Daniel J. Bernstein: The Fight to Publish Encryption Code
Daniel J. Bernstein was a 23-year-old graduate student when he sued the United States government. He won.
Everyone in security calls him djb. He wrote qmail, the mail server with a standing cash prize for anyone who can break it, and the ciphers and curves that now sit inside TLS, SSH, Signal and WireGuard.
He's also the field's most relentless critic of the agencies that write its standards. In 2022 he sued the government a second time, and he hasn't let up since.
Daniel J. Bernstein at a Glance
- Born in East Patchogue, New York, in 1971, Bernstein finished a mathematics degree at NYU in 1991 and a Berkeley PhD in 1995 under Hendrik Lenstra.
- As a Berkeley grad student he wrote a cipher called Snuffle; the government said publishing it required an arms-export license, so in February 1995 he sued, with the EFF's Cindy Cohn as his lawyer.
- In December 1996 Judge Marilyn Hall Patel ruled the export rules an unconstitutional prior restraint on speech, and in 1999 the Ninth Circuit agreed that source code is protected by the First Amendment.
- Sick of sendmail's security holes, he started writing qmail in December 1995 and in March 1997 offered $500 to the first person to find a hole in it; nobody has collected.
- He joined the University of Illinois at Chicago in 1995 and is still there as a research professor, picking up a Sloan fellowship and an Academia Sinica affiliation along the way.
- His Salsa20, Poly1305, Curve25519 and ChaCha designs, released between 2005 and 2008, became the fast, patent-free building blocks of modern encryption.
- In August 2022 he announced his second lawsuit against the US government, a records fight over NIST's post-quantum standards and the NSA's role in them.
- He's still arguing: between 2025 and 2026 he published a nine-part blog series on the NSA and the IETF.
The Life of Daniel J. Bernstein
From Long Island to Berkeley
Bernstein was born on October 29, 1971, in East Patchogue, on the south shore of Long Island. He holds both American and German citizenship, and his own CV lists French, German and Danish among the languages he's studied.
He finished his bachelor's degree in mathematics at New York University in 1991 and went west to Berkeley, where he earned a PhD in mathematics in 1995 under Hendrik W. Lenstra Jr., one of the world's leading number theorists.
By then he'd already picked a fight that'd outlast his thesis.
Snuffle and the State Department
As a grad student, Bernstein wrote a small encryption system called Snuffle and wanted to do what academics do: publish the paper, post the source code and talk about it at conferences.
Under the Arms Export Control Act and the International Traffic in Arms Regulations, encryption software counted as a munition, and the government told him that sharing Snuffle required an export license. In February 1995 he sued in federal court in San Francisco, represented by the Electronic Frontier Foundation's Cindy Cohn.
The first win came in December 1996, when Judge Marilyn Hall Patel held that the regulations were an unconstitutional prior restraint on speech. The government moved the rules to a different agency, and in August 1997 Patel struck those down too.
In May 1999 a Ninth Circuit panel affirmed that software source code is speech protected by the First Amendment. The government asked for a rehearing, then rewrote the regulations instead, and after oral argument in October 2002 the case was dismissed because the new rules no longer clearly applied to him. By then the point had been made.
Sick of Sendmail
In December 1995, having just finished teaching a course on algebraic number theory, Bernstein found himself with spare time and a grudge. "Every few months CERT announces Yet Another Security Hole In Sendmail," he wrote in the first qmail documentation. "I'm sure there are many more holes waiting to be discovered."
He was right: 14 sendmail holes were announced over the next two years. qmail, built from the ground up around the idea that mail delivery must be secure because it can never be turned off, went into public beta in January 1996.
In March 1997 Bernstein offered $500 to the first person to publish a verifiable security hole in the latest qmail. A group of users added a $1,000 prize of their own for a year; nobody claimed it, and the money went to the Free Software Foundation. When Georgi Guninski claimed a remote exploit in 2005, Bernstein denied it on the grounds that nobody gives gigabytes of memory to each qmail-smtpd process.
By October 2001 qmail was the second most common SMTP server on the internet. Bernstein later placed it in the public domain, and he backed his DNS software, djbdns, with a $1,000 guarantee of its own.
The Professor at UIC
Bernstein joined the University of Illinois at Chicago in 1995 as a research assistant professor of mathematics, statistics and computer science, earned tenure in 2001 and became a full professor in 2005. Since 2008 he's been a research professor in the computer science department.
The honors followed: an NSF CAREER award, a Sloan Research Fellowship from 2002 to 2006, and by his own count $3.5 million in external funding for his UIC research as of 2025. He's also affiliated with Academia Sinica in Taiwan.
He's been at UIC for 30 years now, "time flies when you're having fun," as his positions page puts it, and his website still carries a page titled "What it's like to work at UIC."
Snuffle 2005
Bernstein never dropped the Snuffle name. In 2005 he released the Salsa20 stream cipher, also known as Snuffle 2005, along with the Poly1305 authenticator and Curve25519, a Diffie-Hellman function that turns a 32-byte secret key into a 32-byte public key at speeds that embarrassed the competition.
In January 2008 came ChaCha, "Snuffle 2008," a tweak of Salsa20 with better diffusion. All of it was fast, all of it was free of patents, and all of it was released into the public domain.
Those designs are now everywhere. ChaCha20 with Poly1305 and Curve25519 ship in TLS, in OpenSSH, in the Signal protocol and in WireGuard, which means most people run djb's math every day without knowing his name.
Suing the Government Again
Bernstein's second war is about what comes after today's cryptography. He co-edited an early textbook on post-quantum cryptography in 2009, has championed Classic McEliece, the code-based scheme NIST passed over, and has spent years arguing that the agency's choices are being steered by the NSA.
On August 5, 2022, he announced on his blog his second lawsuit against the US government, a Freedom of Information Act fight over records of the NSA's involvement in NIST's post-quantum standardization. In 2023 he published a series of posts arguing that NIST had miscounted the security level of Kyber-512, the lattice-based scheme it'd selected.
Since October 2025 he's written a nine-part series titled "NSA and IETF," accusing the internet standards body of letting the agency weaken the case for hybrid encryption, which pairs post-quantum algorithms with the elliptic curves he designed. Part nine appeared in August 2026.
Bernstein Today
Bernstein still teaches at UIC, still publishes at a pace that fills a long bibliography page and still speaks wherever cryptographers gather. In 2025 he addressed the OpenSSL Conference on writing code that's fast, constant-time and correct, all three at once.
His website, cr.yp.to, looks the way it did in 1999 and still hosts qmail, djbdns, the guarantee pages, the lawsuit papers and his advice on placing work in the public domain.
Daniel J. Bernstein: Trust the Math, Not the Agency
Most security pioneers built a thing. Bernstein built things and then argued, in court and in public, about who gets to decide whether they're allowed to exist.
He won the argument once, and the right to publish code without a license is part of why the modern internet runs on open cryptography. He's making the argument again, this time about quantum computers, and NIST and the IETF would probably prefer he stopped.
He won't. The $500 is still on the table.
QUOTE:
"Amateurs hack systems, professionals hack people."