de Deutsch en English fr Français es Español tr Türkçe ja 日本語 zh 中文 ar العربية ru Русский pt Português
Enigma Maschine
Version 1.8 · Shareware

Encryption of the
next generation

Three cryptographic protection layers. No cloud. No server. Fully offline. Your messages belong only to you.

2768
Possible keys
3
Protection layers
0
Servers / Cloud
10
Languages
History

From the broken machine to unbreakable encryption

The original Enigma machine, developed in the 1920s, was considered the most secure communication system of its time. The Wehrmacht used it millions of times in World War II – convinced the encryption was impenetrable. They were wrong.

The three weaknesses
01
No self-encryption: The Enigma could never encode a letter as itself – A never became A. This apparent strength became a weakness: attackers could exclude certain letter pairs.
02
Cribs – predictable phrases: Operators started every day with standard phrases like "Weather for..." or "Nothing to report". These known plaintexts enabled Turing's systematic attack.
03
Human error: Operators used weak key settings, repeated daily keys and violated security procedures. The technology was secure – the procedure was not.
ROTORCRYPT X — The answer to all three weaknesses

RotorCrypt X fundamentally eliminates all three historical weaknesses. Every configuration – rotors, plugboard, reflector, positions – is cryptographically generated at random for each individual message. No opening phrases, no repetitions, no exploitable patterns. The Unicode character space with 65,536 characters makes combinatorial attacks 10²¹² times harder than the 26-letter Enigma. AES-256-GCM as a second layer protects completely even if the Enigma layer were ever attackable. HKDF-SHA3-256 rotates keys after every message – even a compromised session key reveals nothing about past or future messages.

1923
Original Enigma

26 letters · 3–5 rotors · Mechanical · Broken 1941

10²¹²
Times harder

65,536 instead of 26 characters increases the combinatorial attack space by 10²¹²

2026
RotorCrypt X

65,536 chars · 1–50 rotors · Cryptographic · Quantum-resistant

History & Security

From Bletchley Park to RotorCrypt X – why Enigma failed

Arthur Scherbius (1878–1929) publicly presented the Enigma in 1923 öffentlich vor. The name comes from Greek: „Rätsel". The goal – making messages readable only by the recipient – sounds familiar. The Wehrmacht used it millions of times from 1926 onwards. It was cracked. RotorCrypt X was built from those failures.

Timeline of Decryption
1923
Arthur Scherbius presents the Enigma

26 letters, rotating rotors, mechanical-electrical encryption. Initially rejected by the military, adopted by the German Navy from 1926. Scherbius did not live to see its success – he died in 1929 in an accident with his horse-drawn carriage.

1931
Hans-Thilo Schmidt – the first betrayal

The German cipher bureau employee handed secret documents to French intelligence: an operating manual and key material. The French passed the information on to British and Polish services.

1932
Marian Rejewski – the mathematical breakthrough

At the Polish Biuro Szyfrów (Cipher Bureau), Rejewski reconstructed the internal logic of Enigma through mathematical analysis – without ever having seen the machine. Together with Jerzy Różycki and Henryk Zygalski, he laid the groundwork for everything that followed.

1934
Cyclometer & Zygalski Sheets

The Poles developed the Cyclometer for systematic key determination. Zygalski invented perforated paper sheets that made certain code properties visible when overlaid. When the Wehrmacht started changing keys daily from 1936, new methods were needed.

1938
Bomba kryptologiczna

The world's first electromechanical decryption machine. It systematically tested possible keys – a revolutionary approach. But when the Germans introduced additional rotors, the Poles reached the limits of their resources.

1939
Knowledge transfer at Pyry

Shortly before the war began, representatives of Poland, Britain and France met south of Warsaw. The Poles handed over machines, methods and all their findings. Without this step, Bletchley Park would have been impossible.

1940
Alan Turing & Gordon Welchman – the British Bombe

As part of Operation Ultra, top secret at Bletchley Park under the codename Government Code and Cypher School, Turing and Welchman developed a far more powerful version of the Polish Bomba. The Bombe could not decrypt messages directly – but it drastically reduced possible keys. Women played a significant role: Margaret Rock, Mavis Lever and others. Dilly Knox also contributed to the analysis.

1941–44
Victory in the Atlantic & on D-Day

The Allies read German radio messages almost in real time. U-boat attacks were intercepted, convoys warned. On 6 June 1944, the Normandy landings directly benefited from deciphered troop movements and orders. Historians estimate: Ultra shortened the war by at least one year.

1970er
Secret revealed

Ultra remained strictly secret for decades – the methods used were not to become known. Only from the 1970s did the public learn what really happened at Bletchley Park.

Why Enigma failed
01
No letter could encrypt itself: An A was never ciphered as A. This flaw in the reflector gave Turing the mathematical lever for the Bombe.
02
Human errors & phrases: Operators began each day with standard texts like „Wetter für..." oder „Keine besonderen Vorkommnisse" and used weak keys. These known plaintexts made the attack possible.
03
Only one protection layer: Enigma had no second independent encryption layer, no key rotation, no authentication. Knowing the rotor position meant knowing everything.
Why RotorCrypt X is unbreakable

RotorCrypt X combines three completely independent cryptographic protection layers. Each one alone would suffice – together they cannot be overcome by any known method.

Layer 01 – Rotor layer (modernised)
Up to 50 rotors, 65,536 Unicode characters instead of 26 letters. The key space is 10²¹² times larger than the original Enigma. Self-encryption – Turing's attack point – technically still exists, but is irrelevant: with 65,536 characters there are no more predictable letter pairs.
Layer 02 – AES-256-GCM
Military standard. Even if the rotor layer were weakened by an unknown attack: AES-256 stands as a second completely independent wall. The strongest known quantum attack (Grover algorithm) reduces AES-256 to effectively 128 bits – still unassailable for millions of years.
Layer 03 – HKDF-SHA3-256 & Perfect Forward Secrecy
Fresh keys are derived for every message. Enigma had no key rotation – a compromised daily key endangered all messages of the day. With RotorCrypt X, even if a single key is compromised, every other message remains protected.
Supercomputer
10²¹³
years for brute-force
Quantum computer
10¹⁰⁷
years with Grover attack
Universe
1,4×10¹⁰
years old (reference)
Key space
2⁷⁶⁸
possible keys
Enigma advantage
10²¹²×
larger attack space
Features

Six layers. Impenetrable security.

01
Enigma Machine

Unicode-capable with up to 50 rotors, 65,536 characters, fully randomized plugboards, reflectors and rotor positions – every message unique.

Unicode · 1–50 Rotors · 65,536 Chars
02
AES-256-GCM

The Enigma ciphertext is encrypted with AES-256 in Galois/Counter Mode. GCM provides encryption and authentication – any tampering is detected and rejected.

AES-256-GCM · Authenticated Encryption
03
HKDF-SHA3-256

Fresh keys are derived for every message using HKDF with SHA3-256. Keys rotate after each message (Perfect Forward Secrecy).

HKDF · SHA3-256 · Perfect Forward Secrecy
04
Argon2id

Password hardening with 64 MB RAM, 3 iterations, 4 threads. A 12-character password means mathematically over 1,000 years of brute-force time. GPU and ASIC attacks are structurally defeated.

Argon2id · 64 MB · 3 Iter. · 4 Threads
05
Split Key

Each side generates a unique 256-bit random ID on connection. Only when both IDs combine does the shared key emerge — combined with ECDH (Curve25519). Neither side alone can compute it.

Split-Key · ECDH · Curve25519
06
Forward Secrecy²

After key exchange, the contact ID is irreversibly deleted. Even if all files and sourcecode are later obtained — past messages remain permanently protected.

Forward Secrecy · No static keys
🔒
Replay Protection

Each message decryptable only once. Replay attempts detected and blocked immediately.

🛡️
Bootstrap Protection

Circular HMAC dependency – mathematically irresolvable.

📴
Fully offline

No internet. No servers. No cloud. No account.

🔑
Local keys

Key files never leave your device.

🌐
Unicode support

All 65,536 Unicode characters. All 8 languages.

📱
Desktop & Mobile

Identical key file format on Windows and Android.

Quantum Security

Secure against
quantum computers

Grover's algorithm effectively halves the key length. With 768 bits, 384 effective bits remain after quantum attack – 10107 times the age of the universe.

MethodTime requiredResult
Brute-Force (10¹⁸/sec)10²¹³ years✔ Secure
Grover's algorithm10¹⁰⁷ years✔ Quantum-resistant
Age of the universe1,4 × 10¹⁰ yearsReference
DES 56-bit
AES-128
AES-256
RotorCrypt X 768-bit
How it works

Simple to use.
Uncompromisingly secure.

1
Create contact

Create a contact, key file is created automatically.

2
Exchange key file

Exchange securely with partner once.

3
Handshake

Green banner: full security active.

4
Communicate

Encrypt, send, done.

About the program

Your messages belong to you.

RotorCrypt X is free encryption software that protects your communication with a combination of historical Enigma logic and state-of-the-art cryptography. Developed for people who take privacy seriously.

"Secure. Free. Your control."
✔ Keys only on your device
✔ Fully offline
✔ No provider, no access
✔ Portable, also USB drive
Target groups

Journalists · Activists · Lawyers · Doctors · Entrepreneurs · Politicians · Whistleblowers · IT professionals · Private individuals

Other solutions vs. RotorCrypt X
Other solutionsRotorCrypt X
✗ Keys on foreign servers✔ Keys only on your device
✗ Cloud required✔ Fully offline
✗ Provider can access data✔ No provider, no access
✗ Internet dependent✔ Portable, also USB drive
Download & Full Version

Try for free.
Communicate securely.

In 1943, Alan Turing's Bombe machine cracked the 3-rotor Enigma — in hours.
RotorCrypt X with 50 rotors would take longer than the universe is old, even with today's technology.

Layer 1
Rotor Logic
Up to 50 rotors. Each multiplies the key space. 3 rotors were cracked in 1943 — 50 were not.
Layer 2
AES-256-GCM
Military standard. Authenticated encryption. Tampering is detected and rejected.
Layer 3
HKDF-SHA3-256
Quantum-resistant key derivation. Keccak algorithm. No known attack exists.
Shareware — Free
3 Rotors
✗  Like the original Enigma 1943
✗  Cracked by Alan Turing's Bombe
✓  AES-256-GCM + HKDF-SHA3-256
✓  Much more secure than 1943 — but not maximum
⬇  Windows Version Download ⬇  Android Version Download
RECOMMENDED
Full Version
50 Rotors
✓  2768 possible key combinations
✓  Longer than the universe to crack
✓  AES-256-GCM + HKDF-SHA3-256
✓  Windows & Android · Lifetime license
Buy Full Version via PayPal

License key by e-mail · No subscription trap

FAQ

Frequently asked questions

Can the NSA read my messages?

No — and for three reasons that together form a wall even state-level actors cannot penetrate.

First: there is nothing to request. No server, no cloud, no database. Whoever issues a court order — there is simply no entity that could hand over any data.

Second: the mathematics do not allow it. The key space contains more combinations than there are atoms in the observable universe — and that is not a metaphor. Even a quantum computer halving the search space via Grover's algorithm faces a computational task that is unsolvable with any physically conceivable means. On top of that: quantum attacks require long-lived keys sitting in memory as a target — those simply do not exist in RotorCrypt X, because they are destroyed immediately after the connection is established.

Third: even with full device access there is nothing to extract. If someone had access to all encrypted files, the device, and the entire source code — past messages would still be gone forever. The key IDs required for decryption were irreversibly deleted the moment the connection was set up. The mathematical path cannot be reconstructed retroactively.

What if my device is stolen?

Nothing. A thief sees only encrypted garbage — and gets no further. The password is hardened with a technique that brings even GPU clusters to their knees: millions of attempts per second are still useless. After 10 wrong attempts the software automatically wipes all keys to military standard — the device becomes permanently unusable for the attacker.

If the device has not been used for 5 minutes, all keys have already vanished from RAM. No contact name, no plain text, no message is visible on the device — everything is encrypted with no recognizable pattern.

Even if someone had access to all files and the entire source code of the software: past messages cannot be mathematically reconstructed, because the key IDs were irreversibly deleted after the connection was established.

How do I exchange the key with my contact?

No USB stick needed. Both sides open the app and each generate a one-time random ID. These IDs can be exchanged over any channel — even a messenger or email is sufficient, since the ID alone is useless.

The app derives a shared key from these two IDs that neither side alone knows or can pre-compute. The software then deletes the IDs irreversibly — past messages remain protected even if someone later gains access to the device.

Is the algorithm transparent?

Fully documented and mathematically verifiable. All security mechanisms are described in the technical documents.

Desktop and Mobile together?

Yes. Identical key file format (13,600 bytes). PC-encrypted → Android-decrypted – and vice versa.

Shareware vs. Full version – what's the difference?

The shareware version includes all core functions and is free. However, only 3 rotors are available. For context: during World War II, the original Enigma machine also operated with 3 rotors – and was famously cracked. RotorCrypt X with just 3 rotors is far more secure than the original thanks to modern additional layers (AES-256-GCM, HKDF-SHA3-256) – but for maximum security we strongly recommend the full version with up to 50 rotors. Each additional rotor multiplies the key space and makes decryption without knowing the rotor count virtually impossible.

What is EAR99 and does it apply to me?

EAR99 is a US export classification for many common commercial goods without special cryptographic restrictions. RotorCrypt X uses only standardized, publicly available algorithms and may fall under this classification. EAR99 is not a global clearance, however — other countries have their own rules. Users are responsible for complying with the applicable national regulations in each case.

Am I allowed to export the software to my country?

In most countries yes — but not everywhere. Sanctioned or restricted jurisdictions are excluded. The list changes; please check official government sources (e.g. OFAC, EU sanctions lists) or contact us at compliance@bagdadi.de before using the software in regions with an unclear legal situation.

What do I do if I am unsure about the export question?

Contact a lawyer specialising in export control or write to us at compliance@bagdadi.de. When in doubt: refrain from exporting until the situation is clear. Also check whether the recipient appears on any sanctions or embargo lists (e.g. OFAC, EU lists).

What happens when I switch my Android phone?

Your messages and settings are not lost — there are two ways, depending on how you proceed.

Setting up a new phone with device transfer: If you use Android's (Google) data transfer when setting up your new phone, the system automatically transfers the app along with its data to the new device. In this case no further action is needed.

Reinstalling via Google Play: If you reinstall the app fresh from the Play Store, all local data — contacts, keys and message histories — will be permanently lost, because RotorCrypt X deliberately creates no cloud backup. Your privacy remains fully protected this way. If you purchased your licence through Google Play, the software automatically recognises your purchase — you do not need to pay again.

Licence key manually: If you purchased your licence key through this website (outside Google Play), you will need to enter it yourself once after reinstalling. Keep your licence key stored safely.