447 comments

mmsc8 days ago
For anybody interested, the actual encrypted message:

  BTTE UM ANGABE DES MARSQWEGES X BEFINDE MIQ IN X ROSENOW ROSENOW X SOFORT FUNKANTWORT X WASCHBBSCH
which, given misspellings, translates approximately to:

  Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio. Waschbusch.
booty8 days ago

    I am in Rosenow, Rosenow. 
From the article:

    After trying many different approaches, GPT–6 
    Astra focused on using the repeated place name 
    ROSENOW ROSENOW as a crib. 
This feels extremely underexplained! Why would Astra think to use that as a "crib"? Was it common to repeat the place name in these messages?

(Is it possible that this is a misreported detail? It feels like a singular ROSENOW would be an equally effective crib)

TheDong8 days ago
This was explained in the article right there:

> it suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message

It makes sense that Nr. 172 and Nr. 173 might be related since they were sent at around the same time.

In Nr. 173, "ROSENOW ROSENOW" was also present.

It also makes sense that a longer crib would generally be more effective than a shorter one.

JimmyBiscuit8 days ago
Rosenow is a municipal (around 32km²) and in there is a district also called Rosenow. So the sender just specified his current position a bit more.
hmokiguess8 days ago
Maybe naive of me, but could it simply just be the overfitting of the same tokens being sent on the input twice because of repetition rather than some unknown implied intelligence.
xnorswap8 days ago
Out of interest, what was the ciphertext?

Edit: Found it from here: https://mvueh-enigma-solved.carterl.chatgpt.site/

    ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC
pjc508 days ago
Do we have any kind of transcript as to how the message was cracked, and whether this was cheaper or more expensive than simply Bombe-style trying all the combinations?
mrguyorama8 days ago
As the article states, the LLM built code for both an enigma simulator and a bombe simulator.

Breaking enigma is often about using lucky or educated guesses to heuristically reject large chunks of keyspace to leave the remaining keyspace computationally tractable.

Note that the key (lol) complication with this message seems to be that it had a wheel rollover that most messages do not have to deal with, and that rollover drastically reduces how much you can reduce the potential keyspace using all the techniques noticed by the original crackers.

The wheel rollover I think just requires more brute force. Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd. For example, modern compute clusters like supercomputers can tractably brute force enigma with no cleverness in like a day or less, while home computers would still take thousands of years to compute that. It's very scalable. Did astra have access to significant compute?

However, even considering that, the inferences made by the LLM are good, and picking this specific message to attack, precisely because it should be soluble but might have had an extra wheel rollover that made it more computationally intractable for hobbyists but not a large company is a clever thing to do for the LLM.

russdill8 days ago
The bombe method requires a crib of sufficient length
xg158 days ago
Interesting. Do we know the reason why those specific messages were sent with different keys? I would imagine that there were separate keys for special high-security messages or something like that, but the almost identical content and the way the key was changed here (first only part of the configuration, then suddenly everything) makes it look more like an error or a test.
jpablo8 days ago
Why wasn't this in the article?
lionkor8 days ago
Its at the very top, when you move the slider :)
podgorniy8 days ago
gemini 3.8 flash in anrigravitiy oneshoted the descryption in about 45min non-steered run (opus is still running with the task, has some script to run for about 100min)

Prompt

Decrypt encrypted with enigma `ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC`

Result

Raw Decryption (verbatim from the machine): BTTEUMANGABEDESMARSQWEGESXBEFINDEMIQINXROSENOWROSENOWXSOFORTFUNKANTWORTXWASCHBBSCH 2. Segmented German (with military telegraph conventions expanded): BTTE UM ANGABE DES MARSQWEGES . BEFINDE MIQ IN : ROSENOW ROSENOW . SOFORT FUNKANTWORT . WASCHBBSCH

(Standard German radio conventions: X represents punctuation/spacing; Q was frequently substituted for CH to prevent transmission ambiguities; BTTE was an enciphering operator typo for BITTE; WASCHBBSCH was an operator typo for the signature WASCHBUSCH).

3. Corrected German: „Bitte um Angabe des Marschweges. Befinde mich in Rosenow, Rosenow. Sofort Funkantwort. Waschbusch.“

4. English Translation: "Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio. Waschbusch."

Cryptographic Verification Re-encrypting the plaintext using the identical key settings reproduces the exact ciphertext byte-for-byte:

Enigma ( M raw ) = ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC Enigma(M raw

)=ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC 19:10

coderintherye8 days ago
How do you know it didn't just get the result from the web?

Putting "ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC" into google search returns the result from Gemini with similar explanation, which it references to a Yahoo article about the Astra breakthrough and that's a result as of 3 hours ago.

podgorniy8 days ago
UPD out of curiosity I ran the same prompt against gemini 3.8 flash via api with and withouth internet search.

with search it found and referenced pages, including the hn ones. Without search it just described what one would need to descrypt (`To decrypt this ciphertext, the specific Enigma machine parameters are required:`) and the list.

Out of curiosity ran the same prompt against bunch of models - grok, kimi k3. They all say the same thing that they need model version, rotors and so on to descrypt.

When file output tool is enabled, some models give python script.

--

I read through some of the logs that antigravity gives. It produced intermediate results, scripts, calls, assumptions (about german language). I've shares random bits in comment below to give a taste of what it was doing.

--

The freshness of the news reduces changes that model fetched response from them

xg158 days ago
Wow. Was there any indication how it did that? Did it bruteforce the key and check which result looks sufficiently German, or was it just LLM magic like "decoding" base64 purely in the inference loop?

(Or did it look up the results on the web?)

podgorniy8 days ago
TLDR: it created program to decypher the string using opensource solutions related to enigma

--

it searched for enigma-related repos and implementations, fetched various github repos parts, build inline descryption program.

It ran bunch of various scrips like:

clang++ -g -fsanitize=address /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/enigma.cc -o /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/enigma_dbg && echo "ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC" | /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/enigma_dbg -u B -w 123 -r AAA -g ... -c -l /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/english

and

sed -n '1060,1130p' /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/enigma.cc

and

Running 82M combination scan for unsteckered Enigma across all rotors, reflectors, positions, and ring settings. Monitoring progress.

and

Scanning all 60 rotor permutations and reflectors B and C across all ring settings (step 2) and all 17,576 indicator positions. Monitoring progress.

--

I also have opus running. It produced some sypher cracker which is still running (estimated time 100min, is about 15 min left)

--

My point is that astra isn't special. This appears to be quite narrow, well-documented and explored task. The goal itself is approacheable by other LLMs and non-researches task.

irl_zebra8 days ago
I am not an SME and I oneshotted this in just 60 seconds by Googleing it.
podgorniy8 days ago
You won this time... :D
tantalor8 days ago
Neat, but "did it entirely on its own" is incongruous with "developing the necessary Python and C++ software for an Enigma simulator".

I'd start by asking how much of that generated software is novel, or easily found on the web? Then, how much of the breaking process was offloaded to that software? If Astra is just handing off tasks to another computer, then I'm not sure how much credit it deserves. Finally, it looks like Astra provided some useful insights which narrowed down the search. Were these insights cribbed from elsewhere?

voiper18 days ago
It's a given now that LLMs are leveraging code to do things.

"On it's own" generally means "not steered" or otherwise given professional guidance or input.

I would say "developed the necessary software for a simulator" to be even more impressive - "here solve this problem" and "OK, but first I have to built the entire lab!"

snthpy7 days ago
Indeed. It didn't write it's own TCP implementation either. Nor operating system, nor compiler, nor build its own wafer etcher...

My comment probably sounds facetious but I'm actually intrigued by why we seem to view using the level immediately underneath as cheating whereas the levels below that are taken for granted?

snthpy7 days ago
Why do we view using the level of abstraction immediately below as cheating while the levels below that are taken for granted?
tehlike8 days ago
Why does any of this matter? Llm is a memory of knowledge, of course it got what it got based on prior work.

It can code enigma simulator from the algorithm. That's not really a problem. Astra will send computing to programs, LLMs are not good at computing themselves, why is this a big deal?

elicash8 days ago
"I baked this cake on my own from scratch!"

"Oh?! You harvested and ground the wheat? You extracted the sugar? You laid the eggs?"

pramsey7 days ago
nonethewiser8 days ago
>I'd start by asking how much of that generated software is novel, or easily found on the web? Then, how much of the breaking process was offloaded to that software? If Astra is just handing off tasks to another computer, then I'm not sure how much credit it deserves. Finally, it looks like Astra provided some useful insights which narrowed down the search. Were these insights cribbed from elsewhere?

Well were they? Short of you showing us the answer just sitting there or some tool that can already solve it I see no reason to believe this was the case. And the problem being out there unsolved for a long time implies it's not the case.

And that's taking your concern at face value. It just seems incredibly pedantic to say it didn't solve the problem by itself because it created it's own tools to help solve it. Beyond that we could also fault it for not creating the GPU's it's running on.

adrianmonk8 days ago
I took "on its own" to mean that it didn't need any additional prompting or guidance from the person sitting at the AI console. If so, then the originality of its work or the resources it used isn't the point. They're reporting that it did whatever it did without requiring supervision.
dgoxow8 days ago
I think this is a bit late for the war effort.
peesem8 days ago
interesting, YouTube channel Veritasium just published a video on how Enigma was broken during WWII. at the very end they also give message that has yet to be decoded, although apparently they're different.

https://www.youtube.com/watch?v=JsBZOcqZerk

mmahemoff8 days ago
WRT the timing, Veritasium maybe looked at the last few weeks and decided there's a fast-closing window in which to report on any famous messages yet to be solved.
pocksuppet8 days ago
It is a private equity channel, so this is surely the reason. They have a team whose job is finding the most engaging content topics.
sorahn8 days ago
I just finished watching that video, and thought to myself "I'm sure someone else with Chat GPT tokens to burn has already done that"

And then I come to hackernews and well, not quite, but I'm sure that one will be done shortly too.

Perz1val8 days ago
Maybe both watched Tom Scott a month ago about Bletchley Park?
globular-toast7 days ago
This is a much more interesting video than the Veritasium one IMO. I mean, if you don't already know anything about Enigma then, sure, the Veritasium one is decent. But it's been done so many times and who doesn't know it at this point? Somehow, though, I hadn't understood the scale of the operation at the Park and how it was kept secret that whole time. The bits about compartmentalisation of knowledge were particularly interesting.

Read the full thread on Hacker News →

Related stories