Ross Anderson: The Researcher Who Challenged the Banks
In the early 1990s, British bank customers who reported "phantom withdrawals" from cash machines were told they were lying or mistaken. The banks denied their systems had flaws. Ross Anderson, a former freelance security consultant whose work on ATM payments went back to the 1980s, suspected the banks.
He went back to Cambridge in his mid-thirties to find out, and the paper he wrote, "Why Cryptosystems Fail," launched a career-long mission: turning security engineering into a real discipline. Then he wrote the textbook, built the conferences, trained the professors and took on the card industry, the NHS and, finally, his own university.
He died in March 2024, six months after Cambridge forced him to retire, in the middle of a campaign against that decision.
Ross Anderson at a Glance
- Born in 1956 and schooled in Glasgow, Anderson read mathematics at Trinity College, Cambridge, worked for Ferranti on inertial navigation and spent 1984 to 1991 as a self-employed computer security consultant, including work on ATM payments.
- He returned to Cambridge as a research student in 1992, and his 1993 paper "Why Cryptosystems Fail" showed that most bank fraud came from implementation errors and management failures, not broken ciphers.
- With Eli Biham and Lars Knudsen he designed Serpent, which won the second-largest number of votes in the contest to become the Advanced Encryption Standard; with Biham he built the Tiger hash function.
- He started the Fast Software Encryption workshops, chaired the first Information Hiding workshop, founded the Foundation for Information Policy Research in 1998 and helped launch the field of security economics in 2001.
- Security Engineering, first published in 2001, became the field's standard textbook; the third edition, from 2020, is free to download.
- His Cambridge group repeatedly broke Chip and PIN, showing in 2010 that a stolen card could be used with any PIN, and exposed how Chinese spies hacked the Dalai Lama's office.
- He was elected a Fellow of the Royal Society in 2009, won the BCS Lovelace Medal and an EFF Pioneer Award, and in 2023 co-wrote the paper that warned of "model collapse" in AI.
- Cambridge made him retire at 67 in September 2023; he kept teaching at Edinburgh and campaigning against the policy until his death on 28 March 2024.
The Life of Ross Anderson
A Glasgow Schoolboy With Nine Highers
Ross J. Anderson was born on 15 September 1956 and went to the High School of Glasgow, where in 1973 he passed Highers in maths, physics, chemistry, biology, geography, English, French, German and Latin. He went up to Trinity College, Cambridge, in 1974 to read mathematics, and in 1974 and 1975 also worked for Ferranti as a development engineer on inertial navigation systems.
After graduating in 1978 he took a gap year through Europe, Africa and the Middle East, then worked on multilingual typesetting. From 1984 to 1991 he was a self-employed consultant, mostly on computer security, and in 1987 he joined the Institute of Bankers. He also filed a 1986 patent application for a "fast cryptogenerator."
His work on ATM payments gave him a front-row seat at a scandal. Customers reported cash vanishing from their accounts, and the banks, denying any flaw in their systems, told them they were lying or mistaken.
Why Cryptosystems Fail
In 1992 Anderson returned to Cambridge as a research student under Roger Needham, the computer scientist with whom he coined the phrase "programming Satan's computer" for the difficulty of designing cryptographic protocols. His first widely cited paper, "Why Cryptosystems Fail," appeared at the ACM's computer security conference in 1993.
It surveyed how retail banking systems actually failed, and its answer was uncomfortable: the threat model cryptographers worked from was wrong. Most frauds came not from cryptanalysis or clever technical attacks but from implementation errors and management failures.
That argument, that security fails for human and economic reasons more than mathematical ones, became his life's work. He finished his Ph.D., titled "Robust Computer Security," in 1995, and was hired as a lecturer the same year.
Serpent and Tiger
The 1990s were also Anderson's cryptographic decade. With Israeli cryptanalyst Eli Biham he designed Tiger, a hash function built to run fast on the new 64-bit processors after Hans Dobbertin's attack on MD4.
With Biham and Lars Knudsen he designed Serpent, a block cipher that reached the final round of the U.S. competition to replace DES and, in Anderson's words, "got the second largest number of votes." Rijndael won and became AES.
He also built communities. In December 1993 he organised the first Fast Software Encryption workshop in Cambridge, and in 1996 he chaired the first Information Hiding workshop. His group went on to break almost all the copyright-marking schemes then in use, and its StirMark tool became the industry standard for testing them.
In 1998 he founded the Foundation for Information Policy Research, the think tank he chaired and used for two decades of fights over surveillance, ID cards and medical privacy.
Writing the Textbook
Anderson's Security Engineering: A Guide to Building Dependable Distributed Systems came out in 2001, with second and third editions in 2008 and 2020. Its premise was that cryptographers, protocol people and operating-system people barely talked to each other, while software and hardware security were "a practitioners' art" and "black magic" respectively. He wanted one discipline with shared tools, and he wrote the book that defined it.
The same year he published the paper that helped launch security economics. "If Alice guards a system but Bob pays the cost of failure, you can expect trouble," as he later summarised it; network externalities, moral hazard and asymmetric information explained more about real breaches than any cipher strength. He chaired the first Workshop on the Economics of Information Security in 2002, and in 2008 started the Security and Human Behaviour workshop to bring psychologists into the room.
He became Professor of Security Engineering in October 2003, and in 2009 was elected a Fellow of both the Royal Society and the Royal Academy of Engineering.
Breaking Chip and PIN
Anderson's lab lived by the maxim that "good research comes from real problems," and no problem was more real than the EMV cards, known in Britain as Chip and PIN, that banks swore couldn't be defrauded. In 2008 his group's paper on tampered payment terminals won the best practical paper award at the IEEE Security and Privacy symposium and a slot on BBC's Newsnight.
In 2010 they went further with "Chip and PIN is Broken," a man-in-the-middle attack in which a stolen card could be used with any PIN at all. It won an outstanding paper award and another slot on Newsnight. Their later work on the EMV "pre-play" attack offered an explanation for disputed transactions that looked like card cloning, which banks often refused to refund.
When the UK Cards Association demanded that Cambridge take a student's thesis on the subject off the web, Anderson answered with what Computer Weekly later called "a brilliantly polite but scathing letter."
In between he found time for "The Snooping Dragon," a 2009 investigation into how Chinese intelligence compromised the computers in the Dalai Lama's private office, and for Database State, a report on the failings of British public-sector IT many of whose recommendations the government elected in 2010 adopted.
Model Collapse and Chat Control
Anderson never stopped moving into new territory. In his last decade his group worked on adversarial machine learning and on the economics of patching durable goods, and his research helped the EU develop a 2019 rule requiring sellers of goods with software inside to patch them for as long as customers can reasonably expect. The Cambridge Cybercrime Centre he built up collects data on spam, phishing and underground forums for more than 300 researchers at over 80 universities.
In 2023 he was a co-author of "The Curse of Recursion," which showed what happens when AI models are trained on the output of earlier models: the tails of the original distribution disappear and later generations degrade, a failure the paper called "model collapse."
He also wrote "Chat Control or Child Protection," a rebuttal of the case for mandated scanning of private messages, and counted the defeat of the EU's scanning regulation in the European Parliament as "our big policy win of 2023."
Anderson's Last Fight
In September 2023 Cambridge forced Anderson to retire when he turned 67. He called the policy "unlawful age discrimination" on his own homepage, campaigned against it, and carried on at 20 percent at Cambridge and 20 percent at Edinburgh, where he'd held a chair since 2021 and where all his security engineering lectures went online.
He gave an interview to the Archives of IT on 12 March 2024. On 28 March he died, aged 67. His former student Frank Stajano broke the news on the Cambridge security group's blog the next day: "His enthusiasm, his wide-spectrum intellectual curiosity and his engaging prose were unmatched."
Churchill College held a celebration of his life on 22 June 2024, Darmstadt held a memorial that September, and Cambridge hosted a "Rossfest" symposium in his memory on 25 March 2025. Thirty of his research students had earned Ph.D.s; ten became professors.
Ross Anderson: Programming Satan's Computer
Anderson's great insight was that security isn't a property of algorithms but of systems, incentives and people, and that engineers learn more from the bridge that falls down than from the hundred that stand. Every security economist, every incident post-mortem and every researcher who follows the money owes him a debt.
His Cambridge homepage has been preserved as he left it, retirement protest and all, and his September 2023 CV runs to nearly 300 numbered publications. The textbook remains free, as he wanted.
The university that retired him now hosts his obituary on its website. There's a paper about incentives in that somewhere.
QUOTE:
"Amateurs hack systems, professionals hack people."