Encryption with Trigrams
One Time Pad Encryption The Easy Way
Drone ISR Course Video
Digital Radio will get you KILLED (and how to avoid that)
Follow Along to ENCRYPT your BAOFENG Radio using ANDFLMSG
Signal Compromise: What to Know
If you’ve been following the news in the Tech world over the past 48 hours you’ll know the revelation that’s now too big to hide: Signal Foundation has disclosed that its messenger system has been compromised leaving millions of accounts exposed, including government representatives and journalists. This is no doubt the work of nation state actors (all signs pointing to the Russians) but, and I can’t emphasize this enough, you were warned.

Signal is not and has never been ‘secure’, despite what the marketing tells you along with the criminally stupid parrots or bad faith actors you’ll find online. Its primary draw has been convenience: it claims and end to end encrypted messaging, calling, and video conferencing app that (so they say) has ‘never been broken’. Its just so doggone easy that its a one stop shop for making all your bad dreams into good ones. The devil is in the details. Signal’s data is centralized, meaning all of its pass-through traffic is located in one place (think of a storm drain here and you get the idea). In case you didn’t know, that place is Amazon Web Services. Not good for privacy. Further, Signal requires an account to be registered with a phone number, which is in turn tied to a laundry list of metadata even if the user is generating ‘randomized’ phone numbers. Real life is not a Jason Bourne movie and, since the US Government was dumb enough to authorize sensitive data to be passed along Signal’s network (because their own assets built it, but that’s another story), it became a big juicy target for foreign intelligence services both friend and foe alike. All that’s needed is a target’s phone number and a winning attitude.
As I’ve shouted from the rooftops for years, Signal is nothing more than another white side messaging app. There should be zero expectation of privacy on it, let alone security nor anonymity. Because its white side, no sensitive data should be passed through it. I don’t care what big bruv gov says, they’re wrong and never authorize anything they do not have a backdoor into as it is, but now we know the rest of the world does too.
What actually took place (this time, anyway) was a relatively simple phishing attack. Any user can see a list of registered accounts on Signal by simply searching phone numbers. Take a list of those numbers registered to a geographic area (DC is a great place to start) and blast out a link designed to harvest the target’s data when they click. Very simple attack nearly as old as the internet itself. Once you’ve got that then you’re in – you’ve got the account data in real time. Wasn’t sophisticated by any means as they claim.

So – what does this mean for you? I’ll say again that Signal is not nor should it be considered in any way secure. It lacks basic security features such as masking users’ data which is in part by design. Signal Foundation cannot nor will they change this. Its a feature, not a flaw, as part of the program’s original mission: to have a government use messaging app that bridged mobile devices to computers in a centralized system that could be supervised. That’s why their boss, Katherine Maher, is a hand picked spook who comes from a family of spooks. Doesn’t mean don’t use it, just means don’t use it for anything serious. And if you do, don’t be shocked by the consequences.

Serious alternatives must have the following characteristics: decentralization, open source code, and a random user hash generated as the account identification. It also needs to have basic privacy interfaces such as a notification when screenshots are taken. Signal doesn’t do this much to the woe of many dumb users getting caught using their inside voice outside in a dumbass group chat. There’s too many to name these days and keep in mind this list is in perpetuity – what we do today we might not be doing next week – but some strong options are SimpleX, Session, Briar and DeltaChat. Do not, and I can’t stress this enough, pay for a messaging app if you’re at all concerned about obscuring metadata. For starters its stupid with the sheer number of great free options, but also it creates yet another metadata blip on your attack surface. The four I mentioned each create a random user hash, are end to end encrypted (and have been independently audited by someone other than a trust-me-bro) and, most important, do not host users’ data on AWS.
As always this goes hand in hand with sound tradecraft practices like compartmentalizing your contacts and keeping your electronic devices shielded from connectivity when not in use. Woe unto he who doesn’t use a faraday bag to protect his mobile devices.
A Coming Ammo Crunch?
You’ve all been hearing the rumors, but where there’s smoke is there fire? I’ve had several reach out over the past week about ammo shortages starting to manifest on the supplier side. Since we’re in kinda a unique position as an ammo wholesaler I can shed some light on what’s happening. Bottom line up front, its probably a good idea to pick up some more of whatever your caliber of choice near term.
The War with Iran is causing a residual supply chain crunch both on the shipping side due to fuel costs (which is in turn raising material cost) and also fears of a potential deployment of ground troops in an expanded capacity. I don’t personally see a ground invasion of Iran proper happening, but I do see expanded combat deployments to Bahrain, Kuwait, and Qatar as a quick response force for the targeting of US assets in Iraq. This is not ending anytime soon in spite of signals attempting to quell investor fears. Its definitely happening. On top of that, I also expect expanded ammo budgets for DHS and DOW which will in turn divert production to meet those demands. So, availability is going to become more limited.
There’s other elements to this as well. Earlier this year Palmetto State announced AAC’s ammo production would become limited due to a powder shortage. This is largely reflective of the ammo industry operating at capacity as is with demand largely exceeding capacity. A war, and a potentially brewing larger one, strains that further.
So in short there’s absolutely a coming ammo shortage the effects of which haven’t hit the consumer side just yet, for how long who knows. But I do know we anticipated the problem and made moves before hand to keep prices on our side stable.
Stay safe out there and train hard. -NCS
Tablet Tradecraft: Rules For Clandestine Messaging on Mobile Tablets
Scenario: You’ve got a team of pipe hitters you’ve assembled to do all the things. You’re running radio as both a clandestine and tactical organizational net (a la The Guerrilla’s Guide to the Baofeng Radio) but there exists a gap. Not all your trigger pullers are sitting beside a radio waiting to get rally point instructions. Mobile devices are a reality of the asymmetric battlefield, and although the example might sound dramatic, if you think about the world in those terms simple security measures become easy. Proper tradecraft permeates all aspects of life and in practice, the very same aims many have for privacy, security and anonymity resonate well with sound practice.

First things first, break out of the ‘all or nothing’ mentality. Security tradecraft, and in turn messaging, is an ever evolving continuum in terms of technology. While I understand that technology is beyond the reach of some, simply shutting down or defaulting to one particular tool is absolutely bad tradecraft. Statements like ‘well everything is compromised’ or ‘we’re just going to do it this way because so and so won’t train’ is a non-starter. Those are excuses. Either learn to learn or you will learn to suck, but either way don’t complain about the results.
So let’s talk about those mobile devices. Before we even get into the basic operating rules an underlying truth is that the device itself must be open source, easy to source in my working environment, and mitigates the physical RF footprint it emits. What’s that mean? WiFi-only Android tablets. I need the ability to configure a device on the fly and get several of them up and running in a hurry. A WiFi tablet has no inherent data connection unless I enable it, and even then its only connecting where I want it. If you’ve got a cell connection on your tablet, congrats, you just have a big cell phone.
Let’s talk messaging apps themselves. The watchword here is decentralization. While no messaging app should be considered completely secure, there are several that work quite a bit better than others. Decentralization means that messages are stored and forwarded through a network of nodes rather than a centralized host. What this does is layer the data in motion between the sender and the recipient. Further, if you’re sending via one means and receiving a response on another (otherwise known as backchanneling) you’re creating several smokescreens for that data in motion. Impossible to track? No. But a hell of a lot harder than using a centralized platform such as Signal.

One of the things I do is keep a SD card pre-loaded with the apps I plan to use. This involves downloading the physical APK files themselves from Github – most of developers have a dedicated Github page with a clean install file of the apps you’re looking for. We’re not using Google for this – the idea is to reduce the amount of metadata as much as possible while keeping in mind the only absolute way is to not use it at all, which doesn’t do anything to solve our problem. Loading APK files on the tablet itself is pretty easy, just make sure to click through the ‘enable installation from this source’ in the system security settings and you’re off the races. Make sure that the messaging apps you’re installing are routing all of their traffic through Orbot, which is the Android equivalent of Tor. What this is doing is masking your data in motion the same way most people understand a VPN does. Orbot can be configured to activate when the device is turned on, adding layers to the onion that is data in motion. Keep in mind each of these layers is a smoke screen or an obfuscation of the point of entry (or exit in the case of the recipient) into a network. Its not an absolute all-or-nothing; your behaviors and uses are.
Let’s get into where to go from there.
White, Red, Black: Compartmentalization of Contacts is Key.
Far and away one of the most difficult concepts for civilians to wrap their minds around is compartmentalization. I’m not talking to everyone via the same means. And on that note, I’m also not setting up a group chat that we all have equal access to. Equality is for communists, effective organization demands hierarchy. The game is mitigating what can be scraped by bad actors and everyone seems shocked every time one of these rather dumb group chats gets its content (and members) leaked online via screenshots. If you’re organizing people for purpose, each of those needs to be compartmentalized with as few contacts in the compartment as absolutely necessary. This is a simple counterintelligence technique that goes along way to stymie threat actors.
Contacts and the method of communications are broken down into three colors: White, Red and Black. White side communications are those where the association between sender and recipient are known and the data itself is not sensitive. While you’re not necessarily shouting it in public, the means and method itself is not obscure. Red side communications have a sensitive purpose with an association possibly known between the sender and recipient. This is a more private sidebar where sensitive topics are discussed or short timeframe coordinating instructions are given. Black side communications conceal both the relationship between the sender and recipient. This is where clandestine instructions are being given, with both sender and recipient understanding how to decode the message itself. More on this in a bit – but this is where physical encryption comes into play.
Practice Wardriving.

Wardriving is the art of moving around in a working environment looking for open WiFi connections and using them. Normally this carries the act of actually driving in a moving vehicle along with it, but, its not limited to that. for our purposes we’re simply sending a message – no network intrusion or stealing credit card numbers. Most public spaces have open WiFi connections even if they’re notionally password protected. Coffee shops and fast food joints normally have a very basic password that they hand out to customers. Normally you’d want to avoid these connections like the plague for security reasons, but in this case, this is where we’re connecting to the internet to send our message. Once we’ve made our comms shot, we’re disconnecting and moving on.
Disrupt Your Own Patterns Of Life.
We all have our own bad habits. As I break down in The Guerrilla’s Guide to Signals Intelligence, patterns of life are everything that encompass our daily routine. Humans are creatures of habit and those patterns of life are the timeline by which we conduct our behaviors. This extends to our network of contacts as well. Assume everything is being observed, whether physically or electronically (because in the case of the latter, it absolutely is). What’s routine for us becomes known as our baseline. Everything that violates that baseline then becomes a potential action indicator. One of the goals we’re accomplishing through using a WiFi tablet for messaging is obscuring our patterns of life as is. None of our tools make a difference if the underlying behaviors haven’t changed.
The first thing this entails is under no circumstances using a device for clandestine purposes from a network node associated with you. This might seem trivial to mention but you’d be surprised how many people manage to mess this one up. I can recall more than one HVI from Afghanistan getting rolled up from us running time-sensitive targeting (TST) on their cell phones that didn’t previously have an association with them simply from being powered on at their last known dwelling. Today we have AI tools doing exactly that and its largely non-governmental. Might sound Orwellian but welcome to the tech reality. In order to mask that, you’ve got to change your own daily habits. Hard, maybe, but functions of the underground aren’t easy.
Don’t Rely Exclusively On Electronic Encryption.
Far and away electronic encryption is the kryptonite of the spec-reciters and otherwise ill-informed. Its no more than a sales buzzword. This is not to say that messengers claiming a specific level of encryption of traffic do not live up to the claims, often they do, but the devil is always in the details. Everything has a weakness ranging from problems in the algorithm to flaws in the user interface to the user himself. No matter how well designed an app may be there’s some design issue buried within which becomes an exploit in the attack surface.
The most common one of these has nothing to do with the method of electronic encryption: taking screenshots. Let’s say you’ve set up a Red Side net with three others. One of those is compromised and proceeds to take screenshots of the messages themselves. His handler has you. Whoops. Messenger apps that are truly privacy-conscious have a notification to all users as soon as there’s been a screenshot taken. On that note, you should have a setting to sanitize messages on a set period after the recipient has read it.
On the less dramatic side recognize that without your own audit, you’re simply going off ‘trust me bro’ for what might cost you your life. I’m kinda funny about that personally, not out of a sense of self preservation but rather commitment to cause. Doing things wrong gets people killed but more importantly kills the objective of your movement, which is a reality very few in the US understand. Its not your fault, you’ve been insulated from consequences for too long and video games made you stupid. But as a friendly warning, all of this stuff is fun and games until you get hurt.

Clandestine messages, even being sent over ‘encrypted’ apps, absolutely must be physically encrypted. While there’s a ton of different ways to do this I’m a big fan of using trigrams (such as in the appendix of the Guerrilla’s Guide to the Baofeng Radio) due to their simplicity. Trigrams are handy due to having a master list that can be used over a longer duration versus One Time Pad, which has a finite number of messages defined by the number of pad keys that both the sender and the recipient have.
Trigrams are faster and simpler, but suffer from a potential complete compromise if one of the keys is lost or captured. A cryptographer tasked with counterintelligence has to know first a list of words assigned a trigram and second the rotation of the letters. If the key itself is compromised they have both. The strength of One Time Pad (OTP) lay with its absolute robustness of encryption: it is unbreakable if used only once. So while it may take more time (at least at first), OTP is the most robust method even if more labor intensive.

Another element to physical encryption is simple codewords used as action indicators for short messages. These are most often used to indicate a compromise of a device or an asset, signaling duress or waving off an activity already in motion.
When Not In Use, Put It Away.
It’d be kinda off to be walking down the street with a radio in your hand, right? Visibility aside, you wouldn’t do that due to exposure – when a tool is not in use we put it away. But that said with electronic devices there are tools which can exploit their contained data even when we assume they’re powered off. Long story short, this is not usually the case.
Expanding on that concept is the question of whether or not you’re really disconnected from that network even if you think so. You may not be. I’ve encountered public spaces that connected to my devices without my permission during traveling even with all connectivity shut off. The Denver Airport still connected to my phone even though I was running CalyxOS at the time and had all data switched off as I usually do while traveling via air. Now exactly how they connected is another topic for another day, but the bottom line here is that just because you assume one thing doesn’t make it so in reality.
The only way to be sure is to create a physical air gap which is something I do with all of my devices when not in use. Its not that I’m particularly paranoid about technical surveillance or that I have an overbearing fear of an EMP taking our devices offline. Paranoia would imply an unfounded fear, and my concern comes from knowing damn well the capabilities exist in both cases. For this reason I’m a major proponent of using Faraday bags to create a physical barrier between your device and your working environment. This rule absolutely applies to a tablet you’ve configured for clandestine messaging. When you’re done doing business, device goes back in the bag.
Everything Is Disposable.
This last rule applies broadly to just about every tool an asset might employ in a working environment from weapons to clothes to electronic devices. Once used its contaminated and needs to be destroyed in the event of a compromise. How you go about that is up to you, but just know the simpler the better.
This goes back to the original rule above, that one of the necessities of the device itself is that I can source and reconfigure a new one on the fly. If I’m married to one particular device to do all the things, replicating it under duress becomes a major problem. Having all of my files ready to go makes life easy.
The nice thing about practicing tradecraft techniques with tablets is that you can do it in public and most people won’t bat an eye. It costs you very little other than some time and you’ll learn a thing or two in the process. Get out there and get after it. -NCS
PVS-14: Covert Surveillance Tool
One of the more common questions I get from first time night vision buyers is to break down the pros and cons of single tube units versus duals. Obviously there’s a price point at work in there guiding the decision, but I always stress another angle as well: don’t undervalue the utility of the PVS-14 in a semi or non-permissive environment. Lemme explain.

Dual tube night vision is great because there’s no change in your depth perception under them. This is a huge deal if you’ve ever stumbled around in the woods at night or driven with them. The PVS-14 can take some getting used to if you’re unaccustomed to walking around basically with one eye covered. But in the land of the blind the one-eyed man is king, so to speak, and that was undoubtedly the case across my last two deployments overseas. In Kirkuk I ran a PVS-7D and I’d rather forget that experience. Obviously dual tubes are what most people seek and for a good reason.

But with that said dual tubes come with essentially double the weight and, what I think is quite a bit more important, a significantly higher signature. Let’s talk about semi-permissive and non-permissive environments and why you’d need a Night Operating Device (NOD) in the first place. The general rule of thumb in the modern era is that night vision is for movement, thermal is for target detection / static observation. So with that said night vision becomes the tool of choice for activities in support of an underground network: moving logistics, surveillance, and close target reconnaissance. Each of these tasks require maintaining a plausible cover for action / status. You’ll have to be able to explain away your pocket lint if you’re caught, so the lower the profile the better. And that might include driving, sneaking around in back alleys and breaking into dark spaces. Think Watergate Burglars and you get the idea. G. Gordon Liddy would have loved some decent NODs, I’m sure of it.

In this case the PVS-14 really begins to shine. I can carry it in my pants pocket and conceal the support equipment (a night cap, J-arm and mount) on other parts of my body. If I’m running duals I’ve got a significantly higher profile. A PVS-14 is small enough to be hidden in a lot of public spaces and go unnoticed – even in a camera bag it doesn’t exactly look out of place. Duals on the other hand look exactly like what you’d think NODs look like. Now, these assumptions might not keep you out of trouble, but it is a worthy consideration when you’re explaining every potential angle of a cover for status.

There’s one other practical aspect of the PVS-14 that many miss and its the most fundamental rule of common sense. Two is one, one is none. If I have two devices now I have another equipped person on my team. By myself, I can only see what I see. But someone has to pull security. The ability to crossload capabilities is critically important; inevitably not everyone has the means to afford night vision in all cases, but it in no way diminishes the reality that having NODs is mission critical.
