Skip to content
HN On Hacker News ↗

The Farnese letter

▲ 47 points • 6 comments • by grigolin • 3w ago • HN discussion ↗

Pangram verdict · v3.3

We believe that this text is a mix of AI and human-written content.

43 %

AI likelihood · overall

Mixed
62% human-written 38% AI-generated
SEGMENTS · HUMAN 3 of 10
SEGMENTS · AI 3 of 10
WORD COUNT 1,578
PEAK AI % 81% · §8
Analyzed
Sep 19
backend: pangram/v3.3
Segments scanned
10 windows
avg 158 words each
Distribution
62 / 38%
human / AI fraction
Verdict
Mixed
Pangram v3.3

Article text · 1,578 words · 10 segments analyzed

Human AI-generated
§1 Human · 15%

In April 1542 a letter left Rome for the court of Charles V in Spain. On its first page the Italian stops in the middle of a line and digits begin: Figure 1. The opening of the cipher, f. 70r. Archivio Apostolico Vaticano (AAV), Segr. Stato, Spagna 1A, photograph supplied through DECODE record 92. Detail enlarged from the photograph. Read with the key recovered below, the first ten digits group like this: 73 4 57 4 9 03 5 d o p o · l a Dopo la, "after the". The 9 stands for nothing: it is a null. The difficulty is deciding where each code ends. 73 is d, but 7 3 is also two letters, n m.

§2 AI · 74%

Even with the key, a run of digits can be read more than one way. Two problems follow: finding the key without knowing where one code ends and the next begins, and then, once a key exists, telling the writer's words from a plausible guess.

§3 Human · 16%

The letter The sender was Cardinal Alessandro Farnese, grandson of Paul III and, at twenty-one, head of the papal secretariat. The recipient was Giovanni Poggio, bishop of Tropea and nuncio, the Pope's ambassador, at the Emperor's court.1 The letter opens in ordinary Italian: Poggio will have heard by word of mouth from Giovanni Ricci da Montepulciano about la materia della pace, the peace between the Emperor and France, so Farnese will not repeat it. Montepulciano had returned from Spain in February with the Emperor's terms and had left Rome for Spain again in late March.2 Montepulciano's name is also on a cipher key. Aloys Meister's 1906 study of papal cryptography prints, among the old ciphers of the papal secretariat, a key headed Cifra ultima con Mons. Poggio mandata per il Montepulciano: the latest cipher with Poggio, sent by Montepulciano. Meister dates it 1538–42.3 The letter fills eight pages on four leaves, 70r to 73v in the archive's numbering: r for the front of a leaf, v for the back. Page 70r is cleartext for most of its length. Then the digits take over in the middle of a line and fill the whole of pages 70v to 72r. On 72v they surround a cleartext passage about church business and news from Ancona, "fresh and from a good source". The cipher ends on 73r, and the rest of that page is clear. Page 73v is clear and dated Da Roma alli X[?] di Aprile 1542: the day is a Roman numeral beginning with X whose remaining strokes lie under a flourish, still unread. What is in clear is the frame; the instructions are in cipher.4 Figure 2. Ff. 70r and 70v. AAV, Segr. Stato, Spagna 1A, through DECODE record 92, public previews. The change from prose to digits comes near the foot of 70r. The cipher continues across the next page. Ludwig Cardauns cited this volume in his 1912 collection of the nuncios' reports, but his selected correspondence does not include this letter.5 In July 2019 George Lasry set the text as Part 5 of the Vatican Challenge on MysteryTwister, a site of cipher puzzles: key unknown, plaintext unknown, language probably Italian. In their study, published online in 2020, Lasry, Beáta Megyesi, and Nils Kopal still listed the Spagna 1A material as unsolved. Their digit-frequency analysis placed it in a separate cluster. They compared another part of the collection, IA-1, with Meister's Poggio key, without success, and thought this letter, IA-2, used a different key.6 On 16 September 2026, the challenge page still displayed zero solves.7 The search began with a public transcription, now distributed with the DECODE record and the challenge. Its header credits EHum, dates the transcription 9 January 2016, and records about six and a half hours' work on the eight pages. The transcription contains 6,577 cipher digit positions: 44 recorded as ?, unreadable, and 207 with a mark above them, mostly dots. There is no consistent word division. The full ciphertext is reproduced as text, with its page and line breaks. The counts and searches below used this public transcription. I checked it against the larger photographs later.8 What the counts show In the public transcription, digit 7 makes up 17.5 percent of the text and 1 only 3.1. A few pairs are far more common than chance: 80 occurs 349 times, 57 317, 27 263, 03 258, 73 220. Doubled digits are nearly absent: 00 six times, where independent digits would give about 117; 11 three times; 44 twice. And the digits alternate between two groups, 4 5 6 8 and 0 1 2 7 9, with 3 belonging to neither: after 73, for instance, the next digit is 6, 8, 4 or 5 in 93 percent of cases.9 Figure 3. How often each digit follows each other digit in the public transcription. The five pairs in bold turned out to be the codes for t, p, c, l, and d. The pale diagonal is the avoidance of doubles. Author's computation from EHum's 2016 transcription. That looks like consonants and vowels taking turns.

§4 Mixed · 60%

But it does not decide whether 73 is one code or two frequent neighbors, and no fixed rule of cutting, such as pairs at even positions or certain digits always beginning a pair, gave a consistent result. The papal ciphers of the 1540s used several designs. In some, one digit stands for several letters and the reader chooses. In some, pairs spell syllables.

§5 Human · 26%

One 1545 key writes the vowels as pairs and the consonants as single digits.10 I tried these designs with earlier versions of the search, without obtaining readable Italian.11 The design that fitted was a simple one also printed in Meister's collection: every letter has one code, of one or two digits, and the reader tells them apart by context. Figure 4. A key of that design: Meister no. 7, for Alessandro Vitelli, dated by Meister to 1546. Single digits for some letters, pairs for the rest, one null, a few words. Aloys Meister, Die Geheimschrift (1906), p. 179; Getty Research Institute copy, digitized by Internet Archive. Cropped from the printed edition. The search I searched for the key and the code boundaries together. An outer search changed the assignments of letters to codes.

§6 Mixed · 67%

For each candidate key, an inner decoder searched for a good way to divide the digits and read them. The outer search could then compare keys by how well their readings scored.12 To judge those readings, I trained a character model that estimates the probability of each letter from the four before it: a five-gram model. It trained on about 4.9 million letters. Most came from Machiavelli, Castiglione, and Vasari on Wikisource.

§7 Mixed · 45%

About 720,000 came from Italian-looking lines extracted from the OCR of Cardauns's Nuntiaturberichte aus Deutschland I.7, which includes correspondence of the Farnese secretariat from 1541–44.

§8 AI · 81%

That volume does not print this letter.13 I lower-cased the text, stripped accents, folded v into u, deleted h, and collapsed doubled letters. These were guesses about the clerk's habits, and they turned out to match: the letter writes tute, esendo, facia; its key has one code for u and v and none for h. A letter sequence absent from the corpus still needed a chance. The model blended the counts for a four-letter context with estimates from shorter contexts, down to individual letter frequencies. This smoothing let it score unfamiliar names and damaged words without ruling them out altogether.14 Reading a candidate key The decoder walks the digits from left to right.

§9 Mixed · 51%

Under the key eventually recovered, the opening has these two possible paths, among others: Digits 7 3 4 5 7 4 One path 73 4 57 4 d o p o Another 7 3 4 57 4 n m o p o The first path consumes 73 at once and emits d; the second consumes 7 and 3 separately and emits n m.

§10 AI · 78%

Each emitted letter adds its base-10 log probability to the path's score. The letters that follow can favor one path over the other, so the decoder keeps several partial readings alive. Each partial reading is a state, which records the position in the digits, the last four emitted symbols, and the score so far. If two paths reach the same position with the same language-model context, their possible continuations are identical: only the better-scoring path needs to survive. Among different contexts, the decoder keeps the eight best at each position. This is a beam search. It is an approximation: a path discarded early cannot recover when later letters would have made it convincing. In the successful searches, I set aside the digits with a dot or comma above them and cut the text at those places and at unreadable digits. Each fragment began with a fresh language-model context. The key received the sum of its best surviving fragment scores, including penalties for nulls and digits it could not decode. The dotted codes would come back once the letters were known.15 Changing the key The outer search began with random assignments, favoring codes that occurred more often. It could swap two assignments, move one to an unused code, or turn off an optional unit such as a null. It accepted any improvement. It could also accept a worse key, with a chance that fell as the run went on. This is simulated annealing. Accepting worse moves lets the search escape a key that beats its immediate neighbors but is still wrong. I repeated the search from fresh random keys.