A 16-bit math shortcut doomed the NSA's Clipper Chip
In 1993, the United States government unveiled the Clipper Chip, an encryption microprocessor meant to secure phones while giving federal agents a built-in wiretap backdoor. But in 1994, computer scientist Matt Blaze exposed a fatal design blunder. The chip's Law Enforcement Access Field validated itself with a tiny 16-bit checksum. Because that meant only 65,536 possible combinations, an ordinary workstation could brute-force a fake identifier in 42 minutes, entirely disabling government eavesdropping.
The Rise of Key Escrow and the Clipper Chip
In the early 1990s, the rapid adoption of consumer digital telecommunications posed an unprecedented challenge to government surveillance. Law enforcement agencies, led by the Federal Bureau of Investigation, warned that widespread, unbreakable commercial encryption would blind legal wiretaps, creating a world where criminal conspiracies could coordinate with absolute technical impunity. The executive branch sought a compromise: strong cryptography that ordinary citizens and businesses could use against adversaries, paired with a guaranteed mechanism for lawful government interception.
In April 1993, the Clinton administration announced the Clipper Chip initiative, formalized under the Escrowed Encryption Standard as Federal Information Processing Standard (FIPS) 185. Manufactured as a tamper-resistant hardware microchip, the Clipper Chip was intended to be embedded directly into commercial telephone handsets, modems, and voice encoders. Designed by the National Security Agency, the chip used a proprietary, classified symmetric encryption algorithm called Skipjack. Skipjack operated on 64-bit data blocks using an 80-bit key, providing robust mathematical security against third-party eavesdroppers.
The political foundation of the Clipper Chip was key escrow. Each manufactured chip was provisioned with a unique, permanent cryptographic key known as the unit key. Rather than allowing users exclusive control over their communications, this unit key was split into two mathematical components. These components were deposited with two separate, independent government escrow agents. Under the official protocol, federal investigators armed with a valid judicial warrant could petition both agencies, combine the two halves of the key, and reconstruct the target device's unit key to intercept phone calls.