Category Archives: History

Hacker History of OPSEC

The moment armies transmitted, their operations were being exposed as unclassified observations. In theory this was a risk since the first ever conflict, yet in practice we see a turning point with modern radio because of the sheer scale of the problem. And that’s arguably where a hacker history of OPSEC starts.

August 1914 seems the foundational moment in doctrines of modern secrecy. Russia’s Second Army under General Samsonov marched into East Prussia sending its orders by radio, often in the clear, and the German staff officers under Max Hoffmann simply listened. They knew where the Russians were going before the Russians arrived, and the result was the encirclement at Tannenberg, one of the most lopsided defeats of the war.

Two months later the British Admiralty stood up its famous Room 40 to do the listening professionally, and within two years both sides had learned that an enemy transmits far more than the words in its messages. Which station talks to which, how often, from where, and in what rhythm all reveal the future of battle. That craft became known as traffic analysis, and defending against it demanded what would much later get a name: operational security, or OPSEC.

By the end of WWI all sides were using radio silence discipline, call-sign rotation, dummy traffic, as well as entire state censorship regimes, such as DORA in Britain from 1914, or the Espionage Act and Creel Committee apparatus of 1917.

Of course WWII brought it all back into practice again, analysis of one’s own operations from the view of the enemy’s eyes.

Named point-to-point Lorenz links between German command centres, each a separate teleprinter circuit Bletchley tracked and tried to read. Trout, Whiting, Perch, Squid, Stickleback, Shad, where every spoke is one link.

Deception programs were built around the observation of the enemy’s behavior, such as the unbelievably successful Allied Operation Bertram, which fed the German Panzerarmee’s intelligence staff a false picture of the timing and axis of the October 1942 attack at El Alamein; Rommel himself had left for Berlin to party with Hitler (receive a field marshal’s baton, star at a Sportpalast rally, and assure the press that Germany held the door of Egypt in its hand, before he settled into the Heereskurlazarett relaxation at the Semmering resort). Hitler’s desperate midnight phone call pulled his “fox” out of an “alpine cure” (spa treatment) as his men were being out-observed into a total rout.

Source: “Images of War: The Armour of Rommel’s Afrika Korps” by Ian Baxter. Rommel’s men give him a look of disgust; his impatient and stretched orders fall apart as Montgomery easily outsmarts him.

The London Controlling Section came by 1942 and then the American equivalent Joint Chiefs’ Joint Security Control in 1944. BODYGUARD, the 1944 deception plan covering the Normandy invasion, treated every convoy schedule, radio net, and press release as a signature to be shaped. The same war supplied the canonical failure, B-Dienst reading the convoy traffic of the Atlantic, and the state-level Office of Censorship from December 1941 and the careless-talk campaigns from 1942, evolving into posters on high-risk American defense office walls well into the 1980s. I remember seeing some still hanging in 1994 even, the genesis of my own award-winning security awareness campaigns.

The Vietnam War offers an interesting footnote. American bombers kept arriving over targets where the enemy was already waiting, both the B-52 strikes called ARC LIGHT and the long air campaign against the North called ROLLING THUNDER. In 1966 a joint investigation team codenamed Purple Dragon went looking for the spies and found none. The giveaways were all in plain view: refueling tankers launched hours ahead and circled in predictable orbits, strikes ran on stereotyped schedules, and radio warnings meant to keep friendly aircraft clear of the target also told anyone listening where the target was. The enemy just watched and counted, which is the Tannenberg lesson of WWI and the wartime method of the Joint Security Control all over again.

NSA’s own declassified history is unsparing about the causes of failure, calling it ignorance of history, and the team coined the term OPSEC precisely so the lesson would finally have a name that would land and stick. Unsurprisingly, briefings on the subject like to reach back to Washington’s letter of 26 July 1777 to Elias Dayton, on how even the smallest trifles of information are worth collecting, as evidence that nobody should be claiming novelty on a practice as old as conflict itself.

Then, fast forward to 1987, with personal computers now settled onto corporate desks, when the monthly journal of the American Society for Industrial Security, Security Management, ran an article on control selection that introduced its readers to the Department of Defense methodology of OPSEC. On page 81 of volume 31 the “operations security” pioneered by the department was made applicable to corporate control planning, and defined:

OPSEC denies information to adversaries by identifying, controlling, and protecting indicators

This was simply Defense doctrine of that period; JCS Pub 18 had set joint operations security policy on 25 October 1974. DoD Directive 5205.2 established the department-wide program in 1983 so the transition to civilian information security four years later was reasonable. NSDD 298 carried the same identifying, controlling, and protecting language into national policy a few months after the article ran, on 22 January 1988, creating the Interagency OPSEC Support Staff. The trade press was circulating the formula and then the White House standardized it. This was somewhat common knowledge within hacker circles, not least of all because of all the news about the 414s, such as the cover of Newsweek in 1983; two years after the Security Management article, “Hagbard” of the KGB hacking case disappeared, leaving only a ring of fire in a remote German forest.

The youngest member of the 414s was said to be the only one legally able to appear on the cover of Newsweek, September 5, 1983

The civilian readership was arguably prepared also by military service. The Air Force pamphlet You and OPSEC went through the U.S. Government Printing Office in 1975, fourteen pages of second-person instruction distributed to airmen. U.S. Army Intelligence and Security Command published A Road Map to OPSEC: The 902d Military Intelligence Group in 1984, seventeen pages describing the counterintelligence unit’s OPSEC survey services. Federal depository distribution put this material out in the open for everyone to see; the digitized copy of the 1984 guide is on the shelves at the University of Illinois at Urbana-Champaign, famous for its role in early Web development. The genre descends from the wartime information campaigns that had been teaching the same silence discipline to the whole population a generation earlier. Security Management’s audience in 1987 included the veterans and cleared-facility officers that this material had trained over the preceding decade. Nobody really forgets the best OPSEC training, which is the whole point.

A second commercial thread then starts to flourish in the early 1990s, oriented to that era’s fears around economic dominance and threats of espionage. Protecting Corporate America’s Secrets in the Global Economy, published by the American Institute for Business Research in 1992 (253 pages, Cornell’s depository copy), applies the acronym within a threat model of foreign intelligence services collecting U.S. business information. The surrounding institutional activity becomes an OPSEC Professionals Society formed in 1990. IOSS ran industry outreach under NSDD 298 throughout this time, and Congress passed the Economic Espionage Act in 1996. In the same way corporations were starting to adopt encryption from the military, they also adopted the OPSEC that the military ran in the original doctrine, including foreign services as a shared adversary.

Methodology as Merchandise

Promotion is an art, not a science. OPSEC is a science, not an art.

Some may remember the moment Check Point launched its partner program in 1997 under the clever OPSEC brand. It was promoted through the company’s own SEC filings as their Open Platform for Secure Enterprise Connectivity, but the appropriation wasn’t subtle. Dan Blacharski’s Network Security in a Mixed Environment, a 1998 trade manual, shows how the acronym bled into eight long and dense pages of firewall coverage, starting page 400. Even Phrack started talking like this too, looking at issue 56, May 2000, which is a reference-list pointing back at the Check Point platform instead of the OPSEC it was referring to. Through the early 2000s the acronym registers in InformationWeek as well. And Network Magazine took that marketing baton and ran with it across twenty pages in early 2003 alone, as Check Point’s partner certification exploded and made OPSEC into standard product-coverage vocabulary. Meanwhile, actual practitioners of security operations continued preserving the real meaning; JP 3-13 counted OPSEC as a capability of information operations in October 1998, and the Journal of Information Warfare was writing it into volumes 3 and 4 in 2004.

Hacker publications of course talked about the practice of hiding tracks, yet they tended to not adopt large institutional military vocabulary. Agent Steal’s guide to federal prosecution, bylined in the text “From Federal Prison, 1997” and published in Phrack 52 in January 1998, covers source protection, informants, wiretaps, and sentencing without sounding like it’s from the government. The term had been in continuous commercial print for a quarter century by the time a hacker conference speaker started promoting it as being novel at Ekoparty in September 2012, while also admitting he had overheard ex-government hackers (e.g. NSA) using the term. Phrack finally absorbed this all in issue 69 of 2016, as if it had been there all along.

And so the oldest discipline, re-branded after multiple military lessons of the first half of the 20th century, was known as OPSEC in computer hacking circles since the 1980s. This blog was writing about “Ctrl-Alt-Del when you leave your seat” in January 2006, not because it was ahead but because it was so late. Usage simply depended on how much someone wanted to reveal knowledge/alignment with state-based military culture, like a civilian who says FUBAR, klicks instead of kilometers, or asks for a SITREP instead of an update. For many, it’s poor OPSEC to say OPSEC.

Trump Targets Yosemite Where Buffalo Soldiers Stood

On April 20, 1871, President Grant signed the Ku Klux Klan Act. Within six months he had suspended habeas corpus in nine South Carolina counties and sent federal troops into the upcountry to break the Klan. On March 1, 1872, he signed the Yellowstone Act, declaring the land…

reserved and withdrawn from settlement, occupancy, or sale under the laws of the United States, and dedicated and set apart as a public park or pleasuring-ground for the benefit and enjoyment of the people.

Ten months separate the two signatures because they are related. Both rested on the same premise that federal authority, once asserted, would be enforced against private interests that considered themselves above the law. Fifty years later those interests marched under the banner America First, when the second Klan claimed the slogan as its own, advertised itself as the only America First society, and asserted a copyright it never held.

Enforcement continued past the appropriation. Congress paid Yellowstone’s first superintendent nothing for five years, then in 1886 eliminated the civilian budget entirely, and the Army took the duty. Cavalry patrols reached Yosemite and Sequoia in 1891. In the seasons of 1899, 1903, and 1904 the duty fell to Buffalo Soldiers of the 24th Infantry and 9th Cavalry, who evicted the sheep herders and timber cutters. Captain Charles Young of the 9th, acting superintendent of Sequoia in 1903, completed the wagon road into the Giant Forest that a decade of civilian administration had failed to build.

Fast forward to the Trump “America First” administration, which has spent more than a year discussing a land exchange with Kingsbarn Realty Capital. The Nevada firm holds property on Yosemite’s western edge, where it plans upscale single-family homes. These developers want to pave a road from those homes to the park to reduce 28 miles to 11. A previous owner tried to develop the same parcel and win road access, and a court stopped him a decade ago. Kingsbarn’s lawyer says the exchange would avoid the legal obstacles that stopped that owner in court. A loophole, in plainer words. Interior says no final decision has been made.

No statute needs repeal. An exchange of equal value, papered by counsel, targets what the Congress that armed Grant against the Klan withdrew from sale.

A slogan first printed in the 1880s, marched as a Klan banner by the 1920s
The Economist/The New Yorker weren’t wrong

Washington Tells Kyiv Hold Fire So CIA’s Ratcliffe Could Land in Moscow

Did you hear that a Texas politician, and current CIA Director, John Ratcliffe flew to Moscow this week? The Wall Street Journal, then Politico and CBS, stated the purpose was to warn Russia against attacking NATO. CBS added that he also went to talk Iran, threatening sanctions unless Hormuz reopens. Peskov said contacts were only made between intelligence services, as Putin stayed out of it. Trump, always the one to state the inverse of reality, called the unusual trip “semi-routine.”

The same day AP quoted a U.S. defense official in Europe and a NATO official calling Patriot interceptor inventory in Europe “beyond critical,” drained by Hegseth without anything to show for it. The U.S. official said Europe has “very limited” capability against even a single ballistic missile. The Pentagon and NATO of course deny the Hegseth-folly on record. Meanwhile, CSIS puts U.S. inventory at 2,330 interceptors before February 28 and roughly 800 today, which suggests 65 percent may have been spent on Iran. In other words, at least sixteen U.S. military sites were hit, personnel pulled out of the ones too exposed to hold, and intelligence hardware from a Riyadh CIA station to the TPY-2 radar in Jordan was lost, while Hegseth threw away the “defense” capabilities of America. Beyond all the misfires he didn’t plan ahead and so his brevity code is Winchester.

Inside the service, the cash shortage is no secret. “They’re just not speaking publicly about it,” said Todd Harrison, a defense analyst at the conservative American Enterprise Institute. “And I suspect that is a deliberate decision of the civilian leaders in the Pentagon, starting at secretary, that this is for political reasons, that they don’t want to look like they’re damaging future military readiness over a war that is becoming increasingly a political liability.”

Let’s synthesize the headlines. A warning delivered from an empty magazine is America disclosing its response ceiling being dramatically lowered. Remember how Biden sent Burns to Moscow in November 2021 to warn against invading Ukraine? It’s a lesson in lowering the ceiling. He wagged a finger at Moscow about sanctions and Ukrainian aid, with U.S. troops ruled out in public. Putin gleefully and stupidly invaded four months later. Ratcliffe’s apparent worry is a ballistic missile strike on NATO. AP’s own sources place this years away at best while Russia bombs Ukraine nightly. So an effect of a CIA director personally arriving to say please don’t ballistic Germany, means everything below that line is allowed by Trump? That Leipzig drone bearing GRU hallmarks to blow up Ukrainian aircraft, eighteen drone disruptions at one airport since January, the Vulkan campaign knocking out critical infrastructure that Dobrindt calls daily hybrid warfare while insisting Germany is “not at war”, are the real question now.

An EU official explained the label to Politico: hybrid means whatever isn’t a direct attack, so no military response is required and insurance premiums don’t change. The frog being boiled to death is told as long as they aren’t dead yet the water is fine.

Moscow’s hybrid warfare expansion is undeniable. In February I described three failure modes converging on the Russian economy this summer. The Iran war postponed them. Urals went from $55 to $125 and Bruegel counts 1,184 billion rubles of windfall through June. The structure held underneath. July’s deficit was 724 billion rubles, seven months at 2.8 percent of GDP. Ukrainian refinery strikes converted the export windfall into fuel queues in 66 regions, wage delays, cash withdrawals, and anger that DW’s respondents say points at… the West. A regime in that condition craves a cheap external conflict. Germany foolishly banked on American Patriot launchers and now can’t get the missiles to load in them. That’s why it’s so, so important to read this detail: the C-17 staged through Riga, sat on the Vnukovo apron for eight and a half hours, and Washington had to ask Kyiv to suspend strikes until it left. The ally briefed in advance was the one told to stop shooting. Whether Berlin heard anything before the motorcade footage hit social media is a question for Henrichmann’s oversight committee to get on the record.

In usual Trump style, his men went begging for help on Hormuz from the country that is profiting most from Hormuz staying shut, having already granted Russia a 30-day oil waiver in March. The Kremlin put some people in the room to listen, and what they heard confirmed Germany is on the table.

I guess my real outstanding question is, while Germany was getting the boot, was Snowden given any offers? CBS noted that Ratcliffe personally negotiated the Karelina release in April 2025, and Moscow freed a former Marine earlier this month. Detainee trading is his usual beat.

The Antisemitism of Peter Oberacker

The category of antisemitism that Republican State Sen. Peter Oberacker practices has a name in German scholarship: Schuldabwehr-Antisemitismus or “guilt defense”.

Adorno’s 1959 lecture and Schönbach’s 1961 study made this clear, so it’s no surprise to anyone. The defining move is the defense of the perpetrators’ memory at the expense of the victims’. Oberacker posted a photo of Hitler’s soldier on Veterans Day 2015 with the caption “gave his life for his country,” and when the post resurfaced in August 2026 he added “war sucks,” “veterans of all conflicts,” and “didn’t have a choice.” Each sentence exists to unfairly place the Wehrmacht dead on the same ledger as the people the Wehrmacht killed.

Oberacker posted this photo with an antisemitic caption. When confronted with it, Oberacker said he looks at the picture differently now in light of mounting antisemitism, while he expanded into even more antisemitic statements.

Wehrmacht criminality was in evidence at Nuremberg in 1946 and tried separately in the High Command case in 1947 and 1948. The Hamburg Institute’s exhibition ran from 1995 and again from 2001. Germany’s own national Veteranentag, approved by the Bundestag in 2024 and first observed June 15, 2025, covers Bundeswehr veterans only. The Federal Republic declines to salute its predecessor army. An American congressional candidate applies a far weaker standard to the Wehrmacht than the German defense ministry does. And think about it in American terms. Memorial Day was created to honor the Union soldiers who died defending America against the Slaveholder Rebellion. To say an enemy of the state, the Wehrmacht or the Confederacy, should be memorialized the same as the people killed trying to stop them, is nonsense.

The Bundeswehr’s 2018 Traditionserlass states that for the armed forces of a democratic constitutional state the Wehrmacht as an institution cannot found tradition; individual Wehrmacht members may be included only after case-by-case examination that weighs personal guilt and requires an exemplary act, such as participation in the military resistance.

All that is to say we are looking at antisemitism as the scholarship defines it, met in the 2015 caption and three more times in just one interview about it. The IHRA examples include denying the mechanisms of the genocide. The Wehrmacht was a mechanism, and a defense of the Wehrmacht that never names what it did erases that mechanism and harms the victims. So the claim is exact: he committed an easily recognized form of antisemitism, in public, and then he defended it, which is itself another level of antisemitism.

How did he defend it? By falsely accusing others of antisemitism. Take a look at his methods of disinformation.

For Mamdani, an elected official, and Piker, a streamer who holds no office, they only have taken positions on Israel and Zionism; neither has a single documented statement expressing hostility to Jews as Jews, and the IHRA definition itself states that criticism of Israel like that leveled at any other country cannot be regarded as antisemitic. Oberacker undermines the definition, as he fails to understand that his accusations only make himself look more antisemitic. It is antisemitic to make every Jew answerable for an Israeli government, which is what accusations do when they treat any criticism of Israel as the offense. Jews can live outside of Israel, and Jews everywhere criticize Israel. Zionism itself is of Christian political lineage that predates Jewish political campaigns by half a century. Restorationism, from Shaftesbury’s 1840 memorandum to Palmerston through Balfour, wanted Jews settled in Palestine partly to remove them from Europe, an aim it shared with the antisemites of the period. A political idea with that ancestry can and should be criticized, especially given the foundational hostility to Jews (treating them as disposable tools for political purposes).

And then look at Oberacker’s accusations against politician Platner. It’s almost too stupid to believe. The evidence is a tattoo Platner says he got it as a Marine without knowing and has since covered it. A skull resembling the Totenkopf circulates in military settings because of a culture that reads Wehrmacht and SS insignia as period detail rather than as antisemitism. That culture is the exact same one Oberacker practices when he reads an actual Hoheitsadler on his grandfather’s chest as circumstance. The accusation of Oberacker should be pointed at himself, because the standard he applied to Platner convicts himself first in 2015.

The antisemitism of Oberacker has no content about Jews, and that’s his whole game. He erases the people who are meant to be protected, because he uses it to enable himself instead. It is a designation he assigns to his opponents and withholds from allies and ancestors. Look at how he hired as campaign manager Bobby Walker, a Young Republican officer who took part in a leadership group chat that praised Hitler, and removed him only after Politico published the messages in October 2025.

A man who very clearly and openly practices antisemitism while prosecuting others on evidence he would never accept against himself is not some flawed opponent of antisemitism. He is antisemitic, an active participant, where he doesn’t need to help living or dead Jews at all, because his use of the term is only for his own political benefit.