Cryptography is easy to think of as a purely technical subject: passwords, encrypted messages, banks, spies and the mathematics underneath them. But it also belongs in a broader conversation about digital sustainability. A digital system is not especially sustainable if people cannot trust it, if compromised software must be abandoned, or if essential services become fragile because security was treated as an afterthought.
We use cryptography constantly, usually without noticing it. It helps protect messages, online payments, cloud accounts, software updates and data stored on our devices. If you have ever wondered what is cryptography, the basic idea is straightforward: mathematical techniques are used to protect information so that only the right people or systems can read it, verify it or prove where it came from.
That matters for privacy. It also matters for resilience. As more of daily life moves into connected systems, secure digital infrastructure becomes part of keeping those systems useful, trustworthy and viable over time.
What Cryptography Actually Does
Cryptography is not one single technology. It is a collection of methods used for goals such as confidentiality, authentication and integrity. The U.S. National Institute of Standards and Technology describes cryptography as the use of mathematical techniques to protect information and maintains standards covering encryption, digital signatures, hash functions and key management.
Encryption is the part most people recognize. Readable information, called plaintext, is transformed into ciphertext using an algorithm and a key. Someone without the appropriate key should not be able to recover the original information. Depending on the system, the same key may be used to encrypt and decrypt data, or a public and private key pair may be involved.
Cryptography also helps answer a different question: did this information really come from the source it claims to come from, and has anyone changed it? Digital signatures can be used to authenticate a sender and detect unauthorized changes. NIST’s Digital Signature Standard exists for exactly those purposes.
Why Cryptography Matters in Everyday Life
Most people encounter cryptography dozens of times a day without consciously deciding to use it. When a browser establishes an encrypted HTTPS connection, when a password manager unlocks a vault, when a messaging service encrypts a conversation, or when a device checks whether an update is authentic, cryptographic tools are doing part of the work.
The result is not perfect security. It is a layer of trust that makes ordinary online activity possible. Without effective encryption and authentication, online banking, remote work, cloud storage, e-commerce and many public services would expose users to far greater risks.
This is also where security intersects with sustainability. Digital infrastructure can only deliver long-term social and economic value if people can continue to rely on it. A system that is efficient but routinely compromises personal information is not resilient. A connected service that becomes unsafe because it cannot verify legitimate updates has a longevity problem as well as a cybersecurity problem.
Hashing Is Different From Encryption
Hashing is often discussed alongside encryption, but it performs a different job. Encryption is designed to be reversible by an authorized party with the correct key. A cryptographic hash function takes an input and produces a fixed-size output that is not intended to be reversed.
That makes hashes useful for checking integrity. Change the underlying data and the resulting hash should change too. Hashes can therefore help systems detect whether a file or message has been altered.
Password storage is a special case. Secure services should not simply store passwords in plaintext or use a fast general-purpose hash. The OWASP Password Storage Cheat Sheet recommends modern, deliberately expensive password-hashing approaches such as Argon2id, along with unique salts. The point is to make stolen password databases substantially harder to crack at scale.
Where You See Cryptography in the Real World
On the web, HTTPS uses encryption to protect information travelling between a browser and a website. That is essential, but it is worth separating encryption from legitimacy. A scam website can use HTTPS too. The U.S. Federal Trade Commission notes that the “s” in HTTPS means the connection is encrypted, not that the seller or website itself is trustworthy.
Messaging services may use encryption in transit or, in some cases, end-to-end encryption that prevents the service provider from reading message content. Payment systems use cryptographic techniques to protect transactions and authenticate participants. Password managers encrypt stored credentials. Phones use encryption to protect local data. Software developers use digital signatures so devices can verify that an update came from an authorized source.
Companies also depend on cryptography for remote access, internal systems, cloud storage and customer records. That is why weak security can become a business sustainability problem as well as a technical one. Our article on why phishing can become a hidden business waste stream looks at the time, disruption and duplicated work that security failures can create even before the wider damage is counted.
Security Is Part of Digital Sustainability
Digital sustainability is often discussed in terms of energy use, data centres, device manufacturing and electronic waste. Those are central issues, but longevity also depends on whether systems remain safe enough to use.
A laptop, phone, router or smart device can remain physically functional while becoming increasingly risky if it no longer receives trustworthy security updates. Cryptography does not solve the broader problem of short product support cycles, but it is one of the mechanisms that allows secure updates to work. NIST’s platform firmware resiliency guidance, for example, describes authenticated update mechanisms that use digital signatures to verify that firmware updates are genuine and authorized.
That connection matters in a world already struggling with electronic waste. The Global E-waste Monitor has documented how the growth of connected electronic equipment is driving an expanding waste stream. Security support is not the only factor that determines how long a device stays useful, but it is increasingly one of them.
This is where cybersecurity and the right to repair begin to overlap. Repairable hardware is valuable, but long-lived devices also need software, firmware and security ecosystems that continue to support them. Extending product life means thinking about both the physical object and the digital systems that keep it trustworthy.
The Limits of Cryptography
Cryptography is powerful, but it is not magic. Strong algorithms can still be undermined by stolen keys, weak passwords, bad configuration, outdated software or people being tricked into giving attackers access.
If someone enters their password into a convincing phishing page, encryption between their browser and that fake website does not rescue the account. The connection may be encrypted while the destination is malicious. Likewise, a private encryption key stored carelessly can turn a mathematically strong system into a practical security failure.
Implementation matters too. Security teams spend so much time on patching, access controls, audits and key management because cryptography only works as part of a larger system. A good algorithm cannot compensate for every bad decision around it.
What Regular Internet Users Can Do
You do not need to understand the mathematics behind encryption to benefit from it. What matters is choosing services and habits that let good security mechanisms do their job.
Use strong, unique passwords rather than reusing one password across multiple accounts. Turn on multi-factor authentication where it is available; CISA notes that stronger, phishing-resistant MFA methods offer better protection, although any MFA is preferable to none. Keep operating systems, browsers and apps updated so known vulnerabilities can be fixed.
Look for HTTPS when entering sensitive information, but do not treat a padlock as proof that a website is genuine. Check the domain, be cautious with links in unexpected messages, and go directly to a known website when something feels wrong. The FTC’s online shopping guidance makes the same distinction: HTTPS means the connection is encrypted, while scammers can encrypt their sites too.
It also helps to consider the longevity of the devices and services you choose. A product with a long support window, repair options and reliable security updates has a better chance of remaining useful. Refurbishment can also keep capable hardware in circulation; our look at refurbished phones and e-waste reduction explores that side of the equation.
Cryptography Is Infrastructure, Not Decoration
Cryptography rarely gets noticed when it is working well. That is partly the point. It sits underneath everyday digital activity, helping protect confidentiality, verify identity and detect tampering while people get on with whatever they actually came online to do.
Its sustainability value is similarly indirect. Encryption will not cut the energy use of a data centre or recycle an old phone. But durable digital systems need more than low emissions: they need trust, resilience and the ability to remain safely useful. Cryptography is one of the foundations that makes that possible.
As more of society becomes digital, that foundation matters more. The challenge is not simply to build more connected technology, but to build systems that people can keep using with confidence for as long as possible.