POPSEC: Operational Security Lessons Learned from Archer

Please consider subscribing to my Patreon.

Sterling Archer is a well-known, widely loved secret agent whose methods are… unconventional. Despite having a background in covert and clandestine operations, he manages to fuck up on a pretty consistent basis, often with hilarious and disastrous results. Fortunately, the multitude of mistakes made by him and his cohort provide a wealth of learning opportunities for those of us who watch.

Lesson 1: Op First, Drinks After

Archer is notorious for his love of Glengoolie Blue Label… or literally anything else with an alcohol content greater than or equal to that found in NyQuil. While Sterling’s reputation for being a boozehound certainly sets the stage for some entertaining and hilariously catastrophic scenarios, the truth is that if you’re actually trying to keep secrets, and accomplish anything either covert or clandestine, you may actually want to skip the Scotch until it’s time to celebrate your success. Drinking can slow your reflexes, dull your situational awareness, and strip away your inhibitions in ways which may endanger both you, your colleagues, and your operation. Additionally, even after your operation is complete, it is wise to remember that alcohol lowers inhibitions, and it is best to drink in moderation so as to keep your wits about you when in mixed company.

Lesson 2: Cocaine is Probably a No?

I mean, do whatever you want, but if we’re being honest, cocaine basically never leads to good life choices, and that goes double when you actually have good reason to keep your mouth shut about literally anything. Additionally, if you’re trying to fly under any sort of radar, it’s generally a good call to avoid carrying anything super illegal which isn’t directly related to completing your task at hand. In fact, you may actually want to expand this general rule to also include illicit substances which are not cocaine, including but not limited to: opiates, amphetamines, and probably even weed, even if possession is legal in your state. While there are doubtless exceptions to this rule, in general it is probably best to stick to No-Doze and Jolt for your upper fix.

Lesson 3: Maybe Don’t Sleep with Fellow Operatives

Relationships are messy. Workplace relationships are about eleventy times messier than your normal level of messy, especially if at least one person in the relationship has had multiple workplace relationships. Ongoing relationships impact the judgement of those engaging in them, and catastrophic relationship-ending events can damage, if not outright destroy, the trust necessary for running a successful operation. It’s true that we spend a lot of time in close quarters with those with whom we collaborate, but there are enough fish in the sea that it’s probably worthwhile to turn our gaze outside of the goldfish bowl of our affinity groups or other organizational collectives.

Lesson 4: Brag Less

Yeah, okay, Burt Reynolds IS pretty cool, but that doesn’t mean you should brag to him about being recognizable because you’re “the world’s most dangerous spy.” In fact, you probably shouldn’t actually tell people you’re a secret agent. Or admit to it when asked. Or cop to it when accused. There are varying schools of thought on how best to go about denying your involvement in anything secretive, but general consensus is don’t discuss things outside of the very limited context needed in order to complete operations, and don’t give any indication that you’re up to anything remarkable or interesting. It’s important to note that lying is not most people’s strong suit, so employing tactics like misdirection instead of relying on outright falsehoods may be a more viable option, especially in the long term. When in doubt, speak at great length on a dull subject, then politely excuse yourself once your conversation partner’s eyes have safely glazed over from boredom.

Lesson 5: Leave Your Personal Shit at Home

While your personal issues may not be “parachuting into Russia under pretext of committing a political assassination to find out whether a high-ranking KGB operative is your father”-level bad, Archer’s profoundly poor decisions in this realm serve as an excellent reminder of how our personal issues can negatively impact both our safety and our odds of completing our objectives if we are unable to set them aside to focus on our work. We all have problems in our personal lives, but if you are unable to set them aside and focus on your projects, the responsible choice is to recuse yourself from your work until you are able to focus on it without allowing your distraction to put yourself, your peers, and your operation at risk.

Lesson 6: Take Briefings Seriously

While it may be tempting to zone out during briefings, or only skim over relevant documents and/or communiques, it’s important to remember that minutiae can be the deciding factors in whether or not a mission is successful. Pirate King Archer has a wonderful resource in Noah, but Sterling’s unwillingness to listen or learn proves his undoing. In fact, this is a recurrent theme throughout Archer’s misadventures: time after time, Sterling’s missions and his personal safety are compromised by his cavalier attitude towards obtaining and retaining relevant information. Never underestimate the value of preemptive research when undertaking something risky. It’s generally better to have unnecessary information than it is to suffer from a lack thereof: the more information you have, the better prepared you are if things don’t go according to plan.

Lesson 7: Don’t Be Distracted by a Pretty Face

While it may be tempting to allow yourself to be distracted by an attractive person, it is important to remember that at best, a pretty face is just that: a distraction. At worst, an attractive person may be an actual adversary using your sexuality to neutralize you, and lure you into divulging sensitive information. Mercedes Moreno falls in the middle when she uses her sex appeal to divert and neutralize Archer so her mother can continue sneaking people across the border into the US. There are cases where it is both possible and pragmatic to use these tactics to your advantage. Playing along may allow you extract information from an adversary or to seed disinformation, but this tactic should never be undertaken lightly. Instead, this should be done deliberately and with every possible precaution in place, including an extraction plan for when the job is done and the faux relationship ceases to be useful to your aims.

Lesson 8: Don’t Reuse Aliases

Archer habitually reuses the same pseudonym, despite using different cover stories each time. We never actually see this bite Sterling in the ass (except for when he’s called on it in meetings, and subsequently uses the name “Rando” instead of his usual “Randy,”) it’s important to keep in mind that reusing a pseudonym can compromise your identity and your operation. If you’re going to use pseudonyms, it is best practice to use names which are both plausible and disposable, rather than reusing names, or using ostentatious handles. It’s unlikely that anyone will remember Emily Jones based solely on her name, but highly likely that people will take note of (and remember) Mariah Carey or Catherine Catastrophe. Retiring pseudonyms after use is still crucial. There is still always a chance that people will remember even an unremarkable name, and it is wise to compartmentalize both actions pertaining to an operation, and operations themselves, whenever possible.

Lesson 9: Never Trust Someone Offering You “Unhackable” Security

The first thing you should know is that, given an adversary with sufficient skill and resources, there is no such thing as “unhackable.” Since “unhackable” is an impossible objective to achieve, it stands to reason that at best, anyone claiming an “unhackable” service or product is a charlatan. At worst, they may actually be malicious, as shown in Cyril’s encounter with George Spelvin, a security contractor out to gain access to data on ISIS field operatives, and sell it to the highest bidder. A couple related things to keep in mind are: don’t take security advice from people who don’t understand the threats you face, and don’t trust anyone offering easy security solutions. Proper security practices are going to offer defense in depth in order to prevent creating a single point of failure, and will necessarily be tailored to the assets you are trying to protect, and the adversaries you’re protecting against.

It’s true that Archer is full of countless operational security fails and just plain bad tradecraft, but Sterling does manage to correctly implement what may be the most important security measure of all: Archer’s affinity group is reliable. No matter how many times they fuck up, or fight among themselves, the coalition of secret agents formerly known as ISIS understands that solidarity means nobody gets left behind.

Published by

Elle Armageddon

Elle Armageddon is a Bay Area-born anarchist, antifascist, blogger, glitter enthusiast, and smartass security professional. In addition to writing, furiously tweeting, and mucking around with a chemistry set that looks suspiciously like a bar, you can also find them providing medical and legal support for protesters, babysitting their niblings, and politely asking people to stop doing unconscionable things to the computers. If you'd like to support their writing, you may do so at https://patreon.com/armageddon They can also be found on Twitter: @ElleArmageddon

Leave a Reply

Your email address will not be published. Required fields are marked *