Running key
Using a book instead of a word, and why that is better but still not enough.
A book instead of a keyword, and why it still falls short
The weakness of the Vigenère table is repetition: a short keyword cycles, and that cycle is findable. The obvious fix is to make the key as long as the message. Use a page from a shared book, start at an agreed line, and the key never repeats within any single message. This is the running-key cipher, and it was a serious refinement.
The mechanics are identical to Vigenère — each plaintext letter is shifted by the corresponding key letter — but the key material is a stretch of natural prose rather than a recycled word. Two correspondents with the same edition of, say, a legal dictionary or a Bible verse agree on a starting point; one enciphers, the other deciphers. No short cycle, no Kasiski examination to exploit.

The trouble is that both the plaintext and the key are natural language, and natural language is not random. Both streams carry the statistical fingerprint described by frequency analysis. A skilled analyst attacking a running-key ciphertext can work simultaneously on what the key might be and what the plaintext might be, using each hypothesis to constrain the other. Where a common English digraph appears in the ciphertext, it is most likely produced by two common sequences — and there are not many candidates. The mutual constraint collapses the search space far faster than brute force.
This attack, developed in detail by cryptanalysts in the nineteenth century, means the running key is not remotely comparable to the one-time pad. The pad's key is genuinely random; a book page is not. Predictable letter distributions in the key are the lever that breaks the system.
The running-key cipher nonetheless had practical appeal: it required nothing but two copies of a commonly owned text, left no special cipher apparatus to be found, and was far stronger than anything with a short repeating keyword. It was used. It was also read, by analysts who understood that natural language, wherever it appears — plaintext or key — always leaves a fingerprint.