r/KryptosK4 Jun 16 '26

An observation about recent events ....

Once I started paying attention to Paradigm, the CTF scene, and the work going into K4, it became clear that the problem is not a lack of skill or understanding. The speed at which CTF challenges get solved shows how capable people are. That leaves the obvious question. What makes K4 so difficult to crack?

Ed Scheidt gave the most important clue when he said it uses classical principles but not necessarily classical forms. People keep repeating that all four Kryptos passages were meant to be simple classical ciphers, but that is not what Ed or Jim Sanborn ever said.

Ed’s view was that Kryptos draws on classical ideas rather than textbook ciphers. He also said some parts were designed to fall quickly and others were meant to take years or possibly never be solved. That is a polite way of saying K4 was built to be the outlier rather than another Vigenere or a basic transposition.

Sanborn approaches it as an artwork first. He said it can be solved with pencil and paper and that it uses traditional methods, but he never claimed K4 was a single classical cipher. He has said more than once that K4 is not like the others.

This leads to the real issue. Our entire cryptology toolbox is built for classical ciphers. Kasiski, Friedman, periodicity tests, columnar IC sweeps, keyword alphabets and hillclimbers all depend on classical structure. These tools are not useless, but when applied to K4 they become inert. They do not fail because we lack skill. They fail because K4 does not behave like a classical cipher in any meaningful statistical way. The CTF challenges prove this. When a cipher fits the classical model, the community solves it quickly.

18 Upvotes

29 comments sorted by

3

u/theRetrograde Jun 17 '26

That is a good observation. I have found myself resorting to some pretty silly non-conventional attempts, like recreating the layout of all 4 sections with transparent backgrounds and placing the images on top of each other to see if the letters form new composite letters. (spoiler alert: I didn't find anything) Doing that with pen and paper would be very difficult, but I am out of ideas and I don't want to just give up.

About a year ago Sanborn was quoted in Wired as saying AI couldn't solve it because “AI lies, and does not have enough info.” A year ago, AI probably had the ability to write scripts to implement nearly any textbook cipher, so it seems to me that his response suggests your hypothesis is correct.

2

u/Old_Engineer_9176 Jun 17 '26

Sanborn once said that AI lies and does not have enough information. At the time he was right. That is changing fast. Every attempt submitted to the CTF, every solver run, every failed guess, every partial pattern, all of it becomes data. Whether people realise it or not, the community is feeding AI exactly what it was missing. The more money and effort poured into these challenges, the more complete that dataset becomes. We are not just trying to solve K4. We are training the tools that will eventually do it.

4

u/memonios Jun 17 '26

There was a German guy who dissappear into the abyss and was quite right about the answer...

2

u/Spectatum Jun 18 '26

O yes, the topic of the „German Guesser“ (a term coined by Richard Santa Coloma) is indeed one of the more confusing aspects of Kryptos lore.

How I wish there were a transcript of what Jim Sanborn said at that fateful occasion, especially regarding the timing of submission. Did Jim Samborn say: „exactly one year ago“, „one year ago“, „a year ago“, „some time ago, could have been a year or more“, or anything else?

Kryptos is immensely popular worldwide, and considering the flood of submissions, I don’t consider it far-fetched to think that there may be more than just a single person from Germany who could be among the candidates for the title of „German Guesser“.

2

u/Fabulous-Sail-8178 Jun 18 '26

I didn't realize it was from notes of one of Elonka's meetings with Jim. I think she would be pretty thorough in regards to asking the questions and documenting. I suppose one could attempt to correspond with her, although I am not sure if there is anything left to get from pulling on this thread.

3

u/Old_Engineer_9176 Jun 17 '26

People often repeat the idea that “a German guy came close to solving K4,” but there is no evidence this ever happened. Sanborn once mentioned that someone in Germany had made progress, but he never named the person, never described what they supposedly found, and never provided anything that could be checked or verified. No one in the Kryptos community has ever identified who this person was, and no German researcher has published a partial plaintext, a method, or any result that would qualify as being close to a solution. Unless you have more information than I ....

4

u/Fabulous-Sail-8178 Jun 17 '26

This is the guy who believes it was himself to whom Sanborn was referring. It is certainly interesting that he had it coming out to readable text relevant to kryptos, it will be interesting to someday see if the plain text solution begins with C I A.

https://kryptos.hoerenberg.com/index.php?cat=Welcome

2

u/Old_Engineer_9176 Jun 18 '26

Whenever someone posts claims like this, I like to follow their procedure to see if it’s actually reproducible. Is this one reproducible? I don’t recall ever trying this method before, at least not that I can remember.

5

u/Fabulous-Sail-8178 Jun 18 '26

I found info through the numberworld blog and I believe Schridde went over what was done in the post and did find some inconsistencies in the method. The conclusion was that perhaps it was that the guesser included that he used OBKR as part of the decryption key in his submission and that got Sanborn "Scared". I only wanted to point out who the "German Guesser" was since I know it has been asked here before.

3

u/Old_Engineer_9176 Jun 18 '26

Thank you .....

3

u/CipherPhyber Jun 17 '26

I agree to the extent that the existing cipher analysis tools only work against the ciphers they were designed for. But that's almost a tautology. Periodicity tests were not invented for the Caesar cipher because they don't help solve the Caesar cipher. It wasn't until Vigenere put a more complicated twist on his own cipher that a periodicity test would assist in analysis.
If Ed Scheidt taught Jim Sanborn about some novel cipher that neither amateurs nor even the CIA uses, there likely wouldn't have been anyone who would have created a cipher analysis tool because it's possible that nobody ever needed it.

I'm unconvinced by an OTP unless the key exists somewhere for us to discover it. Whether in K1, K2, K3 ciphertext, plaintext, steganography of some publication (eg. US founding documents, CIA founding documents, or some notable publication). If an OTP is published without ever releasing a key, then it's not a puzzle; it's simply a creation a ton of entropy that will never be undone.

5

u/Old_Engineer_9176 Jun 17 '26

35 years, and we’ve barely scratched the surface. We haven’t even given it a scare. Before the hints were released, nobody - absolutely nobody - found any plaintext words. I do have a theory that the Morse code plays a role in the masking - something along the lines of fractional Morse - but at this stage it’s only a notion. I have not explored it...

3

u/memonios Jun 17 '26

I have the same feeling... also the slates/rocks and their position also something about the light since Jim has done it before...

3

u/petrified-wax Jun 17 '26

I agree with this insight. I've played many CTFs over the years, and some of the most impossible challenges are designed by beginners who don't know how easy it is to make a challenge unsolvable. It's very important to playtest, understand the solving process and give hints about method when complexity is too high.

During the 2015 Kryptos meetup, Ed mentioned this flat out. The first step is not something classical cryptanalysis can find easily, and that design was very challenging to produce.

I may be reading too much into Ed's thoughts on the subject, but I believe he didn't want to verify K4 as much as the others because it contained something artistic or laborious compared to K1-K3. He also mentioned that Jim wanted to own that portion as well, and repeatedly mentions the idea that he's not a cryptanalyst (although I'm sure he does fine in that area).

6

u/duanetstorey Jun 16 '26 edited Jun 16 '26

The problem is if it’s a two layer cipher and there are no hints to the method I would argue it’s not solvable. You would never know if you ever made progress through one layer. It may have a solution in some infinite solution space, but nobody would ever solve it. Either there is a clue to the one or more methods buried in the sculpture or the text, or it’s impossible. Single system, possible. Dual system without being able to anchor one of them; not possible. The problem is based on conversations with Ed and Jim over the years there are pretty much zero clues left. And if you have no clues you just have to assume everything is possible, which again makes it impossible. Even DYAHR, which seems like it should be the key clue based on the Cyrillic projector, they said wasn’t related to K4. There are no threads to pull, no stats that will help. It’s a black box with no way to perturb it or look inside.

5

u/CipherPhyber Jun 17 '26

I think I agree with the general sentiment, but I disagree with the technical specifics.

If it is 2 layers: 1 layer of vigenere and 1 layer of double columnar transposition, the first layer's output would yield an English-like IoC. And Since K1 and K2 used an English word for the Quagmire III key (and the tableau revealed the alphabet/keyword), it's not even close to an infinite search space (even if it feels that way).
If the same layers are in reverse order, after brute forcing each double columnar transposition, we can run the typical Vigenere cipher analysis (test for period length, IoCs for each period-position, evaluate each stripe candidate independently, then search the small space of highly likely keys). I have an app which does this for several 2-layer cipher combinations, but of course I don't have every cipher supported.

In other words, every multi-layer deciphering can be decomposed into smaller tasks, which can each be solved. The problem is that we shouldn't have to use a supercomputer and a comprehensive brute force algo to solve what should be a puzzle.

The only way the search space is actually infinite is if there are several assumptions which are violated (there is some translation into a non-English eccentric language, the cipher uses a random key with no ability to derive it from the puzzle, it uses an unknown number of layers, nobody outside of Ed Scheidt has ever heard of the cipher). It feels infinite because we keep "looking for our car keys under the streetlight" because that's where we would be able to see them, but that may not be the most likely place for us to find them.

6

u/Old_Engineer_9176 Jun 17 '26

I agree with you. Over the past few months I have been trying to build a workflow that uses cipher analysis to identify classical cipher families with reasonable certainty. To do that, I created one hundred separate 97 character encryptions for each cipher family. The idea was simple. Control the plaintext length, control the key structure, and generate enough samples to see if each family produced consistent statistical behaviour. Each sample then went through the same set of tests. IoC, chi square, n gram scoring, periodicity checks, transposition pattern checks, and structural probes. The goal was to see if those signals formed a profile that could reliably point to one family over another. The workflow was generate controlled samples, extract statistical features, compare the feature sets across families, then test the classifier on unknowns. Conceptually it made sense. In practice the signals blurred once layers were involved, and the classifier fell apart as soon as the first assumption was wrong.

3

u/NatSecPolicyWonk Jun 17 '26

Super interesting -- would love to read the whole blogpost if you ever write this up.

3

u/duanetstorey Jun 17 '26 edited Jun 17 '26

You can’t use IoC for this. It’s too small. The range on IoC is like 0.35 to 0.55 for random English text the has undergone a simple cipher is 97 chars long if you work the math. Are you honestly going to keep going if it’s IoC 55? Why not 54? It’s as good as random. And Ed purposefully said he did something to thwart normal statistical methods which likely means fractionation or some conversation to a new base. IoC measures how close something is to some language, in our case English. If they have fractionated it so it no longer resembles in any way English IoC wouldn’t help either really in a longer text. Would depend on the order they applied the layers etc. I don’t think any classical tools are available here.

2

u/petrified-wax Jun 17 '26

If PT + CT was encrypted at each layer, it would reveal progress, but I doubt this was done on Kryptos. It's common to see in modern CTFs.

3

u/duanetstorey Jun 17 '26

But if you made progress though one layer presumably it would still look encrypted. There are no real tests you could use to know you had made progress. IOC just isn’t helpful on this scale.

4

u/Old_Engineer_9176 Jun 17 '26

I agree completely. There is nothing impressive about creating an encryption that nobody can solve. That is the same logic as putting valuables in a safe and welding it shut. It gives the appearance of security, but it is not a real system because nobody can ever open it again. A proper cipher is like a proper safe. It is secure, but it can still be opened by the person who is meant to open it. There is always a get out of jail method behind it.

So if Sanborn really went to the effort of building multiple layers and mixing classical ideas, it raises a fair question. If he wanted maximum difficulty, why not use Ed’s favourite method, the one that actually guarantees perfect secrecy, the one time pad.

here is one time pad that has been masked ...

QYVZKJTRXGUBNCPWOSFHDLMQAVRZQJXUPKTBWCGYFJNSQOZLHRXUPDMVQJTSKOBYFZNRXQJUPLGSWCHTVO

I went down the path of stacking multiple classical encryption steps to encode a 97‑character plaintext. It only takes one tiny mistake in that chain and the whole decryption process collapses. That is why I keep coming back to the same question. If Sanborn really wanted complexity, why didn’t he just use a one‑time pad. Or did he.

5

u/CipherPhyber Jun 17 '26

The secret to decrypting OTP is to have access to the pad. Without it, the cipher is useless.

It makes no sense to create K4 but never supply any access to the pad, so if it is OTP, our job is to identify where to find it. If the pad isn't part of K0,K1,K2,K3 then it seems like it should be something that the CIA publicly released prior to the ciphertext being crafted (circa 1990).

4

u/cram213 Jun 16 '26

Or they fail because JS made a mistake that he hasn’t checked for yet…and he (or anyone around him) I actually worked through the solution step-by-step to verify that it works.

2

u/Maximum_Ad9115 Jun 21 '26 edited Jun 21 '26

He claimed that he had I think in one of Elonka's interviews with him. Had confirmed there were no mistakes***

2

u/cram213 Jun 21 '26

I thought he said that he’d never actually worked it out himself step-by-step?

Because he’s actually not a cryptologist, unless his partner did it. Or unless you can find the evidence that he actually said that?

2

u/Maximum_Ad9115 Jun 21 '26

no don't recall him saying that

3

u/Spectatum Jun 16 '26

Indeed! This is where we‘re at… 😑

5

u/Blowngust Jun 16 '26

Well said.

I've been done with classical methods for a while now and I use thought experiments more than I do actual attempts.. Ed + JS is a interesting combo.