Files
mosaic/output/manuals/03_Covert_Communications.md
T

51 KiB

Manual 03: Covert Communications

Mosaic Reference Library -- Operational Tradecraft Series Compiled from declassified CIA manuals, Grugq OPSEC lectures, Allen Dulles operational writings, JSOU clandestine networks research, and open-source intelligence tradecraft.

Classification: UNCLASSIFIED -- compiled from publicly available and declassified sources. Original classification markings retained for provenance only.


Table of Contents

  1. COMSEC Fundamentals
  2. Dead Drops
  3. Brush Passes
  4. Signal Sites
  5. Cut-Outs and Impersonal Communications
  6. Digital COMSEC
  7. Codes and Coded Communications
  8. Telephone Discipline
  9. Communication Planning

Chapter 1: COMSEC Fundamentals

1.1 The Communication Problem

Communication is the lifeblood of any intelligence operation and its greatest vulnerability. Every contact between an operative and their handler, between cells of a network, between a source and a case officer, creates a moment of exposure. The opposition does not need to read the content of a message to extract intelligence from it -- the mere existence of communication between two parties can be sufficient to destroy an operation.

The Grugq articulated a hierarchy of communication security that distinguishes between what most people think COMSEC means and what it actually requires. Most people think of encryption -- making messages unreadable. That is necessary but radically insufficient.

1.2 The Four Goals of Secure Communications

Secure communications must achieve four distinct goals, listed in order of increasing difficulty and decreasing familiarity:

Goal 1: Unreadable Content

The content of the message cannot be read by an interceptor. This is classical encryption and is the easiest of the four goals to achieve. Modern cryptographic tools (AES-256, Signal Protocol, PGP) provide content security that is, for practical purposes, unbreakable through mathematical attack.

Achieving Goal 1 alone provides a false sense of security. Encrypted communications between two known parties still reveal that those parties are communicating, when they communicate, how often, and how much data they exchange.

Goal 2: Inaccessible Meaning

Even if content is intercepted and decrypted, the meaning of the message is not apparent. This is the domain of codes, where pre-arranged meanings are assigned to innocuous words or phrases. A message reading "The weather in Madrid is beautiful" might mean "The dead drop is loaded."

Goal 2 supplements Goal 1. If encryption fails (key compromise, implementation flaw, quantum computing), coded meaning provides a second layer. However, codes are fragile -- they require pre-arrangement, they cannot convey complex or unanticipated information, and their use can be detected through statistical analysis of language patterns.

Goal 3: Avoid Traffic Analysis

No link can be established between the communicating parties. This is where most communications security fails. Traffic analysis does not care what you said. It cares that you said something to someone, at a particular time, from a particular location.

Traffic analysis reveals:

  • Who communicates with whom (social graph mapping)
  • When they communicate (timing patterns, activity cycles)
  • How much they communicate (relationship intensity)
  • Where they communicate from (geographic correlation)
  • How their communication patterns change (events, operations, meetings)

The CIA spy ring in Lebanon was destroyed not through cryptanalysis but through traffic analysis. Agents had dedicated mobile phones kept at static locations with pre-arranged meetings at fixed sites (a Pizza Hut in Beirut). The phones themselves created patterns -- dedicated devices at fixed locations, activated on predictable schedules. Hezbollah's counterintelligence did not need to decrypt a single message. The metadata was sufficient.

Defeating traffic analysis requires that no observable link exists between the sender and receiver. This means no shared communication channel, no correlated timing, no geographic proximity, and no behavioral pattern that connects the two parties.

Goal 4: Avoid Knowledge of Channel Existence

No one knows that a communication channel exists at all. This is the highest and most difficult level of COMSEC. If the opposition does not know you are communicating, they cannot analyze traffic, attempt decryption, or investigate the relationship.

Steganography (hiding messages in images or other media), dead drops (no electronic channel at all), and short-range burst transmissions (SRAC) all aim to achieve Goal 4. The communication happens in a way that leaves no trace that any communication occurred.

1.3 The Hierarchy of Importance

Goals 1 and 2 (content security) are what most people focus on. Goals 3 and 4 (channel security) are what actually matter in operational environments, because they are harder to achieve and their failure is more immediately catastrophic.

An intercepted but encrypted message is a problem. A pattern of communication between an operative and a source that enables identification of both parties is a disaster.

The Grugq summarized this principle: "Systems based purely on secrecy [encryption] have anomalous usage that attracts attention." An encrypted app on a phone is itself an indicator. A phone that only turns on for brief periods at specific locations is itself suspicious. Encryption protects content; it does not protect against the inference that something worth encrypting is happening.

1.4 The Anonymity-First Principle

The correct priority for operational communications is: anonymity first, then encryption.

This means:

  1. First, ensure that no link can be established between the communicating parties (Goal 3)
  2. Then, ensure that no one knows the communication is happening at all (Goal 4)
  3. Then, encrypt the content (Goal 1)
  4. Then, code the meaning (Goal 2)

This reversal of conventional thinking is the fundamental lesson of every modern intelligence compromise. The FBI did not break Silk Road's encryption -- they followed the metadata. Hezbollah did not decrypt CIA communications in Beirut -- they followed the phones. The NSA's mass surveillance programs are overwhelmingly focused on metadata collection, not content interception, because metadata is more operationally useful.


Chapter 2: Dead Drops

2.1 What a Dead Drop Is

A dead drop is a pre-arranged concealment location where one party deposits material for another to retrieve at a later time. The defining characteristic is that the two parties never meet. There is no direct contact, no shared physical space at the same time, and no communication channel beyond the dead drop itself and its associated signaling system.

Dead drops address Goals 3 and 4 simultaneously. There is no electronic communication to intercept or analyze, and if the site is well chosen, there is no visible indication that a communication is taking place.

2.2 Site Selection

The success or failure of a dead drop operation depends overwhelmingly on site selection. A poorly chosen site compromises the operation regardless of how well it is serviced.

Selection Criteria

  1. Accessible without suspicion. Both parties must be able to visit the site as part of normal, plausible daily activities. A site that requires either party to make an unusual trip or visit an area inconsistent with their cover creates exposure.

  2. Natural concealment opportunity. The site must offer a place to hide material that is accessible but not casually discoverable: a gap in a stone wall, a hollowed brick, a magnetic container behind a metal railing, loose flagstone with a cavity beneath, the underside of a park bench.

  3. Not under surveillance. The site must not be covered by CCTV cameras, not within the sight line of security guards, and not in an area with high passive observation (e.g., a cafe with outdoor seating facing the site).

  4. Away from regular foot traffic but not isolated. A completely deserted location makes anyone who visits it conspicuous. A moderately trafficked park, trail, or residential street provides the cover of normal activity without the risk of accidental discovery.

  5. Memorable but not distinctive. Both parties must be able to locate the exact spot reliably without maps or GPS (both of which create records). The site should be near a landmark but not at the landmark itself.

  6. Weather resistant. Material must survive exposure to rain, snow, temperature extremes, and humidity. Use waterproof containers.

  7. Multiple approach routes. Both parties should have more than one plausible path to the site, enabling SDR variations.

Site Survey Procedure

Before a dead drop site is approved for operational use:

  1. Visit the site at different times of day and different days of the week to assess traffic patterns and surveillance exposure
  2. Identify the specific concealment location and test that it can accommodate the expected material
  3. Walk the approach routes and identify SDR elements (choke points, observation posts, direction changes)
  4. Photograph the site (discreetly) for the other party's recognition
  5. Identify a signal site that is near enough to be practical but not so close that servicing the signal and servicing the drop look related

2.3 Dead Drop Containers

The container must protect the material from environmental damage and casual discovery:

  • Magnetic containers that attach to metal surfaces (undersides of benches, inside drainpipes, behind electrical boxes)
  • Faux rocks and bricks that blend with the environment
  • Waterproof capsules for burial or submersion
  • Modified everyday objects (a dead battery, a crushed soda can, a used coffee cup) that would not attract attention if discovered

The container should be camouflaged to match its surroundings. A bright metal box in a hedge is obviously planted. A dirty container that looks like trash is invisible.

2.4 Dead Drop Procedures

Loading

  1. Conduct a full SDR before approaching the site
  2. Arrive at the site through a natural-looking route consistent with cover activity
  3. Confirm the site is not under observation (look for new cameras, unusual vehicles, people lingering)
  4. Load the container with the material
  5. Place the container in the concealment location
  6. Depart through a different route than arrival
  7. Set the load signal at the pre-arranged signal site

Clearing (Retrieval)

  1. Check the signal site first -- if the load signal is not set, do not approach the dead drop
  2. Conduct a full SDR before approaching the site
  3. Arrive through a natural route
  4. Retrieve the container
  5. Depart through a different route
  6. Clear the load signal and optionally set a receipt signal
  7. Do not open or examine the material until in a secure location

Timing

  • Load and clear at different times -- never within the same hour, ideally on different days
  • Do not establish a pattern (every Tuesday at 3 PM)
  • The clearing party should retrieve within the agreed window -- material left too long risks discovery or degradation
  • If the material is not retrieved within the agreed window, the loading party must assume compromise and abort

2.5 Dead Drop Security

  • Never revisit a compromised site. If there is any indication that a site has been discovered -- container missing, container moved, signs of disturbance, new surveillance in the area -- the site is burned permanently.
  • Vary sites regularly. Even sites that appear secure develop risk over time through environmental changes, new construction, new camera installations, or pattern development.
  • Dust containers with detection material (UV powder, marked adhesive) that would transfer to anyone who handles the container, providing evidence of compromise.
  • Maintain a reserve of pre-surveyed sites so that losing one site does not interrupt operations.
  • Separate the signal site from the drop site by enough distance that a watcher on one cannot observe the other.

Chapter 3: Brush Passes

3.1 What a Brush Pass Is

A brush pass is a brief, planned physical exchange that occurs as two parties walk past each other in a public space. The transfer takes less than one second. Neither party stops, neither acknowledges the other, and to any observer, nothing has occurred beyond two strangers passing on a sidewalk.

Where a dead drop separates the parties in time (they never occupy the same space simultaneously), a brush pass separates them in attention -- they are in the same space at the same time but the interaction is so brief and so natural that it is effectively invisible.

3.2 The Technique

Physical Mechanics

  1. Approach from opposite directions along a path in a crowded area
  2. Item is palmed -- held in the hand in a way that is invisible to observers. The item must be small enough to palm: a USB drive, a folded note, a memory card, a key
  3. Moment of transfer: As the parties pass each other, a brief hand contact transfers the item. This can be a handshake-like grip, a brush of fingers, or a pass through a carried bag or newspaper
  4. Neither party stops or reacts. Both continue walking in their original direction at their original pace
  5. Neither party acknowledges the other -- no eye contact, no nod, no verbal exchange

Environmental Requirements

The brush pass requires a specific environment to work:

  • Crowd density. Enough people that two individuals passing close together is normal, not remarkable. Markets, subway platforms, busy sidewalks, shopping districts, transit stations, and event venues provide ideal cover.
  • Movement flow. Both parties must be walking in a natural flow of pedestrian traffic. Two people walking directly toward each other on an empty sidewalk is conspicuous.
  • No surveillance chokepoint. The pass location should not be under a camera with a clear angle on the hands of both parties.

3.3 Practice

A brush pass requires significant practice to execute smoothly. A fumbled transfer -- dropped item, visible hand contact, unnatural hesitation -- defeats the entire purpose.

Practice regimen:

  1. Solo palm practice. Practice palming objects of various sizes until the hand position is natural and the object is invisible.
  2. Approach timing. Practice walking at normal speed and arriving at the transfer point at the correct moment relative to the other party.
  3. Transfer practice. Practice the hand contact with a partner until the transfer is smooth, quick, and produces no visible reaction from either party.
  4. Distressed practice. Practice after physical exertion, in uncomfortable weather, while carrying bags, and while wearing gloves.
  5. Crowd practice. Practice in actual crowd environments to develop comfort with proximity, timing, and noise.

3.4 Brush Pass Security

  • Conduct SDR before the pass -- both parties must be confident they are not under surveillance
  • Have a pre-arranged abort signal -- if either party detects surveillance, the pass does not happen, and both parties continue as if they were never going to meet
  • The brush pass location should not be the same location every time
  • Do not combine brush passes with verbal communication -- the pass is the exchange, nothing more
  • If the item is critical, have a fallback plan (dead drop, secondary brush pass location) in case the primary attempt is aborted

Chapter 4: Signal Sites

4.1 The Purpose of Signals

A signal site is a pre-arranged location where a physical indicator communicates a binary message: go/no-go, loaded/cleared, danger/safe, ready/not ready. Signals are the triggering mechanism for other tradecraft -- they tell a party when to service a dead drop, when to show up for a meeting, or when to abort.

Signals exist because the alternative -- communicating these messages electronically -- creates the traffic analysis vulnerability that Goals 3 and 4 seek to avoid. A chalk mark on a lamppost generates no metadata.

4.2 Types of Signals

Mark Signals

A visible mark placed on a surface:

  • Chalk mark on a wall, curb, mailbox, or lamppost
  • Thumbtack on a bulletin board (color or position conveys meaning)
  • Tape on a traffic sign, utility pole, or railing
  • Grease pencil mark on a window

Mark signals are easy to set and check but vulnerable to weather (rain washes chalk) and environmental cleaning (maintenance crews remove marks).

Placement Signals

An object placed in a specific position:

  • Flower pot in a specific window (present = go, absent = no-go)
  • Car parked in a specific spot
  • Newspaper left on a specific bench
  • Stone placed on a specific wall

Placement signals are more weather-resistant than marks but require the signaler to have access to the object and location.

State Signals

The state of an existing object:

  • Window blind up versus down
  • Gate open versus closed
  • Specific item displayed in a shop window
  • Light on versus off in a specific window

State signals are the least conspicuous because they involve no foreign object or mark -- the signal is embedded in the normal state of the environment.

4.3 Signal Site Selection

Signal sites must satisfy specific requirements:

  1. Visible in normal passing. Both the setter and the checker must be able to interact with the signal site as part of a natural route. The checker should not need to stop, stoop, or change direction to observe the signal. A chalk mark at eye level on a wall that the operative walks past daily is ideal.

  2. Not under dedicated observation. Avoid signal sites under CCTV or in areas with security guards. Avoid locations where a regular observer (a shopkeeper, a parking attendant) would notice someone setting or checking the signal.

  3. Weather resistant. If using chalk, choose a sheltered surface (under an overhang, inside a phone booth, on the interior face of a wall). If using placement signals, ensure the object will not be moved by wind, cleaning crews, or passersby.

  4. Unambiguous. The signal must be clearly present or clearly absent. A faded chalk mark that might or might not still be visible creates dangerous ambiguity.

  5. Separate from the operational site. The signal site should not be close enough to the dead drop, meeting location, or operational target that checking the signal could lead surveillance to the operational site.

4.4 Signal Protocols

Two-Signal System

A basic protocol uses two signals:

  • Load signal: Set by the loader after placing material in a dead drop. Checked by the retriever before approaching the drop.
  • Receipt signal: Set by the retriever after successfully clearing the dead drop. Checked by the loader to confirm the material was received.

Three-Signal System

A more robust protocol adds a danger signal:

  • Load signal: Same as above
  • Receipt signal: Same as above
  • Danger signal: Set by either party to indicate that the operation is compromised, the site is under surveillance, or an emergency has occurred. The danger signal cancels all pending operations and may activate emergency protocols.

Signal Timing

  • Signals should be set and checked within agreed windows
  • A signal that has been set for longer than the agreed window should be treated as potentially compromised (either the other party has been prevented from responding, or the signal has been discovered)
  • Do not check signals obsessively -- repeated visits to the signal site create a pattern

4.5 Signal Discipline

  • Each signal has one and only one meaning. Overloading signals with multiple meanings creates confusion and operational risk.
  • Confirm signals are separate from action signals. A signal that says "the drop is loaded" is different from a signal that says "I acknowledge receipt." They use different sites or different marks.
  • Regularly rotate signal sites, just as drop sites are rotated.
  • If a signal site may have been observed (someone was watching when you set the mark, the area has new cameras), burn the site.

Chapter 5: Cut-Outs and Impersonal Communications

5.1 The Principle of Indirect Contact

Impersonal communication ensures that two individuals who need to exchange information never come into direct contact. This is the foundational organizing principle of clandestine networks: if the handler and the source never meet, the compromise of one does not directly expose the other.

The methods divide into passive (no real-time link between parties) and active (real-time communication channel exists).

5.2 Passive Methods

Passive methods generate no electronic signature and create no real-time connection between the parties:

Dead Drops

Covered in Chapter 2. The paradigmatic passive method: one places, another retrieves, no contact.

Live Drops

A live drop uses a human intermediary -- a cut-out -- to physically carry material from one party to another. The cut-out knows neither the identity nor the role of the parties. They receive a package from a stranger and deliver it to another stranger.

Live drops are more flexible than dead drops (no fixed site required) but introduce the risk of the cut-out being identified, followed, or compromised.

Mail Drops

Material is sent through the postal system to a pre-arranged address. The address is controlled by the receiving party (or by a further cut-out) and is not linked to either party's true identity.

Mail drops require careful attention to postal inspection triggers:

  1. Use business-to-individual format, not person-to-person
  2. Use typed labels, not handwritten
  3. Weight should not be round metric numbers
  4. Return address must be real and verifiable (backstopped)
  5. Packaging should look professional and new (not reused)
  6. Avoid heavy taping
  7. Do not ship from drug-source zip codes
  8. Use packaging consistent with the stated business context

These criteria are derived from the FBI drug mail profile -- the same triggers that flag drug shipments will flag suspicious intelligence packages.

Clandestine Signals

Covered in Chapter 4. Signals themselves are a form of impersonal communication -- they convey a binary message without any direct contact between the parties.

5.3 Active Methods

Active methods create a real-time or near-real-time communication channel. They offer more flexibility and speed but generate detectable signatures:

Radio

Short-wave radio, burst transmissions, and numbers stations have been used since World War II. Radio provides one-way communication (numbers station to agent) without any connection infrastructure. The agent needs only a commercially available radio receiver, which is impossible to distinguish from innocent use.

Telephone

Covered in Chapter 8. Telephone communication is fast and flexible but creates extensive metadata records.

Internet

Covered in Chapter 6. Digital communications offer speed and capacity but generate metadata and create electronic links between parties.

5.4 The Cut-Out

A cut-out is a person who serves as an intermediary between two parties who cannot or should not meet directly. The cut-out knows their task but not the identities or roles of the people they connect.

Properties of a Good Cut-Out

  • No known connection to either party or to the intelligence operation
  • Plausible reason for movement in the areas where they operate (a delivery driver, a commuter, a regular at a certain cafe)
  • Unaware of the operational significance of the material they transport
  • Reliable without being informed -- will follow instructions consistently
  • Replaceable -- the operation does not depend on any single cut-out

Courier Considerations

Couriers are the most secure form of active material transfer. They physically carry material from point A to point B, leaving no electronic trace.

Operational experience, particularly from Middle Eastern and Irish clandestine networks, has shown that women and children decrease suspicion at checkpoints. A woman carrying a shopping bag through a military checkpoint faces less scrutiny than a military-age male with a backpack. This is not an endorsement of involving non-combatants -- it is a recognition of how checkpoint profiling works and how adversaries exploit it.

5.5 Cellular Network Structure

The most sophisticated application of cut-out principles is the cellular network, where an entire organization is structured so that members of one cell know only their immediate contacts and the cell's internal members. If a cell is compromised, the damage is contained to that cell and its immediate links.

JSOU research on clandestine networks found that organizations using this structure with excellent tradecraft can remain hidden even from expert adversaries. Destroyed cells are replaced within weeks from a hidden reserve structure. The key insight: the visible (operational) cells are at the periphery and are expendable. The hidden infrastructure that recruits, trains, and deploys new cells is the organization's actual center of gravity.

Counterintelligence should therefore "attack the clandestine infrastructure, not just visible cells" -- and conversely, clandestine organizations should protect their regenerative infrastructure above all else.


Chapter 6: Digital COMSEC

6.1 The Digital Communications Environment

Digital communications offer unprecedented speed, capacity, and global reach. They also offer unprecedented surveillance capability to any adversary with access to network infrastructure, device compromise tools, or metadata analysis programs.

The challenge of digital COMSEC is that the technology simultaneously enables secure communication and enables surveillance of that communication. Every solution creates new attack surfaces.

6.2 SRAC (Short Range Agent Communications)

SRAC represents the closest digital analog to a dead drop -- a burst communication system that operates over extremely short range (typically infrared or short-range WiFi) and transmits in less than one second.

How It Works

  1. The agent carries a small transmitter device
  2. A concealed receiver is placed at a pre-arranged location (inside a building wall, in a vehicle, mounted inconspicuously)
  3. The agent walks past the receiver at normal speed
  4. When in range (typically a few meters), the device transmits an encrypted data burst lasting less than one second
  5. No internet connection is required
  6. The receiver stores the data for later retrieval by the handler through a separate channel

Why SRAC Matters

SRAC achieves all four COMSEC goals simultaneously:

  • Goal 1: Content is encrypted
  • Goal 2: Even if decrypted, the meaning can be coded
  • Goal 3: No traffic analysis is possible -- there is no persistent communication channel to monitor
  • Goal 4: The burst is so brief and short-range that detecting its existence requires a receiver positioned within meters at the exact moment of transmission

SRAC is the gold standard for agent communications in hostile environments. Its limitation is that it requires physical proximity (the agent must walk past the receiver) and physical infrastructure (the receiver must be placed and maintained).

6.3 Burner Phone Discipline

Mobile phones are ubiquitous and therefore tempting for operational communication. They are also the most comprehensively surveilled communication devices in existence.

The Grugq's analysis identifies the critical principle: a mobile phone has multiple identifiers beyond the SIM card. Replacing the SIM is insufficient. The phone itself has an IMEI that is transmitted with every connection. The phone's location pattern, calling pattern, and even the user's voice are fingerprints.

Burner Phone Rules

  1. Phone OFF means battery out, SIM out, and ideally in a shielded bag. A phone that is "off" but has a battery can still be activated remotely and can still be tracked by some systems.

  2. Never use at locations associated with you. Home, work, regular social locations -- any phone powered on at these locations can be linked to the person who lives or works there.

  3. Never turn on at the same location as your real phone. Powering on a burner at a location where your real phone has established a pattern creates an immediate correlation.

  4. Do not let your real phone go OFF when the burner goes ON. Paired events -- where one phone deactivates as another activates -- are powerful indicators of relation. Keep the real phone showing normal usage patterns while the burner is operational.

  5. Never carry phones for different compartments together. Co-location of devices links them. If two phones are always at the same tower at the same time, they belong to the same person or the same car.

  6. Four locations will identify 90% of people. Mobility patterns are unique. A burner phone that visits the same home, office, gym, and grocery store as a known phone is trivially attributable.

  7. Store the burner away from home. If the burner is at a known residential address overnight, it is linked to the resident.

  8. Keep the real phone showing normal usage. Sudden gaps in the real phone's activity correlate with burner phone activation.

Burner Phone Summary

Burner phones are useful for signaling only -- brief, low-content communications that do not require extended conversation. They are not suitable for substantive communication because the duration and pattern of use creates exploitable metadata.

Buy with cash. Activate from a neutral location. Never power on near home or work. Use briefly. Destroy after a single operational use or a short operational period.

6.4 Tor, VPNs, and Network Anonymity

Network anonymity tools provide Goal 3 (traffic analysis resistance) for digital communications but with significant caveats.

Tor

Tor routes traffic through multiple relays, hiding the user's IP address from the destination and hiding the destination from the user's network. It is the best available tool for network-level anonymity but has known limitations:

  • Tor is detectable. Your ISP can see that you are using Tor, even if they cannot see where you are going. In an environment where Tor use itself is suspicious, this is a Goal 4 failure.
  • Anonymity set matters. Tor provides anonymity within the set of Tor users at your location and time. At a university with 30,000 students, many of whom use Tor, the anonymity set is large. At a small office where you are the only Tor user, the anonymity set is one. The Harvard bomb threat case demonstrated this: using Tor from campus during a bomb threat reduced the suspect pool to campus Tor users during the threat window.
  • Traffic correlation. A global adversary who can observe both the entry and exit of Tor traffic can correlate timing to deanonymize users. Nation-state adversaries may have this capability.

VPNs

VPNs hide traffic from the local network but require trust in the VPN provider. The VPN provider sees all traffic. VPNs are useful for evading local network surveillance but do not provide anonymity against a motivated adversary who can compel the VPN provider to produce records.

Operational Guidance

  • Use Tor from clean devices at locations with large anonymity sets
  • The PORTAL approach (dedicated hardware Tor gateway) prevents accidental bypass -- all traffic is forced through Tor at the network level, and the user cannot make a mistake that reveals their real IP
  • Remove WiFi cards from operational machines to prevent malware from exfiltrating the real IP address
  • Never use anonymization tools from locations associated with your real identity
  • Combine network anonymity with device anonymity (burner laptop purchased with cash)

6.5 Steganography

Steganography hides data within other data -- typically, a message hidden within an image file, audio file, or video. Where encryption makes a message unreadable, steganography makes the message invisible.

Steganography addresses Goal 4 directly. An image posted to a public photo-sharing site that contains a hidden message is indistinguishable from any other image. The communication channel itself is invisible.

Limitations

  • Steganalysis. Sophisticated analysis can detect the statistical anomalies that steganographic embedding creates. This is an arms race between embedding techniques and detection techniques.
  • Capacity. The amount of data that can be hidden without detectable distortion is limited. Steganography is suitable for short messages, not bulk data transfer.
  • Key management. The recipient must know that a steganographic message exists and must have the key/method to extract it. This requires a pre-arranged protocol.
  • Fragility. Image compression, format conversion, or resizing can destroy the hidden message.

Practical Application

Steganography is best used as a channel existence concealment layer on top of encryption. The message is first encrypted (Goal 1), then embedded steganographically in a carrier file (Goal 4), then transmitted through an anonymous channel (Goal 3).

6.6 Identity and Communications Migration

Regular migration of communication platforms and identities creates temporal compartmentation. Old identities and channels are abandoned, creating silos that limit the damage from any single compromise.

The practice:

  1. Change communication platforms (IRC servers, messaging apps, forums) on a schedule
  2. Change identifiers (nicknames, account names, email addresses) with each migration
  3. Do not contaminate between time periods -- old logs from a previous identity cannot be linked to the new one if migration is done properly
  4. Use different encryption keys for each identity period
  5. Abandon old keys and accounts completely -- do not reuse them even if they seem safe

Migration provides plausible deniability and limits the window of exposure for any single compromise.


Chapter 7: Codes and Coded Communications

7.1 The Role of Codes

Codes serve Goal 2 (inaccessible meaning) but they must be understood for what they are and what they are not. Codes are not encryption. They are a layer of meaning protection that supplements encryption and serves specific operational purposes.

7.2 Signaling Codes

The primary operational use of codes is signaling -- conveying pre-arranged binary or limited messages through otherwise innocuous communication:

  • "The weather in Madrid is beautiful" = the dead drop is loaded
  • "I'll be late for dinner" = abort the meeting
  • "Uncle Robert is visiting next week" = new intelligence available
  • A specific emoji in a social media post = ready for contact

Signaling codes must be:

  1. Generic. The coded phrase must sound natural in the context where it will be used. A phrase that is unusual or out of character attracts attention.
  2. Consistent. Each code means one thing. Do not reuse codes for multiple meanings.
  3. Limited to simple binary signals. Go/no-go, yes/no, safe/danger. Codes cannot efficiently convey complex information.
  4. Pre-arranged. Both parties must agree on the code meanings before they are needed. Codes cannot be improvised in real time.

7.3 Why "Talking Around" Does Not Work

There is a persistent temptation to use circumlocution -- "talking around" a classified or sensitive topic -- as a substitute for proper COMSEC. This does not work.

The Grugq's assessment is direct: "Talking around classified subjects does not protect the information." The reasons:

  1. Context makes meaning clear. If two people known to be involved in intelligence are having a conversation where they carefully avoid certain words but clearly discuss an operation, the content is obvious to any analyst.
  2. Circumlocution is itself suspicious. A conversation that dances around a topic is more notable than a direct conversation about an innocuous topic.
  3. Humans are bad at it. Under stress, fatigue, or excitement, people revert to direct language. The circumlocution degrades before the conversation ends.
  4. Recorded conversations can be analyzed at leisure. An analyst with a transcript and unlimited time will extract the meaning from any circumlocution.

The lesson: if information cannot be communicated securely, do not communicate it at all. Do not attempt to communicate it "carefully." Either use proper COMSEC (encryption + anonymity + channel concealment) or wait until you can.

7.4 Self-Made Cipher Systems

The temptation to create a personal cipher system is equally dangerous. Self-made cipher systems rarely work because:

  1. Cryptography is a specialized discipline requiring deep mathematical knowledge
  2. Ciphers that seem strong to their creators are often trivially breakable by professionals
  3. Historical examples (Zodiac killer, various criminal organizations) show that amateur ciphers are routinely broken
  4. Professional cryptographic tools are freely available and provably secure

Do not invent your own encryption. Use established, peer-reviewed cryptographic tools. Codes are for signaling. Encryption is for content protection. These are different functions requiring different solutions.

7.5 Personal Codes for Operational Notes

Dulles recommended that operatives carry no names or addresses in clear and instead use a personal code -- a private notation system that is meaningless to anyone who finds the notebook.

This is a specific, limited application:

  • Phone numbers with digits transposed according to a memorized pattern
  • Names replaced with unrelated words from a private mapping
  • Addresses encoded as coordinates or references to a private key

The purpose is not to defeat a cryptanalyst (any simple substitution code can be broken with effort) but to prevent a casual discoverer -- a pickpocket, a maid, a border agent -- from immediately identifying contacts and addresses.


Chapter 8: Telephone Discipline

8.1 The Dulles Rules

Allen Dulles described the telephone as "the greatest material curse to the profession." His rules for telephone use remain foundational:

  1. Always assume every conversation is listened to. This was true with copper wire taps in the 1940s and is exponentially more true with digital telephony, where calls are routinely intercepted, recorded, transcribed, and stored by multiple intelligence services.

  2. Never dial before thinking out what to say and how to say it. The telephone encourages spontaneous conversation. Spontaneous conversation produces security failures.

  3. Unplug the telephone during confidential conversations. The telephone is a microphone connected to the telephone network. Even when not in a call, it can be activated remotely. Better to have no phone in the room.

  4. Avoid the phone when possible. Make a day's journey instead. If the information is important enough to protect, it is important enough to deliver in person. A face-to-face meeting after an SDR is infinitely more secure than a phone call.

8.2 Modern Application

The underlying principles have not changed. The specific threats have expanded:

Metadata

Modern telephony generates extensive metadata beyond the content of the call:

  • Calling party number and called party number
  • Call duration
  • Cell tower locations for both parties (geographic tracking)
  • IMEI of both devices
  • Time and date
  • Frequency of contact between the numbers

Metadata analysis can map entire networks without intercepting a single word of content. The NSA's bulk metadata collection programs demonstrated that call records alone reveal organizational structure, key nodes, and operational patterns.

Voiceprint

Voice biometrics can identify speakers across calls, even across different phone numbers. If an operative's voice is in a voiceprint database (from a legal intercept, a public speech, or a media appearance), any subsequent phone call can be attributed to them regardless of what phone they use.

Location Tracking

Mobile phones continuously report their location to cell towers. This location data is stored by carriers and is available to intelligence and law enforcement agencies. A phone that is present at a meeting location at the time of a meeting, and is also present at the operative's home address, links the operative to the meeting.

Modern Rules

  1. No substantive communication by phone. Phone calls are for logistics and signaling only. Substantive intelligence discussion happens in person, in a swept location.
  2. No operational discussion even on encrypted calls. Encrypted apps protect content but not metadata. The fact that you called a known intelligence contact using Signal is itself intelligence, regardless of what you discussed.
  3. Phone-free zones for sensitive meetings. All phones -- personal and burner -- remain outside the room during sensitive discussions. A phone in the room is a microphone and a location beacon.
  4. Assume compromise. Design communications plans that remain secure even if phone calls are intercepted and recorded. This means phone calls contain nothing that would be damaging if transcribed and published.

Chapter 9: Communication Planning

9.1 The Communication Plan

Every intelligence operation requires a communication plan -- a pre-arranged structure that defines how, when, and through what channels the parties will communicate. The plan must balance security (minimizing exposure) with reliability (ensuring messages get through) and timeliness (ensuring time-critical information is delivered within the required window).

9.2 Components of a Communication Plan

Primary Channel

The default method of communication for routine exchanges. This should be the most secure method available and the one that has been most thoroughly tested:

  • Dead drops with signal sites for low-tempo, high-security requirements
  • SRAC for agent communications in hostile environments
  • Encrypted digital communications for higher-tempo requirements where network anonymity can be maintained

Alternate Channel

A backup method if the primary channel is unavailable (compromised, disrupted, or impractical for a specific communication):

  • If primary is dead drops, alternate might be a brush pass at a pre-arranged fallback location
  • If primary is digital, alternate might be a physical method (dead drop, courier)

Emergency Channel

A method for communicating that an emergency has occurred -- the operation is compromised, a party is in danger, or immediate action is required:

  • Pre-arranged phone signal (a specific number of rings, then hang up)
  • Emergency signal site (a specific mark at a specific location)
  • Emergency meeting at a pre-arranged time and place
  • A digital signal (a specific post on a public platform)

Emergency channels must be:

  • Simple to activate under stress
  • Monitorable without special equipment
  • Unambiguous in meaning
  • Rarely used (so that their use is clearly an emergency, not routine)

Duress Signal

A signal embedded within normal communication that indicates the communicator is under coercion -- they are being forced to communicate and the content should be treated as hostile disinformation:

  • A specific word or phrase included in a message
  • An agreed-upon deviation from normal protocol (e.g., using a middle initial that is not normally used)
  • A specific error introduced into a coded message

9.3 Communication Frequency

The Security-Timeliness Tradeoff

More frequent communication means faster intelligence delivery but greater exposure. Less frequent communication means better security but risk of stale intelligence and loss of situational awareness.

The frequency decision depends on:

  1. Threat level. In a high-threat environment (hostile counterintelligence is active and capable), communication should be as infrequent as possible. The CIA used 2-4 hour SDRs before any operational activity in Moscow, and high-security operations involved weeks or months of planning with 12-hour SDRs. This pace limits communication to what is truly essential.

  2. Intelligence perishability. Information that is time-critical (tactical intelligence, warning intelligence) requires faster channels. Strategic intelligence that remains valid for weeks or months can be communicated at lower frequency.

  3. Operational tempo. Active operations (surveillance, preparation for a meeting, an ongoing recruitment) require more frequent communication than dormant operations.

Threat Level Frequency Method
Extreme (hostile CI active) Monthly or less Dead drops, SRAC
High (competent CI) Bi-weekly Dead drops with signal sites
Moderate (limited CI) Weekly Mixed dead drops and digital
Low (minimal CI) As needed Digital with proper COMSEC

These are guidelines. The specific frequency for any operation is determined by the intersection of threat, intelligence requirements, and operational tempo.

9.4 Communication Schedules

Fixed Schedules

Communication occurs at pre-arranged times (e.g., dead drop serviced on the first Tuesday of each month):

  • Advantage: Both parties know when to expect communication without any signaling
  • Disadvantage: Predictable pattern that can be surveilled; missed window creates ambiguity (was there nothing to communicate, or was the party unable to service the drop?)

Signal-Triggered

Communication occurs when triggered by a signal (e.g., check the dead drop when you see the chalk mark):

  • Advantage: No predictable pattern; communication happens only when needed
  • Disadvantage: Requires additional signal infrastructure; delay between signal setting and checking

Hybrid

Fixed schedule with signal-triggered exceptions:

  • Routine communication on a fixed schedule (monthly dead drop)
  • Priority communication via signal-triggered channel (emergency chalk mark triggers immediate brush pass)

This is the most common approach because it provides both predictability (both parties know the baseline) and flexibility (urgent matters can be communicated outside the normal cycle).

9.5 Communication Security Review

Before finalizing a communication plan, review each channel against the four COMSEC goals:

Channel Goal 1 (Content) Goal 2 (Meaning) Goal 3 (Traffic Analysis) Goal 4 (Channel Existence)
Dead drop N/A (physical) Code if needed No electronic link Concealed if site is good
Brush pass N/A (physical) Code if needed Brief physical proximity Hidden by crowd
SRAC Encrypted burst Code if needed No persistent channel Sub-second, short range
Signal site N/A (binary) Inherent (pre-arranged) No electronic link Concealed by environment
Encrypted phone Strong Code possible Metadata exposed Phone existence known
Tor + encrypted message Strong Code possible Tor-level anonymity Tor usage detectable
Steganography Encryption + hiding Code possible Depends on carrier channel Strong if done well

No single channel achieves all four goals perfectly. The communication plan should use multiple channels to provide defense in depth -- if one channel is compromised, the others continue to provide security.

9.6 Communication Failure Protocols

The plan must account for communication failure. What happens when:

  1. A dead drop is not serviced. How long before the loading party assumes compromise? What is the fallback? Typically: wait one additional cycle, then shift to alternate channel.

  2. A signal is not set. Does this mean "nothing to communicate" or "the signaler has been compromised"? Fixed schedules help resolve this ambiguity -- if a signal is expected on a specific date and does not appear, the failure is meaningful.

  3. A party misses a scheduled contact. One missed contact is not necessarily alarming. Two consecutive missed contacts should trigger concern. Three should trigger emergency protocols.

  4. A channel is suspected compromised. Switch to alternate channel immediately. Communicate the compromise through the alternate channel. Abandon the compromised channel permanently.

  5. All channels are compromised. This is the catastrophic scenario. Emergency protocols should include a face-to-face emergency meeting at a pre-arranged location and time (e.g., third bench from the north entrance of a specific park, first Sunday after a communication failure, between 10:00 and 10:30).


Appendix A: Communication Security Checklist

Before establishing an operational communication channel:

Channel Assessment

  • Content protection (encryption or physical security) verified
  • Meaning protection (codes for signaling) established if needed
  • Traffic analysis resistance assessed -- can communication between parties be linked?
  • Channel existence concealment assessed -- can the channel itself be detected?

Infrastructure

  • Dead drop sites surveyed and approved
  • Signal sites selected and tested
  • Alternate channel established and tested
  • Emergency channel established and tested
  • Duress signals agreed upon

Device Security (if digital)

  • Dedicated devices for each compartment
  • Devices purchased anonymously (cash, no loyalty cards)
  • Devices never powered on at home, work, or associated locations
  • Real phone maintains normal usage pattern during burner operations
  • Devices stored away from home when not in use

Behavioral Security

  • SDR conducted before every operational communication event
  • Communication frequency appropriate to threat level
  • No pattern in timing, location, or method
  • No cross-contamination between communication compartments
  • Cover story for communication activity if observed

Appendix B: Key Principles Summary

  1. Anonymity first, then encryption. Channel security matters more than content security.
  2. Four locations identify 90% of people. Device discipline is not optional.
  3. The telephone is a curse. Assume every call is intercepted. Say nothing you would not publish.
  4. Dead drops achieve all four COMSEC goals when properly executed.
  5. Traffic analysis is the real threat -- metadata destroys operations that encryption protects.
  6. "Talking around" classified subjects does not protect the information. Either communicate securely or do not communicate.
  7. Codes are for signaling, not encryption. Keep them generic, consistent, and simple.
  8. Self-made cipher systems do not work. Use established cryptographic tools.
  9. Every communication creates exposure. Minimize frequency to what the operation requires.
  10. Plan for communication failure. The plan that assumes all channels always work is the plan that fails catastrophically.

Sources: CIA operational manuals (declassified), CIA CHECKPOINT program (SECRET//ORCON//NOFORN), Grugq OPSEC lectures and PORTAL documentation, Allen Dulles operational writings, JSOU Report 12-3 on clandestine networks, Army FM 2-22.3, CIA Lebanon station compromise analysis, Silk Road / DPR case study, Harvard bomb threat case study, PIRA case studies, Robert Morris worm case study, Fatah/BSO operational procedures.