About Sophie

Cybersecurity, assurance, technology, identity, and life.

“I dare do all that may become a woman. Who dares do more is none.”

New Series: Sophie Baskerville’s History of Cybersecurity

sophie @ baskerville.net ©️1977-2026 Sophie Baskerville

Octet III | What Systems Reveal


“A system can reveal far more than its designer intended”

Purple-and-sepia collage representing the third octet of Sophie's A History of Cybersecurity. Across the image, people, machines, papers, punched tape, mathematical notation, radio signals, and monitoring equipment are layered together to show how supposedly secure systems can reveal information in unexpected ways.

At the upper left, a young woman stands beside cryptanalytic worksheets and a complex cipher machine, representing Genevieve Grotjan Feinstein and the breaking of PURPLE by analysing patterns in intercepted messages rather than by capturing the original machine. Nearby, an operator works at an Enigma-like machine, while handwritten tables and settings suggest the predictable human choices and procedural habits exploited in cillies.

At the upper centre, a woman studies long punched-paper sheets covered in letters and marks, evoking Joan Clarke, Banburismus, and the careful statistical comparison of Naval Enigma traffic before scarce Bombe time was committed. To the upper right, a glamorous woman and a male collaborator sit beside punched rolls and radio-wave graphics, representing Hedy Lamarr and George Antheil’s synchronised frequency-hopping concept, with wartime aircraft, radio masts, and a naval vessel in the background.

The centre of the collage contains large racks of electronic equipment and looping punched paper tape, representing Colossus and the transition from human cryptanalysis to fast, programmable electronic processing. Above the racks is a logbook page with a moth attached to it, referring to the Harvard Mark II incident in which an actual moth was found inside a relay, and to the wider themes of debugging, observability, and preserved evidence.

At the lower left, Claude Shannon sits thoughtfully beside papers covered with probability curves, information-theory diagrams, logic symbols, and punched tape, representing the mathematical foundations of secrecy and the distinction between what an observer can learn and what is merely difficult to calculate.

At the lower right, a cutaway secure room contains a person working at communications equipment while glowing purple signal lines escape through the walls and surrounding infrastructure. Outside, another figure wearing headphones watches a waveform display beside antennas and monitoring equipment. This represents TEMPEST and the idea that information may escape through unintended electromagnetic, conducted, optical, acoustic, or other physical channels even when the intended cryptographic protection remains intact.

Fine violet lines connect the different scenes across the collage, visually linking the eight artefacts through the shared theme of systems revealing more than their designers intended.

𝗢𝗰𝘁𝗲𝘁 𝘁𝗵𝗲 𝗧𝗵𝗶𝗿𝗱

What Systems Reveal

The third group of eight artefacts moves from wartime cryptanalysis into the foundations of modern information security.

A recurring idea connects them: a system can reveal far more than its designer intended.

Images in this article are generated by

EU AI Marker icon

EU AI Act Regulation 2024/1689

Genevieve Grotjan reconstructed the behaviour of PURPLE from patterns produced by a machine the Americans had never seen. Enigma operators added their own patterns through supposedly random choices. Joan Clarke and her colleagues used weak statistical evidence to decide which cryptanalytic possibilities deserved scarce machine time. Hedy Lamarr and George Antheil tackled a different problem: how two machines could remain synchronised while refusing to stay conveniently on one radio frequency. Colossus then showed what happened when selected parts of cryptanalytic thought became electronic and extraordinarily fast.

The Harvard Mark II moth changes scale completely. Instead of grand strategy or cryptanalysis, there is a relay, a fault, an insect, and an unusually good incident record. It becomes an excuse to examine debugging, observability, evidence, and the rather important distinction between a bug and a security vulnerability.

The final two artefacts go deeper.

Shannon’s Communication Theory of Secrecy Systems and TEMPEST are deliberately much larger articles. Both subjects are fundamental, highly technical, and frequently simplified until the simplification becomes misleading.

That extra length is not intended as an entrance examination.

Each begins with a “What you really need to know” section, and both are written so that the main argument can be followed without advanced mathematics, radio engineering, or prior cryptographic study. Analogies, worked examples, and call-outs carry the essential ideas; optional SUPER-TECH call-outs preserve some of the more formal or specialist detail for readers who want it. A reader who understands only the opening sections should still leave knowing substantially more than when they arrived.

That matters particularly for these two subjects because their popular versions are often wrong in opposite directions. Cryptography is sometimes presented as mystical mathematics available only to specialists; TEMPEST alternates between being dismissed as Cold War folklore and inflated into claims that every electronic device broadcasts every secret to anybody with an aerial. Neither treatment is useful.

Shannon’s Communication Theory of Secrecy Systems
This is where the series pauses and asks what secrecy actually means. Shannon turned an intuitive objective into something that could be stated mathematically: under perfect secrecy, observing the ciphertext gives the adversary no additional information about the plaintext. The article distinguishes information-theoretic secrecy from computational difficulty, explains why one-time pads are special and inconvenient, and repeatedly asks the question that matters most: what can the observer learn, from what evidence, under which assumptions?

TEMPEST
Shannon asks what the encrypted message reveals. TEMPEST asks what the rest of the machine may reveal while that message is being protected. Information can escape through unintended electromagnetic signals, conductors, displays, shared infrastructure, optical effects, acoustic effects, or deliberately manufactured physical channels. The article ranges from wartime cipher equipment and Spycatcher to keyboard emanations, display reconstruction, shielding, controlled space, and modern research, while being deliberately careful not to turn specific demonstrations into imaginary universal capabilities.

The aim here is understanding rather than mystique.

Taken together, the octet moves from recognising patterns, through understanding people and machines, to something broader:

Defining exactly what a security claim covers.

The cipher may be mathematically strong.
The operator may still choose badly.
The implementation may still reveal structure.
The machine may still leak.
The observer may still know something you forgot to include in the model.

Security becomes much easier to reason about once we stop asking only whether a particular defence works and start asking: What can the adversary actually observe?

That is the thread running through this octet.

And, indeed, through rather a lot of cybersecurity.

Octet the THIRD – Contents