10 Spy Tricks: An Office Espionage Series

I spend a great deal of my time dealing withdeveloping and distributing new types of spy
highly sensitive, highly confidential information.ware. Then there is another niche market
Over the years I have noticed that many of thededicated to selling protection against these pieces
institutions I have worked with have gone toof malware. Folks, I talking millions of dollars each
great pains and considerable expense to makeyear, connected to these two enterprises. Would
certain their computer systems have state of theit surprise you to know that many of the same
art firewalls and "hacker-proof" encoding systems.people writing the protection software also write
Nonetheless, they continue to leak data like athe malware?Any who, how to these insidious
sieve!How can this be? Simple, they are guardingpieces of data stealing malware get into your
the air conditioner duct instead of the frontsystems? Simple, you or one of your associates,
door.So, what do I know about it? My knowledgeput them there.I know what you're thinking, "Not
of the field is pretty backdoor in nature.First of all,me! I would never do such a self destructive
I work a lot with people who love nothing morething. Neither would anyone I work with." And, at
than to stir up hate and discontent whereverleast intentionally, you're right. But, take look at
they go. They will intentionally uncover and publishthe most common avenues of entry and think
sensitive information. It is fun for them. In orderthrough your response again.Most Common
to find out why they do these things I do a lot ofSources of Spyware:
debriefing with them when an incident1. Screen savers
occurs.Second, I have two brothers who made2. Emoticons
carriers out of law enforcement. One of my3. Clip Art
brothers served many years as a state trooper4. Spam
and another as a sheriff's deputy. They were5. Email attachments
both extremely successful in the investigation6. Unprotected web browsing (cookies)
facet of the job and I am about to tell you why.7. Peer to Peer applications (mp3 files)
Then you can see if you are vulnerable to the8. Shareware
same kind of attack.The sources of data loss, in9. Freeware
no particular order, are as follows.1. Waste10. Involuntary Download (may present as a
Archeology.fictitious error you must click to correct)
Simply speaking, someone who really wants toSo, have you EVER added any of this to your
know your secrets will go through your trash.system, even to an email? I know me too.
And guess what? It is completely legal. Buy aOh well, as MaElla (my grandmother) used to
$20.00 shredder, and use it.2. Taps.say, "Once bitten, twice shy."What have we
Seriously, if you have a wireless system it islearned?Basically, don't put anything unverified on
pretty simple to eaves drop via laptop from theyour system, even if it is really, really cool.Bye
coffee shop next door.3. Pop-ins.the way, does anyone know where MaElla got
Be extremely wary of maintenance crews and"Once bitten, twice shy"?Part VFirst and
repair staff you haven't called in. Check ID's. Also,foremost, never use a cordless phone for
be aware of someone who comes in asking a lotanything other than the convenience of answering
of questions. You may be surprised what thea call. Switch to a corded line for any specific
reception staff will tell someone who smiles andcommunications.Monitoring cordless and cellular
asks nicely.4. Hacking in.phone calls has become a million dollar hobby in
Do you know the easiest way to hack in to aAmerica. Some even sell their monitored
secure system? Steal the password taped to theconversations on line. Think ex-girlfriend
computer screen at Ed's work station. Trust me,sites.Mobile phones are an even greater liability.
I see it every day. You know what else? MostNot only are means available to monitor the
people use the same password for every systemconversations, but it is not particularly difficult to
they need to access.5. Cordless phones.track the location of the parties based on their
Remember most cordless phones and cells aresignal. Now, that is scary.This tracking will become
basically fancy radios. If it puts out a signal, theeven easier when newer 3G phones come online
signal can be picked up with a scanner.6. Tickingbecause their base stations are even closer
bombs.together.What can you do?
Answering machines, voice mail, fax machines1. Use a regular line for increased security.
anything that requires an access code can be2. Dedicate a secure line in your office for
beaten (remember the password taped to thesensitive communication. They are not cheap.
computer?).7. Starbucks.Or-Com offers one that has fair reviews for
Never discuss sensitive information in a publicabout $300.00.
restaurant! If I wanted to know about a3. Use first names on non-secure lines.
corporations business, I go to the snack bar at4. Speak in general terms on non-secure lines.If
lunch and read the paper over coffee. You won'tyou think these precautions a completely paranoid,
believe the things you hear (if you're in education,you may be right. On the other hand, browse
teacher lounges are hair raising!).8. Brain cramps.Spy Emporium for an overview of just a few of
Unlocked cabinets, offices, desks, paper workthe surveillance devices available.Part VI.If you
left out, answering stupid questions over thework with confidential data, and you use any of
phone. Hello?9. Traitors.the following pieces of technology, it is just a
Face it, some folks will sell you out for the rightmatter of time until your confidentiality is
price. The right price might be as simple ascompromised.1. Disposable roll fax machines.
someone asking, "So, what confidential things areUsed rolls contain copies of every item the
you working on these days?" You really wouldn'tmachine has received.2. Unattended fax machines.
believe what people have told me in answer toFax machines left on are excellent sources for
that question. Keep sensitive information on astealing confidential data. When I expect a fax, I
need to know basis.10. Describing a spy.alert the office staff to put it in a folder in my
The typical spy is a short, fat, tall, thin man, within-box.3. Dictation machines.
curly, bald hair. She often wears provocativelyIf you use dictation machines and leave tapes on
conservative clothing and is liberally conservative.the secretaries' desk to be transcribed don't be
In other words, ANYBODY is the typical spy.Nowshocked when a tape goes missing (Tell the truth,
I will expound upon each section individually.Partthis has already happened hasn't it?).5. Answering
1One of the first areas I mentioned in breaches inmachines.
security was "rifled" trash. I believe this to beMost are accessible with a 3 or 4 digit code. Most
foremost method of stealing confidentialpeople don't change the factory set "3, 4, and 5."
information. In reality it isn't even stealing. InThese are easy to hack.6. Cordless microphones.
California Versus Greenwood the Supreme CourtCrystal clear signals for about 1,300 feet or a
held the Constitution does not prohibit warrantquarter mile.Part VII.One of the most popular and
less search and seizure of garbage left forreliable methods for gathering information from an
collection outside the curtilage (the enclosed areaorganization is to "scout the perimeter." Although,
immediately surrounding a home or dwelling) of athis is not as sexy as the "mission impossible"
home. This could include places of business.Heremethods, it is very popular and very
are some pro-active steps you can take.1. Don'teffective.Here are your most frequent weak
transfer confidential documents to recyclingspots.1. The company lunch room. Many people
vendors.2. If you have a copier, install a shredderactually carry confidential files with them to
next to it.3. Purchase a cross-cut shredder forreview over lunch.
extremely sensitive documents.4. Destroy all2. The neighborhood coffee klatch. This is true
waste paper.5. Get shredders for each individual.for the same reason as above.
People won't wait in line to use a bulk shredder.6.3. The guy who is always at the newsstand
DON'T KEEP CARDBOARD BOXES OFwhen you pick up your paper. You know the one
UNINVENTORIED OLD DOCUMENTS LYINGyou discuss current office events with because
AROUND.Part II.Remember, James Bond is nothe doesn't know the people anyway.
interested in your secrets.That being said,4. The chatty new friend your spouse just made.
competitors, disgruntled employees, ex-spousesThink about this when discussing business with
and other wreakers of havoc are interested inyour spouse.
your secrets.There are many methods of5. Any off-site meeting places. Luncheon rooms,
"bugging" out there.The five main categories are,county offices, etc.Part VIIINext to going through
in alphabetical order: Acoustic, Optical, RF, Tie-In,the trash, the most vulnerable area for
and Ultrasonic.1. Acoustic - low tech glass to theexploitation is the human brain.
wall, ventilation, electrical out-let, out side theThe major offenders:
window, stand by the door, close proximity1. Unsecured offices, cabinets, drawers and
listening.2. Optical - high end and expensive.3. RF -doors.
radio frequency and receiver devices.4. Tie-in -2. Files left on the desk over night.
hooking directly in to a phone line. The box is3. Group passwords.
usually easily accessible on an exterior wall.5.4. Company phone directories.
Ultrasonic - think transmitter, receiver but with5. Desktop rolodexes.Part IXAnother source of
audio pressure rather than radio waves.The mostcompromised confidential information is the office
prevalent and dangerous of this is alphabeticallytraitor. Most people have a price. The price may
and most destructively listed first. Always behave been paid the last time they were insulted,
aware of your immediate surrounding whendegraded or unappreciated at the office. One the
discussing confidential information.Part IIIAlwaysother hand, there may be an actual monetary
check the identification of persons who pop in toprice for which a trusted associate can be
do technical work around your office. This isturned.Here are some of the characteristics you
especially true if you PERSONALLY have notmay need to be on the look out for.1. Those
called them for service. These folks are known aspassed over for raises, passed over for
"spooks".You see, "Spooking" is a hide in plain sitepromotion.
method of gaining access to confidential2. Those experiencing significant financial difficulty.
informationIt seems carrying a clipboard will gain a3. Those who gamble.
spook access to most places, even those with4. Those that employ recreational
confidential data to protect.But, there are otherpharmaceuticals (including alcohol).
common tools the spook may carry to increase5. Those involved in labor and management
their appearance of authenticity: 2-way Radio,disputes.
Maglight, Construction worker hard hat, and my6. Those that seem to always be on the lookout
personal favorite the attention tone cell phone.for the next big deal.Part X.Basically, if you take a
Now, this particular ruse means the spook has alook at the qualifications for a field agent for the
partner but is anything more impressive than thatCIA you can build a fair profile of what an office
tone from the "base office" checking thespy may "look like."1. A Bachelors Degree, rarely
technicians' status?However, the most powerful,more.
by far, access granting technique (I mean this will2. Solid academic record, not outstanding.
get you in anywhere) is a set of Dickies. Yes,3. Interest in inter-business and international
Dickies. The same things you wore for summeraffairs.
jobs in high school and college. They are a virtual4. Solid interpersonal skills.
cloak of invisibility in our culture.Most common5. Solid communication skills.
guises:1. Telephone/communications technicians -6. Frequent traveler.
(typically wearing blue/grey Dickies)2. Computer7. Interest in foreign languages.
service technicians - (polo shirt and tan Dickies8. Prior residence outside the area.
pants)3. Copy machine technicians - (polo shirt and9. Possible prior military experience.
blue Dickies pants)4. Custodians - (typically anyone10. Experience in business and/or economics (but
with a set of blue/grey Dickies is granted cartwith deficit skills in their own finance
blanche access)5. Messenger services - (typicallymanagement).
wearing brown Dickies)6. A/C heating technicians -11. The person is usually between the ages of
(typically wearing blue-green Dickies)The beauty21-35.
of this type of "spooking" is nobody ever12. Previous work in law enforcement or
challenges these folks. And if some particularlycorrections.
diligent person does question them, the spook13. May be considered a loner, not a joiner.
goes into his, "fine with me, but it will be at least14. No police record.
four weeks until I can get back here. We're really15. Hobbies include martial arts, scuba, hunting,
backed up." That is usually enough to intimidateproficiency with firearms, chess, math, avid
even the most on top of things staff member.Ireader, may write prolifically or play a musical
don't usually recommend testing out theseinstrument, etc.
surveillance techniques, the power of the Tricky16. The person may be interested in training
Dickie is not to be believed unless you actually seemanuals and field guides.In other words, just
it in action. So, get your lazy brother-in-law a setabout anybody who would make a good
of Dickies and send him through your office. Youemployee. The key is to look for unusual
won't believe the results. Afterwards, get the lazygroupings of these skills. Most people will meet 3
bum to do your yard work so you get youror 4 of the criteria. Those who meet 6 or more
moneys worth from the Dickie investment.Partshould be considered possible candidates.This
IVThere are many ways of stealing computersection completes a ten part series concerning
files. As a matter of fact there is a whole nicheconfidentiality and security.
market dedicated to nothing more than