Competitor Ciphers & Challenges
The Mystery Of The Missing Silver › Forums › The Mystery Of The Missing Silver › Competitor Ciphers & Challenges
- This topic has 21 replies, 4 voices, and was last updated 8 hours, 2 minutes ago by upsidedown.
-
AuthorPosts
-
-
24th September 2026 at 10:30 am #150018Puzzling_PelicanParticipant
A place to post all the ciphers, cryptography puzzles and challenges made by competitors (and alumni!) for each other, all in one place throughout this year.
If you have put together any cipher-related problems (whether using an existing cipher or one you came up with yourself) that you would like to see other competitors try to break, post them in this thread.A few quick rules, just to help out the moderation team:
- Give each challenge a title. If you can’t think of one, use “username-<num>”. This makes it easier to refer back to individual challenges.
- Post both the challenge and its solution. When posting a challenge, split it into 2 parts: the challenge (what you want the forum to see) and the solution (so Harry, Jodie or the Elves can check how difficult the challenge is before releasing it). These should be 2 separate posts clearly labelled “<title>” and “<title> – Solution”. Only the challenge will be released initially, the solution will remain unpublished.
- Set a release date for the solution (optional). If you want the solution to be released after a particular date, write “Release date: dd/mm/yyyy” immediately after the title line in the solution post. The moderation team should be able to schedule it to be automatically published.
- Submit a proof when solving a challenge. To prove that you have solved someone’s challenge without simply posting the plaintext, [EDIT BY HARRY: the original post said “run the Python script below with your username and the plaintext. This generates a cryptographic hash which proves you know the correct plaintext without revealing it. Post this hash as your solution.” We prefer not to post user generated code here on the forum, but will post our own Puzzle Proof app on the cipher tools page as soon as we can. In the meantime enjoy the puzzles below!]
- Reply to the original challenge once solved. Once you have solved someone’s challenge, reply to their original post with the hash you generated. The creator can verify your solution by running the same script with your username and their intended plaintext and checking that the hashes match.
[EDIT by HARRY: I hope you don’t mind, but I have removed the clever script you posted here on the basis that we prefer to be in control of things like that. Instead we will post our own “Puzzle proof” app on the cipher tools page soon.]
Good luck and happy puzzle making!
Puzzling Pelican- This topic was modified 2 weeks ago by Harry. Reason: To remove python script and explain why!
-
24th September 2026 at 10:50 am #150038Puzzling_PelicanParticipant
Upsidedown – Bombe
To start this thread off, I wanted to re-highlight a challenge made by upsidedown last year, designed around the Turing–Welchman Bombe.
All credit goes to upsidedown for this challenge, thank you!
This challenge was originally posted in Harry’s Christmas Miscellany. However, very few people have solved it, and it appears no solutions were posted on the forums last year (mine didn’t get through the moderation pipeline before the forums closed). I think that such a well put together challenge deserves more attention from competitors.Alumni, this will be fun for you too.
https://www.cipherchallenge.org/wp-content/uploads/2025/12/CC2025-the-bombe.pdf
https://www.cipherchallenge.org/wp-content/uploads/2025/12/CC2025-the-bombe.pdf-
24th September 2026 at 5:45 pm #150751Puzzling_PelicanParticipant
My solutions || Puzzling_Pelican (upsidedown’s proof method):
4. 3e6dc4df4a31c55f8967cd5754a61472
5. a107333c5783fa12ef299ea0c021df00
6. 99bd5cad526338b5c95d56acef18ae11
7. ???? Please send clues (rot 13’d), I have been waiting half a year with 26 intermediate candidates and no progress on the 2nd partP.S. “Instead we will post our own “Puzzle proof” app on the cipher tools page soon”: That would be amazing, thank you!
-
26th September 2026 at 11:37 am #151104upsidedownParticipant
I agree with the plugboard pairings in your solutions, but I was expecting different Bombe indicators for 5 & 6. Not sure if it’s my mistake or yours, and I don’t have time at the moment to work it out. If you add AAR to your indicator for 5, and add ZZO to your indicator for 6, you get the values I was expecting. Possibly something to do with working backwards to find indicators at the start of the message? Or a problem with the step function?
7 is possible to solve, but it is rather difficult without knowing what the second cipher is. I’ve prepared a few hints (all encrypted with the same settings I used for upsidedown-2025-6). The plaintext comes from the same source as the other plaintexts.
upsidedown-2025-7 Hint 1: PSDA DCST VUHZ BPRU PKOG AFJH YVHE SCZE WVNI BTLF HLCG WAGZ PNGA TLCB JGMQ TMUN HWXI ZWWU XHEQ YZZN YWFE LXEW UWUY RQTF OUUZ NWAU TCMQ NPUI UMSL GW
- This reply was modified 1 week, 5 days ago by Harry.
-
26th September 2026 at 6:15 pm #152107Puzzling_PelicanParticipant
Thank you for the clue. As for the indicator mismatch, I think it came from me forgetting to combine rings and indicators in my proofs (subtracting my rings is the same as adding those differences).
-
26th September 2026 at 6:16 pm #152162Puzzling_PelicanParticipant
I would argue that there is a 3rd cipher.
The clue helped a lot, I do not think I would have solved it without.
Thank you for this challenge, I truly enjoyed it.
Puzzling_Pelican || Plaintext without any spaces or punctuation:
fa1361a0e38d9abf37157875dc082689 -
27th September 2026 at 10:32 am #152203upsidedownParticipant
Excellent, well done. Glad you enjoyed it 🙂
Yes, a third cipher is a reasonable interpretation; the 2nd and 3rd stages share a key and are ultimately quite similar, which is why I have grouped them.
-
28th September 2026 at 8:53 pm #152653Puzzling_PelicanParticipant
@upsidedown Just for testing the proof, here is part 7 (no spaces but all symbols, note the en-dash in the title)
NCC-PROOF-v1:b1cf087304633f345818d95c07e5923bafd28a5b3fd4eb77dc5146b1e60a15b4 -
29th September 2026 at 11:05 am #153323upsidedownParticipant
@Puzzling_Pelican Yep, I can reproduce your proof. For avoidance of doubt the challenge identifier used was “Upsidedown – Bombe”
Harry: further to my other comments, maybe replacing confusable characters like em-dash & en-dash to a hyphen would be helpful? Also curly quotes to straight quotes.
-
-
24th September 2026 at 3:07 pm #150530upsidedownParticipant
@Puzzling_Pelican thanks for the kind words.
I’m interested in making my Bombe guide accessible to a wide audience, so readers: please tell me if you find any errors, or more importantly anything that’s confusing or unclear. Should you have any questions, I’m very happy to help. And I can provide hints for the included challenges on request.
If anyone is interested in learning how Alan Turing and Gordon Welchman cracked Enigma, and has some familiarity with a programming language, give my guide a go!
I have an updated version that fixes an error (in the last paragraph of page 23, “n – 1” should say “n – 2”) and a few typos which may be published soon on the resources page.
-
25th September 2026 at 12:24 pm #151366Robb27Participant
@Puzzling_Pelican & @upsidedown.
Hi both! I can’t believe I missed this last year. I was busy with work, so if it was within the Christmas Miscellany, that might be the reason. I’ve downloaded the pdf and will enjoy working though it. -
27th September 2026 at 10:32 am #152206upsidedownParticipant
@Robb27 Hi, nice to see you again 🙂 Hope you like it!
-
29th September 2026 at 5:13 pm #153493Robb27Participant
I have completed up to and including Scrambler … nice to see I get a mention [Edited by Harry to avoid data leak ;-)!] 😉
- This reply was modified 1 week, 2 days ago by Harry.
-
6th October 2026 at 6:07 pm #158580Robb27Participant
@upsidedown Challenge: upsidedown-2025-4
To check I am good to this point I have the following for challenge upsidedown-2025-4Your MD5 method:
Using Robb27
Scrambler at the offset mentioned and resulting Plugboard pairs in the format described per your pdf
1a7f2b4cae1a3eca6eb06c3f2d05c8b6NCC SHA-256 method:
Using Robb27
Plugboard pairs entered to the “Puzzle answer” input as letter pairings in the same order as above separated by a space, no commas or double speech marks.
PROOFv1:581054d4e5ea9ef92df3499164bcc80e241ec56916cf0d579dc5dbbcb5cca3af -
7th October 2026 at 12:03 pm #159012Robb27Participant
@upsidedown Challenge: upsidedown-2025-5
I believe I have the right plugboard settings. I can generate the same MD5 hash that @Puzzling _Pelican posted a107333c5783fa12ef299ea0c021df00.
Using the NCC SHA-256 proof tool with just the plugboard settings I get “PROOFv1:e745a32b93ae1f697cfff1eb96a35f50ea271920099135125c8544f7906efdb4” which should allow you to verify.
I think the issue discussed with @Puzzling _Pelican regarding the indicators stems from the criteria “The middle rotor didn’t turn”. With this restriction the rings and indicators are not uniquely identifiable, each of the 17,756 different settings will generate the same correct plugboard output (at least that is what I am seeing). In the pdf instructions, you use the indicator as part of the MD5 hash, so it is not surprising that the plugboard can be correct, but the MD5 hash is wrong.
I guess for the next challenge, where the middle rotors turn, then this wont be an issue? I’ll soon find out!
-
7th October 2026 at 4:47 pm #159313Robb27Participant
@upsidedown Challenge: upsidedown-2025-6
Again, I believe I have the right plugboard settings. I can generate the same MD5 hash that @Puzzling _Pelican posted 99bd5cad526338b5c95d56acef18ae11.
Using my username and the same indicator setting as P_P I get:
MD5 5b3f0810ad7dcc3d7eb9467f07cc53fd.
NCC SHA-256 PROOFv1:b742c9aff08d80f6f9595c9615b07e0a2154b6aebaa4a700a606478af26a75e5I have a BOMBE setting returned from my program using the method you describe. If I use this, instead of the same setting as P_P, along with the plugboard, the MD5 I get is 75cc0728fad74469b8f7667316c1829a. Would this be what you were expecting? If not, I may have misunderstood the BOMBE instruction.
-
8th October 2026 at 4:46 pm #160840upsidedownParticipant
@Robb27 I agree with your proofs for upsidedown-2025-4 & 6, and the plugboard proof you posted for 5. For 75cc0728fad74469b8f7667316c1829a, what I was expecting was that value plus ZZA (so, first two indicator letters go back one letter).
I’m not sure I follow what you’re saying about rings. This shouldn’t affect the Bombe indicators (i.e. the indicators you’d see on the Bombe drums for the first letter in the message when the Bombe stops) because within the context of a Bombe run the rings are always assumed to be zero (and it doesn’t matter what the rings are because the middle rotor doesn’t turn).
I will see if I can figure out what’s going on here; it is looking like my mistake given that you and @Puzzling_Pelican reproduced identical indicators.
The code I run to get the indicators I expect for upsidedown-2025-5 is just:
menu = Menu("icanfeel...", "GSJSEDXBP...") Bombe(menu, ("I", "II", "III"), "B").run()and my Bombe implementation just prints what I call the “Bombe indicators” when it finds the stop. My Bombe.run() method looks roughly like this:
def run(self): for pos in range(26**3): grund = decode_grund(pos) if this is a valid stop: print("".join(alphabet[g] for g in grund)) def decode_grund(pos): return [pos // 676, (pos // 26) % 26, pos % 26] # This function gets the scrambler permutation output when 'letter' is input # at 'offset' in the menu/crib. def scrambler(self, letter, offset): # Since we assume that no middle rotor turnover # occurs, the top two rotors should be kept the # same pos = 26 * (self.pos // 26) + (self.pos + offset) % 26 return self.lookup.get(pos, letter)Does this look roughly equivalent to what you’ve written? Particularly the ‘pos = 26 * (self.pos // 26) + (self.pos + offset) % 26’ line – that’s implementing the Bombe stepping which differs from regular stepping.
-
-
28th September 2026 at 8:56 am #152622harryKeymaster
@Puzzling_Pelican and @upsidedown, if you email me at cipher@soton.ac.uk I can send you a link to test our new puzzle proof tool as promised. Thank you, Harry
- This reply was modified 1 week, 3 days ago by Harry.
- This reply was modified 1 week, 3 days ago by Harry.
-
30th September 2026 at 4:21 pm #154667harryKeymaster
As promised, we have built a puzzle proof tool so that your fellow competitors can establish that they solved one of your challenges without having to publish the proof. It can be found on the cipher tools page. It would be great if one of our alumni could write up a short explainer – we have a news item about this tomorrow, but I am sure you can do better than that. One of the neat features is that the calculations are all done in your browsers, so we don’t ever have to see or store your solutions!
Harry
-
3rd October 2026 at 9:44 pm #156958upsidedownParticipant
upsidedown-2026-1: Puzzle Proof Puzzle?
In the recent news post, I included the following proof:
PROOFv1:e88c1923b4cf0a46f856a0afe9814b8051ebd392b0970b8a6f623728ddbc8dc2
To generate it, I used my forum name, the challenge id upsidedown-2026-1, and a two-word phrase. What was the phrase? Prove your solve using a proof of your own.
-
-
AuthorPosts
- You must be logged in to reply to this topic.