27 KiB
OPSEC Principles Manual
Synthesized from: Allen Dulles "Some Elements of Intelligence Work," the Grugq's OPSEC analyses (Silk Road, Harvard bomb hoax, Morris Worm, PIRA, Reservoir Dogs, Yardbird), JSOU Report 12-3, CIA CHECKPOINT travel intelligence
Classification: OPEN SOURCE — compiled from publicly available materials
Table of Contents
- OPSEC Fundamentals
- The Dulles Foundation
- Compartmentation
- The Operational Phase Framework
- Identity & Persona Management
- Communications Security
- The STFU Principle
- Informant Awareness & Counter-Intelligence
- Case Studies
- The OPSEC Checklist
Chapter 1: OPSEC Fundamentals
1.1 What OPSEC Is (And What It Isn't)
OPSEC is not a tool. It is not encryption software. It is not Tor. It is not a VPN. It is not a burner phone.
OPSEC is a mode of operating.
This distinction matters because people who think OPSEC is a tool believe they can install it, configure it, and forget it. They are wrong. They will be caught.
OPSEC is the continuous discipline of minimizing the information available to your adversary about your identity, intentions, capabilities, and activities. It encompasses every decision you make — what you say, where you go, what you buy, who you associate with, what devices you use, what patterns you create.
As the Grugq writes: "OPSEC is a mode of operating, not a tool or a collection of tools." And: "It is more important to compartment sensitive activities and structure your operational environment for impact containment than to install particular software."
1.2 The OPSEC Tradeoff
High OPSEC means low efficiency. High efficiency means weak OPSEC. There is no way around this tradeoff. Every security measure adds friction — latency in communications, complexity in logistics, constraints on behavior. The question is never "how much OPSEC do I need?" but rather "how strong is my adversary?"
The strength of opposing forces dictates minimum security requirements. Operating against a corporate security team requires different OPSEC than operating against a nation-state intelligence service. Calibrate accordingly, but when in doubt, overestimate the adversary.
1.3 The Practice Imperative
"Amateurs practice until they get it right. Professionals practice until they can't get it wrong."
OPSEC routines must be automatic. Under stress, you will not rise to the level of your aspirations — you will fall to the level of your training. If you have never practiced an SDR, you will not execute one properly when you actually need it. If you have never used a dead drop, your first attempt under operational pressure will be clumsy and observable.
The Dulles corollary: "The man or woman who does not indulge in the daily security routine, boring and useless though it may sometimes appear, will be found lacking in the proper instinctive reaction when dealing with the bigger stuff."
Practice your security routines during peacetime. Make them habitual. When the moment comes, habit will save you where conscious thought cannot.
Chapter 2: The Dulles Foundation
Allen Dulles distilled a career of intelligence work into a set of principles that have not been improved upon in seventy years. They are presented here not as historical curiosities but as operational fundamentals.
2.1 Security Above All
"The greatest of them all is security. All else must be subordinated to that."
This is the meta-rule. Every other principle derives from this one. When in conflict between security and any other objective — speed, convenience, thoroughness, ego — security wins. Always.
2.2 Security Lives in the Details
"The little things are in many ways more important than the big ones. It is they which oftenest give the game away."
You are more likely to be compromised by a careless phone call than by a broken cipher. You are more likely to be identified by a receipt in your pocket than by a failed dead drop. The big operational decisions get careful thought. The small daily habits are where discipline breaks down.
Specific Dulles directives:
- Never leave things unattended or where you might forget them
- Learn to write lightly — the blank page underneath has been read
- Destroy documents thoroughly, not casually
- Carry as little written material as possible, for the shortest possible time
- Never carry names or addresses in clear text — use a personal code only you understand
- If you must clip small papers to larger ones, do so — loose papers get lost
2.3 Never Admit
"Even though you feel the curious outsider has probably a good idea that you are not what you purport to be, never admit it. Keep on playing the other part."
People doubt their own suspicions. If you maintain your cover consistently, observers will often convince themselves they were wrong. But the moment you admit — even partially, even indirectly — the game is over. No half-admissions. No "well, I'm a little involved in that." Nothing.
2.4 Vanity Is the Enemy
"The next greatest vice is that of vanity. Its offshoots are multiple and malignant."
The need to be recognized, to show how clever you are, to hint at your secret life — this is the operational equivalent of painting a target on your chest. The Provisional IRA lost members because they boasted in pubs. Ross Ulbricht lost Silk Road because he needed social validation on forums. Robert Morris lost his freedom because he couldn't resist explaining his worm to friends.
The best operative is the one nobody suspects. If you need external validation for your work, find a different profession.
2.5 The Telephone Problem
"The greatest material curse to the profession is undoubtedly the telephone."
Written in the 1950s, this warning has only become more relevant. Modern phones are tracking devices that record your location, contacts, timing, metadata, and potentially content. The telephone is not merely a temptation to slackness — it is an active surveillance device you carry voluntarily.
Dulles's rule: "Always act on the principle that every conversation is listened to." This was prudent caution in 1955. In 2025, it is a documented fact.
Modern application: See Chapter 6 (Communications Security) for detailed phone OPSEC procedures.
2.6 Carelessness Is Irreversible
"Mistakes made generally cannot be rectified."
In most professions, a mistake is a learning experience. In operational security, a mistake is a compromise. You cannot un-send the email that contained your real name. You cannot un-visit the location that linked your cover to your identity. You cannot un-say the words that confirmed a suspicion.
Think before you act. Then think again. Then act.
Chapter 3: Compartmentation
3.1 The Principle
Compartmentation is the separation of information, people, and activities into discrete cells with no interaction, access, or knowledge of each other. It is the cornerstone of any solid counter-intelligence program.
If any single compartment is compromised — by informant, surveillance, or technical penetration — the damage stops at the compartment boundary. Without compartmentation, a single compromise cascades through the entire operation.
3.2 Types of Compartmentation
Organizational compartmentation: Structuring a group so that cells are isolated from each other. Members of Cell A know only Cell A's members and have contact with one liaison in Cell B. That is the limit of their knowledge.
Functional compartmentation: Separating activities so that each function (surveillance, logistics, execution, communications) is performed by a different team with no cross-visibility.
Temporal compartmentation: Regularly changing communications platforms, identities, and infrastructure to create chronological silos. Old identities and channels are abandoned. Compromise of a current compartment cannot reach into past compartments.
Personal compartmentation: Separating your own illicit activity from your regular life. This is what CIA case officers do — they compartment their espionage from their cover life. The first rule: never discuss your illicit activities with anyone outside the compartment.
3.3 Compartmentation for Individuals
The Grugq provides a practical framework for personal compartmentation:
The threat model: Two people (Alice and Bob) want to exchange information. They need to protect against an adversary learning:
- That two people have been in contact (low risk)
- That Bob has been in contact with someone (medium risk)
- That Alice has been in contact with someone (high risk)
- That Alice has been in contact with Bob (extreme risk)
Each risk level requires different countermeasures. Protecting against (1) requires hiding the existence of communication. Protecting against (4) requires complete persona separation.
Practical implementation:
- Separate devices for separate compartments (never use the same laptop for personal and operational activity)
- Separate locations for separate compartments (never conduct operational communications from home)
- Separate identities for separate compartments (no shared usernames, emails, or behavioral patterns)
- Never cross-contaminate between compartments
- If a compartment is compromised, the others survive
3.4 The Cost of Poor Compartmentation
Ross Ulbricht ran the Silk Road marketplace for over two years. He was caught because his operational persona (Dread Pirate Roberts) and his personal identity (Ross Ulbricht) shared:
- Ideology (Austrian School of Economics, mises.org)
- Geographic location (San Francisco)
- Timezone (evident in posting patterns)
- Technical interests (PHP, Bitcoin security)
- An email address (posted from the "altoid" operational persona on BitcoinTalk)
- Server access location (frosty@frosty.com admin accessed Silk Road server from 500 feet from Ulbricht's Gmail login location)
Any ONE of these links might not have been sufficient. Together, they were damning. Compartmentation must be total or it is meaningless.
Chapter 4: The Operational Phase Framework
4.1 The Five Phases
Every operation — cyber or physical, offensive or defensive — moves through five distinct phases:
- Target Selection — Choosing what to attack/collect/influence
- Planning & Surveillance — Gathering information, developing the plan
- Deployment — Moving into position, preparing infrastructure
- Execution — Conducting the operation
- Escape & Evasion — Getting away clean
Most failures happen because phases 4 and 5 receive less attention than phases 1-3. The Grugq notes that "all real criminals know that the most important part of an operation is the getaway." Hackers and amateur operatives routinely neglect the escape phase.
4.2 Phase Analysis
Target Selection: This is where strategy meets intelligence. Poor target selection wastes resources and creates unnecessary exposure. Security forces prioritize identifying people involved in target selection and planning — they are the principals, more valuable than the people who execute.
Planning & Surveillance: The phase where most intelligence collection occurs. Pattern of life analysis, vulnerability assessment, route planning. Also the phase where pre-operational contact creates the most risk. Every meeting, every communication, every reconnaissance visit creates a potential link.
Deployment: Moving from planning to readiness. Infrastructure is activated, teams are positioned, logistics are finalized. This is the point of commitment — once deployment begins, the operation is live.
Execution: The operation itself. Duration should be minimized. The longer you are exposed, the greater the risk. Execute the plan, don't improvise unless the plan fails.
Escape & Evasion: The most neglected and most critical phase. How do you leave the scene? How do you dispose of evidence? How do you break the link between yourself and the operation? How do you return to normal life without anomalous behavior?
4.3 The Harvard Bomb Hoax — Phase Failure Analysis
In December 2013, Harvard student Eldo Kim sent bomb threats to avoid a final exam. His operational analysis through the phase framework:
Target Selection: Correct — buildings where his exam was held. Planning: Minimal — chose Tor Browser Bundle and GuerillaMail. Deployment: Fatal error — used Tor from the Harvard campus network. Execution: Succeeded — emails were sent. Escape & Evasion: Non-existent — no plan for what happens after.
The deployment error was decisive. Using Tor from the campus network reduced the anonymity set from "anyone on the internet" to "Harvard students using Tor at the time the bomb threats were sent." That was a very small number. He was identified within hours.
The lesson: Never take an action that reduces the pool of suspects. If all students are suspects, you only need to avoid narrowing the pool. Using an anonymizing tool from a specific location during a specific time window does exactly the opposite.
Chapter 5: Identity & Persona Management
5.1 The Contamination Problem
Contamination occurs when information from one persona leaks into another. It is the most common cause of identity compromise, and it is almost always caused by convenience or carelessness, not by technical failure.
Types of contamination:
- Direct link: Using a personal email from an operational account (Ulbricht)
- Behavioral link: Both personas share ideology, writing style, or interests (DPR/Ulbricht)
- Geographic link: Accessing both personas from the same location (Ulbricht)
- Temporal link: Both personas are active at the same times, inactive at the same times
- Technical link: Same device, same browser fingerprint, same IP, same VPN exit node
5.2 Persona Separation Rules
- Separate devices. Never use the same physical device for different personas. If this is impossible, use separate VMs with separate network paths.
- Separate locations. Never access different personas from the same physical location. This includes WiFi networks — your home WiFi MAC address is unique.
- Separate behaviors. Different personas should have different writing styles, different interests, different posting schedules, different political views.
- Separate infrastructure. Different email providers, different VPNs, different cryptocurrency wallets, different SIM cards.
- Never cross-contaminate. Never copy-paste between persona environments. Never visit a personal site from an operational browser. Never use operational tools from a personal device.
5.3 Isolation and Its Dangers
Underground operatives face a severe psychological challenge: isolation. The security requirements of deep cover preclude normal social interaction. Ulbricht's case illustrates what happens:
- He rented a room under an assumed name
- He had no "mainstream" social circle to calibrate against
- His only social interaction was with Silk Road forum members and admins
- Social isolation drove him toward ideological extremism
- Isolation degraded his security discipline over time
Mitigation: Maintain a cover social life that provides genuine human connection. Have non-operational friends. Exercise. Maintain routines that keep you grounded in normal reality. The underground life, sustained too long in isolation, produces bad judgment.
Chapter 6: Communications Security
6.1 The Four Goals
Secure communications must achieve four objectives, in ascending order of difficulty:
- Content protection — Make the message unreadable to unauthorized parties. Solved by encryption.
- Meaning protection — Make the message's significance inaccessible even if the text is readable. Addressed by codes.
- Traffic analysis resistance — Prevent the adversary from knowing that a connection exists between the communicating parties. Very difficult.
- Channel concealment — Prevent the adversary from knowing that the communication channel exists at all. Extremely difficult.
Most people stop at goal 1. Encryption is the easy part. Goals 3 and 4 are where operations succeed or fail.
6.2 Metadata Kills
The content of your message matters less than the fact that you sent it. Modern intelligence services collect metadata — who communicated with whom, when, for how long, from where — at massive scale. Metadata reveals:
- Organizational structure (who talks to whom)
- Operational tempo (communication frequency increases before operations)
- Geographic patterns (where calls originate)
- Relationships (contact frequency indicates relationship strength)
Encryption protects content. It does not protect metadata. The CIA Lebanon rollup demonstrates this: Hezbollah identified CIA agents not by breaking encryption but by identifying phones that were used exclusively for handler communication. The pattern — dedicated device, static location, predictable activation schedule — was the vulnerability.
6.3 The Telephone Rules (Modern Application)
Dulles warned about the telephone in the 1950s. The Grugq updated these warnings for the mobile era:
Physical identifiers:
- IMEI — unique hardware identifier for the phone device itself
- IMSI — unique subscriber identifier on the SIM card
- Both must be changed together to break the link
Location tracking:
- 4 location data points will uniquely identify 90% of mobile phone users
- Your mobility pattern (home → commute → work → gym) is as unique as a fingerprint
- "Mirroring" — when two devices travel together — links them permanently
Burner phone rules:
- Phone OFF means battery removed, SIM removed, placed in shielded bag
- Never power on at locations associated with you — home, work, friends
- Never turn on your burner at the same location as your personal phone
- Never let your personal phone go OFF when your burner goes ON (paired events are indicators of relation)
- Never carry phones for different compartments together
- Store the burner away from your home
- Keep your personal phone showing normal usage pattern at all times
- Buy with cash, never register, discard after limited use
6.4 Codes vs. Encryption
Codes protect meaning. Encryption protects content. They serve different purposes.
The US Army COMSEC handbook warns against "talking around" — trying to discuss sensitive subjects using circumlocution. "Self-made reference systems" rarely work because "few people are clever enough to refer to an item of information without actually revealing names, subjects, or other pertinent information."
Practical code discipline:
- Keep codes generic and consistent
- Limit codes to simple signaling (go/no-go, danger/safe, meeting confirmed/canceled)
- Do not attempt to discuss complex operational details via code
- Pre-arrange all codes before the operation begins
- Use different code systems for different compartments
Chapter 7: The STFU Principle
7.1 The Rule
If someone is not actively sharing the risk of an operation, they have no need to know about it. Period.
This is the single most violated principle in operational security. People talk. They talk because they are proud, because they are scared, because they are drunk, because they want to impress someone, because they need to process what they've experienced. Every word spoken to someone outside the operation is a potential compromise.
7.2 The Morris Worm — Case Study in Talking
Robert Morris created the first major internet worm in 1988. He was brilliant. He was also incapable of keeping quiet.
Morris briefed his friends on all aspects of the worm: how it was developed, how it worked, what vulnerabilities it exploited. At one meeting at a Legal Seafood restaurant, he was so excited that "he literally jumped up on a table pacing back and forth on the table explaining how it worked."
His friends were subpoenaed. They testified. Morris was convicted.
His lawyer later reflected: "He did testify that he wrote the worm. He came in and testified, 'I did it, and I'm sorry.' I turned to my co-counsel and asked, 'Should I prove he didn't do it or he's not sorry?'"
7.3 Need-to-Know Evaluation
Before sharing any operational information, ask:
- Is this person actively sharing the risk of this operation?
- Do they need this specific piece of information to perform their role?
- Will withholding this information degrade their ability to function?
If the answer to any of these questions is no, do not share. Even within the operation, restrict knowledge to the specific aspects each person needs. The team driver does not need to know the exfiltration plan. The lookout does not need to know the target's name.
Chapter 8: Informant Awareness
8.1 The Oldest Threat
Technical surveillance can be defeated with tradecraft. Cryptography can protect communications. Compartmentation can contain damage. But none of these measures protect against an informant — a member of your own organization who reports to the adversary.
When a group with robust security practices is compromised and the technical indicators don't explain how, the answer is almost always an informant.
8.2 The PIRA Lesson
The Provisional IRA in the 1970s demonstrated every form of self-incrimination possible:
- Singing IRA songs in pubs (public affiliation)
- Boasting about operations while drunk (direct disclosure)
- Responding to inquiries with "a nod and a wink" (confirmation)
- Attending pro-IRA rallies (surveillance opportunity)
- Socializing with operational colleagues off-duty (pre-operational contact)
British security forces exploited this systematically. Known members (identified through public behavior) were monitored. Their social contacts were mapped. Unknown members were identified through association. The entire organizational graph was eventually exposed through link analysis starting from a handful of pub boasters.
The lesson is simple: Never publicly display operational affiliation. Never socialize with operational contacts in personal contexts. Never discuss operations outside of operational necessity. Alcohol is a vulnerability, not a social lubricant.
8.3 Detection Indicators
Signs that an organization may have been penetrated:
- Opposition demonstrates knowledge of operations that should be compartmented
- Arrests or disruptions that don't match the opposition's known technical capabilities
- Indictments with unusually specific geographic information about members
- Operations fail in ways that suggest foreknowledge
- "Lucky" coincidences that benefit the opposition repeatedly
The Grugq's analysis of the Lauri Love hacking case: "The lack of information on how Mr Love was caught, along with the revelation of good security practices suggests one thing: informant."
8.4 Anti-Informant Measures
From the Reservoir Dogs SOP (Fatah/BSO methodology):
- Assigned aliases — Random, per-operation, prevents pattern development
- Just-in-time assembly — Form team immediately before operation
- Dedicated support teams — Each function compartmented
- Strict need-to-know — No one knows the complete plan except the principal
- Post-operation dispersal — Team disbanded, infrastructure destroyed
These measures limit the damage an informant can cause but do not prevent infiltration. The only true defense against informants is rigorous vetting and the acceptance that some level of penetration risk is inherent in any organization with human members.
Chapter 9: Case Studies
9.1 Silk Road — The Complete Failure
Timeline: 2011-2013 Actor: Ross Ulbricht (Dread Pirate Roberts) Outcome: Arrested, convicted, life sentence
What went right:
- Tor hidden service for the marketplace
- Bitcoin for financial transactions
- Pseudonymous identity (DPR)
What went wrong (everything else):
- Used personal email from operational persona (altoid → rossulbricht@gmail.com)
- Shared ideology between personas (Austrian economics on both accounts)
- Same geographic location (San Francisco) and timezone
- Server admin access from same physical location as personal Gmail
- Social isolation drove extremism and poor judgment
- Sought social validation on forums, lowering security discipline
- No backstopping of operational personas
- Used same computer for personal and operational activity
Key lesson: Compartmentation is binary. It either exists or it doesn't. A single contamination link between personas makes all other security measures irrelevant.
9.2 Harvard Bomb Hoax — Anonymity Set Reduction
Timeline: December 2013 Actor: Eldo Kim (Harvard student) Outcome: Identified within hours
The operation: Send bomb threats to cancel a final exam. The method: Tor Browser Bundle + GuerillaMail from Harvard campus. The failure: Using Tor from the campus network reduced the suspect pool to Harvard Tor users during the threat window — a very small number.
Key lesson: Anonymity tools provide anonymity only within the set of users at that location and time. Smaller the set, less the anonymity. He should have used a nearby cafe with no connection to the university.
9.3 CIA Lebanon — Phone Pattern Analysis
Timeline: 2011 Actor: CIA spy network Adversary: Hezbollah counter-intelligence Outcome: Entire network rolled up
The tradecraft: Agents used dedicated mobile phones for handler communication. Phones kept at static locations. Pre-arranged meeting at fixed location.
The failure: Hezbollah identified the pattern — dedicated devices that activated only for specific contacts, from specific locations, at predictable intervals. The pattern, not the content, was the vulnerability.
Key lesson: Encryption protects content. Anonymity protects identity. Systems based on secrecy alone — where usage itself is anomalous — attract attention and enable pattern analysis. Anonymity must come before encryption.
Chapter 10: The OPSEC Checklist
10.1 Pre-Operation
- Threat model defined (who is the adversary, what are their capabilities?)
- OPSEC level calibrated to adversary strength
- Operational compartmentation established
- Separate devices for separate compartments
- Separate identities with no cross-contamination
- Communication plan established (methods, schedules, emergency protocols)
- Cover story developed and backstopped (if applicable)
- Need-to-know enforced for all participants
- SDR procedures planned (if physical component)
- Escape and evasion plan developed
- Evidence disposal plan developed
- Emergency abort criteria defined
10.2 During Operation
- SDR executed before any operational activity
- Cover maintained at all times
- Communications limited to operational necessity
- No unnecessary logs or records created
- Devices used only for designated compartment
- No pre-operational contact with team members outside operational context
- Counter-surveillance awareness maintained
- Anomalies noted and assessed
10.3 Post-Operation
- Operational infrastructure sanitized or destroyed
- Temporary identities retired
- Devices wiped or physically destroyed
- No post-operational contact with team members
- No discussion of operation with anyone outside need-to-know
- Return to normal behavioral patterns without anomalies
- After-action review conducted (lessons learned, security assessment)
- STFU
This manual is a living document. Content will be enriched as additional sources are collected and analyzed.