Make a cipher, then break one — the 1,200-year duel of codemakers and codebreakers, in your hand. Tap the ▸ sections to go deeper. No app, no signup.
Nine tabs, in the order history found them. Each cipher leaks something different, and each tool works only while its assumptions hold.
Every cipher this lab breaks, you can also build. Shift the alphabet and you have a Caesar; add a keyword and it is Vigenère; stretch the key to the length of the message and it becomes a one-time pad; move the alphabet after every letter and you have a rotor machine; abandon shared keys entirely and you have RSA. Type below and watch each one work — then go and break them. 打字睇住佢變密碼。
There is no Shor mode, because Shor is not a cipher. It is the only thing on this page that has no encrypt side at all — an attack, and nothing else.
Pick a number — the shift. Slide every letter that far down the alphabet: with shift 3, A→D, B→E, and Z→C (it wraps around). The disk above is a cipher wheel: turn the inner ring by the shift and each outer letter points at what it becomes.
There are only 25 useful shifts, so a Caesar cipher is trivial to break — you can just try all of them. Its real lesson is the shape of every cipher that followed: a public method plus a secret key.
In 1883 Auguste Kerckhoffs argued a cipher must stay secure even if the enemy knows exactly how it works — everything rests on the key. "Security through obscurity" (hiding the method) fails the moment the method leaks, and it always leaks.
Every modern cipher, including AES, follows this: the algorithm is public and studied worldwide; only the key is secret.
A Caesar cipher uses one shift, so its letter frequencies survive and it falls to frequency analysis. Vigenère uses a keyword to change the shift on every letter — the same plaintext letter encrypts differently depending on position. That flattens the frequencies and blinded codebreakers from the 1500s until Charles Babbage and Friedrich Kasiski cracked it in the 1800s by finding the key's length.
The secret here is a key, not a scrambled alphabet — one number, somewhere between 1 and 25. That is the entire defence, and it is why this attack needs no technique at all. You simply write out all 25 answers and read the one that is English. 廿五個可能,全部試曬就得。
A cipher's strength has a hard ceiling: the number of keys an attacker must try. Caesar has 25. You just read all of them on one screen. It does not matter how clever the method is or how well it is hidden — 25 guesses is not security, it is a formality.
This is why modern ciphers quote key sizes in bits. AES-128 has roughly 3.4 × 10³⁸ keys. The method is public, exactly as Kerckhoffs demanded; the defence is that exhausting the keyspace is not physically possible. Caesar's defence was that you would not bother.
Except that the number on the box is not the number that protects you. In 2006 a Debian maintainer, tidying up compiler warnings in OpenSSL, commented out two lines that fed entropy into the random number generator. He had even asked on a mailing list whether it was safe, and got an ambiguous answer. The keys still said 1024 or 2048 bits. But only 32,768 distinct values could ever be generated, and every SSH key, SSL certificate and VPN key made on a Debian system for the next twenty months could be enumerated — a keyspace smaller than a Caesar cipher's is large, discovered in 2008 after two years in production. You just broke 25 keys by reading. Someone with a laptop broke 32,768 the same way.
What comes next. Enlarging the key is the obvious repair. Scramble the whole alphabet instead of sliding it and you get 26! ≈ 4 × 10²⁶ keys — far too many to try. That cipher held until a scholar in Baghdad noticed the key space was never the point. Tab ②.
After frequency analysis killed the substitution cipher, the repair was to stop using one alphabet. A keyword changes the shift on every letter, so the same plaintext letter encrypts differently each time and the fingerprint vanishes. It was called le chiffre indéchiffrable for three centuries. The flaw is that the key repeats. 密鑰會循環,就係破綻。
Vigenère resisted for three centuries because it destroys the single-letter fingerprint: the same plaintext letter encrypts differently depending on where it sits. Frequency analysis on the whole message returns mush.
Charles Babbage (around 1854, unpublished) and Friedrich Kasiski (1863) saw the flaw. The cipher is not one alphabet, it is N alphabets used in rotation, where N is the key length. Split the ciphertext into N columns by position and every column has been enciphered with a single Caesar shift — and single-letter frequency analysis works perfectly on each one.
So the whole attack reduces to finding N. Kasiski looked for repeated groups of letters and measured the gaps between them, since a repeat usually means the same plaintext met the same key letters; the key length divides those gaps. The index of coincidence, introduced by William Friedman in 1922, does the same job statistically and is what the bars above measure.
Caesar fails because the key is too short. Vigenère fails because the key repeats — and repetition is structure, which is exactly what a codebreaker eats. Stretch the key until it is as long as the message and never reused, and you get the one-time pad, which is genuinely unbreakable and was proved so by Claude Shannon in 1949.
The catch is that the pad must be truly random, as long as everything you will ever send, and never used twice. Get any of that wrong and it degrades into a Vigenère with a very long key. That is precisely the mistake in the Venona challenge on the next tab.
Scrambling the whole alphabet gives 26! ≈ 4 × 10²⁶ keys, so nobody can try them all — and it does not matter. Every letter keeps its fingerprint: English leans hard on E, then T. Drag a gold English letter onto a tall bar and the plaintext starts to appear. Drag a placed letter to another bar to move or swap it, or fling it off the board to discard it. 拖字母上去,明文慢慢浮現。
Tabs ②, ④ and ⑤ all work on this same message and this same board — a thousand years of technique applied to one ciphertext. Break as much as you can with each, then move to the next.
Single letters carry one fact each. Pairs carry far more: English is full of TH, HE, IN, ER and almost devoid of QJ or ZX. This tool scores your whole decryption on how English its letter pairs look, then tries swaps that improve the score.
It is not an oracle, and it will get things wrong. Anything you placed by hand is pinned (gold dot) and will not be moved — so the loop is: read the output, drag a correction, run it again. That is exactly how Crypt Breaker's Workbench was used in 1985.
The search is a loop of tiny experiments: exchange two letters, re-score, keep the exchange only if the score went up. Each press below runs one experiment on the real board.
Every pair gets a number for how often English follows the first letter with the second: about −1 for very common, about −9 for almost never. Add them up; higher (closer to zero) means more English. The first pairs of the current text:
Bletchley Park, 1940. Enigma had about 159 quintillion daily settings, and no amount of counting would ever touch it. What broke it was not mathematics about the machine but knowledge about the people using it. German operators sent a weather report every morning, in the same format, at the same hour. They signed off the same way. So a codebreaker could say: somewhere in this message is the word WETTER — and start not from 159 quintillion, but from a guess. The machine even helped, because no letter could ever encipher to itself, so any alignment where the guess collided with the ciphertext was instantly eliminated. At Bletchley they called that a crash.
That guess is a crib, and it is the technique on this tab. Statistics run out; what does not run out is that you usually know something about the message. One correct crib hands you several letters at once — far more than any single bar ever will.
What this board is and is not. The message below is a fixed substitution cipher, not Enigma. You can build a real Enigma on the Encrypt tab and watch the no-self-encryption property for yourself; here you are practising the reasoning Bletchley used, on a cipher simple enough to finish in a browser.
Word boundaries leak the shape. A cipher word like GUUJ has a doubled letter in third and fourth place, and only a handful of English words fit that shape at all. Pick a word below to see which ones do; every candidate shown is already consistent with the letters on your board.
The letters above update to match whichever challenge you pick. The method never changes — only the mapping does.
In Baghdad's House of Wisdom, Al-Kindi wrote the first known description of frequency analysis around 850 CE. His insight: a substitution cipher hides which symbol stands for a letter, but not how often it appears. Count the symbols, compare to a language's known letter frequencies, and the mapping unravels. That one idea made every fixed-substitution cipher readable to anyone who knew it — and such ciphers stayed in serious use for centuries afterwards anyway, because the people relying on them did not.
In 1586 Mary plotted against Elizabeth I in letters enciphered with a nomenclator — a substitution alphabet plus a codebook of symbols standing for whole names and phrases. Walsingham's codebreaker Thomas Phelippes broke it by counting symbols, then forged a postscript onto Mary's letter asking Babington to name the gentlemen who would act with him. The decrypts were read at her trial. She was executed in 1587.
The counting is the same idea you are using here; the cipher is not the same object. A nomenclator's codebook entries have no letter frequencies to exploit, which is exactly why breaking one took a codebreaker rather than an afternoon.
A warning about the shape of this page. The tabs are chronological, but they are not a ladder where each tool supersedes the last. Every tool below attacks a different weakness under different assumptions. Bigrams do not replace the Vigenère procedure — they cannot touch a repeating key. A crib is not universally stronger than counting; it buys power by assuming you know a word. And nothing in tabs ①–⑤ touches a correctly used one-time pad. What actually accumulates is not power but options: more ways for a cipher to leak, and more kinds of evidence worth collecting.
Notice what never changes: the ciphers on this page are exactly as strong as they always were. What improved was the attacker. That is the uncomfortable asymmetry at the heart of cryptography — you must defend against every future technique, while an attacker need only wait for one.
Letter frequencies are only reliable on average. In a short message the counts wobble, so the tallest bar is not guaranteed to be E and near-ties are genuine coin-flips. Intercept more text and the counts settle toward their true frequencies. Same reason a poll of 10,000 beats a poll of 10.
You can measure it here rather than take it on faith, and the result is blunter than the textbook version. Run Tool 1 on anything on this page and it scores somewhere between nothing and about a third of the letters — even on the longest passage. Counting single letters gets you the shape of the plaintext, never the plaintext. That is the wall, and it is where Tool 2 exists.
Now run Tool 2 down the list. On the long and medium passages it usually finishes the job outright. On the short ones it lands somewhere between helpful and embarrassing. On the very short ones it fails completely — and tells you it succeeded. Same algorithm, same English statistics, no extra cleverness anywhere: only the amount of ciphertext changed.
That is the whole lesson of this page. Volume is a weapon. A codebreaker who cannot break your message today may simply need more of it — which is the entire business model of the next section.
Robert W. Baldwin built CBW at MIT in 1984–85 to attack files scrambled by the Unix crypt command; it was released publicly on Usenet in 1987. The workflow is the one you are using: the program proposes a plaintext guess, you accept, reject or correct part of it, and it runs again with your correction locked in. Baldwin reported that a practised user broke a mail message in about twenty minutes.
Two honest differences. Unix crypt was a one-rotor machine, not a fixed substitution — the alphabet moved. And CBW leaned on bigram statistics, the frequency of letter pairs, which carries far more signal than single letters. But the governing law was identical: enough ciphertext, and the statistics do the work. Files encrypted with crypt have not been considered secret since.
Tool 2 on this page is that idea, kept deliberately small. It scores letter pairs, proposes swaps, and refuses to touch anything you placed by hand — so you stay the judge and it stays the assistant. Baldwin's design principle was that the machine should be fast at counting and the human fast at recognising English. Neither is good at the other's job.
Single letters give you 26 numbers. Letter pairs give you 676, and English uses them very unevenly: TH is everywhere, QJ essentially never. So a candidate decryption can be scored by adding up how probable each of its letter pairs is in ordinary English. A good mapping produces a high score; a scrambled one produces a terrible score. That number is the fit shown under the button, rescaled so that 100 means "as English as the reference text" and 0 means "no better than random".
Pressing Refine with pairs runs a simple search: try exchanging two plaintext letters, keep the exchange if the fit improves, repeat until no exchange helps. Letters you placed yourself are frozen, so every correction you make narrows what the search may consider. That is the human-in-the-loop part, and it is where the method gets its power.
Where it lies, and you can watch it happen. Load a very short challenge and run the pair pass. The fit climbs to 100 — a perfect score — while the plaintext is complete nonsense and the letters are essentially all wrong. Nothing is broken. With that few pairs, dozens of mappings fit the statistics equally well, so the search finds one and reports total confidence. A score is a statement about statistics, not about meaning. Read the plaintext, never the number.
The same failure wears a subtler disguise on longer text: the search stops at the first arrangement it cannot improve, which sometimes is not the right one. Pin a letter you are sure of and run it again — every pin removes a whole region of wrong answers from the search.
One more caveat worth stating plainly: the reference statistics here are counted from this page's own English passages, excluding whichever message you are attacking. A tool trained on its own answer key would look far cleverer than it is.
If volume is a weapon, the obvious move is to collect everything and break it whenever you can. Intelligence services have done exactly that for as long as there has been traffic to collect — the Venona project stored Soviet cables in the 1940s and read some of them years later. Storage is cheap and patience is free. Your encrypted traffic today is someone's plaintext later.
What changed is the expected date. In 1994 Peter Shor showed that a large quantum computer could factor integers and compute discrete logarithms in polynomial time — which is to say it breaks RSA, Diffie–Hellman and elliptic curve outright, not by wearing them down but by dissolving the mathematics they stand on. No such machine exists today, and forecasts of when one might arrive range from roughly a decade to never; treat any single number, ten years included, as an opinion rather than a measurement.
Two things soften it. Shor's algorithm does not break symmetric ciphers — Grover's gives only a square-root speedup, so AES-256 stays comfortable. And the replacements are already standards: NIST published ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) with effect from 14 August 2024, adding the code-based HQC as a backup in March 2025. NIST and NSA guidance deprecates today's public-key algorithms by 2030 and disallows them by 2035.
The uncomfortable part is that harvest-now-decrypt-later makes those deadlines retroactive. Anything you send today that must stay secret into the 2040s is already exposed, because the interception happens now and the decryption happens on the attacker's schedule. That is the argument for migrating early rather than on the deadline.
The plaintext of the ciphertext you picked is:
…
Work out the letter mapping yourself, or hit Guess by frequency and fix the near-ties.
Every tool so far worked because the key was shorter than the message, so it had to repeat, and repetition is structure. Take that away — a key as long as the message, truly random, used exactly once — and cryptanalysis stops. Not "gets hard". Stops. Shannon proved it in 1949. 一次性密碼本,用完即棄。
Notice this is just Vigenère with a key as long as the message. Same machine, one changed assumption, and the whole page becomes useless against it.
In 1949 Claude Shannon defined perfect secrecy: a ciphertext gives an attacker no information whatsoever about the plaintext beyond its length. Formally, the probability of any message given the ciphertext equals its probability beforehand. He proved the one-time pad achieves it — and, more brutally, that any cipher achieving it needs a key at least as long as the message. There is no clever scheme waiting to be found that gives perfect secrecy on a short key. That door is closed by arithmetic.
This is the only cipher on this page that is not merely unbroken but unbreakable, and it is the reason the arms race had to move somewhere else entirely.
American aircraft were being lost over North Vietnam at a rate nobody could explain. The enemy seemed to know mission plans in advance, down to the exact time on target. The obvious conclusion was that the codes had been broken, and Admiral U. S. Grant Sharp Jr. stood up a joint NSA and Defense Department team to find out how. It was codenamed Purple Dragon.
The codes were fine. The team found 50 separate non-secure communications carrying specific operational detail — time-on-target information going out in clear between 75 minutes and 15 hours before missions. Nobody was decrypting anything. They were listening to the chatter around the cipher and watching the patterns: the refuelling requests, the schedules, the sudden bursts of routine traffic before a raid.
The team needed a name for what they were doing, and picked operations security — OPSEC — partly because the acronym got attention. It worked well enough that the Joint Chiefs mandated it across every US command, and in 1988 Reagan's NSDD-298 made it national policy.
Why this belongs on the one-time pad tab. Everything above proves a mathematical statement: under its assumptions, this ciphertext tells an attacker nothing. Purple Dragon is the reminder that the ciphertext is not the only thing you emit. Shannon's proof is about the message. It says nothing about when you sent it, how often, to whom, or how much — and that is frequently enough.
Three requirements, and all three are operational rather than mathematical:
Pads are still used where those costs are acceptable — a diplomat carrying a sealed book, a hotline between two capitals. For everyone else the question became: can two strangers agree a key over a wire an enemy is listening to? That question stayed open until 1976. Tab ⑦.
Every cipher so far assumed you had already shared a key somehow. That assumption is the unexamined hole in the whole page. Public-key cryptography closes it: publish a key that locks, keep the one that unlocks. RSA's security rests on one bet — that factoring a large number back into its two primes is hard. Recover the primes and you recover the private key. 分解質因數就攞到私鑰。
Public-key cryptography is usually introduced as a solution to a logistics problem, which makes it sound like plumbing. It was not experienced that way. In 1991 Phil Zimmermann released Pretty Good Privacy as free software, and it spread across the internet almost immediately — because for the first time, two people who had never met and shared no secret could exchange something an eavesdropper could not read.
The US government treated strong cryptography as a munition, and Zimmermann spent three years under criminal investigation for export. In April 1993 the Clinton administration proposed the Clipper Chip: encryption for everyone, with every chip's key split in half and held by two federal agencies, reconstructible on demand. The argument was that law enforcement had to keep up. The counter-argument was that a key someone else holds is not a key, and by 1996 Clipper was dead — helped by Matt Blaze demonstrating you could defeat its escrow while still using the chip.
Why this belongs here. Every tab before this one assumed you and your recipient had already shared a secret. That assumption is fine for an admiral with a courier and useless for everyone else. What the next exercise picks apart is the machinery that removed it — and the reason people fought over that machinery for a decade is that removing it changed who gets to have a private conversation.
Pick two primes p and q. Publish N = p × q and a public exponent e. Encrypt with c = mᵉ mod N. Anyone can do that. Decryption needs d, the inverse of e modulo (p−1)(q−1) — and computing it requires knowing p and q, not just their product.
So the public key hands the world everything except the one thing that matters. Multiplying two 300-digit primes takes microseconds; splitting the result back apart is, as far as anyone knows, infeasible. "As far as anyone knows" is doing enormous work in that sentence, and it is the whole of the security.
Two honest qualifications. Recovering d lets you decrypt efficiently, but "only d decrypts" is too strong — the red box above shows a message read with no private key at all. And while factoring is certainly sufficient to break RSA, it has never been proved that breaking RSA requires factoring. They are believed close; they are not known equal.
Tab ① made the point that the algorithm must be public and only the key secret. RSA goes further: half the key is published too. On every certificate that carries an RSA key, N and e are printed for anyone to read. The design is so confident in the difficulty of factoring that it hands the attacker the number to factor.
That confidence has been repaid for fifty years by classical computers. It was never a proof, and in 1994 someone found a different kind of computer for which the bet does not hold. Tab ⑧.
Shor's insight was not a faster way to divide. It was that factoring is secretly a question about repetition — and repetition is the one thing a quantum computer is extraordinarily good at detecting. Everything below is the classical half of his algorithm, which runs perfectly well in your browser. Only one step needs the hardware nobody has yet. 週期就係答案。
Step 2 is trivial arithmetic. Step 1 is the whole problem. Above, you found the period by computing every power in turn — for a 20-digit N that is fine, and for the 617-digit N protecting your bank it is hopeless, because the number of powers you must try grows with N itself. Classically, period-finding is no easier than factoring.
A quantum computer does not try the powers one at a time. It prepares a superposition over all exponents at once, then applies a quantum Fourier transform, which is an operation that turns a repeating pattern into a sharp spike at its frequency. Measuring gives the period in polynomial time. That is the entire quantum contribution: one step, doing one thing — detecting repetition — that classical machines cannot do at scale.
Breaks outright: RSA, Diffie–Hellman and elliptic curve cryptography. All three rest on factoring or discrete logarithms, and Shor dissolves both. That is essentially every public-key algorithm securing the internet today.
Does not break: symmetric ciphers. The best known quantum attack on a key search is Grover's, which gives a square-root speedup — AES-256 retains around 128 bits against it, still far out of reach. Hashes are less tidy: preimage search gets the same square-root treatment, while collision resistance is a different problem with its own bounds, so "halve the security" is not one rule covering all hash properties. The one-time pad in tab ⑥ remains perfectly secret regardless, because Shannon's proof is information-theoretic and does not care what machine you own.
When: no machine capable of running Shor at these sizes exists, and published expert forecasts range from about a decade to never. Treat any single figure — including ten years — as an opinion rather than a measurement. What is not an opinion is that the replacements are already standards: NIST published ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) with effect from 14 August 2024, adding code-based HQC as a backup in March 2025, and guidance deprecates today's public-key algorithms by 2030 and disallows them by 2035.
This is where tab ⑧ meets the lesson from tab ②. An attacker does not need the machine on the day they intercept your traffic — only on the day they decide to read it. Recording encrypted traffic now and decrypting it whenever the hardware arrives is called harvest now, decrypt later, and storage is cheap while patience is free.
So the migration deadlines are effectively retroactive. Anything you send today that must stay secret into the 2040s is already exposed, because the interception happens now and the decryption happens on somebody else's schedule. Every tab on this page has been a demonstration of the same asymmetry: you must defend against every future technique, while an attacker need only wait for one.