Recommended Posts

The best of the British code breakers have apparently met their match in a WWII-era secret message recently discovered attached to the leg of a long-dead pigeon. :(

Cryptographers at Britain?s Government Communications Headquarters (GCHQ), the spy agency in charge of signals intelligence, have been analyzing the short handwritten message for weeks but threw up their hands Friday, saying it will be impossible to decode ?without access to the original cryptographic material.?

The note, written on official stationary with the heading ?Pigeon Service,? was discovered in a red canister attached to the skeletal leg of a pigeon in a chimney in Surrey. The message is made up of 27 seemingly random five-letter blocks and though it?s undated, government analysts believe the pigeon met his end while on a secret mission during the Second World War. The note is signed ?Sjt W Stot? and was intended for the destination ?XO2.?

In a statement released overnight, the GCHQ said that during the war, secret communications would often utilize specialized codebooks ?in which each code group of four or five letters had a meaning relevant to a specific operation, allowing much information to be sent in a short message.? The GCHQ said that those messages may have been put through an additional layer of security by being re-coded with what?s known as a one-time pad.

One-time pads make up a theoretically uncrackable secret communications system in which an agent could encode a message using a key that uses truly random numbers to translate plain text into what looks like jibberish. The recipient of the coded message would then only be able to decode the message if they possessed an identical key. After a single use, both keys would be destroyed.

?This means that without access to the relevant codebooks and details of any additional encryption used, it will remain impossible to decrypt,? the GCHQ said.

Nearly a quarter million carrier pigeons were used during the Second World War by various branches of the British military including Britain?s Special Operations Executive, according to the GCHQ. In the air, the small birds fought their own version of the war, braving enemy hawk patrols and soldiers on the ground taking potshots.

The GCHQ has enlisted the Pigeon Museum at Bletchy Park to trace the identity of the pigeon ? each was given a service number ? but is still seeking information on what ?Sjt W Stot? and ?X02? could tell them about the note?s origin and purpose. Was it vital information about the secret D-Day invasion plans? Was it nothing but a training exercise?

One GCHQ historian told BBC News the most helpful suggestion came from the public already:

?A member of the public? suggested that, since the message was found in the chimney, the first two words are most likely to be ?Dear Santa,?? the historian said.

source

post-37120-0-69013100-1353712040.jpg

Link to comment
https://www.neowin.net/forum/topic/1121802-help-spies-crack/
Share on other sites

I think the first and last words are key to solving this maybe something polite? like sir or major etc ... it seems to be some kind of formal greeting, also the 27 1525/6 might be a cipher clue ... or as I have been learning the last few days it might be an intensifier OR the second half to a decryption code (that way if they sent it attached to the post, you could decrypt it) means they could change half the process each time

correct me if you think im wrong just thought I would try and be usful

AoAKN HVPKD FNFJU YIDDC

RQXSR DJHFP FOVFN MIAPX

PABUZ WYYND CNPNW HJRZH

NLXKE AENER ONOIB AREEQ

UAOTA RBQRH DJOFM TPZEH

LKXEH REEHT JRZCQ FNKTQ

KLDTS FQIRU AOAKN 27 1525/6.

Don't bother trying to crack it. It's probably encrypted using a one-time pad. It's the only cipher that is 100% mathematically proven to be impossible to decrypt.

I think the first and last words are key to solving this maybe something polite? like sir or major etc ... it seems to be some kind of formal greeting

You're making stuff up :p

Anyway, the 27 1525/6... it's 27 blocks of 5...

Don't bother trying to crack it. It's probably encrypted using a one-time pad. It's the only cipher that is 100% mathematically proven to be impossible to decrypt.

You're making stuff up :p

:/ Im just taking a guess ... lol when trying to decrypt something like this you have to try and look for human error this is not made by a computer this is a human made encryption there will be mistakes and give aways Im not saying I could crack it but hey its just a lil fun why not share a few ideas xD .... like SJT could also be a hint / encrypted thing ... I would guess its a prefix

Sjt W Stot

CPL CL_L

COL CL_L

CSM CM_M

PFC PC_C

MSG MG_G

GEN GN_N

PVT PT_T

PV2 P2_2

LTC LC_C

PFC PC_C

SGM SM_M

SMA SA_A

CPT CT_T

SGT ST_T

PO3 P3_3

PO1 P1_1

PO2 P2_2

ENS ES_S

CPO CO_O

Amn An_N

A1C AC_C

SrA SA_A

Windows 9 product key :laugh:

O.o shh people will know im a time lord

I think the first and last words are key to solving this maybe something polite? like sir or major etc ... it seems to be some kind of formal greeting, also the 27 1525/6 might be a cipher clue ... or as I have been learning the last few days it might be an intensifier OR the second half to a decryption code (that way if they sent it attached to the post, you could decrypt it) means they could change half the process each time

lol well since cryptographers have been unable to crack it for weeks, I highly doubt someone here on Neowin is going to find the solution.

That looks like a knock off of a caesarian shift cipher. The fun part is figuring out how the letters shift.

lol well since cryptographers have been unable to crack it for weeks, I highly doubt someone here on Neowin is going to find the solution.

Not true. I know some people on this same forum that can reverse engineer key codes for software and then write a key generator for said software. Maybe they just have not been pointed at this yet.

Thing is, if this code requires a one time pad to decipher it we're kinda screwed. The first and last block being identical could mean several things. It could be part of a key to decipher the code or it could simply indicate the beginning and end of a message.

My personal opinion is this is little more than a dyslexics love letter.

Depends on the algorithm used. If its a known one (AES), yes, in billions of years it can be cracked. But what if its a homemade one that only one person knows? Uncrackable.

if a message was sent, then 2 people knew the decryption if two people know it at least so do many O.o just need to find the grandkids of all the spies in wwII

I think that it could be a Caeser Substitution Cipher but without a Cipher Disk I wouldn't be able to try decoding it. The only two other things it could be using are Bentley's Complete Phrase Code or Polyalphabetic Substitution.

The other possibility is that it's a double encryption, using one or two methods, which was quite common during World War Two to protect sensitive information.

If anyone cracks this I think it'll probably lead to one of 2 possible outcomes;

1) You win yourself a job for GCHQ

2) You win yourself a permanent place on the list of people to be watched

;)

If anyone cracks this I think it'll probably lead to one of 2 possible outcomes;

1) You win yourself a job for GCHQ

2) You win yourself a permanent place on the list of people to be watched

3) Be found in a shallow grave with a bullet hole to the back of the head

;)

Fixed that for ya ;)

  • Like 2

I'm a time lord

Then would you be so kind to go back in time and get us the key, all mighty lord of time? :rofl:

Like Rfirth said, I think the bottom letters are the key. I tried doing 1=A and then 5 more than o = T, which spells "AT" but I think that's just a quiescence....I'm close!

Then would you be so kind to go back in time and get us the key, all mighty lord of time? :rofl:

Like Rfirth said, I think the bottom letters are the key. I tried doing 1=A and then 5 more than o = T, which spells "AT" but I think that's just a quiescence....I'm close!

Then why isn't the lower case "o" used elsewhere in the text. I think that the "Ao" is the cipher key i.e. A=o. Also if "1=A" and "o=T" then the first two characters would be 1T which doesn't really make sense.

This topic is now closed to further replies.
  • Posts

    • How many other companies will follow Ford's lead? Or, have they already gotten lazy and become enslaved to AI--and now can't figure out how to get out of that mess.
    • Why would any self-respecting intelligent person follow any recommendation by Donald's GOP administration? With almost two years of fabrications, deceit, and blatantly illegal behavior, why believe them now? They had best be gone after the November 2026 election, so we'll wait and see.
    • AltSendme 0.4.1 by Razvan Serea AltSendme is a minimal, cross-platform application designed for fast, secure, and private peer-to-peer file transfers. It allows users to send files or entire directories directly between devices without relying on cloud servers, accounts, or any personal information. Everything is encrypted end-to-end using modern protocols like QUIC and TLS 1.3, ensuring both strong security and low-latency performance. Transfers are verified with BLAKE3 for data integrity, and interrupted downloads automatically resume, making the experience reliable even on unstable connections. You can transfer anything—images, videos, documents, and more. Integrity checks are performed on both ends, so your files are automatically verified for correctness during both sending and receiving. AltSendme works seamlessly across local networks or long-distance links, capable of saturating multi-gigabit connections for extremely fast delivery. With built-in NAT traversal and encrypted relay fallback, it connects devices almost anywhere. The app integrates with the Sendme CLI and will soon support mobile and web platforms. Fully free and open-source, AltSendme offers a lightweight, privacy-first alternative to traditional cloud-based services, removing size limits, upload costs, and unnecessary data exposure. AltSendme 0.4.1 changelog: Release Highlights Self-hosted relays: Run your own iroh relay so transfers don't rely on public infrastructure. Includes a full deployment template in deploy/relay/ with Docker Compose for a VPS and configuration examples for production use. Fly.io support: One-click deploy template for Fly.io, including a quick-start config (fly.dev.toml) for testing without a custom domain, plus production setup with Let's Encrypt and your own hostname. Relay settings UI: New Settings → Network panel to choose how AltSendme connects: automatic public relays, custom self-hosted URLs (with optional auth token), or disabled. Test connections, verify latency, and see live relay status in the footer. Disable relays: Turn off relay servers entirely when you only need same-network transfers (e.g. LAN). Direct connections only. No relay hop required when devices can reach each other. Android graduates from beta: Android is now part of the regular release cycle alongside desktop. APKs ship with each version (universal, arm64, and armv7). Other improvements Private relay access control via shared auth token Relay fallback notifications when a custom relay is unreachable Broadcast mode toggle in sharing settings Android release build fixes (split-per-ABI APKs, universal APK preservation) UI polish: mobile safe-area insets, dropzone layout, transfer progress animation Bug fixes for minification-related serialization issues and system tray icon loading What's Changed feat(relay): add relay status functionality and settings UI (a120cdf) feat(relay): implement custom relay server configuration and verification (51276c7) feat(relay): add configuration for private relay access and enhance observability features (48fbabf) feat(relay): enhance relay URL validation, display connection status (d4fffa0) feat(relay): add RelayChangeGuard component and enhance relay-related translations (16ba514) feat(broadcast): add toggle setting for broadcast mode in sharing UI (ca6d977) fix(relay): correct QUIC discovery port, pin image, templatize fly.dev (52a2ba5) fix: More broken serialization due to minification (67491a9) fix(android): preserve true universal APK across per-ABI builds (e9f256f) fix(ui): conditional safe-area insets padding on mobile (1182f0e) refactor(transfer): CircularRing component animation fix (944572b) chore(android): drop x86 and x86_64 release APKs, keep universal+arm64+armv7 (34ada0b) Download: AltSendme 0.4.1 | ARM64 | ~9.0 MB (Open Source) Download: AltSendme for MacOS | Android Links: AltSendme Home Page | GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • You are mostly right about the ephemeral nature of it. As I mention in the article, if you dont add a second device or take a backup of your account before uninstalling it, then yes you will lose access to your account. That said, in terms of actual user experience when you sync multiple devices your message history carries across and there's also a Saved Messages chat like there is on Telegram to send messages and attachments between your installs. But yh, what you point out are correct and its not trying to emulate Messenger or Telegram.
    • OK so SearXNG is a meta search engine that you can install locally or use via a public instance. It scrapes other search engines which you choose and then sorts the results. Not as complicated as multiple relays
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      492
    2. 2
      +Edouard
      224
    3. 3
      PsYcHoKiLLa
      150
    4. 4
      Steven P.
      75
    5. 5
      FloatingFatMan
      71
  • Tell a friend

    Love Neowin? Tell a friend!