Mike Rosulek's *The Joy of Cryptography* is a mathematics textbook on provable security. It explains why cryptographic constructions satisfy formal definitions and what each definition permits an attacker to do. This recommendation concerns the current online edition, accessed on 7 October 2026, and excludes earlier PDF drafts and any print version. In the preface, Rosulek argues that security demands reasoning about arbitrary components across every possible input, because output that looks random in a sample proves nothing. We recommend the book to programmers prepared to work through mathematics who want to state exactly what a security claim protects, from whom, and under which assumptions.
The early chapters build the method that the rest of the book reuses. Beginning with the one-time pad, Rosulek writes the attacker's position as a library: a set of subroutines the adversary may call, with secret values held inside. A security definition says that two libraries are interchangeable to any calling program, and a proof converts one into the other through a sequence of justified transformations. The format exposes two inputs: the queries the adversary may make and the assumptions the construction depends on. How a ciphertext looks plays no part. Rosulek also marks where his early proofs stop.
The chosen-ciphertext material shows the method absorbing a stronger adversary. Chosen-plaintext security gives the attacker encryptions, and chosen-ciphertext security adds decryptions. Rosulek's decryption oracles, including oracles that reveal only whether a ciphertext is correctly formatted, model an active attacker who submits altered ciphertexts and learns from the replies. Malleability lets that attacker modify a ciphertext predictably, and confidentiality proved against the weaker adversary does not extend to such manipulation. The reader learns to separate the access an attacker holds from the property at stake, confidentiality or authentication.
The same format gives privacy questions a precise shape. Each definition names the secret it protects and the view from which it is protected: a plaintext hidden from an attacker who sees ciphertexts, or one who also receives decryption replies. A reader can check both before accepting that something stays private. In our assessment, the precision also sets a limit. A proof that one secret stays hidden from one view does not establish anonymity, conceal who communicated with whom, or certify a messaging product as private overall. Each of those claims needs its own definition and evidence.
The secure-messaging chapter separates two ratchet properties. A symmetric ratchet evolves the key and deletes old state. Under the chapter's assumptions, an attacker who captures the current state cannot recover keys for earlier messages, which is forward secrecy. An asymmetric ratchet mixes fresh contributions from the parties into later keys, so security can recover after a compromise once the parties supply input the attacker did not see. The double ratchet combines both, and group messaging and MLS receive separate treatment. Deletion protects past messages but does nothing against an attacker who still controls an endpoint. A reader can then ask of any messaging design which compromise it survives and on what condition.
Ratcheting limits how long a compromise exposes traffic. Authenticated key exchange settles a separate question: with whom the key is shared. Rosulek shows that ordinary Diffie-Hellman alone permits a person-in-the-middle attack, in which each victim ends up sharing a key with the adversary. Authenticated key exchange associates the established key with the holder of a known public key. His successive attempts to authenticate the exchange with signatures show that a signature alone does not make a complete protocol; the protocol must also bind the parties' identities and the transcript context. By our reading, the guarantee reaches as far as a public key the participant already knows. Tying that key to a named person or organization is a separate problem.
The zero-knowledge chapter applies the same comparison to interactive proofs. For sigma protocols, honest-verifier zero knowledge compares real transcripts of the interaction with transcripts generated by a simulator that never holds the secret witness. If the two are indistinguishable, the transcript gives the verifier nothing it could not have produced alone. The definition covers only verifiers that follow the protocol. Before treating a transcript as harmless, a reader should therefore ask whether the verifier in question was assumed honest.
These parts share one structure. A one-time pad, a decryption oracle, a captured ratchet state, an intercepted key exchange and a simulated transcript each become a statement about what an attacker can see or query, what stays hidden from that view and what the construction assumes. The same structure sets the book's scope: it explains why constructions meet definitions, and it does not audit code, endpoints, deployments or current standards. The preface addresses third- and fourth-year undergraduate computer science students. It expects a first discrete mathematics course covering functions, sets, tuples and strings; discrete probability, including conditional probabilities and bounds; and the ability to read pseudocode correctly and recognize when two programs are equivalent. The library proofs depend on that last skill, since they compare programs. Read the book to determine, for a given construction, which adversary it was proved against, with what access, which secret stays hidden and under which assumptions.
