Search
RSS Feed

How hard can it be? – Part 1: I thought breaking Enigma would be easy

by Christian Rudolph

Published: 24 July 2026

Tags: Enigma Bletchley Park encryption scientific rigour critical thinking

A recreational four-part summer series about trying to recover the settings of real wartime Enigma messages, eighty years after Bletchley Park had already read them.


Standing in one of the huts at Bletchley Park, I found myself looking at a real wartime intercept lying on a desk. Everyone knows Enigma was broken. Turing, the Bombe, the war supposedly shortened by two years – the story is so well worn that it has become a kind of national furniture. Which is precisely why I assumed that breaking a message myself would be more or less trivial. Eighty years of progress. A computer in my pocket with computational power beyond anything available to wartime cryptanalysts. Surely this was a solved problem, and solved problems are easy.

I was wrong, and the manner of being wrong turned out to be more interesting than being right would have been.

A photograph on a desk

The whole thing was triggered by a book. I had been reading The Bletchley Riddle with my son, which, in my personal opinion, is outstanding, and it put me in exactly the frame of mind to notice things I would otherwise have walked past. On one of the desks in the huts, among the reconstructed clutter of wartime working life, lay a sheet of paper. It had a date on it: 28/2/41. I took a photograph, the way you do, without any particular plan.

A German intercept, shown at Bletchley Park

A German intercept, shown at Bletchley Park

The date matters, as it turns out, though I did not appreciate why at the time. A message from February 1941 at least appeared to offer a relatively conventional three-rotor problem, rather than one of the more exotic systems and procedures that appeared elsewhere or later in the war. As Enigma challenges go, it looked like a fair fight. If any Enigma message was going to yield to an afternoon of enthusiasm and a modern laptop, it was this one.

Then I found that the Bletchley Park Trust publish an Enigma simulator online, and the idea arrived fully formed: could I attack this? Not admire it, not read about it – actually break it, from ciphertext to German, myself.

At first I thought I could not. But let me explain the machine first, because the reason I failed, initially, is the whole point.

What the machine actually does

Enigma is, at heart, a very elaborate way of swapping letters. You press a key, current flows through a series of scrambling stages, and a lamp lights up showing the encrypted letter. The genius – and the weakness – is all in how that current flows.

An original Enigma machine, shown at Bletchley Park

An original Enigma machine, shown at Bletchley Park

It helps to trace a single letter. I find it easiest to pretend, just for a moment, that each rotor is a simple shift, though in reality each one is an arbitrary scramble of the alphabet rather than a neat step along it. Ignore the plugboard for now. Press A. The first rotor turns it into, say, B; the second into C; the third into D. The current then hits the reflector, which sends it back through the rotors by a different path – turning D into, say, M – and back out through the three rotors again: M to L, L to K, K to J. The lamp for J lights up.

Here is the beautiful part. Because the reflector bounces the current back through the same machinery, the whole process is symmetric. On the identical settings, if I now press J, the current runs J–K–L–M–D–C–B–A, and A lights up. Encryption and decryption are the same operation on the same machine. This is why the recipient, with his Enigma set exactly as the sender's had been, simply typed the gibberish in and read the German out. It is also why the machine can never encrypt a letter as itself – a small fact that Bletchley would exploit ruthlessly, but that is a later story.

One more thing, and it is the thing that makes the whole problem hard: the rotors move. After every single keystroke the fast rotor steps on by one position, and periodically drags the middle and slow rotors with it. So the scrambling is different for every letter you type. Press A twice and you get two different lamps. This is why the starting position of the rotors is so critical — get that wrong and every letter after the first is wrong too. Finding that starting position is the heart of the attack. Incidentally, this is also why all rotors acting by a single increment would not make any sense. If the rotors merely shifted the alphabet by fixed amounts, three rotors would offer little more than one: the shifts could simply be added together. Their power comes from each rotor containing a different, irregular wiring of the alphabet, combined with movement that changes the overall substitution after every keystroke.

The settings that define the day

Every Enigma operator on a particular network used the same daily key: the same rotor selection and order, ring settings and plugboard connections. Individual messages also required their own starting position, or message setting, which had to be conveyed to the recipient according to the procedure then in use. I have a photograph of one of these – an Army sheet, headed OKH-Maschinenschlüssel A Nr. 39 – and it is worth looking at, because it makes concrete what "the settings" actually means. My favourite detail is the warning printed at the top: Geheim! Nicht ins Flugzeug mitnehmen! – Secret! Do not take into an aircraft! Losing a key sheet to a crashed plane behind enemy lines was precisely how the Allies got their hands on documents like this one, so the instruction was entirely sincere.

A sheet with Enigma settings from the Army, shown at Bletchley Park

A sheet with Enigma settings from the Army, shown at Bletchley Park

The sheet is a month at a glance. Each row is one day – and note that the dates count down the page, from the 31st at the top to the 1st at the bottom. Reading across, each day gives you the Walzenlage (which three rotors, in which order), the Ringstellung (how far each rotor's internal wiring is rotated relative to its ring), the Steckerverbindungen (the ten plugboard pairs), and the Kenngruppen (four little three-letter groups used to tell the recipient which day's key was in use).

Take a single day as an example. One day's row specifies a wheel order of I, V, III and a ring setting of 16 07 02 – three rotors, in that order, each turned to that internal offset – followed by ten plugboard pairs swapping letters two at a time. Get all of it right and you read German. Get any one field wrong and you get noise, or worse, something that looks almost right. Hold on to that last phrase, because it is where the whole afternoon came apart.

The attack, and why it very nearly worked

My plan was the obvious one. There are only so many rotor orders and starting positions – a large number, but not an impossible one for a computer. So try them all. For each combination, decrypt the message and score how German-looking the result is, using the statistical fingerprints that any language leaves: how often letters coincide, how often common pairs appear. Rank every combination by that score. Read off the winner.

The computer did this happily and handed me a ranked list. And the top of the list was, quite clearly, not random. The best few thousand settings scored meaningfully better than pure chance. Something real was being detected.

But when I looked at the actual decrypts of those top-ranked settings, none of them were German. They were German-ish. Right sort of letter frequencies, right texture, occasional real fragments – and then nonsense. And here is the killer: across the top 2,500 hits, the statistical significance separating a good candidate from a mediocre one was simply too low. The scores formed a gentle slope, not a cliff. There was no bright line that said this one. Someone – some human – would have had to sit and read all 2,500 by eye to find the real message hiding among the near-misses. That is not an attack. That is a punishment.

The villain of the piece

Why did the attack fail to produce a clear winner?

The plugboard.

Before the current enters the rotors, and again after it leaves, the plugboard swaps ten pairs of letters. Twenty of the alphabet’s twenty-six letters are therefore involved. Crucially, this is not merely a final substitution that can be peeled away afterwards. The plugboard alters the signal before it passes through the moving rotors and then alters it again on the way out. Its effect is entangled with the rotor settings at every position in the message.

My attack had tried to identify promising rotor settings first and solve the plugboard afterwards. That sounds like a sensible division of labour, but Enigma does not divide so politely. A rotor setting can be right without producing readable German under the wrong plugboard, while incorrect settings can still acquire deceptively respectable language scores by chance. The result was not one obvious answer but a broad hill of candidates, none standing far enough above its neighbours to be trusted.

Let me show you, because this is the one point in the whole affair that has to be seen rather than described. Here is a short message that I invented entirely: Keine besonderen Vorkommnisse. Nächste Meldung um null Uhr, or "nothing to report, next signal at midnight." Two conventions that are important to know: Enigma had no key for the "ä" Umlaut. "Ä" would have been written as "AE". The machine also had no space key, so words normally ran together; where a break needed marking, X was used as a separator. So, the message above could have been enciphered roughly as shown below:

KEINEXBESONDERENXVORKOMMNISSEXNAECHSTEXMELDUNGXUMXNULLXUHR

If enciphered on a standard 1941 machine, this is what would have gone over the air:

LFUPO MDTJT GJXQZ DPSPN WGVDC YMAFT JZCTW AJXPW WUUNO STVRO JTTBB RSH

Broken into five letter groups for operator convenience, as was typical for Army and Luftwaffe messages (Navy messages used four letter groups). Now suppose I have done the hard part. I have found the correct three rotors, in the correct order, at the correct ring settings – everything right except the plugboard, which I have left empty. Surely something readable should show through. Here is what comes out:

DLMQX QRGDM RSWNN KXQFR KZMPA OISLM RSSCU NCGXV LBGJG ZOIWX RJWCA JWE

Nothing. Not a word, not even a fragment. It is surprisingly indistinguishable from the ciphertext above it. And yet the rotors and all other settings are correct. Only when the plugboard is also set exactly right does the message appear:

KEINE XBESO NDERE NXVOR KOMMN ISSEX NAECH STEXM ELDUN GXUMX NULLX UHR

The reason is arithmetic, and it is worse than it looks. Ten plugboard cables do not swap ten letters – each cable works in both directions, so ten pairs swap twenty of the twenty-six letters, leaving only six untouched. And the plugboard wraps the rotor scrambling on both sides, entry and exit, so the two layers do not add, they multiply. Solving the rotors without the plugboard does not get you most of the way there. It gets you nowhere you can see. That is why the statistical attack could rank the rotors nearly right and still leave me staring at gibberish: the plugboard was standing between me and every near-correct answer, and it does not yield to being nearly solved.

Thus, the statistical approach tantalises and then betrays you. The plugboard leaves just enough signal for a fitness score to sense that the rotors are nearly right – and not enough for it to say which setting is actually correct. The right answer and a hundred wrong ones all sit in the same gentle band near the top. This is precisely why the wartime codebreakers had a cleverer method that attacked settings and plugboard together. For now the lesson had landed, and it was not the lesson I expected.

A better experiment

Ernest Rutherford is supposed to have said that if your experiment needs statistics, you ought to have done a better experiment. It is a characteristically unfair remark, and like most unfair remarks it contains an uncomfortable amount of truth.

My statistical attack was the experiment that needed statistics. It gave me a probability distribution – a ranked heap of maybes – and no defined endpoint. It could tell me where the answer probably was, and then leave me to do the actual work by hand. What Bletchley built instead did not ask which output looked most like German. Given a guessed fragment of plaintext – a crib – it asked whether a proposed setting generated a logical contradiction. Most settings could therefore be rejected absolutely rather than merely scored poorly. The Bombe’s surviving “stops” were not guaranteed answers; they still had to be checked. But it had transformed an unmanageable mountain of plausible-looking results into a much smaller collection of settings that had passed a hard consistency test.

How they managed that – and what they had to give up to get it – is where this series is going next.


Similar and related posts: