Codes and Ciphers: The Secret Math of Messages
Two different things hiding under one word, and the reason every hand-shuffled message eventually falls apart
By Daon Opus · Updated October 1, 2026
The note I read in under a minute
My daughter folded a note into a small square, handed it to me with both hands like a telegram, and asked me not to open it until she was out of the room. The note was in a code: she had shifted every letter by some amount and told me I would never work it out.
I had it in under a minute, and not because I was clever. I had it because she had used the same letter far more often than any other, and English only has one letter that behaves that way. Her cipher had hidden the alphabet and handed it straight back. That is not a failure of arithmetic. It is a fact about language, and once you see it you cannot unsee it in any secret message.
A code swaps words. A cipher swaps letters.
The two words get used interchangeably, and they should not be. A code replaces an idea with another idea: an agreed table where APPLE means MEET AT SEVEN. Nothing inside the word is scrambled. A cipher works below the word level, replacing every letter so the structure of the language survives intact underneath.
That difference is why the two break in different ways. A code is only as strong as its table, and a small table can be guessed. A cipher leaves no table to steal — which is exactly where its weakness hides.
Twenty-six letters is the entire machine
Every hand-built letter cipher rests on one small move: give the letters numbers, then move each number by a fixed amount. A becomes 1, B becomes 2, up to Z at 26. A shift is then adding the same number to every letter at once — arithmetic a child can do and an adult faster.
The only subtlety is what happens when you run off the end. Push the 24th letter along by five and you land on 29, which is not a letter. You wrap back to 3. That wrap is not a new idea — it is what happens when you count past twelve on a clock, as our article on the clock describes — except the dial has twenty-six positions. Mathematicians write it in one line: past 26, subtract 26. They call it modulo. Shifting the 22nd letter by 7 gives 29, and 29 mod 26 is 3.
That single line is all a hand cipher is. Everything built on it — Enigma, the wartime machines, the one in your pocket — is just a cleverer answer to which number goes with which letter, and when.
One shift undoes itself
Exactly one shift behaves strangely. Shift by thirteen and every letter lands on the opposite half of the alphabet: A swaps with N, B with O, C with P. Do it again. Thirteen plus thirteen is twenty-six, a whole turn of the dial, and you are back where you started.
This is the only shift that is its own undo, which is why rotating by thirteen hides spoilers on forums. It is not secure by any standard. It is just mathematically charming, which is a perfectly good reason to know it.
English has a fingerprint
Here is what breaks every letter cipher, and it has nothing to do with arithmetic. Take any long piece of English and count the letters. One is far ahead of the rest. E appears about once in every eight letters, then T, then A and O and I. At the other end, Q, X, J and Z barely show up — Z manages less than one letter in a thousand. English is not a uniform spray of letters, and that distribution barely changes.
Now shift an entire paragraph by five. Every letter changes identity — and the ranking does not move by one place. The commonest letter stays the commonest. The cipher renamed the fingerprint. It did not remove it.
So the attack takes one step: count the letters in the scrambled message, and the commonest one is very probably the commonest letter in real English. Substitute it back and the rest almost assembles itself. This is frequency analysis, it is about two hundred years old, and it needs no computer — a pencil, and the willingness to be a little boring for ten minutes.
The spaces never moved either
There is a leak even faster than counting, and it costs nothing to spot. A shift cipher changes letters, so it leaves every space exactly where it was. Look at the scrambled message and you can see the shape of the words: four letters near the start, two one-letter words in the middle, one long word at the end. That skeleton is the hidden message's skeleton. You have the outline without breaking a single letter.
This is worth sitting with, because it explains the pattern better than the cipher does. You do not actually read letters. You read patterns. A letter cipher scrambles the atoms of a message and leaves the molecule intact. It is the same mistake as rearranging the furniture in a house and expecting nobody to recognise the house.
The opposite move is no better. A transposition cipher does not replace letters, it rearranges them, leaving the frequency table untouched, so the analysis above finishes in one step instead of twenty. Two different strategies, one identical mistake: only the letters were scrambled, and a message was never made of letters to begin with.
This is not the number-systems question
Worth separating, because the two get confused constantly. This article substitutes one symbol for another while keeping the alphabet human-sized. Choosing which symbols is a different subject, and it deserves its own guide. What stays here survives any choice of alphabet: language is patterned, and hiding the letters does not touch the pattern.
Modern encryption succeeds by abandoning the scrabble entirely. It does not hide which letters you used; it removes the shortcut that made hiding them worthwhile. Our article on prime numbers covers that side.
Try it on these three
Write a short note and shift every letter by four. Then read it back with the word lengths only, blanking out the letters — can your reader guess the message from the shape alone? Next, find a long piece of English, count the letters, and see whether the commonest one really is E. Last: a friend sends you “vjg mga ku wpfgt”. The commonest letter is G, and a two-letter word sits in the middle. Work out the missing letters — then say which clue you needed.
Frequently Asked Questions
Is this how passwords and banking actually work?
No, and the gap is instructive. Everything above is what you can do with a pencil in ten minutes, which is exactly why nobody uses it. Real systems publish a rule that is easy one way and hopeless the other. Letter-shuffling has excellent teaching value and zero security value — a good description of most of mathematics.
Why does it work on long messages but not short ones?
Because it is a counting argument, and counting needs room. In a message of a dozen letters the commonest letter may simply be whichever one you happened to need. The pattern is certain; the evidence grows with length. That is the general lesson underneath the whole article — statistics need a sample, and small samples promise far more than they can deliver.
What about languages with different symbols or no spaces?
The reasoning survives, with different details. Other alphabets have their own ranking, and languages written without spaces remove one leak while adding another, because character frequencies become the analyst's handle instead. The fingerprint is not an artefact of the Latin alphabet. It is what having a patterned language means.
Is there a letter cipher that would survive this?
Not one that a person operates by hand, which is the honest answer. Make the key long enough and a single message really does tell an attacker nothing — which is why the ciphers that matter are built on arithmetic rather than shuffling. But if the key travels with the note, is reused, or a person does the work, the pattern comes back. A secret kept by a human being is a counting problem waiting to happen.
Write one secret note this week. Pick a message, a shift of your choice, and write it out shifted — then let the guesser work from the word lengths alone before they count a single letter. Send the decoded version to our free math tutor apps, or post your hardest message on Math Q&A and we will tell you whether the giveaway was a common letter, a leaked word length, or a shift that never stood a chance.