Technical Articles
Whitepapers · Cryptography · Security
A running ledger of technical papers on cryptography, randomness, quantum computation, and the security of systems people already depend on. Newest first.
- 2026 · 06 · 29
How to Think in Qubits
A quantum computer does not try every possibility at once. An n-qubit register carries 2ⁿ complex amplitudes, but measurement returns a single n-bit outcome sampled by the Born rule — if all of them could be read out, NP-complete problems would fall, and they have not. The machine evolves one state; the power lies in interference, where amplitudes on wrong answers cancel and amplitudes on the right one reinforce, until a single measurement is overwhelmingly likely to be correct.
- 2026 · 06 · 28
Field Guide to NIST Modes of Encryption
The approved modes are not a menu of equivalent options but a rigorously tested foundation — standardized so that systems interoperate cleanly and so that the vulnerabilities introduced by bespoke, unreviewed constructions never get the chance to appear. Regulatory compliance and consumer trust follow from that discipline, not the other way around.
- 2026 · 06 · 19
Crypto-Grade Entropy Verification
Random number generators are routinely justified by an appeal to physical unpredictability followed by a clean pass through a statistical test battery. That justification is insufficient. Unpredictability is not a property of an output bit string — it is a property of an adversary's uncertainty, and a cryptographic argument must lower-bound that uncertainty.
- 2026 · 05 · 28
Quantum Foundation — Understanding the Bell Inequality
A self-contained guide to Bell's theorem, entanglement, and device-independent randomness, written for readers with a basic background in linear algebra and probability. Derives the CHSH bound algebraically, explains why quantum mechanics violates it, treats entanglement in detail, and closes on the 2026 ETH Zurich demonstration of certified perfect randomness as the concrete application.
- 2026 · 05 · 27
Business Case — Crypto Chip Design with Open-Source Tools
Custom silicon is no longer the exclusive domain of large corporations. A startup with FPGA experience can design a production-grade chip on a free, open-source toolchain and have it manufactured by a world-class foundry through shared-wafer services. For founders willing to pair that engineering discipline with sound commercial judgment, the reward is differentiated, workload-optimized silicon that was, until very recently, out of reach.
- 2026 · 05 · 15
A Friendly Tour of Post-Quantum Digital Signatures
In 2024 NIST finalized its first batch of quantum-safe standards; on 14 May 2026 it advanced nine further digital-signature candidates to a third round of evaluation. A ground-up account of the mathematics behind thirteen of these schemes.
- 2026 · 04 · 25
Vulnerabilities of Human Cognition
The most consequential attack surface of the early twenty-first century is not silicon but neural. Where twentieth-century information warfare targeted communication channels, contemporary adversaries target the inferential machinery that processes those channels — and they do so with industrial precision. Until the vulnerabilities of the human cognitive system are understood, they will keep being exploited.
- 2026 · 04 · 22
How to Play the Security Game
Security is not a state. Security is a game — an unending series of strategic interactions between people with conflicting goals, incomplete information, limited resources, and the capacity to learn from one another. The attacker adapts. The regulator changes the rules. The CFO re-prioritizes. Users find workarounds, vendors externalize their risk onto your balance sheet, and the game continues whether or not you are paying attention.
- 2026 · 04 · 12
Infeasibility of Grover's Algorithm Against AES-128
The familiar claim that Grover "halves the effective key length" is mathematically correct and almost always decoupled from the engineering reality of building, running, and error-correcting the required circuit. Develops from first principles the structure of the algorithm, what it means to implement AES-128 as a quantum oracle, the role of entanglement and coherence throughout, and the concrete resource estimates — logical qubits, physical qubits, circuit depth, gate count, wall-clock time — a realistic attack would demand.
- 2026 · 04 · 02
Cryptography Career Guide 2026
Global cryptography employment reached 1.6 million professionals in 2025, with openings up 47% year over year. For fresh graduates and young professionals entering the field, the T-Model offers a strategy for acquiring skills in the right order rather than a list of certifications to collect.
- 2026 · 03 · 28
Randomness, Entropy, Unpredictability, and Information
There is more to randomness than any one discipline can hold. Most of the confusion around it dissolves once a single uncomfortable fact is accepted: "random," "unpredictable," "entropic," and "nondeterministic" do not name one property of the world.
- 2026 · 03 · 25
AUTOHARDEN — A Hardening Framework for Vehicle Cybersecurity
An implementation-level hardening framework for connected vehicles, closing the gap between high-level regulatory requirements (ISO/SAE 21434, UNECE WP.29 R155) and the configurations that actually defend against demonstrated attack vectors. A seven-layer attack-surface taxonomy catalogues the exposure; a 94-control hardening framework supplies verifiable directives, analogous to CIS Benchmarks for enterprise ICT assets.
- 2026 · 03 · 21
History of Public Key Cryptography
From classified origins in the 1960s through the post-quantum era of today. The narrative is deliberately person-centered — the individuals who made the discoveries, their backgrounds, their education, the contexts that shaped them — because the revolution that transformed how humanity secures digital communication is one of the more remarkable stories in modern science.
- 2026 · 03 · 21
Efficient Online Computation of Health Tests for Entropy Sources
Hardware random number generators underpin cryptographic systems, yet their physical entropy sources degrade, drift with the environment, and can be manipulated by an adversary. Continuous health testing during operation is mandated by every major certification framework, NIST SP 800-90B and BSI AIS 31 among them. This paper asks whether three classical statistics — mean, median, and standard deviation — are viable as lightweight online health indicators for HRNG output streams.
- 2026 · 02 · 15
Taxonomic Framework for Block Cipher Modes of Operation
Modes have proliferated across NIST publications (SP 800-38A through 800-38G), IEEE standards, and the academic literature, leaving practitioners with a bewildering array of choices and no principled basis for selection. The core thesis is simple: every mode that deserves to exist must occupy a unique point in a well-defined requirement space. Two modes at the same point means one is redundant; a universally inferior mode either serves a niche not yet identified, or should be deprecated.
- 2025 · 06 · 15
Smartphone Hacking
Modern Android handsets carry enough sensitive data to attract the full spectrum of threat actors — criminal gangs, advanced persistent threats, state agencies. Since 2020 the South Asian region, India and Pakistan and Bangladesh among others, has seen a surge in real-world attacks running from basic social engineering to sophisticated zero-click exploits.
- 2024 · 12 · 24
Smishing in Pakistan
SMS phishing has become a significant threat in Pakistan, exploiting near-universal mobile use to deceive people into surrendering sensitive information. A survey of reported cases and existing literature identifies the vulnerabilities behind the rise — limited public awareness, inadequate regulatory measures, technological constraints — and proposes mitigations at both the individual and governmental level.
- 2024 · 03 · 01
PQC as It Stands in Industry
The arrival date for quantum computers capable of breaking standard cryptography remains uncertain: IBM targets an inflection point by 2029, QuEra a 10,000-qubit system by 2026. The uncertainty is largely beside the point. Adversaries are already harvesting encrypted traffic for later decryption, and HNDL attacks require no quantum computer at all.
- 2024 · 02 · 08
GNSS as Critical Global Infrastructure
Critical infrastructure takes its time from satellites. An overview of how timing systems work, and of the GNSS dependencies running quietly through the financial, telecommunications, and electric power sectors.
- 2024 · 02 · 07
How to Do Risk Assessments
Risk assessment is not about avoiding risks but about managing them. Root cause analysis is not about blaming others but about learning from mistakes. And neither one is a one-time event.
- 2024 · 02 · 02
When the Stars Fall — Starlink's Apocalypse
If the Starlink constellation were compromised and fell into the hands of rogue elements, the repercussions would reach far past connectivity. Thousands of interconnected satellites, built to provide global internet coverage, suddenly under the control of malicious actors — here is what might unfold.
- 2024 · 01 · 31
Understanding Cyber Warfare Concepts
Cyber warfare is the strategic use of cyber tools and techniques by state or non-state actors to achieve specific objectives, often through harm or disruption to critical infrastructure, systems, or individuals — with consequences that reach national security, the economy, and society. The concepts, defined.
- 2024 · 01 · 25
Speed Optimization of the AES Function
Algorithmic optimization refines the mathematical operations and structures of AES rather than the hardware beneath it. Favouring the algorithmic angle over hardware-specific tricks buys consistent performance across every environment the cipher lands in, from embedded systems to high-performance computing clusters.
- 2024 · 01 · 18
Aging of AES
Adopted by the U.S. government in 2001, AES remains among the most widely trusted methods of protecting data — a symmetric-key algorithm using the same key, up to 256 bits, in both directions. But how secure is it in practice, a quarter century on, against adversaries who want into the systems it guards?
- 2024 · 01 · 17
Trust on Electronic Voting Machines
Electronic voting machines let voters cast ballots without paper or manual counting, and have been adopted widely — in India most of all. The advantages are real: faster results, fewer human errors, improved accessibility. So are the risks, and they reach the integrity of the electoral process itself.
- 2024 · 01 · 04
The StarShield Program
StarShield represents a paradigm shift in space-based communication: security engineered to a different standard, resilience under conditions that break conventional links, and a set of critical advantages for US defense.
- 2024 · 01 · 02
Zero Knowledge — Proof without Privacy Panic
Imagine proving you are over 21 without flashing your ID. Sounds impossible — but zero-knowledge requires no magic, only ingenious cryptography. The concept is transforming how we prove things online, safeguarding privacy while preserving the security guarantee that made the proof necessary in the first place.
- 2023 · 12 · 30
Dark Side of Mega-constellations
Constellations like Starlink leave bright streaks across the sky that interfere with astronomical observation, and their congestion of low Earth orbit raises collision risk and compounds the debris problem that could hinder space exploration outright. The proliferation also carries surveillance and privacy concerns. Global connectivity has a bill attached, and part of it is paid by the sky.
- 2023 · 12 · 29
Absolute Security Does Not Exist
Some believe absolute security is attainable through advanced technology — embedded solutions, the one-time pad, quantum tech. The view ignores the human factor, the complexity of systems, and the unpredictability of threats. There is always a trade-off against usability, always the possibility of error or a malicious insider, always an unknown vulnerability waiting. Security is a continuous process, not a final state.
- 2023 · 12 · 29
The High Cost of Availability in the C.I.A. Triad
Confidentiality yields to encryption and integrity to algorithms; availability yields to nothing cheap. It demands redundancy, jam resistance, backup infrastructure, and careful planning against failure — and the cost climbs with every distinct accessibility requirement of workers and clients. It is the most expensive corner of the triad, and the one most often assumed for free.
- 2023 · 12 · 28
Confidentiality vs Integrity vs Availability — How to Prioritize
Confidentiality keeps data to authorized parties, integrity keeps it unaltered in storage and transit, availability keeps it reachable when needed. Which matters most is a question of context, which is why the experts disagree. In a hospital, unavailable patient data delays life-saving treatment — and availability becomes paramount in a way it never is elsewhere.
- 2023 · 12 · 27
Entity Authentication — The Most Elusive Security Goal
Entity authentication establishes trust by confirming who, or what, is on the other end of an interaction. Its fine-grained properties are what make it robust: liveliness (active participation), identification (accurate recognition), willingness (voluntary engagement), and two-wayness (bidirectional verification).
- 2023 · 12 · 24
The Spy Game That Shook the World
In the audacious secret operation "Rubicon," the CIA and West German intelligence covertly owned Crypto AG, the Swiss firm selling encryption devices to more than 120 countries. Iran, India, Pakistan, even the Vatican — their most secret communications were intercepted and decoded for decades. A monumental intelligence coup, and equally a glaring spotlight on the decision-makers who bought the devices and never detected a thing.
- 2023 · 12 · 23
What Is a Digital Certificate?
A digital certificate is definitive proof of authenticity supplied by a digital signature: the public key of a website or user, bound by the signature of a Certification Authority. Anyone who trusts the CA can verify the signature and thereby validate the key. It is the check your browser performs, silently, on every HTTPS address you visit.
- 2023 · 12 · 22
Quest for Quantum Supremacy
One camp holds that quantum machines capable of threatening classical cryptography are a century away, the technology too complex to reach that level of performance. The other expects RSA and ECC to fall within a decade, on the strength of gains in qubit quality and coherence. Reality probably sits somewhere between the two extremes — which is itself a planning constraint.
- 2023 · 12 · 21
What Is Digital Trust?
One view holds digital trust to be a myth, on the grounds that digital technologies and services are inherently insecure, unreliable, and unethical. But trust is a necessity rather than an option — adoption depends on it. Consumers have a right to expect that their data will be treated with respect, their safety ensured, and their privacy protected.
- 2023 · 12 · 20
Password vs Passphrase
Two schools of thought in cybersecurity. Passwords, a mix of characters and symbols, are traditional, hard to remember, and vulnerable to attack. Passphrases are longer and built from words, more secure for their length and complexity, and easier on the person who has to type them — which is why they keep gaining ground.
· Ledger begins ·