Category Archives: History

Introducing RAIV: Redundant Array of Inexpensive Videocards

Since Wirken.AI supports open weights, the question comes up often how big can it go. Well, I lived and worked through the early 1990s of DEC Storageworks RAID, as pioneered in the early 1980s as disk shadowing on the HSC50/HSC70, and my mind immediately went to repeating the past.

Source: Internet search

Cheap datacenter GPUs are being sold used in volume. Pooling them for local inference is well documented, so we just need to think about the redundancy. This is a build with a mirror and a spare, the way we built disk shelves in the old days.

Introducing the Redundant Array of Inexpensive Videocards (RAIV).

AI dance all day
AI dance all night, all weights
local, all is right

Parts

Who knows where prices will go, but here we are in September 2026. The MI50 figure is Pillitteri’s August survey; the board and CPU combo is the going rate from online markets.

Qty Item Unit Line Note
7 AMD Instinct MI50 32GB, used €220 €1,540 6 in two mirrored groups of 3, plus 1 spare. Verify 32GB on each.
1 Supermicro H12SSL-i + EPYC 7302, used €900 €900 5 x16 + 2 x8 PCIe 4.0 slots. Any 7002-series EPYC is fine.
4 16GB DDR4-3200 ECC RDIMM, used €30 €120 64GB. More only if you offload to CPU.
1 2TB NVMe €120 €120 Model storage.
2 1,200W ATX PSU, 80+ Gold €180 €360 Each card needs two 8-pin. Split cards across supplies. Add2PSU adapter to sync.
7 PCIe 4.0 x16 riser cable, 30cm €35 €245 Double-width cards will not sit in adjacent slots. Risers space them out.
7 MI50 fan shroud + 40mm server fan €15 €105 3D-printed shrouds are on Printables; Delta or Sunon fans.
1 Open GPU frame, 8 slot €60 €60 Mining frame. A 4U case works if you have the rack depth.
1 Fan controller, PWM, 8 channel €25 €25 Server fans at full speed are unpleasant.
1 CPU cooler, SP3 €50 €50
Total ca. €3,530 96GB usable per mirror, 192GB across both, 32GB spare.

For comparison, one DGX Spark is 128GB for about $4,000. Two RTX PRO 6000 cards are 192GB for around $17,000.

Quality Test Purchase

Before you get a pack, try getting one card and testing it. Run rocm-smi –showmeminfo vram and confirm 32GB. Load a model that fills it and run for an hour. It’s a problem in the market that 16GB cards are listed as 32GB with modified firmware. When one passes, then you can feel better about getting six more from the same seller.

Board Setup

BIOS: enable Above 4G Decoding and Resizable BAR. Without them the cards do not enumerate; one builder replaced a motherboard over this. Give each card an x16 or x8 slot. A card on a one-lane riser holds weights but cannot process a prompt at usable speed.

Given this isn’t fancy cooling, limit each card to about 150W with rocm-smi –setpoweroverdrive. Generation speed is limited by memory bandwidth, not compute, so this limit will affect little.

Software

Ubuntu 24.04. Do not install the ROCm SDK, since AMD in their vendor wisdom doesn’t support it; the ROCm 7.0 changelog reads painfully “Removed support for AMD Instinct MI50 and MI60.” Use one of the gfx906 llama.cpp containers that bundle the ROCm 7.2 runtime with kernels built for the card. The host needs the amdgpu driver and your user in the video group. The Vulkan build of llama.cpp is the fallback. Recent Ollama releases omit the gfx906 files; skip it.

Mirror and Spare

One model across all seven cards is a stripe. If a card fails, the process exits, and the model no longer fits. Ruh roh.

Split into two groups of three. Run two llama-server processes, one per group, each with its own copy of the model, on two ports. A 100B-class model at four-bit fits in 96GB with room for context. Put nginx or Caddy in front with a health check on /health and failover between backends.

The seventh card stays installed, powered, and idle. When a card in group A fails, the proxy serves from B. Move the spare into A’s group, restart A. One in-flight conversation is lost. Dance, dance, dance.

Test

Load both groups. Start a long generation on A. Pull the power lead on one of A’s cards. Time until the proxy serves from B. Restart A with the spare and time the reload. Record both.

Run all seven cards at full load for an hour and monitor the host: CPU temperature, VRM temperature, PCIe errors in dmesg.

Fun fact, in 1997 I built a fat Sun workstation to run a hospital’s massive StorageWorks shelf (fronting a huge robot arm that fed tapes from a room full of them) and the whole thing shut down under load from the Sparc (CPU) overheating, not from the disks. Ah, the good old days.

I found no published failover timings for a build like this, in any language. Let’s do this and publish some. Share and share alike.

Russian Fingerprints on the Manufactured Ceuta Crisis

Two weeks ago, on the anniversary, I posted the mechanism of the 1953 Tehran coup: buy the press, hire one mob to riot in the government’s name, hire a second mob to attack the first, and let the resulting chaos prove the government has lost control.

Think about everyone in the street being paid by the same source to whip up attention. The modern-day Ceuta crisis in Spain had been running in the news for twenty days when I posted the history of Iran. And then today I read a Spanish police report that was like deja vu all over again.

On 30 July 2026 a crowd that had been mobilised to look spontaneous walked into Ceuta and a government began to fall. Right, ok, but on 19 August 1953 was a crowd paid to look spontaneous walked through Tehran and a government fell.

Back in the 190s every visible actor in Tehran was Iranian. It took sixty years for the actual operators to admit they came out of Washington and London. Fast forward to today and the Spanish Prime Minister, three days ago, named Russia and Israel within five weeks. Too soon? Well, he is being destroyed for it by the kind of people who would say they still believe Iran was overthrown by Iranians, or that the moon landing was fake.

Red Hot PDF

Let’s look at the police report. The Centro Nacional de Inmigración y Fronteras (CENIF), the intelligence unit of the National Police’s immigration and borders directorate, prepared a 55-page one at the request of Plaza 3 of the Central Instruction Court at the Audiencia Nacional, Judge María Tardón. The data goes until 26 August. Demócrata has published it as a PDF. There also is a 61-page technical annex on the digital organisation, ten dossiers on uniformed officers and 24 on plainclothes handlers. The four videos are listed but not released.

Here are the juicy bits, in the order made by the report.

  1. The entry was a process, not an event. The report refuses to analyse 30 and 31 July except as a procedure with a before, a during and an after, and states flatly:

    No se trata de algo incidental cuya generación pueda asociarse a un factor ocasional o espontáneo.

  2. The crowd was not migrating. Of those who entered, no fewer than 90 percent returned to Morocco voluntarily and almost immediately; the report puts migratory intent at five to ten percent. Nearly all were Moroccan nationals. They moved, in the report’s words, with relative calm, no crushes, no bottlenecks, conveying a sense of impunity, as a movement free of any consequence, and that perception was probably reinforced by what the report calls the “almost active” tolerance of the Moroccan security forces. Migration, the conclusions say, operated only as a formal cover.
  3. The mobilisation was built. Open platforms first, Facebook, Instagram, TikTok, from 24 July; then closed WhatsApp groups on 29 and 30 July with operational instructions, including the advice that each group communicate by handwritten note rather than online because the internet was monitored. The message count in monitored groups peaked at 1,974 on 30 July, a 3,363 percent increase over the maximum before the 28th. Three distortions gave it credibility: Supreme Court judgment 814/2026 on border rejections, reduced to the viral line “if you enter swimming they can’t return you”; Spain’s closed extraordinary regularisation, reduced to “in Spain you get papers in the end”; and Throne Day. The report reproduces an Arabic poster with Pedro Sánchez’s face on it announcing 30 July 2026 as the last deadline before Spain closes the door on regularisation. The Prime Minister was the bait.
  4. Throne Day was the cover. The official ceremonies were held at Rincón/M’Diq, a few kilometres from the border, with the King, the establishment and foreign guests present. The report reads the choice of date two ways: it seeded the message that the security forces were busy with the royal protection detail and the frontier was unguarded, and the King’s proximity carried what the report calls a “tacit consent” that implicitly accompanied the viral campaign. A message circulating in the days before: “There will be attacks from the sea and from El Kriay, through the forest and by Bab Khemis, on the occasion of Throne Day.”
  5. The Moroccan cordon stood down. Satellite imagery at 17:07 on 30 July shows police presence confined to the entrance of the official crossing; none on the beach access, the breakwater, or the roads and roundabouts from Castillejos to El Tarajal; taxis parked in order on the left of the Bab Sebta roundabout; the main routes open while a crowd accumulated on the beach and the roads. The report calls the Moroccan police response over 30 and 31 July “at the very least, total permissiveness”: not a single serious attempt to reduce, disperse or move the crowd from the perimeter on the 30th. Interviewed migrants say, almost unanimously, that Moroccan officers were not merely passive but gave directions to enter through the water at the breakwater and not by other routes. Open-source video shows uniformed officers directing people toward predetermined access points and organising heavy vehicles carrying large numbers of people, and non-uniformed individuals managing the flow, in some cases giving instructions to the uniformed officers. That video is titled “Ceuta_Agentes_Dinamizadores” in the annex.
  6. The crowd was sequenced. First wave to 11:00: males 15 to 25, high proportion of minors, 95 to 98 percent Moroccan, equipped with wetsuits, fins, floats and waterproof phone cases. Second wave 11:00 to 22:00: adults to 40, whole families, small children at 18 to 25 percent, sub-Saharans at 20 to 25 percent, in sportswear and flip-flops, no equipment. Third wave from 22:00 through the 31st: the first profile again. The report assigns the two phases explicit tactical objectives. First, collapse the border management system at one point in one way, diverting Spanish capacity to sea rescue while saturating the reception yard. Second, once the yard gate was opened, eliminate Spain’s capacity to respond, because a notable presence of families, women and small children “deactivates the possibility of using coercive means or reactive force to re-establish control.” The report considers 75,000 to 85,000 people reaching a single point without road blockages, transport failures or public-order incidents “incompatible with a group of spontaneous origin, with no internal organisation, and no minimum support of directed organisation on the ground.”
  7. The mafias couldn’t have done it. CENIF ran the five known maritime smuggling organisations and the four to six Ceuta narco groups through Europol’s SOCTA criteria. One smuggling group operates in Ceuta, with capacity for three to five people a day. Since January 2024: 2,983 operations, 1,822 arrests, and “not a single reference to these organisations encouraging the mobilisation.” They had never had the capacity to summon 75,000 people even at peak strength in 2021 to 2023, and the operation made them no money: the only detectable reaction was opportunistic, about 150 people moved to the mainland by 24 August at a discounted €5,000 a head.
  8. The state that could stop it, did. On 15 August a second call went out, more visible and earlier than the first, without the “unique opportunity” framing, directed at the fence rather than the water, and answered by an almost exclusively sub-Saharan crowd. Morocco detained 294, 248 of them sub-Saharan, allowed nothing to reach the fence, and expelled the Spanish press from the area. The report:

    Es decir, parece que asistimos a un proceso “manejado” de forma que una segunda convocatoria artificialmente más detectable se convierta en un ejercicio de control que “blanquee” la gestión precedente de la respuesta de las Fuerzas y Cuerpos de Seguridad.

    The report describes the whole as “actions of calculated ambiguity and gradual advance with intermittent activity,” which it identifies as the signature of grey-zone strategy, projected “not on Morocco but on Spain and the international community.”

  9. The author is unnamed by design. CENIF describes five levels, from the crossers up through message dynamisers, on-ground organisers and planners to direction, and states that Level 5 could not be individualised by the delivery date, while noting that “the basis of its conception seeks the concealment of authorship.” Eighty-two bodies were recovered in Spanish waters, by telephone note from the Ceuta Instituto de Medicina Legal on 26 August. Morocco acknowledged fourteen.

The Formula

The CIA’s internal history of Iran, obtained under FOIA and published by the National Security Archive in 2013, states plainly:

The military coup that overthrew Mosadeq and his National Front cabinet was carried out under CIA direction as an act of U.S. foreign policy, conceived and approved at the highest levels of government.

The operational perspective comes from Donald Wilber’s 1954 after-action report, Overthrow of Premier Mossadeq of Iran, written as an eyes-only handbook for future operations and leaked to the New York Times in 2000. The State Department’s 2017 retrospective FRUS volume supplies the NSC and CIA files around it. Read all together they describe a method.

Disinformation is built on a grain of truth, which can be any real grievance.

Nothing actually new there, except confirmation where it was applied. Iran’s Mossadeq had dissolved the Majlis by referendum; the propaganda campaign Wilber ran through paid Tehran newspapers turned a constitutional dispute into a story about a dictator in league with communists, with some of the articles written in Washington and placed in Tehran. Crowds purchased in advance and released on cue, through people who controlled the protection rackets. A first mob sent out shouting for Mossadeq and for communism, to frighten the middle class and the army. A second mob hired to attack the first.

Handlers on the ground coordinating by phone while Kermit Roosevelt ran it from inside the embassy compound.

And afterwards, perhaps most relevant to operators today, a story of spontaneous national uprising that the authoring state defended for six decades, including a 1989 FRUS volume that historians called a fraud for omitting the operation entirely.

Let’s map it to Tarajal.

Real grievance: a Supreme Court judgment, distorted into a slogan, with the target’s own Prime Minister on the poster.

Crowds assembled in advance: 80,000 people arriving in taxis on clear roads.

A first mob to produce the crisis: young men with fins to exhaust containment, then children to disarm it.

Handlers: 24 dossiers and ten uniformed fiches, and video of the plainclothes men instructing the uniforms.

And then the second mob: On 15 August the call went out again, louder, and the same security forces that had stood back on 30 July detained 294 people and closed the border. CENIF calls the second call artificially detectable and its function laundering. Roosevelt would have called it the second crowd: the same source producing the chaos and then producing the order, so that the target government is seen to have lost control and the neighbour is seen to have it.

The report’s own comparison table shows the method being refined as it was running.

May 2021 Aug–Sep 2024 Jul 2026
Moroccan presence before Reduced Increased Reduced
Response during Permissive Containment Permissive
Entries ~10,000 1,000–2,000 75,000–85,000
Follow-up call None 15 Sep, 3,795 arrests 15 Aug, 294 arrests
Second-call outcome Absolute control Absolute control

Wilber wrote his history as a handbook. This one is vibe coded, iterating through three pushes.

The crowd of 30 July and the cordon of 15 August marched to the beat of the same drummer. That is the actual point, which begs the question of who. The lesson of 1953 is that nobody in the streets of Tehran was American. Duh. The Iranian police turned, the Iranian mobs marched, the Iranian papers printed. Reading the uniforms tells you who executed. It never tells you who authored, and it never will, because the method is designed so that it won’t.

The report sounds just like Iran, but Ceuta in its own words: the basis of its conception seeks the concealment of authorship.

The Call

On 31 August Pedro Sánchez told Cadena Ser that after 30 and 31 July, disinformation had spread on networks tied to Russia, Israel and an international far right that uses migration to attack Spain and Europe, and that Morocco had neither conceived nor executed the entry. The second half of that is where he is vulnerable, and I come to it below. The first half is the correct reading of a hybrid operation, and it is the reading his critics refuse to make.

Start with the category. When Belarus moved people to the Polish and Lithuanian borders in 2021 and Russia moved them to Finland’s in 2023, the Council and Commission named the method: instrumentalisation of migration, a third state moving bodies to an EU frontier while Russian channels amplify the collapse. The signature of that method is not a Russian in the street. It is state-attributable amplification at hour zero. EUvsDisinfo exists because of it. Sánchez was invoking a category the European Union had already defined against Moscow.

Then the finding. The EEAS confirmed Russian attempts to exploit the crisis online. The Commission had said on 6 August that the actors were Russian state media, diplomatic channels and government-sponsored outlets, amplifying across multiple platforms from 30 July. Diplomatic channels means embassy and ministry accounts. That is the Russian state acting under its own flag during the crisis, not a proxy. Brussels added that it saw no Russian activity before the 30th, and the Spanish right ran that caveat as an acquittal. It is the opposite. In an instrumentalisation campaign, arriving at hour zero with prepared assets is the participation.

Then the escalation. Three weeks into the crisis a pro-Russian group, NoName057, whose named leaker is a teacher wanted by the Audiencia Nacional, living in Russia under Kremlin protection and on Europol’s most-wanted list, published a 500-page file of names, photographs and phone numbers of around a thousand Spanish police, Guardia Civil and military personnel. Spanish intelligence attributes it; JUCIL has it before the Audiencia Nacional. In the same window an anonymous account calling itself The Political Room announced a mysterious 120-page CNI report whose only takeaway was that the CNI had monitored Moroccan networks and must have warned. Nobody has produced it; Demócrata could not verify it exists. CENIF’s final conclusion calls the resulting assault on the CNI a textbook offensive counterintelligence action. Doxxing the responding forces and discrediting the intelligence service are not commentary on a border incident. They are the second mob.

Then Israel. Its UN ambassador, on day two, asked why Spain still maintains colonial enclaves in Africa. Its foreign minister called the Spanish Prime Minister a liar. Its defence industry built the eyes over the border: Barak MX in 2022, Heron drones, a billion-dollar IAI reconnaissance satellite in 2024, Elbit artillery in 2025, a joint military committee with Rabat that met in Tel Aviv in January. The EEAS found only isolated accounts on the Israeli side, and that is fair as a finding about bots. It is not a finding about a state whose officials joined the operation in their own names.

Then alignment. Moscow signed its Deepened Strategic Partnership with the King in 2016 and, last October, a new joint committee with Bourita, the same week Lavrov signalled acceptance of Morocco’s autonomy plan, and Russia then abstained rather than block Resolution 2797. Washington drafted 2797, recognised Moroccan Sahara in 2020 as the price of Israel’s normalisation, and reaffirmed it on Throne Day, the day the crossing began. Delhi opened India’s first overseas defence plant outside Casablanca last September. Starlink signed Royal Air Maroc on 4 August. Rabat ran this in the knowledge that every state with leverage over it had already taken its side of the Sahara question, and two of them would join in.

The report’s phone sample is the evidence the critics wave. Ninety point eight percent Moroccan prefixes among the lines that dynamised the call; of the rest, Algeria under three percent of the whole, and no Russian, Israeli or American lines anywhere in the enumeration. That is proof of who executed. Wilber’s Tehran newspapers were Iranian too. The report’s own after-phase section lists the Moroccan counter-narratives that followed the crossing, the “mafias” story in ABC and the “Algerian prefixes” story in La Razón among them, as products of the operation. Russia and Israel are not in that list because Morocco did not invent them. Europe’s diplomatic service did.

The report’s claim that the campaign followed a pre-established viral design model is footnoted to a marketing-school blog post on the K-factor and attributed loosely to Harvard Business School. Typical. Harvard often fronts ideas others made viable first. The inference that the message pattern was engineered actually rests on the message-volume and the sequences, which the report does document. Thankfully it doesn’t mention my 2012 BSidesLV presentation where I predicted this exact methodology (using Israel as an example of what to watch).

The Phone

On 17 and 18 May 2021 Morocco opened the border and roughly 8,000 people entered Ceuta at El Tarajal. On 18 May Sánchez flew to Ceuta with Marlaska and overflew the frontier by helicopter against security advice. On 19 May, according to The Objective’s reconstruction, Moncloa’s systems detected the extraction of around 2.6 gigabytes from the Prime Minister’s phone by Pegasus. The government sat on it for a year. The judicial inquiry later counted fourteen attacks: five on Sánchez, four on Robles, two on Marlaska, who lost over six gigabytes, and one attempt on Planas. The Defence Ministry reset Robles’s phone before it could be examined. Judge Calama shelved the case.

On 14 March 2022 Sánchez wrote to Mohammed VI accepting the Moroccan autonomy plan for Western Sahara, reversing half a century of Spanish policy without informing his coalition partner or Parliament. Asked in Parliament this May whether Pegasus has ever been raised with Rabat, the government answered that the matter does not form part of bilateral relations.

This summer an Algerian-flagged hacker persona, Jabaroot, published the identities of some 70,000 Moroccan intelligence personnel and asked its Telegram forum who was interested in the original Pegasus data relating to Pedro Sánchez. Attribution of the 2021 intrusions to Morocco is not a Spanish judicial finding. It is the working assumption of everyone outside Moncloa, anchored on the French investigation of the Macron intrusions. What was in the 2.6 gigabytes is unknowable. That is the point of it.

The executor of the 2021 Ceuta operation extracted the Prime Minister’s phone during the 2021 Ceuta operation. The Prime Minister then reversed policy in the executor’s favour. In 2026 the executor ran the same operation at ten times the scale and put the Prime Minister’s face on the recruiting poster. This is the half of Sánchez’s statement that fails: Morocco did conceive and execute the crossing, his own police have it on video, and the reason he cannot say so is sitting in Rabat in a 2.6-gigabyte file. That is a fact about leverage. It does not make the other half wrong. A leader who names the states he can name, and names them correctly, is doing more than a leader who names none.

I was Right About Loch Ness in 2012

The CIA denied Ajax for sixty years, because of course. The 1989 FRUS volume omitted it. The 2013 admission came by FOIA and the 2017 volume came after the nuclear deal made it safe. The whole period, the operation’s authorship was an open question where many knew the answer, and the party that had the strongest interest controlled the archive to delay the reveal.

Ceuta keeps the structure. The report says it cannot individualise the top level. The Interior Minister writes to the police director asking since when he knew. The police director replies that no document attributes planning or execution to a government.

The opposition reads the cover of a book (the uniforms) and declares the story ends on Morocco alone, without reading a page inside. They maintain a state in which 80,000 people crossed a European border under the guidance of a neighbouring state’s security forces, 82 bodies came out of the water, two foreign states worked the aftermath under their own flags, and the only person who named those two states is the one they tell to stop talking.

Germany has weathered the same pattern this year and I’ve repeatedly shown Dobrindt making the mistake: treat the flow as the threat, and the state that weaponised it as a rumour. That is what a hybrid operation is built to produce, as I warned in 2012 about the emerging threat of social media on mobile phones. The correct call is both halves. Rabat moved the people. Moscow moved the story, and Jerusalem signed its name to it. The second half is what turns any old border incident into an internationally reported government crisis, and Sánchez is the one leader in Europe who actually said the second half.

Somebody read the old handbook, and so did Sánchez.

Hacker History of OPSEC

The moment armies transmitted, their operations were being exposed as unclassified observations. In theory this was a risk since the first ever conflict, yet in practice we see a turning point with modern radio because of the sheer scale of the problem. And that’s arguably where a hacker history of OPSEC starts.

August 1914 seems the foundational moment in doctrines of modern secrecy. Russia’s Second Army under General Samsonov marched into East Prussia sending its orders by radio, often in the clear, and German staff officers, most famously Max Hoffmann at the Eighth Army operations desk, simply listened. They knew where the Russians were going (slowly forward) before the Russians arrived, and the result was a left/right flank attack for encirclement at Tannenberg, one of the most lopsided defeats of the war. After Germans massacred Russians trapped by them for days, pushing the dead into 10s of thousands, General Samsonov shot himself to death. Inverse to those listening, two Russian commanders despised each other and refused to communicate, so Rennenkampf could have broken the encirclement but instead said and did nothing while the Russian army was completely destroyed.

Two months later the British Admiralty stood up its famous Room 40 to do the listening professionally, and within two years both sides became expert in analysis of what is being transmitted beyond just the words in its messages. Which station talks to which, how often, from where, and in what rhythm all reveal the future of battle. That essential WWI craft became known as traffic analysis, and the defense doctrine against it demanded what eventually earned a simple name: operational security, or OPSEC.

By the end of WWI all sides were using radio silence discipline, call-sign rotation, dummy traffic, as well as entire state censorship regimes, such as DORA in Britain from 1914, or the Espionage Act and Creel Committee apparatus of 1917.

Of course WWII brought it all back into practice again, analysis of one’s own operations from the view of the enemy’s eyes.

Named point-to-point Lorenz links between German command centres, each a separate teleprinter circuit Bletchley tracked and tried to read. Trout, Whiting, Perch, Squid, Stickleback, Shad, where every spoke is one link.

Deception programs were built around the observation of the enemy’s behavior, such as the unbelievably successful Allied Operation Bertram, which fed the German Panzerarmee’s intelligence staff a false picture of the timing and axis of the October 1942 attack at El Alamein; Rommel himself had left for Berlin to party with Hitler (receive a field marshal’s baton, star at a Sportpalast rally, and assure the press that Germany held the door of Egypt in its hand, before he settled into the Heereskurlazarett relaxation at the Semmering resort). Hitler’s desperate midnight phone call pulled his “fox” out of an “alpine cure” (spa treatment) as his men were being out-observed into a total rout.

Source: “Images of War: The Armour of Rommel’s Afrika Korps” by Ian Baxter. Rommel’s men give him a look of disgust; his impatient and stretched orders fall apart as Montgomery easily outsmarts him.

The London Controlling Section came by 1942 and then the American equivalent Joint Chiefs’ Joint Security Control in 1944. BODYGUARD, the 1944 deception plan covering the Normandy invasion, treated every convoy schedule, radio net, and press release as a signature to be shaped. The same war supplied the canonical failure, B-Dienst reading the convoy traffic of the Atlantic, and the state-level Office of Censorship from December 1941 and the careless-talk campaigns from 1942, evolving into posters on high-risk American defense office walls well into the 1980s. I remember seeing some still hanging in 1994 even, the genesis of my own award-winning security awareness campaigns.

The Vietnam War offers an interesting footnote. American bombers kept arriving over targets where the enemy was already waiting, both the B-52 strikes called ARC LIGHT and the long air campaign against the North called ROLLING THUNDER. In 1966 a joint investigation team codenamed Purple Dragon went looking for the spies and found none. The giveaways were all in plain view: refueling tankers launched hours ahead and circled in predictable orbits, strikes ran on stereotyped schedules, and radio warnings meant to keep friendly aircraft clear of the target also told anyone listening where the target was. The enemy just watched and counted, which is the Tannenberg lesson of WWI and the wartime method of the Joint Security Control all over again.

NSA’s own declassified history is unsparing about the causes of failure, calling it ignorance of history, and the team coined the term OPSEC precisely so the lesson would finally have a name that would land and stick. Unsurprisingly, briefings on the subject like to reach back to Washington’s letter of 26 July 1777 to Elias Dayton, on how even the smallest trifles of information are worth collecting, as evidence that nobody should be claiming novelty on a practice as old as conflict itself.

Then, fast forward to 1987, with personal computers now settled onto corporate desks, when the monthly journal of the American Society for Industrial Security, Security Management, ran an article on control selection that introduced its readers to the Department of Defense methodology of OPSEC. On page 81 of volume 31 the “operations security” pioneered by the department was made applicable to corporate control planning, and defined:

OPSEC denies information to adversaries by identifying, controlling, and protecting indicators

This was simply Defense doctrine of that period; JCS Pub 18 had set joint operations security policy on 25 October 1974. DoD Directive 5205.2 established the department-wide program in 1983 so the transition to civilian information security four years later was reasonable. NSDD 298 carried the same identifying, controlling, and protecting language into national policy a few months after the article ran, on 22 January 1988, creating the Interagency OPSEC Support Staff. The trade press was circulating the formula and then the White House standardized it. This was somewhat common knowledge within hacker circles, not least of all because of all the news about the 414s, such as the cover of Newsweek in 1983; two years after the Security Management article, “Hagbard” of the KGB hacking case disappeared, leaving only a ring of fire in a remote German forest.

The youngest member of the 414s was said to be the only one legally able to appear on the cover of Newsweek, September 5, 1983

The civilian readership was arguably prepared also by military service. The Air Force pamphlet You and OPSEC went through the U.S. Government Printing Office in 1975, fourteen pages of second-person instruction distributed to airmen.

U.S. Army Intelligence and Security Command published A Road Map to OPSEC: The 902d Military Intelligence Group in 1984, seventeen pages describing the counterintelligence unit’s OPSEC survey services. Federal depository distribution put this material out in the open for everyone to see; the digitized copy of the 1984 guide is on the shelves at the University of Illinois at Urbana-Champaign, famous for its role in early Web development. The genre descends from the wartime information campaigns that had been teaching the same silence discipline to the whole population a generation earlier. Security Management’s audience in 1987 included the veterans and cleared-facility officers that this material had trained over the preceding decade. Nobody really forgets the best OPSEC training, which is the whole point.

A second commercial thread then starts to flourish in the early 1990s, oriented to that era’s fears around economic dominance and threats of espionage. Protecting Corporate America’s Secrets in the Global Economy, published by the American Institute for Business Research in 1992 (253 pages, Cornell’s depository copy), applies the acronym within a threat model of foreign intelligence services collecting U.S. business information. The surrounding institutional activity becomes an OPSEC Professionals Society formed in 1990. IOSS ran industry outreach under NSDD 298 throughout this time, and Congress passed the Economic Espionage Act in 1996. In the same way corporations were starting to adopt encryption from the military, they also adopted the OPSEC that the military ran in the original doctrine, including foreign services as a shared adversary.

Methodology as Merchandise

Promotion is an art, not a science. OPSEC is a science, not an art.

Some may remember the moment Check Point launched its partner program in 1997 under the clever OPSEC brand. It was promoted through the company’s own SEC filings as their Open Platform for Secure Enterprise Connectivity, but the appropriation wasn’t subtle. Dan Blacharski’s Network Security in a Mixed Environment, a 1998 trade manual, shows how the acronym bled into eight long and dense pages of firewall coverage, starting page 400. Even Phrack started talking like this too, looking at issue 56, May 2000, which is a reference-list pointing back at the Check Point platform instead of the OPSEC it was referring to. Through the early 2000s the acronym registers in InformationWeek as well.

Source: Information Week

And Network Magazine took that marketing baton and ran with it across twenty pages in early 2003 alone, as Check Point’s partner certification exploded and made OPSEC into standard product-coverage vocabulary. Meanwhile, actual practitioners of security operations continued preserving the real meaning; JP 3-13 counted OPSEC as a capability of information operations in October 1998, and the Journal of Information Warfare was writing it into volumes 3 and 4 in 2004.

Hacker publications of course talked about the practice of hiding tracks, yet they tended to not adopt large institutional military vocabulary. Agent Steal’s guide to federal prosecution, bylined in the text “From Federal Prison, 1997” and published in Phrack 52 in January 1998, covers source protection, informants, wiretaps, and sentencing without sounding like it’s from the government. The term had been in continuous commercial print for a quarter century by the time a hacker conference speaker started promoting it as being novel at Ekoparty in September 2012, while also admitting he had overheard ex-government hackers (e.g. NSA) using the term. Phrack finally absorbed this all in issue 69 of 2016, as if it had been there all along.

And so the oldest discipline, re-branded after multiple military lessons of the first half of the 20th century, was known as OPSEC in computer hacking circles since the 1980s. This blog was writing about “Ctrl-Alt-Del when you leave your seat” in January 2006, not because it was ahead but because it was so late. Usage simply depended on how much someone wanted to reveal knowledge/alignment with state-based military culture, like a civilian who says FUBAR, klicks instead of kilometers, or asks for a SITREP instead of an update.

For many, it’s poor OPSEC to say OPSEC.

Trump Targets Yosemite Where Buffalo Soldiers Stood

On April 20, 1871, President Grant signed the Ku Klux Klan Act. Within six months he had suspended habeas corpus in nine South Carolina counties and sent federal troops into the upcountry to break the Klan. On March 1, 1872, he signed the Yellowstone Act, declaring the land…

reserved and withdrawn from settlement, occupancy, or sale under the laws of the United States, and dedicated and set apart as a public park or pleasuring-ground for the benefit and enjoyment of the people.

Ten months separate the two signatures because they are related. Both rested on the same premise that federal authority, once asserted, would be enforced against private interests that considered themselves above the law. Fifty years later those interests marched under the banner America First, when the second Klan claimed the slogan as its own, advertised itself as the only America First society, and asserted a copyright it never held.

Enforcement continued past the appropriation. Congress paid Yellowstone’s first superintendent nothing for five years, then in 1886 eliminated the civilian budget entirely, and the Army took the duty. Cavalry patrols reached Yosemite and Sequoia in 1891. In the seasons of 1899, 1903, and 1904 the duty fell to Buffalo Soldiers of the 24th Infantry and 9th Cavalry, who evicted the sheep herders and timber cutters. Captain Charles Young of the 9th, acting superintendent of Sequoia in 1903, completed the wagon road into the Giant Forest that a decade of civilian administration had failed to build.

Fast forward to the Trump “America First” administration, which has spent more than a year discussing a land exchange with Kingsbarn Realty Capital. The Nevada firm holds property on Yosemite’s western edge, where it plans upscale single-family homes. These developers want to pave a road from those homes to the park to reduce 28 miles to 11. A previous owner tried to develop the same parcel and win road access, and a court stopped him a decade ago. Kingsbarn’s lawyer says the exchange would avoid the legal obstacles that stopped that owner in court. A loophole, in plainer words. Interior says no final decision has been made.

No statute needs repeal. An exchange of equal value, papered by counsel, targets what the Congress that armed Grant against the Klan withdrew from sale.

A slogan first printed in the 1880s, marched as a Klan banner by the 1920s
The Economist/The New Yorker weren’t wrong