“When Randomness Became Routine”

Choose three random letters.
Not memorable letters. Not your initials. Not the beginning of a name, a word, a swear word, a place or the previous setting still visible through the machine’s little windows. Do not run your fingers conveniently across neighbouring keys. Do not develop a favourite. Do not repeat yourself.
Images in this article are generated by

EU AI Act Regulation 2024/1689
Now do that correctly, several times a day, while tired, hurried, cold, frightened, under fire or being shouted at by someone who regards radio procedure as the only remaining barrier between civilisation and administrative collapse.
The Enigma machine offered its operators an enormous number of possible configurations. It also repeatedly asked human beings to supply choices that behaved as though they were random.
They did not.
The predictable settings and habits that resulted became known at Bletchley Park as cillies. They were not a mathematical defect in Enigma. They were something more persistent: a secure mechanism being weakened by the ordinary behaviour required to operate it. This artefact is an operational-security failure rather than another account of rotors, plugboards and heroic machinery.
The machine was only part of the system
There was no single, unchanging “Enigma procedure”. Different German armed services, networks and periods used different indicator systems, keys and operating rules. Procedures were altered when weaknesses were suspected or conditions changed, creating the sort of historical thicket in which confident diagrams breed freely.
Broadly, an Enigma network distributed a set of shared settings for a defined period, often a day. These might specify the rotor selection and order, ring settings, plugboard connections and other elements needed by everyone using that key. Individual messages then required an additional starting position or message setting, so that every transmission was not enciphered from precisely the same rotor position.
That message-specific choice was important. Two messages sent under the same configuration and starting at the same point could expose relationships between their ciphertexts. Giving every message a fresh starting position was supposed to prevent that.
But someone had to choose it.
In some Army and Luftwaffe procedures, the operator selected groups of letters for the initial position and message setting, then transmitted an enciphered indicator telling the receiving station how to configure its machine for that message. A 1945 Allied survey described a six-letter indicator and observed that carelessness entered when operators selected its components. Contemporary examples included adjacent keyboard letters such as ASD, or taking the final rotor position of one message as the starting point for the next.[2]
The cryptographic design created a vast space of possible choices.
The operator inhabited only a small, comfortable corner of it.
What was a cilly?
Bletchley Park’s 1944 Cryptographic Dictionary treated a cilly as a characteristic Enigma weakness associated with recognisable message settings. It referred to settings that could be identified as keyboard patterns, pronounceable groups or similar non-random choices. It even coined cillier for an operator, or a whole Enigma key, prone to producing them.
A cilly might be:
- adjacent letters on the keyboard;
- a pronounceable sequence;
- initials or part of a familiar name;
- the last visible rotor position after the previous message;
- a setting close to one the operator had just established;
- or any recurring choice revealing that the supposed randomness came from a person with habits.
The exact use of the term varied. Wartime documents sometimes applied it specifically to stereotyped indicator settings and sometimes more broadly to predictable operator behaviour that yielded a useful cryptanalytic attack. The spelling also wandered between cilli, cillis and cillies, because secret organisations tend not to fully document informal terminology and its full origin – giving future archivists something to argue about.[1]
The important point was not the label. It was that analysts could recognise the operator inside the ciphertext.
The girlfriend called Cillie
One enduring explanation says that the term came from a German operator who repeatedly used the name of his girlfriend, Cillie, when choosing settings.
Unusually, this is not merely a tale invented fifty years later by someone standing beside a museum Enigma. A classified 1944 US Army report on British Bombe work told essentially that story. It said that one operator repeatedly used the six letters of his girlfriend’s name and that “cillies” subsequently became the term for stereotyped choices. The same report listed convenient keyboard selections such as QWE and AST.
That establishes that the story circulated among wartime cryptanalysts.
It does not prove that the woman existed, that her name was spelled exactly that way, or that this single operator genuinely supplied the term’s origin. The Bletchley Park dictionary defines the technical usage but does not preserve the romantic etymology. The sensible treatment is therefore to present Cillie as a contemporary origin story, not as a securely documented participant whose exasperated descendants should expect a plaque.[3]
Whether or not there was one particular girlfriend, operators did choose names, initials and familiar sequences. The wider phenomenon is well supported. The anecdote survives because it compresses the whole weakness into one image: a machine designed to defeat industrial cryptanalysis being nudged open by someone thinking fondly of home.
War is full of many stranger attack surfaces.
Humans are poor random-number generators
People do not naturally select uniformly distributed symbols.
They select things that look random enough.
A sequence such as QAZ, ASD or PYX may seem arbitrary when chosen quickly, but keyboard geometry makes it more likely than most of the other 17,000 possible three-letter combinations. A name or pronounceable group feels easier to remember. Reusing the final setting of the previous transmission saves a few seconds and avoids another decision. Choosing a nearby rotor position is physically and mentally easier than deliberately moving every wheel somewhere unrelated.
None of these habits need be dramatic. That is what makes them useful.
Suppose an analyst had to test every possible setting. Even with electromechanical assistance, the cost could be considerable. If operators favoured a small collection of patterns, the analyst could test those first. A predictable choice did not necessarily reveal the whole daily key, but it could provide a foothold, identify related traffic, produce a useful Bombe menu or reduce a vast search into something operationally manageable.
The 1944 American Bombe report explicitly described cilly settings as an aid to inferring likely configurations on particular communications links. Bletchley’s analysts also maintained registers of message indicators, call signs, interception details, lengths and transmission times partly to detect cillies and other recurring characteristics. They called one such register a Blist, from “Banister list”, because one can never have enough eccentric terminology.[3][1]
The artefact was therefore not merely one silly setting.
It was accumulated behaviour.
One operator choosing ASD once was an inconvenience. An operator choosing it repeatedly became a statistical identity. Several operators on the same network developing recognisable habits became an intelligence source.
Do not confuse the cilly with the crib
Popular accounts often bundle every Enigma weakness under “operator error”, then stir cillies, cribs, repeated messages, weather reports and captured codebooks into one historical soup.
They are related, but not identical.
A crib was a probable piece of plaintext expected to appear somewhere in an encrypted message. Routine expressions, reports, headings or predictable formats could provide likely words against which ciphertext was tested. Since Enigma would not encipher a letter as itself, impossible placements could be discarded, and a promising crib could be converted into a menu for a Bombe run.
A cilly concerned a predictable setting or indicator choice. It provided information about where or how the machine might have been started.
A kiss was the same or substantially similar message sent in two different cryptographic systems, allowing the more vulnerable version to illuminate the stronger one.
The categories could help one another. A cilly might expose a setting from which a message could be read. A routine message might provide a crib. A lower-grade version might provide a kiss. Traffic analysis might identify the operator, unit or network most likely to exhibit the useful habit.
Breaking Enigma was not one clever trick. It was an industrial process for combining small pieces of advantage until the remaining search could be mechanised.
The operator supplied several of those pieces free of charge. Systems are usually designed with a safety margin. This provides a measure of protection against failure of the system, whether that system is a building, a window-cleaning cradle for use on skyscrapers, or a cryptographic design. Attacks may be better than expected, information may leak, equipment may be worn or defective, operators may misunderstand instructions or not implement them because they don’t realise how critical they are. Or the instruction may ask the impossible, such as make up random characters. Giving away your safety margin for free is beyond unwise; it is an invitation to failure. Bletchley staff were happy to RSVP to such invitations.
The Herivel tip
John Herivel identified a related weakness before the Bombes were generally available.
At the beginning of a new key period, an operator had to configure the machine according to the day’s instructions. That involved adjusting the letter rings and placing the rotors into the machine. Herivel reasoned that a hurried or tired operator might then select the initial position for the first message without moving the rotors very far from the positions in which they had just been handled or inserted.
If enough early messages were collected, their indicators might cluster around the underlying ring settings.
The individual message would reveal little. A group of operators making the same kind of convenient choice could expose the neighbourhood in which the cryptanalysts ought to search. GCHQ describes Herivel’s insight as the prediction that hurried operators would make choices leaking information about the configuration; it became especially important after a German procedural change removed an earlier attack derived from the Polish indicator method.[4]
The Herivel tip, or Herivelismus, was not exactly the same thing as every cilly. It attacked a particular relationship between setup procedure and operator-selected starting positions. It belongs in the same artefact because the underlying failure is identical:
the procedure required the operator to introduce unpredictability at precisely the moment when convenience encouraged the opposite.
Cryptographers had examined the machine.
Herivel examined the person sitting in front of it; what today analysts may term a “chair-keyboard interface issue”.
Mavis Lever and the psychology of the operator
Mavis Lever, later Mavis Batey, became particularly adept at thinking about what an operator might choose.
She was recruited to Bletchley Park as a young linguist and worked with Dilly Knox’s team against Italian and later Abwehr Enigma. GCHQ credits her with the Italian naval decrypt indicating “D-3” readiness before the Battle of Cape Matapan and with a major role in breaking Abwehr Enigma, which became important to the Allied deception supporting D-Day.
Her recollections emphasised the psychological side of the work. Analysts imagined the circumstances of the person enciphering the message: hurried in combat, bored during routine traffic, inclined towards initials, familiar names, keyboard patterns or earthy vocabulary. She joked that this made her exceptionally knowledgeable about short German obscenities, one of the less obvious benefits of a career in national service.
Batey’s more famous Italian breakthrough also illustrates the broader principle. An Italian operator transmitting a dummy test message appears to have repeatedly pressed the same key. Because Enigma could never encipher a letter as itself, the one ciphertext letter that failed to appear helped identify the plaintext key and contributed to reconstructing the machine’s wiring. The mistake was not a cilly in the narrow indicator-setting sense, but it was another case of an operator replacing the required complexity with something easy.
The machine behaved correctly. The test procedure did not.[5]
That distinction is this entire article in miniature.
Operators were not idiots
It is easy to tell this story as clever British cryptanalysts defeating foolish German wireless operators.
That is satisfying, patriotic and not particularly useful.
The operators were working inside a demanding communications system. They had to receive messages, abbreviate or format them, configure equipment, create indicators, encipher text, transmit Morse accurately, correct errors, keep logs and comply with procedures, often in unpleasant operational conditions. The translated 1940 Enigma instructions devote detailed attention to recovering from a single incorrect keypress, including reversing rotor movement or restarting the encipherment if the correct state could not be restored.
This was skilled, repetitive labour performed under pressure.[6]
Security procedure added cognitive effort to the operator’s real task, which was getting the message through. When the secure behaviour was slow, forgettable or awkward, shortcuts emerged. Some operators were careless. Others were probably doing what organisations still train people to do indirectly: complete the mission, meet the deadline and make the supposedly random field stop obstructing the workflow.
The defenders had designed randomness as a human responsibility without giving humans a reliable mechanism for producing it.
Blaming the individual is therefore incomplete. The deeper failure was procedural design.
The operator became part of the key
Traffic analysts could sometimes recognise individual wireless operators by their Morse rhythm or fist. They could identify networks through frequencies, call signs, schedules and routing behaviour. GCHQ’s history of the German BROWN network describes how personal idiosyncrasies, insecure chatter and recurring operator practices became as useful as direction finding or technical radio fingerprinting.
Cillies extended that fingerprint into cryptographic operation.
An operator might favour particular letters. A station might have a local convention. A unit might reuse a convenient pattern. The choice of setting became behavioural metadata.
This means the operator was not merely someone possessing the key.
The operator became part of the key-generation process.
And because people have recognisable habits, that part of the process could be profiled.[7]
Modern defenders would recognise the shape immediately. Users create predictable passwords despite complexity rules. Developers seed pseudo-random generators with timestamps. Systems oxymoronically reuse nonces. Administrators derive secrets from hostnames or dates. Recovery questions ask for facts that are memorable precisely because they are not secret. Teams copy yesterday’s configuration because generating a fresh one is tiresome and the meeting starts in four minutes.
The technical implementation may allow billions of possibilities.
The operational process selects from twelve.
Machinery still needed human mistakes
Cillies did not make the Bombes unnecessary.
They made the Bombes more useful.
A Bombe did not wander intelligently through Enigma’s entire keyspace and emerge holding a plaintext like a mechanical oracle. It tested logical implications derived from a crib or other cryptanalytic hypothesis. Analysts needed to construct a useful menu, select likely circumstances and examine candidate stops. Operator habits could reveal promising settings or relationships, helping the machinery attack a smaller and better-defined problem. A wartime account of Army and Air Force Enigma explicitly noted the use of Bombe menus derived from cillies.[2]
This relationship matters.
The romantic version of computing history says machines replaced human intuition.
At Bletchley Park, machinery scaled human inference. Intercept operators collected the traffic. Traffic analysts grouped it. Cryptanalysts identified habits and probable text. Clerks built records. Engineers built and maintained Bombes. Bombe operators ran the jobs. Checking machines and human analysts investigated the results.
The cilly was where the enemy operator’s human behaviour entered that Allied production line.
One person took a shortcut. Thousands of people and machines were organised to notice.
What changed?
The Germans did alter Enigma procedures during the war. Some changes disrupted existing Allied methods and forced new attacks. Different networks also varied widely in discipline. Naval Enigma, in particular, often imposed more elaborate procedures than some Army or Luftwaffe systems, although no organisation ever achieved immunity from capture, repetition, predictable text, operator behaviour or the general human appetite for making complicated systems tolerable.
The lesson is not that Enigma remained permanently vulnerable to one girlfriend’s name.
It is that improving the machine did not remove the surrounding system.
A new indicator procedure might defeat one attack while creating another dependency. More complex instructions could reduce obvious repetition while increasing operator burden. Stricter rules could help, provided they were followed under operational conditions. Captured documents, cribs, traffic analysis and mistakes continued to interact.
Security was not located in the wooden box.
It was distributed across key sheets, message forms, training, wireless discipline, operators, rotors, couriers, intercept stations and the people interpreting the resulting traffic.
The Enigma machine was merely the part museums could later put behind glass.
The cybersecurity lesson
Cillies are an early example of usable security failing under workload.
The official model assumed that the operator would choose a fresh, unpredictable setting.
The real model included fatigue, memory, keyboard layout, physical movement, repetition, habit and urgency.
The gap between those models was exploitable.
This is not merely a lesson about weak passwords. It applies whenever security depends upon users repeatedly making high-quality discretionary choices:
- selecting random values;
- recognising every malicious prompt;
- classifying every document correctly;
- checking every certificate warning;
- devising unique secrets;
- noticing tiny anomalies;
- or following a long procedure whose purpose is invisible while its inconvenience is immediate.
A control that works only when people behave as ideal random-number generators is neither a complete nor a realistic control.
A procedure that remains secure only when nobody is hurried has not been designed for real-world operations.
And an organisation that attributes every predictable workaround to “user error” may be documenting its own design failure with unusual persistence.
What the artefact really is
The obvious artefact is an Enigma machine with three letters visible in its rotor windows.
The better artefact is the indicator log.
Line after line of supposedly arbitrary groups. Beside them: time, call sign, frequency, message length and originating station. One group resembles a keyboard row. Another is pronounceable. A third begins where the previous message ended. The same operator appears tomorrow and makes the same kind of choice.
No single entry proves much.
The pattern does.
That is what Bletchley Park exploited: not stupidity, not one legendary girlfriend and not a magical weakness concealed inside Enigma’s rotors. It exploited the fact that repeated human choice produces structure.
Enigma’s designers built a machine with an immense number of settings.
Its operators kept visiting the same few.
And on the other side of Europe, someone was keeping a list.

00010010 DC2
References & Links
[1] The 1944 Bletchley Park Cryptographic Dictionary, especially cilli, cillier, pronounceable and Blist. The surviving Tony Sale transcription is based on the NARA copy and includes the complete dictionary. 1944 Bletchley Park Cryptographic Dictionary
[2] Tentative List of Enigma and Other Machine Usages, 30 March 1945. Contemporary Allied survey covering Army/Air Force Enigma procedures, stereotyped settings, reuse of positions and Bombe attacks. Tentative List of Enigma and Other Machine Usages PDF
[3] US 6812th Signal Security Detachment, Report on the British Bombe, Eastcote, 1944. A particularly valuable primary source because it explicitly gives QWE / AST and says an operator repeatedly used the six letters of his girlfriend Cillie’s name. 1944 Eastcote Bombe Report PDF
[4] GCHQ, “John Herivel”. Describes his reasoning about hurried operators and the later importance of the Herivel tip after the German procedure change. GCHQ – John Herivel
[5] “Cracking the codes of gardens: The life of Mavis Batey” Matapan, D-3 and Abwehr.
University of London – Mavis Batey
Decoding Nazi Secrets transcript; Batey’s own recollections about operator psychology and “dirty German words”.
PBS NOVA – Decoding Nazi Secrets transcript
[6] The translated 1940 Enigma General Procedure, captured German instructions held in the US National Archives, including detailed procedures and treatment of cipher mistakes.
Translated 1940 Enigma General Procedure
[7] Tony Comer, GCHQ, “The BROWN Story”, 8 May 2020. GCHQ says individual operator idiosyncrasies could be as valuable as direction finding or radio fingerprinting, and describes analysts building detailed knowledge of operators’ habits and personal lives.
GCHQ – The BROWN Story
