A cybersecurity policy professor on believing in the research process—and yourself ‘It Is an Act of Faith’ In high school, I liked math and was good at math and thought that I was going to be a mathematician: a weird thing to want to be as a teenager, but there it is. There were a lot of mathematicians who meant a lot to me; Andrew Wiles, with his proof of Fermat’s Last Theorem, loomed very large for me. I was also fascinated by a lot of older mathematicians; I did a research project on Madame Du Châtelet, who had translated Newton’s Principia into French. But I went to college with some people who were a lot better at math than I was. It was a new experience for me not be the strongest student in the class. I started to understand if I worked as hard as I possibly could, maybe I could major in math, but I was never going to be a great mathematician. I was good enough at math to appreciate and enjoy it, but I wasn’t good enough to come up with original math. It’s like the ability to appreciate great classical music while also knowing that you’re never going to perform it at that level. In theoretical math, the thinking is we’re going to perfectly prove everything—there will be no exceptions. In some ways, cybersecurity’s the opposite: there’s no way to actually finish this job. Instead, we’re going to perfectly prove how secure this encryption algorithm is, and then we’ll implement it … but then someone’s got to manage the encryption keys, someone else has to install the update … and 1,000 things are going to go wrong. The question I’ve found most interesting about cybersecurity research is: How do you marry the rigorous technical