Enigma was the most famous cipher ever broken, and it was broken while it was still in service. This page is about why — because the reasons are still the reasons we build security the way we do.

Why "it's old" is not the reason

It is tempting to say a 1920s machine is insecure because it is old, as though age were the defect. The useful question is what a cipher has to guarantee, and Enigma fails three requirements that any modern one takes for granted.

1. Keys were reused

Operators were issued a key sheet a day (a month at sea) and set the same rotors, rings, positions and plugboard pairs for every message in it. One key protected thousands of letters — which is exactly the condition that makes statistical analysis work, because the language underneath starts to show through the cipher. Modern cryptography assumes the key is used for a small, fixed amount of data; when that amount grows, the cipher stops being safe.

2. The plaintext was guessable

Military radio traffic had set phrases in predictable places — a routine weather report, an opening formula — so an analyst could guesspart of the message, put the guess and the ciphertext side by side, and learn something about the key. This is crib dragging, and it is devastating against Enigma because the plugboard pairs can be recovered one at a time from a good crib. It also made the cipher malleable: an attacker could insert a chosen phrase, light the matching lamp and change the meaning of a message without breaking it. A modern cipher is authenticated precisely so that a modified message is detectable.

3. The search space was small

Once the plugboard was known, the remaining key was the rotor order (336 choices with no repeated rotor), the starting positions (26³ = 17,576) and the reflector (3) — about 18 million combinations altogether. The British bombe, designed by Alan Turing with a vital correction from Welchman, was built to search that spacemechanically because checking it by hand was hopeless.

Today that same search takes seconds on a laptop, which is the point: a cipher's security has to hold against an adversary with a modern computer and unlimited time on the ciphertext. Cryptography that depended on the opponent's equipment being slow was never going to survive.

What the war taught cryptanalysts

What replaced it

The short version

None of this makes Enigma worthless — it makes it a machine worth understanding. You can still operate it on thesimulator, with the wirings the Wehrmacht and Kriegsmarine actually used, and watch for yourself how little the machine knows about the person on the other end of the wire.