The Magic Word
From shibboleth to passkey, every word guarding your life has an expiration date.
The Brazilian Job
A few years ago, hackers operating out of Brazil guessed my PlayStation password. That’s on me: I used a weak password for years so it was easier to type on PlayStation’s annoying controller keyboard. The digital pickpockets were likely after the credit card on file, but they didn't get it; I noticed the login attempt emails in time and Sony had the account back to me within five hours.
But for reasons known only to God, one of the first things they did was delete my entire friends list. Every name on it, fifteen years of accumulated multiplayer invites, real-life-friends-now-strangers from high school that I apparently can never again reacquaint with over another casual invite, random people from around the world that shared a singular fond memory of a decade-past match, usernames that existed nowhere else and could never come back again.
The credit card, of course, had fraud protection. The friends list didn't. Which is how I learned, earlier than most, that the treasure behind the magic word is never quite the one the thieves or the security team think it is.
Abracadabra Was Never a Myth
We use "magic word" as a dead metaphor, a thing you say to a five-year-old withholding a cookie. The lineage is less cute. In the book of Judges, the men of Gilead held the fords of the Jordan against fleeing Ephraimites and required one word of every man who wanted to cross: shibboleth. The Ephraimite dialect couldn't produce the sh sound. Forty-two thousand men failed the first authentication check on record and it cost them their war and their lives.
In the tale of Ali Baba and the Forty Thieves, the cave of stolen treasure opens for anyone who says the magic words. The door does not care whose mouth they come from. In security lingo you call that a bearer token. And when Ali Baba's brother Cassim gets inside and the door shuts behind him, he cannot remember the phrase; panicking, he tries the whole pantry, open barley, open wheat, open chickpea, and the door holds until the thieves return. Death by unrecoverable credential. Abracadabra, for its part, enters the record in the second century as a fever cure, written out in a diminishing triangle and worn as an amulet: a word deployed as medical infrastructure. The first Christians walked into a world saturated with this technology: healing amulets, curse tablets, papyri strung with the names of gods and angels. When the converts at Ephesus burned their spellbooks, Luke priced the bonfire at fifty thousand pieces of silver (Acts 19:19), history’s most expensive credential revocation. The posture is the one thing that never changed: a word addressed to a power you cannot read, trusted to work anyway.
None of this is behind us. Somewhere between six and seven million bitcoin sit behind exposed public keys, the untouched wallet of bitcoin’s vanished creator Satoshi, first among them. It is a dragon’s hoard waiting to bestow its vast riches to whoever first speaks the fated counterword. My own password manager holds a little over five hundred entries that control access to my entire life. I try to think of it as a database. It is obviously a grimoire.
The Word That Became Voltage
Cryptography is Greek for hidden writing, and it may be the only technical term in the field that has never been a metaphor. What changed is the substrate.
Somewhere in the last eighty years the word went physical: compiled into voltages, etched into silicon, buried in the doped channels of a chip the size of a communion wafer. Code is the one (human) language left whose words act by physics rather than convention: a vow binds because we agree it does; a line of code runs because electrons must. It is the speech-act with the voltage still attached, which is presumably why the United States government spent the 1990s classifying strong encryption as a munition, alongside fighter jets, until a Berkeley graduate student named Daniel Bernstein convinced a federal judge that code is speech, and the export regime buckled.
Arthur C. Clarke said any sufficiently advanced technology is indistinguishable from magic. Run the observation the other direction and you get a working definition: magic is power without comprehension. The Australian philosopher Paul Tyson has argued for years that modernity never actually disenchanted the world, and by that definition he is plainly right. We evacuated the spirits from the trees and the wells, then wrote incantations into every object we own, sealed them where no one can read them, and called the result rational.
New Word, Same Expiration Date
Passkeys are the industry's current answer to human beings being bad at keeping secrets. A passkey is a cryptographic keypair: the site holds the public half, your device holds the private half (the public half is useless alone), and no reusable secret ever crosses the wire. Nothing to phish, nothing to reuse, nothing to leak in a breach. It is a genuine upgrade and you should use it.
Notice, though, what the upgrade trades. A password asked you to know a secret. A passkey asks you to trust a custodian, because for most people the private halves live in keychains run by Apple, Google, and Microsoft (the global good guys), synced through accounts you can lose, governed by recovery flows you don't control.
And custodians defend their caves. Cassim at least had the dignity to forget the word himself. The thieves quartered him and hung the pieces at the cave mouth as a warning to the next visitor, a deterrence practice we have since civilized: when a YouTuber allegedly caught a look at unreleased iPhone software through a friend of an Apple engineer last year, Apple hauled him into federal court, took a default when he didn’t answer, and this June agreed to let him contest it, slowly bleeding out in public, where every future leaker can watch.
The announcements skip the second trade: today’s passkeys sign with elliptic curves, and elliptic curves are the mathematics a sufficiently large quantum computer dispatches first. Five billion passkeys are now in circulation, and every one of them speaks, for now, a language with a published expiration date. The password's replacement was born mortal, same as the password.
The Counterspell
The machine that does the dispatching runs Shor's algorithm, and the honest way to describe it is a counterspell: one machine that makes an entire class of words stop being trustworthy at once, everywhere, the same afternoon. Against symmetric ciphers, the kind that lock your hard drive, quantum computing merely dents. Against the public-key mathematics that runs the internet's handshakes, signatures, and wallets, it is terminal, if and when the machine arrives.
In 2019, the best estimate said breaking RSA-2048, the internet’s old workhorse lock, would take twenty million noisy qubits.
In 2025, Craig Gidney revised it to under a million.
This year a preprint claims under a hundred thousand, caveats attached.
The biggest machines hold a few hundred to a couple thousand physical qubits, so the gap is real; the sober surveys put arrival somewhere in the 2030s, IBM says 2029, and Scott Aaronson says nobody knows. But the size of the required machine has fallen in one direction for seven years, and you can read the true forecast in behavior rather than press releases.
The NSA requires quantum-resistant signatures on new software and firmware for national-security systems starting next January. NIST, the American standards agency, deprecates RSA and elliptic curves in 2030 and strikes them from its standards in 2035. The White House priced the migration for its own civilian agencies at $7.1 billion, and governments do not issue seven-billion-dollar compliance orders against a threat they price at zero.
The migration has already begun without you: more than sixty percent of the human web traffic crossing Cloudflare, a network much of the web rides through, has switched to quantum-resistant handshakes (strictly, hybrid ones) over the past two years, and OpenSSH, the tool that administers most of the world's servers, now prints a warning when you connect with classical crypto. The spells that plumb your entire life are being swapped mid-flight, and you never noticed.
The Breach Precedes the Weapon
One more mechanic, the one that moves the deadline from the 2030s to yesterday. Intelligence agencies do not wait for the decoder to exist before running the tape recorder.
The practice is called harvest now, decrypt later: capture encrypted traffic in bulk today, warehouse it, read it the decade the machine arrives. Major security agencies now write their guidance on the assumption it is already happening. The cryptographer Michele Mosca reduced it to an inequality: if the years your secret must hold, plus the years migration takes, exceed the years until the machine, you are already too late. If that breaking machine is even fifteen years out, the inequality has already failed for anything that must stay secret that long: health records, sources, diaries, preferences, diplomacy. It’s already on tape and can be recalled.
And no one will announce the break. The Allies read Enigma for years while Germany trusted it absolutely, then kept the fact classified for three decades. The CIA and West German intelligence secretly owned Crypto AG, the Swiss firm that sold cipher machines to more than a hundred governments, and spent decades reading the traffic of customers who were paying for the privilege; the full story arrived in 2020, fifty years after the CIA’s purchase, in a newspaper. The failure of a cipher is itself the kind of secret the winners keep. Oh, but I’m sure your info is safe—definitely no breaking story in 2040 that you had no idea about.
Living in the Light
The litany.
Turn on passkeys anyway; mortal or not, they beat what you're doing now.
Move anything that matters to Signal, which finished its quantum-resistant upgrade last October.
Anything that must never surface belongs on actual paper.
Date your assumptions: whatever you send today, assume it is readable in fifteen years, and decide what gets written down at all.
You can do it all this week.
Then there is the harder conclusion. If everything you have ever sent through a wire (every message, every login, every whispered DM) sits on tape awaiting its decoder, then transmitted secrecy was always margin, a fig leaf. That margin is now being called.
The Christian tradition has a word for the day everything hidden becomes visible: apokalypsis means unveiling, and it was never primarily about mushroom clouds.
"What you have whispered in an ear in private rooms will be proclaimed on the housetops" (Luke 12:3)
A claim about the structure of reality long before it became a plausible description of signals intelligence. Privacy is not duplicity; the same Jesus who warned about the housetops commands prayer behind a shut door and alms so secret the left hand misses them (Matthew 6). Some secrets guard intimacy, safety, and duty. The unveiling to fear is not the end of the private life but the end of the double one. And there has never been a better decade to practice being one person instead of two, to live now the way you would live if the sealed half of your life were already legible.
Tonight I'll open the grimoire, retire a few of the weakest words that guard the replaceable things, and turn the passkeys on. Housekeeping, mostly.
But some nights it will feel like what it is: getting the house ready for daylight.



