Famous and Not So Famous Unsolved Codes
Elonka Dunin, Klaus
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
In a captivating presentation at DEF CON 32, renowned crypto experts Elonka Dunin and Klaus Schmeh delved into the intriguing world of unsolved encrypted messages, highlighting both widely recognized and lesser-known cryptographic puzzles that continue to baffle researchers. The talk, titled "Famous and Not So Famous Unsolved Codes," explored the historical context, persistent challenges, and ongoing efforts to decipher these enigmatic texts. Dunin, a game developer and crypto authority, and Schmeh, a German IT security and crypto history expert, are co-authors of "Codebreaking: A Practical Guide," underscoring their deep expertise in the field.

Key moments
- 0:00 Speakers introduce famous and not-so-famous unsolved codes.
- 0:27 First unsolved code: The Kryptos sculpture at CIA headquarters.
- 2:00 K4, the unsolved part of Kryptos, and recent clues.
- 3:20 Kryptos in Dan Brown's "The Lost Symbol" and Nola K.
- 4:22 Next mystery: The Debosny's cryptograms from 1882.
- 4:40 Henry Debosny's quick marriages and suspicious deaths.
Famous and Not So Famous Unsolved Codes
Speakers: Elonka Dunin, Klaus Schmeh
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=tJyH6FDFy_E
Overview
In a captivating presentation at DEF CON 32, renowned crypto experts Elonka Dunin and Klaus Schmeh delved into the intriguing world of unsolved encrypted messages, highlighting both widely recognized and lesser-known cryptographic puzzles that continue to baffle researchers. The talk, titled "Famous and Not So Famous Unsolved Codes," explored the historical context, persistent challenges, and ongoing efforts to decipher these enigmatic texts. Dunin, a game developer and crypto authority, and Schmeh, a German IT security and crypto history expert, are co-authors of "Codebreaking: A Practical Guide," underscoring their deep expertise in the field.
The core of their discussion revolved around two prominent examples: the Kryptos sculpture at CIA headquarters and the Debosny's cryptograms from a 19th-century murder case. Through these examples, the speakers illustrated the diverse nature of cryptographic challenges, ranging from modern artistic ciphers designed with intentional complexity and misdirection to historical puzzles shrouded in mystery and the passage of time. The enduring nature of these unsolved codes serves as a testament to the sophistication of cryptographic design, the limitations of brute-force attacks without sufficient context, and the persistent human fascination with secrets.
This article provides a detailed technical analysis of the cryptographic mysteries presented by Dunin and Schmeh, examining their origins, the efforts made toward their solution, and the reasons for their continued resistance to decipherment. It also explores the broader implications for cryptography and codebreaking, offering insights into the methodologies employed by both creators and solvers of complex ciphers. The talk ultimately underscored the collaborative spirit of the codebreaking community, emphasizing that even in an age of advanced computational power, human ingenuity, historical research, and collective effort remain paramount in confronting the most formidable cryptographic challenges.
Background
▶ Watch: Speakers introduce famous and not-so-famous unsolved codes. (0:00)
The presentation provided essential historical and contextual background for each of the unsolved codes discussed, framing them within their respective eras and circumstances. The Kryptos sculpture, arguably the most famous modern unsolved cipher, was commissioned in 1988 and installed in 1990 outside the CIA headquarters in Langley, Virginia. Its creation involved sculptor Jim Sanborn and cipher designer Ed Scheidt, who is described as a "spook" with a long involvement with the CIA, despite the non-existence of a "CIA Cryptographic Center" as he is sometimes listed. The sculpture's inscription is divided into four sections, K1 through K4, with the first three parts successfully deciphered over the years, leaving K4 as the enduring challenge. The sculpture's prominence was further amplified by its significant role in Dan Brown's 2009 novel "The Lost Symbol," a sequel to "The Da Vinci Code," which featured both Kryptos and Freemasons and even included a character, Nola K, named after Elonka Dunin due to her assistance with the book's research.
In stark contrast to the modern, institutionally linked Kryptos, the Debosny's cryptograms transport us back to 1882 in Essex County, New York. This historical puzzle emerges from a grim criminal case involving Henry Debosny, a stranger who arrived in the county, quickly courted and married a widow named Elizabeth Wells. His previous two wives had died shortly after marriage, adding a sinister undertone to his rapid courtship. Tragically, Elizabeth Wells was found dead—stabbed and shot—only weeks after their wedding, making Debosny the prime suspect. The sequence of events was swift: Debosny arrived on May 1st, married five weeks later, and his wife was murdered seven weeks after that. While in jail awaiting trial, Debosny, described as an educated individual proficient in literature, multiple languages, and art, created a series of encrypted messages. His trial began on January 20, 1883, culminating in a death sentence on April 16. A peculiar detail of his story is that he sold his body to a local physician for scientific experiments to afford a new suit for his execution. These cryptograms, penned under such dramatic circumstances, remain unsolved, providing a tangible link to a dark historical event and the mind of a condemned man.
The persistence of these unsolved codes highlights several fundamental challenges in cryptanalysis. For Kryptos, the short length of K4 (just 97 characters) significantly reduces the statistical information available for frequency analysis and other common cryptanalytic techniques. The possibility of a key accessible only on CIA grounds, intentional misdirection by the designer, or even a deliberate mistake rendering it unsolvable adds layers of complexity. For Debosny's cryptograms, the lack of contextual information regarding the cipher method used, the specific language, or any potential keys, combined with the historical distance, makes their decipherment a formidable task. These puzzles serve as powerful reminders that while modern cryptography focuses on security against sophisticated attacks, historical codes often present unique difficulties rooted in incomplete information and the passage of time.
Key Findings
▶ Watch: K4, the unsolved part of Kryptos, and recent clues. (2:00)
The central "key finding" of this talk is the enduring nature of these specific cryptographic puzzles, emphasizing that despite decades of dedicated effort from a global community of cryptanalysts, both the modern Kryptos K4 and the 19th-century Debosny's cryptograms remain unbroken. This speaks volumes about the inherent difficulty of certain ciphers, the impact of limited ciphertext length, and the challenges posed by historical context and potential misdirection.
For Kryptos K4, the primary finding is its continued resistance to solution, even after the decipherment of the preceding three sections (K1, K2, K3). The talk highlighted specific clues provided by the sculpture's creator, Jim Sanborn, which represent significant contributions to ongoing efforts:
- 2010 Clue: Sanborn revealed that starting at the 64th character of K4, the word "Berlin" appears, followed by the word "clock." This partial plaintext provided a crucial anchor, sparking extensive research into "clocks in Berlin" by the codebreaking community, suggesting a potential thematic or geographical link within the message.
- January 2020 Clue: A second clue was released: the word "Northeast."
- Pandemic-era Clue: During the pandemic, Sanborn provided a third clue to "stir things up": the word "East."
Despite these explicit plaintext clues, which collectively reveal a "big chunk" of the supposedly deciphered text, the full message of K4 has not been fully understood or reconstructed. This paradoxical situation—having parts of the solution without understanding the whole—is a key finding, suggesting that the remaining unknown parts are exceptionally complex, or that the provided clues are themselves part of a larger, still unfathomed puzzle. The speakers noted that the brevity of K4 (only 97 characters) is a major factor contributing to its difficulty, as it severely limits statistical analysis. Other contributing factors include the possibility of a necessary key being physically accessible only on CIA grounds, potential misdirection embedded in the cipher's design, or even an outright mistake by the creator that renders it fundamentally unsolvable.
Regarding Debosny's cryptograms, the key finding is their very existence as a historical artifact of a sensational murder case and their continued status as an unsolved mystery. These messages, created by Henry Debosny while imprisoned for the murder of his wife in 1882, represent a tangible, personal cryptographic challenge from a bygone era. Unlike Kryptos, where the cipher designer is known and provides clues, the context for Debosny's method is almost entirely absent. His known intellectual capabilities—fluency in several languages, artistic talent, and literary knowledge—suggest a potentially sophisticated, or at least personalized, cryptographic approach. The fact that these messages have resisted decipherment for over a century, despite the historical significance of the case, underscores the difficulty inherent in breaking codes without any initial knowledge of the cipher system, key, or even the language if it's not immediately obvious. The speakers emphasized that these cryptograms are not just academic puzzles but are deeply intertwined with a dramatic historical narrative, making their decipherment potentially illuminating for understanding Debosny's motives or thoughts.
In essence, the key findings illustrate the formidable nature of both deliberate, modern cryptographic puzzles and accidental, historical ones. They demonstrate that short ciphertext, coupled with unknown keys, complex cipher designs, or the erosion of context over time, can create truly enduring mysteries that challenge even the most dedicated codebreakers.
Technical Deep Dive
▶ Watch: Kryptos in Dan Brown's "The Lost Symbol" and Nola K. (3:20)
The technical deep dive into these unsolved codes reveals the diverse challenges faced in cryptanalysis, spanning from modern, intentionally complex artistic ciphers to historical puzzles lacking crucial contextual information.
Kryptos K4: The Modern Enigma
The Kryptos sculpture, located at CIA headquarters, is a monumental work of art that also functions as a complex cryptographic puzzle. Its inscription consists of four distinct sections, K1 through K4. While K1, K2, and K3 have been solved, the 97-character K4 segment remains stubbornly unbroken, representing one of the most famous unsolved codes in the world.
The design of Kryptos is attributed to sculptor Jim Sanborn and cipher designer Ed Scheidt. The ciphers for K1, K2, and K3 are known to employ a combination of classical techniques, including a Vigenère cipher (polyalphabetic substitution) and transposition ciphers. However, the specific method for K4 has not been publicly confirmed, contributing to its difficulty.
Several technical factors contribute to K4's resilience:
- Short Ciphertext Length: At just 97 characters, K4 is exceptionally short. In cryptanalysis, shorter ciphertexts provide less statistical information, making techniques like frequency analysis (counting the occurrences of letters or letter pairs) significantly less effective. Modern ciphers are often designed to resist such attacks, but even classical ciphers become much harder to break when the sample size is small. Without enough data, it's difficult to infer the underlying language or the key length.
- Ambiguous Cipher Type: While K1-K3 used known classical ciphers, the exact cipher for K4 remains unknown. It could be a variation of a classical cipher, a more obscure historical cipher, or even a custom-designed algorithm. Without knowing the cipher family, cryptanalysts face an enormous search space.
- Potential External Key Material: The speakers raised the possibility that a necessary key for K4 might only be accessible on CIA grounds. This introduces a physical constraint, preventing a purely intellectual or computational attack. Such a key could be a physical object, a location, or information derived from the environment around the sculpture itself.
- Intentional Misdirection or Error: Sanborn, the sculptor, has been known to be playful with his clues. The speakers mentioned the possibility of intentional misdirection ("misdirected in some way") or even a mistake in the cipher's construction ("might have a mistake that makes it unsolvable"). An error could render the cipher undecipherable in its intended form, or it could be a deliberate obfuscation technique to add an extra layer of complexity.
- Partial Plaintext Clues: Sanborn has provided several crucial partial plaintext clues over the years:
- In 2010: "Berlin" starting at the 64th character, followed by "clock." This gave cryptanalysts an explicit string of characters within the decrypted text. The sequence "Berlin clock" suggests a potential theme or a specific object related to Berlin timekeeping.
- In January 2020: "Northeast."
- During the pandemic: "East."
These clues, while helpful, have not led to a complete solution. The fact that a "big chunk of what is supposedly the deciphered text" is known, yet the full message remains elusive, points to the profound difficulty of the remaining segments or the intricate way the known segments integrate with the unknown. Cryptanalysts must now work backward from these known plaintext segments to deduce the cipher and key, a process known as a known-plaintext attack, but even this has proven insufficient for K4.
Debosny's Cryptograms: The Historical Puzzle
The Debosny's cryptograms present a different set of technical challenges rooted in historical context and limited information. Created by Henry Debosny in a jail cell in 1882, these messages lack the modern context of a known designer offering clues.
- Unknown Cipher System: The most significant technical hurdle is the complete absence of information regarding the cryptographic system employed by Debosny. It could be a simple substitution cipher, a more complex polyalphabetic cipher, or even an ad-hoc system created by Debosny himself. Without any hint of the cipher's nature, cryptanalysts must attempt to identify the cipher type first, a task that is often harder than breaking the cipher once its type is known.
- Unknown Key: Even if the cipher system were identified, the key used by Debosny would still be unknown. Historical ciphers often relied on short, memorable keys, but without any clues, discovering this key is a brute-force problem against an unknown algorithm.
- Limited Contextual Information: Beyond the dramatic circumstances of their creation, there is little to no information about the intended recipient, the message's content, or any surrounding documents that might shed light on Debosny's cryptographic habits. This lack of context makes it difficult to guess potential plaintext words (cribs), which are invaluable in cryptanalysis.
- Debosny's Background: Debosny's intellectual capabilities—his knowledge of literature, multiple languages, and artistic skills—suggest he was capable of designing a non-trivial cipher or using an uncommon one. This personal touch could make the cipher highly idiosyncratic and resistant to standard techniques. His multiple language skills also introduce the possibility that the message might not be in English, adding another layer of complexity.
- Physical Artifacts: The cryptograms exist as physical artifacts from the late 19th century. Analyzing the handwriting, paper, and any other physical characteristics might offer subtle clues, but this is often a laborious and specialized process.
The technical approaches to these cryptograms involve exhaustive searches through known historical ciphers, statistical analysis (if enough ciphertext exists, though the talk doesn't specify the length of Debosny's messages), and linguistic analysis. However, without a starting point or a "crib," these efforts are akin to searching for a needle in an enormous haystack. The enduring mystery of Debosny's cryptograms is a stark reminder of how effectively a cipher can protect its secret when all external context is lost to time.
Demo / Proof of Concept
▶ Watch: Next mystery: The Debosny's cryptograms from 1882. (4:22)
The talk "Famous and Not So Famous Unsolved Codes" did not feature a live demonstration or a proof of concept in the traditional sense, as it focused on historical and ongoing cryptographic puzzles rather than exploitable vulnerabilities or new tools. The speakers presented the historical context and current status of the Kryptos sculpture and Debosny's cryptograms, relying on descriptive narratives and images (including some created with Lego for the Debosny story) to illustrate the challenges.
Defensive Implications
▶ Watch: Henry Debosny's quick marriages and suspicious deaths. (4:40)
While the talk primarily focused on historical and artistic cryptographic puzzles, the enduring nature of these unsolved codes carries several defensive implications for modern cybersecurity and information protection. These historical challenges highlight fundamental principles that remain relevant in contemporary cryptographic practices.
Firstly, the case of Kryptos K4, with its short ciphertext length (97 characters) and resistance to decades of analysis even with partial plaintext clues, underscores the inherent difficulty of breaking short messages without sufficient statistical data. In modern secure communication, this translates to the importance of padding and ensuring that encrypted messages are long enough to resist certain types of cryptanalytic attacks, even if the underlying cipher is theoretically strong. Conversely, it also implicitly warns against relying solely on short, custom-made ciphers for critical data, as their security may be overestimated, yet their decipherment equally difficult due to lack of public scrutiny and standardized analysis.
Secondly, the possibility of an external, physically constrained key for Kryptos K4 (e.g., "only accessible on CIA grounds") points to the concept of multi-factor authentication and physical security in modern systems. While not a direct security vulnerability, it illustrates how combining cryptographic strength with physical access control can create extremely robust barriers to information access. For defenders, this reinforces the idea that layered security, integrating digital cryptography with physical safeguards and operational security, offers the strongest protection.
Thirdly, the mention of potential "misdirection" or "mistakes" in Kryptos K4's design serves as a cautionary tale. In modern cryptographic system design, simplicity and transparency are often prioritized to ensure auditability and reduce the likelihood of hidden flaws or backdoors. Intentional misdirection, while perhaps artistically interesting, introduces complexity that can be difficult to manage and verify. For defenders, this emphasizes the importance of using well-vetted, standardized cryptographic algorithms and protocols that have undergone extensive public review, rather than relying on proprietary or custom-built solutions that might contain subtle flaws or intentional obfuscations that could later be exploited.
Finally, the Debosny's cryptograms illustrate the power of obscurity and the loss of context over time. Without any knowledge of the cipher system, key, or even the original language, these messages have remained secure for over a century. While modern cryptography aims for Kerckhoffs's Principle (the security of a cryptosystem should depend only on the secrecy of the key, not on the secrecy of the algorithm), the Debosny case shows that a complete lack of any initial information can render even simpler historical ciphers unbreakable. For defenders, this highlights the importance of key management and metadata protection. Ensuring that keys are securely stored and managed, and that sensitive metadata about encrypted communications (e.g., cipher type, key derivation methods) is also protected, can significantly increase the robustness of a defensive posture against future attacks, especially those that might leverage historical context or patterns.
In essence, these historical puzzles, while not directly related to current cyber threats, serve as valuable case studies in the principles of cryptographic strength, the challenges of cryptanalysis, and the enduring human element in both creating and breaking codes. They implicitly advocate for robust, well-understood cryptographic practices, layered security, and careful consideration of all factors that contribute to information protection.
Key Takeaways
- Kryptos K4 Remains a Formidable Modern Challenge: Despite three sections being solved and multiple explicit plaintext clues ("Berlin," "clock," "Northeast," "East") provided by the sculptor, the 97-character K4 segment at CIA headquarters continues to resist full decipherment, highlighting the difficulty of breaking short ciphertexts.
- Historical Cryptograms Offer Unique Insights: The Debosny's cryptograms, originating from an 1882 murder case, demonstrate how a complete lack of contextual information about the cipher system, key, or language can render even potentially simpler historical codes exceptionally difficult to solve over time.
- Short Ciphertext is Inherently Hard to Break: The limited length of K4 significantly reduces the statistical information available for cryptanalysis, making it resilient to common techniques and underscoring a fundamental challenge in codebreaking.
- Misdirection and Errors Complicate Cryptanalysis: The possibility of intentional misdirection or even a mistake in the cipher's design for Kryptos K4 adds layers of complexity, requiring cryptanalysts to consider factors beyond pure algorithmic decryption.
- Community Effort is Crucial for Unsolved Codes: Platforms like Mystery Twister, recommended by the speakers, illustrate the value of public engagement and collaborative effort in tackling and solving cryptographic challenges, from beginner-friendly ciphers to advanced, unsolved mysteries.
- Cryptographic Puzzles Transcend Time and Purpose: From artistic installations at intelligence agencies to personal messages penned by a condemned man, unsolved codes demonstrate the enduring human fascination with secrets and the intellectual rigor required for both their creation and their eventual solution.
About the Speaker(s)
Elonka Dunin is a distinguished figure in the world of cryptography and gaming. Described as a game developer, a crypto authority, and a book author, she has a deep passion for cryptographic puzzles. Her involvement with the famous Kryptos sculpture led to her being the inspiration for the character Nola K in Dan Brown's 2009 novel "The Lost Symbol," a testament to her significant contributions to research in the field. She co-authored the book "Codebreaking: A Practical Guide" with Klaus Schmeh.
Klaus Schmeh is a prominent German IT security expert, crypto expert, and crypto history expert. Like Dunin, he is also a prolific book author and co-authored "Codebreaking: A Practical Guide." Schmeh has a notable track record of publicly presenting crypto mysteries, often seeing them solved by his blog readers, demonstrating his ability to engage and inspire the codebreaking community. His expertise spans both modern IT security and the rich history of cryptography.