Essay · Quantum & Physics

Riemann and the Locks

What a proof would actually do to cryptography, and who would have a reason to mind.

The question arrives attached to the spectral thread almost every time: if the primes are unravelled, does the internet stop working, and is that why the Riemann Hypothesis is still standing? It is a fair question with a clean answer, and the answer is more interesting than either the reassurance or the conspiracy.

This is a companion to The Quantum Chaos Mirror, which handles the mathematics. This one handles the consequences, with the same rule: every joint marked, and the parts that cannot be supported named rather than smoothed.

01

The proof changes nothing about the locks

What RSA actually rests on

The popular version of this question assumes that the Riemann Hypothesis is the keystone holding up internet security, and that pulling it out brings the building down. It is not, and it does not. The mistake is a conflation of two different things the primes are doing.

RSA security rests on the difficulty of factoring a specific large composite number into its two prime factors. That is a computational problem about one number at a time. The Riemann Hypothesis is a statement about the global distribution of the primes — specifically about the size of the error term in the prime counting function, which RH would pin at roughly √x·log x rather than the weaker bound currently proved. Knowing exactly how densely primes are spread across the number line tells you nothing about how to split a particular 2048-bit semiprime into its factors. The two problems touch the same objects and ask unrelated questions of them.

There is a second reason the proof itself would be uneventful: analytic number theory has been operating under RH for a century. Hundreds of published results are stated conditionally — 'assuming RH, the following holds' — and the algorithms that matter in practice already behave as though it were true. Miller's deterministic primality test is conditional on the generalised Riemann Hypothesis, and cryptographic key generation uses probabilistic tests that do not need it at all. A proof would convert a large body of conditional theorems into unconditional ones. That is a genuine event in mathematics and a non-event in security engineering.

So the accurate headline is: if RH is proved true tomorrow, no key becomes weaker, no protocol becomes breakable, and no ciphertext becomes readable that was not readable the day before.

  • EstablishedRSA rests on integer factorisation hardness, not on the distribution of primes; RH bounds the error term in π(x).
  • EstablishedMuch of analytic number theory is already stated conditionally on RH or GRH; a proof removes hypotheses rather than adding capability.
  • Refuted'Proving the Riemann Hypothesis breaks internet encryption.' It does not. No standard cryptosystem's security reduces to RH being false.

02

The tool, not the theorem

The one version of the worry that is not silly

There is a serious form of the concern, and it survives everything above because it is not about the statement at all. It is about the machinery.

Nobody expects RH to fall to an ingenious rearrangement of existing techniques. The consensus is that it will require genuinely new mathematics — a new operator, a new cohomology, a new way of seeing the primes that we currently do not have. And a new way of seeing the primes is exactly the kind of thing that could carry unintended consequences into computation. The person who invents an instrument sharp enough to prove RH may find that the same instrument does something else on the way past. That is not paranoia; it is the ordinary history of mathematics, in which techniques built for one purpose repeatedly turn out to solve unrelated problems in a neighbouring field.

The honest weight to put on this: it is a possibility with no mechanism attached. There is no known route from a spectral proof of RH to a fast factoring algorithm, and no result suggesting one exists. The concern is a statement about our ignorance of what the new mathematics would contain, and ignorance is not evidence. It should be held as a reason for the cryptographic community to keep its options open, which it already is, and not as a prediction.

It is also worth noting which direction the risk points. If the RH machinery did yield a factoring shortcut, the shortcut would be a classical algorithm — runnable on ordinary hardware, immediately, everywhere. That would be a far more abrupt event than the quantum threat, which requires hardware that does not yet exist at scale. Low probability, high abruptness. That asymmetry is the entire case for taking it seriously at all.

  • LicensedNew mathematics sufficient to prove RH could contain unanticipated computational consequences; techniques migrate across fields routinely.
  • AssertedThat such consequences would specifically include fast factoring. No known route, no mechanism, no partial result pointing that way.
  • EstablishedA classical factoring shortcut would be deployable immediately on existing hardware — unlike the quantum threat, which is hardware-bound.

03

The threat that is actually scheduled

Shor, harvest-now-decrypt-later, and lattices

While the RH scenario is speculative, a concrete one is already on the calendar, and it makes the Riemann question look almost recreational by comparison.

Shor's algorithm, published in 1994, factors integers and computes discrete logarithms in polynomial time on a quantum computer. It breaks RSA, Diffie–Hellman, and elliptic-curve cryptography — the entire public-key layer of the current internet — and it does so by a route that is fully understood. The only missing ingredient is a fault-tolerant machine of sufficient size, which does not exist yet. Nobody credible claims to know the date. Everybody credible agrees the direction.

This produces the 'harvest now, decrypt later' problem, which is the reason the transition is happening now rather than later. Encrypted traffic captured today can be stored and decrypted whenever the hardware arrives. Any secret that must remain secret for twenty years is already exposed if it is protected only by RSA today. That, not the Riemann Hypothesis, is what drives the timeline.

The response is post-quantum cryptography. NIST completed its selection process and standardised ML-KEM (from CRYSTALS-Kyber) for key encapsulation and ML-DSA and SLH-DSA for signatures in 2024. The lattice-based schemes rest on problems like Learning With Errors and finding short vectors in high-dimensional lattices — geometry, not arithmetic. Their hardness has no dependence on the primes whatsoever. Deployment is already underway in browsers and messaging protocols, typically in hybrid mode alongside classical algorithms.

The relevant point for this essay: the migration away from prime-based cryptography is happening for reasons that have nothing to do with RH, and it happens to close the RH scenario as a side effect. A total unravelling of the primes would not touch a lattice.

  • EstablishedShor's algorithm breaks RSA, DH and ECC in polynomial time given a fault-tolerant quantum computer; the algorithm is proved, the hardware is not built.
  • EstablishedNIST standardised ML-KEM, ML-DSA and SLH-DSA in 2024; lattice hardness (LWE, SVP) is independent of prime structure.
  • LicensedHarvest-now-decrypt-later makes the migration urgent for long-lived secrets regardless of when quantum hardware arrives.
  • Refuted'Post-quantum cryptography is proved unbreakable.' Lattice problems are believed hard, not proved hard — the assumption moved, it did not disappear.

04

Would anyone suppress it?

The incentive argument, stated without flattery to either side

The suspicion that institutional forces do not want RH solved is worth taking seriously enough to answer properly rather than dismissing as conspiracy thinking, because the underlying instinct — that capability and disclosure diverge — is correct and well documented.

Start with what is true. Classified mathematics is real. Differential cryptanalysis was known at IBM and the NSA years before Biham and Shamir published it in 1990. Non-secret encryption equivalent to RSA and Diffie–Hellman was developed at GCHQ by Ellis, Cocks and Williamson in the early 1970s and stayed classified until 1997. The Dual_EC_DRBG standard is widely believed to have contained a deliberate backdoor. So the claim 'agencies have withheld cryptographically relevant mathematics' is not speculation; it is history.

Now the part the conspiracy framing gets wrong. Suppression is not the strategy that a capability advantage recommends. If an agency held a factoring breakthrough, publishing nothing and warning nobody is exactly what it would do — but that is silence about its own tool, not suppression of a public research programme. It has no lever with which to stop several hundred number theorists across a dozen countries from working on a Millennium Prize problem, and it would gain nothing by trying: the advantage comes from adversaries continuing to use the vulnerable system, which is helped by their complacency, not by mathematical secrecy. The observable behaviour would be quiet migration of their own systems while saying little. Which is, awkwardly for both readings, roughly what the public post-quantum migration looks like from the outside.

And the sufficient explanation is much duller. RH is unsolved because it is extraordinarily hard. It has resisted Hilbert, Hardy, Selberg, Weil, Connes, and everyone since, in full public view, with a million-dollar prize and permanent fame attached. Attributing that to interference requires assuming the interference is more effective than the difficulty — and the difficulty is already sufficient on its own. Adding a suppressor explains nothing further, which is the standard test an extra hypothesis has to pass.

The version of this suspicion worth keeping is narrower and more useful: institutions disclose on their own schedule, and the gap between what is known and what is public is real and sometimes decades long. That is a reason to treat official reassurance as data rather than as verdict, and it applies to the post-quantum timeline more than it applies to Riemann.

  • EstablishedClassified cryptographic mathematics is documented: GCHQ non-secret encryption (1970s, declassified 1997), differential cryptanalysis known before publication, Dual_EC_DRBG.
  • LicensedAn agency holding a factoring breakthrough would rationally stay silent and migrate its own systems rather than attempt to suppress public research.
  • Refuted'RH is unsolved because it is being suppressed.' The difficulty of the problem is a sufficient explanation; the extra hypothesis does no additional work.
  • AssertedAny specific claim that a solution already exists in classified form. No evidence; unfalsifiable as usually stated.

05

What this thread is actually about

Where the corpus's interest in Riemann does and does not sit

It is worth being explicit about why this question keeps arriving attached to the spectral material, because the two interests are different and conflating them weakens both.

The reason to care about the Riemann Hypothesis in this corpus is not that it guards anything. It is that the zeros behave like the energy levels of a chaotic quantum system, that the explicit formula and the trace formula share an architecture, and that a fully deterministic sequence produces statistics indistinguishable from randomness at every order checked. That is a claim about the structure of arithmetic and its unexplained resonance with physics. Cryptography is downstream infrastructure that happens to use the same objects for an unrelated reason.

Keeping those separate protects the interesting claim. If the spectral thread is presented as being about breaking codes, it inherits an urgency it does not have and a set of critics it does not need. If it is presented as what it is — an unexplained correspondence between the deepest structure in number theory and the spectra of chaotic quantum systems — it stands on its own and does not require a threat to justify attention.

The practical summary, for anyone who wants only that: proving RH breaks nothing. Quantum computers will break RSA and the migration to lattice-based cryptography is already standardised and underway. The only live risk from the Riemann direction is that the unknown mathematics required to prove it might contain something else, and that is a reason for preparedness, not alarm. The preparedness is already happening for other reasons.

What would show this wrong

  • If a reduction is ever exhibited from the truth or falsity of RH to a factoring algorithm, section 01 is wrong and must be rewritten rather than qualified. No such reduction is currently known.
  • The claim that new RH machinery could yield a factoring shortcut has no mechanism attached. If it is cited here as a likelihood rather than an unquantified possibility, it has been overstated.
  • Lattice hardness is a believed assumption, not a theorem. If a fast classical or quantum algorithm for Learning With Errors or short-vector problems is found, the post-quantum standards fail and nothing in this essay's reassurance survives.
  • If a specific, documented instance of a state actor suppressing public number-theoretic research emerges — as distinct from withholding its own results — section 04 understates the case and should be corrected.
  • Absence of evidence for classified breakthroughs is weak evidence, given the documented decades-long disclosure gaps. This essay should not be cited as proof that no such capability exists, only that no reason exists to assume it does.
  • If quantum hardware capable of running Shor at cryptographic scale is demonstrated, the timeline framing here becomes historical and the urgency claims must be restated as fact rather than projection.

The reason to want the Riemann Hypothesis settled has never been what it protects. It is that a fully determined sequence of integers behaves like the energy spectrum of a chaotic quantum system, and nobody knows why. That question does not need a threat attached to be worth a century of work.

Sources