Standard cryptographic research typically evaluates a design by whether it satisfies a formal definition in a given model with stated costs. Systems that matter in society, however, run for years under heavy and sometimes hostile use and must fit strict resource budgets. Motivated by this tension, this talk asks what it means for designs to "work" once deployed, through three lenses: stability, models, and cost. Secure society runs on rails for naming and paying. Here I will use anonymous credentials and cryptocurrencies as concrete examples. Even with strong cryptography, the lifecycle of anonymous records and the everyday handling of abuse and disputes influence how the system behaves in practice. Relegating these questions to afterthoughts tends to make such systems unsustainable in the long run. Multi-party data flows shift attention to what platforms and collaborators learn about users. Alongside our own work, I will draw on deployed secure aggregation, encrypted search systems, and private set intersection. New stresses appear when schemes designed for simple paper models are run in multi-client settings with different service requirements. Computation based on large machine-learning models now drives many online systems. Here the focus is on secure machine learning (ML), from differential privacy to cryptographic techniques. On realistic models, generic secure computation and proof techniques remain expensive, so secure ML–crypto co-design built around model structure and service budgets becomes necessary. With these case studies, the talk aims to sharpen our sense of how stability, models, and cost shape cryptographic system design.