Procedure, not mathematics
Almost every historical break came from how a system was used rather than from the system itself.
The lock is rarely the problem
Cryptanalysts remember the mathematical breaks — the elegant frequency table, Babbage's period recovery, the bombe running through rotor positions — because those are the stories that travel well. But the historical record tells a quieter and more consistent story: almost every system that failed in practice failed because of how it was used, not because of what it was.
The distinction matters. A cipher can be theoretically sound and operationally catastrophic. The weakness lives not in the algorithm but in the hands that run it — in the clerk who repeats a message indicator, the officer who insists on a predictable opening, the commander who transmits the same situation report at the same time every morning. Mathematics cannot protect against any of that.

The gap between the design and the desk
The Vigenère tableau is the obvious case. For roughly three centuries it resisted every published attack, and for good reason: a polyalphabetic system with a long, non-repeating key genuinely obscures the frequency signature that dismantles monoalphabetic substitution. The tableau was not broken by finding a flaw in the grid. It was broken because operators used short words as keys, used the same key repeatedly, and used it for message after message. The keyword repeats, the period becomes detectable, and Charles Babbage had his opening. The vulnerability was procedural from start to finish.
Rotor machines pushed the mathematical difficulty to a level that would have been unimaginable to any earlier cryptanalyst. The wiring, the stepping, the sheer number of starting positions — the combinatorics were staggering. And yet the machines were broken, substantially, because the people operating them did what people under operational pressure always do: they took shortcuts. Indicators were set lazily. Some operators opened every message with a standard greeting or a weather report whose format the enemy already knew. Cribs — those guessed fragments of expected plaintext — became the primary lever because procedure handed them over reliably.
This was not a failure of the machines. It was a failure of discipline maintained across millions of messages, under fatigue, at speed, by people who could not know what the enemy was doing with their habits.
What procedure actually means
"Procedure" covers a wide range. It includes the formal rules — how keys are to be chosen, distributed and destroyed, how indicators are to be set, how often settings rotate. It also includes everything that happens when those rules meet reality: the operator who cannot be bothered to generate a genuinely random indicator, the unit that reuses yesterday's settings because the new key list has not arrived, the commander who demands confirmation of an urgent message in plain language because the cipher clerk is asleep.
Each deviation is small. Each one is also a gift to the analyst on the other side. Traffic analysis — reading volume, timing and routing without ever touching the content — compounds the problem further, because the structure of communications leaks intention even when the words are perfectly encrypted. A surge of traffic from a previously quiet station tells a story. So does the sudden silence that precedes an offensive.
The one-time pad sits at one end of this spectrum: provably unbreakable under the right conditions, catastrophic in practice when those conditions slip. Two messages enciphered on the same pad page collapse the whole guarantee. The mathematics remains intact; the procedure failed. Almost every documented one-time pad failure traces back to exactly this kind of reuse — a key page used twice because of supply failure, haste, or simple human error.
The consistent lesson
What makes procedural failure so durable as a historical pattern is that it is not specific to any era or any system. Nomenclators were compromised by codebook capture and careless handling. Rotor machines were compromised by indicator laziness and predictable cribs. One-time pads were compromised by reuse. In every case the system itself was, at the level of theory, doing its job.
The cryptanalyst's real target has usually been the gap between what a system demands and what human beings under operational conditions actually deliver. That gap has proven remarkably stable across centuries. Stronger mathematics narrows it from one side; training, auditing and strict procedure narrow it from the other. History suggests the second is harder to sustain.