up:: Foundations MOC

What Came Before Digital Trust?

Long before anyone typed a password, people needed a way to prove that a message was genuine and had truly come from whoever it claimed. A king pressed his signet ring into hot wax at the foot of a charter, and everyone who received it understood two things at once: that the order was really his, and that no hand had altered a word of it since the wax set. That small act, a private object making a public mark anyone can recognize and no one can counterfeit, is the ancestor of nearly everything that keeps the modern internet trustworthy. The cryptography has been rebuilt many times since, and the idea underneath it has held steady for thousands of years.

This matters because the primitives that secure your bank connection can feel like alien machinery invented by mathematicians in the 1970s, when in truth each one is a very old human answer to a very old human problem, rendered in math instead of wax and metal. Once you see the lineage, the digital signature, the certificate authority, encryption, and the infrastructure of trust behind the padlock stop being abstractions and become the latest chapter of a story that runs back 2,500 years.

The seal a whole kingdom agreed to honor

The signet ring is the oldest of these ideas still in daily use. In the ancient world a person of standing carried a ring carved with a unique device, and pressing it into clay or wax produced a mark that stood in for their identity and their consent.1 The power of the ring came from a split a modern cryptographer would recognize instantly: the impression was public, seen by anyone who handled the document, while the carved matrix that produced it stayed private, worn on one person’s hand. Anybody could recognize the seal, and only its owner could make it.

That split is exactly what a digital signature rests on today. A private key stays with one holder, a public key is shared openly, and the math lets everyone verify a mark only the private-key holder could have produced. The seal proved three things a signature still proves: that a message came from its claimed author, that the contents were unaltered, and that the author could not later disown it. The ancient world leaned hard on that last property. The Book of Esther records a decree written in the king’s name and sealed with the king’s ring, and states plainly that such an order could not be revoked, precisely because the seal made its origin undeniable.2 That is non-repudiation, described 2,000 years before the word existed.

Recognizing whose seal sat in the wax was its own act, the one we now call authentication. A sentry who knew the royal crest could believe a rider carried the king’s authority without ever having met the king, because the seal, rather than the messenger’s face, carried the proof. The danger then is the danger now: the seal proves control of the ring and says nothing about whether the ring was stolen, which is why a valid credential in the wrong hands has always been the quiet failure of trust systems.

A single ring only scales so far. Kingdoms and merchant networks needed seals that strangers across a whole territory would honor on sight, so authority flowed downward through them. A monarch’s great seal authenticated the officers who acted in the crown’s name, and those officers’ seals authenticated the documents beneath them.3 That hierarchy of vouching is the certificate authority in everything but name. A root authority everyone already trusts vouches for intermediaries, who vouch for the ordinary certificates your browser meets, and you believe a website you have never seen because you can trace its seal upward to one you already honor.

Scrambling a message so only the right eyes could read it

Proving who sent a message is one problem, and keeping its contents from anyone who intercepts it is another, just as old. The Spartans are said to have wrapped a strip of leather around a rod of fixed thickness called a scytale, written across the wound strip, then unwound it into a jumble that only an identically sized rod could realign, though historians debate how much genuine secrecy the device actually delivered.4

The decisive leap came in 1467, when Leon Battista Alberti described two concentric disks that could be rotated against each other to swap one alphabet for another partway through a message, a design so influential that historians of cryptography call him the father of the Western tradition.5 Turning the inner disk made the same letter encipher to something new, which defeated the frequency analysis that had cracked simpler ciphers for centuries. About 300 years later Thomas Jefferson built the same principle into a stack of lettered wheels, a wheel cipher good enough that a close descendant stayed in United States military service well into the 20th century.6

Every one of those devices did what encryption does now. Each transformed a readable message into something useless to anyone lacking the secret setting, whether that setting was the rod’s diameter, the disk’s rotation, or the order of the wheels on their spindle. The modern version swaps a mechanical setting for a mathematical key and a hand-turned disk for an algorithm like AES, and the shape is unchanged. Anyone may see the scrambled text, and only the holder of the key can turn it back into words.

The courier you had to trust

Here the ancient world hit the wall that shaped modern cryptography most of all. A cipher is only as safe as the secret both sides share, and for most of history that secret had to travel, carried by a courier who could be bribed, captured, or turned. Diplomats sealed dispatches in locked pouches and swore their couriers to secrecy, and America’s founders wrote to each other in cipher on the working assumption that couriers and the mails could be intercepted.7 The unglamorous truth of pre-modern secret communication is that the whole system’s safety came down to whether you could trust the person carrying the key.

That is the key-distribution problem, and it is the exact problem public-key infrastructure and modern key exchange were built to retire. Public-key cryptography lets two strangers agree on a shared secret over a line anyone can hear, so the secret never has to ride in a pouch at all. PKI answers the companion question the sealed courier also raised, whether the crest on the seal was authentic in the first place. It binds a public key to a verified identity through a chain of trusted signatures, so you can trust a stranger’s key the way a medieval clerk trusted a seal he recognized. The courier you once had to trust became math you can verify for yourself.

The same primitives, carried into math

Line the two eras up and the correspondence is nearly one-to-one.

Physical ancestorWhat it provedDigital descendant
A signet ring pressed into waxThis is genuinely from me, and unalteredDigital signature
Recognizing whose seal it isYou are who you claim to beAuthentication
A royal seal a whole realm honorsA trusted authority vouches for thisCertificate authority
The scytale and the cipher diskOnly the right eyes can read thisEncryption
The sealed courier and the trusted crestTwo parties can share a secret safelyPKI and key exchange

The digital versions are stronger than their ancestors, because their security rests on mathematics rather than the loyalty of a courier or the difficulty of hand-carving a ring. The jobs themselves are identical, which is the useful thing to hold onto. When a vendor or a standards body talks about signatures, certificate authorities, and key exchange, they are describing the maintenance of an apparatus humans have relied on since antiquity, now running under every login and payment on earth.

Why quantum is a threat to trust itself

Seeing the lineage makes the quantum threat land where it actually falls. The popular telling is that quantum computers will “break encryption,” which sounds like a danger to secrecy alone. The deeper exposure is to the seal. A quantum computer running Shor’s algorithm can reconstruct a private key from the public key everyone already holds,8 which in the language of this essay means carving a perfect copy of the signet ring from the public impression alone. An attacker who can do that gains far more than the ability to read a scrambled message. They can seal fraudulent orders that every sentry in the kingdom will honor, because the seal is authentic and only the ring was ever supposed to make it.

That is why the migration matters beyond the mathematics. What is at stake is the 2,500-year-old apparatus for proving that a message is genuine and its sender is real, an apparatus now carrying the entire digital economy. Certificate authorities are the royal seals of the internet, and a forged one would let an attacker impersonate any institution at will, the failure the Guide covers as PKI collapse. The work of the post-quantum transition is to recut every one of these seals in math a quantum computer cannot copy, and to finish before anyone builds the machine that could.

The reassuring part of the history is that humanity has changed the medium of trust several times, moving from clay to wax to metal to mathematics, and the apparatus survived each move because people understood what it was for. This is one more of those moves. Understanding the lineage is how a decision-maker stops treating the transition as a niche cryptographic errand and starts treating it as the upkeep of trust itself, which is exactly what it is.


Everything here is the map, given freely. When your team needs the trust layer behind its own systems found, understood, and carried safely into its post-quantum form, that’s the work I do.

Last verified 2026-07-26 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.

Footnotes

  1. On seals and signet rings as marks of identity and authenticity in the ancient world, see Encyclopaedia Britannica, “Seal (identification device),” britannica.com/topic/seal-identification-device. The practice of impressing a carved seal to authenticate documents runs from Mesopotamian cylinder seals through Greek and Roman signet rings.

  2. The Hebrew Bible, Book of Esther 8:8: “for the writing which is written in the king’s name, and sealed with the king’s ring, may no man reverse.” The passage ties the king’s seal directly to an order’s irrevocability, the ancient form of non-repudiation.

  3. On the great seal as the instrument authenticating acts done in a sovereign’s name, and its delegation through subordinate seals, see The National Archives (UK), “Great Seal,” nationalarchives.gov.uk. The hierarchy of a paramount seal vouching for lesser ones is the structural ancestor of the certificate-authority chain of trust.

  4. Plutarch, “Life of Lysander,” 19, describes the Spartan scytale. Simon Singh, The Code Book, 1999, recounts it as an early transposition device; Thomas Kelly, “The Myth of the Skytale,” Cryptologia 22:3, 1998, doi.org/10.1080/0161-119891886902, argues its use as a cipher may be a later interpretation, which is why the claim is hedged.

  5. David Kahn, The Codebreakers: The Story of Secret Writing, Macmillan, 1967, names Leon Battista Alberti (whose 1467 treatise De componendis cifris introduced the cipher disk and polyalphabetic substitution) “the Father of Western Cryptography.” Also Simon Singh, The Code Book, 1999, chapter 1.

  6. Thomas Jefferson Foundation, “Wheel Cipher,” Monticello, monticello.org/research-education/thomas-jefferson-encyclopedia/wheel-cipher/. Jefferson’s design (c. 1790s) was independently reinvented and adopted by the U.S. Army as the M-94, in service from 1922 into the World War II era.

  7. David Kahn, The Codebreakers, Macmillan, 1967, on cryptography among the American founders, including the ciphers used by Thomas Jefferson, James Madison, and the Continental Congress’s Committee of Secret Correspondence, adopted because couriers and the postal system were assumed to be compromised.

  8. P. Shor, “Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer,” SIAM Journal on Computing, 1997, quant-ph/9508027.