The Moral Character of Cryptographic Work?
📜 Abstract
Cryptography rearranges power: it configures who can do what, from what. This makes cryptography an inherently political tool, and it confers on the field an intrinsically moral dimension. The Snowden revelations motivate a reassessment of the political and moral positioning of cryptography. They lead one to ask if our inability to effectively address mass surveillance constitutes a failure of our field. I believe that it does. I call for a community-wide effort to develop more effective means to resist mass surveillance. I plead for a reinvention of our disciplinary culture to attend not only to puzzles and math, but, also, to the societal implications of our work.
✨ Summary
Summary
Phillip Rogaway argues that cryptography is not politically neutral because it reallocates power: cryptographic systems influence who can communicate, observe, control, or exclude others. The paper develops an ethical argument that cryptographers have responsibilities extending beyond producing technically correct mathematics. They should consider how their research affects human rights, democratic participation, privacy, and the distribution of institutional power.
The essay contrasts two forms of political engagement. Implicit politics arises from the social consequences embedded in technical work, while overt politics involves activism, public policy, and participation in democratic debate. Rogaway situates this argument within the postwar history of scientific responsibility, drawing parallels with physicists’ responses to nuclear weapons, the Nuremberg trials, environmentalism, and professional codes of ethics.
A central criticism is that academic cryptography has become overly inward-looking. The field’s emphasis on elegant formal models, asymptotic results, publication incentives, and speculative constructions has, in Rogaway’s view, marginalized practical privacy problems—especially secure messaging and resistance to traffic analysis. He contrasts “crypto-for-crypto,” work primarily oriented toward disciplinary production, with “crypto-for-privacy,” work intended to protect individuals and communities from surveillance and coercive power.
The paper examines the political tendencies of several cryptographic technologies. Conventional encryption often tends to empower individuals, but system architecture can redirect that power toward content providers or governments. Identity-based encryption can centralize trust in a key-generating authority. Differential privacy can protect individuals while leaving centralized data collection and institutional power largely unquestioned. Fully homomorphic encryption and indistinguishability obfuscation may have privacy-preserving applications, but excessive claims about their near-term utility can obscure the continued weakness of deployed systems and provide political cover for large-scale data collection. Academic cryptanalysis, by contrast, generally serves privacy when it exposes weaknesses before they are exploited against users.
Rogaway frames mass surveillance as a threat not only to personal confidentiality but also to freedom, dissent, journalism, whistleblowing, and democratic change. He contrasts a law-enforcement narrative—privacy as an individual good opposed to collective security—with a surveillance-studies perspective that treats surveillance as an instrument of power and privacy as a social and political good. In this account, pervasive monitoring can produce conformity and inhibit experimentation, opposition, and social progress.
The proposed response is a more socially directed research culture. Rogaway recommends developing secure-messaging systems in the untrusted-server model, big-key cryptography resistant to key exfiltration, anonymous messaging, privacy-preserving broadcast systems, memory-hard password hashing, and defenses against algorithm-substitution and precomputation attacks. He advocates applying practice-oriented provable security to these problems, choosing research topics according to social value, using academic freedom to pursue uncomfortable questions, scrutinizing military funding, and treating ordinary people—not only governments and corporations—as the ultimate constituency for cryptographic research.
He also calls for systems-level engagement. Cryptographers should understand APIs, middleware, operating systems, deployment environments, law, and institutional incentives; use privacy tools such as Signal, Tor, Tails, PGP, and OTR; replace cartoon adversaries with realistic models of intelligence agencies and powerful corporations; and help build decentralized, open cryptographic infrastructure. He proposes terms such as “anti-surveillance research,” “anti-surveillance technologies,” and “conscience-based research” to make the political objective of this work more explicit.
Subsequent influence
The paper’s documented influence is primarily intellectual, educational, and institutional rather than the introduction of a specific cryptographic standard. It was disseminated through a related USENIX Security 2016 presentation, and later scholarship on ethics in mathematics identifies it as an important post-Snowden contribution to discussions of ethical responsibility in cryptography. (usenix.org) A 2025 UC San Diego graduate course on the legacy of the cypherpunks includes the paper in its reading sequence on anonymity, cryptography, and politics, indicating continued use in cryptography and technology-policy education. (cseweb.ucsd.edu) The author’s publication page also records related post-Snowden activities, including work on mass surveillance, an open letter by cryptography and security researchers, and the IACR’s Copenhagen Resolution. (web.cs.ucdavis.edu)