[05] What went wrong
[05] · D'AGAPEYEFF INVESTIGATION

What went wrong

The cipher was set for a reader with a pencil. Start there and the problem changes shape.

D'Agapeyeff tells his reader to arm himself with "squared paper, tracing paper, a graduated ruler", counters with letters printed on them, and coloured pencils. He then works three cryptograms by hand in front of you, and the hardest of them — a Vigenère with an unknown key — he cracks in five pages. The challenge on page 159 is offered in the same voice: test your skill. Not here is something nobody can read.

So the intended cipher was almost certainly simple: a keyword square turning letters into two-digit coordinates, then a columnar transposition with a keyword. That is the exact combination he teaches on pages 117–125. A patient reader with squared paper could get it.

Eighty-seven years and 82 million machine-tested keys later, it has not been got. When an easy cipher cannot be solved, the interesting question is not "what exotic system is this" but "what broke". Below is every way it could have broken, and what the measurements say about each.

Errors in the printing

P1

A single mis-set digit ruled out as the cause

One is visible — the zero at digit 195 — and there could be more that are invisible, because a 6 set as an 8, or a 2 as a 4, breaks no rule. There are roughly 1,400 such undetectable single-digit slips available.

But it cannot matter. One wrong digit corrupts one unit out of 196. Under a substitution that is one wrong letter; under a transposition it is still one wrong letter, just somewhere else. The four-gram score of a 196-letter message barely notices. And it was tested directly: setting digit 195 to 6, 7, 8 and 9 in turn and rerunning the entire width sweep each time moved the best score from −1.35 to −1.33. Nothing.

P2

A dropped or inserted digit impossible

Lose one digit and every digit after it lands in the wrong half of its pair: row digits start appearing in column positions and the 6789 / 12345 alternation collapses from that point to the end of the message. The alternation is perfect across all 392 working digits.

So nothing was dropped and nothing was added, anywhere in the body of the text. This is one of the few things about this cipher that can be stated flatly.

P3

Lines or groups printed in the wrong order ruled out by E8

This was the most attractive of the printing hypotheses. The cryptogram is set as eight lines of ten groups; each line is fifty digits, an even number, so swapping two lines preserves the alternation perfectly and leaves no visible trace. A typesetter reordering two lines of a meaningless-looking digit block is entirely plausible.

E8 kills it. Swapping printed lines moves blocks of 25 units, and a block move leaves every n-gram inside the block intact: real English cut into 25-unit blocks and shuffled still shows about 18.5 recurring triples. Reordering the five-digit groups still shows 13.1. The cipher shows 5, which is what you get only when every unit has moved independently.

Whatever scrambled this message did it one unit at a time. No printing accident does that.

P4

A group missing from the end cannot be excluded

Seven lines of ten groups and a last line of nine. Eighty groups would have been the natural count, and 400 digits would be 200 units. If the compositor lost the final group, the parity test would never notice — loss at the very end costs nothing downstream.

It would cost two or three units of plaintext, which is survivable, and it would change the arithmetic of every transposition: 200 units instead of 196 gives different column lengths at every width. That is a real gap in the search, and a cheap one to close for anyone who wants to: rerun the width sweep assuming 197, 198, 199 and 200 units with the tail unknown.

Errors at the desk

H1

The short cells put in the wrong columns tested

196 units do not fill a rectangle evenly at most widths. At width 13 the last row holds two units; at width 11 it holds seven. The convention is that the long columns are the leftmost ones, and every serious attack assumes it — including, until now, this one. By hand, on squared paper, getting that wrong is the easiest mistake in the whole procedure, and the resulting ciphertext is not a valid columnar transposition of anything.

The attack was rerun with the constraint dropped, so that any column may be the long one, at every width from 2 to 13. Best score −1.34, at width 12 — which is what this machinery returns from noise. Not this either.

H2

A letter skipped or doubled while filling the rectangle the strongest candidate

This is the one that hurts, and it is the one no search can undo.

Write the plaintext across a keyed rectangle, twelve columns wide, and drop a letter at position forty. Everything after that point shifts one place left. Every subsequent letter is now in the wrong column, and no key on earth reads it back out correctly. The first thirty-nine letters are fine; the remaining hundred and fifty are permanently scrambled by a transposition that never existed.

And the message that results looks exactly like what we have. Frequencies preserved (E6). Order destroyed one unit at a time (E7, E8). Alternation intact, because the slip happened before the digits were written down. It would defeat the reader, and — this is the part that fits — it would defeat the author too, which is why the answer was never published and the challenge was quietly dropped from the reprint.

Nothing in the measurements distinguishes this from a correct transposition with a key too long to find. That is uncomfortable, and it is the honest position.

H3

A column read in the wrong direction, or the square misread partly covered

Reading one column upwards instead of downwards reverses a run of fifteen or so units in place. Looking a letter up in the row above the right one, for part of a message, corrupts a scattered handful. Both are ordinary hand errors; the first is partly covered by the boustrophedon routes in the geometry sweep, the second is cheap enough not to matter.

H4

The keyword numbered wrongly harmless

Miscount the alphabetical rank of the keyword's letters and you get a different column order — but still a valid one. Every column order at every width from 2 to 15 has been searched to optimality, so a mis-numbered key is already inside the search space. This cannot be the problem.

The key that moved

K1

The key came from the book, and the book changed tested, and worth more

He was writing the last page of a book that then went through proofs. A key taken from his own text — a phrase from a paragraph, a page number, the date he wrote it — could be true when he enciphered and false by the time it was printed. Page numbers shift. Sentences get cut.

Tested: every word of three letters or more that appears anywhere in Codes and Ciphers — 5,484 of them — used as a transposition key, numbered by alphabetical rank exactly as he does on page 117, read four ways each. Plus every date in 1939 in three formats, because page 127 suggests precisely that: "instead of Manchester as keyword you can simply use the current dates, as for instance 2. 5. 1939."

26,140 trials. Best score −1.42, on the word REES. Nothing.

What that does not cover is a key phrase rather than a single word, or a key drawn from a passage that was cut before publication and is therefore not in the book we have. Both remain open, and the second is exactly the failure mode this heading is about.

K2

A dictionary code keyed to his own pagination ruled out in its direct form

He gives two full pages to this idea (129–130): number each word by page and position, send the numbers, optionally encipher them again. If the plaintext under the square were page-and-word references into his own book, and the pagination moved in proof, the message would be irrecoverable to him as well — which fits the story better than almost anything.

It does not survive contact with the text. E1 shows the five-digit groups are not the units, and a two-digit unit cannot address a page. What does survive is the shape of the idea: he writes on page 128 that "an enciphered code of this kind should be very difficult to break", and a code layer underneath the square would leave a plaintext with no English statistics at all.

K3

Fixed-length code groups underneath ruled out

If the plaintext were five-letter commercial code words — the kind Chapter IV is entirely about, built with a deliberate two-letter difference between any two words, which is a design that suppresses repetition by construction — then units at the same position within each group would share a template and stand out.

Measured at every period from 2 to 8. Every coset's index of coincidence sits within noise of a shuffled control: at period 5 the cosets run 0.073, 0.062, 0.072, 0.081, 0.067 against a shuffled control mean of 0.073. There is no periodic structure in this message at any period.

Which one it probably was

Ranked by how well each survives the measurements, and by what it would take to confirm:

CauseFits the evidenceHow you would ever know
H2 — a letter skipped while filling the rectangle completely, including the author's own failure to reproduce it search for a key that reads correctly up to some position and then stops. A partial solve of the first thirty or forty letters is the signature
K1 — a key he could not reconstruct well; explains the withdrawal from the 1952 reprint a key phrase rather than a key word; or a crib
A long or double key, correctly executed completely, but then it was never solvable by hand and he mis-set the difficulty out of reach by search — two ten-letter keys is eleven years of this machine, two twelve-letter keys is longer than the universe has had
P4 — a group lost from the end possible, and cheap to test rerun the sweep at 197–200 units
P1–P3 — printing errors in the body badly; E8 excludes the block ones and single digits are too cheap to matter already excluded

The uncomfortable reading, and the one this page ends up endorsing: the message may not be internally consistent. Not corrupt in the sense of a misprint, but corrupt in the sense that the author's own hand slipped somewhere in the middle of a procedure he then could not retrace. Everything measured here is compatible with that, and nothing measured here can distinguish it from a correct cipher with a key beyond reach. If it is true, no amount of searching will find the message, only the first fragment of it — and that fragment is what a solver should now be hunting for.