Skip to content

Welcome to the Brushbeater Store!

Its been one hell of ride getting here. Seven, nearly eight, years since the launch of the original Brushbeater blog and look at how far we’ve come. Hundreds of classes, ranging from the original open enrollment Radio Telephone Operator (RTO) Course way back in March of 2017 to small unit tactics to three bestselling books. Pretty amazing to see the growth from a small blog of a disgruntled Vet to what it is today. Virtually no social media presence and fighting every day for that readership and the following its created. 

And now here we are. 

But the store in and of itself is only just now finding its legs too. We’re very much in the infancy of what I aim for it to become…the one stop shop for the American Patriot. Its been said that the American Populace is the most heavily armed on earth and while that may or may not be true, I intend on putting some additional teeth behind that. 

The unprecedented success of The Guerrilla’s Guide to the Baofeng Radio enabled Brushbeater Training and Consulting to jumpstart that capacity to arm you in as many ways as possible – through knowledge and professional references, through training courses in person, through social networking on the forum, and soon through equipment as well. Communications, optics, tactical trauma, you name it – we’re going to have it. All in an effort to give this community of Patriots the very best. 

Ain’t no savior gonna come out of thin air. Its up to you. 

I’m just getting warmed up. Join me.

The Guerrilla’s Guide to the Baofeng Radio: Thoughts on the Reality of Unconventional Warfare and Communications

There’s been a raging debate about the little cheap Chinese radio literally since the things started showing up in the US a little over a decade ago. It started with the “sad hams” that my friend and best selling author Joe Dolio affectionately refers to, quick to safeguard their own known and trusted brands. Certainly not without good reason; China is not always known for producing reliable goods at certain bargain pricepoints. But on the upside, the little radios DID lead to a boom in not just Amateur Radio but interest in communications from the preparedness perspective as well. And that alone is an indisputable fact. 

Many of us with dirt time overseas encountered a lot of these radios in their early form being used by insurgents, most notably by the Taliban in RC South and RC East where much of the heavy fighting occurred. Back then we called them Icoms as a blanket label because we simply didn’t know what we didn’t know. Us trigger pullers don’t like complications and the Signals Intelligence (SIGINT) guys tasked with exploitation really only knew what they were taught. Which was enough to accomplish the task…and leave much to be desired. 

Like all Professional Soldiers I looked for understanding above all else. If you’re not constantly engaged in learning new skills you’re not sustaining that warrior’s path, and communications always became a giant glaring hole in terms of capability. So when these little radios popped up I jumped on them. 

That brings us to the “tactical” crowd…you know these types, and I at one point in my life was among them as well. Latest things that go bang and all the gear to go with it. These days that’s got a healthy representation of young guys just getting into this stuff and consuming knowledge from social media, for good and bad. While I won’t comment on that, I will say that when it comes to communications this gives way to the second point of contention some have with the Baofeng in its most basic form: it lacks any native (built in) communications security (COMSEC) capabilities. What do I mean when I say that? 

COMSEC to us on the dot mil side of the house meant the frequency hopping algorithm and the encryption key loaded into the SINCGARS family of radios. We only knew our equipment and were generally discouraged from asking questions, but in a nutshell, this would prevent eavesdropping on tactical  communications. What it didn’t do was mask the signature of our presence, as I discussed in the book, but it would mask what we were saying. That certainly has value. 

I wrote The Guerrilla’s Guide to the Baofeng as a manual for the would-be Freedom Fighter in an Unconventional Warfare (UW) environment. Not a conventional force, not a well funded force, and certainly not the flannel shirt wearing cheese dick crowd that only latches on to the latest trends. I wrote this book as an ode, of sorts, to the lessons the Taliban taught us. They won, by the way, in case anyone was wondering. All you have is what you have, and when it comes to communications that’s most likely the Baofeng UV-5R. Love it, hate it, or indifferent, that’s the reality. You must fight with what you have.

In Afghanistan those same inexpensive Chinese radios were in the Taliban hands, and while interception was often times simple enough, radio direction finding (RDF) wasn’t always so. This was mainly due to the terrain itself. So while pattern analysis of the radio chatter was important and even critical at the tactical level (at times), it could also easily be defeated just based on physics. Not only that, you can’t intercept what’s not being transmitted. Simple rules like keeping your transmissions short, and even utilizing data bursts, go a long way in preserving COMSEC for the would-be guerrilla. 

The nice thing about plain old analog radios is that the end user has complete control over exactly what’s transmitted – and that goes for everything from voice communications to utilizing your own digital protocols. I break this down step by step in The Guerrilla’s Gudie to the Baofeng Radio utilizing free software and inexpensive tools sourced nearly anywhere on the planet – just add the radio. 

Had the Taliban done what’s covered in the book, our SIGINT teams would have had an incredibly hard time dealing with them even more so than we did. It doesn’t work the way it does in the movies or on an airsoft field, even though some will tell you otherwise. Combat is very much a continuum extending well beyond the glitz and terror of a gunfight. And the reality of communications is very much a key part of that. 

So while the online flaming back and forth won’t likely ever cease, from the sad hams bemoaning anyone crowding their beloved repeaters to the tacticool kids lecturing us poors on the realities of combat against IPSC targets, the rest of us can focus on understanding the nature of the potential UW environment here in the US and taking the appropriate measures to build the aggregate levels of capability. 

The book’s aim was to do just that. And the Brushbeater store is going to be expanding that capacity in a very big way. Stay tuned. 

 

Spectrum Management, Small Unit Tactics and the Next Generation

I was once asked, years ago, to define what the small unit actually was. The person asking was intensely well qualified, mind you, far more than I, to comment on the subject. Having had a distinguished career in several of the Special Forces Groups, his question lay not in probing my own knowledge but making me think. Following an engaging thought experiment he stated “I sometimes wonder if what we were taught all these years was wrong”. His rationale lay with tactics, and the underlying training doctrine, remaining in stasis.

I happen to agree – tactics and task organization do not exist in a vacuum, rather, they thrive in a constant state of evolution. Tactics are that strategy you employ to successfully complete a task. Task organization is how you manage your resources. Taking into account the multitude of resources developing on the modern battlefield on vibrant display today, there is a strong case to be made for a new revolution in not just how we mitigate the evolving risks but integrate them into our own order of battle.

Another close friend and mentor who happened to be an Infantry Company Commander in Vietnam once noted the proliferation of night vision and thermal for hunting use. Just twenty years ago that would be out of the price range of most, but its commonplace now. NODs revolutionized tactics for a time. While there is a case to be made for the underlying skill – development of natural night vision and spatial awareness sans a set of NODs – it would be idiotic to suggest they are not a requirement on the modern battlefield in any capacity. Proper employment has a learning curve, as does the equipment needed. The debate over passive versus active aiming will likely continue to rage, but it will not go away. The equipment is here and the tactics must evolve lest we find ourselves at a disadvantage.

To a far larger extent is the proliferation of Thermal Imagers in smaller and smaller sizes making small unit integration seamless. Just a decade ago thermal was clunky, heavy, and had a short battery life. Not anymore. It has become a requirement for observation purposes day and night to have that piece of equipment on a patrol. But even more importantly is the measures to safeguard that same patrol from an adversary using it. Both are a product of the Global War on Terror with the tactics evolving to mitigate their presence a reflection of their proliferation on both sides of a future conflict. We now see those results in Ukraine.

This leads us to drones. There can be no doubt, taking into account the lopsided victories of the Azeris in Nagorno-Karabakh once the Israeli drones were fielded, that the use of drones is the greatest game changer at the macro level to date, be it armed birds with a payload or small units for local Intelligence, Surveillance, and Reconnaissance (ISR). The presence of cheap technology is forcing the way we think of small unit warfare, be it the conventional linear meat grinder we are observing in Ukraine or the continuing brooding asymmetric war here at home. Just as we view the guy with the iron sighted AR-15 as well behind the power curve, in the near future the same will be said of the lack of enablers discussed here.

I go back to the statement in the first paragraph…what if what we were taught was wrong. Certainly gives one pause to wonder, taking for granted all the buzzwords that gave us comfort. Terms like “frequency hopping” and “encryption”, absent the necessary defining details. What if what we were taught regarding communications, at the small unit level, was not just wrong, but will get people killed on the modern battlefield? It is an incredibly valid question. We took for granted those terms above for far, far too long, generating a ridiculous level of hubris. The Russians have demonstrated a rather formidable electronic warfare capability, even if falling a bit shorter than expected in some cases. But the idea of frequency hopping in the 30-88mHz range was intended to prevent jamming, not interception. And the encryption itself, while still secure, is nearly 30 years old, mitigating neither interception nor detection of the signal. The use of that particular portion of the spectrum for military ground communications and that specific waveform, easily identifiable to those with even cheap equipment, instantly fingerprints a unit’s presence.

To make matters worse, thinking has hinged upon greater use of the RF spectrum to create geospatial awareness. Something that has a better name – micromangement – in an attempt to integrate all of the communications between air and ground elements pipelined straight to the Ground Force Commander. Sounds great, except that in practice it cannot account for the amount of RF generated and easily exploited by those with the capability. As an aside, this equipment is meant for conventional forces, no matter how special the unit fielding it claims to be. All the buzzwords cannot account for the fact that a consistent signal emission with a unique and repeated pattern is a serious problem. What we were taught was wrong and nothing has been done to change the way we train, making the age-old assumption the next war will be the same as the last.

Early in the Russian invasion of Ukraine much chatter was made of the Russian conventional forces’ use of Baofeng radios  – simple analog, little else. Why were they not fielding the new Azart radio system? Maybe they can’t field it…not enough to go around. Perhaps. The Russian bear is not so strong after all and assorted other overconfident statements. I’m not particularly a fan of bravado ignoring our embarrassing exit from Afghanistan just over a year ago. But little consideration was made to another factor: the Azart, with its NXDN digital protocol, may be mistaken for the Ukrainian use of DMR for tactical communications. This would become a serious problem for electronic warfare groups tasked with coordinating first the location of enemy units (based on their electronic signature) and second to hammer them with indirect fire. The confusion of two similar systems in danger close proximity is the same as shooting it out within a couple hundred meters – it negates one side’s ability to use airpower or artillery without killing its own. It was certainly not a perfect solution and caused many of its own problems. But then again, this is always the case. Early in the GWOT US forces unofficially made use of many Motorola FRS radios to free up bandwidth until it was formally banned due to the threat of triggering IEDs. I remember it well.

Cheap technology in the form of spectrum analyzers and SDR is making the task of signals intelligence faster, easier and more streamlined than ever before. The ability to have an inexpensive and small device gives a new capability to the team on the ground. Hunt the signal, kill the Unit emitting it. And that leads us back to our fundamental point. Management of the RF emissions of a small unit is every bit as important as considerations to thermal protection and operating at night. To make matters more complicated, communications is the most intangible, and in turn most misunderstood, of those skills. Worse yet is the US propensity for micromanagement at the small unit level. It is a lesson being learned the hard way for both sides in Ukraine, but one that only a single side apparently seems to draw its lessons. In the end, regardless of the nature of the conflict, asymmetric or conventional, management of the RF spectrum will be necessary for a unit’s survival. Just as with the proliferation of NODs, thermal and cheap drones, the fielding of inexpensive equipment in innovative ways will win that fight.

Not buzzwords.

Why HF Radio is a Critical Asset

High Frequency (HF) radio should be a top communications priority among Armed Americans. While line of sight (LOS), tactical-level communications usually get most of the focus from those starting out in commo, HF really begins to shine when the need for extended local, regional and even global communications becomes a mission requirement for coordinating the flow of information. Why is that?

The reality of building underground resistance forces is that the coordinating entity is often outside the region in conflict. Cellular structure of that resistance relies upon long distance communications first then local level communications for distribution – in short, HF over regions then VHF / UHF at the local most level. Madman Actual discussed some time back how the Taliban implemented these techniques using the higher end of HF near 30mHz, what we call the CB band in the US, in an effort to evade ISAF Signals Intelligence teams. While they were still intercepted, direction finding (DF) of the point of origin was extremely difficult if not impossible. This level of coordination trickled down to the VHF handhelds they used at the tactical level.

The US Army is dusting off the HF skills as well. While it became an afterthought for a long while, the PRC-150 and new 160 maintained that capability in the SOF community despite the fact that Tactical SATCOM (TACSAT) took the forefront in Beyond Line of Sight (BLOS) communications. Anticipating a war with China, those HF skills become critical should the Chinese target the SATCOM constellation – and they will.

The American Partisan in that scenario has an advantage should they be equipped with HF capability and well experienced in its use. The learning curve is already mastered with the task and purpose now given. But for day-to-day situations, an HF radio becomes a pretty handy piece of equipment as well.  It opens the door to shortwave radio, which are international broadcasts of news and entertainment that are often perspectives much different from our controlled corporate media complex. Despite government tyranny, these cannot be shut down or jammed in total. During the last unrest in Cuba the Radio Recon Group used HF to transmit words of encouragement to courageous Cuban people standing up to the tyranny of communism. While the government jammed us, parts of our message got through, and was proof that freedom activism certainly extends to the world of communications.

All of this may sound dramatic to some, but it illustrates the very real role HF radio plays in a signals package and why you need to include it in your own capabilities. The learning is often high – its not exactly a plug and play affair – and sometimes the success is not an instant gratification the same way tactical level communications can be. But that said, many newer radios on the market today are built to make life much easier than in eras of the recent past. One such example is the Xiegu G90. With a built in antenna tuning unit (ATU), antenna analyzer, SDR-style waterfall display, and 20 watts output power, its one of the best units on the market for the beginner in HF or those looking to built covert / clandestine radio kits for distribution over a region. There’s other radios on the market with longer track records, but the G90 has proven itself becoming extremely popular with the parks on the Air (POTA) and Summits on the Air (SOTA) backpacking radio communities. And its for that reason I chose to offer it first to this community as its one of the best options at any price point.

Some of the references I strongly suggest to pair with an HF radio is the Special Forces Antenna Handbook (and the large-print version) for a deep understanding on antennas well suited to this purpose, The Guerrilla Dispatch Volume 1 for an in-depth look at HF operating techniques, and The Guerrilla’s Guide to the Baofeng Radio for a crash course in digital operations, data bursts and encryption which apply to any communications system. Finally, none of this matters without training – get out and put the metal in the meat.

I’ll see you out there. Stay dangerous. -NCS

Data In Motion: The Key to COMSEC

Communications Security, or COMSEC, is one of those deep topics. Its not a clean, neat answer in nearly any case, with the caveat given most often “it depends”. Whatever the purpose is behind your communications, some degree of COMSEC has to be employed. Those three distinct purposes I defined in The Guerrilla’s Guide to the Baofeng Radio as being:

  1. Sustainment: Sustaining qualities of life; emergency services, etc
  2. Tactical: Supporting / coordinating fire and maneuver
  3. Clandestine: Covert instruction / coordination among an Underground

The method by which each of these roles are filled vary widely. So-called experts get hung up on various pieces of equipment and its capabilities (or the lack thereof) baked in, always forgetting the most important part:

DATA IN MOTION IS THE TARGET OF SIGNALS INTELLIGENCE.

Whatever the medium may be in passing the data from point A to point B, it is imperative to recognize data in motion is the actual target of signals intelligence. What is not transmitted is not intercepted. If that transmission is short enough, no matter what’s actually transmitted, its also not likely to be intercepted. If no discernible pattern is observed on part of the Signals Intelligence (SIGINT) Team, it is likely they’ll miss the transmitted data by simple oversight. Last, if that data in motion is transmitted in such a way that it requires the message in its entirety to decode, it is likely that COMSEC is preserved.

SIGINT teams function at two levels simultaneously – tactical exploitation, meaning real time decision making based on what’s intercepted, and pattern analysis, done at a higher echelon over a long period of time for the purpose of predicting an enemy’s next moves based on historical behavior patterns.The former can be anything from interception of voice traffic to awareness of threats within a battlespace, the latter through analysis of previous actions. But all of this is done in the effort to, and as a result of, exploitation that very same data in motion. Without it, the SIGINT role is fruitless.

That leads us to understanding that the brevity and obfuscation of data in motion is the real key to COMSEC, with forms of encryption serving to strengthen the preservation of that data should it be intercepted. This is not to dismiss the role of encryption; quite the opposite, in fact; but it is an assertion of the reality that COMSEC begins and ends with keeping a communications plan strictly disciplined in any of the three roles of communications, transmitting only when necessary, and keeping those to short bursts under 5 seconds. Failure to do so will absolutely lead to interception by even novice SIGINT Low-Level Voice Intercept (LLVI) teams and absolutely by airborne platforms.

Once the data in motion has been found, SIGINT teams begin specifically searching for the geolocation of:

  • The Point Of Origin (POO)
  • The Recipient

The first is most critical and the easiest to target through triangulation should they transmit long enough or get overly chatty at the tactical level. Their use of electronic encryption is irrelevant, their signal gives them away to anyone with the proximity and means to intercept and get a bearing. The Recipient is more difficult, unless they’re complete idiots, transmitting a response on the same frequency and via the same recognizable pattern or method.

In The Guerrilla’s Guide to the Baofeng Radio I cover exactly how to do that with inexpensive components. A radio, of course, a K1 cable, a tablet, and free software. The techniques described in the book can work for nearly any communications means; any radio, any type. It is not isolated to the Baofeng alone.

From the SIGINT side, recognizing that interception of data in motion is the first task, one of the best tools available today is the TinySA spectrum analyzer. The ability to visualize broad swaths of the radio spectrum at once looking for those spikes that indicate something’s transmitting – coupled with a waterfall to identify what type of signals are being transmitted – any signal, analog or digital, has a unique visualization to it. When paired with a communications receiver and recorder for audio output, capturing that data in motion, followed by triangulation of the POO, expedites the process of targeting an enemy’s communications.

All of this requires training in the real world. While intelligence and communications tasks are fun topics of conversation, even the most knowledgeable out there find themselves coming up short when the real-world application is lacking. Both the Signals Intelligence and Tactical Signals Exploitation Courses should be your first stop for professional instruction.

I’ll see you out there. Stay dangerous, stay free. -NCS

Clandestine Communications: One Time Pads

Originally appears on American Partisan and in The Guerrilla Dispatch, Volume 1. One Time Pad is the most robust form of encryption used for clandestine purposes as described in The Guerrilla’s Guide to the Baofeng Radio for sending instructions to groups over a region. The best tool on the market for OTP key generation is our OTP Generator available here. -NCS

Given the current climate and direction of the United States, I believe all American Partisan readers would agree that knowing clandestine communication methods is a useful arrow to have in our quiver.

One such method for encrypting clandestine communications is the One Time Pad, or OTP. An OTP is a method of encryption that uses basic addition and subtraction to create a coded message, and is simply a table of numbers grouped into five digits (seen in Figure 1). Both the person sending the message and receiving the message have the pad, but no one else does. This means that the method is particularly strong against “Man in the Middle” attacks because even if the message is intercepted by enemy SIGINT operations, it is nearly impossible to decode unless you have the pad. It is called “one time pad” because once that pad is used once, it is never used again. Thus, even if a single pad is captured, it does not compromise the entire communication chain. NOTE: DO NOT USE THIS SPECIFIC TRAINING PAD FOR ACTUAL SECURE MESSAGES.

Figure 1: A sample One Time Pad (OTP) we will use for this article.

Pad Creation

Figure 2: A letter/symbol-to-numeric conversion table.

There are several different methods you can use to generate a pad. One method, which is “old school”, involves a typewriter or notebook and five (or more) 10-sided game dice. You would roll the dice, get your numbers, and record the numbers. We DO NOT recommend that you type the pad on a computer if it can be helped because the computer may store some or all of the file on it, thereby introducing risk and potential compromise into your pad. If you absolutely cannot avoid using a computer, the computer should be either air-gapped (which only lessens your avenues of compromise, not eliminates them entirely) or you should use a temporary operation system like TAILs and run it off a flash drive (previous AP articles on the TAILs OS can be found here and here).

The second method is to use an OTP generator such as the AmRROM[1] Dark Labs ADL-1 OTP Generator. My colleague NC Scout did a review of the system here, and I also own a system and can personally vouch that the generator makes pad creation infinitely faster and easier. The ADL-1 creates everything you need for a One Time Pad – the pad itself, a letter/symbol-to-numeric conversion table (Figure 2 shows an example of this), and even instructions on how to encode and decode messages.  Once the pad is created, generating a new pad will destroy the old pad forever. Even if you do nothing, the pad automatically deletes itself after five minutes of inactivity, ensure the pad is secure.

The important thing is that the person(s) who will be decoding the One Time Pad should have the pad and the letter/symbol-to-numeric conversion table in their possession at the time the message needs to be sent. You don’t want to be in a position where you need to transmit a secure message and have to find a way to somehow get the receiving person or station a pad AND a message at the same time (because the message is then not secure since the key to decode it is with it). This is why it is important to set up these systems and processes in place before you need them.

Message Encoding

Assume that you and your counterpart in a different county are planning to meet up to discuss some current events in your AO. You have already exchanged the necessary materials to use a One Time Pad, and you now want to utilize that pad to inform him of the location and time of the meeting. Your message reads:

Meet at the old church at five pm Tues

The first step is to convert those letters to numbers using the conversion table in Figure 2. So “m” = 79, “e” = 2, “t” = 6, “space” = 0, etc.

M e e t   _   a t    _    t h e     _     o l d     _          c h u r c h        _   a t  _     f i v e     _    p m   _    t u e s    _

79 2 2 6  0  1 6   0    6 75 2  0   5 78 72  0  71 75 85 82 71 75  0  1 6  0  73 3 85 2  0  80 79  0  6 84 2 83 0

We then group those numbers into five digit groupings and line them up under our pad (in Figure 1) starting with the second grouping in the pad. The first five digit group stays the same as that is denoting which pad should be used for decoding the message.

32244 52687 97412 86319 11011 59341 73741 29248 65123 56878 19652 15821

– – – – –  79226 01606 75205 78720 71758 58271 75016 07338 52080 79068 42830

Notice how we didn’t use the entire pad? It doesn’t matter. The rest of the pad needs to be trashed even though we used only a fraction of it for this message. The pad “32244” will never again be used to send a message. Does this mean you need have a lot of pads created? Absolutely, which is why the ADL-1 is so awesome. You can spend an hour and generate hundreds of pads for use. But, I digress.

Below, Line 1 is the message to be encoded, Line 2 is the pad, and Line 3 is the encoded message that you would transmit to your receiver. To encode the message, subtract the number on the bottom (the pad) from the number on top (the plaintext message). This makes sense when subtracting a 5 from a 7. “But how do I subtract 6 from 2?” you ask? In this case, add a “1” in front of the 2 to make it a 12 and now subtract 6 from 12. So, the math looks like this:

Line 1: – – – – – 79226 01606 75205 78720 71758 58271 75016 07338 52080 79068 42830

Line 2: 32244 52687 97412 86319 11011 59341 73741 29248 65123 56878 19652 15821

Line 3: 32244 27649 14294 99996 67719 22417 85530 56878 42215 06212 60416 37019

Verify the message was encoded correct by decoding the message yourself (which we will walk through in the next section). If it is, then send the encoded message to whoever the recipient is.

REMEMBER: Line 1 is the message to be encrypted, Line 2 is the OTP Pad, and Line 3 is what is ACTUALLY TRANSMITTED.

Message Decoding

You have just received the message from your counterpart dictating where the next meeting will be. Time to decode the message! We start by looking at the first five digit grouping because that tells us which pad to use. Then, just as in encoding, we line the pad underneath the message. Since we subtracted to encode, we now must add to decode. If two numbers add up to a two digit number (6 + 6 = 12), just drop the leading “1” and keep the 6 – just as we added the “1” in order to perform subtraction when we encoded the message. Below, Line 1 is the encoded message you received, Line 2 is the pad, and Line 3 is the decoded message.

Line 1: 32244 27649 14294 99996 67719 22417 85530 56878 42215 06212 60416 37019

Line 2: 32244 52687 97412 86319 11011 59341 73741 29248 65123 56878 19652 15821

Line 3: – – – – – 79226 01606 75205 78720 71758 58271 75016 07338 52080 79068 42830

We can now reference those numbers to our conversion table and get out message.

79 2 2 6  0  1 6   0    6 75 2  0   5 78 72  0  71 75 85 82 71 75  0  1 6  0  73 3 85 2  0  80 79  0  6 84 2 83 0

M e e t   _   a t    _    t h e     _     o l d     _          c h u r c h        _   a t  _     f i v e     _    p m   _    t u e s    _

Final Thoughts and Conclusions

 There are ways to even strengthen your One Time Pad encryptions, such as utilizing Brevity Matrices. Again, my colleague NC Scout has you covered on his blog here on what a Brevity Matrix is and how to use one. Better yet, take his Advanced RTO course and get hands on “meatspace training” on the topic as well as other methods of clandestine communications (training calendar here). Here is a great After Action Report from my friend JohnyMac on the class (we took the class together, and I highly recommend it). You can also utilize encrypted flash drives to pass the encoded messages from person to person. Using a free program such as VeraCrypt can be a powerful tool for securing messages and files. Chad “Chainsaw” Sawyer did a fantastic article for AP on VeraCrypt that can be found here and walks you through how to use it. Finally, you can use steganography to encode the message in plain sight! What is steganography? Stay tuned for my next article, because I will lay out what it is and how to use it.

You have all of the tools you need to produce clandestine communications at your fingertips, and it all can be had for free! You just need to practice with it and set it up BEOFRE YOU NEED IT. You absolutely will make mistakes, and that is okay – I still make mistakes on OTPs due to lapses in concentrations or simply adding/subtracting wrong. This is why we practice!

Just imagine if someone was able to intercept that encrypted flash drive. They would first have to break the encryption on the flash drive. If they somehow did that, they would need the One Time Pad to even get the decoded message. Then, on top of that, they would need the Brevity Matrix to decode the code words and phrases used. That is a triple layer of protection (quadruple if using steganography) that, depending on the sensitivity of your message, may well be worth its’ weight in gold.

 

The Alternative to Rolling Dice for OTP Pads – The ADL-1 OTP Generator, by GuerrillaLogistician

Originally appears on American Partisan and authored by my friend “Guerrilla Logistician”. Get your OTP Generator here. -NCS

The many facets of encryption can be daunting at best. There are many ways to deal with encryption that can be expedient while losing some of your security. If you go to one of the NCScout classes, he will go in much more detail and honestly, he teaches it far better than I can. Suffice it to say that encryption, especially digital versions, has been extremely important to everyday life for ages.  From Caesar Ciphers during the roman empire all the way to the present people have tried to hide plain text messages. During the revolutionary war invisible ink was a common item along with Mask Letters.  It has become even more important with technology from the use of passwords, securing financial transactions to how both parties organize protests using encryption apps. If you’ve been a long-time listener of scouts podcast you will also know many of the failures in security that were considered impossible to read. Not only have civilian organizations, law enforcement but even our government accessed private information. Sometimes they stopped terrorists form acting other times they arrested people over politics, but regardless of your beliefs one thing is clear. Encryption is a very complicated environment to understand for those we’re not actively learning about it.

With all that said let’s discuss what scout teaches and now currently sells on his website. The one-time pad or OTP for short is an encryption technique the theoretically cannot be broken if done properly. Without the encryption pad any open transmission of the message can reasonably be read as any message you could imagine within the length of characters.  In as plainly as I can say this the OTP you create for encryption can be any number length you wish. In theory you could encrypt a whole novel, but as scout points out in his courses the longer you are on air the easier you are to track down. Scout uses a combination of trigram and OTP for clandestine encryption. It not only shortens the message it shortens the time you are on air. Some of you will know what a number station is and although they are dying out due to the ability to use the Internet in the same fashion they still exist.

Rules for OTP

  1. Keep your message as short as possible.
  2. Each group you talk to should have their own set of OTP pads and shouldn’t be operating off a community book of pads. This will prevent the loss of an OTP from compromising everyone.
  3. Make sure any OTP pads Are distributed by hand and not over the Internet. Distributing OTP pads in a compromised manner means anyone could be reading your messages.
  4. Never reuse an OTP pad.

OTP pads

First this isn’t an article on how to use OTP pads. I am sure not only does the brushbeater website have that information, but so does The Guerrillas Guide to the Baofeng Radio.

An OTP pad for the most part is a string of five numbers that are randomly generated over and over again to get the necessary characters for a message. The reason we don’t just write down random numbers is because humans aren’t as random as chance. Back during the Cold War Russians and most likely many Americans spent hours rolling 10-sided dice. This is a small and a simple way to create an OTP, and you know for sure That these numbers can’t be reproduce. Why don’t we just write down random numbers instead of wasting the time with dice?

35684 23876 31355 25673 Human

71110 77586 00302 55636 Dice

20715 61729 79112 62131 OTP GEN

As you can see above, they look equally random but there are no 1s 0s or 9s from the human.  Also, it is rare that we string the same number next to each other.  We sadly tend to follow patterns and we also neglect things.  As you can see versus the dice and OTP generator briefly everything looks random, but to a good crypto analyst they will figure out patterns in the human touch out quickly. Unfortunately dice takes a long time although they are very easy to pack.  So instead of employing several people in rolling dice and writing down OTP pads we can rely on the power of chips to do our work. You can go online and pull a random OTP generating app for many locations. You then could transfer onto a computer that has no access to the Internet and possibly create some very random pads. Provided the author of the app isn’t setting you up with software to fool you with.  Luckily for us a bunch of hackers and nerds have done a lot of the footwork for us. Partisan labs produce an all-in-one OTP generator that will not only print out your OTP it will also print instructions on how to use the OTP properly.  This generator is open source, readable hackable or modifiable by you or others.  The hacking community has gone over this generator several times and found no faults in the coding.  They are a known entity and lean in on the patriotic side of things.  For those who know who AmRRON they are closely tied to those guys.

Several other places have sold similar devices as partisan labs, but don’t tend to stick around. With that said if you go to brushbeater store you will find he sells the exact same generator. Partisan labs aren’t the only people who make these devices Although they tend to be the ones that have stayed in business full time. I have owned one of these for a while now and while very simple they come with a small learning curve and some points you will need to remember.

If you have any issues with your OTP generator partisan labs will help you.  Mine was purchased from ready made resources.  I had an issue with a faulty printer after some heavy use, and they fixed my unit no issue.

ADL-1

https://brushbeater.store/products/adl-1-one-time-pad-printer

Not every person who preps or the potential partisan needs one of these. This device is a time saver and a force multiplier for groups. If you must deal with people across a region this device is for you, or if you happen to be the commo specialist you will want this. Realistically all this can be done with dice and time, but with this device you can securely make an OTP pad make an exact copy without the use of a copy machine. There are some drawbacks to this machine which should be noted so you don’t put yourself or people into a bind.

This device works on an entropy-based randomization system which you don’t need to know or care about. It then connects to a simple push button system that will print out your OTP pad onto receipt paper. This is phenomenal for in field use and generating small pads four teams going on patrol. The downside with the printer and its lack of ink is over time the paper will fade.  So, you won’t need to store ink cartridges, but the OTP pad has a shelf life due to heat. This means if you are going to be handing out OTP pads for long duration storage you will need some copier that is not connected to the Internet or to hand write what was generated. If anyone paid attention back in the day many printers stored copies of what was printed, so be very careful with your home copier, much less a work one. Use common sense when copying your OTP pads.

Powering the ADL-1

One nuance of the ADL’s is their lack of ability to charge your batteries when they are plugged in to land power. Without good batteries or power this device can really struggle to print out very clear pads. Luckily two special batteries come along with the device. Also, if connected to a power supply that has less amps then required you will get a blank page printed out. So, if you invest in this device you will want to get the specific battery charger for 18605 batteries, and probably a power supply. 18650 batteries are included so you are ready to print when it arrives.  Most sites that sell the ADL-1 also sell the power supply for 30 dollars, but brushbeater doesn’t.  You will have to decide what you want to get on your own, but you can buy both a charger and block for the same price.  They don’t ship with a power supply mostly because people have gotten creative with this device or have ample power supplies handy.  Below are links to what I have but shop around, buy one or the other depending on your needs.

battery charger


https://www.amazon.com/dp/B09QL23FX8?psc=1&ref=ppx_yo2ov_dt_b_product_details

Power supply 12 – 13.8 vdc. 2.1 mm center positive, 2 amps


https://www.amazon.com/dp/B00Q2E5IXW?psc=1&ref=ppx_yo2ov_dt_b_product_details

Paper



Specifications
2.25 x 1.5 inches (40mm) external diameter.
No more than 2.5 mil (0.06 – 0.07mm) thick.  About 40 ft with core, 70 ft coreless

Obviously, the dimensions of the roles are important as well, you can’t have a huge role or one that doesn’t fit in the printer. Lastly make sure the roll is placed in the machine properly. The paper should be feeding from the base of the roll towards the front of the machine, not over top of the roll. If you mess this up it won’t print anything out and the device will print a blank sheet as if it doesn’t have enough power.

Storing OTP pads

A neat trick I developed for storing OTP pads and making them readily available or just easily copyable uses baseball card binder sheets.  You can place the OTP pad in one of the slots front and back and have a binder to flip through and organize.  Add to that the sleeves make copying on a machine way easier.  Any good nerd store that has 10-sided dice will have these sheets fairly cheaply.  That said if you print out large pads, or ones with other information you may have to fold the slip.  250-character pads fit perfectly though, and 500 characters might work as well with some of the extra paper trimmed off.  You can also make them weather resistant with a bit of tape to seal the OTP pads in.

Conclusion

If you are going to be printing out OTP pads consistently or doing large batches this device is probably one of the most secure formats available. You can always do it the old school way and save the cash of this device but in the end, you will want this in your supplies if things go bad long term. I would get on the ball and buy one of these as they are not something that Amazon carries, and many stores also tend not to keep these in stock.  If you are going to be running a TOC, then this device is absolutely for you.  If you are a radio guy this will protect your communications and is a must as well.  Regardless, if you buy this device over say a DMR radio, you will most likely want OTP pads ready to go.  Either bite the financial bullet or start rolling dice get cracking.

 

 

The All-New Brushbeater Range-R Card

The Range-R card is one of those things that I never expected would have taken off the way it did – over 800 sold thus far in three versions – and there’s no doubt in my mind that if people speak with their wallets, the people have spoken in volumes in this case.

When I saw it the first time it immediately reminded me of the old PSO Soviet scope rangefinders. Put the feet on the horizontal line and wherever the head comes up to, that’s the distance to the target. The Soviet methodology of fielding Snipers was quite a bit different from the American methodology. Rather than treating them as isolated assets they were viewed in what we’d come to call Designated Marksmen, or a native asset to the larger Infantry Squad. Extended range snap shots were more critical than mathematical ranging and pinpoint shot placement. Their training program was reflective of this, based around the experiences of the Eastern Front of WWII and Stalingrad in particular. With limited ammo and resources they created riflemen and their equipment was reflective of this effective methodology.

Everything is based around averages. In real life we don’t know exactly how tall our target is, but we do know what the average of all targets are – and with that said we can create mental images of how far things appear to be. In my years of doing this I’ve gotten used to estimating range based on how things appear; people, cars, fences, etc. In many years of doing it with mils you begin to know based on what it looks like to the naked eye before you find it in the glass. It takes experience and that’s where this rangefinder begins to shine. No batteries, no gimmicks, and a low margin for error if you do your part.

But you knew all that and I’m not one for resting on laurels. How do we take a tool and make it better? How to we cram the absolute most functionality into one package? There were a few pieces of first line kit in Afghanistan that were “don’t leave your bed without” as I was discussing on the Angery American podcast last night with Chris Weatherman, Carl Ericson and the Tactical Rifleman crew last night: your compass, a map of your operations box, and a protractor. GPS was fine for confirming what you knew, but in those days just over a decade ago the Iranians were already playing man in the middle with the satellite signals. Map and paper – hard skill – was the bread and butter and it never failed us.

So with that in mind I sought to include plot pointers (the whole reason you carry a protractor) for 1:24k (UTM), 1:25k & 1:50k (MGRS) for map reading and land navigation. Based on the feedback I’ve received from the extremely popular Micro Cards, I’ve included bullet drop scales for both 5.56 and 7.62 NATO (M80 Ball) to give the shooters holdover points based on the range. All of this put in one package is designed to give the shooter an inexpensive option that requires no batteries, no IR or thermal signature, and can be used in a number of ways to train Riflemen in not just marksmanship but land navigation as well.

Get yours today.

TinySA Ultra – SIGINT SETUP, by GuerrillaLogistician

The TinySA Ultra is an interesting little device and the improvement over the TinySA.  While this is a spectrum analyzer, we can use it for signals intelligence. This article will be a basic guide for the beginner, as this thing honestly has more capabilities than this article could cover.  Some of you will find better ways to do things and I hope you will either send in your suggestions or I will meet you on the forums. The key here is research and experimentation, but for those of you who bought this and don’t know where to start this is the guide for you. Realistically you want to go to tinysa.org and find out its full potential. For the guerilla sigint guy this should get you started though.

  1. On off switch
  2. Menu switch that can be clicked inward or rotated left and right.
  3. (Not pictured) USB-C jack.
  4. (Not pictured) microSD card slot.
  5. (Not pictured) 3.5 mm headphone jack.

https://tinysa.org/wiki/pmwiki.php?n=Main.FirstUse

The initial setup of one of these is easy and I will leave the instructions with the designer or possibly a dispatch article in case your internet goes dead.  Remember to attach the cables properly before doing the self-test and calibration, as pictured above.  There are several youtubers that run through the setup as well as the info provided by the website. A couple key points for you guys.  You will want to charge your device before you really play with it, you don’t want it dying halfway through the setup. The stylus that comes along with the device makes life a lot easier.  Anything can be used to touch the screen, just make sure it isn’t sharp or will leave marks on your screen. You can also access all the settings by pushing in on the swiveling toggle button next to the power switch if you don’t have a stylus or you are in gloves. A simple press in and then moving the tab left or right will get you to where you want to go.

This is the developers initial guide to the TinySA Ultra, goes into some stuff about the device that will help some of you get around.

https://tinysa.org/wiki/pmwiki.php?n=TinySA4.Ultra

The unlock code for Ultra mode is 4321 then click the x1 to confirm that number. I will assume at this point you have done a SELF TEST and CAL with the cable attached using the links above.

Understanding the initial screen

The main screen for the uninitiated will be a bit confusing but with time you’ll figure it out fast. I will focus on what I think you should know and why.

1. This tells you what trace your pip is on, the frequency it’s located on and your decibel level. You can have more than one pip and you will get similar information next to this one.  A second PIP will have a different number and possibly color.  I will leave that info out for brevity though, refer to the website for more.

2. This is your pip which gives you basic information on 1 such as frequency.

3. This number represents how fast your scan through the selected spectrum is. The slower this scan the longer it will take to detect and the more you will miss. On the image you will see about 700 milliseconds, but this can vary greatly depending on the bandwidth you are looking at. The more of the band the longer this takes, although some settings change the scan rate as well. If your scan is long, you will see a green bar at the base of your graph coming across as the data changes.

4. This is your start frequency in the bottom left corner, and this delineates where your search begins. The 100.0MHz/ next to it is the spacing between your vertical lines on your graph and will change depending on your setting.

5. This is the ending frequency of your scanning area.

SETUP INSTRUCTIONS

All setup starts from the main menu in case you get confused, bump into something wrong etc. If you are already in the sub directory jump to that point.  If you ever get confused use the BACK button and return to the original menu screen.  You will understand this later.  All MENU directions will be MENU > Next MENU, because some of the menu items aren’t intuitive.

My preferred SIGINT SETUP

My preferred setup for signals intelligence is straightforward. Anyone who’s run any radio like the G90 that has a waterfall knows how easy it is to see people talking.  Not only can you see the frequency to tune to, but you also have a good guess on how long ago they were on. The first thing you want to do is set up your trace. The trace is the line that is going across the screen, and you have an option of up to four traces at once. I prefer a setup where I can have the Max signal strength presented to me plus a current signal strength which shows me the current reception levels across the bands I’m looking at. Underneath your trace the waterfall is continuously flowing down like a sonar screen. We’ll start with setting up the traces because anytime you do anything on this device it resets the waterfall so that will be the last thing we do.

TRACE>CALC OFF> MAX HOLD This sets Trace 1 (yellow) to show the highest signal strength received while the device is on.

TRACE>TRACE 1>TRACE 2>ENABLE This sets the Trace 2 (green) like the default trace showing you current signal fluctuation.

DISPLAY>WATER FALL (note you can do this a second time and you can extend the waterfall compressing the trace line to about ¼ the screen.  If you are primarily interested in signals over time and viewing the waterfall this will help.)

*Optional* CONFIG>MORE>EXPERT CONFIG> HAM BANDS (This displays the ham bands in your spectrum as grey vertical lines

FREQ SELECTION

All frequency selection is done by two main steps for the purposes we need. When you click on the frequency button.  The only settings you need to worry about are START and STOP.  Everything else updates itself and is of no real consequence. You’ll want to be careful of your scanning speed as it can take a long time to scan the full capabilities of this device. The slower the scan the more you will miss transmissions, especially those quick digital transmissions.  You may watch a large portion of the spectrum and then want to focus on certain areas, every time you change your frequency settings the waterfall and data reset.

START/STOP you will need to set the Start Stop on your frequency tab to the spectrum you would like to be scanning. The less frequency bandwidth used in between these two numbers the faster your scan rate, and greater chance of catching fast transmissions, or accidental key ups. This also will give you a better detailed waterfall and allow you to see each signal in more detail. If you know someone is only working with FRS GMRS radios, you can dial down to that frequency.

NUMB PAD – I have marked the number pad in the image for ease of understanding. The letters represent GIGA MEGA and KILO hertz respectively. The backspace arrow returns you to the previous screen, and the x1 is basically a confirmation or enter key.  Clicking G,M,K acts just like the x1 key and sets the frequency. I love this feature because if you don’t know anything about frequencies and somebody tells you a specific frequency to look at, you can punch it in without trying to do math in your head.  You might be half asleep in a makeshift TOC out of coffee and reliably work this device. I feel like this feature really takes the Fudd out of the equation, at least in the frequency department.

FREQ CHOICES

For the beginning SIGINT Operator, I have left a link to the US reference of band allocations. Honestly for the purposes of learning this device and seeing what’s out there zero to 800 megahertz is absolutely a great starting point. This will cover most VHF/UHF radios all the way up to cellphone signals which will stick out.  This device, however, will get up very high and you can pick up some of the civilian commercial drones very easily with this device. That said you may want to adjust your frequencies to specific areas of interest.  Also, if you happen to have two of these devices you can run one as a broad-spectrum visual aid and then set the other one to this specific band and homemade Yagi antenna for direction finding. The more you practice the more you will understand and the more adapted you will be to finding people trying to hide.

https://upload.wikimedia.org/wikipedia/commons/c/c7/United_States_Frequency_Allocations_Chart_2016_-_The_Radio_Spectrum.pdf

SAVING your Settings

When you shut off your TinySA Ultra all the settings go back to stock, so you will want to know how to set this back up.  You will also want to save your PRESET which you will have 4 empty slots for that purpose.  The settings will be stored with the frequency as reference so if you play with your settings change your frequency to know which is which.

PRESET>STORE> STORE #

You can setup your presets for them to load on startup if you wish.  I keep my startup stock personally, but this is an option.  Once you have stored your settings to load them is easy.

PRESET>Ex. 0Hz 800MHz (frequency range you selected)

Extra Knowledge

DISPLAY>SWEEP ACCURACY>

NORMAL sets the default sweeping mode

PRECISE sets the precise scanning mode.

FAST sets the fast-sweeping mode.

NOISE SOURCE optimizes the wide span scanning of noise sources.

SPEEDUP allows setting the acceleration factor for fast sweeping.

RBW – sets the scanning resolution.  I recommend setting it to auto unless you have a specific reason.

Rotate Display – Use this to flip the screen 180 degrees.  Maybe you want to mount this on something and want toredirect the USB-C cable up or you are left-handed.

MEASURE

AM settings to optimize observations of AM modulation
FM settings to optimize observations of FM modulation

LEVEL>LNA Turns on and off the Low Noise Amplifier. The built-in LNA provides up to 16dB noise level reduction. The LNA is easily overloaded and has reduced gain above 4GHz.

LEVEL>LISTEN (toggles on and off) This allows you to listen to basic radio signal both FM/AM modulation.  This wont replace a good scanner it does just the basics, but you can listen to certain signals.

CONFIG>USB used to connect to a computer with software and run the TinySA Ultra by the software.

STORAGE>SAVE CAPTURE will save an image of your trace, you can also use LOAD CAPTURE to displace your trace.  I suggest for ease of operation to have AUTO NAME checked on.  It will not save waterfall information.

LESSONS you can visualize.

The last little bit of knowledge I want to present comes from instructions out of the Guerillas Guide to Baofeng.

Lesson 1 Transmission Length – Try sending a transmission using analog/digital in voice, then use either a text message feature or text with a tablet.  Compare the length of time.  If you want to really flex your SIGINT skills have a friend select the frequency, and try to tack them down.

Lesson 2 Antenna Polarization – Try watching a person who is talking the radio from vertical and horizontal antenna positions. Using a stubby antenna and getting some distance will show you how the signal strength changes.  You can also try guessing how the radio is being held with the stock antenna by moving it from vertical to horizontal.