PeciaBK All articles
Culture & History

Between the Cracks: How Modern Information Couriers Are Hiding Messages in Plain Sight

PeciaBK
Between the Cracks: How Modern Information Couriers Are Hiding Messages in Plain Sight

Photo: Chris Whytehead, CC BY-SA 3.0, via Wikimedia Commons

Somewhere in a specific neighborhood in Chicago — the exact location shifts depending on who's talking — there is a USB drive embedded in a crack in a concrete retaining wall. It has been there for at least eight months. People who know about it know because they were told, in a specific way, through a specific channel, that it existed. The drive contains files. The files are encrypted. The key to decrypt them exists somewhere else, embedded in the metadata of a photograph posted to a public image-sharing forum.

This is not a spy novel. This is Tuesday.

Tradecraft Doesn't Retire, It Relocates

The dead drop — the practice of leaving information in a physical location for someone else to retrieve, with no direct contact between parties — is as old as espionage itself. The KGB used them. The CIA used them. Robert Hanssen, the FBI agent who spent two decades passing secrets to Soviet and Russian intelligence, was famously devoted to them. The whole appeal is structural: if the two parties never meet, never call, never email, there is no interaction to surveil, no relationship to map.

What's happening now in certain corners of American cities is a direct evolution of that logic, updated for an era of ubiquitous digital surveillance, metadata analysis, and the creeping sense that no online communication is truly private regardless of what the encryption app's marketing copy says.

The people building these systems aren't necessarily spies. They're journalists protecting sources, activists coordinating in high-risk environments, privacy researchers testing their own theories, and a loose category of individuals who have decided, for reasons they don't always explain, that they need a channel that leaves no digital fingerprint.

The USB Layer

Physical dead drops using USB drives became a minor cultural phenomenon around 2010, when an artist named Aram Bartholl began embedding drives in walls around New York City as a public art project he called "Dead Drops." The idea was playful, semi-public — a comment on sharing culture more than a functional covert channel.

The current iteration is something different. The drives being used in the more serious corners of this subculture are encrypted, often using open-source tools, and the locations are not public. They're communicated through a separate channel — sometimes a coded post on a public forum, sometimes a coordinate embedded in image metadata, sometimes a physical note left at a different location.

The drives themselves are often modified. Some are embedded in resin and designed to look like part of the surface they're attached to. Others are housed in weatherproof enclosures and attached to urban infrastructure — the kind of thing that looks like a forgotten sensor or a piece of maintenance hardware to anyone who isn't looking for it specifically.

"The physical object is almost a decoy," one person active in these communities wrote in a long post on a forum that requires an invite to access. "The real information isn't on the drive. The drive is a key. The actual content is somewhere else entirely."

Steganography and the Art of Hiding Nothing in Plain Sight

This is where steganography enters the picture. Unlike encryption, which scrambles data so it can't be read, steganography hides the fact that data exists at all. A photograph of a parking lot posted to a public forum might contain, embedded invisibly in its pixel data, a complete set of instructions. A message. A key. An entire document.

The technique has been around for decades in various forms, but the tools for implementing it have become significantly more accessible. Open-source steganography software is freely available and actively maintained. The barrier to entry is low enough that it's no longer exclusively the domain of nation-state intelligence operations.

The combination — physical drop plus steganographic key distributed through a public channel — creates a handoff system with an unusual property. Each component, examined in isolation, is either meaningless or legal. The USB drive contains encrypted data; without the key, it's noise. The photograph looks like a photograph. The connection between them exists only in the mind of someone who already knows it's there.

"It's not that it's unbreakable," a security researcher who has studied these networks explained. "It's that it's expensive to break. You have to know what you're looking for, where to look, and how to connect the pieces. That's a lot of resources to throw at something when you're not even sure it exists."

The Map of Who's Using This

Mapping the actual population of people using these methods is, by design, almost impossible. What's visible from the outside suggests several overlapping communities.

Journalists and their sources are one group. In the post-Snowden landscape, the standard advice for sensitive source communication has evolved considerably, and some journalists covering national security beats have started exploring physical-digital hybrid methods as a supplement to encrypted messaging apps.

Activist networks operating in environments where digital surveillance is aggressive represent another cluster. Certain labor organizing contexts, immigration rights work, and protest coordination have driven people toward methods that don't rely on any platform or service that could be compelled to produce records.

There's also a substantial contingent that seems to be doing this primarily as practice — privacy researchers, security professionals, and people who have built communities around the craft of covert communication as a kind of discipline. For them, the methodology is partly the point.

Why Encryption Alone Isn't Enough for Some People

This is the question that gets at something real. End-to-end encryption is widely available and, when implemented correctly, genuinely strong. Signal is free. Why go to the trouble?

The answer, for the people most committed to these hybrid methods, has less to do with the strength of any particular cryptographic algorithm and more to do with metadata. Encrypted messages still generate traffic patterns. They still require accounts, phone numbers, identifiers of some kind. They still pass through infrastructure that can be monitored for the fact of communication even when the content is protected.

A dead drop leaves no metadata. There is no server log recording that a message was sent. No timestamp. No account. No record that two people are in communication at all. For certain use cases, that's the property that matters most.

The Authorities Are Watching, Mostly Confused

Law enforcement awareness of these methods exists, but the response has been largely reactive. The challenge is fundamental: monitoring a system that operates in the gap between the physical and digital worlds requires resources and coordination across jurisdictions that don't naturally talk to each other.

There's no inbox to subpoena. No account to freeze. The evidence, if it exists, is scattered across a concrete wall in one city and a forum post in another, connected by a methodology that isn't visible until you already understand it.

For now, the cracks in the infrastructure remain. And in those cracks, information keeps moving — quietly, slowly, and almost entirely out of sight.

All Articles

Related Articles

Paper Trails and Chalk Marks: Why Gen Z Is Going Analog to Disappear

Paper Trails and Chalk Marks: Why Gen Z Is Going Analog to Disappear

Ears to the Sky: Inside the Obsessive World of Amateur Signal Hunters Cracking Government Transmissions

Ears to the Sky: Inside the Obsessive World of Amateur Signal Hunters Cracking Government Transmissions

Voices from Nowhere: The Unexplained Radio Transmissions That Have Been Running for Decades

Voices from Nowhere: The Unexplained Radio Transmissions That Have Been Running for Decades