No, Cryptography Is Not “Dual Use” the Same Way AI Is

Actor and functional application matter Originally published at AGI SurveilLance . Mainly, cryptography does one critical thing—encrypts data. It is considered “dual use” as a technology because one can employ encryption whether as a private citizen, a soldier, or a criminal. But, like a wall, it’s an inherently defensive tool by its nature. One cannot really attack with cryptography. [1] The term “cryptographic attack” refers to an attack on the cryptography of a target. [2] During the Crypto Wars , many battles were fought, but ultimately the winning side was that having public, open, ~unrestricted cryptography was the best equilibrium. In my eminently reasonable opinion, reasonable, informed people can disagree about the particular place to draw certain lines, because there are hard trade-offs and technological limits. A similar dynamic exists in the infosec community over which vulnerabilities, exploits, and offensive security tools to make public and which to keep private. Offensive security is actually a functionally dual use situation because, as with a sword, it can be used to attack or parry—the dual application is independent of the user. In the hands of a defender or sec