“A system can reveal far more than its designer intended”

𝗢𝗰𝘁𝗲𝘁 𝘁𝗵𝗲 𝗧𝗵𝗶𝗿𝗱
What Systems Reveal
The third group of eight artefacts moves from wartime cryptanalysis into the foundations of modern information security.
A recurring idea connects them: a system can reveal far more than its designer intended.
Images in this article are generated by

EU AI Act Regulation 2024/1689
Genevieve Grotjan reconstructed the behaviour of PURPLE from patterns produced by a machine the Americans had never seen. Enigma operators added their own patterns through supposedly random choices. Joan Clarke and her colleagues used weak statistical evidence to decide which cryptanalytic possibilities deserved scarce machine time. Hedy Lamarr and George Antheil tackled a different problem: how two machines could remain synchronised while refusing to stay conveniently on one radio frequency. Colossus then showed what happened when selected parts of cryptanalytic thought became electronic and extraordinarily fast.
The Harvard Mark II moth changes scale completely. Instead of grand strategy or cryptanalysis, there is a relay, a fault, an insect, and an unusually good incident record. It becomes an excuse to examine debugging, observability, evidence, and the rather important distinction between a bug and a security vulnerability.
The final two artefacts go deeper.
Shannon’s Communication Theory of Secrecy Systems and TEMPEST are deliberately much larger articles. Both subjects are fundamental, highly technical, and frequently simplified until the simplification becomes misleading.
That extra length is not intended as an entrance examination.
Each begins with a “What you really need to know” section, and both are written so that the main argument can be followed without advanced mathematics, radio engineering, or prior cryptographic study. Analogies, worked examples, and call-outs carry the essential ideas; optional SUPER-TECH call-outs preserve some of the more formal or specialist detail for readers who want it. A reader who understands only the opening sections should still leave knowing substantially more than when they arrived.
That matters particularly for these two subjects because their popular versions are often wrong in opposite directions. Cryptography is sometimes presented as mystical mathematics available only to specialists; TEMPEST alternates between being dismissed as Cold War folklore and inflated into claims that every electronic device broadcasts every secret to anybody with an aerial. Neither treatment is useful.
Shannon’s Communication Theory of Secrecy Systems
This is where the series pauses and asks what secrecy actually means. Shannon turned an intuitive objective into something that could be stated mathematically: under perfect secrecy, observing the ciphertext gives the adversary no additional information about the plaintext. The article distinguishes information-theoretic secrecy from computational difficulty, explains why one-time pads are special and inconvenient, and repeatedly asks the question that matters most: what can the observer learn, from what evidence, under which assumptions?
TEMPEST
Shannon asks what the encrypted message reveals. TEMPEST asks what the rest of the machine may reveal while that message is being protected. Information can escape through unintended electromagnetic signals, conductors, displays, shared infrastructure, optical effects, acoustic effects, or deliberately manufactured physical channels. The article ranges from wartime cipher equipment and Spycatcher to keyboard emanations, display reconstruction, shielding, controlled space, and modern research, while being deliberately careful not to turn specific demonstrations into imaginary universal capabilities.
The aim here is understanding rather than mystique.
Taken together, the octet moves from recognising patterns, through understanding people and machines, to something broader:
Defining exactly what a security claim covers.
The cipher may be mathematically strong.
The operator may still choose badly.
The implementation may still reveal structure.
The machine may still leak.
The observer may still know something you forgot to include in the model.
Security becomes much easier to reason about once we stop asking only whether a particular defence works and start asking: What can the adversary actually observe?
That is the thread running through this octet.
And, indeed, through rather a lot of cybersecurity.

III
Octet the THIRD – Contents
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 017 | 1940 | Genevieve Grotjan Feinstein and PURPLE Diplomatic cryptanalysis | When the Pattern Revealed the Machine Genevieve Grotjan Feinstein spotted the pattern that broke open the Japanese diplomatic cipher machine known to the US as PURPLE. That insight enabled the construction of an analogue machine and the exploitation of diplomatic traffic during the Second World War. She later contributed to Venona, including work around recognising key reuse. The artefact is a reminder that cryptanalytic breakthroughs often begin as disciplined attention to a faint pattern others had not yet recognised, not as cinematic genius glowing under one convenient desk lamp. |
| 018 | 1940 to 1941 | Enigma cillies and operator keying habits Operational-security failure | When Randomness Became Routine A cilly was a guessable Enigma message setting: something pronounceable, patterned, related to an indicator, or otherwise born from operator habit rather than randomness. Bletchley Park exploited these human shortcuts alongside cribs, Herivel-type insights and machine assistance. The often-retold “girlfriend name” examples should be handled carefully, but they point to a real lesson: users create patterns when systems demand tedious randomness. Mavis Lever, later Mavis Batey, is rightly associated with spotting lazy Enigma usage in Italian and Abwehr work; the wider artefact is operational security collapsing under human convenience. |
| 019 | 1940 to 1945 | Joan Clarke, Banburismus and Hut 8 Cryptanalytic method | The Mathematics Before the Machine Joan Clarke was one of the few senior female cryptanalysts at Bletchley Park and the longest-serving member of Hut 8, which attacked German naval Enigma. Her work on Banburismus and related methods helped reduce the search space for naval keys. This artefact matters because naval Enigma was operationally critical and technically stubborn. Clarke also exposes a familiar security problem with historical record-keeping: when secrecy and sexism work together, attribution becomes a casualty. |
| 020 | 1942 | Hedy Lamarr and George Antheil frequency hopping patent Anti-jamming communications | The Signal That Would Not Sit Still Hedy Lamarr and George Antheil patented a frequency-hopping idea during the Second World War to make radio-controlled torpedoes harder to jam or intercept. It was not deployed in that wartime form, but it anticipated spread-spectrum thinking used in later secure and resilient wireless communications. It is not cybersecurity in the narrow compliance-checklist sense, mercifully. It belongs because communications security includes resistance to interception, jamming and traffic manipulation, and because Lamarr is one of the clearest examples of technical invention being dismissed when it came from the wrong sort of person. |
| 021 | 1944 | Colossus Codebreaking computer | The Computer Britain Pretended It Had Never Built Colossus was built at Bletchley Park to help attack the Lorenz cipher, not Enigma, and it is central to both computing and cybersecurity history. It linked electronics, probability, intercepted traffic and operational intelligence at a scale pencil-and-paper work could not have matched. Its secrecy delayed public recognition for decades, while the broader workforce around it was also under-credited. Colossus is an artefact of high-end security as collective engineering: mathematicians, engineers, operators, intercept stations and intelligence analysts all formed the system. |
| 022 | 1947 | Harvard Mark II moth and the visible bug Debugging artefact | When the Bug Was Visible The famous moth taped into the Harvard Mark II logbook did not invent the word bug, which predates electronic computers. It did, however, help make debugging visible: a fault was observed, preserved, labelled and folded into the culture of computing. The common Grace Hopper version of the story is useful but needs care. Hopper helped popularise the story and cement the bug in computing folklore, but the artefact itself matters because it turns security-adjacent fault finding into a disciplined habit: evidence rather than folklore. |
| 023 | 1949 | Shannon’s Communication Theory of Secrecy Systems Cryptographic theory | Unique does not mean easy. Ambiguous does not mean secret Claude Shannon made secrecy mathematical. His work linked cryptography to information theory, defined concepts such as perfect secrecy and helped move the field from craft to science. For cybersecurity, it is a founding text because it asks what can be proved about secrecy rather than what merely feels hard to guess. |
| 024 | 1950s onward | TEMPEST and emissions security Side channel | The Cipher Worked. Yet the Secret Escaped. TEMPEST work showed that systems can leak information through electromagnetic emissions and other physical side channels. This widens cybersecurity beyond software and passwords: a secure computation may still radiate clues. The idea later echoes in power analysis, acoustic leakage, cache timing attacks and the general misery that physics keeps joining the threat model. |
