For most of the 1990s, a strong encryption program was legally a weapon. Not metaphorically. Export-grade cryptography sat on the United States Munitions List alongside fighter aircraft and artillery, and emailing a copy of the wrong software to someone abroad was arms trafficking under the same statute that governs selling rifles to foreign governments.
The people who broke that framing were not soldiers or spies. They were a mailing list. And they won not by hacking anything, but by publishing - a book, a t-shirt, a court case, and a manifesto that opened by parodying Marx.
This is the story of the Crypto Wars: how mathematics got classified as a weapon, and how a loose collective of programmers who called themselves cypherpunks made that classification impossible to hold. Almost everything you use to stay private online - Signal, PGP, HTTPS, Tor - exists in the space they pried open.
//A Specter Haunting the Modern World
In mid-1988, an ex-Intel physicist named Timothy May wrote a short document and handed it out to a handful of people at the Crypto '88 conference. It opened:
"A specter is haunting the modern world, the specter of crypto anarchy."
The Marx parody was deliberate. May's argument was that public-key cryptography - then barely a decade old - would do to the state's power over information what the printing press did to the church's. If any two people could communicate in perfect secrecy, and prove who they were without revealing anything else, then whole categories of state and corporate control simply stopped working. It closed: "Arise, you have nothing to lose but your barbed wire fences!"
May read it aloud again in September 1992, at the first meeting of a group convened by Eric Hughes, John Gilmore and himself, in the San Francisco Bay Area. A programmer named Jude Milhon, watching the room, coined the name: cypherpunk, from cipher and cyberpunk. The manifesto went out to the new mailing list that November.
The following year Hughes wrote the movement's more practical companion piece, A Cypherpunk's Manifesto (1993), and gave it the line that became the whole ethos:
"Cypherpunks write code. We know that someone has to write software to defend privacy, and ... we're going to write it."
That sentence is the hinge of this entire story. The cypherpunks did not petition, and with one crucial exception they did not litigate. They shipped working code and dared the government to stop mathematics from spreading. The mailing list that formed around them ran for years and passed through, among many others, Julian Assange, Bram Cohen who later wrote BitTorrent, and Adam Back whose Hashcash is cited in the Bitcoin whitepaper.
//The Law They Were Fighting
The legal reality in 1992 was genuinely strange. Under the International Traffic in Arms Regulations (ITAR), cryptographic systems above a low strength threshold - 40-bit symmetric keys, trivially breakable even then - were "defense articles." Exporting one without a State Department licence was a federal crime under the Arms Export Control Act.
"Export" was interpreted broadly enough to be almost meaningless. Publishing strong crypto source code on a US website that a foreigner could download was, on the government's reading, exporting a munition. A domestic academic could write it; the moment it crossed a border, it was arms trafficking.
The obvious absurdity - that the same string of characters was protected academic work inside the country and a weapon outside it - is exactly the contradiction the cypherpunks set out to make undeniable.
//Zimmermann and the Book
In 1991, Phil Zimmermann released Pretty Good Privacy - PGP - free, with source code, uploaded to the internet where anyone could grab it. It was the first strong, usable public-key encryption most people could actually get their hands on. It spread worldwide in weeks.
In February 1993 the US Customs Service opened a criminal investigation into Zimmermann for munitions export. It ran for about three years. He faced the genuine prospect of prison for writing software and letting people have it.
His answer, in 1995, is one of the great pieces of legal theatre in the history of computing. MIT Press published the complete source code of PGP as a physical book - PGP: Source Code and Internals - typeset, bound, with an ISBN. Books are protected speech under the First Amendment and freely exportable. The identical bytes on a floppy disk were arms trafficking; printed and bound between covers, they were literature. Anyone abroad could legally buy the book, run it through an OCR scanner, and recompile PGP.
The move dared the government to argue in open court that the First Amendment stops at the compiler. In January 1996 the investigation was dropped with no charges. The government had looked at the fight and decided not to have it.
//The Clipper Chip
The government's counter-move was to try to own the infrastructure. In 1993 the NSA and the Clinton administration proposed the Clipper chip: strong encryption for phones and computers, built in, with one condition. Every chip shipped with a key held in escrow by the government. Encrypt all you like; the state keeps a copy of the key.
The cipher was Skipjack, an 80-bit NSA algorithm, classified at the time. The escrow mechanism rode in a field attached to every encrypted session called the LEAF - the Law Enforcement Access Field - which carried the session key wrapped so that only the government could recover it.
In 1994, a Bell Labs researcher named Matt Blaze took the specification apart. The LEAF was validated by a 16-bit checksum. Sixteen bits is nothing - about 65,000 possibilities, brute-forceable in minutes. Blaze showed you could construct a bogus LEAF that passed the checksum but contained no recoverable key. You kept Clipper's strong encryption and simply switched the government's access off.
It was a fatal, structural embarrassment. The one feature that justified Clipper's existence did not work. Combined with the fact that nobody wanted to buy a phone with a government key in it, and that free strong crypto like PGP already existed, Clipper was dead by 1996.
//Code Is Speech - Almost
The intellectual victory came through the courts, and this is the part most retellings get wrong, so it is worth getting right.
Daniel Bernstein was a graduate student who had written an encryption algorithm called Snuffle and wanted to publish it, including the source code, as academic work. The export rules meant publishing it could make him an arms trafficker. Backed by the EFF, he sued the government.
He won at the district level: on 25 August 1997, Judge Marilyn Patel ruled the export regulations an unconstitutional prior restraint on speech. On 6 May 1999, a three-judge panel of the Ninth Circuit affirmed, holding that source code is speech protected by the First Amendment. That ruling - "code is speech" - is the one everybody quotes.
Here is the part that usually gets dropped. The Ninth Circuit then agreed to rehear the case en banc, and in doing so it withdrew the panel opinion. A withdrawn opinion is not binding precedent. Before the full court could rule, the government substantially loosened the encryption export rules - in January 2000 - which took the pressure off, and the case was eventually dismissed in 2003 with no final decision on the merits.
So the honest statement is this: "code is speech" was affirmed by a federal appeals panel, became one of the most influential ideas in technology law, and was never actually settled as binding precedent, because the government retreated rather than risk losing it for good. The cypherpunks did not need the final ruling. The threat of it, plus PGP already being everywhere, was enough. In 2000 the export controls were gutted, and the Crypto Wars were effectively over.
//Who Won, And What It Cost
The cypherpunks won comprehensively. Strong encryption is now the default, baked into every browser, every phone, every messaging app. The idea that you could put mathematics back on the munitions list is, today, faintly absurd - which is precisely the measure of how completely they succeeded.
But the war did not end so much as change shape. The state's interest in reading private communications did not evaporate; it moved. The Snowden disclosures in 2013 showed mass collection happening at the network and metadata level, going around the encryption rather than through it. "Going dark" is the recurring argument governments still make for lawful-access backdoors, most recently in the fights over end-to-end encryption in messaging. Every one of those debates is the Clipper chip argument, wearing new clothes.
And the cypherpunks were right about something uncomfortable, too. The same tools that protect a dissident protect a criminal. Crypto anarchy delivered Signal and it delivered ransomware payment rails. May saw that coming and did not much care; for him the tradeoff was settled the moment you decided individuals should have power the state cannot override. You do not have to share that conclusion to see that he called the technical trajectory almost perfectly.
//The Lesson That Carries
The through-line worth taking from the Crypto Wars is not nostalgia. It is method.
The cypherpunks beat the most powerful state on earth on the encryption question without committing a single act of the thing the word "hacker" conjures. No intrusions. No leaks of stolen data. They wrote code and released it, they published source in forms the First Amendment protected, and they took the government to court. The most radical thing they did was make working privacy tools ordinary.
That is the version of the outsider-against-the-system story that actually worked, and it worked precisely because it stayed on the right side of the line between defending privacy and attacking people. The barbed wire came down because someone wrote the code and dared to publish it. That is still the move.
//Sourcing and Uncertainty
The manifesto dates and quotes are from the primary texts and May's own preface: written mid-1988, distributed at Crypto '88, read at the September 1992 founding meeting, posted to the list in November 1992. Hughes' manifesto and its "Cypherpunks write code" line are from 1993. The cypherpunk founding details (Hughes, May, Gilmore; Milhon coining the term) are from the standard histories.
Zimmermann's timeline - PGP in 1991, the Customs investigation opened February 1993, the MIT Press book in 1995, the case dropped January 1996 - is from his own account and contemporary reporting. The Clipper timeline (proposed 1993, Blaze's LEAF finding in 1994, defunct by 1996) and Skipjack's later 1998 declassification are from Blaze's papers and the standard record.
The Bernstein sequence is the one to be careful with, and is stated above exactly as the record supports it: district court win August 1997, Ninth Circuit panel affirming "code is speech" May 1999, that panel opinion withdrawnon grant of en banc rehearing, export rules loosened January 2000, case dismissed 2003 with no binding merits ruling. Anyone who tells you "code is speech" is settled Ninth Circuit precedent is overstating it.
The interpretation is mine: the reading of the PGP book as demonstration rather than loophole, the framing of every modern lawful-access debate as the Clipper argument recurring, and the closing argument about method. The claim that the cypherpunks "won" is a judgement about encryption specifically; on metadata and mass collection, the Snowden material suggests the state adapted rather than conceded.