Scienceblogs.de, a German science blogging portal, includes a relatively famous list of 50 unsolved ciphers, which range from cryptograms published by serial killers to the famous Voynich manuscript.
180 comments
https://aaymeloglu.github.io/unsolved-ciphers/
But I got nothing on Daniel Bordeau, who in the past week seems to have built himself a whole code breaking factory!
After I gave up (mostly because ChatGPT had given me incomplete information needed to solve it) I checked the source of the dispute. It was a site very similar to this one and someone had an AI agent working on the same problem, publishing dozens or hundreds of pages of notes. The agent found the solution page and concluded it was wrong because many of the 32 source passages supposedly didn’t contain enough text.
I dug up the PDF of the book and found the mistake - whenever a passage continued onto the next page, the agent wasn’t including that continuation. The passages weren’t actually too short.
Annoying that ChatGPT can cite sources like this without being able to properly weigh their reliability.
Verifying sources is a recursive problem - where do you stop? Humans have intuitive feel for it, but agents don’t or at least not yet (I wonder if intuition is just a secondary neural net which is currently being added to the agents as we speak).
Also as a human you are able to examine agents erroneous trajectory, real or imaginary, without contaminating your own. Agent have a problem with that - as soon as someone else’s thought is in the context it can lose track of provenance and veracity. Sometimes I think we need a bloom filter to retroactively assign “dirty” flag to invalidated or questionable token spans already in the context.
I don’t mean that to say AGI is here or easy or necessarily that close but it’s likely going to feel like one thing after another until one day most of these things that make you think “how could something so capable be that dumb” are largely solved.
It can’t make it past the abstract, in some cases - just like most people!
Investors are not putting billions into OpenAI to crack historical ciphertexts. This is supposedly a trillion dollar general purpose artificial intelligence, but still can't reliably tell me how many p's are in 'raspberry'.
Cracking pre-computer era ciphers with LLMs is like me claiming I have a super-efficient hypersonic precooled hybrid air-breathing rocket engine that will revolutionize all forms of transportation, and then for a demo bragging about how nicely I can grill with it at my backyard BBQ.
I’m sure I can make some brand new “discovery” that is completely useless, which is why it wasn’t “discovered” in the first place.
but most things are unsolved because nobody even knows they exist
This headline is misleading.
In NZ there's a famous story about gold miners who were mining one side of a river, and didn't go to the other side because it was too much work. One miner's dog swam over, so the dude went to get his dog and found a motherlode.
After all, the whole LLM thing started because they started increasing the parameter counts, even though there was no particular reason an AI would get better with more parameters.
Then it’s OK, they can reproduce known attacks, but that’s just pattern matching against papers already in the training data.
Then it’s OK, they found previously unknown attacks on SpoC and a flaw in KINDI’s security proof, but those are obscure competition schemes nobody uses.
Then it’s OK, Claude found a new attack on HAWK that cuts the effective security of a NIST post-quantum signature candidate roughly in half, but HAWK isn’t deployed and a human researcher was involved.
Then it’s OK, Claude independently found a new cryptanalytic attack on AES that improves the previous best technique by 200–800×, but it’s only 7-round AES, not the full 10 rounds.
Then it’s OK, it found a practical key-recovery attack on 13-round LEA that runs in under an hour instead of requiring ~2^86 work, but LEA has 24 rounds.
Then it’s OK but none of this breaks a production cipher.
Wake me up when it breaks full AES.
Then—
So it used a known key. It didn't come up with a key from thin air. The only gotcha is that apparently this key was used two weeks earlier than it was documented (maybe the operator was using the wrong page from the codebook?).
> Astra felt compelled to check its work and found that, in fact, the English cruiser HMS Canterbury arrived in Sevastopol on November 24, 1918, based on its original logs
Then follows a picture of the original log papers.
In this case, though, that seems unlikely from the fact that the key used was an actual key documented as being used for other messages.
https://www.youtube.com/watch?v=yVm8oZx9WSM
Also relevant to today's AI concerns:
- MC 900 Foot Jesus
Read the full thread on Hacker News →
Related stories
- GPT-6 Astra Solves a WWI German Radio Cipherprinzai.comLobsters · 11 points · 12 days ago
- GPT-6.1 Sol replaces GPT-6 Sol after just 7 days, with near-Astra intelligenceartificialanalysis.aiHacker News · 47 points · about 17 hours ago
- OpenAI says planned GPT-6.1 is too insecure to releasearstechnica.comArs Technica · 0 points · 1 day ago
- Addendum to GPT-6 Astra System Card: GPT-6.1 Soldeploymentsafety.openai.comHacker News · 3 points · 1 day ago
- Hacker News · 2 points · 7 days ago
- Hacker News · 4 points · 6 days ago