By 1586 Mary Stuart had been Elizabeth I's prisoner for eighteen years. Catholic Europe regarded her as England's rightful queen, which made her the natural figurehead for any plot against Elizabeth, and it made her correspondence the most-watched mail in the kingdom. That summer a young Catholic gentleman, Anthony Babington, wrote to Mary proposing exactly such a plot: foreign invasion, a domestic rising, Mary's rescue, and the "dispatch of the usurping Competitor" by six gentlemen of his acquaintance.
The letters travelled in and out of Chartley Hall sealed inside the bung of a beer barrel, carried by a courier named Gilbert Gifford. What neither Mary nor Babington knew was that Gifford was working for Sir Francis Walsingham, Elizabeth's principal secretary and spymaster, and every barrel stopped first at Walsingham's cipher secretary, Thomas Phelippes.
Mary did not write in plain English. She used a nomenclator: a cipher alphabet of 23 symbols standing in for letters (the Elizabethan alphabet had no separate j, v or w), a further 35 symbols standing for whole words and names, four nulls that meant nothing and existed only to confuse, and a special sign, the dowbleth, meaning "the next letter is doubled." It looked formidable. To Phelippes, a practised frequency analyst, it was an afternoon's work.
Type a message and the disc turns each letter under the pointing hand, revealing its sign on the raised inner wheel. Unlike Caesar's wheel this alphabet is scrambled, not shifted: knowing one letter tells you nothing about the others, and there are about 25,000,000,000,000,000,000,000 possible arrangements. That is the strength Mary was relying on.
Drag the disc, or click any letter on the outer ring, to turn it under the hand. Both rings turn together: in a nomenclator the pairing of letter and sign is the key itself, so it never changes.
J is written as I, V as U, and W as UU, exactly as a 16th-century secretary would. Word signs are shown in red, nulls in grey, the dowbleth in blue.
The signs above are stylised after the Babington cipher key preserved in the State Papers at The National Archives, Kew; they are drawn in the spirit of the original rather than traced from it, and the word list is a representative sample of the 35 in the real key.
Now sit where Thomas Phelippes sat. Below is an intercepted letter in Mary's signs. You do not have the key, but you have something better: the knowledge that English is not random. E is the most common letter, then T, A, O; THE is the most common word. Count the signs, match the pattern, and the key falls out. Click a sign, then choose the letter you think it stands for.
Once Phelippes could read Mary's hand he could also write in it. Before the letter was resealed and sent on to Babington, Walsingham had a postscript added in Mary's own cipher, asking for the one thing the plot had not yet put on paper:
Babington never answered it, but it no longer mattered. Mary's own reply of 17 July 1586, in which she approved the plot, was read aloud at her trial at Fotheringhay that October. She was beheaded on 8 February 1587.
The two columns will not match perfectly, because a short letter is a small sample, but the top of each list lines up often enough to break in. Once E, T and A are placed, look for the three-sign group that recurs most: it is almost certainly THE. Nulls are the signs that sit in odd positions and refuse to fit any pattern.
Mary wrote candidly because she trusted the cipher. Plaintext would have made her cautious; false confidence made her explicit. Security theatre creates risk it does not remove.
A scrambled alphabet has ~4 × 1023 keys, yet frequency analysis ignores the key space entirely and attacks the structure of the message. Modern ciphers are judged by resistance to analysis, not by how many keys exist.
The cipher was never the weakest link; the courier was. Gifford was a trusted insider working for the adversary. Encryption cannot protect a message from the person you hand it to.
Phelippes did not just read the letter, he altered it and Babington could not tell. Today that is why we pair encryption with authentication, as AEAD modes do.
Mary's security depended on the enemy never seeing the key table. Two centuries later Kerckhoffs would state the rule properly: assume the enemy knows the system and rely only on the key. Read the principle.
Break a scrambled alphabet against the clock in the Substitution Cipher Challenge, or go back to where it began with the Caesar Cipher Wheel.