The Written History of Bitcoin, Part 0: Pre-History

By Kurt Wuckert Jr.

A Post in the Archive

In September 1996, a message appeared on the cypherpunks mailing list from a user calling themselves "Doshai." The subject line concerned banking over the internet. The post was technical and ahead of its calendar by at least a decade. It described problems with online financial systems that most engineers wouldn't encounter for years: the trust model of intermediaries, the necessity of cryptographic proof in place of institutional authority, the structural requirements for moving money across networks without a central chokepoint.¹

The post sat quietly in the mailing list archives, where it remains today. You can still read it. File that name away. We'll come back to it.

Watch the companion video here:

But to understand why that post matters, we have to go back further. Twenty years further, to a time before Big Banks, Big Tech and Big Government were collectively and actively killing Satoshi, his history and his evention: bitcoin.

Timeline of cryptographic innovations from 1976 to 2008, showing the building blocks that eventually became bitcoin

Timeline of cryptographic innovations from 1976 to 2008, showing the building blocks that eventually became bitcoin

The Key Exchange

In November 1976, two Stanford researchers named Whitfield Diffie and Martin Hellman published a paper in the IEEE Transactions on Information Theory titled "New Directions in Cryptography."² The paper solved a problem that had constrained every cryptographic system in history: how do two people create a shared secret when they've never met and every channel between them is being watched?

Every previous answer required a trusted courier or a sealed diplomatic pouch. Diffie and Hellman proved, mathematically, that two people could construct a shared key over a completely open channel and that anyone eavesdropping on every single exchange would still be unable to derive the key.

This sounds abstract until you realize what it unlocked. Before this paper, encryption was the exclusive domain of governments and militaries, organizations that could afford to distribute keys through secure physical channels. After this paper, encryption belonged to anyone with a computer and an afternoon to read the math.

Everything that follows in this story traces back to that 1976 paper, which ran eleven pages in a journal that most people outside academia had never heard of.

Trees and Blindfolds

Three years later, in 1979, Ralph Merkle filed a patent for a data structure called a hash tree.³ The concept was elegant: organize data into a tree where every parent node is a hash of its children, building up to a single root hash that represents the entire dataset. If any piece of data changes, the root hash changes. There are lots of applications of this idea, but the part that matters for our story is that with this, you can prove that a specific piece of data belongs to the set by providing a short path through the tree, without downloading the whole set of data.

File that concept away, but don't forget it. When Satoshi Nakamoto wrote Section 8 of the Bitcoin whitepaper, describing how ordinary users could verify their own transactions without running a full node, the mechanism he described was Merkle's hash tree. The mechanism that was supposed to make bitcoin usable by everyone, from a phone in a coffee shop, was invented in 1979.

In 1982 and 1983, Chaum published the theoretical work that invented digital cash.⁴ His key insight was a technique called blind signatures: a way for a bank to sign a digital token without ever seeing what it was signing. The result was money that was both verifiable (the bank's signature proved it was real) and untraceable (the bank couldn't link the signed token back to the person who requested it).

Chaum had built something remarkable: digital cash with real privacy. But he had a blind spot: His system required a bank. The cash was private, but the infrastructure was centralized. A single company had to operate the system, and every token's validity depended on that company staying alive.

We'll see exactly what happens when that company dies, and what lesson its bankruptcy teaches everyone who comes after.

The Manifestos

Excerpt from The Crypto Anarchist Manifesto, Tim May, 1988, distributed at the Crypto '88 conference

Excerpt from The Crypto Anarchist Manifesto, Tim May, 1988, distributed at the Crypto '88 conference

In September 1988, at the Crypto '88 conference in Santa Barbara, a former Intel physicist named Tim May handed out a single page of text titled "The Crypto Anarchist Manifesto."⁵

The document reads like prophecy. May predicted anonymous digital cash, untraceable communications, encrypted markets for information, and the collapse of government control over information flows. He wrote it in language borrowed from Marx, deliberately, because he was making an argument about the inevitability of technological change: the tools were coming whether anyone wanted them or not, and the political consequences would be enormous.

Five years later, he would put his ideas to the test. In 1993, May demonstrated "BlackNet," a proof-of-concept anonymous information market where anyone could buy or sell secrets and data with no identity attached. It was a demonstration, not a real product, but it terrified the intelligence community enough to generate government attention. May's point was simple: the technology already exists, and banning it is like banning math.

Meanwhile, David Chaum had moved from theory to practice. In 1989, he founded DigiCash in Amsterdam.⁶ Banks signed licensing agreements. Real trials ran with real digital dollars. For a brief moment, it looked like the future of money had arrived. But there were snakes in the grass around Chaum...

And then, in 1991, Phil Zimmermann lit a different kind of fire.

Zimmermann was a software developer in Boulder, Colorado, who believed that ordinary people deserved the same encryption tools that governments used. So he wrote PGP, Pretty Good Privacy, and released it for free on the internet.⁷

The United States government responded by treating Zimmermann like an arms dealer. A federal criminal investigation lasted three years. The legal theory was that exporting strong encryption software constituted illegal arms trafficking under the International Traffic in Arms Regulations. Zimmermann's defense was simple: code is speech. The First Amendment protects it. The case became the rallying point for an entire movement, and the government eventually dropped the investigation. But the fight established a principle that would matter for everything that came after: publishing cryptographic software is a protected act.

The Timestampers and the Proof

That same year, 1991, two researchers at Bellcore, Stuart Haber and W. Scott Stornetta, published a paper in the Journal of Cryptology called "How to Time-Stamp a Digital Document."⁸

Their system chained cryptographic hashes together sequentially so that no document could be altered after the fact without breaking the chain. If you changed a single byte in any timestamped document, the chain of hashes from that point forward would become invalid. The chain was its own proof of integrity, a ledger that audited itself every time a new entry was added.

This is the most directly cited work in the Bitcoin whitepaper. Satoshi cited Haber and Stornetta three times, more than any other source. Their concept of hash-linked chains was the structural model for the blockchain itself.

There's a detail that makes this part of the story strange and beautiful. Haber and Stornetta needed a public, immutable place to anchor their hash chains, and digital public databases weren't permanent enough for the job. They needed a record that no one could alter or delete after publication. Their solution? They published their hash digests in the classified ads of the New York Times.

Every week, a small ad appeared in the paper: a string of characters that meant nothing to anyone who saw it but served as an unforgeable timestamp for every document in their system. The world's most advanced cryptographic timestamping service, anchored to a newspaper. The old world's most trusted record, the printed page, serving as the trust anchor for the new world's trustless systems.

The Bitcoin whitepaper's references section with Haber and Stornetta's three citations highlighted

The Bitcoin whitepaper's references section with Haber and Stornetta's three citations highlighted

A year later, in 1992, two more researchers gave the story its next ingredient. Cynthia Dwork and Moni Naor published "Pricing via Processing or Combatting Junk Mail" at the CRYPTO '92 conference.⁹ Their idea was aimed at email spam: what if sending a message required a small computational cost? Not enough to notice for a single email, but enough to make blasting millions of messages economically irrational.

They had invented proof of work. They didn't call it that, and they had no idea what it would become.

The List

In late 1992, Tim May, Eric Hughes, and John Gilmore organized a mailing list for people who wanted to build, not just theorize.¹⁰ The list was called "cypherpunks," and it became the gathering place for the minds who would spend the next fifteen years constructing the building blocks of programmable money.

In March 1993, Eric Hughes published "A Cypherpunk's Manifesto."¹¹ It opens with a line that defines the movement: "Privacy is necessary for an open society in the electronic age." Hughes drew a sharp distinction between privacy and secrecy: privacy is the power to selectively reveal yourself to the world. Secrecy is hiding everything. The cypherpunks wanted privacy, specifically through code, not through laws.

The mailing list archives are primary source material for everything that follows in this series. The posts are archived, searchable, and frequently surprising in their specificity. The people on this list were not speculating about the future. They were building it, one piece at a time, arguing about the details in public.

The Contenders

Comparison table showing eCash, b-money, Bit Gold, KARMA, RPOW, and Bitcoin across key properties: centralized vs. decentralized, proof of work, double-spend solution, and deployment status

Comparison table showing eCash, b-money, Bit Gold, KARMA, RPOW, and Bitcoin across key properties: centralized vs. decentralized, proof of work, double-spend solution, and deployment status

On March 28, 1997, a British cryptographer named Adam Back announced Hashcash to the cypherpunks mailing list.¹² Back took Dwork and Naor's proof-of-work concept and applied it: a specific system where you prove you burned CPU cycles by finding a hash with a certain number of leading zeros. The work is hard to do and trivial to verify. Hashcash was designed to fight spam, but Back never built a currency on top of it.

However, the mechanism he described, partial hash collision as proof of computational expenditure, is the exact premise upon which bitcoiners would later call "mining." When miners search for a hash below a target value, they are running a brute-force sequence based on Adam Back's 1997 invention.

In November 1998, Wei Dai published a theoretical blueprint called "b-money" on the cypherpunks mailing list.¹³ It described a decentralized digital cash system where money creation was tied to proof of work and transactions were broadcast to all participants. Dai laid out two protocols. The first required every participant to run a node and maintain a complete database of account balances, which he acknowledged was impractical at scale. The second introduced the idea of a smaller set of "servers" who maintain the ledger while everyone else verifies their work.

Dai acknowledged that his system had unsolved problems. The honest accounting of what he didn't know is one of the things that makes his paper worth reading carefully. Bitcoin solves several of b-money's open questions with elegant solutions, and Satoshi references Dai for his brilliance and his humility.

Around the same time, in 1996 and refined through 2004, a financial cryptographer named Ian Grigg developed what he called Ricardian Contracts.¹⁴ Grigg's innovation was a system for writing financial contracts that were simultaneously human-readable (a legal document anyone can understand), machine-readable (software can parse and execute them), cryptographically signed (they can't be forged or altered after the fact), and uniquely identified by a hash of their contents.

The Ricardian Contract is the bridge between law and code. It solved a problem that most digital cash researchers didn't even acknowledge: how do you create a digital financial instrument that a court can enforce AND a computer can process? Most of the cypherpunk community was focused on making money that worked without courts. Grigg was thinking about making money that worked with them. This distinction becomes relevant when you look at how bitcoin's scripting system was actually designed: to encode conditions, agreements, rules, and multi-party logic directly on the network and validated on the blockchain.

Between 1998 and 2005, Nick Szabo designed a concept called Bit Gold.¹⁵ First conceived around 1998 and fully described publicly in 2005, Bit Gold chained proof-of-work solutions together, with each new solution referencing the previous one. A chain of computational proofs, each building on the last. Architecturally, it is the closest pre-bitcoin design to bitcoin itself, even though it was never implemented.

Szabo's idea had two critical gaps. He never solved the problem of how to prevent a single powerful node from dominating the chain. And he lacked a mechanism for adjusting the difficulty of the proof-of-work puzzle as computing power changed over time. Without difficulty adjustment, the system would either become trivially easy to game or impossibly hard to participate in. These are precisely the problems bitcoin solves with its competitive mining and difficulty retargeting.

In June 2003, a Cornell researcher named Emin Gun Sirer published KARMA, a system that used proof of work as a currency for peer-to-peer networks.¹⁶ Nodes earned karma tokens by contributing computational resources and spent them by consuming resources. KARMA demonstrated something that seems obvious in hindsight but wasn't proven at the time: proof-of-work tokens could function as a medium of exchange in a distributed system, moving between peers who had never met.

Then, on August 15, 2004, Hal Finney announced RPOW, Reusable Proofs of Work, on the cypherpunks list.¹⁷ Finney's system took a hashcash style proof-of-work token and converted it into a reusable token that could be transferred from person to person. This was the first system that bridged hashcash toward something resembling digital cash.

Finney's design still required a central server, a trusted computing platform, to prevent double-spending. He knew this was a weakness. He said so. The entire cypherpunk community knew that the double-spend problem, how to prevent someone from spending the same digital token twice without a central authority to check, was the remaining wall that no one had climbed.

Anatomy of bitcoin diagram showing how each precursor technology maps to a component in the bitcoin system

Anatomy of bitcoin diagram showing how each precursor technology maps to a component in the bitcoin system

The Pieces on the Table

By 2005, every building block existed:

  1. Public key cryptography (Diffie and Hellman, 1976) meant anyone could create unforgeable digital signatures without a central authority.
  2. Merkle trees (Merkle, 1979) meant you could verify any transaction belonged to a set without downloading the entire ledger.
  3. Hash-linked timestamping (Haber and Stornetta, 1991) meant you could chain records together so that altering any past record broke every subsequent one.
  4. Proof of Work Proof of work (Dwork and Naor, 1992; Back, 1997) meant you could make digital actions economically expensive, creating a measurable cost that proved effort.
  5. Digital Cash Theory & Application (Chaum, 1983; Dai, 1998; Szabo, 1998-2005) had mapped the design space and the failure modes.
  6. Programmable Contracts (Grigg, 1996) had shown that financial instruments could be simultaneously legal, human-readable, and machine-executable.
  7. Token transferability (Finney, 2004) had demonstrated that proof-of-work tokens could move between participants.
  8. Digital Cash (Chaum, 1989-1998) had provided the most important lesson of all; by failing. When the company went bankrupt, every digital dollar in the system vanished with it.⁶ The lesson was brutal and specific: digital cash that depends on a company is not cash at all.

Every piece was there. What was missing was a set of rules.

Someone needed to combine all of these pieces under a single system of incentives where participants had economic reasons to behave honestly, where cheating was unprofitable by design, where consensus emerged from a race condition. A competition. A market where the price of lying exceeded the reward, both in monetary terms but also because lies would be publicly recorded.

The Shadow in the Archive

Go back to September 1996 now. Back to that post on the cypherpunks mailing list. "Doshai" discussing banking over the internet, digital transactions, and the architecture required to make it work.¹

The ideas in that post are remarkably specific about the problems that needed solving and the shape of a solution. It sits quietly in the archive at the exact moment when the cypherpunks community was working through exactly these questions: how do you build money that doesn't require the user to trust anyone?

That mailing list produced the people and the ideas that bitcoin was built from. Whoever eventually assembled the pieces into a working system had been reading these threads. The evidence is in the citation list.

What Came Next

In October 2008, a message appeared on the Cryptography Mailing List at metzdowd.com. Notably, and this is often mixed up, it did NOT get published to the cypherpunks, but to its more professional and commercial cousin. A nine-page document was attached. The author's name was Satoshi Nakamoto. The paper was titled "Bitcoin: A Peer-to-Peer Electronic Cash System."¹⁸

The abstract opens with a single sentence that summarizes everything Chaum tried, everything Dai proposed, everything Szabo theorized, and everything Finney prototyped: "A purely peer-to-peer version of electronic cash would allow online payments to be sent directly from one party to another without going through a financial institution."

The whitepaper's introduction contains another sentence that serves as the thesis statement for three decades of failed attempts: "What is needed is an electronic payment system based on cryptographic proof instead of trust."

The bibliography cites Haber and Stornetta (three times), Back, Dai, and others. Every citation is a thread running back through the story we've just traced. The whitepaper didn't appear from nowhere. It appeared from right here.

In Section 8, Satoshi described how ordinary users would interact with the system: through Simplified Payment Verification, using Merkle proofs. Ralph Merkle's 1979 hash tree, embedded in the system's core design, ensuring that you didn't need to download the entire blockchain to prove your transaction was real.

"That would be like every Usenet user runs their own NNTP server. The design supports letting users just be users..."¹⁹ - Satoshi Nakamoto

The pieces had found their puzzle-maker.

Eight References

But before we leave the whitepaper and move on, there's something worth looking at more carefully. The bibliography.

The Bitcoin whitepaper contains exactly eight citations. Most readers, if they look at the reference list at all, notice the obvious ones: Dai's b-money, Back's Hashcash, Haber and Stornetta's timestamping work (cited three times). These are the names we've already traced through this story, connecting the whitepaper to the cypherpunk mailing list and to the academic timestamping community, and they are exactly the citations you would expect from someone steeped in those threads.

Two others sit quietly in the list, and when you look closely at them, they tell you something about whoever compiled it that the more obvious citations do not.

Citation number two is a paper by Henri Massias, Xavier Serret-Avila, and Jean-Jacques Quisquater: "Design of a secure timestamping service with minimal trust requirements."²⁰ It was presented at the 20th Symposium on Information Theory in the Benelux in May 1999.

Jean-Jacques Quisquater is a heavyweight. Professor of cryptography at the Universite catholique de Louvain in Belgium. Over 220 published papers across his career. Twenty patents. Nineteen years at Philips Research in Brussels before moving to academia. If you work in European cryptographic research, you know the name, but outside that circle it rarely appears in popular accounts of bitcoin's origins.

The paper itself is a technical refinement of timestamping systems, building on Haber and Stornetta's foundation. It is well-regarded and thoroughly obscure outside its subfield. The Benelux symposium is a respected regional academic conference in information theory, the kind of event where European researchers present to other European researchers. It does not generate headlines or blog posts on the cypherpunks list. You find this paper if you are conducting systematic literature searches through formal European cryptographic research institutions, if you have access to academic databases and you're reading conference proceedings cover to cover. You do not find it on a weekend browse through mailing list archives.

What kind of person, building a system in 2008, was reading proceedings from a 1999 Belgian cryptography symposium?

Citation number eight is the oldest reference in the whitepaper by nearly two decades. William Feller, "An Introduction to Probability Theory and Its Applications," published in 1957.²¹

Feller was a Croatian-American mathematician at Princeton. His textbook is considered one of the foundational works in probability theory. It sits on the shelf of graduate students in mathematics, physics, and theoretical computer science at programs around the world. Satoshi cited it because Section 11 of the whitepaper models the probability of an attacker catching up to the honest chain using a Poisson distribution. The math depends on random walks and competing Poisson processes, which are core Feller material.

Citing the 1957 original rather than a modern derivative, or presenting the math without attribution (which is what most working programmers would do), is a specific academic choice. It is the kind of citation you make when you were trained in a program that taught you to cite foundational sources, when you read the original because your advisor put it on the reading list.

The Bitcoin whitepaper's 8 references grouped by intellectual domain: cypherpunk community, formal academic cryptography, and classical mathematics

The Bitcoin whitepaper's 8 references grouped by intellectual domain: cypherpunk community, formal academic cryptography, and classical mathematics

Take the eight citations as a set. There are the cypherpunk names: Dai and Back. There are the formal academic cryptographers: Quisquater and colleagues, Haber and Stornetta, Merkle. And then there is William Feller's 1957 probability textbook, which belongs to neither camp, predates the entire digital era by decades, and points to a kind of mathematical training that few practicing cypherpunks in 2008 would have had.

The bibliography is a fingerprint. It tells you something about the person, or persons, who left it. How many people in 2008 moved fluently across all of those worlds? We are going to leave that question open, because it is one of the threads this series will follow through eighteen articles.

A Strange Choice

There is one more detail from the whitepaper's implementation that deserves attention before we leave the pre-history. It has nothing to do with the bibliography, but it rhymes with the same question: who was this person?

Bitcoin uses an elliptic curve called secp256k1 for all of its public key cryptography. Every address, every digital signature, every transaction input, and every spent output depends on this curve.

In 2008, this was a strange choice. The curve that virtually every developer and every security library defaulted to was secp256r1, also called NIST P-256. It was recommended by the National Institute of Standards and Technology. It was baked into SSL, TLS, and commercial software at every level. If you were building a cryptographic system in 2008 and you didn't have a specific reason to do otherwise, you used the NIST curve.

The difference between the two curves lives in a single letter, and that letter determines whether you need to trust anyone.

The "k" in secp256k1 stands for Koblitz. A Koblitz curve has fully deterministic, constructive parameters. Every number in the curve's definition is derived from a transparent mathematical process. There is no hidden seed, no opaque randomness, no arbitrary constants, and nothing you have to take on faith. What you see is what you get, and anyone with the specification can verify the construction from scratch.

The "r" in secp256r1 stands for "random." The NIST curve's parameters were generated by hashing a seed value. That seed was selected by the National Security Agency. It has never been publicly disclosed. It has never been explained or justified. You are asked to trust that the parameters were not specially constructed to create a weakness that only the generator would know about.

Now the timeline.

In August 2007, one year before the Bitcoin whitepaper, two Microsoft researchers named Dan Shumow and Niels Ferguson presented at the CRYPTO conference.²² They demonstrated that a NIST-recommended random number generator called Dual_EC_DRBG contained what amounted to a backdoor. If you knew a secret mathematical relationship between two constants in the algorithm, you could predict all of its future outputs after observing just 32 bytes of data. The presentation was public. Bruce Schneier wrote about it immediately, asking the question everyone in the cryptographic community was thinking: did NIST just standardize a compromised algorithm at the NSA's request?²³

Anyone paying close attention to cryptographic security research in 2007 knew that NIST's recommendations had a credibility problem.

In 2008, Satoshi chose secp256k1. The one curve type whose construction makes that class of attack structurally impossible. Deterministic parameters mean no hidden mathematical relationship, which means there is no trapdoor to exploit even if you built the curve yourself.

Timeline showing the 5-year gap between Satoshi's curve choice in 2008 and the cryptographic community's migration to safe curves in 2013

Timeline showing the 5-year gap between Satoshi's curve choice in 2008 and the cryptographic community's migration to safe curves in 2013

The rest of the world took five years to arrive at the same position. In 2013, the Snowden leaks confirmed that the NSA had deliberately compromised Dual_EC_DRBG. Reuters reported that the NSA paid RSA Security $10 million to make the backdoored algorithm a default in their widely used toolkit. That same year, Daniel Bernstein and Tanja Lange published their formal critique of NIST curve parameters, and the broader cryptographic community began its migration toward verifiably safe curves like Curve25519.²⁴ The migration that Satoshi made, alone, five years earlier, when the evidence was circumstantial and the consensus had not yet shifted.

Satoshi's only known public comment on the curve choice came from the bitcoin forum. His explanation: "I didn't find anything to recommend a curve type so I just picked one."

"Just picked one!?"

The one that happened to be immune to the exact vulnerability class that the cryptographic establishment would not confront until half a decade later. The one whose parameters require zero trust in any government agency, because trust was never part of the construction.

You can read that as coincidence. You can read it as something else. This series has seventeen more articles to explore the question, and we will.

The DigiCash failure: promotional material from the 1990s alongside the 1998 bankruptcy, visual contrast between the promise and the outcome

The DigiCash failure: promotional material from the 1990s alongside the 1998 bankruptcy, visual contrast between the promise and the outcome

Click here for the official PART 1: 2005-2009 in bitcoin


Footnotes

¹ "Doshai," cypherpunks mailing list post on banking over the internet, September 1996, Cypherpunks Archive.

² Diffie, W. & Hellman, M., "New Directions in Cryptography," IEEE Transactions on Information Theory, IT-22(6), November 1976, Stanford.

³ Merkle, R., US Patent 4,309,569, "Method of providing digital signatures," filed 1979, granted 1982, Google Patents.

⁴ Chaum, D., "Blind Signatures for Untraceable Payments," Advances in Cryptology, 1983.

⁵ May, T., "The Crypto Anarchist Manifesto," 1988, Satoshi Nakamoto Institute.

⁶ DigiCash BV filed for bankruptcy in 1998. The company's digital cash system, eCash, ceased to function when the company closed.

⁷ Zimmermann, P., released PGP (Pretty Good Privacy) in 1991. The subsequent federal investigation under ITAR was dropped in 1996.

⁸ Haber, S. & Stornetta, W.S., "How to Time-Stamp a Digital Document," Journal of Cryptology, vol. 3, pp. 99-111, 1991, Springer.

⁹ Dwork, C. & Naor, M., "Pricing via Processing or Combatting Junk Mail," CRYPTO '92, Weizmann Institute.

¹⁰ The cypherpunks mailing list was organized by Tim May, Eric Hughes, and John Gilmore in late 1992.

¹¹ Hughes, E., "A Cypherpunk's Manifesto," March 9, 1993, Satoshi Nakamoto Institute.

¹² Back, A., "Hashcash: A Denial of Service Counter-Measure," 2002 (original cypherpunks announcement: March 28, 1997), hashcash.org.

¹³ Dai, W., "b-money," November 1998, weidai.com.

¹⁴ Grigg, I., "The Ricardian Contract," 1996/2004, iang.org.

¹⁵ Szabo, N., "Bit Gold," 2005, Satoshi Nakamoto Institute.

¹⁶ Sirer, E.G. et al., "KARMA: A Secure Economic Framework for Peer-to-Peer Resource Sharing," Cornell University, June 2003.

¹⁷ Finney, H., "RPOW: Reusable Proofs of Work," August 15, 2004, Satoshi Nakamoto Institute.

¹⁸ Nakamoto, S., "Bitcoin: A Peer-to-Peer Electronic Cash System," 2008, bitcoin.org.

¹⁹ Nakamoto, S., bitcointalk.org forum post, July 29, 2010, bitcointalk.org.

²⁰ Massias, H., Avila, X.S. & Quisquater, J.J., "Design of a secure timestamping service with minimal trust requirements," 20th Symposium on Information Theory in the Benelux, May 1999.

²¹ Feller, W., "An Introduction to Probability Theory and Its Applications," Vol. 1, John Wiley & Sons, 1957.

²² Shumow, D. & Ferguson, N., "On the Possibility of a Back Door in the NIST SP 800-90 Dual Ec Prng," CRYPTO 2007 Rump Session, August 2007.

²³ Schneier, B., "Did NSA Put a Secret Backdoor in New Encryption Standard?" Schneier on Security, November 15, 2007, schneier.com.

²⁴ Bernstein, D.J. & Lange, T., "Security dangers of the NIST curves," 2013, cr.yp.to. On the RSA-NSA payment: Menn, J., "Exclusive: Secret contract tied NSA and security industry pioneer," Reuters, December 20, 2013.


Be good to each other. And stay curious.