1721'01'51'71'9 2'12'68 3'2 3'32'03'7 000000 1'62'71'23'43'8
2'8 2'2 3'9 4'04'14'24'84'4 000000 9 31'3000 1'8 42'32'4000
4'62'93'5 5'154'34'700 0 61'13'65'05'23'04'94'52'53'11'4 —

Washington · April 1935 · Schmeh Top 50 no. 17 · explained

The Roosevelt cryptogram

Three lines of digits above a schoolboy threat to the President, reproduced by William Friedman, unread since 1935

They are the numbers 1 to 52, each written once, in an order that looks like a hand-written shuffle. There is no text behind them.

Daniel Bourdeau · resolved

Summary. Read at glyph level from the sharpest copy available, the number block is a permutation of 1 to 52: nine single digits and 43 tick-joined pairs, every value once, plus eighteen zeros in groups of six and three. Thomas Ernst noticed this in 2017 and called the block a doodle; the claim checks out. The permutation is not a random one: its values drift upward with position, it runs through 39 40 41 42 in a row, and it decomposes into sixteen rising chains where a shuffle would give about 26. Those are the marks of a person writing down "random" numbers without repeating any. The one family of cipher readings that can be tested at this length, alphabetically ordered homophones or a rank-derived transposition key, fails while matched 52-letter controls are recovered. Status: explained as a constructed sequence, not read. There is no message to read.

01 The object

A sheet received by the Secret Service on 24 April 1935, according to the receiving stamp on its face, headed “Secret Service” in a looping hand, with a diagonal “261” top right, three lines of digits, two lines of block capitals, and a skull and crossbones above a dagger driven through a boot. William Friedman reproduced it as figure 2 of the first of his 1959 lectures, printed by the NSA as The Friedman Legacy (1992), with one sentence: an authentic example of a transposition cipher, sent to President Roosevelt, which the Secret Service asked him to decipher, and which to his chagrin said “Did you ever bite a lemon?” That reading takes every second letter of NDOIMDEYLOAUEETVIEBR?; the line under it, OR ELSE YOU DIE!!, is in clear. Friedman said nothing about the digits.

Klaus Schmeh posted the letter in 2015 and again in December 2017 as number 17 of his fifty unsolved cryptograms. In the comments Marc Gutgesell observed that no tick-joined pair repeats and that the loose digits are 1 to 9; Thomas Ernst listed the 43 pairs, found they were exactly 10 to 52, and concluded the block was “a doodle, if not a fake”, perhaps made to give Friedman a lemon to bite. Nobody has proposed a reading since.

02 The reading

Two copies exist: Schmeh’s 614-pixel scan and the figure in the NSA book. The Internet Archive holds a 300 ppi scan of the book, and its figure, cropped here, is the sharpest copy of the block that can be had without the original.

The Roosevelt letter: three lines of digits with ticks, the letter lines, a skull and crossbones and a dagger through a boot
Figure 2 of The Friedman Legacy, NSA Center for Cryptologic History, 1992, from the Internet Archive scan.

The “apostrophes” of the standard transcription are short ticks written between and above two digits, and the two digits under a tick are one number. Digits without a tick stand alone. Read that way the block is:

1 7 2  10 15 17 19 21 26  8  32 33 20 37  000000  16 27 12 34 38
28 22 39 40 41 42 48 44  000000  9 3 13  000  18 4 23 24  000
46 29 35 51 5 43 47  000  6 11 36 50 52 30 49 45 25 31 14 —

The 43 pairs are the numbers 10 to 52, each exactly once. The nine loose digits are 1 to 9, each exactly once, in the order 1 7 2 8 9 3 4 5 6. The eighteen zeros come in groups of 6, 6, 3 and 3. That is the whole content of the block: a permutation of 1 to 52 with four separators. Friedman’s or the Secret Service’s pencilled trial letters under the digits, which two commenters noticed, are not recoverable from either scan.

03 A shuffle written by hand

A permutation of 52 numbers can be tested against a fair shuffle. This one fails in four ways at once.

statisticobservedfair shuffle of 52p (200 000 shuffles)
rank correlation of value with position+0.3900.002
neighbours differing by exactly +15about 10.003
rising chains (values whose positions increase)16about 26.5below 1 in 200 000
neighbours summing to 534about 10.018

The rising chains are the telling one. Follow each value to the next: 1 2 3 4 5 6 appear in that order along the block, so do 7 8 9, 21 to 25, 26 to 31, 32 to 36 and 37 to 43. The writer worked upward through the unused numbers in several interleaved passes, fell back for the ones skipped, and when fresh numbers ran short wrote 39 40 41 42 straight off. Every anomaly in the table is of that kind. Three of the four pairs summing to 53 straddle a zero group (37|16, 44|9, 47|6), which Gerd noticed in 2017; it is a mild excess and not a structure anything else depends on.

The one object that comes in 52 is a deck of cards, so the block was also tested as a riffle-shuffled deck. Sixteen rising chains is what four riffles produce, but a deck riffled four times does not also drift upward by 0.39 and run four consecutive cards: the joint event has probability 0.003 under the Gilbert-Shannon-Reeds model at four riffles and 0.023 at three. A hand-written list explains the block better than a deck does. Neither contains a text.

04 The cipher readings that can be tested

A block in which every number appears once can be a cipher in only two ways: a homophonic substitution with 52 homophones each used once, or a transposition key derived from a 52-letter phrase by ranking its letters. With an unordered key either reading can produce any 52-letter text at all, so neither can be tested or refuted; one commenter demonstrated this by fitting an arbitrary sentence. With an ordered key, homophones assigned to the alphabet in order or the phrase recovered from the inverse permutation with letters nondecreasing along the ranks, the plaintext is fixed by 51 boundary choices, about 66 bits, against roughly 70 bits of redundancy in 52 letters of English. That is testable, just.

The test: simulated annealing over nondecreasing maps from 1 to 52 onto the alphabet, scored by a character 5-gram English model, in six readings (sequence order and inverse permutation, alphabet forward and reversed, zero groups as word breaks or ignored), with 60 restarts of 60 000 steps each. The control: 52-letter passages of Dickens and Melville enciphered with ordered homophonic keys and attacked identically.

readingbest score, nats per letterbest candidate
sequence, alphabet a to z−3.02abadefillbookofmdoomloorstsbadfallsnowassadovyouslod
sequence, a to z, zeros as word breaks−2.70abadefillbooko endoonloorsus dad falltoowast adovyouslod
sequence, alphabet z to a−3.18uttooooonsnnolonominoffeedertootooenlatedtoldandenno
inverse permutation, a to z−2.63derssteeretiryehereheissuehistwehisthinnootrustoutst
inverse permutation, z to a−3.03ttheeetsiteseatstetstreeatssedassseesspooneibeendeed
controls, 8 passages−1.48 to −1.977 of 8 read at 88 to 100% of letters; one at 46%

Nothing from the block comes within 0.6 nats per letter of a recovered control, and no candidate holds a run of English longer than a chance word. The block’s own structure works against an ordered key: under a forward alphabet the nine single digits must all become a, b or c, so every candidate opens “aba”. The ordered readings are excluded at the strength the controls allow; the unordered ones cannot be tested, and a block that is only consistent with an untestable key is not distinguishable from a doodle.

05 What it means

Ernst’s arithmetic is right, and the permutation carries the fingerprints of a hand that wrote 1 to 52 once each in a made-up order, then dressed the list with runs of zeros. The letter lines below it are a transposition so shallow that Friedman read it at sight; the number lines above are a cipher-shaped object with nothing inside. Whether the sender meant it as a hoax on the Secret Service, as Ernst suggests, or simply copied out what he thought a cipher looked like, the block cannot be read because it does not encode anything. An unordered one-time key remains possible in principle and is indistinguishable from a doodle.

What would reopen the question: the original sheet in the William F. Friedman Collection at the NSA, whose reverse carries a typed text and whose face carries the pencilled trials, or a second message from the same hand.

06 Sources