Own project / research
Cipher
Cipher is an experimental programming language. It explores one question in particular: can the rules about where sensitive data is allowed to go be checked by the compiler, so they hold even when someone forgets them.
One value, checked at build time
The problem it looks at
Most privacy and security failures are not exotic. A value that should have stayed private reaches a log line, an API response or a third party, because nothing in the language stopped it from getting there.
Code review, linters and runtime checks catch some of this. They catch it late, they catch it unevenly, and they depend on someone knowing to look in the first place.
The idea
Give the compiler enough understanding of which values are sensitive that it can follow them through a program and check how they are used.
Where a use breaks the rules, the build is rejected. The rule then holds because of how the language is built, not because everyone on the team remembered it that day.
What the compiler works with
Cipher adds a small set of research types and checks. These are the parts that carry the information-flow idea.
secret<T>
A label that marks a value sensitive. It travels with the value through the program the way a type does, so the compiler can see where the value goes.
A declassification boundary
A secret value becomes an ordinary one only through an explicit, checked step. A plain assignment or a cast will not do it.
capability<A>
Authority to do a privileged thing, passed as a value you can see in the code, rather than an ambient permission that is always available.
temporary<T>
A value whose runtime storage is cleared when it leaves scope, so a secret does not sit in memory longer than it needs to.
Runtime policy guards
A second boundary that checks at run time, for the cases the compiler cannot settle on its own.
Native compilation
Cipher compiles to native code through LLVM. The checks run inside the compiler, not as a separate tool that can be skipped.
What a rejected flow looks like
A short example, using real Cipher identifiers. The point is the first line that does not compile.
let password: secret<string> = "hunter2"
say(password) // rejected: a secret value sent straight to output
let intent = request_intent("Declassify")
let cap = prove(intent)
let visible: string = declassify(password, cap)
say(visible) // allowed: declassified through an explicit capability
Where Cipher stands
Cipher is a research alpha. It compiles and runs real programs, and the information-flow checks described here work on the cases they are built for. It is not production-ready, and it should not yet be used to protect real sensitive data.
The source is not public and there is no release date. What is on this page is a description of work in progress, not a plan or a promise.
- Working: the compiler and language, and the flow checks for outputs the compiler knows about.
- Still experimental: the parts beyond the core language, including encrypted storage and messaging.
- Not the whole picture: the checks reduce accidental disclosure. They are not a defence against every kind of attack, and they do not cover code outside Cipher's own checks.
Why I work on this
Cipher is where I test security and reliability thinking against a hard problem, on my own initiative and without a deadline deciding the answer.
What it turns up feeds back into how I design and review other software. Cipher is not a product, and client code is never used to develop it.
Where to go next
Cipher is one part of my work.