Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Sunday, 25 August 2019

The Last Suit You'll Ever Wear (Gumshoe, Night's Black Agents)

I've been tangentially aware of DEF Con for a while, but I began dipping into some of the video panels over the past few weeks. This one is worth watching if you have any interest whatsoever in cyber security. If you don't want to watch it all the way through, scoot to about 30 minutes in. That's the bit I want to talk about today.


This stuff fascinates me. You may have seen the speaker elsewhere, or read his work. He's Jayson E. Street, and he's had articles in Forbes as well as talkathons in Las Vegas. He's an ongoing (if that's the right word) speaker at DEF Con, and there are several videos of his on YouTube. I'm going to quote one sentence from the Forbes article, because it ought to be engraved in words of fire on the beating heart of every IT professional: 'it appears ease of use will once again trump security.'

Now, let's talk about that suit.

"If I am in this suit, I am out to screw you over terribly," says Street. Well, so are your Night's Black Agents. So what is it about the suit?

It does two things.

First, it fits in. Look at that conservative cut. He wouldn't be out of place in any North American business environment, and probably not in most places in Europe. He'd melt here in Bermuda - the waistcoat (vest o'doom) is not your friend in our climate.

Second, it allows him to transport any number of Trojans, horses and otherwise, without suspicion. USB pens, a flashlight that is also a video recorder, you name it. "When I walk into your facility, I am a walking, talking Google street car." Except this street car can leave things behind, like those pens, so he can pick up on your conversation later. Or plug in an external hard drive, if he wants a chunk of data. Bring along a tablet packed with useful apps. Who knows? But it's all hidden there in that vest o'doom, detectable if he goes through some form of X-ray security, or is just plain given a pat-down, but otherwise unseen.

The key to his entire talk, but especially this section, is this: anyone can do what he does. Most of the tools in his vest o'doom are commercially available, particularly in the US. Street bought some of his gear from Think Geek, for crying out loud. I shop at Think Geek (or I used to, anyway). Admittedly I wasn't buying USBs packed with keyloggers, but still ...

So how can we gamify this?

You could treat it as a simple Electronic Surveillance spend, where every 1 point spent buys 2 points Digital Intrusion. That seems a little bland. You could make it a combined spend, by saying that the agent can spend Bureaucracy or Flattery as well as Electronic Surveillance, each point adding to the pool, provided at least 1 point Electronic Surveillance is spent. So 1 point Bureaucracy plus 1 point Electronic Surveillance equals 4 points Digital Intrusion. That's probably enough to crack most OPFOR installations.

As a Cooperative task (p50 main book), assuming the agent with Electronic Surveillance is not at her best dealing with people, it could be: lead character (the one with Flattery/Flirting/Reassurance and Disguise) goes in, and secondary (with Electronic Surveillance) talks the lead through the technical stuff, presumably using an earpiece. So the secondary spends Electronic Surveillance to give the lead a Digital Intrusion pool. Or, using broadly the same trick but with Preparedness, reduce the Difficulty of future Digital Intrusion checks, or reduce the opposition's defensive pools. "Yeah, we thought of that. Which is why I sent Billy in during the day with my special vest o'doom, posing as one of the external audit team. Boy, are they going to be pissed when they find that nasty data stick of mine, plugged into the CFO's desktop!"

Or you could chain it to some Technothriller Monologue, to refresh 4 points Digital Intrusion. This may require some Disguise spends, mind you. "What they don't know will hurt 'em, I think to myself, as I dip into the vest o'doom for another of my specialty pens. This one goes in the CFO's office, this one for the CEO, and, oh, look, is that the exchange server? Let me just pop my tainted data stick in that little beauty."

Or it could be a great way to drop a clue. The agents find a nerdy-looking corpse stuffed behind a dumpster, but whichever goon did the deed didn't search the body thoroughly. Here's this funny vest, and it's stuffed full of data, or maybe it's still receiving output from those special little pens. The agents have to get to the data somehow, but that's their problem.

That's it for now. Enjoy!

Sunday, 21 July 2019

Car Hacking (Night's Black Agents, Dracula Dossier, Esoterrorists)

"By definition, a connected car has more control units, computing power, lines of code and wireless connections than a “non-connected” car – all of which make it more susceptible to attacks. By exploiting a weakness, a hacker could take control of the brake or steering systems, show incorrect information on the dashboard dials, or grab driver data."

From IIoT World, author Simon Hartley, The State of Auto Cybersecurity: Current Vulnerabilities of Connected Vehicles.

In 2015, Chris Valasek and Charlie Miller grabbed the world's attention by hacking, and gaining control over, a Jeep's dashboard functions from ten miles away. In 2018, the situation hasn't gotten any better. If a vehicle's autonomous or semi-autonomous, it's a cinch it can be controlled remotely. If it can be unlocked and operated via a smartphone app, it's a cinch someone's devised a way to spoof the app and steal the car.

Again, from the article, we're talking about devices that will require code somewhere in the 200 to 300 million line range - basically, a long, long, *long*, technical document. Or, if you like comparing it to literary works, Hamlet to the power of 837,988. That's a lot of stabbings and poison.

Code without mistakes or bugs, of course. Each bug introduces vulnerability. Vulnerabilities can and will be exploited.

That's before you consider that allowing third party software - apps - to have any degree of control over the vehicle means that the app, with all its vulnerabilities, is also a risk factor.

So, for example:

  • I need to know where that vampire's been. She always drives that sporty Tesla. OK, spending a point of Digital Intrusion or Electronic Surveillance, whichever the Director thinks suits the task. I'm going to crack the car's GPS with this smartphone app, and see where the Tesla's been for, say, the past week.
  • An infotainment system, you say? With a huge touchscreen right in the dash that controls every non-driving function? Well color me impressed. Let's just play with that satellite mapping software … oh, gee, looks like the route you wanted to take is blocked by a car wreck. Best take that recommended detour. No, we haven't set up an ambush there, honest, Hey! I can play videos! Has he got passengers? Cue up that blackmail material, and let's hope his wife is watching.
  • No, no, I don't need to have any pools in Digital Intrusion or Electronic Surveillance. I just need to make a Preparedness check, and boom! Here's a sneaky little app I bought off the dark web. Shall we say, a 3-point dedicated Digital Intrusion pool? Why, yes, I think we shall.
  • It probably goes without saying, but all these shiny toys need to be updated regularly, a task many users avoid. So known bugs and weaknesses still sneak through, because the necessary defenses weren't installed. Plus, anything that relies on passwords is only as safe as the user lets it be - which often isn't safe at all.
  • Oh! I can use this smartphone app to lock and unlock the car, send destination information to the GPS, remotely stop or start the car, send its current location to the app, and run real-time diagnostics. I wonder if that power can be abused in some cunning way …
Of course, all this assumes someone's driving the vehicle. A self-driving car is a different story. This might seem a boon for those bloodsuckers who have to sleep during the day; just add tinted windows and some grave soil, and all your worries drift away. Except if someone's hacked the guidance software then they can tell your car to go, well, anywhere they want. Imagine being delivered to your slayer like a giftwrapped package!

Of course, what's sauce for the goose is good for the gander. Just what are the agents driving these days? A top-of-the-line sportscar, all the better for those thrilling chases? Well, that could be a problem, if the Conspiracy has some half-decent hackers on its side. Maybe it's time to get into vintage muscle cars. It can be tricky to get the parts for a '67 Thunderbird, but at least it won't freak out when someone waves a smartphone at it.    

Enjoy!

Sunday, 7 July 2019

Hotel Wi-Fi Horror (Night's Black Agents)

Inspired by this article in the Guardian.

Short version: hotel wi-fi is incredibly insecure. This is partly because the people charged with protecting it are hotel people, who put service before security.

“Hospitality companies,” writes Bloomberg's Patrick Clark, “long saw technology as antithetical to the human touch that represented good service. The industry’s admirable habit of promoting from the bottom up means it’s not uncommon to find IT executives who started their careers toting luggage. Former bellboys might understand how a hotel works better than a software engineer, but that doesn’t mean they understand network architecture.”

Hackers love hotels because that's where people spend money. That means everything's vulnerable,  including their credit cards, passport numbers, personal details - pretty much everything guests might have wanted kept secret. Moreover it doesn't stop at one hotel. Hack, say, Marriott in Ohio, and you probably have access to every Marriott in the chain.

The aftershock can be brutal. When Marriott did get hacked, it put at risk 383 million guest records, as well as more than 5 million unencrypted passport numbers and more than 9 million encrypted payment cards.

I imagine most of you reading this have been to at least one sci fi or fantasy convention in your lives. Perhaps you go to several each year. Consider this a warning: you, too, could become a sad statistic in some future article about identity theft. You do have a Virtual Private Network, right?

It doesn't help that most hotels, anxious to keep expenses low, don't bother to upgrade out-of-date systems. Nor do their staff get trained on the best way to avoid trouble. If a customer asks to charge his phone, does the server plug it into the wall, or into the office computer? Are there unsecured, unwatched ports - say, in the bar?

With all that in mind, a scenario seed:

Puttin' On The Ritz

The agents are hired to infiltrate a high-profile hotel IT system, say one of the hotels in the Ritz-Carlton chain. That gives the Director plenty of options, from Washington DC to Tokyo. The client wants any and all data  that can be retrieved about guests arriving and departing between a set of dates. Nothing's too trivial; if the hotel records how the guest likes her eggs, then the client wants to know about it.

The agents may believe they're being hired as deniable cut-outs for a major intelligence service, or by a mafia don on the make. If the target is somewhere high-profile, like the Ritz-Carlton Macau, then the agents may be able to work up full profiles about the guests' gambling habits as well.

The job ought to be simple, but there are two problems:

First, there's a guest in the penthouse suite who's very paranoid about security. Her machines are VPN protected, and she takes care not to let her guard down. Her personal assistant seems to be the one in charge; perhaps if the PA could be dealt with, it would be easier to get the data.

Second, Heat jumps through the roof shortly before the hack ends. The agents gain 3 points Heat, with no idea why. Turns out there's a VIP, a Saudi royal, who recently arrived at the hotel, and the VIP's complaining about everything from the olives in his martini to the laughable internet security. The VIP's particularly hot on internet security, because six months ago his identity was stolen and large purchases made with his credit card. The hotel's jumping like a flea on a hot griddle, which is why Heat spiked. If the VIP could be satisfied, things would go back to normal.

One of these two - the penthouse guest or the Saudi royal - has Conspiracy links, but the agents won't find that out until their plotlines have been dealt with. The question is, which?

Or are the agents' mysterious paymasters the ones with Conspiracy links?

Enjoy!


Sunday, 14 April 2019

Espionage FUBAR (GUMSHOE, Night's Black Agents).

This week's post is inspired by recent events in Florida, at the President's member's club Mar-a-Lago.

You've almost certainly seen the reports by now, but a brief recap: a Chinese national was caught by Secret Service agents on Sat 30th March, as she attempted to infiltrate the club with two passports, four cell phones, malware on a data stick, and a laptop with an external hard drive. It's not clear why she was there. The theory being passed around in the papers is that she wanted to infiltrate an event organized by a "spa owner" (alleged whorehouse madam and human trafficker) which was to take place that evening.

It seems remarkably amateurish, especially for China. Given that Mar-a-Lago probably isn't the most secure installation in the world, I'd have thought it'd be much, much easier to suborn a senior staff member at the resort, and keep them on permanent payroll for moments like this. Or even get one of China's people hired as full-time staff. Heck, if all you want to do is put malware on the system, given that Mar-a-Lago's cyber security is probably even shakier than its front door policy, sneaking malware in via someone's Facebook page seems the better bet. Frankly, it sounds more like something North Korea would indulge in, given its penchant for wacky schemes and ambitious hacking.

Gamification coming right up.

Compromised

The Night's Black Agents hear, via Network - so before the media gets it, but only just - that a security breach at a Conspiracy-friendly government locale was foiled by alert security, and that the person responsible was captured, along with a quantity of suspicious items. Director's choice as to what, exactly, was on the agent when they were captured, but suggested kit includes assassination tools (particularly those known to work on vampires), data sticks chock-full of malware, mini cameras and similar surveillance tools. There's enough information for the agents, particularly anyone with Vampirology, to realize that, whoever it was, they knew enough about vampires to take effective countermeasures against them.

The precise location is going to depend on your campaign, but suggested locales are the House of Parliament in London, a high-profile event venue like the British Museum, the Berlaymont Building in Brussels, the Federal Chancellery in Berlin, or the Victoria Palace in Romania.

This raises two red flags for the agents. First: does this mean there's a Node of the Conspiracy operating at that location? Second: who is this luckless infiltrator, and what do they know about the Conspiracy?

To answer that question, the agents are going to have to rescue the infiltrator, or at least take possession of any notes taken from the infiltrator's interrogation. Both will involve sneaking into a National-level installation at the very least, with all the chicanery that implies. However there's a potential big reward on offer, because apart from anything else, whoever sent that infiltrator in will want them back. That means the agents could earn themselves Excessive Funds, or at least one big, fat, favor from a Vampire program like China's Room 452. The agents will need to move very quickly to pull this off, since it's only a matter of time before the infiltrator is put somewhere even the agents can't break into.

For a Dracula Dossier variant, the agent is from Edom, and might even be a Prince. Pearl is the obvious choice, but Tyler and Elvis are strong contenders. If this happened, then Edom will be very eager to get them back. However it raises a third red flag: was the Prince betrayed by a mole within Edom, or is this an elaborate attempt to defect?

Enjoy!

Sunday, 23 September 2018

A Nation State Robbing Banks: 80 Million and a Spelling Error (Night's Black Agents)

This post is inspired in part by Kento Bento's video about the biggest bank heist in modern history:


You may remember me mentioning this bank heist before, back in 2016 when not all the facts were in.

A couple quick points before I dive into Lazarus. Night's Black Agents Directors and agents wondering if Human Terrain is useful, wonder no more. Think about how cleverly this whole thing had to be coordinated: the thieves knew if they hit this particular bank on this particular day, and then transferred the stolen money to a bank in the Philippines, they'd be in the clear. Bangladesh, being Muslim majority, had its weekend on Friday and Saturday. The hack starts Friday. They come in on Sunday to sort out their problems, but they can't talk to their colleagues in New York because, on Sunday, their Christian colleagues are all off for the day. Monday works, but the bank in the Philippines, where the money is sent, is celebrating Chinese New Year, so it can't be contacted. That was fiendishly clever timing on someone's part.

Two, you may remember me mentioning a missing IT expert in the previous post. That expert, Tanveer Hassan Zoha, did turn up eventually. Detectives found him wandering near the airport and took him home, six days after he went missing. The IT expert claimed he could discover the identity of some of the culprits, and went with special police to the Bangladesh bank to have a look at the bank's records. Two days after that he was abducted from an auto rickshaw, and his family claimed the police were no help finding him. As far as I can determine his abductors were not caught. If he ever issued a public statement about his abduction, he didn't make it in an English language publication, as far as I know.

Bangladesh Airport connects to Hong Kong via Cathay Dragon, and Hong Kong is only a ferry ride away from Macau. That's where the alleged thieves went - it was a stopping point on their journey to North Korea, according to Kento Bento.

Which brings me to Lazarus Group, an entity that has been committing cybercrime since the early 2000s. Its earliest known attacks targeted South Korea, and it's alleged that the group has links to the North Korean government. This is difficult to prove, and might be a fake-out to throw blame on a believable straw man. That said, if anyone's going to think it's a good idea to back a group of crooks on a cybercrime spree, it's the dictator who may have poisoned his half-brother at an airport shopping concourse.

Lazarus has hit banks before, but banks aren't its only focus. It likes to hit South Korean targets, and allegedly was responsible for the Sony hack in 2014. The group demanded Sony withdraw its film The Interview, a comedy about an attempt on Kim Jong-un's life.


The Interview had so-so reviews and according to IMDB lost a ton of money - budget $44 million, worldwide gross something in the region of $12 million. Sony pulled the film from theatres in December 2014, allowing only a limited independent cinema release, and that after President Obama criticized Sony for giving in to terrorist threats.

Cybercrime experts Kaspersky Labs analyzed the Bangladesh hack, and give Kaspersky praise because it has nailed down the perfect hacking mini-scenario for Night's Black Agents Directors.

Initial Compromise. A single system inside the bank is breached with remotely accessible vulnerable code, perhaps through a webserver or a watering hole on a seemingly trustworthy website. The premise is simple: find a site you know the target visits, like a Chinese takeaway. The security on that site is bound to be less robust than the target's IT. Break it, infect it, wait for your target to visit - and the mouse takes the cheese. Snap!

Foothold Established. The group establishes persistent backdoors so they can come and go as they like.

Internal Reconnaissance.  The groups spends days, weeks, learning the network and identifying useful resources, like a backup server with vital information or an email server that can let the hackers into anything connected to that server. With the Bangladesh hack, Lazarus was particularly interested in SWIFT authentication, so it went after any server that might contain SWIFT authorization codes as well as IT admin systems.

Deliver and Steal. The great hack begins. Presumably followed by a scene Kaspersky does not mention, tentatively titled RUN AWAY!

This is the perfect breakdown for scenes in a game. What's more, they don't have to be about Digital Intrusion and nothing else. Human Terrain, Surveillance, Infiltration, Electronic Surveillance, potentially Flattery, Bureaucracy - all these will be useful, particularly in the early stages of the hack.

I see this as a potential Thrilling Digital Intrusion contest, starting with the initial compromise and moving through to final execution. The technothriller dialogue opportunities, particularly in the Initial Compromise or Internal Reconnaissance, are fascinating. It's a reminder that a Thrilling Contest doesn't have to be over in a few minutes. This one takes months - though at the table on the day the whole thing might take an hour's game time at most.

As for North Korea, well … it'd make a hell of a Node.

Enjoy!

Sunday, 5 June 2016

Secure Correspondence (Night's Black Agents, Dracula Dossier)

Just a quick one this week, to give Night's Black Agents Directors a nifty new way to correspond with agents in the field.

This is based on Stephen Leather's book Black Ops. One of these days I'm going to have to do a Not Quite Book Review on Leather; he's a lot of fun. British, used to be a journo for the Daily Mirror, been writing novel length fiction (meow) since 1997, and he's good at it, in a mannered and clever kind of way. Stephen King once said of horror maestro James Herbert that Herbert's work had a 'raw urgency,' the kind that grabbed you by the lapels and screamed in your face. By that scale, Leather stands in your way and speaks both loudly and firm, but doesn't quite reach the same level of urgency.

From a Night's Black Agents perspective Leather's most useful quality is that he writes both spy fiction and horror. Black Ops is pure spy fiction, starring Leather's recurring not-Bond, 'Spider' Shepherd, former SAS and policeman turned spy. What I want to talk about today is a neat little trick used by some of the characters in that novel to communicate, and how easy it would be to use that trick in game.

Secure communication via email is always a problem. Experts say that email is by its very nature insecure. Companies like Lavabit or SilentCircle used to say they could secure their transmissions, but they don't make that claim any more. SilentCircle went so far as to smash its own servers rather than hand them over to the authorities. The metadata - who sent the email, when, and to whom - is always vulnerable, SilentCircle's CEO pointed out as the servers went silent.

But what if there was no metadata?

Black Ops' spy handler has a simple procedure. Create an email identity - let's say cushing1913 - on a service like outlook. Make sure both the handler and the agent knows the identity and the password. Then, when messages need to be delivered, create an email, but don't send it; save it to drafts instead. Alert the other party that there's a message, say by text message. The other party logs on to the email address, checks drafts, reads the message and then deletes it.

Nothing was ever sent, therefore there is no metadata. By saving it in drafts you don't even need to specify a receiving email addy. Theoretically the email client can be hacked, but so long as the sender and receiver promptly check and destroy messages as soon as they can, there's a very small window of opportunity for hackers to intercept messages.

I very much doubt it's foolproof, but it's a fascinating glimpse into workable tradecraft. One of Leather's greatest strength is that he bothers to find out how things work, and then weaves that knowledge into the narrative without being too obvious about it. No long lectures, no technobabble, just a quick but thought-provoking glimpse into a working system, and then on with the show.

From a Director's perspective the utility is obvious. Anyone can create an outlook identity. It costs no money and very little time to set one up. Once you've done that, cushing1913 - it might be Dracula Dossier's Harker, Hopkins, or someone else - can send messages to agents in the field in real time. It's the perfect means of sending scanned documents, like anything from the Hawkins Papers, to the players. Or bits of the Dossier itself, or instructions, or what-have-you.

It's ingenious, simple, and free. What's not to like?

Sunday, 20 March 2016

80 Million and a Spelling Error: Hacking (Night's Black Agents)

When I was just starting out as a low level employee for a financial institution I shall not name, a senior staff member was caught with his fingers in the electronic till. He rigged the system so that, every so often, dormant accounts or trust funds would deposit a trifling amount of money in his personal account. It was never much more than a few dollars, even cents, at a time, but spread over many accounts and over a long period of time those small sums added up to one big payout. He was caught when he went to lunch one day and forgot to lock his machine. Someone came into his office to drop something off, noticed the suspicious activity on his monitor, and passed it on to the higher-ups. It became a police matter very soon after that.

I was reminded of him when I read about the $80 million heist carried out electronically via the Bangladesh Bank. His scheme wasn't original, but it paid off big time, and he would have gotten clean away had he not made a very simple mistake, the kind of error we all make every day. Not quite cautious enough, not quite careful or suspicious enough, and it's game over. It's stories like these that have me paying cash rather than electronic POS whenever I can.

If you haven't already read this one: sophisticated criminals ripped off the central bank of Bangladesh, breaching its systems and then sending requests for money transfer to the US Fed, where Bangladesh Bank had billions stored. Several transfers took place, only for the whole thing to come crashing to a halt when someone misspelled the word Foundation as Fandation on one of the request forms. If that request had gone through the gang - and given the level of preparation it probably was a gang - would have made off with at least a billion, and probably more, since there's no reason to think they would have stopped until Bangladesh's accounts were empty. An IT expert who publicly voiced suspicion that apathetic bank officials had, at the very least, contributed to the caper through their negligence has gone missing. The bank's governor resigned; apparently his employees failed to tell him what had happened, and he only found out about the heist when it hit the papers. Though the bank has said it expects to recover some of the money it seems likely that the bandits will make a clean getaway. Most of it went to casinos in the Philippines, presumably so it could be efficiently laundered, and as a consequence the Philippines may once again be blacklisted by the Money Laundering Task Force. This is all the more important for the Philippines because there are elections coming in May; this kind of news is the last thing the ruling Liberal party needs. At least $30 million in cash ended up in the hands of an ethnic Chinese in Manila, but as for the rest, it could be anywhere.

So what does this story tell us about what it takes to be a hacker in Night's Black Agents?

To begin with, as discussed in last week's post on black baggers, you have to know a lot about human nature and how organizations work. Whoever did this had to know how Bangladesh Bank operated. They probably studied the habits of bank employees for some time before making a move, both in the real world and via keylogger virus or similar on their work machines. They knew when to strike, and how, for maximum impact.

This has been the case since time immemorial, which in computer terms goes back all the way to last week Tuesday. I have on my bookshelf Secrets of a Super Hacker by someone writing under the pseudonym Knightmare. It's hopelessly out of date from a technical perspective - if ever I want to know how to cut up an 8 inch floppy, Knightmare has me covered - but its lessons on interpersonal interaction and information finding are still very relevant. One chapter's devoted to social engineering, another to reverse social engineering, and he spends a remarkable amount of time discussing the joys of dumpster diving and how information found in the trash can help you pillage companies' accounts.

Speaking of, I wonder what Bangladesh Bank did with its trash. Even today banks generate so much paper, reams of physical data. You'd like to think it was all shredded, pulped or otherwise rendered unreadable. But maybe not; after all, Kapersky Labs has a very beautiful interactive map that claims Bangladesh is, at time of writing, the 41st most attacked country in the world. These things don't happen by chance. That same map says Russia is #1 - not an award to be proud of, hope those nuclear silos are doing just fine - Vietnam is #3, the US is #2, and most of Europe seems to be hovering in the 10s and 20s. Apart from Norway, Sweden and Finland, which are #133, #87 and #149. Come on, guys, Finland's not that bad. I know some great Finns. Don't be shy. Bear in mind this is real time data, so by the time you read this everything will have changed, with the possible exception of the top 2.

Incidentally, Kapersky, I notice Bermuda doesn't even feature on the map. Way to hurt my feelings, fellas.

So we're looking at Bureaucracy, Human Terrain, and probably Reassurance to reflect social engineering, and Urban Survival for those dumpster diving expeditions. The hacker is an urban animal; no hiking through the piney woods and living off fresh caught fish or beef jerky for this bunch. A decent Infiltration pool might also be helpful, for breaking into installations and making off with the contents of the shredder. With enough dedication almost anything can be pieced back together. It isn't about whether it can be done, but rather if it's worth the effort. Research is a must, as is Traffic Analysis. Depending on whether or not the hacker makes a dishonest crust by, say, fleecing banks in Bangladesh, or catching those who do, points in Streetwise or Criminology might be in order.

While the hacker is probably the least athletically inclined of all the Night's Black Agents types, it would be a very foolish player who didn't put some points in self defense. However pools in Mechanics and Surveillance are more likely. You're the one who watches, not the one who goes in with a cosh and a black bag.

With all that in mind, consider this example:

Kayo

One sentence: Former Nollywood actor and con artist shooting for the big leagues.

Investigative: Accounting 1, Bureaucracy 1, Bullshit Detector 3, Cryptography 1, Data Recovery 2, Electronic Surveillance 2, Human Terrain 2, High Society 1, Research 1, Traffic Analysis 1, Reassurance 2, Languages 2, Streetwise 1, Urban Survival 1

General: Athletics 8, Cover 10, Digital Intrusion 15, Disguise 6, Health 8, Infiltration 10, Mechanics 4, Network 15, Shooting 8 (base 14, with special weapons training), Stability 7, Surveillance 5, Sense Trouble 1.

MOS: Digital Intrusion (silly not to, really).

Cherries: Athletics (Parkour), Digital Intrusion (cracker's cryptid), Infiltration (open sesame), with special weapons training in the AK47. I picture this as an actor's conceit, for when Kayo decides to relive his glory days in Mafia Soldiers or the like.

As has become traditional, let's end this with a scenario seed:

A not for profit has announced a competition, the Shreddathon Challenge, to see who can be the first to piece together five sets of shredded documents, with $50,000 going to the winner. One team, the Hatfall Brigade, was coming very close to this goal with its specially designed computer program, but just as the final pieces were coming together three of the five programmers were brutally murdered, and the program was stolen. Shortly afterward the hacking community discovers that the not for profit hosting the challenge only ever existed in cyberspace; its backers have disappeared. What happened to the team, and what was the Shreddathon Challenge really all about?