1147 lines
51 KiB
Markdown
1147 lines
51 KiB
Markdown
# Manual 03: Covert Communications
|
|
|
|
> **Mosaic Reference Library** -- Operational Tradecraft Series
|
|
> Compiled from declassified CIA manuals, Grugq OPSEC lectures, Allen Dulles operational
|
|
> writings, JSOU clandestine networks research, and open-source intelligence tradecraft.
|
|
>
|
|
> **Classification:** UNCLASSIFIED -- compiled from publicly available and declassified sources.
|
|
> Original classification markings retained for provenance only.
|
|
|
|
---
|
|
|
|
## Table of Contents
|
|
|
|
1. [COMSEC Fundamentals](#chapter-1-comsec-fundamentals)
|
|
2. [Dead Drops](#chapter-2-dead-drops)
|
|
3. [Brush Passes](#chapter-3-brush-passes)
|
|
4. [Signal Sites](#chapter-4-signal-sites)
|
|
5. [Cut-Outs and Impersonal Communications](#chapter-5-cut-outs-and-impersonal-communications)
|
|
6. [Digital COMSEC](#chapter-6-digital-comsec)
|
|
7. [Codes and Coded Communications](#chapter-7-codes-and-coded-communications)
|
|
8. [Telephone Discipline](#chapter-8-telephone-discipline)
|
|
9. [Communication Planning](#chapter-9-communication-planning)
|
|
|
|
---
|
|
|
|
# Chapter 1: COMSEC Fundamentals
|
|
|
|
## 1.1 The Communication Problem
|
|
|
|
Communication is the lifeblood of any intelligence operation and its greatest vulnerability.
|
|
Every contact between an operative and their handler, between cells of a network, between
|
|
a source and a case officer, creates a moment of exposure. The opposition does not need to
|
|
read the content of a message to extract intelligence from it -- the mere existence of
|
|
communication between two parties can be sufficient to destroy an operation.
|
|
|
|
The Grugq articulated a hierarchy of communication security that distinguishes between
|
|
what most people think COMSEC means and what it actually requires. Most people think of
|
|
encryption -- making messages unreadable. That is necessary but radically insufficient.
|
|
|
|
## 1.2 The Four Goals of Secure Communications
|
|
|
|
Secure communications must achieve four distinct goals, listed in order of increasing
|
|
difficulty and decreasing familiarity:
|
|
|
|
### Goal 1: Unreadable Content
|
|
|
|
The content of the message cannot be read by an interceptor. This is classical encryption
|
|
and is the easiest of the four goals to achieve. Modern cryptographic tools (AES-256,
|
|
Signal Protocol, PGP) provide content security that is, for practical purposes,
|
|
unbreakable through mathematical attack.
|
|
|
|
Achieving Goal 1 alone provides a false sense of security. Encrypted communications
|
|
between two known parties still reveal that those parties are communicating, when they
|
|
communicate, how often, and how much data they exchange.
|
|
|
|
### Goal 2: Inaccessible Meaning
|
|
|
|
Even if content is intercepted and decrypted, the meaning of the message is not apparent.
|
|
This is the domain of codes, where pre-arranged meanings are assigned to innocuous words
|
|
or phrases. A message reading "The weather in Madrid is beautiful" might mean "The dead
|
|
drop is loaded."
|
|
|
|
Goal 2 supplements Goal 1. If encryption fails (key compromise, implementation flaw,
|
|
quantum computing), coded meaning provides a second layer. However, codes are fragile --
|
|
they require pre-arrangement, they cannot convey complex or unanticipated information,
|
|
and their use can be detected through statistical analysis of language patterns.
|
|
|
|
### Goal 3: Avoid Traffic Analysis
|
|
|
|
No link can be established between the communicating parties. This is where most
|
|
communications security fails. Traffic analysis does not care what you said. It cares
|
|
that you said something to someone, at a particular time, from a particular location.
|
|
|
|
Traffic analysis reveals:
|
|
|
|
- **Who communicates with whom** (social graph mapping)
|
|
- **When they communicate** (timing patterns, activity cycles)
|
|
- **How much they communicate** (relationship intensity)
|
|
- **Where they communicate from** (geographic correlation)
|
|
- **How their communication patterns change** (events, operations, meetings)
|
|
|
|
The CIA spy ring in Lebanon was destroyed not through cryptanalysis but through traffic
|
|
analysis. Agents had dedicated mobile phones kept at static locations with pre-arranged
|
|
meetings at fixed sites (a Pizza Hut in Beirut). The phones themselves created patterns --
|
|
dedicated devices at fixed locations, activated on predictable schedules. Hezbollah's
|
|
counterintelligence did not need to decrypt a single message. The metadata was sufficient.
|
|
|
|
Defeating traffic analysis requires that no observable link exists between the sender and
|
|
receiver. This means no shared communication channel, no correlated timing, no geographic
|
|
proximity, and no behavioral pattern that connects the two parties.
|
|
|
|
### Goal 4: Avoid Knowledge of Channel Existence
|
|
|
|
No one knows that a communication channel exists at all. This is the highest and most
|
|
difficult level of COMSEC. If the opposition does not know you are communicating, they
|
|
cannot analyze traffic, attempt decryption, or investigate the relationship.
|
|
|
|
Steganography (hiding messages in images or other media), dead drops (no electronic
|
|
channel at all), and short-range burst transmissions (SRAC) all aim to achieve Goal 4.
|
|
The communication happens in a way that leaves no trace that any communication occurred.
|
|
|
|
## 1.3 The Hierarchy of Importance
|
|
|
|
Goals 1 and 2 (content security) are what most people focus on. Goals 3 and 4 (channel
|
|
security) are what actually matter in operational environments, because they are harder
|
|
to achieve and their failure is more immediately catastrophic.
|
|
|
|
An intercepted but encrypted message is a problem. A pattern of communication between an
|
|
operative and a source that enables identification of both parties is a disaster.
|
|
|
|
The Grugq summarized this principle: "Systems based purely on secrecy [encryption] have
|
|
anomalous usage that attracts attention." An encrypted app on a phone is itself an
|
|
indicator. A phone that only turns on for brief periods at specific locations is itself
|
|
suspicious. Encryption protects content; it does not protect against the inference that
|
|
something worth encrypting is happening.
|
|
|
|
## 1.4 The Anonymity-First Principle
|
|
|
|
The correct priority for operational communications is: **anonymity first, then encryption.**
|
|
|
|
This means:
|
|
|
|
1. First, ensure that no link can be established between the communicating parties
|
|
(Goal 3)
|
|
2. Then, ensure that no one knows the communication is happening at all (Goal 4)
|
|
3. Then, encrypt the content (Goal 1)
|
|
4. Then, code the meaning (Goal 2)
|
|
|
|
This reversal of conventional thinking is the fundamental lesson of every modern
|
|
intelligence compromise. The FBI did not break Silk Road's encryption -- they followed
|
|
the metadata. Hezbollah did not decrypt CIA communications in Beirut -- they followed
|
|
the phones. The NSA's mass surveillance programs are overwhelmingly focused on metadata
|
|
collection, not content interception, because metadata is more operationally useful.
|
|
|
|
---
|
|
|
|
# Chapter 2: Dead Drops
|
|
|
|
## 2.1 What a Dead Drop Is
|
|
|
|
A dead drop is a pre-arranged concealment location where one party deposits material for
|
|
another to retrieve at a later time. The defining characteristic is that the two parties
|
|
never meet. There is no direct contact, no shared physical space at the same time, and
|
|
no communication channel beyond the dead drop itself and its associated signaling system.
|
|
|
|
Dead drops address Goals 3 and 4 simultaneously. There is no electronic communication to
|
|
intercept or analyze, and if the site is well chosen, there is no visible indication that
|
|
a communication is taking place.
|
|
|
|
## 2.2 Site Selection
|
|
|
|
The success or failure of a dead drop operation depends overwhelmingly on site selection.
|
|
A poorly chosen site compromises the operation regardless of how well it is serviced.
|
|
|
|
### Selection Criteria
|
|
|
|
1. **Accessible without suspicion.** Both parties must be able to visit the site as part
|
|
of normal, plausible daily activities. A site that requires either party to make an
|
|
unusual trip or visit an area inconsistent with their cover creates exposure.
|
|
|
|
2. **Natural concealment opportunity.** The site must offer a place to hide material that
|
|
is accessible but not casually discoverable: a gap in a stone wall, a hollowed brick,
|
|
a magnetic container behind a metal railing, loose flagstone with a cavity beneath,
|
|
the underside of a park bench.
|
|
|
|
3. **Not under surveillance.** The site must not be covered by CCTV cameras, not within
|
|
the sight line of security guards, and not in an area with high passive observation
|
|
(e.g., a cafe with outdoor seating facing the site).
|
|
|
|
4. **Away from regular foot traffic** but not isolated. A completely deserted location
|
|
makes anyone who visits it conspicuous. A moderately trafficked park, trail, or
|
|
residential street provides the cover of normal activity without the risk of accidental
|
|
discovery.
|
|
|
|
5. **Memorable but not distinctive.** Both parties must be able to locate the exact spot
|
|
reliably without maps or GPS (both of which create records). The site should be near
|
|
a landmark but not at the landmark itself.
|
|
|
|
6. **Weather resistant.** Material must survive exposure to rain, snow, temperature
|
|
extremes, and humidity. Use waterproof containers.
|
|
|
|
7. **Multiple approach routes.** Both parties should have more than one plausible path
|
|
to the site, enabling SDR variations.
|
|
|
|
### Site Survey Procedure
|
|
|
|
Before a dead drop site is approved for operational use:
|
|
|
|
1. Visit the site at different times of day and different days of the week to assess
|
|
traffic patterns and surveillance exposure
|
|
2. Identify the specific concealment location and test that it can accommodate the
|
|
expected material
|
|
3. Walk the approach routes and identify SDR elements (choke points, observation posts,
|
|
direction changes)
|
|
4. Photograph the site (discreetly) for the other party's recognition
|
|
5. Identify a signal site that is near enough to be practical but not so close that
|
|
servicing the signal and servicing the drop look related
|
|
|
|
## 2.3 Dead Drop Containers
|
|
|
|
The container must protect the material from environmental damage and casual discovery:
|
|
|
|
- **Magnetic containers** that attach to metal surfaces (undersides of benches, inside
|
|
drainpipes, behind electrical boxes)
|
|
- **Faux rocks and bricks** that blend with the environment
|
|
- **Waterproof capsules** for burial or submersion
|
|
- **Modified everyday objects** (a dead battery, a crushed soda can, a used coffee cup)
|
|
that would not attract attention if discovered
|
|
|
|
The container should be camouflaged to match its surroundings. A bright metal box in a
|
|
hedge is obviously planted. A dirty container that looks like trash is invisible.
|
|
|
|
## 2.4 Dead Drop Procedures
|
|
|
|
### Loading
|
|
|
|
1. Conduct a full SDR before approaching the site
|
|
2. Arrive at the site through a natural-looking route consistent with cover activity
|
|
3. Confirm the site is not under observation (look for new cameras, unusual vehicles,
|
|
people lingering)
|
|
4. Load the container with the material
|
|
5. Place the container in the concealment location
|
|
6. Depart through a different route than arrival
|
|
7. Set the load signal at the pre-arranged signal site
|
|
|
|
### Clearing (Retrieval)
|
|
|
|
1. Check the signal site first -- if the load signal is not set, do not approach the
|
|
dead drop
|
|
2. Conduct a full SDR before approaching the site
|
|
3. Arrive through a natural route
|
|
4. Retrieve the container
|
|
5. Depart through a different route
|
|
6. Clear the load signal and optionally set a receipt signal
|
|
7. Do not open or examine the material until in a secure location
|
|
|
|
### Timing
|
|
|
|
- Load and clear at different times -- never within the same hour, ideally on different
|
|
days
|
|
- Do not establish a pattern (every Tuesday at 3 PM)
|
|
- The clearing party should retrieve within the agreed window -- material left too long
|
|
risks discovery or degradation
|
|
- If the material is not retrieved within the agreed window, the loading party must
|
|
assume compromise and abort
|
|
|
|
## 2.5 Dead Drop Security
|
|
|
|
- **Never revisit a compromised site.** If there is any indication that a site has been
|
|
discovered -- container missing, container moved, signs of disturbance, new surveillance
|
|
in the area -- the site is burned permanently.
|
|
- **Vary sites regularly.** Even sites that appear secure develop risk over time through
|
|
environmental changes, new construction, new camera installations, or pattern development.
|
|
- **Dust containers with detection material** (UV powder, marked adhesive) that would
|
|
transfer to anyone who handles the container, providing evidence of compromise.
|
|
- **Maintain a reserve of pre-surveyed sites** so that losing one site does not interrupt
|
|
operations.
|
|
- **Separate the signal site from the drop site** by enough distance that a watcher on
|
|
one cannot observe the other.
|
|
|
|
---
|
|
|
|
# Chapter 3: Brush Passes
|
|
|
|
## 3.1 What a Brush Pass Is
|
|
|
|
A brush pass is a brief, planned physical exchange that occurs as two parties walk past
|
|
each other in a public space. The transfer takes less than one second. Neither party
|
|
stops, neither acknowledges the other, and to any observer, nothing has occurred beyond
|
|
two strangers passing on a sidewalk.
|
|
|
|
Where a dead drop separates the parties in time (they never occupy the same space
|
|
simultaneously), a brush pass separates them in attention -- they are in the same space
|
|
at the same time but the interaction is so brief and so natural that it is effectively
|
|
invisible.
|
|
|
|
## 3.2 The Technique
|
|
|
|
### Physical Mechanics
|
|
|
|
1. **Approach from opposite directions** along a path in a crowded area
|
|
2. **Item is palmed** -- held in the hand in a way that is invisible to observers. The
|
|
item must be small enough to palm: a USB drive, a folded note, a memory card, a key
|
|
3. **Moment of transfer:** As the parties pass each other, a brief hand contact transfers
|
|
the item. This can be a handshake-like grip, a brush of fingers, or a pass through
|
|
a carried bag or newspaper
|
|
4. **Neither party stops or reacts.** Both continue walking in their original direction
|
|
at their original pace
|
|
5. **Neither party acknowledges the other** -- no eye contact, no nod, no verbal exchange
|
|
|
|
### Environmental Requirements
|
|
|
|
The brush pass requires a specific environment to work:
|
|
|
|
- **Crowd density.** Enough people that two individuals passing close together is normal,
|
|
not remarkable. Markets, subway platforms, busy sidewalks, shopping districts, transit
|
|
stations, and event venues provide ideal cover.
|
|
- **Movement flow.** Both parties must be walking in a natural flow of pedestrian traffic.
|
|
Two people walking directly toward each other on an empty sidewalk is conspicuous.
|
|
- **No surveillance chokepoint.** The pass location should not be under a camera with a
|
|
clear angle on the hands of both parties.
|
|
|
|
## 3.3 Practice
|
|
|
|
A brush pass requires significant practice to execute smoothly. A fumbled transfer --
|
|
dropped item, visible hand contact, unnatural hesitation -- defeats the entire purpose.
|
|
|
|
Practice regimen:
|
|
|
|
1. **Solo palm practice.** Practice palming objects of various sizes until the hand
|
|
position is natural and the object is invisible.
|
|
2. **Approach timing.** Practice walking at normal speed and arriving at the transfer
|
|
point at the correct moment relative to the other party.
|
|
3. **Transfer practice.** Practice the hand contact with a partner until the transfer
|
|
is smooth, quick, and produces no visible reaction from either party.
|
|
4. **Distressed practice.** Practice after physical exertion, in uncomfortable weather,
|
|
while carrying bags, and while wearing gloves.
|
|
5. **Crowd practice.** Practice in actual crowd environments to develop comfort with
|
|
proximity, timing, and noise.
|
|
|
|
## 3.4 Brush Pass Security
|
|
|
|
- Conduct SDR before the pass -- both parties must be confident they are not under
|
|
surveillance
|
|
- Have a pre-arranged abort signal -- if either party detects surveillance, the pass
|
|
does not happen, and both parties continue as if they were never going to meet
|
|
- The brush pass location should not be the same location every time
|
|
- Do not combine brush passes with verbal communication -- the pass is the exchange,
|
|
nothing more
|
|
- If the item is critical, have a fallback plan (dead drop, secondary brush pass
|
|
location) in case the primary attempt is aborted
|
|
|
|
---
|
|
|
|
# Chapter 4: Signal Sites
|
|
|
|
## 4.1 The Purpose of Signals
|
|
|
|
A signal site is a pre-arranged location where a physical indicator communicates a binary
|
|
message: go/no-go, loaded/cleared, danger/safe, ready/not ready. Signals are the
|
|
triggering mechanism for other tradecraft -- they tell a party when to service a dead drop,
|
|
when to show up for a meeting, or when to abort.
|
|
|
|
Signals exist because the alternative -- communicating these messages electronically --
|
|
creates the traffic analysis vulnerability that Goals 3 and 4 seek to avoid. A chalk
|
|
mark on a lamppost generates no metadata.
|
|
|
|
## 4.2 Types of Signals
|
|
|
|
### Mark Signals
|
|
|
|
A visible mark placed on a surface:
|
|
|
|
- Chalk mark on a wall, curb, mailbox, or lamppost
|
|
- Thumbtack on a bulletin board (color or position conveys meaning)
|
|
- Tape on a traffic sign, utility pole, or railing
|
|
- Grease pencil mark on a window
|
|
|
|
Mark signals are easy to set and check but vulnerable to weather (rain washes chalk) and
|
|
environmental cleaning (maintenance crews remove marks).
|
|
|
|
### Placement Signals
|
|
|
|
An object placed in a specific position:
|
|
|
|
- Flower pot in a specific window (present = go, absent = no-go)
|
|
- Car parked in a specific spot
|
|
- Newspaper left on a specific bench
|
|
- Stone placed on a specific wall
|
|
|
|
Placement signals are more weather-resistant than marks but require the signaler to have
|
|
access to the object and location.
|
|
|
|
### State Signals
|
|
|
|
The state of an existing object:
|
|
|
|
- Window blind up versus down
|
|
- Gate open versus closed
|
|
- Specific item displayed in a shop window
|
|
- Light on versus off in a specific window
|
|
|
|
State signals are the least conspicuous because they involve no foreign object or mark --
|
|
the signal is embedded in the normal state of the environment.
|
|
|
|
## 4.3 Signal Site Selection
|
|
|
|
Signal sites must satisfy specific requirements:
|
|
|
|
1. **Visible in normal passing.** Both the setter and the checker must be able to interact
|
|
with the signal site as part of a natural route. The checker should not need to stop,
|
|
stoop, or change direction to observe the signal. A chalk mark at eye level on a
|
|
wall that the operative walks past daily is ideal.
|
|
|
|
2. **Not under dedicated observation.** Avoid signal sites under CCTV or in areas with
|
|
security guards. Avoid locations where a regular observer (a shopkeeper, a parking
|
|
attendant) would notice someone setting or checking the signal.
|
|
|
|
3. **Weather resistant.** If using chalk, choose a sheltered surface (under an overhang,
|
|
inside a phone booth, on the interior face of a wall). If using placement signals,
|
|
ensure the object will not be moved by wind, cleaning crews, or passersby.
|
|
|
|
4. **Unambiguous.** The signal must be clearly present or clearly absent. A faded chalk
|
|
mark that might or might not still be visible creates dangerous ambiguity.
|
|
|
|
5. **Separate from the operational site.** The signal site should not be close enough to
|
|
the dead drop, meeting location, or operational target that checking the signal could
|
|
lead surveillance to the operational site.
|
|
|
|
## 4.4 Signal Protocols
|
|
|
|
### Two-Signal System
|
|
|
|
A basic protocol uses two signals:
|
|
|
|
- **Load signal:** Set by the loader after placing material in a dead drop. Checked by
|
|
the retriever before approaching the drop.
|
|
- **Receipt signal:** Set by the retriever after successfully clearing the dead drop.
|
|
Checked by the loader to confirm the material was received.
|
|
|
|
### Three-Signal System
|
|
|
|
A more robust protocol adds a danger signal:
|
|
|
|
- **Load signal:** Same as above
|
|
- **Receipt signal:** Same as above
|
|
- **Danger signal:** Set by either party to indicate that the operation is compromised,
|
|
the site is under surveillance, or an emergency has occurred. The danger signal cancels
|
|
all pending operations and may activate emergency protocols.
|
|
|
|
### Signal Timing
|
|
|
|
- Signals should be set and checked within agreed windows
|
|
- A signal that has been set for longer than the agreed window should be treated as
|
|
potentially compromised (either the other party has been prevented from responding,
|
|
or the signal has been discovered)
|
|
- Do not check signals obsessively -- repeated visits to the signal site create a pattern
|
|
|
|
## 4.5 Signal Discipline
|
|
|
|
- Each signal has one and only one meaning. Overloading signals with multiple meanings
|
|
creates confusion and operational risk.
|
|
- Confirm signals are separate from action signals. A signal that says "the drop is
|
|
loaded" is different from a signal that says "I acknowledge receipt." They use
|
|
different sites or different marks.
|
|
- Regularly rotate signal sites, just as drop sites are rotated.
|
|
- If a signal site may have been observed (someone was watching when you set the mark,
|
|
the area has new cameras), burn the site.
|
|
|
|
---
|
|
|
|
# Chapter 5: Cut-Outs and Impersonal Communications
|
|
|
|
## 5.1 The Principle of Indirect Contact
|
|
|
|
Impersonal communication ensures that two individuals who need to exchange information
|
|
never come into direct contact. This is the foundational organizing principle of
|
|
clandestine networks: if the handler and the source never meet, the compromise of one
|
|
does not directly expose the other.
|
|
|
|
The methods divide into passive (no real-time link between parties) and active (real-time
|
|
communication channel exists).
|
|
|
|
## 5.2 Passive Methods
|
|
|
|
Passive methods generate no electronic signature and create no real-time connection
|
|
between the parties:
|
|
|
|
### Dead Drops
|
|
|
|
Covered in Chapter 2. The paradigmatic passive method: one places, another retrieves,
|
|
no contact.
|
|
|
|
### Live Drops
|
|
|
|
A live drop uses a human intermediary -- a cut-out -- to physically carry material from
|
|
one party to another. The cut-out knows neither the identity nor the role of the parties.
|
|
They receive a package from a stranger and deliver it to another stranger.
|
|
|
|
Live drops are more flexible than dead drops (no fixed site required) but introduce the
|
|
risk of the cut-out being identified, followed, or compromised.
|
|
|
|
### Mail Drops
|
|
|
|
Material is sent through the postal system to a pre-arranged address. The address is
|
|
controlled by the receiving party (or by a further cut-out) and is not linked to either
|
|
party's true identity.
|
|
|
|
Mail drops require careful attention to postal inspection triggers:
|
|
|
|
1. Use business-to-individual format, not person-to-person
|
|
2. Use typed labels, not handwritten
|
|
3. Weight should not be round metric numbers
|
|
4. Return address must be real and verifiable (backstopped)
|
|
5. Packaging should look professional and new (not reused)
|
|
6. Avoid heavy taping
|
|
7. Do not ship from drug-source zip codes
|
|
8. Use packaging consistent with the stated business context
|
|
|
|
These criteria are derived from the FBI drug mail profile -- the same triggers that flag
|
|
drug shipments will flag suspicious intelligence packages.
|
|
|
|
### Clandestine Signals
|
|
|
|
Covered in Chapter 4. Signals themselves are a form of impersonal communication -- they
|
|
convey a binary message without any direct contact between the parties.
|
|
|
|
## 5.3 Active Methods
|
|
|
|
Active methods create a real-time or near-real-time communication channel. They offer
|
|
more flexibility and speed but generate detectable signatures:
|
|
|
|
### Radio
|
|
|
|
Short-wave radio, burst transmissions, and numbers stations have been used since World
|
|
War II. Radio provides one-way communication (numbers station to agent) without any
|
|
connection infrastructure. The agent needs only a commercially available radio receiver,
|
|
which is impossible to distinguish from innocent use.
|
|
|
|
### Telephone
|
|
|
|
Covered in Chapter 8. Telephone communication is fast and flexible but creates extensive
|
|
metadata records.
|
|
|
|
### Internet
|
|
|
|
Covered in Chapter 6. Digital communications offer speed and capacity but generate
|
|
metadata and create electronic links between parties.
|
|
|
|
## 5.4 The Cut-Out
|
|
|
|
A cut-out is a person who serves as an intermediary between two parties who cannot or
|
|
should not meet directly. The cut-out knows their task but not the identities or roles
|
|
of the people they connect.
|
|
|
|
### Properties of a Good Cut-Out
|
|
|
|
- **No known connection** to either party or to the intelligence operation
|
|
- **Plausible reason for movement** in the areas where they operate (a delivery driver,
|
|
a commuter, a regular at a certain cafe)
|
|
- **Unaware of the operational significance** of the material they transport
|
|
- **Reliable** without being informed -- will follow instructions consistently
|
|
- **Replaceable** -- the operation does not depend on any single cut-out
|
|
|
|
### Courier Considerations
|
|
|
|
Couriers are the most secure form of active material transfer. They physically carry
|
|
material from point A to point B, leaving no electronic trace.
|
|
|
|
Operational experience, particularly from Middle Eastern and Irish clandestine networks,
|
|
has shown that **women and children decrease suspicion at checkpoints.** A woman carrying
|
|
a shopping bag through a military checkpoint faces less scrutiny than a military-age male
|
|
with a backpack. This is not an endorsement of involving non-combatants -- it is a
|
|
recognition of how checkpoint profiling works and how adversaries exploit it.
|
|
|
|
## 5.5 Cellular Network Structure
|
|
|
|
The most sophisticated application of cut-out principles is the cellular network, where
|
|
an entire organization is structured so that members of one cell know only their
|
|
immediate contacts and the cell's internal members. If a cell is compromised, the damage
|
|
is contained to that cell and its immediate links.
|
|
|
|
JSOU research on clandestine networks found that organizations using this structure with
|
|
excellent tradecraft can remain hidden even from expert adversaries. Destroyed cells are
|
|
replaced within weeks from a hidden reserve structure. The key insight: the visible
|
|
(operational) cells are at the periphery and are expendable. The hidden infrastructure
|
|
that recruits, trains, and deploys new cells is the organization's actual center of
|
|
gravity.
|
|
|
|
Counterintelligence should therefore "attack the clandestine infrastructure, not just
|
|
visible cells" -- and conversely, clandestine organizations should protect their
|
|
regenerative infrastructure above all else.
|
|
|
|
---
|
|
|
|
# Chapter 6: Digital COMSEC
|
|
|
|
## 6.1 The Digital Communications Environment
|
|
|
|
Digital communications offer unprecedented speed, capacity, and global reach. They also
|
|
offer unprecedented surveillance capability to any adversary with access to network
|
|
infrastructure, device compromise tools, or metadata analysis programs.
|
|
|
|
The challenge of digital COMSEC is that the technology simultaneously enables secure
|
|
communication and enables surveillance of that communication. Every solution creates new
|
|
attack surfaces.
|
|
|
|
## 6.2 SRAC (Short Range Agent Communications)
|
|
|
|
SRAC represents the closest digital analog to a dead drop -- a burst communication system
|
|
that operates over extremely short range (typically infrared or short-range WiFi) and
|
|
transmits in less than one second.
|
|
|
|
### How It Works
|
|
|
|
1. The agent carries a small transmitter device
|
|
2. A concealed receiver is placed at a pre-arranged location (inside a building wall,
|
|
in a vehicle, mounted inconspicuously)
|
|
3. The agent walks past the receiver at normal speed
|
|
4. When in range (typically a few meters), the device transmits an encrypted data burst
|
|
lasting less than one second
|
|
5. No internet connection is required
|
|
6. The receiver stores the data for later retrieval by the handler through a separate
|
|
channel
|
|
|
|
### Why SRAC Matters
|
|
|
|
SRAC achieves all four COMSEC goals simultaneously:
|
|
|
|
- **Goal 1:** Content is encrypted
|
|
- **Goal 2:** Even if decrypted, the meaning can be coded
|
|
- **Goal 3:** No traffic analysis is possible -- there is no persistent communication
|
|
channel to monitor
|
|
- **Goal 4:** The burst is so brief and short-range that detecting its existence requires
|
|
a receiver positioned within meters at the exact moment of transmission
|
|
|
|
SRAC is the gold standard for agent communications in hostile environments. Its limitation
|
|
is that it requires physical proximity (the agent must walk past the receiver) and physical
|
|
infrastructure (the receiver must be placed and maintained).
|
|
|
|
## 6.3 Burner Phone Discipline
|
|
|
|
Mobile phones are ubiquitous and therefore tempting for operational communication. They
|
|
are also the most comprehensively surveilled communication devices in existence.
|
|
|
|
The Grugq's analysis identifies the critical principle: a mobile phone has multiple
|
|
identifiers beyond the SIM card. Replacing the SIM is insufficient. The phone itself
|
|
has an IMEI that is transmitted with every connection. The phone's location pattern,
|
|
calling pattern, and even the user's voice are fingerprints.
|
|
|
|
### Burner Phone Rules
|
|
|
|
1. **Phone OFF means battery out, SIM out, and ideally in a shielded bag.** A phone that
|
|
is "off" but has a battery can still be activated remotely and can still be tracked
|
|
by some systems.
|
|
|
|
2. **Never use at locations associated with you.** Home, work, regular social locations --
|
|
any phone powered on at these locations can be linked to the person who lives or
|
|
works there.
|
|
|
|
3. **Never turn on at the same location as your real phone.** Powering on a burner at a
|
|
location where your real phone has established a pattern creates an immediate
|
|
correlation.
|
|
|
|
4. **Do not let your real phone go OFF when the burner goes ON.** Paired events -- where
|
|
one phone deactivates as another activates -- are powerful indicators of relation.
|
|
Keep the real phone showing normal usage patterns while the burner is operational.
|
|
|
|
5. **Never carry phones for different compartments together.** Co-location of devices
|
|
links them. If two phones are always at the same tower at the same time, they belong
|
|
to the same person or the same car.
|
|
|
|
6. **Four locations will identify 90% of people.** Mobility patterns are unique. A burner
|
|
phone that visits the same home, office, gym, and grocery store as a known phone is
|
|
trivially attributable.
|
|
|
|
7. **Store the burner away from home.** If the burner is at a known residential address
|
|
overnight, it is linked to the resident.
|
|
|
|
8. **Keep the real phone showing normal usage.** Sudden gaps in the real phone's activity
|
|
correlate with burner phone activation.
|
|
|
|
### Burner Phone Summary
|
|
|
|
Burner phones are useful for **signaling only** -- brief, low-content communications that
|
|
do not require extended conversation. They are not suitable for substantive communication
|
|
because the duration and pattern of use creates exploitable metadata.
|
|
|
|
Buy with cash. Activate from a neutral location. Never power on near home or work. Use
|
|
briefly. Destroy after a single operational use or a short operational period.
|
|
|
|
## 6.4 Tor, VPNs, and Network Anonymity
|
|
|
|
Network anonymity tools provide Goal 3 (traffic analysis resistance) for digital
|
|
communications but with significant caveats.
|
|
|
|
### Tor
|
|
|
|
Tor routes traffic through multiple relays, hiding the user's IP address from the
|
|
destination and hiding the destination from the user's network. It is the best available
|
|
tool for network-level anonymity but has known limitations:
|
|
|
|
- **Tor is detectable.** Your ISP can see that you are using Tor, even if they cannot see
|
|
where you are going. In an environment where Tor use itself is suspicious, this is a
|
|
Goal 4 failure.
|
|
- **Anonymity set matters.** Tor provides anonymity within the set of Tor users at your
|
|
location and time. At a university with 30,000 students, many of whom use Tor, the
|
|
anonymity set is large. At a small office where you are the only Tor user, the
|
|
anonymity set is one. The Harvard bomb threat case demonstrated this: using Tor from
|
|
campus during a bomb threat reduced the suspect pool to campus Tor users during the
|
|
threat window.
|
|
- **Traffic correlation.** A global adversary who can observe both the entry and exit of
|
|
Tor traffic can correlate timing to deanonymize users. Nation-state adversaries may
|
|
have this capability.
|
|
|
|
### VPNs
|
|
|
|
VPNs hide traffic from the local network but require trust in the VPN provider. The
|
|
VPN provider sees all traffic. VPNs are useful for evading local network surveillance
|
|
but do not provide anonymity against a motivated adversary who can compel the VPN
|
|
provider to produce records.
|
|
|
|
### Operational Guidance
|
|
|
|
- Use Tor from clean devices at locations with large anonymity sets
|
|
- The PORTAL approach (dedicated hardware Tor gateway) prevents accidental bypass --
|
|
all traffic is forced through Tor at the network level, and the user cannot make a
|
|
mistake that reveals their real IP
|
|
- Remove WiFi cards from operational machines to prevent malware from exfiltrating
|
|
the real IP address
|
|
- Never use anonymization tools from locations associated with your real identity
|
|
- Combine network anonymity with device anonymity (burner laptop purchased with cash)
|
|
|
|
## 6.5 Steganography
|
|
|
|
Steganography hides data within other data -- typically, a message hidden within an
|
|
image file, audio file, or video. Where encryption makes a message unreadable,
|
|
steganography makes the message invisible.
|
|
|
|
Steganography addresses Goal 4 directly. An image posted to a public photo-sharing
|
|
site that contains a hidden message is indistinguishable from any other image. The
|
|
communication channel itself is invisible.
|
|
|
|
### Limitations
|
|
|
|
- **Steganalysis.** Sophisticated analysis can detect the statistical anomalies that
|
|
steganographic embedding creates. This is an arms race between embedding techniques
|
|
and detection techniques.
|
|
- **Capacity.** The amount of data that can be hidden without detectable distortion is
|
|
limited. Steganography is suitable for short messages, not bulk data transfer.
|
|
- **Key management.** The recipient must know that a steganographic message exists and
|
|
must have the key/method to extract it. This requires a pre-arranged protocol.
|
|
- **Fragility.** Image compression, format conversion, or resizing can destroy the
|
|
hidden message.
|
|
|
|
### Practical Application
|
|
|
|
Steganography is best used as a channel existence concealment layer on top of encryption.
|
|
The message is first encrypted (Goal 1), then embedded steganographically in a carrier
|
|
file (Goal 4), then transmitted through an anonymous channel (Goal 3).
|
|
|
|
## 6.6 Identity and Communications Migration
|
|
|
|
Regular migration of communication platforms and identities creates temporal
|
|
compartmentation. Old identities and channels are abandoned, creating silos that limit
|
|
the damage from any single compromise.
|
|
|
|
The practice:
|
|
|
|
1. Change communication platforms (IRC servers, messaging apps, forums) on a schedule
|
|
2. Change identifiers (nicknames, account names, email addresses) with each migration
|
|
3. Do not contaminate between time periods -- old logs from a previous identity cannot
|
|
be linked to the new one if migration is done properly
|
|
4. Use different encryption keys for each identity period
|
|
5. Abandon old keys and accounts completely -- do not reuse them even if they seem safe
|
|
|
|
Migration provides plausible deniability and limits the window of exposure for any
|
|
single compromise.
|
|
|
|
---
|
|
|
|
# Chapter 7: Codes and Coded Communications
|
|
|
|
## 7.1 The Role of Codes
|
|
|
|
Codes serve Goal 2 (inaccessible meaning) but they must be understood for what they are
|
|
and what they are not. Codes are not encryption. They are a layer of meaning protection
|
|
that supplements encryption and serves specific operational purposes.
|
|
|
|
## 7.2 Signaling Codes
|
|
|
|
The primary operational use of codes is signaling -- conveying pre-arranged binary or
|
|
limited messages through otherwise innocuous communication:
|
|
|
|
- "The weather in Madrid is beautiful" = the dead drop is loaded
|
|
- "I'll be late for dinner" = abort the meeting
|
|
- "Uncle Robert is visiting next week" = new intelligence available
|
|
- A specific emoji in a social media post = ready for contact
|
|
|
|
Signaling codes must be:
|
|
|
|
1. **Generic.** The coded phrase must sound natural in the context where it will be used.
|
|
A phrase that is unusual or out of character attracts attention.
|
|
2. **Consistent.** Each code means one thing. Do not reuse codes for multiple meanings.
|
|
3. **Limited to simple binary signals.** Go/no-go, yes/no, safe/danger. Codes cannot
|
|
efficiently convey complex information.
|
|
4. **Pre-arranged.** Both parties must agree on the code meanings before they are needed.
|
|
Codes cannot be improvised in real time.
|
|
|
|
## 7.3 Why "Talking Around" Does Not Work
|
|
|
|
There is a persistent temptation to use circumlocution -- "talking around" a classified
|
|
or sensitive topic -- as a substitute for proper COMSEC. This does not work.
|
|
|
|
The Grugq's assessment is direct: "Talking around classified subjects does not protect
|
|
the information." The reasons:
|
|
|
|
1. **Context makes meaning clear.** If two people known to be involved in intelligence
|
|
are having a conversation where they carefully avoid certain words but clearly discuss
|
|
an operation, the content is obvious to any analyst.
|
|
2. **Circumlocution is itself suspicious.** A conversation that dances around a topic is
|
|
more notable than a direct conversation about an innocuous topic.
|
|
3. **Humans are bad at it.** Under stress, fatigue, or excitement, people revert to direct
|
|
language. The circumlocution degrades before the conversation ends.
|
|
4. **Recorded conversations can be analyzed at leisure.** An analyst with a transcript and
|
|
unlimited time will extract the meaning from any circumlocution.
|
|
|
|
The lesson: if information cannot be communicated securely, do not communicate it at all.
|
|
Do not attempt to communicate it "carefully." Either use proper COMSEC (encryption +
|
|
anonymity + channel concealment) or wait until you can.
|
|
|
|
## 7.4 Self-Made Cipher Systems
|
|
|
|
The temptation to create a personal cipher system is equally dangerous. Self-made cipher
|
|
systems rarely work because:
|
|
|
|
1. Cryptography is a specialized discipline requiring deep mathematical knowledge
|
|
2. Ciphers that seem strong to their creators are often trivially breakable by
|
|
professionals
|
|
3. Historical examples (Zodiac killer, various criminal organizations) show that
|
|
amateur ciphers are routinely broken
|
|
4. Professional cryptographic tools are freely available and provably secure
|
|
|
|
Do not invent your own encryption. Use established, peer-reviewed cryptographic tools.
|
|
Codes are for signaling. Encryption is for content protection. These are different
|
|
functions requiring different solutions.
|
|
|
|
## 7.5 Personal Codes for Operational Notes
|
|
|
|
Dulles recommended that operatives carry no names or addresses in clear and instead use
|
|
a personal code -- a private notation system that is meaningless to anyone who finds the
|
|
notebook.
|
|
|
|
This is a specific, limited application:
|
|
|
|
- Phone numbers with digits transposed according to a memorized pattern
|
|
- Names replaced with unrelated words from a private mapping
|
|
- Addresses encoded as coordinates or references to a private key
|
|
|
|
The purpose is not to defeat a cryptanalyst (any simple substitution code can be broken
|
|
with effort) but to prevent a casual discoverer -- a pickpocket, a maid, a border
|
|
agent -- from immediately identifying contacts and addresses.
|
|
|
|
---
|
|
|
|
# Chapter 8: Telephone Discipline
|
|
|
|
## 8.1 The Dulles Rules
|
|
|
|
Allen Dulles described the telephone as "the greatest material curse to the profession."
|
|
His rules for telephone use remain foundational:
|
|
|
|
1. **Always assume every conversation is listened to.** This was true with copper wire
|
|
taps in the 1940s and is exponentially more true with digital telephony, where calls
|
|
are routinely intercepted, recorded, transcribed, and stored by multiple intelligence
|
|
services.
|
|
|
|
2. **Never dial before thinking out what to say and how to say it.** The telephone
|
|
encourages spontaneous conversation. Spontaneous conversation produces security
|
|
failures.
|
|
|
|
3. **Unplug the telephone during confidential conversations.** The telephone is a
|
|
microphone connected to the telephone network. Even when not in a call, it can be
|
|
activated remotely. Better to have no phone in the room.
|
|
|
|
4. **Avoid the phone when possible. Make a day's journey instead.** If the information
|
|
is important enough to protect, it is important enough to deliver in person. A
|
|
face-to-face meeting after an SDR is infinitely more secure than a phone call.
|
|
|
|
## 8.2 Modern Application
|
|
|
|
The underlying principles have not changed. The specific threats have expanded:
|
|
|
|
### Metadata
|
|
|
|
Modern telephony generates extensive metadata beyond the content of the call:
|
|
|
|
- Calling party number and called party number
|
|
- Call duration
|
|
- Cell tower locations for both parties (geographic tracking)
|
|
- IMEI of both devices
|
|
- Time and date
|
|
- Frequency of contact between the numbers
|
|
|
|
Metadata analysis can map entire networks without intercepting a single word of content.
|
|
The NSA's bulk metadata collection programs demonstrated that call records alone reveal
|
|
organizational structure, key nodes, and operational patterns.
|
|
|
|
### Voiceprint
|
|
|
|
Voice biometrics can identify speakers across calls, even across different phone numbers.
|
|
If an operative's voice is in a voiceprint database (from a legal intercept, a public
|
|
speech, or a media appearance), any subsequent phone call can be attributed to them
|
|
regardless of what phone they use.
|
|
|
|
### Location Tracking
|
|
|
|
Mobile phones continuously report their location to cell towers. This location data is
|
|
stored by carriers and is available to intelligence and law enforcement agencies. A phone
|
|
that is present at a meeting location at the time of a meeting, and is also present at
|
|
the operative's home address, links the operative to the meeting.
|
|
|
|
### Modern Rules
|
|
|
|
1. **No substantive communication by phone.** Phone calls are for logistics and signaling
|
|
only. Substantive intelligence discussion happens in person, in a swept location.
|
|
2. **No operational discussion even on encrypted calls.** Encrypted apps protect content
|
|
but not metadata. The fact that you called a known intelligence contact using Signal
|
|
is itself intelligence, regardless of what you discussed.
|
|
3. **Phone-free zones for sensitive meetings.** All phones -- personal and burner --
|
|
remain outside the room during sensitive discussions. A phone in the room is a
|
|
microphone and a location beacon.
|
|
4. **Assume compromise.** Design communications plans that remain secure even if phone
|
|
calls are intercepted and recorded. This means phone calls contain nothing that
|
|
would be damaging if transcribed and published.
|
|
|
|
---
|
|
|
|
# Chapter 9: Communication Planning
|
|
|
|
## 9.1 The Communication Plan
|
|
|
|
Every intelligence operation requires a communication plan -- a pre-arranged structure
|
|
that defines how, when, and through what channels the parties will communicate. The plan
|
|
must balance security (minimizing exposure) with reliability (ensuring messages get
|
|
through) and timeliness (ensuring time-critical information is delivered within the
|
|
required window).
|
|
|
|
## 9.2 Components of a Communication Plan
|
|
|
|
### Primary Channel
|
|
|
|
The default method of communication for routine exchanges. This should be the most
|
|
secure method available and the one that has been most thoroughly tested:
|
|
|
|
- Dead drops with signal sites for low-tempo, high-security requirements
|
|
- SRAC for agent communications in hostile environments
|
|
- Encrypted digital communications for higher-tempo requirements where network
|
|
anonymity can be maintained
|
|
|
|
### Alternate Channel
|
|
|
|
A backup method if the primary channel is unavailable (compromised, disrupted, or
|
|
impractical for a specific communication):
|
|
|
|
- If primary is dead drops, alternate might be a brush pass at a pre-arranged fallback
|
|
location
|
|
- If primary is digital, alternate might be a physical method (dead drop, courier)
|
|
|
|
### Emergency Channel
|
|
|
|
A method for communicating that an emergency has occurred -- the operation is compromised,
|
|
a party is in danger, or immediate action is required:
|
|
|
|
- Pre-arranged phone signal (a specific number of rings, then hang up)
|
|
- Emergency signal site (a specific mark at a specific location)
|
|
- Emergency meeting at a pre-arranged time and place
|
|
- A digital signal (a specific post on a public platform)
|
|
|
|
Emergency channels must be:
|
|
- Simple to activate under stress
|
|
- Monitorable without special equipment
|
|
- Unambiguous in meaning
|
|
- Rarely used (so that their use is clearly an emergency, not routine)
|
|
|
|
### Duress Signal
|
|
|
|
A signal embedded within normal communication that indicates the communicator is under
|
|
coercion -- they are being forced to communicate and the content should be treated as
|
|
hostile disinformation:
|
|
|
|
- A specific word or phrase included in a message
|
|
- An agreed-upon deviation from normal protocol (e.g., using a middle initial that is
|
|
not normally used)
|
|
- A specific error introduced into a coded message
|
|
|
|
## 9.3 Communication Frequency
|
|
|
|
### The Security-Timeliness Tradeoff
|
|
|
|
More frequent communication means faster intelligence delivery but greater exposure. Less
|
|
frequent communication means better security but risk of stale intelligence and loss of
|
|
situational awareness.
|
|
|
|
The frequency decision depends on:
|
|
|
|
1. **Threat level.** In a high-threat environment (hostile counterintelligence is active
|
|
and capable), communication should be as infrequent as possible. The CIA used 2-4 hour
|
|
SDRs before any operational activity in Moscow, and high-security operations involved
|
|
weeks or months of planning with 12-hour SDRs. This pace limits communication to
|
|
what is truly essential.
|
|
|
|
2. **Intelligence perishability.** Information that is time-critical (tactical intelligence,
|
|
warning intelligence) requires faster channels. Strategic intelligence that remains
|
|
valid for weeks or months can be communicated at lower frequency.
|
|
|
|
3. **Operational tempo.** Active operations (surveillance, preparation for a meeting, an
|
|
ongoing recruitment) require more frequent communication than dormant operations.
|
|
|
|
### Recommended Frequencies by Environment
|
|
|
|
| Threat Level | Frequency | Method |
|
|
|---|---|---|
|
|
| Extreme (hostile CI active) | Monthly or less | Dead drops, SRAC |
|
|
| High (competent CI) | Bi-weekly | Dead drops with signal sites |
|
|
| Moderate (limited CI) | Weekly | Mixed dead drops and digital |
|
|
| Low (minimal CI) | As needed | Digital with proper COMSEC |
|
|
|
|
These are guidelines. The specific frequency for any operation is determined by the
|
|
intersection of threat, intelligence requirements, and operational tempo.
|
|
|
|
## 9.4 Communication Schedules
|
|
|
|
### Fixed Schedules
|
|
|
|
Communication occurs at pre-arranged times (e.g., dead drop serviced on the first
|
|
Tuesday of each month):
|
|
|
|
- **Advantage:** Both parties know when to expect communication without any signaling
|
|
- **Disadvantage:** Predictable pattern that can be surveilled; missed window creates
|
|
ambiguity (was there nothing to communicate, or was the party unable to service the
|
|
drop?)
|
|
|
|
### Signal-Triggered
|
|
|
|
Communication occurs when triggered by a signal (e.g., check the dead drop when you
|
|
see the chalk mark):
|
|
|
|
- **Advantage:** No predictable pattern; communication happens only when needed
|
|
- **Disadvantage:** Requires additional signal infrastructure; delay between signal
|
|
setting and checking
|
|
|
|
### Hybrid
|
|
|
|
Fixed schedule with signal-triggered exceptions:
|
|
|
|
- **Routine communication** on a fixed schedule (monthly dead drop)
|
|
- **Priority communication** via signal-triggered channel (emergency chalk mark triggers
|
|
immediate brush pass)
|
|
|
|
This is the most common approach because it provides both predictability (both parties
|
|
know the baseline) and flexibility (urgent matters can be communicated outside the
|
|
normal cycle).
|
|
|
|
## 9.5 Communication Security Review
|
|
|
|
Before finalizing a communication plan, review each channel against the four COMSEC goals:
|
|
|
|
| Channel | Goal 1 (Content) | Goal 2 (Meaning) | Goal 3 (Traffic Analysis) | Goal 4 (Channel Existence) |
|
|
|---|---|---|---|---|
|
|
| Dead drop | N/A (physical) | Code if needed | No electronic link | Concealed if site is good |
|
|
| Brush pass | N/A (physical) | Code if needed | Brief physical proximity | Hidden by crowd |
|
|
| SRAC | Encrypted burst | Code if needed | No persistent channel | Sub-second, short range |
|
|
| Signal site | N/A (binary) | Inherent (pre-arranged) | No electronic link | Concealed by environment |
|
|
| Encrypted phone | Strong | Code possible | Metadata exposed | Phone existence known |
|
|
| Tor + encrypted message | Strong | Code possible | Tor-level anonymity | Tor usage detectable |
|
|
| Steganography | Encryption + hiding | Code possible | Depends on carrier channel | Strong if done well |
|
|
|
|
No single channel achieves all four goals perfectly. The communication plan should use
|
|
multiple channels to provide defense in depth -- if one channel is compromised, the others
|
|
continue to provide security.
|
|
|
|
## 9.6 Communication Failure Protocols
|
|
|
|
The plan must account for communication failure. What happens when:
|
|
|
|
1. **A dead drop is not serviced.** How long before the loading party assumes compromise?
|
|
What is the fallback? Typically: wait one additional cycle, then shift to alternate
|
|
channel.
|
|
|
|
2. **A signal is not set.** Does this mean "nothing to communicate" or "the signaler has
|
|
been compromised"? Fixed schedules help resolve this ambiguity -- if a signal is
|
|
expected on a specific date and does not appear, the failure is meaningful.
|
|
|
|
3. **A party misses a scheduled contact.** One missed contact is not necessarily alarming.
|
|
Two consecutive missed contacts should trigger concern. Three should trigger emergency
|
|
protocols.
|
|
|
|
4. **A channel is suspected compromised.** Switch to alternate channel immediately.
|
|
Communicate the compromise through the alternate channel. Abandon the compromised
|
|
channel permanently.
|
|
|
|
5. **All channels are compromised.** This is the catastrophic scenario. Emergency
|
|
protocols should include a face-to-face emergency meeting at a pre-arranged location
|
|
and time (e.g., third bench from the north entrance of a specific park, first Sunday
|
|
after a communication failure, between 10:00 and 10:30).
|
|
|
|
---
|
|
|
|
# Appendix A: Communication Security Checklist
|
|
|
|
Before establishing an operational communication channel:
|
|
|
|
**Channel Assessment**
|
|
- [ ] Content protection (encryption or physical security) verified
|
|
- [ ] Meaning protection (codes for signaling) established if needed
|
|
- [ ] Traffic analysis resistance assessed -- can communication between parties be linked?
|
|
- [ ] Channel existence concealment assessed -- can the channel itself be detected?
|
|
|
|
**Infrastructure**
|
|
- [ ] Dead drop sites surveyed and approved
|
|
- [ ] Signal sites selected and tested
|
|
- [ ] Alternate channel established and tested
|
|
- [ ] Emergency channel established and tested
|
|
- [ ] Duress signals agreed upon
|
|
|
|
**Device Security (if digital)**
|
|
- [ ] Dedicated devices for each compartment
|
|
- [ ] Devices purchased anonymously (cash, no loyalty cards)
|
|
- [ ] Devices never powered on at home, work, or associated locations
|
|
- [ ] Real phone maintains normal usage pattern during burner operations
|
|
- [ ] Devices stored away from home when not in use
|
|
|
|
**Behavioral Security**
|
|
- [ ] SDR conducted before every operational communication event
|
|
- [ ] Communication frequency appropriate to threat level
|
|
- [ ] No pattern in timing, location, or method
|
|
- [ ] No cross-contamination between communication compartments
|
|
- [ ] Cover story for communication activity if observed
|
|
|
|
---
|
|
|
|
# Appendix B: Key Principles Summary
|
|
|
|
1. Anonymity first, then encryption. Channel security matters more than content security.
|
|
2. Four locations identify 90% of people. Device discipline is not optional.
|
|
3. The telephone is a curse. Assume every call is intercepted. Say nothing you would not
|
|
publish.
|
|
4. Dead drops achieve all four COMSEC goals when properly executed.
|
|
5. Traffic analysis is the real threat -- metadata destroys operations that encryption
|
|
protects.
|
|
6. "Talking around" classified subjects does not protect the information. Either
|
|
communicate securely or do not communicate.
|
|
7. Codes are for signaling, not encryption. Keep them generic, consistent, and simple.
|
|
8. Self-made cipher systems do not work. Use established cryptographic tools.
|
|
9. Every communication creates exposure. Minimize frequency to what the operation requires.
|
|
10. Plan for communication failure. The plan that assumes all channels always work is the
|
|
plan that fails catastrophically.
|
|
|
|
---
|
|
|
|
> **Sources:** CIA operational manuals (declassified), CIA CHECKPOINT program (SECRET//ORCON//NOFORN),
|
|
> Grugq OPSEC lectures and PORTAL documentation, Allen Dulles operational writings,
|
|
> JSOU Report 12-3 on clandestine networks, Army FM 2-22.3, CIA Lebanon station compromise
|
|
> analysis, Silk Road / DPR case study, Harvard bomb threat case study, PIRA case studies,
|
|
> Robert Morris worm case study, Fatah/BSO operational procedures.
|