The History of Encryption and Codebreaking
The contest between code-makers and code-breakers is one of the oldest technical rivalries in human history, spanning diplomatic ciphers, wartime codebreaking, public-key mathematics, and everyday smartphone security. Its breakthroughs, from frequency analysis and polyalphabetic ciphers to machine cryptanalysis and public-key cryptography, repeatedly reshaped war, statecraft, commerce, and the boundary between privacy and surveillance.
Events
Julius Caesar Encrypts His Correspondence
The Roman general Julius Caesar protected his private letters by shifting each letter of the alphabet three places, writing "D" for "A" and so on, the simplest substitution cipher in the historical record. The historian Suetonius described the method around 121 AD, and simple substitution of this kind remained the standard for secret writing for centuries.
Location: Roman Republic
Al-Kindi Breaks Substitution Ciphers with Frequency Analysis
In Baghdad, the scholar Al-Kindi wrote "Manuscript on Deciphering Cryptographic Messages," the first known work of cryptanalysis. By counting the frequency of letters in ciphertext and comparing them to the known frequency of letters in Arabic, he showed that substitution ciphers could be broken by statistical reasoning, founding the science of codebreaking centuries before machine methods.
Location: Baghdad, Abbasid Caliphate
Alberti Invents the Polyalphabetic Cipher
The Italian architect Leon Battista Alberti described a cipher disk that rotated between different substitution alphabets within a single message, the first polyalphabetic cipher. By varying the key as encryption proceeded, Alberti's system defeated the frequency analysis that had broken every earlier cipher.
Location: Rome, Papal States
Vigenère Publishes the Cipher Long Called Unbreakable
Blaise de Vigenère published a table-based polyalphabetic cipher that built on earlier designs by Giovan Battista Bellaso of 1553; the method carried Vigenère's name and, for three centuries, a reputation for being unbreakable. Its weakness, statistical structure in the repeating keyword, went unexploited until the 19th century.
Location: France
The Kasiski Examination Breaks the Vigenère Cipher
The Prussian infantry officer Friedrich Kasiski published a method for breaking polyalphabetic ciphers by locating repeated ciphertext fragments and deriving the length of the repeating keyword. Combined with later statistical techniques such as the index of coincidence, the attack ended the era in which strong manual ciphers could be kept permanently secret.
Location: Prussia
Room 40 Decrypts the Zimmermann Telegram
British cryptographers in the Admiralty's Room 40 decoded a German Foreign Office telegram offering Mexico a military alliance against the United States. The decoded text was passed to Washington and published in the American press on 1 March 1917, helping turn US opinion toward entering the First World War, one of the clearest cases on record of codebreaking changing the course of a war.
Location: London, United Kingdom
Polish Codebreakers Hand Their Enigma Methods to the Allies
Polish mathematicians Marian Rejewski, Jerzy Różycki, and Henryk Zygalski had reconstructed the German Enigma machine and read its traffic from 1932; on 25 July 1939, weeks before Germany invaded Poland, they handed their methods and replica machines to French and British intelligence. Their work became the foundation of the British codebreaking effort at Bletchley Park.
Location: Pyry, Poland
Colossus, the First Programmable Electronic Computer, Enters Service
Built by engineer Tommy Flowers at Bletchley Park to break the German Lorenz cipher used for high-command teleprinter traffic, Colossus began operating in early February 1944. The programmable electronic machine read encrypted messages at high speed and remained a state secret for decades, its existence declassified only in the 1970s, which delayed its recognition in the history of computing.
Location: Bletchley Park, United Kingdom
Diffie and Hellman Publish Public-Key Cryptography
Whitfield Diffie and Martin Hellman published "New Directions in Cryptography," describing a system in which strangers could exchange secret keys over an insecure channel using one-way mathematics, public-key cryptography. The paper ended the assumption that secure communication required a shared secret exchanged in advance; British cryptographers at GCHQ had found similar methods earlier in secret, a priority claim documented when their work was declassified in the 1990s.
Location: United States
RSA Makes Public-Key Cryptography Practical
MIT researchers Ronald Rivest, Adi Shamir, and Leonard Adleman devised the RSA cryptosystem, whose security rests on the difficulty of factoring large numbers, and published it in 1978. Later released on royalty-free terms, RSA became the standard for digital signatures, key exchange, and secure commerce on the early internet.
Location: Cambridge, Massachusetts, United States
PGP Brings Strong Encryption to the Public
Phil Zimmermann released Pretty Good Privacy, free software that encrypted email with strong public-key cryptography, and it spread worldwide within months. The US government opened a criminal investigation into whether Zimmermann had exported munitions without a license; civil liberties groups protested the case, and it was dropped in January 1996.
Location: United States
The Clipper Chip and the First Crypto War
The US government proposed the Clipper chip, an NSA-designed encryption device for telephones with keys held in escrow so law enforcement could obtain them with a court order. Technologists demonstrated the design could be circumvented, and civil liberties groups campaigned against mandated backdoors; the proposal was abandoned by 1996, but the question of government access to encryption returned in later disputes.
Location: United States
The Snowden Disclosures Reshape the Encryption Debate
Documents leaked by former NSA contractor Edward Snowden revealed bulk collection of telephone metadata and programs to undermine commercial encryption and tap internet infrastructure. Technology companies responded by deploying encryption widely, with encrypted connections and messaging becoming standard, while governments and cryptographers argued openly about the balance between surveillance capability and security.
Location: Global
Apple and the FBI Clash Over an Encrypted iPhone
A federal court ordered Apple to build software that would unlock an iPhone used by a perpetrator of the San Bernardino attack; Apple refused, arguing the tool would compromise the security of all its users. Officials citing national security needs and privacy advocates debated the question publicly, other technology firms backed Apple, and the FBI withdrew after purchasing a third-party tool, leaving mandated access unresolved.
Location: United States
NIST Finalizes the First Post-Quantum Encryption Standards
The US National Institute of Standards and Technology published its first three finalized standards for cryptography designed to withstand attacks by quantum computers, FIPS 203, 204, and 205, concluding an eight-year international open competition. Governments and companies began migrating their systems to the new algorithms, intended to replace public-key methods that a large quantum computer could break.
Location: Gaithersburg, Maryland, United States