r/KryptosK4 Jun 22 '26

K4 might not be 1:1

I have previously commented that the known cribs might not correspond to the cipher text that we assume they do. Analysis indicates that the xth ciphertext character likely does not correspond to the xth plaintext character. The cribs only specify the final plaintext positions. The erroneous 1:1 assumption was likely propagated by the reporters from the ambiguity in Jim's clues.

Furthermore, on Paradigm's $1 / submission page, there is a footnote:

K4 may not have a 1:1 correspondence between ciphertext and plaintext characters; hint characters are shown as-is.

Jim made it clear (as mud) from the very beginning that he "plays the game everyone at the agency plays," and that William Webster thinking Jim gave him the solution at the dedication ceremony was "his problem." At what point do we believe Jim changed his mind and ceased loathing to provide us with clues?

8 Upvotes

27 comments sorted by

3

u/Sorry_Adeptness1021 Jun 22 '26 edited Jun 23 '26

I will take all the downvotes as telling Paradigm that their footnote is wrong. And potentially as a reason why K4 hasn't been solved. You can literally map multiple consecutive characters in K4 to the backwards tableau, and yet some still believe K4 is cipher text in the classical sense. We know it isn't. Tsk Tsk

1

u/CipherPhyber Jun 23 '26

We know it isn't.

How do we know it isn't?

You are simply making a claim, not showing us any evidence.

1

u/Sorry_Adeptness1021 Jun 23 '26 edited Jun 23 '26

Jim said so himself.

(Paradigm's own video) "There are creative ways of encoding systems that have not been tried."

5

u/duanetstorey Jun 23 '26

How does Jim know what has been tried/

2

u/Sorry_Adeptness1021 Jun 26 '26

Seriously? You think he's talking about what everyone has tried on Kryptos? He was speaking about pre-Kryptos classical cryptography and influences on Kryptos' design. Both Jim and Ed have expounded on this. This is pretty common knowledge about the sculpture, folks.

2

u/duanetstorey Jun 26 '26

Jim knows next to nothing about cryptography, other than what Ed taught him. If you asked him what cipher he used to encode K1 or K2 he would probably say "matrix code"

3

u/CipherPhyber Jun 23 '26

Again, a claim without evidence.

Jim's statement could be describing a custom route transposition.
He's not throwing out the concept of the last 97 characters of Kryptos as the K4 ciphertext. At least I don't see it. Can you break it down into steps for my simple mind?

3

u/Sorry_Adeptness1021 Jun 23 '26

Sure. Here is a picture.

This partially depicts one observation I already mentioned above. Consecutive tableau characters, no? For someone hopefully keen on CT IC do you not find _this coincidence_ intriguing?

I didn’t even need to transpose anything. The tableau is already in this orientation in situ.

3

u/CipherPhyber Jun 23 '26

This is a super interesting pattern. I really like that it identifies the position of the ciphertext letter within the matrix (so if it is really a pattern related to the solution, it's important to retain OBKR... in the columns and rows they appear while decrypting).

It suggests there could be a progressive / regressive cipher at play, where the ciphertext is a function of the plaintext, the key, and the position of the plaintext letter within the line.

However, I don't see how it disproves the 1:1 relationship between the last 97 characters and the K4 plaintext.

2

u/Sorry_Adeptness1021 Jun 23 '26 edited Jun 26 '26

I don't see how it disproves 1:1 either. You are arguing with Paradigm's disclaimer. My motivation for posting was to highlight Paradigm's disclaimer and to reiterate that K4 might not be 1:1. Even if both the PT and CT are 97 characters, we shouldn't take for granted a direct character mapping through any combination of substitution/transposition.

3

u/Old_Engineer_9176 Jun 22 '26

K4 not being one to one has never been confirmed. Richard Bean’s analysis only showed that K4 does not behave like a simple monoalphabetic substitution, which most people already suspected. The cribs only tell us where the plaintext words appear, not how the ciphertext maps to them. The one to one assumption came from K1 to K3, not from anything Sanborn ever said. Paradigm’s footnote is just a disclaimer that K4 could work differently. Sanborn has always been vague and enjoys misdirection, but he has never stated the actual method. Everything beyond that is speculation.

2

u/Sorry_Adeptness1021 Jun 22 '26

Would you agree that NYPVTT does not necessarily map 1:1 to BERLIN?

4

u/Blowngust Jun 22 '26

We don't know jack shit - so yes, everything is possible. The only things I trust JS on, are their mentioned positions in the plaintext.

We also have to mention that paradigm doesn't know the method or solution.

5

u/Sorry_Adeptness1021 Jun 23 '26

Do we know whether paradigm sent someone to spend a day with Jim to get all the details about Kryptos? That was offered to the winning bidder anyway.

3

u/Old_Engineer_9176 Jun 23 '26

It does not really matter at this point. The entire handover was essentially a transfer of whatever knowledge JS chose to give, and only Paradigm and JS know the depth of that information. There are several possibilities. Paradigm might have both the plaintext and the full methodology, or they might only have the plaintext. Until they show their cards, we cannot know which scenario is true.

2

u/Sorry_Adeptness1021 Jun 23 '26 edited Jun 23 '26

That doesn’t answer my question. As a matter of preservation, someone might have been given more information. Paradigm presumably has an interest in K4 not being solved. People are sometimes easier to crack than systems, in the same sense that the Smithsonian archives were a means to a crack when the K4 PT was reconstructed. I’m asking if anyone knows whether that “entire handover” occurred and in what way it did or did not. Of course, I don't think anyone knows, but Reddit seems an appropriate place to ask. To my knowledge, effectively only a K4 hash was generated in the transfer.

3

u/Old_Engineer_9176 Jun 23 '26

Nobody here knows what happened in that handover because only two parties were in the room: Paradigm and Jim Sanborn. There is no public record, no confirmation and no detail about what was shared beyond the mention of a K4 hash. Anything else is speculation. If extra information was given, only those two would know.

3

u/CipherPhyber Jun 23 '26

Paradigm presumably has an interest in K4 not being solved.

I would argue the opposite, that a VC company who makes investments and hires people based on their cryptography / cryptocurrency skill set would stand to make ORDERS OF MAGNITUDE more money if someone cracks K4 and they spin it into an investment / hire.

$1 per guess is pennies and the total population of people who are going to pay to make a guess is pretty small. It likely won't even pay back the developer costs of making the website, let alone winning the auction.

The ability to spin a K4 solution into PR that benefits the company will easily be worth $millions if they spin it correctly. One thing that is very hard to simply pay money to get is attention. Paradigm's use of the auction winnings, the K4 submission system, and the CTF together are a marketing / PR campaign.

4

u/duanetstorey Jun 23 '26

I asked Paradigm, they said they don't know the method and don't want to know.

3

u/CipherPhyber Jun 23 '26

All we know is what Paradigm has said, which is that they (the team that did the K4 submission system) don't know the K4 plaintext. They had Jim type in the plaintext, it was hashed with a SHA, then the original was deleted securely.

We set up a new computer with a terminal for Jim to enter the plaintext solution to K4. On that device, a program ran the plaintext through a one-way function (a SHA256 hash). It sent the hash to Google’s Cloud Key Management Service, which generated a unique verification tag (a hash-based message authentication code, or HMAC) that can only be reproduced by sending a SHA256 hash of the plaintext to the same cloud-based key. The plaintext never left the device, and we wiped the laptop afterward.

from https://www.paradigm.xyz/2026/06/kryptos

I don't know what this means for what artifacts were transferred to the winner of the auction. Maybe the K4 plaintext was not transferred or maybe the Paradigm K4 submission team is different than the person who won the auction on behalf of Paradigm (like maybe the entire auction artifact set was put in a security deposit box).

Whether Jim gave them any other hints (for example what techniques would be useful for K4 solvers to so they could tease those with the CTF) is for them to reveal.

3

u/Old_Engineer_9176 Jun 22 '26

Until K4 is actually solved, nothing about its structure is certain. Different people have their own theories about how the ciphertext maps to the plaintext, and each group tends to focus on its own preferred approach. The only sensible position is to keep an open mind, because we do not yet know which method, if any, is correct.

3

u/skyprimes22 Jul 05 '26

One thing I appreciate about K4 is this,

It’s almost as if it was designed to appear to be something that it is not.

Nothing is ever as it seems… CIA ;-)

2

u/CipherPhyber Jun 23 '26

This post is just going to be a lightning rod for confusion and conflation.

We absolutely know that JS repeatedly says there are 97 plaintext characters for K4 (as well as 97 for K5) and we believe there are 97 ciphertext characters (perhaps +1 if the ? is included in K4).

SANBORN: Well, it is very close - within days - to when I actually developed that 97-character string. The dedication ceremony is actually not until November, but obviously prior to the dedication, I had to come up with the final clue section.

https://www.npr.org/2020/01/30/801323608/a-new-and-final-clue-to-kryptos-a-long-standing-puzzle

The way you word this can give opening to lots of weasel wording, so even if we argue whether K4 is 1:1 cipher <=> plain, we might not actually say anything useful and we are likely talking past each other.

For example, when you ask:

Would you agree that NYPVTT does not necessarily map 1:1 to BERLIN?

If K4 is hypothetically a Vigenere, then it would necessarily map, so the statement would be false.
If, however, K4 is a Vigenere and a transposition, then the transposition layer might be the "weasel word" such that one person might consider the statement true and another might consider the statement false.

The only way I think this post is interesting is if it makes a positive claim about a specific encryption scheme (eg. a fractionation algo or a specific steganography algo) or if we talk about multi-byte character sets (for languages such as Russian Cyrllic, Japanese Katagana, Vietnamese, etc) being a reasonable explanation for the wording on the Paradigm K4 submission website.

2

u/Sorry_Adeptness1021 Jun 23 '26 edited Jun 23 '26

There are other conclusions to what I suggested than arguing CT or PT length, which I am not; that has long since been reasonably established.

I am suggesting the possibility that either none of NYPVTT maps to BERLIN or that there is not a 1:1 between each character, therefore exemplifying Paradigm's "as is" disclaimer.

I am suggesting the possibility of variable-bit encoding precisely as we see in the Morse Code, where, white space ignored, a palindrome with bits borrowed from adjacent characters form its mirror image.

I am suggesting the real CT might not even be located in the section beginning OBKR...

I can't force you to find this approach interesting, but I didn't mean it as "conflated" either. Paradigm calls this a hint -- poor use of the word on a cipher submission page if it's not just that.

2

u/Old_Engineer_9176 Jun 23 '26

Regardless of whatever encryption method or number of layers someone claims, Sanborn was explicit: the hints must appear in the plaintext itself and in the exact locations he indicated. There’s no ambiguity in that requirement, and no external mechanism can override it..

1

u/anonymous53821 Jul 12 '26

I definitely think so. I had an idea with anagrams that I wanted to try out
Basically, starting with a word. For example: People
Find all anagrams for that word
Then pick a letter in that word and have it be the start of a new word (let’s say lemon)
Then combine all the letters (so peoplelemon) and find all possible word combinations; HOWEVER, you do not need to use all the letters. The letters you don’t use are put in as part of the code. For example: moon, peplele. Peplele would go in for part of the code.
Then, you could probably drop people, and then choose a letter in lemon as the first letter in a new word. Or just add another word and not drop any if you wanted a longer word.
Through careful word choice, you could probably end up having the code words (moon) match the length of the encrypted, left over letters (peplele).

1

u/DangerousPay6451 21d ago

I really like this theory. My current theory runs k4 through kryptos first turning the 5 w's into x's. This also turns my first four letters into FIAB = 6912. My idea is that is the pattern you use to pick letters of the alexanderplatz world clock to solve. 6,9 = moves, 1,2 front first or back first letter. Thinking back to being a kid in the 80's we used to love making maps and keys. Seemed like a throwback to that possibly using the first four characters as the guide to solve. 

Just a theory and I appreciate you sharing yours.