[00:00] This is the Enigma, the encryption machine used by the Nazis in World War II. I see that there is a sigil from the Nazi party on this one, so it must be the real thing. Yes, this was actually used by the Germans in World War II. [00:13] Someone actually asked me the other day, did Hitler use this machine? And I said, I don't know, but then it did come to that and clear and I eat it. Whoa, no way. Could we try encrypting the word? Yeah. I have just the word for it. [00:25] You'd never guess what it is. Well, that's our plain text. That is our plain text. So we need to press the keys and look at the ramps that light up, which will give us our fire text. So the first one is V. [00:38] We have a J. Then an E. F. Then an R. An M. That is... Oh. Now, for someone to decrypt this message, they need to type this text into another Enigma machine. [00:54] But not just any Enigma, their machine has to be set up in the exact same way as the one that encrypted the message. So we need to turn these roses back to the initial setting. That means adjusting a series of rotors and wires to exactly one of trillions of possible combinations. [01:12] If you get it right, finally the algorithm is working. Okay. The message appears. But if just a single setting is out of place, well, then the encryption remains unbroken. [01:24] I could see how decrypting such a thing would get very complicated very quickly. This is exactly what the Nazis relied on. Hitler had come into power in Germany. The Nazi party had taken over. [01:36] Today we rule Germany. Tomorrow the world. By 1939, they were sending hundreds of encrypted messages across Europe every day. With the Allies desperately trying to get the Enigma settings. [01:50] But even if they sometimes got lucky and cracked a message, Each day at midnight, the Germans would change the settings on all their Enigma machines, so none of it would help them read the next day's messages. [02:02] That's why British intelligence assembled a team of the country's greatest minds. Test players, crossword fanatics, and university academics, including Alan Turing, along with hundreds of women from the Royal Navy. [02:14] And bit by bit, they looked for flaws hidden deep within the machine. But they also searched for subtle mistakes made by German operators. At its peak, around 9,000 men and women were executing the most secret code-breaking operations in the world, [02:28] out of an unsuspecting mansion in the English countryside. This is a video about the incredible methods and machines that broke the Enigma. Let's start with how the Enigma actually works. [02:40] And I think the first thing you need to know about the Enigma is that it wasn't actually invented by the Nazis. It was patented in 1918 by a guy called Arthur Sherbius. He was a German inventor who wanted to encrypt messages for banks and businesses. [02:54] Were Enigma machines readily available? Could you like buy one in Germany or were they kept a secret anyway? This, by the way, is Sir Dermot Turing. He's Alan Turing's nephew. The company that was making Enigma machines was really trying to find a market for them. [03:08] So you could definitely go out and buy them. And lots of countries did. So Poland bought one, the British bought one, the Russians bought one, you know. And there's one thing in particular that made Enigma superior to other encryption methods. [03:23] And you only need to play around with it for a bit to figure that out. I'm going to press the L key. Okay. And when I do that, you'll see that one of the lamps on the lamp board lights up. [03:35] The Y, yeah. The Y. That means that the plaintext letter L has been encrypted as a Y. If I press the L again, what do you think might light up? [03:47] Maybe the Y again? Maybe the Y. So let's press it again and see what happens. And what goes up there? Well, that's an H. An H. Not a Y. So it's not a Y. So it's changed. Okay, so with every key press, the substitution is different. [04:02] Yes. This is what separates the Enigma from the most famous encryption methods that came before. The Caesar cipher or simple substitution ciphers, these all encrypt according to a fixed rule. Enigma changes that rule with every single letter you type. [04:17] And for the reason for that, we need to open the box even further, and see what's happening inside. Yeah, that'd be great. Okay, so I'm going to open this up. Inside the Enigma, there are three rotors. [04:30] Each rotor has 26 metal contacts on either side, one for each letter of the alphabet. So, when you slot them into the machine, current flows from one rotor to the next. The wiring between the contacts is totally scrambled. [04:43] So, for example, when you type a Y, current flows down the Y wire to the first rotor, where it first gets switched to an H. And then, in the second rotor, the H gets swapped to a B. And in the third rotor, the B gets swapped to a Q. [04:56] Then, a component called the reflector directs the current back through the rotors by a completely different path, ending up as a letter E. The current then goes up to the lamps above the keyboard and illuminates the letter E, [05:08] indicating how the Y has been enciphered. I just want to say a big thanks to Jared Owen, who made the 3D model of the Enigma for his YouTube channel, and has kindly let us use it here. So check out the link in the description for his original video. [05:21] Now, the moment you type a letter into the Enigma, the rotor on the right rotates. And that's how a rotor encryption machine works. That it actually moves the rotor when you press the key. [05:34] So if you type the same letter again, it will follow a completely different path through the machine. which means you'll get a different letter each time you press the key. So here we can see the rotors in position. Yes. [05:46] And when I press the key, you can at the back see levers which push up against the rotors. Could you put them on the board? There we go. [05:58] There's actually three levers, and they are set to the right-hand side of each rotor. So there's one for each rotor trying to push the three rotors round. Perfect. but it's only the first rotor that turns every time you press a key. [06:11] Right, yeah. The second rotor will only turn when the first rotor reaches a certain position. There's a notch that's connected to the ring. That notch will allow the lever at the back to drop [06:26] and then connect with the ratchet on the next rotor along. So this rotor turns until the notch comes into the turnover position. When it does so, that allows the second lever to drop in and engage with the ratchet on [06:41] the second rotor. I see. Which will then allow the second rotor to turn. You'll see that as the rotors turn, that the second rotor turns at the same time. [06:53] So after 26 rotations of the first rotor, the second one turns once? Yes. And then after 26 rotations of the second rotor, the third one turns once? Yes, absolutely. Yeah, so the third one turns very, very rarely. [07:05] Yeah, okay. The operator can slot the three rotors into the machine in any order. That's three times two times one equals six possible permutations. Then there's the starting position of each rotor, [07:17] which is shown in the window before the operator starts typing. This is called the window setting. There are 26 numbers on each rotor, so that's 26 cubed possibilities. Multiply that by six possible rotor orders, [07:29] and that's over 100,000 ways to set up this commercial Enigma machine. But what the journalists did was they not only bought them, but they said, we're going to modify them. We're going to modify them in a way that nobody else knows what we've done. [07:43] There were a few ways that they did this. So if I undo this clasp here, I can actually turn the ring around, and that changes the relationship between the letter that appears at the top [07:57] and the fixed wiring. of the Raja. I see. So, rotating the ring does two things. First, it offsets the letters from the rotor's internal wiring. For example, at first, [08:09] this rotor connects 1 to 4, so it changes A to D. But rotate the ring by 1, and that same wire now connects 2 to 5, so it changes B to E instead. And second, it changes the position [08:21] where turnover occurs on the adjacent ring. But there was another, vastly more complex upgrade. There is another part of the machine that we haven't looked at yet and this was a part of the machine that was added by the German military. [08:36] It's called the plug board. Each of the keys is connected by a wire to the plug board. So the plug board has a letter for each of the keys because it means that you can substitute the letter, say the first one we have here, [08:52] which is Q, and that's plugged into R. Okay. The Q coming from the keyboard will go into the entry wheel, [09:04] into the first rotor as an R. But if there's nothing plugged in, it will carry straight through. Now, let's consider how this impacts the number of ways messages can be encrypted. This is also known as the key space. [09:17] The revolvable rings change the position where the second two rings would turn over, So that's 26 squared possibilities. And then on the plug board, if you swapped just one pair of letters, that would introduce 325 more possibilities. [09:32] But in the late 1930s, the Maltese typically swapped around 6 letters, and that's 100 billion possibilities. Overall, that brings the grand total for the key space to over 7 times 10 to the power of AP. [09:46] But as long as the machine is set up exactly how it was at the start of the encryption, you can type in the ciphertext and get out the original message. Intact. This is also called the plaintext. [10:00] If both machines are in the correct settings, and I press an E, it will encode to a K, going through the complicated set of wires. But if I press the K under the same settings, it will go back to an E. So it's like a closed loop of electricity. [10:12] of electricity. So we have a key. Awesome. Seems to be working. The way the Germans ensured that all enigmas on a particular [10:24] network were set up in the same way was by sending out pre-arranged instructions for each day of the month. These were called the key sheets. So each morning when the operators sent their first message, [10:37] they would reconfigure their machine to the new daily setting, and that would allow them to encrypt and decrypt messages to other Enigma operators. But, what if you didn't have the key sheets? [10:49] Well, then you would have to figure it out from scratch. By the end of the 1930s, this problem had become urgent. As Nazi Germany grew more powerful, British intelligence could sense that war was becoming [11:01] increasingly likely, and they used Enigma messages to reveal what German forces were planning, but only if the messages could be deciphered in time. So, British intelligence assembled a secret workforce focused on doing this back. [11:16] We're at Bletchley Park. This was Britain's most important code-writing operation during World War II. Bletchley was an unremarkable town, but it was situated conveniently between London and the country's two most prestigious universities, Oxford and Cambridge, [11:31] which is where the British intelligence sought their new recruits. And alongside these academics, Bletchley Park also recruited women from the Royal Navy, known as Wren. And the whole operation was kept as secret as possible. [11:44] Okay, to give you an idea of the secrecy, here is something that the codebreakers at Bletchley Park have to follow Some of the rules do not talk at meals or in transport or when traveling do not talk by your own fireside be careful even in your own hut all in all it seems like a very secretive place to work [12:02] Together, this group of around 150 people started trying to break the enigma. And here was their plan. First, listening stations would intercept German radio messages and send them to Bletchley [12:14] Park. Second, codebreakers would analyze the day's traffic, looking for patterns and weaknesses in the encryption, and third, they would use those clues to try and guess the settings, and then they would put those settings into their own Enigmas, finally cracking the messages. [12:29] But all this rested on one key component. The British needed a working version of the Nazi Enigma machine to figure out the settings, but they didn't have one. See, on top of adding revolvable rings and the plug board, the Nazis had made another upgrade. They had also changed [12:46] the wiring inside each rotor. That meant the Nazi rotors scrambled the letters in a completely different way from the commercial enigma. And without knowing the wiring of the Nazi rotors, it was impossible to determine the settings the Nazis were using each day. So the code breakers [13:00] were stuck. So it was completely hopeless. And that was the situation at the beginning of July 1939. They really hadn't made any progress at all. But what the British and the Germans didn't know [13:12] was that years earlier, another country had already launched a secret effort to break Enigma. In 1931, an employee at the German army's cypher office made contact with French intelligence, offering to sell secrets about the Enigma. [13:27] In exchange for its handsomety, he handed over operating procedures, sample messages, and even key sheets. Now, the French didn't know what to do with them, so they shared them with their Polish allies, and the Polish gave the sheets to their code-breaking team of mathematicians [13:41] who spotted a vulnerability. After an officer set up his Enigma for the day, he had to choose three random letters before sending a message. For example, GEX. Then, he would transmit these three letters encrypted on the day's default settings, [13:57] and he'd do it twice, just in case of a bad signal. For example, the encrypted letters would come out as ASDEIW. After that, he would move his rotors such that these same three letters, GEX, [14:09] would appear in his window up here. These were the so-called window settings. And finally, he would be able to type out the rest of the message. Now, the receiver would decipher the first six letters of the message, [14:21] and they would get G-E-X, G-E-X. And they would know that they have to change their window settings to G-E-X at this point, and only then would they be able to decipher the rest of the message. [14:33] So it was encrypted twice. Right. Which was a security flaw, because if you encrypt something twice you have a relationship created by the first letter of the key [14:45] that's been chosen and the fourth letter. The same letter's been encrypted because you're sending it twice. Okay. And the pre-lock converter and the chip converter as well? Yeah, yeah. I see. And they have this brilliant guy called Marian Riaski [14:57] who essentially said, oh, I recognise this is a problem in permutation theory from when I was doing my undergraduate mathematics. This went up by 1933 the Poles had reconstructed the wiring of the military version of Enigma, even though [15:15] they'd never seen one, they never captured one, and so that meant they were able to reverse engineer it and make replica Enigma machines, and then they could start working out what the second problem was and how to solve that. [15:29] So by the mid-1930s, the Poles were actually able to read German military enigma traffic. But in 1939, the Nazis were getting ready to invade, so they upped their security again. [15:42] By first making two extra rotors, so now it was five to choose from, not three, and that's five times four times three, so 60 possible orders, that increased the key space by a factor of ten. [15:54] And on top of that, they switched from using six plugboard swaps to ten. That's around 150 trillion combinations from the plugboard alone. So, all in all, the key space had grown by a factor of 15,000 to over 100 sextillion. [16:09] The Polish needed help, and by July 1939, they knew a German invasion was likely. So, the Poles called an urgent meeting with British and French intelligence. They revealed everything they knew about the Enigma machine itself, the wiring, [16:23] and they revealed everything they knew about the daily setup of the machine. Just over a month later, Poland was invaded. Their codebreakers fled, and they had to leave behind the device they'd invented to break into Enigma messages, called the Bombar. [16:38] The Brits were now on their own. They were armed with the knowledge given to them by the Poles, but now it was up to them to break the Enigma. Our producer has crafted an Enigma message, and I'm going to try and use all the tips and tricks that the British knew about to try and crack this thing, see if I can get it right. [16:55] F.A.O. Gregor, urgent decryption required. We're on it. So the first thing to look at is the top of the message. By the 1940s, the Germans quickly realized that encrypting three letters twice at the start of each message was a terrible security flaw, so they came up with a new system. [17:14] After setting up the Enigma, the operator would now start each message with three random letters. For example, VER, and they would send them completely unencrypted, naked over the air, and then they would set their own window settings to those three letters, so VER. [17:29] With that, the operator would pick another three random letters, say ITA, but this time they would type them through the Enigma. These three letters were called the indicator, and after this, they would set their own window settings to the indicator, [17:43] so it reads ITA, before finally typing through their actual message. Likewise, when a receiver got the message, they would know that the first three letters, D-E-R, came through unencrypted, [17:55] and they would put them into their window settings and type out the next three letters in the message. They would get three decrypted letters out, I-T-A, and they would put those into their window settings next, and now they were finally ready to read the rest of the message. [18:09] So a receiver is only able to decrypt the message if they could follow these two randomized checkpoints at the start of each message, which should have been a great security addition, except people aren't terrible at being random. [18:22] People very rarely choose random letters. So, for instance, the German operator's girlfriend's name was one that was chosen quite a lot. So, for instance, one common one is Scylla, [18:36] which would be C-I-L. C-I-L. Yeah, hence the term Scylla. And it wasn't his girlfriend's name either. So if the Windows hitting you send in plain text is D-E-R, [18:49] like, you might be like, well, I wonder if they just chose, like, Berlin. And so you would deduce, you could say, like, I guess the indicator is probably L-I-N. Okay, so my message starts with L-O-N. [19:02] So I'm guessing that the operator just chose London. So I know that C-N-G were encrypted from D-O-N. Okay, so here's the universal simulator for the Enigma, and I can actually show you that [19:17] if I put in the window settings on the rotors, L-O-N, I know that if I type C-N-G, I'm supposed to get a D-O-N for London. But for this to work, I need to guess the correct rotor order out of all of the rotors, [19:33] and I need to get the correct ring settings and the plug board. So there's still a lot of guesswork to do for me to be able to get this right. Okay, so I'm now going to record some of the actually trying this. D-O-N-O, D-O-N-O. [19:50] I'm struggling a bit. I won't lie to you. I am struggling a bit. But there was another way the laziness of the operators came through. It was spotted by a British codebreaker, John Harrivel. He compared the messages from all over the network that came from many different operators. [20:05] And he noticed something interesting. Those three letters the operators started their messages with appeared random, but they all seemed to be a very similar random. If you looked at just the first letter every operator chose across hundreds of messages, [20:19] they weren't spread evenly across the alphabet. They centered around a specific location. Same for the second letter, and same for the third. This happened because the operating procedure required the operators to shuffle the rotors [20:32] from the default key sheet settings for the day, those ring settings, And as it turned out, a significant number of operators only shuffled their rotors by a position or two. It's sort of like how people lock their bikes, and only move the rotors a small amount. [20:47] Following the same logic, Harivel concluded that the clustering of window settings around a particular set of three letters throughout the day actually revealed what the daily ring settings were. So this became known as the Harivel tip. [20:59] So I know that the Harivel tip, or the ring settings, are M-O-N, so I can convert them into, well, what that letter is in the alphabet. So M is the 13th, 15th is O, and then 14th is M. I don't know this by heart, I googled it. [21:11] Now I know that if I said D-O-N, I'm supposed to be getting C-N-G out. So now I've got to guess the rotor order for what rotors they were using today. And there were some hints, but besides that, it was basically just a lot of brute force. [21:27] You just have to try them. Let's show 1, 2, 3. D-O-N. No. No. Not even close. 1, 3, 2, 15 and 14, C and G. Oh, there we go. [21:41] Z and G sounds pretty close to C and G that we're supposed to get. I think I've guessed the rotor order to be 1, 3, and 2. All that remains now is the plug board. So maybe a Z needs to become a C. [21:55] A Z and a C. D-O-N. C and G. There we go. So if I was to change my window settings now to DLN, that's that second step of randomization. T-H-P-K-A-K-T-Q-O-G. [22:10] Okay, this kind of looks like text. Looks like James at DLN. Okay. Oh, that took a while. There was a lot of plugboard guesses, but I think I finally figured it out. [22:25] It says James is a legend. James the producer. Okay, we got it. Here we go. It took... how long did it take me? Pencils down, everyone? One hour straight? That's tough. But that was actually an easy example. [22:38] Bletchley codebreakers would have been faced with figuring out multiple plugboard swaps, and in a single message, it would be highly unlikely to use both the hairable tips and the sillies. Even with the operator errors to help them, [22:50] codebreakers at Bletchley had to trawl through hundreds of messages each day just to get a clue of what the Enigma settings were. And doing this manually was a huge task. To make it even harder, some networks were much more secure and didn't have any of these human errors, [23:04] making them far tougher to crack. So what Fletcher and Park needed was an automated way to break these Enigma messages. And that came from exploiting flaws in the machine itself. You see, the weakest part of any encryption device is not the device itself. [23:20] It's the human that's operating it. And kind of like the Enigma, human error is also one of the biggest reasons why our information leaks onto the Internet. You can make an account on the wrong website, or you give your phone number to the wrong company, and your data can end up in the hands of a data broker, who can then sell it on [23:35] to scammers who can impersonate you online or target you with AI-powered scams. But you can protect yourself against this with the help of today's sponsor, Incogni. Incogni contacts data brokers on your behalf and then they request that those data brokers delete your information I been using Incogni since June 2025 and they completed 143 requests on my behalf [23:57] And also, it runs in the background. I don't need to do anything, so it constantly requests these removals. Under unlimited plan, you also get your own personalized risk assessment each month, which means you get practical steps on how you can improve your online privacy. [24:11] They also have an exposure scanner, which finds wherever your personal info shows up online and they put it all in one place so that you can then choose what you want to take down with the help of Incogni's human removal specialist. [24:24] To get your data off the market today, you can go to incogni.com and use the code VERITASIUM to get 60% off their annual plan. You can also click the link in the description or scan this QR code. So I want to thank Incogni for sponsoring this part of the video. [24:37] And now, back to breaking the enigma. So Bletchley Park needed to develop a way to automate the breaking of Enigma, and luckily for them, there was one man in particular who was uniquely qualified for the job. [24:50] Alan Turing had already gained fame for his paper on a device that since became known as a Turing machine, so the British were quick to recruit him at Bletchley Park. When Turing arrived, he realized that if he could describe the process of breaking the [25:04] Enigma as a sequence of some logical test, then he could theoretically devise a machine that would do the job for him. So we're in Hut 8, and this room is the one that apparently [25:16] Alan Turing used as his office when he was put in charge of the naval enigma problem. They've changed a tin tea mug to the radiator, which Alan Turing allegedly did. [25:31] I think what happened was that people would take his mug away to wash it up, and then he couldn't find it when he wanted it. Can you tell me more about what kind of a person he was? A really quite wicked sense of humour, [25:44] very irreverent, and very interesting as well, to talk to if you were interested in the right kind of thing. So if you want to talk to him about a football game, then frankly, think again. But if you want to talk to him about the possibility [25:57] to build a machine that might be able to play a game of chess, he had lots to say about that. To automatically break the enigma, Tern needed a logical test that a machine could perform. some series of procedures after which the machine would say, [26:11] oh, no, these are not the Enigma settings, they're wrong, you should try something else, or, yes, these could be the correct Enigma settings, now you should try and decipher the message with them. The test that he ended up devising came from the fundamental flaw in the Enigma, [26:24] and surprisingly, it exported some of the most unimportant and mundane messages that the Nazis were sending. Certain German outposts sent very similar messages at the same time every day, and that would be a weather report. [26:37] So, for example, if Bletchley Park intercepted a message every day at 6 a.m. from an operator in Biscay, the codebreaker might reasonably guess that somewhere inside this message, there would be text that says, or in German, [26:51] And there was a way to guess where that text was encrypted in the message. If I'm pressing an L, I can keep pressing the L on here, and the L on the alarm panel will never light up. [27:06] You can't encrypt a key to become a cell? No. Okay. Because the current can't flow back through the same wire. It has to go through a different wire. That means I can take this word and I can shift it over the enciphered text [27:21] until I find a position where no letter is enciphered as itself. So if I start, for example, with W and Q aligned, so that the two messages align at the start, and I scan through, here this S is enciphered as itself. [27:35] So that isn't a possible solution. So I'm going to shift it one letter down and try again. Now I have a V, in cipher there's a V, and an E in cipher there's an E, so this doesn't work. So I'm going to shift another position. Oh, no, I have an R in cipher there's an R, so that doesn't work either. [27:49] I'm going to shift it one more. That all looks good. So here we go. Bingo. Now there's no letter that is in cipher as itself. So my guess is that this part of the in cipher text says whether report this gay. [28:01] And this guess at what the enciphered text actually represents is called a crib. In Ecclesiastical Park in Hot Ape Day Handles, it's called a cribbing room. This is Jonah Weinbaum. He wrote his thesis on how the enigma was broken. [28:14] And the cribbing room, their job was to identify good, strong, consistent cribs, which consisted of either weather messages, patterns they had noticed across messages, [28:27] the usage of slang for like, or shorthand. After Turing was sure that he had a crib that reasonably guessed what the encrypted message stood for, he started with his logical test. He assumed that at the start of each message, the window settings for the Enigma were ZZZ, or 262626, [28:45] and that the second rotor hadn't turned in this part of the message. So as soon as the first letter is typed, the rightmost rotor turns to A, or 1. At that position, typing a W in the machine outputs an R, [28:58] and that means that with the Enigma machine in this particular state, W is wired to R, and R is wired to W. As each letter is typed, the rightmost rotor moves one step forward. So when the window on the right reads 2, E and W are wired together. [29:13] At 3, it's T and I, and so on. Now Turing noticed that this encryption produced a kind of loop. For example, at position 6, the Enigma machine maps R to Y, but at 22, it maps Y to S, and at 9, it maps R to S. [29:29] So Turing imagined taking a clone of the Enigma machine at each of these positions. Then the only difference between these machines is just the position of that rightmost rotor. It's either 6, 9, or 22. [29:41] Now, look what happens if you wire these three machines back to back, so that the output of Enigma 6 becomes the input of Enigma 22, and then the output of 22 becomes the input of 9. If Turing hit the letter R on the first machine, it would output a Y. [29:55] Then the second machine would then transform that Y into an F, and the third machine would take that S back to an R, creating a perfect loop. R turns back into R. Now, for this to happen, the settings on these three Enigma machines [30:08] have to match the settings used to encrypt the original message. But if the settings don't match, for example, if the rotors used in the Enigmas are different, then the test is extremely unlikely to produce a loop, [30:20] and R should turn into a different letter instead. This gave Turing the logical test he would after. Theoretically, he could create a machine that looks through all possible Enigma settings, such that when you offset the first rotor by 6, 22, and 9, an R is transformed back into itself. [30:37] Now, out of millions of possible settings, there are multiple combinations that can transform an R back into itself at positions 6, 22, and 9. Turing's task could return hundreds of false positives, so he needed more logical constraints, [30:51] which came in the form of more loops from that crib we saw earlier. Back in the message, notice that R maps to W at position 1, and then W to E right after that, and then E goes to O at position 8, O to S, [31:04] and then back to R, which completes the loop. Following this process, Turing built up an entire menu of these loops of logical constraints. But this whole test rests on the assumption that we guessed the right rotor order. [31:17] Remember that the Germans had five rotors to choose from, and they could slot any three of them into the machine in any order. That's 60 possible configurations. So Turing's machines had to run through this entire process again and again for each rotor order. [31:32] And that still left one component unaccounted for, the plugboard, and 150 trillion possible ways to hook it up. But even though this number is ridiculously large, Turing found a simple way to isolate the plugboard's effects. [31:47] Remember how a letter flows through the enigma, first through the plug board, then through the rotors, then back out via the plug board again. So we can break each enigma into three steps. If you type an R into the enigma, it first gets transformed by the plug board to, for example, a Z, [32:03] and then that gets transformed by the rotors to a Q. Now this Q again gets transformed by the plug board to an X. So X is the letter that flows into the second enigma. But the plug board on the second enigma is set up in the same way, [32:16] so it swaps that X back to a Q. So Q goes to X goes to Q. In other words, back-to-back plug boards cancel each other out. So we can actually simplify this long list of transformations to this. [32:30] That means Turing could treat any series of Enigma machines as the plug board on the way in, then the combined effect of all the rotors, and then the plug board on the way out. But remember, with the correct settings, these three Enigma machines transformed an R back into an R. [32:45] Which means, if the first plug board transformed an R to a Z on the way in, then the last plug board must have transformed a Z into an R on the way out. So the three rotors alone must also create a loop, [32:57] transforming that same letter Z back into itself, with no plug board needed at all. Much like the original loop through the three enigmas, Turing realized this formed the basis of the task, one that he could perform using a simple electrical circuit. [33:11] He'd start with a guess, say that R is plugged to Z, and set that wire live. If the guess is correct, the three enigmas would transform that Z back to itself, leaving a single loop of live wires. [33:23] If the guess was wrong, it's likely that Z would loop back to a different letter, and that letter would loop round to another and another, so current would keep looping around and around the circuit, setting multiple wires live. [33:35] But that would mean that R was simultaneously plugged into multiple letters, which is impossible. This contradiction allowed him to rule out all these letters as a candidate for what R is connected to on the plug board. [33:47] And if all 26 wires went live, he knew that there was no possible plug board configurations for that window setting. So his machine would move the rotors one step forward and start the test again. There were also cases where 25 wires could light up, leaving just one dark. [34:02] Since those 25 possibilities had all been ruled out, that wire that didn't light up pointed to the only remaining candidate for R to be connected to on the plug board. This was Turing's stroke of genius. Even though there were 150 trillion ways to configure the plug board, [34:17] starting with this one guess would allow his machine to rule out multiple possibilities, or even reject incorrect settings entirely, the guess didn't even have to be correct for this to work. They did do this, I guess. [34:29] They did these contradictions, you know, on a piece of paper, following through what is implied. But Turing designed this machine so that it was instantaneous. [34:41] Like it was at the speed, not the speed of light, but the speed of electricity starting in the market. With the help of an engineer, Harold Keane, Turing brought his device to life. Based on some of the ideas that they'd got from the Polish cyber bureau [34:54] just before the war started, Turing and his colleagues came up with this. He called it the bomb, named in honor of the Polish bomber, [35:09] the device that the Polish mathematicians invented to break the earlier versions of Enigma. The first post-type arrived in March of 1940. [35:22] It was a pretty startling achievement, given the war only started in September 1939, to get the civil service to not only approve his design, and then to get the finance to be able to build the thing [35:36] absolutely astonishing. Anyway this is essentially 36 Enigma machines working in parallel working backwards So you start with an assumption that you made that a certain piece of ciphertext represents [35:51] certain plaintext meaning give all that to the machine let the machine go to work at the end of the process the idea is you're going to derive the key of the [36:04] day that the original Enigma operator is using to incite without message which Which means now you can read every message that that guy sent, not just the one that you're analysing. [36:16] And so when we run the machine, we're hoping for a condition when every enigma will find the answer it's been told to find, all at the same exact instant. [36:28] And when that happens, you've essentially solved this equation, and the machine will stop and give you an answer. So, what I'm going to do now is I'm going to run the machine, okay? Let's do it. It's going to be quite loud. [36:50] And eventually you're going to get through all the combinations. 26 times 26 times 26, 17,500 or so. It's going to take the machine about 13 minutes to go through all of those. [37:06] and at some point we're hoping that the machine is going to find an answer that works at which point it's going to come to a stop assuming the machine is actually working correctly [37:18] what are the chances that it is working correctly? about 90% ok, that's good, better than migrating to the machine ok, so what's going to happen? [37:30] machine has found a solution ok, there we go and if you look at these drums on the right hand end that's where the solutions are indicated. These are called the indicated drums. It's the output from the machine. [37:42] And if you look very closely, you'll see a little pointer on each of those drums, pointing to the letters D, K and X. So that's the machine saying, I think D, K, X is an answer. [37:55] Now I'm saying an answer, not the answer. The problem is that you might get multiple answers because it's quite possible you'll find several solutions to the equation. And there was a flaw hiding in Turing's original test. [38:09] Sometimes the machine would stop on what looked like a clean, valid loop, but in reality, that loop could be self-contradictory. It might imply, for example, that R was plugged into both X and S on the plug board at once, [38:21] which is impossible. The machine had no way to catch this. And every time the bomb stopped and offered a solution, an operator would have to check it. So if there were 100 stops, each of which might have taken 15 minutes to check, That's more than 24 hours of work. [38:35] By which point, the Enigma settings would have already changed. The bomb wasn't fast enough. By the time the first bomb was operational, the Nazis were already occupying Austria and Czechoslovakia, and they'd invaded Poland, killing hundreds of thousands in the process. [38:50] Leslie Park desperately needed a way to speed up the bomb. Turing was manning the expectations, so it came as no great shock. After that, there's a mathematician called Gordon Welshman comes into the story. Welshman, another Cambridge mathematician, comes to Bletchley Park working alongside [39:07] Turing, and he comes up with a brilliant modification. Welshman realized that guessing R is plugged to Y is exactly the same as guessing that Y is plugged to R. So Welshman connected these two wires such that if one went live, they both would. [39:22] He would do the same for S and Y and R and S. And this made it more likely that a guess that the plug board would set multiple wires live, so exactly the same input ignition would rule out more potential plug board slots and therefore [39:35] drastically reduce the number of false positives. Instead of the machine stopping and giving you a hundred possible solutions to check out, you only get four, which means that process was so much quicker. So Welshman's improvement [39:50] made the thing practical. Welshman's modification became known as the diagonal board and Turing figured out that in many cases the diagonal board could eliminate over 90% of false stocks. [40:04] This new version of the bomb was ready in August 1940, but by now France had fallen along with Norway and Denmark. Britain was the last major power in Western Europe and the Nazis had begun an aerial onslaught [40:16] trying to bring Britain to its knees. We shall defend our island, whatever the cost. We shall fight on Jesus. [40:29] If I know, we shall stand up to you. For Europe, maybe. During the Battle of Britain, when the question whether to commit the last [40:42] reserve squadrons of fighters to the air battle over Britain. The Air Force commander felt able to do that because the Enigma intelligence had reinforced [40:55] his own perceptions about the balance of forces and we all know that the outcome of that battle was a victory for the British and a strategic defeat for the Germans. By the end of 1941, the British had 16 bombs in operation, [41:11] 6 at Bletchley and 10 in the nearby towns, and they were routinely deciphering German army and Luftwaffe Enigma traffic. This intelligence would soon help turn the tide of the war in North Africa. [41:23] Enigma decrypts revealed that the German army was critically short of fuel and supplies. Armed with that knowledge, British General Bernard Montgomery large defenses that culminated in the victory at the second battle of Al-Alamai in 1942. [41:37] What Turing did was so resilient to protocol changes that it would have worked at any time prior to this. It is fundamental to the structure of the machine and it's so fundamental that they [41:54] actually ultimately had to change the machine itself in order to try to avoid this just to to make it marginally more difficult for them to continue doing it by adding a fourth rotor. And then even doing that was a nightmare for them because you have to have it be backwards compatible. [42:09] So it's like, once Turing did that, it was like game over. You either reinvent the entire machine or prevent them from knowing any information whatsoever. The German Navy did just that. They added a fourth rotor to the naval Enigma machine. [42:24] And they created three extra rotors to choose from. Because of that, Turing had to invent a whole new statistical method to narrow down the choice of rotors, and they also had to work with the Navy to capture key sheets and trick the Germans into revealing a crypt. [42:38] And they had to call in the military to try to generate plaintext for them with the guard name. Well, sometimes if they were really struggling to get plaintext, like in the case of the Blackout with the Naples Enigma, [42:50] they would basically tell them to see mines in particular locations, and then those places would have to go and clear them out. And so they would have to say the location. Oh, that's genius. [43:02] Yeah. Oh, that's really cool. But even then, the codebreakers relied on the members of the British Navy sacrificing their lives to capture vital intelligence from sinking new boats. I'm conscious all the time that codebreaking is not the same as combat. [43:20] and battles are not won by codebreakers sitting in rooms in the safety of Fletchley Park. They're won by people at the sharp end of things. [43:32] By 1943, the Americans had joined the war and built over 100 bombs of their own. You can see the turning point of the war being when the British finally mastered the U-boat Enigma in 1943. [43:48] the sinkings drop like a stone and instead the U-boat sinkings start to rise and that's the point at which Germany has begun to lose war. I'm not [44:01] trying to say that Germany lost the war solely because of the U-boat thing and obviously the Eastern Front was crucially important too but all these things conspired to mean that basically [44:13] by the end of 1943 everybody apart from Adolf Hitler knew that the Germans were going to lose. Enigma traffic from all Nazi forces was now being deciphered daily. This set the stage for the D-Day landing in 1944 and the Allied invasion of Europe. [44:29] Historians estimate that the breaking of Enigma shortened the war by up to two years, and who knows how many lives it saved. Alan Turing's life story is dominated by his sexuality and [44:44] and what happened to him, bearing in mind that being a practicing homosexual in the UK was still illegal for the whole of Alan Turing's lifetime. That story is very strongly coloured by the fact that Alan Turing took his own life. [44:57] That tends to lead to a chain of connections in people's minds that that means that his whole life after World War II was on a downward spiral. [45:10] I have heard this story. From 1945 through to 1950, he was involved in the most exciting technology project that the country had on offer. [45:22] He was very frustrated from time to time because they weren't going fast enough. And he was writing programs for computers that weren't yet being built. So I think he achieved a great deal in the post-war years. And I have to say, I think that the end of his life does not actually define what happened before. [45:39] and I think that we're looking at it the wrong way if we see him as some sort of master. In 1944, Allied forces were preparing to invade Europe. But before they did, Churchill and Roosevelt [45:51] launched one of the most important misinformation campaigns in history. They leaked information to the Nazis that they were going to land on a different beach. The deception plan about where the invasion of Europe was going to take place, [46:03] was it going to be in Normandy or was it going to be at the Pas-de-Calais? But before the Allies could land at Normandy, they needed to know whether this misinformation campaign had actually worked. [46:15] And that meant deciphering messages from Hitler himself. Now that the Enigma had been broken, that should have been easy. But Hitler actually didn't use Enigma. He used a completely different encryption machine, one that the Allies had never seen. [46:30] And while Enigma had a key space of around 10 to the power of 23, this machine had a key space of 10 to the power of 170. That's greater than the number of atoms in the observable universe squared. [46:42] To break this would require a piece of genius that had been described as the greatest intellectual feat of World War II. And the building of an entirely new machine vastly more sophisticated than the bomb. Yet, you've probably never heard of the guy who built it, or the code makers who made it possible. [46:57] That's because this device was so important during the Cold War that it was classified for decades after the bomb and the Enigma. If you want to hear about it, let us know in the comments. Hey, I just want to give a quick shout out to Bletchley Park, the National Museum of [47:13] Computing and Sir Dermot Turing and every expert here who has helped us make this video possible. If you're interested in visiting, all the links are in the description, so check that out. One last thing, by the way, there's still a naval enigma message intercepted in [47:26] the war that no one has been able to decrypt. The ciphertext is in the description. Maybe you can break it. Let us know if you can. [47:38] Thank you.