About this site
A site about secret writing where you can try everything yourself. Made for anyone who's fifteen and wonders how it really works — and for everyone who wishes they'd known this at fifteen.
Who it's for
For you, if you're in secondary school and want to know what happens behind the padlock in your browser. For math and computer science teachers looking for something to show what all those numbers are good for. And for anyone who's been nodding along at the word "encryption" without actually getting it.
Why buttons and not pictures
Most explanations of encryption stop at a drawing of a padlock with a key. You nod along, but you don't understand a thing. The moment you make a key pair yourself, encrypt something, then change one letter and watch it all fail, you understand where the limits are — and those limits are the most interesting part.
That's why every demo genuinely calculates, using your browser's built-in cryptography (for anyone who wants to know: the WebCrypto API). No fake output. What you see, your device really computed, right then.
What now?
If, at the "This is math" boxes, you thought: I want to understand that — here's what you should know.
| In secondary school | Pick a track with a lot of math. Not because you'll already cover these curves, but because you'll learn how a proof works and how to calculate with abstract things. That's the muscle you need for this. |
| At university | Math, computer science, or engineering. Cryptography is its own course, usually from third year onward. What you saw here — prime numbers, clock arithmetic, groups — you'll learn properly in first-year math, under the names number theory and algebra. |
| Belgium | Happens to be a world player. AES — the secret-writing system from chapter 4 that the whole world uses — was invented by two Belgians, Joan Daemen and Vincent Rijmen, and was originally called Rijndael. The research group where that happened — COSIC, at KU Leuven — still exists and still ranks among the world's best. |
| Right now | There are competitions where you solve puzzles by cracking exactly this kind of thing: capture the flag (CTF). Look up "CTF for beginners". You don't need to know anything yet to start. |
How the site is built
| Part | Choice |
|---|---|
| Server | PHP, no framework |
| Demos | WebCrypto (crypto.subtle), no external libraries |
| The curves graph | Drawn by hand on a <canvas>, with the real formulas |
| Styling | One stylesheet, no build step |
| eID | Connection to the beID Hermes Platform |
The site allows no inline scripts at all (for anyone who knows the term: a strict Content Security Policy). That makes building it harder, but a site that explains how to do things securely should hold itself to the same standard.
What happens to your data
What you type into a demo stays with you. The demos run entirely in your browser. Your text, your passwords and the keys you make are never sent anywhere and never stored. Close the tab, and they're gone.
Visit numbers are measured, though. This site uses Google Analytics to see which chapters get read. That places cookies and sends data about your visit — which page, which country, what kind of device — to Google. Don't want that? An ad blocker stops it in most cases.
The eID chapter isn't measured. The pages where a card session runs are deliberately kept out of the statistics. Whatever comes off your card there gets shown once and kept nowhere — not in a database, not in a log file, and nothing goes to a third party.
Contact
Koen Thomeer, MD. Comments, mistakes and questions are welcome — especially if you're fifteen and something didn't make sense. Then it's the explanation's fault, not yours.