History

The history of cryptograms

The puzzle in your newspaper is a decommissioned weapon. For most of recorded history, replacing each letter of a message with a different letter was not a pastime — it was how a general kept a battle plan, how an ambassador kept a negotiation, and how a conspirator kept his neck. It stopped being any of those things for a specific, documentable reason, and the reason is the whole story of this page.

A cipher people trusted

The idea is old enough that we cannot name its inventor. Substitution appears in Egyptian inscriptions, in Hebrew scribal practice, and, most famously, in the Roman shift cipher named after Julius Caesar, who moved every letter a fixed number of places along the alphabet. That shift version is weak — there are only twenty-five of them, and you can try all twenty-five over lunch.

The general form — what a cryptogram is, the kind we publish — is not weak in the same way. Let each letter map to any other letter, and the number of possible keys is 26 factorial: about four hundred thousand billion billion arrangements. A person testing one key per second would still be going long after the sun burns out. For centuries that number was the argument, and it looked unanswerable. It is also completely beside the point, and that is the single most useful thing this puzzle can teach you about secrecy.

al-Kindi, and the sentence that killed it

Around 850 CE, in Baghdad's House of Wisdom, the polymath Abu Yusuf Ya'qub al-Kindi wrote a treatise usually translated as A Manuscript on Deciphering Cryptographic Messages. It contains what is, as far as anyone has found, the first written description of frequency analysis — and with it the first recorded piece of statistical inference of any kind.

His instruction is startlingly plain. Take a text in the same language as the message, long enough to fill a page. Count how often each letter occurs. Rank them. Then count the letters of the enciphered message, rank those, and match the two lists — the most common symbol to the most common letter, the next to the next — and correct by trial from there.

That is it. Four hundred thousand billion billion keys, and none of them matter, because you never search the keyspace. The cipher hands you the frequencies of the original text along with the message, and no amount of key-space arithmetic can take that back. It is the earliest clear demonstration of a principle modern cryptographers state as a rule: a cipher is only as strong as the statistics it destroys, and monoalphabetic substitution destroys none of them.

Al-Kindi's manuscript itself dropped out of view for a very long time and was rediscovered in an Ottoman archive in Istanbul in the 1980s. The technique, however, never went away.

Seven hundred years of using it anyway

Knowing a cipher is broken and behaving accordingly are different things, and Europe took the long route. Simple substitution and its dressed-up cousin the nomenclator — a substitution alphabet plus a list of code words for common names and phrases — remained standard diplomatic practice into the sixteenth century.

The famous demonstration came in 1586. Mary, Queen of Scots corresponded with the conspirators of the Babington Plot in a nomenclator she believed secure. Elizabeth I's cipher secretary Thomas Phelippes broke it by counting, read the letters as they passed, and forged an addition to one of them to draw out the plotters' names. Mary was executed the following year. The cipher had been theoretically dead for seven hundred years; it took a treason trial to make the point stick.

The genuine fix already existed — the polyalphabetic ciphers of the Renaissance, which use several substitution alphabets in rotation and so smear the letter frequencies. Once those spread, plain substitution had no serious use left. What it had instead was an audience.

How it became a puzzle

The nineteenth century is when the cipher changed jobs, and Edgar Allan Poe did more than anyone to push it. In December 1839, writing for Alexander's Weekly Messenger, Poe challenged readers to send in substitution ciphers of their own devising, promising to solve any of them — provided the word spacing was preserved. He kept the promise often enough and publicly enough to build a reputation as a cryptographer, followed it in 1841 with an essay, "A Few Words on Secret Writing", and in 1843 put a cipher at the centre of his most widely read story, "The Gold-Bug". A generation of readers learned that a substitution cipher was something an ordinary clever person could break at a kitchen table.

From there it became furniture. Newspapers ran cryptograms as a standing feature; a convention settled that no letter would ever stand for itself, which quietly removes twenty-six dead guesses; puzzle books gathered them in hundreds. The American Cryptogram Association, founded in 1930, has published a members' magazine of them ever since. Syndicates gave the daily versions brand names — which is why the same puzzle reaches most people today under a trade name rather than a generic one, a tangle sorted out on cryptoquote vs cryptogram.

Why it is not security, and never will be again

Worth saying plainly, because "cipher" is a word that makes people nervous: solving these teaches you nothing about breaking anything real, and hiding anything real behind one would be reckless.

Claude Shannon gave the number in 1949. The unicity distance of a cipher is the amount of ciphertext beyond which only one key can produce sensible plaintext — beyond which, in other words, the answer is unique and merely has to be found. For simple substitution on English it is roughly twenty-eight letters. Six words. Almost every puzzle you have ever solved was, from the moment it was printed, mathematically certain to have exactly one answer.

And a computer does not need al-Kindi's patience. Hill-climbing over letter-pair statistics solves a typical board in milliseconds. Modern ciphers survive precisely because they leak none of the structure this one leaks: no word spacing, no repeated blocks, no frequencies. Everything that makes a cryptogram solvable by a person on a train is exactly what a real cipher is built to destroy. That is not a flaw in the puzzle. It is the puzzle.

al-Kindi's method, run on a real board

Quote: "Integrity without knowledge is weak and useless, and knowledge without integrity is dangerous and dreadful." — Samuel Johnson (English, 1709–1784 — public domain, textually verifiable). Difficulty: Hard (15 words, 17 unique letters).

Why this board. Fifteen words, but only nine distinct ones — integrity, without, knowledge and is each appear twice and and appears three times. It is the clearest board in our corpus for the thing al-Kindi's method actually exploits: the cipher hides the letters and leaves every trace of the structure standing.

  1. Count. That is the entire ninth-century method, and it goes first. Ninety-one letters on this board. Symbol 3 appears eleven times — 12.1% of the text. Nothing else exceeds eight.
  2. Match the count against the language. E is the most common letter in written English at about 12.7%. The board's top symbol is at 12.1%. That is not a hunch, it is a match to within half a percentage point: 3 = E. Al-Kindi's rule has just handed you the most valuable letter on the board, from arithmetic alone.
  3. Watch the method stall, exactly where he said it would. Four symbols — 5, 12, 19 and 11 — are tied on eight occurrences each. English's ranking after E runs T, A, O, I, N, and one of those four tied symbols will turn out to be D, whose ordinary share is about 4%. Counting cannot break that tie on ninety-one letters, and al-Kindi's own text says as much: rank, then correct by trial and by the shape of words. The numbers themselves, and how fast they degrade, are on letter frequency in English.
  4. Spend the given letters. T = 19 and A = 18, everywhere they occur.
  5. Now the structure the cipher failed to hide. Words 1 and 11 are the same nine symbols. So are 3 and 9, and 2 and 10, and 4 and 12. Words 6, 8 and 14 are all 18 12 11. Nine distinct words in a fifteen-word sentence — visible before a single letter was solved.
  6. The three-times-repeated word.18 12 11 is A ? ?AND: 12 = N, 11 = D. Two of step 3's four tied symbols, resolved by shape rather than by counting.
  7. The two-letter word.5 6 is ? ?, and 5 is another of the tied symbols. IS fits: 5 = I, 6 = S.
  8. The long repeat.5 12 19 3 24 7 5 19 16 reads I N T E ? ? I T ?INTEGRITY: 24 = G, 7 = R, 16 = Y. Nine letters for one guess, and it pays twice.
  9. The second repeat.21 5 19 9 2 14 19 is ? I T ? ? ? TWITHOUT: 21 = W, 9 = H, 2 = O, 14 = U.
  10. The third.26 12 2 21 8 3 11 24 3 is ? N O W ? E D G EKNOWLEDGE: 26 = K, 8 = L.
  11. Forced, no guessing left.21 3 18 26 = WEAK. 14 6 3 8 3 6 6 = USELESS. 11 18 12 24 3 7 2 14 6 = DANGEROUS. 11 7 3 18 11 22 14 8 is D R E A D ? U LDREADFUL, giving the board's last letter, 22 = F.

Read it:"Integrity without knowledge is weak and useless, and knowledge without integrity is dangerous and dreadful."

Six guesses, seventeen letters, ninety-one cells. Step 2 was al-Kindi's contribution and it was worth exactly one letter — the right one. Everything after it was the cipher failing to hide the shape of the sentence. Both halves of that are the reason this stopped being a way to keep a secret and became a good way to spend ten minutes.

Or browse more Samuel Johnson cryptograms.

Solve a piece of the history

The method below is a thousand years old and still the fastest way in. Try it on medium cryptograms, or print a pack of philosophy cryptograms and solve them the way Poe's readers did, on paper.

Common questions

Who invented cryptograms?

Nobody can be credited with the invention. Letter-substitution writing turns up independently in Egyptian inscriptions, Hebrew scribal practice and Roman military use — the shift cipher named for Julius Caesar is the best-known ancient example. What is attributable is the moment it became solvable rather than secret: the ninth-century scholar al-Kindi, who wrote down the method for breaking it. Cryptograms as a deliberate entertainment are a nineteenth-century development.

When were cryptograms invented?

Substitution ciphers are at least two thousand years old; the Caesar cipher dates to the first century BCE. The technique for breaking them was written down around 850 CE. Their life as a published puzzle rather than a serious cipher begins in the nineteenth century, with Edgar Allan Poe's cipher challenges to readers from 1839 onward and the newspaper features that followed.

Why are they called cryptograms?

From the Greek kryptos, hidden, and gramma, something written — a hidden writing. The same root gives cryptography and crypt. The word describes the artefact rather than the method, which is why it covers any hidden text and why more specific names — cryptoquote, and the syndicated Cryptoquip — grew up alongside it. Those distinctions are set out on cryptoquote vs cryptogram.

Who first broke substitution ciphers?

The first person known to have written down how is Abu Yusuf Ya'qub al-Kindi, working in Baghdad's House of Wisdom around 850 CE. His treatise describes frequency analysis: count the letters of a sample of ordinary text in the message's language, count the symbols of the enciphered message, rank both, match them and correct by trial. It is also the earliest surviving example of statistical inference applied to anything.

Are cryptograms used in real cryptography today?

No, and they have not been for centuries. A simple substitution cipher preserves word spacing, repeated words and letter frequencies, all of which are precisely what an attacker needs. Shannon's unicity distance for the cipher is around twenty-eight letters, meaning almost any real message has exactly one possible solution, and modern software solves a puzzle-length board in milliseconds. The properties that make it useless as security are the same ones that make it a good puzzle.

What did Edgar Allan Poe have to do with cryptograms?

More than any other single figure. From December 1839 he challenged readers of Alexander's Weekly Messenger to send him substitution ciphers he would solve, solved a great many of them in public, wrote an essay on the subject in 1841, and built "The Gold-Bug" (1843) around deciphering a coded message. That story was the most widely read of his lifetime, and it taught a mass audience that breaking a substitution cipher was an ordinary, learnable skill rather than a specialist art.

Ready to crack one?

Start decoding — it's free