Skip to content
clickidy
🎯 ALL GAMES

READING · 25 MIN

THE CODE THAT
GOT AGENTS KILLED.

In occupied Europe, a memorised poem was the only thing standing between an SOE agent and the Gestapo. A 22-year-old cryptographer named Leo Marks decided that wasn’t good enough - and rebuilt the system from scratch.

Who was Leo Marks? 

Leo Marks (1920-2001) was a British cryptographer conscripted into the codes section of the Special Operations Executive (SOE) in January 1942 - the wartime agency Winston Churchill tasked with sabotage and resistance support across Nazi-occupied Europe. Within about a year he was effectively running SOE’s codes office, still in his early twenties. He later wrote Between Silk and Cyanide: A Codemaker’s War 1941-1945, a memoir of that work that the UK government held back from publication for decades before clearing it in 1998.

The poem code’s fatal flaw 

Before Marks arrived, agents dropped into France or the Low Countries relied on the poem code: memorise a poem, pick a handful of words from it as an encryption key, and use the letters of those words to scramble a message by transposition. No paper key to be caught carrying - which sounded clever until you saw how it broke. Agents leaned on poems they already knew, which narrowed the field of possible keys to whatever a well-read cryptanalyst could pull off a shelf. Worse, a memorised poem is not something you can burn: under interrogation, it could be dragged out of a captured agent, unlocking every message they’d ever sent under it. That second route is the one the surviving record actually documents - the official history of SOE in France found no evidence the Germans read this kind of traffic until prisoners handed over the phrase. It’s a world away from something like a basic Caesar shift, where the “key” is just a number - the poem code’s danger was that the key lived in a person’s head, and people can be broken.

Marks’s fix: keys you could burn 

Marks’s answer was the Worked Out Key, or WOK: instead of a poem in an agent’s memory, each agent carried a set of pre-arranged transposition keys printed on a small sheet of silk. Silk held up to sweat and travel and could be sewn into a lining or a seam. Each key was used once - the agent cut or tore off that section of silk after sending the message and destroyed it, so nothing survived capture that could compromise past or future traffic. Later in the war SOE pushed this further still, moving some traffic to genuine one-time pads, also printed on silk for the same reasons: nothing memorised, nothing reused, nothing left to torture out of anyone.

Why it mattered 

This wasn’t an academic cipher exercise. SOE agents were operating alone, in disguise, inside Gestapo-patrolled cities, and a broken code could roll up an entire resistance network in one sweep. Marks spent the war treating every key as a life-or-death design problem, not a puzzle - which is precisely why the field moved from “memorable” toward “disposable.” It’s the same instinct behind every serious cipher since: the strongest ones are those where the secret can be destroyed the moment it’s used.

Play the ciphers in this story

More Codes & Ciphers history →

WHAT THE RECORDS SHOW 

SOE stopped trusting the poem code because a key held in an agent's memory can be taken off the agent, and over the course of the war it moved agents onto printed keys they could destroy instead: Worked Out Keys first, then single-use keys on silk. What makes that worth explaining is that the poem code was not a lapse of judgement. It was the rule book. The standard statement of what a field cipher should be, set out by Auguste Kerckhoffs in the 1880s and still being reprinted in military manuals decades later, asked for a key that could be "communicated and remembered without the necessity of written notes". A memorised poem answers the memorability half of that requirement almost word for word. What the rule book never accounted for was a user who could be arrested.

Read that way, the shift is stranger than it looks. Moving agents onto a random key printed on silk meant deliberately breaking a published principle of good cipher practice, and doing it in the one environment where carrying paper was most likely to get you shot.

Key Takeaways

  • Kerckhoffs's third requirement for a military cipher, as reprinted in a 1916 US Army manual, asked for a key "communicated and remembered without the necessity of written notes" and readily changeable. The poem code obeyed the first clause and failed the second.
  • The same 1916 manual warned that transposition ciphers fail Kerckhoffs's first three requirements, and noted they were popular with agents anyway because they need no apparatus.
  • SOE's own training syllabus, published from The National Archives files HS 7/55 and HS 7/56, told students the key words "are of no value in themselves but act as a mnemonic", and that short messages in this system are "a prey for anagramming".
  • The catalogue description of SOE's Playfair card index records that that cipher was used until 1942, "when its weaknesses were demonstrated by Leo Marks".
  • Every workaround SOE layered on top, the double security check and the operator "fingerprint", was defeated by the same thing: the agent's own condition, not the mathematics.

Why did SOE trust a poem code at all?

Because the doctrine of the day said a good key lives in the head. Parker Hitt's Manual for the Solution of Military Ciphers, printed at Fort Leavenworth in 1916 for the US Army Service Schools, sets out Kerckhoffs's six requirements in its introduction. The third reads: "The key should be such that it could be communicated and remembered without the necessity of written notes and should be changeable at the will of the correspondents."

That requirement has two clauses, and they pull in opposite directions. A memorised poem is unbeatable on the first and awkward on the second, because changing the key means learning a new poem, which is not something you can do from an attic in Lyon.

Hitt then does something that reads very differently in hindsight. In the section headed "General Remarks on Transposition Ciphers", he writes that "the transposition cipher is not the best one for military purposes. It does not fulfill the first, second, and third of Kirckhoff's [sic] requirements as to indecipherability, safety when apparatus and method fall into the hands of the enemy, and dependability on a readily changeable key word."

That is the scorecard, and the detail in it matters. Hitt marks transposition down on the third requirement for the ready-changeability clause, not the memorability one. The poem code passed the half of the rule that people quote and failed the half they do not.

And then, in the same paragraph: "They seem to be particularly popular with secret agents and spies, presumably because special apparatus is rarely necessary in enciphering and deciphering."

That sentence was in print a quarter of a century before SOE existed.

What SOE's own training syllabus said about the poem code

The best single view of what agents were actually taught is the syllabus of lectures used at Special Training School 103 in Ontario, held at The National Archives at Kew in files HS 7/55 and HS 7/56 and reproduced in full in the published edition. Section D of that syllabus is the cipher course: D.1 codes and cyphers, D.2 Playfair, D.3 the innocent letter, D.4 double transposition. Secret inks sit next door at E.1, which is why an agent's invisible ink training and their cipher training came out of the same folder.

Lecture D.1, dated September 1943, states the governing rule under "The Need for Security": "Do not keep a written note of any code arrangements unless absolutely unavoidable."

Lecture D.4 is the poem code in its working form. On keys, it is blunt about what the poem is for: "These should be from 8 - 20 letters in length and it should be arranged that there is no identity of idea between the first and second key word, i.e. fish and chips, Tottenham Hotspur, etc. The key words are of no value in themselves but act as a mnemonic. Any series of letters would serve, as the key is derived from the jumbled order they would give alphabetically."

Under "Changing the key word", the same lecture names the source of those mnemonics: "Memorization of a poem or a given piece of text from which certain passages are chosen."

Two warnings in that lecture matter more than anything else in it. The first: "The security of double transposition messages is in direct proportion to their length, thus it is not suitable to transmit or even hide in an innocent letter short messages enciphered on this system. They are a prey for anagramming."

The second concerns traffic sent under the same pair of keys. The printed rule is awkwardly worded, but its worked example is not: "a message of 80 letters long should not be sent with one from 70 - 90 letters in length." Two messages of near-identical length in the same key can be worked on side by side, each one's partial solution testing the other's, which is why the syllabus asks students to keep their lengths apart.

Those two warnings sit awkwardly together. Short messages are dangerous. Messages of similar length under the same key are dangerous. And the syllabus's other lectures were simultaneously telling operators to keep every message as short as possible.

The Playfair card index at Kew that recorded every agent's key

The claim that a memorised key leaves nothing written down was never quite true, because headquarters had to hold the other half.

One record makes that visible, though its scope needs stating. The National Archives holds a series, HS 16, consisting of a single card index, and it is a Playfair index rather than a poem-code one. Playfair was the other memorised system SOE issued, and it is being read here as evidence of a headquarters-copy problem that both systems share, not as a poem-code record. Its catalogue description reads: "This series contains the nominal Playfair code card index showing code details for each agent or wireless operator in the field. The Playfair code (invented by one of the devisers of the telegraph, Sir Charles Wheatstone) was that used by SOE agents up to 1942, when its weaknesses were demonstrated by Leo Marks and the code was progressively replaced by more secure coding practices."

The description then says exactly what a card held: "For each agent, the index card shows the letter square to be used and the phrase it was derived from, along with the various security measures agents were to apply to their messages sent from the field."

The letter square, the phrase behind it, and the agent's security measures, on one card, filed by name. That is not a criticism of SOE, since the receiving end cannot decode without it. It is the point: a key that exists in an agent's memory also exists in a drawer in London, and the security of the traffic rested on the more fragile of those two copies. The same arithmetic applies to any memorised key, poem code included, because home station has to hold whatever the agent holds.

SOE's syllabus rated Playfair honestly in lecture D.2, calling it "a substitution cipher in itself easily susceptible of solution", and taught it mainly as something to hide inside an innocent-looking letter rather than to broadcast. It was a lesser system than the double transposition, which is exactly why the 1942 date in that catalogue entry marks a beginning rather than an end.

What a garbled message really cost

The other half of the problem was never cryptanalysis. It was noise, and Hitt had flagged that too, in the same 1916 introduction: "It requires a surprisingly long time to encipher and decipher a message, using even the simplest kind of cipher, and errors in transmission of cipher matter by wire or radio are unfortunately too common."

Lecture D.1 states it in one line under "The Need for Care": "One error may result in the message being indecipherable." A message that will not decode has to be sent again, and lecture A.20.a, dated February 1944 and titled "The W/T Operator", explains why a re-transmission was not a minor inconvenience: "The operator must be off the air as long as possible and on the air for the shortest time possible. Therefore, messages must be SHORT and CONCISE, eliminating all superfluous words."

The same lecture lists what was hunting: fixed direction-finding stations, mobile ones working "in pairs or threes" and "camouflaged as ordinary vehicles with non-metal bodies", hand-carried sets for places a car could not reach, "slow flying aircraft which cruise around over suspected area", and cutting the electricity supply "street by street in the suspected locality". Its instruction on who to protect is the coldest line in the syllabus: "Wireless sets are more easily replaced than operators."

M. R. D. Foot's official history of SOE in France, written with access to the files and published by HMSO, gives the outcome in one sentence at page 104: "In the heroic early days an operator might spend several hours a day at his set: almost all the early operators, as a direct result, were caught."

So the chain runs, link by link, and each link is separately documented in the material above: a memorised key produces a cipher that is unforgiving of a single slip; the syllabus says a slip may leave the message indecipherable; an indecipherable message has to be sent again; and the same syllabus says minutes on air are what the operator must spend least of. None of the sources used here puts a figure on how much of SOE's air time went on re-transmission, so the size of the cost is not something this account can state. Its direction is not in doubt.

Foot reproduces one real teleprint at page 107, a message from Peulevé's set in the Corrèze on 12 March 1944, relaying news of arrests in a circuit at the other end of occupied France, exactly as the deciphering staff handed it over:

TOR 1028 12TH MARCH 1944 BLUFF CHECK OMITTED TRUE CHECK OMITTED 73 SEVEN THREE STOP FOLLOWING NEWS FROM ROUEN STOP XLAUDEMALRAUX DISAPPEARED BELGIVED ARRESTED BY GESTAPO STOP RADIO OPERATOR PIERRE ARRESTES STOP IF CLETENT STILL WITH YOU DO NOT SEND HEM STOP DOFTOR ARRESTES STOP EIGHTEEN TONS ARMS REMOVED BS POLIFE STOP BELEIVE THIS DUE ARRESTATION OF A SEFTION FHEIF WHO GAVE ASRESSES ADIEU

Look at which letters went wrong. POLIFE for police, DOFTOR for doctor, SEFTION for section, and the F at the front of FHEIF for chief: C heard as F, four times. ARRESTES for arrested, twice: D heard as S. In Morse, C is dah-di-dah-dit and F is di-di-dah-dit; D is dah-di-dit and S is di-di-dit. Each of those pairs differs in one element, the first, and in each case a dash arrived as a dot. CLETENT for Clement and HEM for him show a related failure, an element simply lost: M is dah-dah against T's single dah, I is di-dit against E's single dit.

Six of the errors in that message fall into those two pairs. A third pattern sits alongside them and is not a Morse effect at all: FHEIF and BELEIVE each swap an adjacent E and I, which is what a tired hand at a keyboard does, not what a weak signal does. And several errors fit nothing. XLAUDEMALRAUX for Claude Malraux puts X where C belongs, which is a two-element difference; BS for BY is not a near miss in Morse; ASRESSES for addresses both drops a D and substitutes for the other one; BELGIVED has a letter that was never sent. That mixture is what you would expect from a text that has been through an operator, a receiving station, a teleprinter and a printing press.

One transcript is not a survey. But it shows the texture of the problem the codes office was working against, and it is not a texture of random noise. Each stage of that chain leaves its own family of errors, and a cipher whose key sat in one person's memory had no spare capacity to absorb any of them.

Why the security checks could not carry the load

Read the top line of that teleprint again: BLUFF CHECK OMITTED TRUE CHECK OMITTED. That is a real message reaching Baker Street in March 1944 with both of its identity safeguards missing. Understanding why that was not, on its own, treated as an alarm is the rest of the story.

SOE's answer to a captured operator was a deliberate mistake planted in the text. Foot describes the scheme at page 107: checks "individual to each operator", usually "a deliberate spelling mistake or series of mistakes: the seventh letter of the text wrong, or every twelfth letter replaced by the letter preceding it in the alphabet, for example."

The Germans worked it out, and SOE knew they had. So the scheme doubled: "thereafter every operator took a double security check with him, a bluff check that he could confess to the enemy if pressed hard enough and a true check to keep to himself."

Then it collided with the noise. Foot, at page 107: reception "was often so bad, or so badly jammed, or the operators' morse so unsteady, that not even an expert decoder could always tell which of the myriad mistakes were intended and which were accidental; and not all the decoders were expert." The teleprint above shows how much room there was for a deliberate error to pass unnoticed.

There was a second safeguard, and it failed for a related reason. Before leaving, operators recorded a sample transmission so that their personal keying style, their "fist", could be recognised later. Foot notes at page 109 that these styles "vary as widely as handwritings do, and are as readily recognisable", then adds the sentence that undoes it: "Unfortunately it turned out that the styles are also as readily imitable." He gives the scale in the Netherlands immediately afterwards, citing the German officer who ran the operation: "Fourteen SOE transmitters in Holland were successfully worked back to England by half-a-dozen German operators."

The operation, known as NORDPOL, is described at page 312 as a coup by which "the Abwehr staff in Holland had managed over a year before to secure almost complete control of the SOE circuits supposed by London to be operating in Dutch territory". It is worth being exact about the mechanism, because it is often loosely described: what was taken was sets, operators and codes together, through arrests. The traffic was worked back by German operators imitating captured men. It was not a cryptanalytic break. The safeguard designed to expose exactly that situation from London was the check system described above, and that is the same system Foot records at pages 107 and 108 as being unreadable in the noise and unreliable against an operator under pressure.

Every one of these safeguards has the same shape. The check depended on the agent remembering to make an error correctly under torture. The fingerprint depended on nobody being able to copy a hand. Both put the security of the traffic inside the agent, in the same place the key already was.

Was the poem code ever actually broken?

Foot is careful here, and his care is instructive. Writing in the 1960s, he noted at page 105 that "it is useless to expect any authoritative public statement on the subject, and I have made no attempt to pursue it in detail". Within that limit, on the phrase-derived keys of the middle period, he wrote: "no evidence I have seen suggests that the Germans did in fact decipher SOE's messages of this kind before they had discovered from prisoners what the phrase for a particular message or set of messages was."

That is a statement about what one historian found in the files he was shown, not a proof that no break occurred, and the honest reading is that the official history could not say. Foot was writing before the SOE archive was released. The question now lives in the records themselves, and one of them is titled for it exactly: HS 8/366, "Communications: German knowledge of agents' cyphers", dated 1944.

Even so, what Foot could document points one way. The compromises he traced did not begin with a mathematician. They began with a prisoner. A cipher whose security can be transferred from the machine to the human being is a cipher that has moved the attack to where the attacker is strongest, and no amount of agent discipline changes that.

What the one-time pad changed

Half of the idea was already public. Gilbert Vernam's US patent 1,310,719, "Secret signaling system", filed in September 1918 and granted in July 1919, describes sender and receiver holding "identical sections of tape upon which are recorded a series of code signals which are preferably selected at random". A random key, identical at both ends, was in the patent record from 1919, well before SOE was printing silk. What that specification does not require is that the key never repeats, which is the property that makes the system unbreakable rather than merely strong; that requirement is conventionally credited to Joseph Mauborgne rather than to Vernam.

SOE did not arrive at pads in one step either. The intermediate stage was the Worked Out Key, and genuine one-time pads followed it. What had not been solved by anybody was how to put a written key in a coat lining. Foot's description of the result, at page 106, is worth quoting whole because it is the operational shape rather than the theory: "the agent held a pad of silk slips, each printed with columns of random letters or figures from which any message could be enciphered or deciphered; he used the slips in the order he found them on the pad, and was supposed to tear each slip off and burn it after use. Home station held the only duplicate."

The phrase that matters is "held the only duplicate". Under the older arrangement, the key survived every message it enciphered. Under this one, the key stops existing at the moment of use, and the agent's memory is no longer an asset the enemy can seize. The memorability half of Kerckhoffs's third requirement is not satisfied. It is contradicted on purpose.

Property Memorised key Single-use printed key
Where the key lives The agent's memory, plus a record at home station A strip of silk, plus one duplicate at home station
Reuse The same source text serves many messages Each strip enciphers one message
Effect of capture Past and future traffic in that key is exposed Only the strips not yet destroyed are exposed
Cost of re-sending a garbled message The same key enciphers it again, adding traffic in a key already used A fresh strip is spent, adding no traffic to any key
Where the system fails In the agent, under interrogation In the physical destruction of the strip

Foot also records what agents complained about, which is the detail that makes the change feel real: "The only snags SOE's operators found in this arrangement were that the silk was hard to burn and that home station sometimes referred to messages a fortnight old."

Those are the complaints of a system that works. Nobody in that sentence is asking for a cipher that cannot be broken. They are asking for silk that lights.

Every safe-house habit SOE taught follows the same logic once you see it: the dead drop exists so that two people never have to be in one room, and the disposable key exists so that a person and a secret never have to be in one head. If you want the other end of the same war, where the problem was industrial rather than personal, Bletchley Park is where the machine ciphers were being read.

Frequently asked questions

Was the poem code a cipher or a code?

By SOE's own definitions it was a cipher, and the distinction was taught explicitly. Lecture D.1 of the training syllabus draws the line this way: "A code is a method of concealing a message in such a way as to make it appear innocent. A cipher is a method of converting a message into symbols which do not appear innocent, and which have no meaning to a person not possessing the key." The poem supplied key words for a double transposition, which the same syllabus calls "a straight cipher, i.e. a cipher that looks like a cipher", so despite its name the poem code sits squarely on the cipher side of SOE's own boundary.

If the key was memorised, why did headquarters keep a written index?

The series at Kew, HS 16, covers the Playfair arrangements rather than the poem code itself, but it shows the structural point that applies to both. It is a single card index spanning 1940 to 1946, and the catalogue entry describes what each card carried: the letter square an agent was to use, the phrase that square was built from, and the security measures that agent was told to apply. Headquarters cannot decode an incoming message without holding whatever the agent holds, so for any memorised system a central written record was unavoidable, and the index is the surviving example of one.

Did German cryptanalysts break SOE's ciphers?

The official history is deliberately narrow on this, and it was written before the SOE archive was released, so it should be read as a statement about the files one historian was shown rather than a verdict. M. R. D. Foot wrote that no evidence he had seen suggested the Germans deciphered messages of the phrase-key type before prisoners told them what the phrase was, while also stating plainly that he had not pursued the cipher question in detail and that no authoritative public account existed when he wrote. A file now at Kew, HS 8/366, is titled "Communications: German knowledge of agents' cyphers" and is where the question properly belongs. The large German successes he documents, including the fourteen SOE transmitters in the Netherlands worked back by about six German operators, ran on captured sets and captured people rather than on cryptanalysis.

Why did indecipherable messages matter so much?

Because the remedy for one was another transmission, and transmission time was what SOE's own training treated as the mortal risk. Its February 1944 lecture for wireless operators put the requirement as being "off the air as long as possible and on the air for the shortest time possible", against direction-finding that included fixed stations, camouflaged vans working in pairs or threes, hand-carried sets, low-flying aircraft, and cutting the power street by street. Foot records that in the early period almost all operators were caught as a direct result of long hours at the set. A cipher that failed on one mistyped letter added to that time, quite separately from whether anyone could read it.

Why silk rather than paper?

Both the durability and the disposal arguments show up in the record, and the disposal one is the sharper of the two. SOE's syllabus made destruction a standing instruction, telling students it was "essential to destroy all paper used in enciphering or deciphering messages" and warning that "quantities of paper burn very slowly, even when petrol-soaked, and ashes may be deciphered unless broken up". A key printed on cloth can be sewn into a lining, survives sweat and travel, and can be destroyed a strip at a time as it is spent. Even so, Foot records agents reporting that the silk was hard to burn, so the material solved the problem imperfectly rather than completely.

Sources