but my wife, who is not supposed to see them,
is sitting between us and has to hand them to you.
So what do I do?
I put my message in a strong box.
I put a lock on that strong box.
I'd like to tell you the combination to that lock,
but if I tell you had to open it,
I'm also telling my wife how to open it.
So I don't tell anybody had to open it.
I pass it to my wife.
She can't open it.
She passes it to you, you can't open it.
You put a second lock on the strong box.
You then pass the double, you don't tell me the combination.
You don't tell Dorothy the combination, only you know the combination.
You pass it to Dorothy.
She can't take either lock off.
She passes to me, what can I do?
Take off my lock, leaving only your lock.
I pass it back to Dorothy.
She can't take off your lock, but when you get it, you can, you get the message inside.
That's basically how Diffie-Hellman or
Diffie Homan-Merkal Key Exchange works.
Now, what's critical about this is that I made the strong box big enough for you to put a second
lock on it.
If I hadn't done that, if I'd only made it big enough for one lock, you could have taken
the strong box that you got and put it in the bigger strong box.
But now there's a problem.
When I get it, I can't get inside to take my lock off.
It has to be what's called commutative.
And everybody knows what commutative means, although they may have forgotten it.
Addition is commutative.
3 plus 5 is the same as 5 plus 3.
It doesn't matter which order you do the operations in.
You get 8.
5 minus 3 is 2.
3 minus 5 is minus 2.
You get a different answer.
It's not commutative.
Subtraction is not commutative.
And what I had to do was find a commutative one-way function,
although I didn't know that at the time.
And the function I used is a commutative one-way function.
It's exponentiation in module arithmetic.
It doesn't matter whether you first raise alpha to the x1 power and then to the x2 power
or raise it to the x2 power and then to the x1 power.
You get the same result.
You get alpha to the x1, x2.
Multiplication in the exponent is commutative.
And we did this over a finite field where exponentiation is not a smooth function,
which would be easy to invert.
It jumps all over the place.
But it turns out it still works that way.
So that is public key exchange, public key distribution.
digital signatures are more complicated.
That's something that Witt came up with.
It's called a public key crypto system,
and then RSA, Revesh Shemar and Adelman,
came up with the first instance of that.
There you have a public key and a secret key,
and it doesn't matter which order you operate on them,
whether you first use the public key
and then the secret key or the secret key
and then the public key, you get the initial result.
They undo one another.
There, if I use my secret key, I can sign a message.
because there's no privacy,
but I send the encrypted message to you using my secret key.
You use my public key, which you get from a public file, to verify it.
That's how my phone works.
It's got a public key built into it.
Apple knows the secret key.
Apple can sign software updates.
People can take my phone apart and get the public key,
but that doesn't give them the secret key that allows them to sign software updates.
I see.
So in that case, Apple is signing their updates to your phone.
Right.
So I also was reading about symmetric versus asymmetric.
And what you're describing sounds like asymmetric.
Yes.
Asymmetric cryptography uses a public key and a secret key.
It's asymmetric.
Conventional cryptography uses the same secret key to encrypt and decrypt.
And that requires a courier, which is what was required before public key cryptography.
If you were a general in another division, I could send you a key.
I would send a messenger with a key locked to his wrist.
And when you got it, you could open it up and get the key.
And then you and I could use a radio channel to communicate very cheaply and very fast.
But you can't use couriers to communicate keys between a bank and a client.
Yeah, so I saw modern systems.
It's almost like multiple different mechanisms where there's
asymmetric key exchange at the beginning to establish the connection.
And then there's a, that gets you that key symmetric thing.
Exactly.
It's just like I described for Apple signing the software update.
They don't sign the whole thing.
They only sign a hash.
In the same way, we could use a public key crypto system like RSA to exchange messages,
but it's too slow.
So what I do is I send you one message.
Use the following key in AES, the advanced encryption standard.
and then we use AES very quickly to exchange messages.
And that's the difference between asymmetric encryption, which we use at first, where I use the
public key to insipher the message and use the secret key to get the key.
And then we use a symmetric system to very quickly communicate afterward.
I was reading about RSA versus the Diffy-Helman Key Exchange.
And it seems like there was a lot of patents or something like that, patent wars.
What's the context behind that?
I didn't know how patents worked when we wrote the first patent on public key cryptography.
If I'd known, we could have covered RSA.
We would have made a lot of money.
Basically, RSA made, sold their company for $250 million.
We made nothing, virtually nothing from our patents in cryptography.
There was a patent fight between RSA and us, MIT and Stanford.
or between their licensees, and basically MIT won that fight.
And I was pissed at RSA for a long time,
and I was pissed with Jim Bidzos, the president of RSA data security.
And around 1990, around 2000, sometime around there,
I realized it was inconsistent with my approach to life to be pissed at RSA.
They'd won, the fight was over.
And so I approached Jim Bidzow.
and I said, look, Jim, I told him that.
And I said, let's be friends.
Let's bury the hatchet.
And we essentially have.
And friends are better than enemies.
I'm not sure, but I think Ron Revest might have actually nominated
with me for the Turing Award.
Now, he wouldn't have done that if he didn't think we deserve it,
but he wouldn't do it if he was pissed at us.
And friends are better than enemies.
And it's not why I did it.
That's not why I became friends with them.
But again, but it, it, it, it,
It worked out very well.
How did they win the patent
or if your ideas came first?
I remember, I told you,
I didn't know how patents worked.
It's only the claims that matter.
And so if I know that,
we could have written a claim
that would have covered RSA
easily, but we didn't.
And so the patent was written very badly.
Stanford didn't want to invest a lot of money
in this patent.
So it had a law school interest,
turn, write the patent instead of a patent attorney. We made a lot of mistakes. You mentioned
friends are better than enemies. I think, yeah, a lot of people would agree with you. But I also
think most people wouldn't be able to get over losing a $250 million outcome. How did you
kind of get over that and kind of establish friendship? Well, some of it is in my genes, but some of
a lot of it comes from my wife.
Basically, my wife and I have been married 59 years last March,
and we were madly in love when we met.
We followed society's rules,
and we developed a toxic relationship 10 years later.
My wife was ready to leave me,
but I didn't know it because I had blinders on the way many husbands do.
And fortunately, when she met me, she decided I was the one.
and 10, 15 years ago, 10, 15 years after we're married, roughly 50 years ago, she says,
he's still the one, although life with him's impossible, and life with her was no picnic.
So she went around looking for catalysts, ways to improve our relationship, and she eventually
found a group, I won't go into all the details there, I tend to do that, that worked on the
international and the interpersonal at the same time. It was founded by Professor Harry Rathbun,
professor here at Stanford, born the 1890s, so he's no longer alive. I knew him late in his life.
And that's how I, it was based on the teachings of Jesus, which was a problem for me as a Jew,
because it was okay not to go to synagogue, which I didn't do. But it was not okay to study the
teachings of Jesus. That was traitorous. But eventually, Dorothy dragged me to enough meetings
that over a year's time, I came to see that these people, creative initiative as the group,
was called at the time, knew something I had to learn if my marriage was going to survive.
And I surprised myself by being willing to do things that seemed crazy to me.
The most important things were accepting ideas that Dorothy had that seemed crazy to me
that weren't crazy.
Because what happened when she had an idea that seemed crazy to me?
I treat her like she was crazy.
What did that do?
It drove her crazy.
What did that do?
It convinced me I was right that she was crazy.
kept the whole cycle going. By the way, the same happens internationally. We treat countries
in ways that they don't like. They react in ways that seem crazy to us. We treat them like they're
crazy. And it keeps the whole cycle going. So that's how I came. And so it's based on the
gospels. And while I'm not a Christian, I see Jesus as a Jewish reformer rather than as a Christian
Messiah. I view myself as a follower of Jesus. When I was researching the discovery that you had,
it seems like all of a sudden many of the similar discoveries were happening all at the same
time. So for instance, you mentioned Ralph Merkel and us. Oh, and GCHQ claims that they invented
it, just a couple of years before us, but they only have half of it, which is, if they're right,
which is the privacy part. They didn't have anything on digital signatures, but they claim everything.
Right. And then there's also the MIT folks. The MIT folks. Yeah. So I have a thing. I have a
theory about that. I'm going to tell it as a joke. But it is more to this joke than I think
is just a joke. There's a muse that whispers in our ears. There's a muse of poetry. There's a muse
of calculus who whispered in Newton's ear and Leibniz's ear about the same time. There's a muse
that whispered in Ralph's ear about the same time that she whispered in our ears. Most people
don't pay attention to this muse because she sounds crazy. A few people do.
and so that's why I think
there's something in the air
I mean it's not just a muse this
but there's something in the air
that comes to people
but why
you know why didn't it come 50 years earlier
or why like how come it seemed like
they all came very similar
and I noticed I interviewed
Barbara Liskov as well
who did a lot in like data abstraction
and modularity
and there also it was like
on the West Coast and the East Coast,
without even communicating,
they had the same discovery very similar.
I think my joke might actually have something to say about that,
but also there's something that goes on technologically.
We didn't have the computing power to do public key cryptography.
If someone had come up with it 50 years before,
it would have been a nice idea that couldn't be implemented.
So there's like a logistical part to this,
which is just the tools weren't there.
And once they were there, it kind of inspired the right thinking.
Yeah, but calculus, I mean, why that occurred to Leibniz and Newton about the same time.
Oh, and Darwin and someone else thought of evolution about the same time.
So I don't know.
It is mystical.
And maybe we should treat it as that.
Even though I'm a scientist, I believe in the mystical side of life.
There's a cryptography work that you're doing.
And then I think later in your career, I saw this rethinking national security.
And I was curious how you got into this, I guess,
area, this body of work, and what's the problem you're trying to solve?
Well, the problem we're trying to solve is simple. We're going to kill ourselves.
I mean, right now, I estimate that a child born today has probably worse than even odds
of living out his or her natural life as a result of nuclear weapons, all by themselves,
without climate change, without AI, without any of this other stuff.
What are you talking about with this AI threat?
Well, there's debate on that.
Jeffrey Hinton, Yahshua Benjillo,
who won the Turing Award
for their work in artificial intelligence,
think that AI may actually kill human beings off,
something like that.
I mean, because it'll say,
why do I need these stupid people?
Whereas Ed Feigenbaum and Raj Reddy,
who won the Turing Award 30 years ago
for their work in artificial intelligence,
have both told me and given me permission to quote them,
so I'm not giving any secrets away,
that calling AI an existential threat is ridiculous.
It's science fiction.
I don't know who's right,
but I do know we need to build a more cooperative world
for a number of other reasons,
even if not that one.
So why not solve that one at the same time?
We're likely to build AI into our nuclear command and control system.
I mean, God, what a mess.
So right now, I'm working on a bill.
It's HR 3564,
and we have 25, on paper 24 co-sponsors.
The bill is so bad it's passable, but so good that it's a game changer.
Why is it so bad that it's passable?
It has an exception for launch on warning.
If our warning system show a bunch of ICBMs coming our way,
the president doesn't need a second opinion to launch our nuclear weapons.
He can do so all on his own.
There have been mistakes in our warning system,
So I don't like that.
But that's why it's so bad it's passable.
This makes it easy for people to get on board.
Most people don't realize that the president
can launch a nuclear war all in his own right now.
A president could be awakened to 3 a.m. in the morning
during a crisis, too drunk to legally drive a car,
asked what to do.
He might say drunkenly, ah, nuke them.
And right now, theoretically, the military is supposed to do that.
I didn't consider that AI could be coupled with the nuclear bombs too.
I guess AI could.
Oh, it's likely to be.
I mean, we have this problem that we have just minutes of decision time.
Do you not think we're going to use computers to help us there?
Looking back on your career, I mean, being at Stanford during the growth of computing,
I imagine you had a lot of opportunities to work with other famous folks in the industry.
for instance, Don Canoos.
Oh, Don Cano is a good friend.
Yeah, yeah.
Don Canoos doesn't use email.
I mean, I think he does.
But whenever I want to reach him, I have to call his home and talk to his wife, Jill.
That's the other stories that I have.
John McCarthy and artificial intelligence up the hill.
Witt stayed there, by the way, when we were working on public e-cropography.
Because John was away, and Witt and Mary were taking care of his daughter.
driving her to her writing lessons.
And so Witt just walked down the hills to talk to me.
But John McCarthy, there's a meeting at the Faculty Club
maybe 45 years ago.
And Bob Floyd, who many of your people will know,
who's a famous, he died,
but a famous computer scientist here at Stanford,
John McCarthy comes in, Bob Floyd's in the meeting.
He goes over to Bob Floyd.
I say, hi, John.
He doesn't pay any attention to me
because everybody knows that,
I.O. is a waste of time. And so he's not going to waste time on I.O. So he has a very
rapid exchange with Bob Floyd, and he leaves. Well, I'll tell you another thing. I'm finishing
my, and it's 1968. I've just, several months early in 68, I thought, who am I to think I can make
an original contribution to knowledge, which is the definition of a PhD thesis? I'm thinking
of dropping out of the program.
Over spring break, I basically solve my thesis.
It's that quick.
And so I go to Tom Kover, who's since died, my advisor,
and very famous information theorist.
And I go to Tom and I say,
I just have barely enough units,
but I have enough units to meet the course requirements for the PhD,
but I don't have enough units to meet the PhD requirements.
I'm going to have to take units of research.
If I work at IBM Research, would you give me credit for my units of research?
Because my wife was pregnant with our first child, then we'd been married roughly a year, year and a half.
And so I'm being concerned about money.
And he says, sure.
And so I go to IBM Research, Yorktown Heights.
Oh, Tom wants to have me come teach at Stanford, which I've done.
but he says you really should leave for a couple of years
because Stanford, I sometimes joke
that I had to leave for several years
to lose the taint of the Stanford PhD.
Why is that? Stanford was worried about inbreeding.
If they hired me, I was just going to be doing research
like Tom Cover, and they don't need two of them.
They need somebody different.
And so I went away to IBM for a year
because my thesis broke very suddenly,
and I then taught at MIT for two years
before coming back on the faculty in 71.
And this seemed like just a stupid hoop I had to jump through.
But it actually turned out to be very important
because when I was at IBM, Horst Feistel,
who many people's name may recognize,
he was really the father of IBM's research in cryptography.
He was hired in 68.
He was in the same department as me.
I didn't work in cryptography,
but I had lunch with Horst.
And he told me some of the amazing things
that got me started.
And then when I'm at MIT,
Peter Olias, whose name many people today will not recognize,
but he was one of the original contributors to information theory.
Peter gives me a paper by Claude Shannon,
whose name your audience probably will recognize,
written in 1949, I'm sorry, published in 1949,
in the Bell System Technical Journal,
connecting information theory to cryptography,
which is when I realized that,
oh, I've already done a PhD in information theory,
maybe I can do something worthwhile in cryptography.
So that stupid hoop I had to jump through was actually very important.
Because when I got back to Stanford, I started working in cryptography, among other things.
I think at the beginning of the conversation, you said something quickly that you said you had thoughts on death.
And I was curious, like, you know, what are your thoughts on death and, you know, how does it impact you?
I got an email from somebody at the New York Times about a month ago saying that he's working on an obituary and it made me macabre,
but he was wondering if I could read it over
and if I have any comments.
And so the two things, I'm 80 years old.
So my older brother died just after he turned 80.
My mother died at 70.
My father lived in 98.
I hope I'll have more years.
But if I don't, that's okay.
I've had a great ride.
But the two things that concern me about dying
are the people I'll leave behind
who I think are dependent on me but probably aren't.
And the work I do.
because very few people are working on the nuclear issue,
the growth of humanity as a whole to save itself,
that we're headed for disaster.
Very few people realize that.
And very few people put it in terms of a process of change.
We can't stay where we are, we're going to kill ourselves,
we're going to die.
We can't jump to where we need to go.
The world is too dangerous.
But we can get there via a process of change.
I'll tell you one other thing.
humanity is going to die.
I've come to this real...
I mean, it's clear.
I mean, we might last a million years,
but at some point,
it might last a billion years,
but at some point the sun's going to burn out.
Maybe we'll move to other galaxies
and we'll find ways to cheat death for a while.
But eventually, humanity is likely to die.
But if humanity would have died now,
it would be infant mortality.
It would be really sad.
If we've lived a full life, that's something else.
Like, if I had done it,
when I was a child, people would say, oh, what have we missed? If I die at 80, people will say,
some people will be sadden by it, but they'll feel like I've lived a full life. We need to save
humanity from an infant death. We've only been around about 100,000 years. With all the experience
that you have now, if you could go back to when you addressed graduated college and give yourself
some advice, what would you say?
If when I was just graduating college and I was interested in saving the world, which I was not,
I might have gone up to the top of a mountain to a guru and asked them what to do.
Imagine what you'd say, you'd expect him to tell you work for the UN or something like that.
Imagine what you'd say if he told you, if he told me, forget about saving the world,
which was not a problem because I didn't think about saving the world.
Go out and become as famous as you can, make as much money as you can.
in 10 years and I'll tell you what to do. That would have seemed like a detour. But it was actually
the shortest, the shortest distance between two points because 10 years later when I was 30, 35 years
old and I was interested in saving the world, I had a reputation, I had money, and I had to
screw up to get where I am. I had to not be concerned with the world to become concerned with the
world to be able to do something, to do what I can do about it. Awesome. Well, thank you so much
for your time today. I really appreciate it. You're welcome and thank you.
Hey, thank you for watching this podcast.
If you liked it and you want to see the show grow,
please support with a comment or a like.
Also, if you have any recommendations for people you want me to bring on,
please drop a comment.
Guests like Barbara Liskov, Mike Stonebreaker, Mark Brooker,
these were all people that I brought on because someone left a comment.
On another note, aside from the podcast,
I'm working on building the ergonomic keyboard that I wish existed.
Here's a glance at the prototype.
It's a split keyboard.
So there's two sides.
This is in the case.
But yeah, we launched on Kickstarter and we hit our goal within eight hours of launching.
I really appreciate it if you were one of the people who grabbed one of the early units.
We're now working on the long journey of building the tooling now.
And so if you still want to pick one up, I've left the late pledges open on Kickstarter.
So you can grab one there.
I'll put a link in the description.
Thank you again for watching the podcast.
And I'll see you in the next episode.
