Q&A: web cryptography pioneers Martin Hellman, Taher Elgamal, and Tom Jermoluk on recent advances in authentication tech, and what the future could look like
Martin Hellman, Taher Elgamal, and Tom Jermoluk were instrumental in shaping how the Internet works. Now they're looking at what's next for web security. Tweets: @ieeespectrum Tweets: IEEE Spectrum / @ieeespectrum : Three pioneers who helped make the Internet secure to use weigh in on where web cryptography is headed next. https://spectrum.ieee.org/...
Context & Ripple Effects
This Q&A arrives at an inflection point for the field these three built. Martin Hellman's standing was cemented by the $1M Turing Award he shared with Whitfield Diffie in 2016, and Taher Elgamal and Tom Jermoluk were central to making the web usable over insecure networks — so when IEEE Spectrum asks them about authentication, they are auditing their own architecture.
The timing matters because the standards landscape is unsettled: the coverage trail runs through the competition to develop new encryption standards against quantum-computing attacks, the phasing out of SHA-1 that left older devices in the developing world exposed, and David Chaum's contested PrivaTegrity scheme with its carefully controlled backdoor. A joint outlook from the founders is a signal about which of those directions deserves institutional trust.
First-order effects
- IEEE Spectrum's readership gets a first-hand assessment of recent authentication advances from the people who designed the underlying public-key machinery, rather than from vendors selling replacements.
- Hellman, Elgamal, and Jermoluk put their reputational weight behind a specific view of what comes after current web security — a scarce commodity in a debate crowded with competing standardization efforts.
Second-order effects
- Their framing feeds directly into the ongoing contest to replace RSA-era methods with quantum-resistant alternatives, giving policymakers and standards bodies an authoritative reference point when weighing candidates.
- Enterprises still running legacy algorithms get a credibility check on migration urgency — echoing how the SHA-1 retirement stranded users on old browsers and devices.
Third-order effects
- If the pattern holds, transitions in web cryptography increasingly run through founder-level consensus before regulators and agencies act — consistent with how US agencies have already begun preparing for attackers who harvest data now for later decryption.
- The field's direction is being set by a small founding generation whose judgment functions as informal governance over which successor protocols achieve legitimacy.
The trend: Web cryptography is entering a succession moment, with the transition to quantum-resistant authentication shaped as much by its founders' endorsements as by formal standards competitions.