Files
mosaic/output/manuals/03_Covert_Communications.md

1147 lines
51 KiB
Markdown

# Manual 03: Covert Communications
> **Mosaic Reference Library** -- Operational Tradecraft Series
> Compiled from declassified CIA manuals, Grugq OPSEC lectures, Allen Dulles operational
> writings, JSOU clandestine networks research, and open-source intelligence tradecraft.
>
> **Classification:** UNCLASSIFIED -- compiled from publicly available and declassified sources.
> Original classification markings retained for provenance only.
---
## Table of Contents
1. [COMSEC Fundamentals](#chapter-1-comsec-fundamentals)
2. [Dead Drops](#chapter-2-dead-drops)
3. [Brush Passes](#chapter-3-brush-passes)
4. [Signal Sites](#chapter-4-signal-sites)
5. [Cut-Outs and Impersonal Communications](#chapter-5-cut-outs-and-impersonal-communications)
6. [Digital COMSEC](#chapter-6-digital-comsec)
7. [Codes and Coded Communications](#chapter-7-codes-and-coded-communications)
8. [Telephone Discipline](#chapter-8-telephone-discipline)
9. [Communication Planning](#chapter-9-communication-planning)
---
# Chapter 1: COMSEC Fundamentals
## 1.1 The Communication Problem
Communication is the lifeblood of any intelligence operation and its greatest vulnerability.
Every contact between an operative and their handler, between cells of a network, between
a source and a case officer, creates a moment of exposure. The opposition does not need to
read the content of a message to extract intelligence from it -- the mere existence of
communication between two parties can be sufficient to destroy an operation.
The Grugq articulated a hierarchy of communication security that distinguishes between
what most people think COMSEC means and what it actually requires. Most people think of
encryption -- making messages unreadable. That is necessary but radically insufficient.
## 1.2 The Four Goals of Secure Communications
Secure communications must achieve four distinct goals, listed in order of increasing
difficulty and decreasing familiarity:
### Goal 1: Unreadable Content
The content of the message cannot be read by an interceptor. This is classical encryption
and is the easiest of the four goals to achieve. Modern cryptographic tools (AES-256,
Signal Protocol, PGP) provide content security that is, for practical purposes,
unbreakable through mathematical attack.
Achieving Goal 1 alone provides a false sense of security. Encrypted communications
between two known parties still reveal that those parties are communicating, when they
communicate, how often, and how much data they exchange.
### Goal 2: Inaccessible Meaning
Even if content is intercepted and decrypted, the meaning of the message is not apparent.
This is the domain of codes, where pre-arranged meanings are assigned to innocuous words
or phrases. A message reading "The weather in Madrid is beautiful" might mean "The dead
drop is loaded."
Goal 2 supplements Goal 1. If encryption fails (key compromise, implementation flaw,
quantum computing), coded meaning provides a second layer. However, codes are fragile --
they require pre-arrangement, they cannot convey complex or unanticipated information,
and their use can be detected through statistical analysis of language patterns.
### Goal 3: Avoid Traffic Analysis
No link can be established between the communicating parties. This is where most
communications security fails. Traffic analysis does not care what you said. It cares
that you said something to someone, at a particular time, from a particular location.
Traffic analysis reveals:
- **Who communicates with whom** (social graph mapping)
- **When they communicate** (timing patterns, activity cycles)
- **How much they communicate** (relationship intensity)
- **Where they communicate from** (geographic correlation)
- **How their communication patterns change** (events, operations, meetings)
The CIA spy ring in Lebanon was destroyed not through cryptanalysis but through traffic
analysis. Agents had dedicated mobile phones kept at static locations with pre-arranged
meetings at fixed sites (a Pizza Hut in Beirut). The phones themselves created patterns --
dedicated devices at fixed locations, activated on predictable schedules. Hezbollah's
counterintelligence did not need to decrypt a single message. The metadata was sufficient.
Defeating traffic analysis requires that no observable link exists between the sender and
receiver. This means no shared communication channel, no correlated timing, no geographic
proximity, and no behavioral pattern that connects the two parties.
### Goal 4: Avoid Knowledge of Channel Existence
No one knows that a communication channel exists at all. This is the highest and most
difficult level of COMSEC. If the opposition does not know you are communicating, they
cannot analyze traffic, attempt decryption, or investigate the relationship.
Steganography (hiding messages in images or other media), dead drops (no electronic
channel at all), and short-range burst transmissions (SRAC) all aim to achieve Goal 4.
The communication happens in a way that leaves no trace that any communication occurred.
## 1.3 The Hierarchy of Importance
Goals 1 and 2 (content security) are what most people focus on. Goals 3 and 4 (channel
security) are what actually matter in operational environments, because they are harder
to achieve and their failure is more immediately catastrophic.
An intercepted but encrypted message is a problem. A pattern of communication between an
operative and a source that enables identification of both parties is a disaster.
The Grugq summarized this principle: "Systems based purely on secrecy [encryption] have
anomalous usage that attracts attention." An encrypted app on a phone is itself an
indicator. A phone that only turns on for brief periods at specific locations is itself
suspicious. Encryption protects content; it does not protect against the inference that
something worth encrypting is happening.
## 1.4 The Anonymity-First Principle
The correct priority for operational communications is: **anonymity first, then encryption.**
This means:
1. First, ensure that no link can be established between the communicating parties
(Goal 3)
2. Then, ensure that no one knows the communication is happening at all (Goal 4)
3. Then, encrypt the content (Goal 1)
4. Then, code the meaning (Goal 2)
This reversal of conventional thinking is the fundamental lesson of every modern
intelligence compromise. The FBI did not break Silk Road's encryption -- they followed
the metadata. Hezbollah did not decrypt CIA communications in Beirut -- they followed
the phones. The NSA's mass surveillance programs are overwhelmingly focused on metadata
collection, not content interception, because metadata is more operationally useful.
---
# Chapter 2: Dead Drops
## 2.1 What a Dead Drop Is
A dead drop is a pre-arranged concealment location where one party deposits material for
another to retrieve at a later time. The defining characteristic is that the two parties
never meet. There is no direct contact, no shared physical space at the same time, and
no communication channel beyond the dead drop itself and its associated signaling system.
Dead drops address Goals 3 and 4 simultaneously. There is no electronic communication to
intercept or analyze, and if the site is well chosen, there is no visible indication that
a communication is taking place.
## 2.2 Site Selection
The success or failure of a dead drop operation depends overwhelmingly on site selection.
A poorly chosen site compromises the operation regardless of how well it is serviced.
### Selection Criteria
1. **Accessible without suspicion.** Both parties must be able to visit the site as part
of normal, plausible daily activities. A site that requires either party to make an
unusual trip or visit an area inconsistent with their cover creates exposure.
2. **Natural concealment opportunity.** The site must offer a place to hide material that
is accessible but not casually discoverable: a gap in a stone wall, a hollowed brick,
a magnetic container behind a metal railing, loose flagstone with a cavity beneath,
the underside of a park bench.
3. **Not under surveillance.** The site must not be covered by CCTV cameras, not within
the sight line of security guards, and not in an area with high passive observation
(e.g., a cafe with outdoor seating facing the site).
4. **Away from regular foot traffic** but not isolated. A completely deserted location
makes anyone who visits it conspicuous. A moderately trafficked park, trail, or
residential street provides the cover of normal activity without the risk of accidental
discovery.
5. **Memorable but not distinctive.** Both parties must be able to locate the exact spot
reliably without maps or GPS (both of which create records). The site should be near
a landmark but not at the landmark itself.
6. **Weather resistant.** Material must survive exposure to rain, snow, temperature
extremes, and humidity. Use waterproof containers.
7. **Multiple approach routes.** Both parties should have more than one plausible path
to the site, enabling SDR variations.
### Site Survey Procedure
Before a dead drop site is approved for operational use:
1. Visit the site at different times of day and different days of the week to assess
traffic patterns and surveillance exposure
2. Identify the specific concealment location and test that it can accommodate the
expected material
3. Walk the approach routes and identify SDR elements (choke points, observation posts,
direction changes)
4. Photograph the site (discreetly) for the other party's recognition
5. Identify a signal site that is near enough to be practical but not so close that
servicing the signal and servicing the drop look related
## 2.3 Dead Drop Containers
The container must protect the material from environmental damage and casual discovery:
- **Magnetic containers** that attach to metal surfaces (undersides of benches, inside
drainpipes, behind electrical boxes)
- **Faux rocks and bricks** that blend with the environment
- **Waterproof capsules** for burial or submersion
- **Modified everyday objects** (a dead battery, a crushed soda can, a used coffee cup)
that would not attract attention if discovered
The container should be camouflaged to match its surroundings. A bright metal box in a
hedge is obviously planted. A dirty container that looks like trash is invisible.
## 2.4 Dead Drop Procedures
### Loading
1. Conduct a full SDR before approaching the site
2. Arrive at the site through a natural-looking route consistent with cover activity
3. Confirm the site is not under observation (look for new cameras, unusual vehicles,
people lingering)
4. Load the container with the material
5. Place the container in the concealment location
6. Depart through a different route than arrival
7. Set the load signal at the pre-arranged signal site
### Clearing (Retrieval)
1. Check the signal site first -- if the load signal is not set, do not approach the
dead drop
2. Conduct a full SDR before approaching the site
3. Arrive through a natural route
4. Retrieve the container
5. Depart through a different route
6. Clear the load signal and optionally set a receipt signal
7. Do not open or examine the material until in a secure location
### Timing
- Load and clear at different times -- never within the same hour, ideally on different
days
- Do not establish a pattern (every Tuesday at 3 PM)
- The clearing party should retrieve within the agreed window -- material left too long
risks discovery or degradation
- If the material is not retrieved within the agreed window, the loading party must
assume compromise and abort
## 2.5 Dead Drop Security
- **Never revisit a compromised site.** If there is any indication that a site has been
discovered -- container missing, container moved, signs of disturbance, new surveillance
in the area -- the site is burned permanently.
- **Vary sites regularly.** Even sites that appear secure develop risk over time through
environmental changes, new construction, new camera installations, or pattern development.
- **Dust containers with detection material** (UV powder, marked adhesive) that would
transfer to anyone who handles the container, providing evidence of compromise.
- **Maintain a reserve of pre-surveyed sites** so that losing one site does not interrupt
operations.
- **Separate the signal site from the drop site** by enough distance that a watcher on
one cannot observe the other.
---
# Chapter 3: Brush Passes
## 3.1 What a Brush Pass Is
A brush pass is a brief, planned physical exchange that occurs as two parties walk past
each other in a public space. The transfer takes less than one second. Neither party
stops, neither acknowledges the other, and to any observer, nothing has occurred beyond
two strangers passing on a sidewalk.
Where a dead drop separates the parties in time (they never occupy the same space
simultaneously), a brush pass separates them in attention -- they are in the same space
at the same time but the interaction is so brief and so natural that it is effectively
invisible.
## 3.2 The Technique
### Physical Mechanics
1. **Approach from opposite directions** along a path in a crowded area
2. **Item is palmed** -- held in the hand in a way that is invisible to observers. The
item must be small enough to palm: a USB drive, a folded note, a memory card, a key
3. **Moment of transfer:** As the parties pass each other, a brief hand contact transfers
the item. This can be a handshake-like grip, a brush of fingers, or a pass through
a carried bag or newspaper
4. **Neither party stops or reacts.** Both continue walking in their original direction
at their original pace
5. **Neither party acknowledges the other** -- no eye contact, no nod, no verbal exchange
### Environmental Requirements
The brush pass requires a specific environment to work:
- **Crowd density.** Enough people that two individuals passing close together is normal,
not remarkable. Markets, subway platforms, busy sidewalks, shopping districts, transit
stations, and event venues provide ideal cover.
- **Movement flow.** Both parties must be walking in a natural flow of pedestrian traffic.
Two people walking directly toward each other on an empty sidewalk is conspicuous.
- **No surveillance chokepoint.** The pass location should not be under a camera with a
clear angle on the hands of both parties.
## 3.3 Practice
A brush pass requires significant practice to execute smoothly. A fumbled transfer --
dropped item, visible hand contact, unnatural hesitation -- defeats the entire purpose.
Practice regimen:
1. **Solo palm practice.** Practice palming objects of various sizes until the hand
position is natural and the object is invisible.
2. **Approach timing.** Practice walking at normal speed and arriving at the transfer
point at the correct moment relative to the other party.
3. **Transfer practice.** Practice the hand contact with a partner until the transfer
is smooth, quick, and produces no visible reaction from either party.
4. **Distressed practice.** Practice after physical exertion, in uncomfortable weather,
while carrying bags, and while wearing gloves.
5. **Crowd practice.** Practice in actual crowd environments to develop comfort with
proximity, timing, and noise.
## 3.4 Brush Pass Security
- Conduct SDR before the pass -- both parties must be confident they are not under
surveillance
- Have a pre-arranged abort signal -- if either party detects surveillance, the pass
does not happen, and both parties continue as if they were never going to meet
- The brush pass location should not be the same location every time
- Do not combine brush passes with verbal communication -- the pass is the exchange,
nothing more
- If the item is critical, have a fallback plan (dead drop, secondary brush pass
location) in case the primary attempt is aborted
---
# Chapter 4: Signal Sites
## 4.1 The Purpose of Signals
A signal site is a pre-arranged location where a physical indicator communicates a binary
message: go/no-go, loaded/cleared, danger/safe, ready/not ready. Signals are the
triggering mechanism for other tradecraft -- they tell a party when to service a dead drop,
when to show up for a meeting, or when to abort.
Signals exist because the alternative -- communicating these messages electronically --
creates the traffic analysis vulnerability that Goals 3 and 4 seek to avoid. A chalk
mark on a lamppost generates no metadata.
## 4.2 Types of Signals
### Mark Signals
A visible mark placed on a surface:
- Chalk mark on a wall, curb, mailbox, or lamppost
- Thumbtack on a bulletin board (color or position conveys meaning)
- Tape on a traffic sign, utility pole, or railing
- Grease pencil mark on a window
Mark signals are easy to set and check but vulnerable to weather (rain washes chalk) and
environmental cleaning (maintenance crews remove marks).
### Placement Signals
An object placed in a specific position:
- Flower pot in a specific window (present = go, absent = no-go)
- Car parked in a specific spot
- Newspaper left on a specific bench
- Stone placed on a specific wall
Placement signals are more weather-resistant than marks but require the signaler to have
access to the object and location.
### State Signals
The state of an existing object:
- Window blind up versus down
- Gate open versus closed
- Specific item displayed in a shop window
- Light on versus off in a specific window
State signals are the least conspicuous because they involve no foreign object or mark --
the signal is embedded in the normal state of the environment.
## 4.3 Signal Site Selection
Signal sites must satisfy specific requirements:
1. **Visible in normal passing.** Both the setter and the checker must be able to interact
with the signal site as part of a natural route. The checker should not need to stop,
stoop, or change direction to observe the signal. A chalk mark at eye level on a
wall that the operative walks past daily is ideal.
2. **Not under dedicated observation.** Avoid signal sites under CCTV or in areas with
security guards. Avoid locations where a regular observer (a shopkeeper, a parking
attendant) would notice someone setting or checking the signal.
3. **Weather resistant.** If using chalk, choose a sheltered surface (under an overhang,
inside a phone booth, on the interior face of a wall). If using placement signals,
ensure the object will not be moved by wind, cleaning crews, or passersby.
4. **Unambiguous.** The signal must be clearly present or clearly absent. A faded chalk
mark that might or might not still be visible creates dangerous ambiguity.
5. **Separate from the operational site.** The signal site should not be close enough to
the dead drop, meeting location, or operational target that checking the signal could
lead surveillance to the operational site.
## 4.4 Signal Protocols
### Two-Signal System
A basic protocol uses two signals:
- **Load signal:** Set by the loader after placing material in a dead drop. Checked by
the retriever before approaching the drop.
- **Receipt signal:** Set by the retriever after successfully clearing the dead drop.
Checked by the loader to confirm the material was received.
### Three-Signal System
A more robust protocol adds a danger signal:
- **Load signal:** Same as above
- **Receipt signal:** Same as above
- **Danger signal:** Set by either party to indicate that the operation is compromised,
the site is under surveillance, or an emergency has occurred. The danger signal cancels
all pending operations and may activate emergency protocols.
### Signal Timing
- Signals should be set and checked within agreed windows
- A signal that has been set for longer than the agreed window should be treated as
potentially compromised (either the other party has been prevented from responding,
or the signal has been discovered)
- Do not check signals obsessively -- repeated visits to the signal site create a pattern
## 4.5 Signal Discipline
- Each signal has one and only one meaning. Overloading signals with multiple meanings
creates confusion and operational risk.
- Confirm signals are separate from action signals. A signal that says "the drop is
loaded" is different from a signal that says "I acknowledge receipt." They use
different sites or different marks.
- Regularly rotate signal sites, just as drop sites are rotated.
- If a signal site may have been observed (someone was watching when you set the mark,
the area has new cameras), burn the site.
---
# Chapter 5: Cut-Outs and Impersonal Communications
## 5.1 The Principle of Indirect Contact
Impersonal communication ensures that two individuals who need to exchange information
never come into direct contact. This is the foundational organizing principle of
clandestine networks: if the handler and the source never meet, the compromise of one
does not directly expose the other.
The methods divide into passive (no real-time link between parties) and active (real-time
communication channel exists).
## 5.2 Passive Methods
Passive methods generate no electronic signature and create no real-time connection
between the parties:
### Dead Drops
Covered in Chapter 2. The paradigmatic passive method: one places, another retrieves,
no contact.
### Live Drops
A live drop uses a human intermediary -- a cut-out -- to physically carry material from
one party to another. The cut-out knows neither the identity nor the role of the parties.
They receive a package from a stranger and deliver it to another stranger.
Live drops are more flexible than dead drops (no fixed site required) but introduce the
risk of the cut-out being identified, followed, or compromised.
### Mail Drops
Material is sent through the postal system to a pre-arranged address. The address is
controlled by the receiving party (or by a further cut-out) and is not linked to either
party's true identity.
Mail drops require careful attention to postal inspection triggers:
1. Use business-to-individual format, not person-to-person
2. Use typed labels, not handwritten
3. Weight should not be round metric numbers
4. Return address must be real and verifiable (backstopped)
5. Packaging should look professional and new (not reused)
6. Avoid heavy taping
7. Do not ship from drug-source zip codes
8. Use packaging consistent with the stated business context
These criteria are derived from the FBI drug mail profile -- the same triggers that flag
drug shipments will flag suspicious intelligence packages.
### Clandestine Signals
Covered in Chapter 4. Signals themselves are a form of impersonal communication -- they
convey a binary message without any direct contact between the parties.
## 5.3 Active Methods
Active methods create a real-time or near-real-time communication channel. They offer
more flexibility and speed but generate detectable signatures:
### Radio
Short-wave radio, burst transmissions, and numbers stations have been used since World
War II. Radio provides one-way communication (numbers station to agent) without any
connection infrastructure. The agent needs only a commercially available radio receiver,
which is impossible to distinguish from innocent use.
### Telephone
Covered in Chapter 8. Telephone communication is fast and flexible but creates extensive
metadata records.
### Internet
Covered in Chapter 6. Digital communications offer speed and capacity but generate
metadata and create electronic links between parties.
## 5.4 The Cut-Out
A cut-out is a person who serves as an intermediary between two parties who cannot or
should not meet directly. The cut-out knows their task but not the identities or roles
of the people they connect.
### Properties of a Good Cut-Out
- **No known connection** to either party or to the intelligence operation
- **Plausible reason for movement** in the areas where they operate (a delivery driver,
a commuter, a regular at a certain cafe)
- **Unaware of the operational significance** of the material they transport
- **Reliable** without being informed -- will follow instructions consistently
- **Replaceable** -- the operation does not depend on any single cut-out
### Courier Considerations
Couriers are the most secure form of active material transfer. They physically carry
material from point A to point B, leaving no electronic trace.
Operational experience, particularly from Middle Eastern and Irish clandestine networks,
has shown that **women and children decrease suspicion at checkpoints.** A woman carrying
a shopping bag through a military checkpoint faces less scrutiny than a military-age male
with a backpack. This is not an endorsement of involving non-combatants -- it is a
recognition of how checkpoint profiling works and how adversaries exploit it.
## 5.5 Cellular Network Structure
The most sophisticated application of cut-out principles is the cellular network, where
an entire organization is structured so that members of one cell know only their
immediate contacts and the cell's internal members. If a cell is compromised, the damage
is contained to that cell and its immediate links.
JSOU research on clandestine networks found that organizations using this structure with
excellent tradecraft can remain hidden even from expert adversaries. Destroyed cells are
replaced within weeks from a hidden reserve structure. The key insight: the visible
(operational) cells are at the periphery and are expendable. The hidden infrastructure
that recruits, trains, and deploys new cells is the organization's actual center of
gravity.
Counterintelligence should therefore "attack the clandestine infrastructure, not just
visible cells" -- and conversely, clandestine organizations should protect their
regenerative infrastructure above all else.
---
# Chapter 6: Digital COMSEC
## 6.1 The Digital Communications Environment
Digital communications offer unprecedented speed, capacity, and global reach. They also
offer unprecedented surveillance capability to any adversary with access to network
infrastructure, device compromise tools, or metadata analysis programs.
The challenge of digital COMSEC is that the technology simultaneously enables secure
communication and enables surveillance of that communication. Every solution creates new
attack surfaces.
## 6.2 SRAC (Short Range Agent Communications)
SRAC represents the closest digital analog to a dead drop -- a burst communication system
that operates over extremely short range (typically infrared or short-range WiFi) and
transmits in less than one second.
### How It Works
1. The agent carries a small transmitter device
2. A concealed receiver is placed at a pre-arranged location (inside a building wall,
in a vehicle, mounted inconspicuously)
3. The agent walks past the receiver at normal speed
4. When in range (typically a few meters), the device transmits an encrypted data burst
lasting less than one second
5. No internet connection is required
6. The receiver stores the data for later retrieval by the handler through a separate
channel
### Why SRAC Matters
SRAC achieves all four COMSEC goals simultaneously:
- **Goal 1:** Content is encrypted
- **Goal 2:** Even if decrypted, the meaning can be coded
- **Goal 3:** No traffic analysis is possible -- there is no persistent communication
channel to monitor
- **Goal 4:** The burst is so brief and short-range that detecting its existence requires
a receiver positioned within meters at the exact moment of transmission
SRAC is the gold standard for agent communications in hostile environments. Its limitation
is that it requires physical proximity (the agent must walk past the receiver) and physical
infrastructure (the receiver must be placed and maintained).
## 6.3 Burner Phone Discipline
Mobile phones are ubiquitous and therefore tempting for operational communication. They
are also the most comprehensively surveilled communication devices in existence.
The Grugq's analysis identifies the critical principle: a mobile phone has multiple
identifiers beyond the SIM card. Replacing the SIM is insufficient. The phone itself
has an IMEI that is transmitted with every connection. The phone's location pattern,
calling pattern, and even the user's voice are fingerprints.
### Burner Phone Rules
1. **Phone OFF means battery out, SIM out, and ideally in a shielded bag.** A phone that
is "off" but has a battery can still be activated remotely and can still be tracked
by some systems.
2. **Never use at locations associated with you.** Home, work, regular social locations --
any phone powered on at these locations can be linked to the person who lives or
works there.
3. **Never turn on at the same location as your real phone.** Powering on a burner at a
location where your real phone has established a pattern creates an immediate
correlation.
4. **Do not let your real phone go OFF when the burner goes ON.** Paired events -- where
one phone deactivates as another activates -- are powerful indicators of relation.
Keep the real phone showing normal usage patterns while the burner is operational.
5. **Never carry phones for different compartments together.** Co-location of devices
links them. If two phones are always at the same tower at the same time, they belong
to the same person or the same car.
6. **Four locations will identify 90% of people.** Mobility patterns are unique. A burner
phone that visits the same home, office, gym, and grocery store as a known phone is
trivially attributable.
7. **Store the burner away from home.** If the burner is at a known residential address
overnight, it is linked to the resident.
8. **Keep the real phone showing normal usage.** Sudden gaps in the real phone's activity
correlate with burner phone activation.
### Burner Phone Summary
Burner phones are useful for **signaling only** -- brief, low-content communications that
do not require extended conversation. They are not suitable for substantive communication
because the duration and pattern of use creates exploitable metadata.
Buy with cash. Activate from a neutral location. Never power on near home or work. Use
briefly. Destroy after a single operational use or a short operational period.
## 6.4 Tor, VPNs, and Network Anonymity
Network anonymity tools provide Goal 3 (traffic analysis resistance) for digital
communications but with significant caveats.
### Tor
Tor routes traffic through multiple relays, hiding the user's IP address from the
destination and hiding the destination from the user's network. It is the best available
tool for network-level anonymity but has known limitations:
- **Tor is detectable.** Your ISP can see that you are using Tor, even if they cannot see
where you are going. In an environment where Tor use itself is suspicious, this is a
Goal 4 failure.
- **Anonymity set matters.** Tor provides anonymity within the set of Tor users at your
location and time. At a university with 30,000 students, many of whom use Tor, the
anonymity set is large. At a small office where you are the only Tor user, the
anonymity set is one. The Harvard bomb threat case demonstrated this: using Tor from
campus during a bomb threat reduced the suspect pool to campus Tor users during the
threat window.
- **Traffic correlation.** A global adversary who can observe both the entry and exit of
Tor traffic can correlate timing to deanonymize users. Nation-state adversaries may
have this capability.
### VPNs
VPNs hide traffic from the local network but require trust in the VPN provider. The
VPN provider sees all traffic. VPNs are useful for evading local network surveillance
but do not provide anonymity against a motivated adversary who can compel the VPN
provider to produce records.
### Operational Guidance
- Use Tor from clean devices at locations with large anonymity sets
- The PORTAL approach (dedicated hardware Tor gateway) prevents accidental bypass --
all traffic is forced through Tor at the network level, and the user cannot make a
mistake that reveals their real IP
- Remove WiFi cards from operational machines to prevent malware from exfiltrating
the real IP address
- Never use anonymization tools from locations associated with your real identity
- Combine network anonymity with device anonymity (burner laptop purchased with cash)
## 6.5 Steganography
Steganography hides data within other data -- typically, a message hidden within an
image file, audio file, or video. Where encryption makes a message unreadable,
steganography makes the message invisible.
Steganography addresses Goal 4 directly. An image posted to a public photo-sharing
site that contains a hidden message is indistinguishable from any other image. The
communication channel itself is invisible.
### Limitations
- **Steganalysis.** Sophisticated analysis can detect the statistical anomalies that
steganographic embedding creates. This is an arms race between embedding techniques
and detection techniques.
- **Capacity.** The amount of data that can be hidden without detectable distortion is
limited. Steganography is suitable for short messages, not bulk data transfer.
- **Key management.** The recipient must know that a steganographic message exists and
must have the key/method to extract it. This requires a pre-arranged protocol.
- **Fragility.** Image compression, format conversion, or resizing can destroy the
hidden message.
### Practical Application
Steganography is best used as a channel existence concealment layer on top of encryption.
The message is first encrypted (Goal 1), then embedded steganographically in a carrier
file (Goal 4), then transmitted through an anonymous channel (Goal 3).
## 6.6 Identity and Communications Migration
Regular migration of communication platforms and identities creates temporal
compartmentation. Old identities and channels are abandoned, creating silos that limit
the damage from any single compromise.
The practice:
1. Change communication platforms (IRC servers, messaging apps, forums) on a schedule
2. Change identifiers (nicknames, account names, email addresses) with each migration
3. Do not contaminate between time periods -- old logs from a previous identity cannot
be linked to the new one if migration is done properly
4. Use different encryption keys for each identity period
5. Abandon old keys and accounts completely -- do not reuse them even if they seem safe
Migration provides plausible deniability and limits the window of exposure for any
single compromise.
---
# Chapter 7: Codes and Coded Communications
## 7.1 The Role of Codes
Codes serve Goal 2 (inaccessible meaning) but they must be understood for what they are
and what they are not. Codes are not encryption. They are a layer of meaning protection
that supplements encryption and serves specific operational purposes.
## 7.2 Signaling Codes
The primary operational use of codes is signaling -- conveying pre-arranged binary or
limited messages through otherwise innocuous communication:
- "The weather in Madrid is beautiful" = the dead drop is loaded
- "I'll be late for dinner" = abort the meeting
- "Uncle Robert is visiting next week" = new intelligence available
- A specific emoji in a social media post = ready for contact
Signaling codes must be:
1. **Generic.** The coded phrase must sound natural in the context where it will be used.
A phrase that is unusual or out of character attracts attention.
2. **Consistent.** Each code means one thing. Do not reuse codes for multiple meanings.
3. **Limited to simple binary signals.** Go/no-go, yes/no, safe/danger. Codes cannot
efficiently convey complex information.
4. **Pre-arranged.** Both parties must agree on the code meanings before they are needed.
Codes cannot be improvised in real time.
## 7.3 Why "Talking Around" Does Not Work
There is a persistent temptation to use circumlocution -- "talking around" a classified
or sensitive topic -- as a substitute for proper COMSEC. This does not work.
The Grugq's assessment is direct: "Talking around classified subjects does not protect
the information." The reasons:
1. **Context makes meaning clear.** If two people known to be involved in intelligence
are having a conversation where they carefully avoid certain words but clearly discuss
an operation, the content is obvious to any analyst.
2. **Circumlocution is itself suspicious.** A conversation that dances around a topic is
more notable than a direct conversation about an innocuous topic.
3. **Humans are bad at it.** Under stress, fatigue, or excitement, people revert to direct
language. The circumlocution degrades before the conversation ends.
4. **Recorded conversations can be analyzed at leisure.** An analyst with a transcript and
unlimited time will extract the meaning from any circumlocution.
The lesson: if information cannot be communicated securely, do not communicate it at all.
Do not attempt to communicate it "carefully." Either use proper COMSEC (encryption +
anonymity + channel concealment) or wait until you can.
## 7.4 Self-Made Cipher Systems
The temptation to create a personal cipher system is equally dangerous. Self-made cipher
systems rarely work because:
1. Cryptography is a specialized discipline requiring deep mathematical knowledge
2. Ciphers that seem strong to their creators are often trivially breakable by
professionals
3. Historical examples (Zodiac killer, various criminal organizations) show that
amateur ciphers are routinely broken
4. Professional cryptographic tools are freely available and provably secure
Do not invent your own encryption. Use established, peer-reviewed cryptographic tools.
Codes are for signaling. Encryption is for content protection. These are different
functions requiring different solutions.
## 7.5 Personal Codes for Operational Notes
Dulles recommended that operatives carry no names or addresses in clear and instead use
a personal code -- a private notation system that is meaningless to anyone who finds the
notebook.
This is a specific, limited application:
- Phone numbers with digits transposed according to a memorized pattern
- Names replaced with unrelated words from a private mapping
- Addresses encoded as coordinates or references to a private key
The purpose is not to defeat a cryptanalyst (any simple substitution code can be broken
with effort) but to prevent a casual discoverer -- a pickpocket, a maid, a border
agent -- from immediately identifying contacts and addresses.
---
# Chapter 8: Telephone Discipline
## 8.1 The Dulles Rules
Allen Dulles described the telephone as "the greatest material curse to the profession."
His rules for telephone use remain foundational:
1. **Always assume every conversation is listened to.** This was true with copper wire
taps in the 1940s and is exponentially more true with digital telephony, where calls
are routinely intercepted, recorded, transcribed, and stored by multiple intelligence
services.
2. **Never dial before thinking out what to say and how to say it.** The telephone
encourages spontaneous conversation. Spontaneous conversation produces security
failures.
3. **Unplug the telephone during confidential conversations.** The telephone is a
microphone connected to the telephone network. Even when not in a call, it can be
activated remotely. Better to have no phone in the room.
4. **Avoid the phone when possible. Make a day's journey instead.** If the information
is important enough to protect, it is important enough to deliver in person. A
face-to-face meeting after an SDR is infinitely more secure than a phone call.
## 8.2 Modern Application
The underlying principles have not changed. The specific threats have expanded:
### Metadata
Modern telephony generates extensive metadata beyond the content of the call:
- Calling party number and called party number
- Call duration
- Cell tower locations for both parties (geographic tracking)
- IMEI of both devices
- Time and date
- Frequency of contact between the numbers
Metadata analysis can map entire networks without intercepting a single word of content.
The NSA's bulk metadata collection programs demonstrated that call records alone reveal
organizational structure, key nodes, and operational patterns.
### Voiceprint
Voice biometrics can identify speakers across calls, even across different phone numbers.
If an operative's voice is in a voiceprint database (from a legal intercept, a public
speech, or a media appearance), any subsequent phone call can be attributed to them
regardless of what phone they use.
### Location Tracking
Mobile phones continuously report their location to cell towers. This location data is
stored by carriers and is available to intelligence and law enforcement agencies. A phone
that is present at a meeting location at the time of a meeting, and is also present at
the operative's home address, links the operative to the meeting.
### Modern Rules
1. **No substantive communication by phone.** Phone calls are for logistics and signaling
only. Substantive intelligence discussion happens in person, in a swept location.
2. **No operational discussion even on encrypted calls.** Encrypted apps protect content
but not metadata. The fact that you called a known intelligence contact using Signal
is itself intelligence, regardless of what you discussed.
3. **Phone-free zones for sensitive meetings.** All phones -- personal and burner --
remain outside the room during sensitive discussions. A phone in the room is a
microphone and a location beacon.
4. **Assume compromise.** Design communications plans that remain secure even if phone
calls are intercepted and recorded. This means phone calls contain nothing that
would be damaging if transcribed and published.
---
# Chapter 9: Communication Planning
## 9.1 The Communication Plan
Every intelligence operation requires a communication plan -- a pre-arranged structure
that defines how, when, and through what channels the parties will communicate. The plan
must balance security (minimizing exposure) with reliability (ensuring messages get
through) and timeliness (ensuring time-critical information is delivered within the
required window).
## 9.2 Components of a Communication Plan
### Primary Channel
The default method of communication for routine exchanges. This should be the most
secure method available and the one that has been most thoroughly tested:
- Dead drops with signal sites for low-tempo, high-security requirements
- SRAC for agent communications in hostile environments
- Encrypted digital communications for higher-tempo requirements where network
anonymity can be maintained
### Alternate Channel
A backup method if the primary channel is unavailable (compromised, disrupted, or
impractical for a specific communication):
- If primary is dead drops, alternate might be a brush pass at a pre-arranged fallback
location
- If primary is digital, alternate might be a physical method (dead drop, courier)
### Emergency Channel
A method for communicating that an emergency has occurred -- the operation is compromised,
a party is in danger, or immediate action is required:
- Pre-arranged phone signal (a specific number of rings, then hang up)
- Emergency signal site (a specific mark at a specific location)
- Emergency meeting at a pre-arranged time and place
- A digital signal (a specific post on a public platform)
Emergency channels must be:
- Simple to activate under stress
- Monitorable without special equipment
- Unambiguous in meaning
- Rarely used (so that their use is clearly an emergency, not routine)
### Duress Signal
A signal embedded within normal communication that indicates the communicator is under
coercion -- they are being forced to communicate and the content should be treated as
hostile disinformation:
- A specific word or phrase included in a message
- An agreed-upon deviation from normal protocol (e.g., using a middle initial that is
not normally used)
- A specific error introduced into a coded message
## 9.3 Communication Frequency
### The Security-Timeliness Tradeoff
More frequent communication means faster intelligence delivery but greater exposure. Less
frequent communication means better security but risk of stale intelligence and loss of
situational awareness.
The frequency decision depends on:
1. **Threat level.** In a high-threat environment (hostile counterintelligence is active
and capable), communication should be as infrequent as possible. The CIA used 2-4 hour
SDRs before any operational activity in Moscow, and high-security operations involved
weeks or months of planning with 12-hour SDRs. This pace limits communication to
what is truly essential.
2. **Intelligence perishability.** Information that is time-critical (tactical intelligence,
warning intelligence) requires faster channels. Strategic intelligence that remains
valid for weeks or months can be communicated at lower frequency.
3. **Operational tempo.** Active operations (surveillance, preparation for a meeting, an
ongoing recruitment) require more frequent communication than dormant operations.
### Recommended Frequencies by Environment
| Threat Level | Frequency | Method |
|---|---|---|
| Extreme (hostile CI active) | Monthly or less | Dead drops, SRAC |
| High (competent CI) | Bi-weekly | Dead drops with signal sites |
| Moderate (limited CI) | Weekly | Mixed dead drops and digital |
| Low (minimal CI) | As needed | Digital with proper COMSEC |
These are guidelines. The specific frequency for any operation is determined by the
intersection of threat, intelligence requirements, and operational tempo.
## 9.4 Communication Schedules
### Fixed Schedules
Communication occurs at pre-arranged times (e.g., dead drop serviced on the first
Tuesday of each month):
- **Advantage:** Both parties know when to expect communication without any signaling
- **Disadvantage:** Predictable pattern that can be surveilled; missed window creates
ambiguity (was there nothing to communicate, or was the party unable to service the
drop?)
### Signal-Triggered
Communication occurs when triggered by a signal (e.g., check the dead drop when you
see the chalk mark):
- **Advantage:** No predictable pattern; communication happens only when needed
- **Disadvantage:** Requires additional signal infrastructure; delay between signal
setting and checking
### Hybrid
Fixed schedule with signal-triggered exceptions:
- **Routine communication** on a fixed schedule (monthly dead drop)
- **Priority communication** via signal-triggered channel (emergency chalk mark triggers
immediate brush pass)
This is the most common approach because it provides both predictability (both parties
know the baseline) and flexibility (urgent matters can be communicated outside the
normal cycle).
## 9.5 Communication Security Review
Before finalizing a communication plan, review each channel against the four COMSEC goals:
| Channel | Goal 1 (Content) | Goal 2 (Meaning) | Goal 3 (Traffic Analysis) | Goal 4 (Channel Existence) |
|---|---|---|---|---|
| Dead drop | N/A (physical) | Code if needed | No electronic link | Concealed if site is good |
| Brush pass | N/A (physical) | Code if needed | Brief physical proximity | Hidden by crowd |
| SRAC | Encrypted burst | Code if needed | No persistent channel | Sub-second, short range |
| Signal site | N/A (binary) | Inherent (pre-arranged) | No electronic link | Concealed by environment |
| Encrypted phone | Strong | Code possible | Metadata exposed | Phone existence known |
| Tor + encrypted message | Strong | Code possible | Tor-level anonymity | Tor usage detectable |
| Steganography | Encryption + hiding | Code possible | Depends on carrier channel | Strong if done well |
No single channel achieves all four goals perfectly. The communication plan should use
multiple channels to provide defense in depth -- if one channel is compromised, the others
continue to provide security.
## 9.6 Communication Failure Protocols
The plan must account for communication failure. What happens when:
1. **A dead drop is not serviced.** How long before the loading party assumes compromise?
What is the fallback? Typically: wait one additional cycle, then shift to alternate
channel.
2. **A signal is not set.** Does this mean "nothing to communicate" or "the signaler has
been compromised"? Fixed schedules help resolve this ambiguity -- if a signal is
expected on a specific date and does not appear, the failure is meaningful.
3. **A party misses a scheduled contact.** One missed contact is not necessarily alarming.
Two consecutive missed contacts should trigger concern. Three should trigger emergency
protocols.
4. **A channel is suspected compromised.** Switch to alternate channel immediately.
Communicate the compromise through the alternate channel. Abandon the compromised
channel permanently.
5. **All channels are compromised.** This is the catastrophic scenario. Emergency
protocols should include a face-to-face emergency meeting at a pre-arranged location
and time (e.g., third bench from the north entrance of a specific park, first Sunday
after a communication failure, between 10:00 and 10:30).
---
# Appendix A: Communication Security Checklist
Before establishing an operational communication channel:
**Channel Assessment**
- [ ] Content protection (encryption or physical security) verified
- [ ] Meaning protection (codes for signaling) established if needed
- [ ] Traffic analysis resistance assessed -- can communication between parties be linked?
- [ ] Channel existence concealment assessed -- can the channel itself be detected?
**Infrastructure**
- [ ] Dead drop sites surveyed and approved
- [ ] Signal sites selected and tested
- [ ] Alternate channel established and tested
- [ ] Emergency channel established and tested
- [ ] Duress signals agreed upon
**Device Security (if digital)**
- [ ] Dedicated devices for each compartment
- [ ] Devices purchased anonymously (cash, no loyalty cards)
- [ ] Devices never powered on at home, work, or associated locations
- [ ] Real phone maintains normal usage pattern during burner operations
- [ ] Devices stored away from home when not in use
**Behavioral Security**
- [ ] SDR conducted before every operational communication event
- [ ] Communication frequency appropriate to threat level
- [ ] No pattern in timing, location, or method
- [ ] No cross-contamination between communication compartments
- [ ] Cover story for communication activity if observed
---
# Appendix B: Key Principles Summary
1. Anonymity first, then encryption. Channel security matters more than content security.
2. Four locations identify 90% of people. Device discipline is not optional.
3. The telephone is a curse. Assume every call is intercepted. Say nothing you would not
publish.
4. Dead drops achieve all four COMSEC goals when properly executed.
5. Traffic analysis is the real threat -- metadata destroys operations that encryption
protects.
6. "Talking around" classified subjects does not protect the information. Either
communicate securely or do not communicate.
7. Codes are for signaling, not encryption. Keep them generic, consistent, and simple.
8. Self-made cipher systems do not work. Use established cryptographic tools.
9. Every communication creates exposure. Minimize frequency to what the operation requires.
10. Plan for communication failure. The plan that assumes all channels always work is the
plan that fails catastrophically.
---
> **Sources:** CIA operational manuals (declassified), CIA CHECKPOINT program (SECRET//ORCON//NOFORN),
> Grugq OPSEC lectures and PORTAL documentation, Allen Dulles operational writings,
> JSOU Report 12-3 on clandestine networks, Army FM 2-22.3, CIA Lebanon station compromise
> analysis, Silk Road / DPR case study, Harvard bomb threat case study, PIRA case studies,
> Robert Morris worm case study, Fatah/BSO operational procedures.