Skip to content

Matt Blaze

Abstract

Matt Blaze was a young researcher at AT&T Bell Labs in 1994 when he showed that the Clipper chip, the government’s design for encryption with a built-in wiretap, could be used with the wiretap switched off, because the field that let the government in was protected by a 16-bit checksum. The paper landed on the front page of the New York Times and the Clipper chip was dead within two years. He has spent the three decades since finding the flaw in whatever the state or the market proposes as secure: escrowed keys, short key lengths, master-keyed locks, telephone wiretap equipment, voting machines, client-side scanning. He wrote CFS, an early encrypting file system for Unix, co-authored the 2015 “Keys Under Doormats” report that answered the second crypto war, co-founded the DEF CON Voting Village, joined the board of the Tor Project, and, having registered crypto.com in 1993 because it was available, sold it in 2018 for a sum reported at between $5 million and $10 million.

Matt Blaze
Matt Blaze at DEF CON 20, 2012. Image: DEFCONConference, CC BY 3.0, via Wikimedia Commons.

Hunter to Princeton

Matthew Blaze took a computer-science degree at Hunter College in New York in January 1986, a master’s at Columbia in 1988, and a doctorate at Princeton in January 1993 with a thesis on caching in large distributed file systems. He joined AT&T Bell Laboratories in Holmdel, New Jersey, as a founding member of its secure-systems research department, and his first product, written in 1992, was the Cryptographic File System, CFS: a layer over the Unix file system that encrypted files and their names transparently, with the key attached to a directory and held only while that directory was mounted, so that a stolen disk or an NFS server saw only ciphertext. He presented it at the first ACM Conference on Computer and Communications Security in November 1993 and gave the code away; it was later ported to Linux, and the shape of it (a key per directory, encryption below the file-system interface, backups that work without the key) reappears in the encrypting file systems that followed.

The Clipper Chip

In April 1993 the Clinton administration announced the Clipper chip, an encryption device for telephones designed by the NSA and built by Mykotronx. Its cipher, Skipjack, used an 80-bit key and was classified. Before two Clipper chips would talk, each sent a 128-bit Law Enforcement Access Field, the LEAF, containing the chip’s serial number and the current session key encrypted under a unit key that was split between two government agencies. A wiretapper with a court order could decrypt the LEAF, ask the agencies for the two halves of the unit key, and read the call. AT&T, Blaze’s employer, was the only company ever to ship a Clipper product: its TSD-3600 telephone encryptor had been designed around DES in 1992, and the government persuaded AT&T to replace DES with Clipper, bought a quantity of the resulting TSD-3600E at over $1,000 each, and the original DES models were recalled.

Blaze and his colleague Steven Bellovin took notes when an NSA delegation briefed Bell Labs, asked half-jokingly whether they could post a summary to Usenet, were told yes, and did. A week later the NSA invited Blaze to Fort Meade and sent him home with prototype PCMCIA cards, code-named Tessera, that carried the Capstone chip, a Clipper with public-key extras and an open programming interface. The NSA asked only that he play with it, and agreed that he could publish.

The question he chose was how the chip enforced the escrow. A receiving chip would not decrypt until it had been handed a valid LEAF, and the validity check rested on a checksum inside the encrypted field. By feeding the card candidate LEAFs and watching which ones it accepted, Blaze established that the checksum was 16 bits long. A rogue device could therefore generate random LEAFs until one passed, about 65,536 tries, and send that to its peer: the peer would accept it, the two would talk under full-strength Skipjack, and a wiretapper decrypting the LEAF would find garbage. “The only thing stopping you was a 16 bit exhaustive search, a very low barrier even in 1993,” he wrote later.

He wrote “Protocol Failure in the Escrowed Encryption Standard” in April 1994, sent a copy to his NSA contacts so as not to blindside them (they were, he said, “extremely good natured about it”), and submitted it to the ACM’s November conference. Someone sent it to John Markoff of the New York Times. Blaze went to management expecting trouble, since he was an employee of the company whose product he was breaking; some AT&T executives wondered why “some kid in the troublemaking, out-of-control research lab” thought publishing was a good idea, but Bell Labs research management backed him. The story ran on 2 June 1994 under the headline “Flaw Found in Federal Plan for Wiretapping”. Blaze could not find it in the paper until he looked at the top of the front page. Few outside the government bought the phones, and by 1996 Clipper was abandoned. In 1998 the NSA declassified Skipjack, the first cipher of its own design it had ever published (see The Crypto Wars of the 1990s).

Key Lengths and Key Recovery

The crypto war continued with export rules rather than chips, and Blaze became one of the standing signatories of the cryptographers’ side. In January 1996 he, Whitfield Diffie, Ron Rivest, Bruce Schneier, Tsutomu Shimomura, Eric Thompson and Michael Wiener published “Minimal Key Lengths for Symmetric Ciphers to Provide Adequate Commercial Security”: 40-bit keys, the export ceiling, offered “virtually no protection”, 56-bit DES was falling to FPGAs, and new systems should use at least 75 bits now and 90 bits to last twenty years. In May 1997 eleven authors, Blaze among them with Hal Abelson, Ross Anderson, Bellovin, Josh Benaloh, Diffie, John Gilmore, Peter Neumann, Rivest, Jeffrey Schiller and Schneier, issued “The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption”, which argued that any government-access scheme, whatever the name, added a new path to the plaintext, a high-value target, and costs nobody had estimated; a 1998 revision found “its essential finding remains unchanged and substantively unchallenged”. By the end of the decade the export rules were relaxed and key recovery was dropped.

At AT&T he also worked on the machinery rather than the politics: swIPe, an IP-layer encryption protocol with John Ioannidis that preceded IPsec, remotely keyed encryption, and, with Joan Feigenbaum and Jack Lacy, trust management, the idea that a security system should be handed a signed policy and a request and decide whether the credentials satisfy the policy, rather than consulting a fixed list of names. PolicyMaker (1996) and KeyNote (RFC 2704, 1999) were the two languages.

Locks and Safes

In 2003 Blaze, by then at AT&T Labs-Research, applied the same habit to hardware that predates computing. “Rights Amplification in Master-Keyed Mechanical Locks” observed that a master-keyed pin-tumbler lock, the kind that lets a janitor’s key open every door in a building while each tenant’s key opens one, is an oracle: each pin position has one cut for the tenant key and one for the master, and a tenant who files a few blank keys and tries them in their own lock can find the master cut at each position in turn, one pin at a time. A working master key for the building follows from one lock and one key, a metal file and a handful of blanks. John Schwartz put it in the New York Times on 23 January 2003. Schlage’s Lloyd Seliber said “this has been true for 150 years” and that he taught it to locksmiths; the security consultant Marc Weber Tobias said it was serious and simple enough that “an idiot could do it” and rewrote his police guide. Blaze’s answer to the complaint that he had told the burglars: “There’s no way to warn the good guys without also alerting the bad guys. If there were, then it would be much simpler; we would just tell the good guys.” The follow-up, “Safecracking for the Computer Scientist” (2004), is a survey of manipulation attacks on combination locks, offered as a lesson in how a mature industry rates its own products, something he thought computer security had yet to learn.

Wiretaps

Blaze moved to the University of Pennsylvania in 2004 and turned to the eavesdroppers’ own equipment. With Micah Sherr, Eric Cronin and Sandy Clark he examined the “loop extender” gear that police used to tap analogue telephone lines and the newer CALEA interfaces, and found in 2005 that the recorder could be controlled by the person being tapped. The equipment listened for an in-band “C-tone” to learn that the target had hung up and stopped recording. A target who played a continuous low-level C-tone under their own conversation muted the tap for the duration of the call. The same in-band signalling let a target confuse the pen register’s log of dialled numbers. The paper’s recommendation was that wiretap evidence be checked against the phone company’s own records. The following year his students Gaurav Shah and Andres Molina showed the JitterBug, a keyboard sniffer with no network connection that leaked what it had captured by delaying keystrokes by tiny amounts, readable from the timing of the victim’s SSH packets anywhere on the path.

Voting Machines

In 2007 California’s Secretary of State, Debra Bowen, commissioned a “top-to-bottom review” of the state’s electronic voting systems, 42 researchers examining products from three vendors. Blaze led the eight-person team, working in a locked and monitored laboratory at Berkeley, that read Sequoia’s source code, more than 800,000 lines, in under two months. Nothing they found looked like sabotage; the report lists “elementary mistakes: static cryptographic keys, unsecured interfaces, poorly validated inputs, buffer overflows”. On 3 August 2007 Bowen decertified the three vendors’ systems and recertified them only under new conditions for the 2008 elections. That autumn Ohio’s EVEREST study, run between October and December 2007 by teams from Penn State, Penn and WebWise, reached the same conclusion about the machines used there.

The obstacle to that kind of work was legal as much as technical: examining voting-machine firmware meant circumventing copy protection. In 2015 Blaze, Bellovin, J. Alex Halderman, Nadia Heninger and Andrea Matwyshyn petitioned the Library of Congress for a security-research exemption to section 1201 of the DMCA, and got it. The exemption made the DEF CON Voting Village possible: in July 2017 Blaze, Harri Hursti, Jake Braun and Maggie MacAlpine put second-hand voting machines in a room in Las Vegas and let the conference at them. The first, an AVS WinVote, was taken over across Wi-Fi within about ten minutes, and every machine in the room was compromised over the weekend by people who had never seen one before. The village has run every year since, with reports co-authored by Blaze, Joseph Lorenzo Hall and Hursti, and Blaze chairs its board. He testified to the House Administration Committee on election security in 2020.

Doormats and Pockets

The crypto war returned after the Snowden disclosures (see Edward Snowden and the NSA) as a demand for “exceptional access” to encrypted phones and messaging. On 6 July 2015 the eleven 1997 authors, joined by Matthew Green, Susan Landau, Michael Specter and Daniel Weitzner, published “Keys Under Doormats: Mandating Insecurity by Requiring Government Access to All Data and Communications”, whose title carried the argument: a key that opens only for the police does not exist, and “the damage that could be caused by law enforcement exceptional access requirements would be even greater today than it would have been 20 years ago”. Seven months later the FBI took Apple to court over a locked iPhone and made the same arguments as in 1993. When the proposal changed shape again, to scanning content on the device before encryption, the group answered with “Bugs in Our Pockets: The Risks of Client-Side Scanning” in October 2021.

Blaze’s 2011 retrospective on Clipper had already noted the number that undercut the fear: the federal wiretap report for 2010 listed 3,194 court-ordered intercepts, six of which encountered encryption, none of which were defeated by it. Police, he argued, adapt, and the cleartext is nearly always available somewhere on a general-purpose computer. The other half of his 1990s argument was confirmed in 2024, when the Chinese state group known as Salt Typhoon was found inside the systems that US carriers use to fulfil CALEA wiretap orders, the lawful-access door being used by an unlawful visitor. Blaze testified about it to a House Oversight subcommittee on 2 April 2025.

Georgetown, Tor and a Domain Name

In July 2016 the whole board of the Tor Project resigned in the aftermath of the Jacob Appelbaum affair and named its successors, Blaze among them alongside Cindy Cohn, Gabriella Coleman, Linus Nordberg, Megan Price and Schneier. In January 2019 Georgetown announced that he would hold the McDevitt Chair in Computer Science and Law, a joint appointment between the computer-science department and the law school, after fourteen years at Penn.

The domain was a footnote that became a headline. Blaze registered crypto.com in 1993, when “crypto” meant cryptography and the name was free, and used it for his papers. As cryptocurrency grew he added a notice that the site “does not trade in or provide services related to cryptocurrencies” and advised readers that many of them were scams, told The Verge in March 2018 that the name was not for sale, and in July 2018 sold it to Monaco, a Zug-based payment-card start-up, under a non-disclosure agreement. Domain brokers estimated the price at $5 million to $10 million; the company renamed itself Crypto.com.

Dead End

Key escrow is the dead end that keeps being rebuilt. Clipper’s only product was a telephone attachment that the government had to buy itself; the checksum flaw was the least of it. Blaze’s own postscript is that the scheme would have failed had the LEAF been perfect, because it required expensive hardware just as software cryptography was becoming free, and because it created a database of everyone’s keys that any adversary would value above every individual wiretap. Key recovery (1997), the Apple order (2016), client-side scanning (2021) and the successive “lawful access” bills have each been answered by the same group of authors with the same finding, and the Salt Typhoon intrusion of 2024 was a demonstration of what the 1997 report had predicted: the access system built for the police was the one the adversary used.

📚 Sources