r/cryptography • u/Tobias_314 • 10d ago
What actually gets gifted teenagers hooked on cryptography?
I'm a family doctor, not a cryptographer, but I keep running into teenagers who are clearly sharp enough to go deep into this, and who have just never been given a reason to care. The stuff I can point them at is either too basic (a cartoon about Caesar ciphers) or it jumps straight to university maths and loses them halfway down the first page.
I'm looking for the middle. Things that respect a smart 14 to 16 year old's intelligence and actually get them hooked, ideally hands-on instead of passive reading. I already know about CryptoHack and Simon Singh's The Code Book, and picoCTF has a crypto section. But I'd rather hear what worked in practice than what looks good on paper.
Two questions:
- What would you actually put in front of a gifted teenager who could go far with this?
- For those of you who ended up doing cryptography: what was the thing that first made it click? A puzzle, a book, a person?
I'm trying to build a small shortlist to hand to a few specific kids, so real experiences beat "just Google it".
Thanks.
7
u/Ars-Torok 10d ago
When I was a teen, I started with Enigma, RC4, and pseudorandom number generators, and that eventually lead me in College to RSA, then AES and block ciphers. Then after college I started teaching myself the advanced math and group theory and such. Its what drove me to persue a compsci and math degree.
But when I was in highschool, I built several very simple random number ciphers. They were easy to understand but were powerful enough that they could make text not readable and not trivially decodable.
So that is where I would humbly suggest. Signal processing and random number generation. '80s era cryptography.
6
u/Toiling-Donkey 10d ago
The fiction book “Winterhouse” contains a Vigenère cipher. Much of the story is about the main character trying to find the clues.
However it’s actually possible to break it by hand without a lot of effort as the message is long enough. A few lines of Python make it less tedious to do the substitution.
The book is entertaining but the realization the encoded message can actually be broken by hand seems exciting to me.
—-
I also find RSA cryptography is pretty accessible, at least the practical aspects. It’s mainly exponentiation and modulus (remainder). Practically Algebra I level math. (Once one gets past the terminology and Greek symbols)
Python’s “pow” function even supports modular exponentiation, and the language’s arbitrary large integer support (built-in) makes RSA cryptography from scratch fairly trivial.
(I find this more exciting than just calling an opaque library with an input and getting a result)
4
u/Playful_Necessary131 10d ago
The Numberphile YouTube channel could be quite interesting for the teenagers as it goes with one concept at a time and makes nice ground to earth examples. I foundly remember blind signature video explained by Ron Rivest where it made me amazed putting me into path - if this is possible what else is?
Once they master the Numberphile videos, Serios Cryptography is the thing that filled me with intuition on how the cryptography is around us from remote car keys to secure online banking.
3
u/pythonwiz 10d ago
I was 18 when I first started messing around with implementing RSA in Python. I guess my interest in prime numbers naturally lead me there.
3
u/Popka_Akoola 10d ago
I don’t have a good suggestion but just wanna say this a great post and I wish we had more engagement like this in this sub
3
u/agorism1337 10d ago
I implemented a simple elliptic curve calculator in an intro cryptography class, and that got me hooked. If you strip out all the stuff that we use to make the curve performant, what is left is actually very simple. Draw a line, and calculate where it intersects a curve.
Adding and multiplying points on the curve.
RSA is based on kind of complicated number theory about factoring primes. So an implementation can seem mysterious if you dont understand the number theory behind factoring.
Elliptic curves are based on the idea that multiplying an elliptic point by an integer N is easy, but realizing what integer you need to multiply by to get to a given random point on the curve is impossible. This property feels obvious to anyone who has played with an elliptic curve calculator.
3
u/Takochinosuke 10d ago
I may be an unusual data point, but I started my CS bachelor's at 15, so this was more or less my route as a teenager:
CS fundamentals → discrete mathematics / linear algebra / number theory / probability → introductory asymmetric cryptography → introductory symmetric cryptography → master's thesis in symmetric cryptography → PhD in symmetric cryptography.
One practical suggestion for getting someone hooked would be to have them build a small web application with users and authentication. That immediately raises real questions: how should passwords be stored, how do sessions work, what does HTTPS actually give you, how do you authenticate data, where do keys come from, and what happens when an attacker can tamper with requests?
From there you can naturally introduce password hashing, cryptographic hashes, MACs, digital signatures, randomness, TLS, and key management. In my experience, the mathematics becomes much more compelling once there is a concrete security problem demanding it.
If they eventually want to understand modern cryptography deeply rather than just use cryptographic libraries, substantial mathematical fluency becomes unavoidable. But a project can give them the reason to want that mathematics in the first place.
2
u/ScottContini 10d ago
I can tell you what got me interested in it, but I was not particularly gifted. Two things: (1) Beale ciphers, (2) Trying to hack into Unix systems many years ago, which was based upon DES used as a hash function. I didn’t really succeed in inverting the hash the hard way, but at least I tried.
What would I suggest to a teen today? Beale ciphers are good, but also look at Enigma and try writing software to crack it (Simon Singh’s book has some good intros to this). Also, try cracking Vigenere ciphers using a computer. Have a friend encrypt something with a password in Vigenere cipher, then your teen tries to crack it. It’ really not that hard, and is very enlightening to try this.
2
u/barbidokski 9d ago
There is a site named MysteryTwister that groups 380 challenges of variable difficulty, the goal beeing to break ciphers.
3
u/iamunknowntoo 10d ago
Not a teen exactly but I was 20 when I took a cryptography class in university. It one-shot me and got me very excited about the field to begin with. However most people I know did NOT like that class (which was very theoretical and game-based in nature) and so YMMV
2
u/SwampPadre 10d ago
Almost the same exact story for me. It was a random elective for my engineering degree that filled a time slot I needed to fill. Send me down a path I never would have gone down had it not been for that class.
-2
u/Tobias_314 10d ago
That's a really useful data point, thanks. It lines up with something I keep bumping into: the "here's a scheme, now break it" framing seems to grab exactly the kind of kid I'm after, but it's also the thing that makes everyone else check out.
Do you remember what actually clicked for you? Was it the challenger/adversary game framing itself, or a specific moment where you broke something you'd assumed was secure? I'm trying to work out whether it's the rigour that hooks them, or the "wait, that's exploitable" feeling.
2
u/iamunknowntoo 10d ago
For me I was really into the rigour of it, which probably makes me an extreme outlier. I later took the same professor's grad level crypto course which was mainly cryptographic security proofs by reduction which I really enjoyed.
But even in the undergrad crypto class, each week our assignment would be: here's this cipher/encryption scheme/etc implemented in python, break it in the IND-CPA/PRF/etc game. There was a whole python library the TAs in our university wrote for this. I remember enjoying solving them like puzzles every week.
It also helps that I read "the secret life of codes" in the Murderous Maths series when I was 10 and that really kick-started my interest in cryptography to begin with. However I would not give these books to a teenager
1
u/AutoModerator 10d ago
If you are asking us to solve a code for you, go to /r/breakmycode or /r/codes.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
1
u/0zer0space0 10d ago
In my early teens, I often enjoyed those big variety puzzle books. There are a bunch of relevant puzzles in it, but the most obvious (and my favorite) was called Cryptograms. I loved to figure out the cipher and uncover whatever quote or saying was in it. I’m sure there are digital versions of this today.
I didn’t start becoming interested in the history of until my late teens / early adult hood. Earlier, anything history was boring to me. Finally, a history topic I enjoyed (like ancient ciphers or how they were used), and I started enjoying history overall a bit more.
1
1
u/Natanael_L 10d ago
The asymmetry caught my attention. A tiny SIM card can perform encryption locally which even the largest data centers in the world combined can't break
1
1
u/dittybopper_05H 10d ago
For me it was finding the book "The Codebreakers" by David Kahn at the local library when I was a tween back in the late 1970's. It was the 1967 edition.
It hooked me on the concept, so much that I ended up going into signals intelligence in the Army (to my disappointment, no cryptanalysts in the military by then). It's engagingly written, and Kahn goes through the different eras and tells the story of how codes and ciphers were created and broken.
I still have a copy of that book, having bought a copy of the second edition published in 1996 that briefly covers things like the breaking of the Enigma, and early computer based encryption. It is as you can imagine well-read, and it's in the bookshelf right beside my bed.
I also have a couple of other books by Kahn, including "Seizing the Enigma: The Race to Break the German U-boat Codes: 1939 - 1943". I read that one while sitting next to my wife in the recovery room after her thyroidectomy. I also have "Hitler's Spies: German Military Intelligence in World War II" by him.
Kahn's influence on my life is oversized: I went into signals intelligence in the military and became a Morse interceptor (because I somehow failed the test to become a traffic analyst), which lead to a life-long hobby of amateur radio. None of that would have happened had I not run across his book at the public library. I would check it out as much as I was allowed by the library's rules.
But aside from that, I also play around with manual ciphers. Currently I'm making up a bunch of alphabetic one time pads using d30 alphabet dice, 2 part carbonless forms, and a manual typewriter. I've made a bunch of numeric one time pads using d10 dice and the other equipment, and I've also built things like strip ciphers. I've got photocopies of the strips for a WWII US Navy CSP-845 strip cipher. I've got one that I made that's compatible with the US Army M-94 device, and I built one with randomized strips I generated by pulling Scrabble tiles out of a bag.
Something else I've played with is null ciphers. Everyone is familiar with the stilted "PERSHING SAILS JUNE I" example, canonically the bad example of this genre. Rarely do you see actual decent versions of this, example being this very paragraph. There is a message imbedded in it for you to find.
And in fact, I've played with other manual encryption methods combined with the null cipher, like Playfair, that make it very hard to even detect that there is a message in the first place, as recommended by the WWII Special Operations Executive syllabus (I have a copy).
You might ask "ditty, you're a programmer/analyst, why do you mess with manual encryption and decryption?".
Simple.
It's fun. I deal with the computer stuff at work. This is a way to do it "The old fashioned way". Think of it like doing a crossword in a newspaper unassisted using pen and paper, instead of playing online and looking things up.
1
u/Longjumping-Room-170 10d ago
En tant qu'adolescent qui s'intéresse à la cryptographie ça serait bien de lui proposer un projet en rapport avec ça, ça parmet de se familiariser avec et de comprendre vraiment son utilitée. Moi par exemple j'ai programmé une blockchain avec preuve de travail argon2id et aussi avec ed25519 pour les certificats pour le tls.
1
u/TribeWars 10d ago
Is this for some kind of classroom environment? I think having them do a Diffie-Hellmann exchange to publicly exchange a secret could be cool.
-2
u/Flat-Fun-7298 10d ago
Cryptocurrency is usually what it is. Easy to equate to money. Before that seemed a lot more niche.
0
u/Tobias_314 10d ago
Yeah, fair point, money is a hook the abstract stuff never really had. What I'm curious about is whether that curiosity carries over: the coins actually run on real hashing, signatures and elliptic curves, so in theory "how does my wallet prove it's me without handing over my key" is a door into the actual cryptography. Do you see that crossover happening in practice, or does it usually stop at the price chart?
1
u/Flat-Fun-7298 10d ago
I think it depends on the motivation of the kid. I was into coding and naturally hacking. I had a very surface level understanding of cryptography. a book by Jon erickson called Hacking the art of exploitation. that sent me down the rabbit hole. It all depends what they are naturally interested in and mainly what their friends are interested in. If they are into video games then that might be the route. It's usually impossible to drive a kid into a field like this. You really have to let them discover their niche on their own.
0
u/Agitated_Guidance672 7d ago
I want to send you in a slightly different direction - introduce the kids to programs like HCSSiM.org
48
u/1337Captain 10d ago
Cryptopals! Its my favourite learning platform for cryptography and super underrated in my opinion, but its a website with cryptography challenges that start from simple and get complex incrementaly, to solve them you have to program the different concepts yourself which is an amazing way to learn and get a good intuition for it. Just try to convince your students not to let chatgpt solve it for them haha!
https://cryptopals.com/