After the catastrophic breaches at Equifax — 143 million Americans' records, later restated above 145 million — and Yahoo, security engineer Diogo Mónica put a name on an architecture he had built years earlier: 'crypto anchors'. Mónica and colleague Nathan McCauley put the system in place at the payments firm Square before moving to enterprise software firm Docker in 2015.

Typically the web server must hold the database key to function, so whoever hijacks the server inherits it — roughly how Equifax's attackers are thought to have run. With a crypto anchor, the key lives only on a hardened Hardware Security Module that decrypts each record on request and rate-limits itself. Even at a million queries a day, draining Equifax's Social Security numbers would take over six months of continuous presence. Hashing doesn't rescue a conventional design either: with fewer than a billion possible SSNs, stolen hashes can be matched offline at leisure.

'The core concept is to ensure that your data is not only encrypted, but that the only way it can be decrypted or accessed or operated on is physically in your data center,' Mónica said. 'If someone compromises my database, if it gets leaked, it's not useful unless they're in my network.' Haroon Meer, founder of security firm Thinkst, framed the appeal: 'You make them play on your turf, so you see them coming.'

The setup was hardly widespread in 2017, but it ran where it mattered. Besides Square's implementation, Mónica said engineers at Facebook and Uber had told him privately they ran something similar, and Johns Hopkins cryptographer Matthew Green said he had consulted for multiple major tech firms on versions of it — 'old hat' to security designers, 'new in the sense that very few people actually do them.'

Real-time applications must decrypt on demand, so classic encryption places the key on the very web server attackers compromise first.

Hashing alone fails against small keyspaces: Social Security numbers can be exhaustively hashed offline and matched to stolen hashes.

Routing every decryption through one hardened HSM makes the key physically undownloadable and caps the data-out rate by hardware.

The price — hundredths of a second per request — buys an exfiltration clock counted in months, all of it visible to defenders.

Design for exfiltration, not just entry: rate is the resource a defender controls. A bottleneck you own turns a silent breach into a slow, loud siege.

By late 2017 Mónica claimed 'every security-engineering team that's really good is using some form of this', citing private confirmations from Facebook and Uber engineers. HSM vendors Gemalto and Thales had made such setups possible for years, and cloud versions — Amazon's CloudHSM, Microsoft's Azure Key Vault — put the pieces within reach of ordinary firms. Mónica could not promise crypto anchors would have stopped Equifax, whose attack path was still hazy, but argued it would have slowed the attacker and shrunk the haul.

FOLLOW THE EVIDENCE

The sources

  1. 'Crypto Anchors' Might Stop the Next Equifax-Style Megabreach wired.com