# Counterspying:  How to detect a bug?

**URL:** <https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575>\
**Category:** In My Humble Opinion\
**Created:** [July 28, 2005, 1:32pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575 "2005-07-28T13:32:22Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bongmaster](https://avatars.discourse-cdn.com/v4/letter/b/6a8cbe/32.png) [@Bongmaster](https://boards.straightdope.com/u/Bongmaster)\
**Post date:** [July 28, 2005, 1:32pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/1 "2005-07-28T13:32:22Z")

</div>

This is a post I never thought I’d make. I work with sensitive data and we suspect there may be someone bugging the office. I’ve been reading up on the different techniques and gagets people can use to send audio from hidden mics, there is no end to them. This isn’t government related, its more an internal office politics thing but the threat is real enough. We suspect a particular person in the office is spying on our operations for reasons unknown, possibly to report to a competitor.

I was wondering if there were any knowledgeble people in that area around who could recommend a particular scanning device which is good at detecting hidden transmitters. Knowing this person he probably is using an inexpensive device which is well hidden. I have examined the phones and I can’t find any evidence of physical tampering so we suspect a mic hidden in the ceiling or other difficult-to-search area.

If anyone has some advice on how to detect this kind of device I’d really appreciate it.

---

<div class="post-metadata">

**Author:** ![DeadlyAccurate](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@DeadlyAccurate](https://boards.straightdope.com/u/DeadlyAccurate)\
**Post date:** [July 28, 2005, 2:07pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/2 "2005-07-28T14:07:05Z")

</div>

The same companies that sell bugs also sell bug detectors. I don’t know anything about particular companies, products, or brands, but try a Google search on bug detectors.

---

<div class="post-metadata">

**Author:** ![Ravenman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ravenman/32/2929_2.png) [@Ravenman](https://boards.straightdope.com/u/Ravenman)\
**Post date:** [July 28, 2005, 2:10pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/3 "2005-07-28T14:10:31Z")

</div>

I do work with classified information, and my recommendation would be to hire a security consultant for a one-off visit. I’ve watched people do sweeps for listening devices, and it was clear to me that it is a task that requires more skill and technology than the movies tend to portray.

---

<div class="post-metadata">

**Author:** ![MsRobyn](https://avatars.discourse-cdn.com/v4/letter/m/90ced4/32.png) [@MsRobyn](https://boards.straightdope.com/u/MsRobyn)\
**Post date:** [July 28, 2005, 2:21pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/4 "2005-07-28T14:21:49Z")

</div>

What Ravenman said.

In theory, it’s possible to scan for transmitters with an analog radio (digital tuners are too precise for something like this). But what you have is possible industrial espionage. Hiring a security consultant gives you some ammunition for legal action, should that become necessary. A consultant can also make recommendations for keeping sensitive data more secure so this doesn’t happen again.

Robin

---

<div class="post-metadata">

**Author:** ![Madd\_Maxx](https://avatars.discourse-cdn.com/v4/letter/m/5f9b8f/32.png) [@Madd\_Maxx](https://boards.straightdope.com/u/Madd_Maxx)\
**Post date:** [July 28, 2005, 7:57pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/5 "2005-07-28T19:57:59Z")

</div>

No disrespect, but with a name like **Bongmaster** are you sure you’re not just paranoid?

---

<div class="post-metadata">

**Author:** ![Bongmaster](https://avatars.discourse-cdn.com/v4/letter/b/6a8cbe/32.png) [@Bongmaster](https://boards.straightdope.com/u/Bongmaster)\
**Post date:** [July 29, 2005, 12:30pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/6 "2005-07-29T12:30:51Z")

</div>

> [@Madd Maxx](#):
>
> No disrespect, but with a name like **Bongmaster** are you sure you’re not just paranoid?

Hehe…I was waiting for that one! No, my hobby is limited to off work hours. And its not just me, we have a whole series of people thinking the same thing.

Unfortunately having a professional come in and do it is out of the question, mostly due to cost. I want to keep the price around $200-$300 so I was considering stuff like this:

[http://www.spy-tronix.com/item.html?PRID=1524944](http://www.spy-tronix.com/item.html?PRID=1524944)

I have a feeling these devices aren’t really worth the price but I really have no idea.

---

<div class="post-metadata">

**Author:** ![MC\_E](https://avatars.discourse-cdn.com/v4/letter/m/c77e96/32.png) [@MC\_E](https://boards.straightdope.com/u/MC_E)\
**Post date:** [July 29, 2005, 1:36pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/7 "2005-07-29T13:36:45Z")

</div>

Personally, I’d avoid the “Spy Shop” type stuff and look into HAM radio gear. Something like this would probably do the job:

[http://www.optoelectronics.com/rfdetector.htm](http://www.optoelectronics.com/rfdetector.htm)

You may want to see if anyone you trust is into amature radio to help you use it most effectively. You could probably do a decent job on your own, with a little experimentation. Try it out on your cellphone, RC Toy remotes, etc to see how it works and figure out how to determine the source of the transmission.

A friend into amature radio may already have something you can use.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [July 29, 2005, 1:55pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/8 "2005-07-29T13:55:55Z")

</div>

If it’s an analogue transmitter, you could set up an audio signal generator (or just play a WAV file of a continuous tone), then listen on a radio scanner (with headphones, so you can’t hear the actual audio you’re injecting into the room) to see if you can pick up the same sound being broadcast.

But you could just look for the thing; battery-powered bugs (like you see in the movies) have a very limited life span; anything more permanent will be more bulky or must be hooked up to an external source of power - in the telephone - in the USB port (or maybe one of the other ports, such as PS/2 or parallel) at the back of a computer - in the overhead lighting - in a wall socket - in a light switch - inside a wall clock (where there’s room for bigger batteries) - inside a powered item of office machinery - printer, copier, scanner, shredder (although admittedly, it could be hard to find if if’s inside a photocopier).

---

<div class="post-metadata">

**Author:** ![DocCathode](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/doccathode/32/18773_2.png) [@DocCathode](https://boards.straightdope.com/u/DocCathode)\
**Post date:** [July 29, 2005, 8:03pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/9 "2005-07-29T20:03:37Z")

</div>

What makes you so sure it’s an audio bug? Key logging programs and some others can be very well hidden.

I recommend you use whoever Mayor Street uses.

---

<div class="post-metadata">

**Author:** ![Bongmaster](https://avatars.discourse-cdn.com/v4/letter/b/6a8cbe/32.png) [@Bongmaster](https://boards.straightdope.com/u/Bongmaster)\
**Post date:** [August 1, 2005, 1:35pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/10 "2005-08-01T13:35:35Z")

</div>

> [@DocCathode](#):
>
> What makes you so sure it’s an audio bug? Key logging programs and some others can be very well hidden.
> 
> I recommend you use whoever Mayor Street uses.

LOL…

I’m 99.9% sure its not a keylogger based on my complete examination of all the PC’s and servers in the room. Besides, the evidence all points to an audio bug. Uncanny knowledge of certain events that were only discussed in one room, that kind of thing.

---

<div class="post-metadata">

**Author:** ![Ravenman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ravenman/32/2929_2.png) [@Ravenman](https://boards.straightdope.com/u/Ravenman)\
**Post date:** [August 1, 2005, 1:49pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/11 "2005-08-01T13:49:26Z")

</div>

Any chance it could be a biological listening device, like one of [these?](http://en.wikipedia.org/wiki/Image:Human.png)

---

<div class="post-metadata">

**Author:** ![Tomcat](https://avatars.discourse-cdn.com/v4/letter/t/8e8cbc/32.png) [@Tomcat](https://boards.straightdope.com/u/Tomcat)\
**Post date:** [August 1, 2005, 2:01pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/12 "2005-08-01T14:01:41Z")

</div>

There are phone taps, audio pickups, line taps, digital recorders and a whole host of other stuff that I probably don’t know anything about…If you feel your business is being compromised, then you NEED to pay for the specialist. Any other decision is irresponsible.

Let’s say you buy some quick-fix gadget and it comes up with ziltch. Can you now say that you are 100% bug-free? 50%? 25%? No. All you can say is that that one gadget didn’t find anything. And then if something else happens that can only be traced to espionage, then what will you do? Buy another gadget?

How much money can the company lose? How much is at risk? Losing a contract because your competitor knew your price bid is bad. Losing a client because of some privacy issue is worse. How much are you at risk here?

If you go with a specialist then you can say “While we cannot be 100% certain in this day and age, we have taken all reasonable and proper steps to ensure our companies security.” Which, if taken to court, saves your ass.

If you don’t feel capable of making that large of a decision, then maybe you need to escalate this to a manager who can. Find out prices and details of a few options, present them quickly, and let the higher ups make the decision for you. This sounds like it could bite you in the ass…do whatever you can to make sure that it bites someone else if the shit hits the fan.

“Well Mr. Director, **bongmaster** recommended that we try an analog spy-tester. Unfortunately our phone was tapped with a digital chip. We lost the contract for $1m.”

I’d hate to have to face your supervisor after something like that…Cover your ass, spend the proper money, sleep well at night.

-Tcat

---

<div class="post-metadata">

**Author:** ![DocCathode](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/doccathode/32/18773_2.png) [@DocCathode](https://boards.straightdope.com/u/DocCathode)\
**Post date:** [August 1, 2005, 3:27pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/13 "2005-08-01T15:27:17Z")

</div>

Are you sure they aren’t using some accoustic property of the room eg ‘when I stand on my desk and put my ear to the sprinkler pipe, I can hear everything they say next door’. Could they be using a stethoscope, directional microphone, etc to listen in from next door? Who and what occupies the rooms on the six sides of your office?

---

<div class="post-metadata">

**Author:** ![GargoyleWB](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gargoylewb/32/199_2.png) [@GargoyleWB](https://boards.straightdope.com/u/GargoyleWB)\
**Post date:** [August 2, 2005, 12:47am UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/14 "2005-08-02T00:47:47Z")

</div>

There can be simple ways of camoflouging (ugh, I know that’s not how it’s spelled) something temporarily. A small voice activated solid state recorder is commonly sold as credit card sized, or clicky-pen sized. Look for a random object that may just be sitting around, such as a three-ring binder, paperback dictionary, office toy or squishy stress ball, that could conceal a voice-activated recorder.

Honestly, if it’s a temporarily placed passive device (i.e. not broadcasting to another device somewhere else) you have a zero chance of detecting it without dismantling the place into rubble. Luck is all you have.

Given that, if you are certain that there is still a listening device, start thinking about active mis-information, or specific false information that you can track or entrap someone with to discover the source of the leak.

It is also an opportunity to justify the addition of a jumpsuited english femme fatale counter agent to your quarterly budget, for “office support” tasks.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [August 2, 2005, 8:13am UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/15 "2005-08-02T08:13:38Z")

</div>

> [@Ravenman](#):
>
> Any chance it could be a biological listening device, like one of [these?](http://en.wikipedia.org/wiki/Image:Human.png)

A naked adult should be quite easy to spot, especially if he’s waving.

Have you considered setting a trap; invent some tempting fiction that would cause the eavesdropper to blow his cover? (like, I dunno, conspiratorially mentioning that you keep a stash of emergency money hidden in some obscure location, but actually hide a canister of indelible dye there - the kind of canister that can’t be easily opened without spilling the contents everywhere, including the person opening it. Obviously the location needs to be suitably obscure to prevent the likelihood of accidental discovery)

---

<div class="post-metadata">

**Author:** ![Bongmaster](https://avatars.discourse-cdn.com/v4/letter/b/6a8cbe/32.png) [@Bongmaster](https://boards.straightdope.com/u/Bongmaster)\
**Post date:** [August 2, 2005, 3:20pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/16 "2005-08-02T15:20:34Z")

</div>

We pretty much ruled out a human being as the spy since the room is enclosed in glass…it would be very hard to spy like that. And its not really about losing a big contract to competitors, more of someone in the office trying to get an unfair advantage by spying on the technology staff. We’re going through some big changes, this person is new, and a bunch of individuals all are thinking the same thing about this guy based both on his personality and several uncanny “conicidences” which none of us believe happened by pure chance.

We’ve already asked a person in senior management about it and she’s on the fence about what to do. The point was made that even if we buy a $200 bug sweeper we can’t say for sure that the room is secure. This is true…but what if it did find a bug? I’m pretty sure I could trace it back to him by either catching him in the act or something similar.

---

<div class="post-metadata">

**Author:** ![Zabali\_Clawbane](https://avatars.discourse-cdn.com/v4/letter/z/ecd19e/32.png) [@Zabali\_Clawbane](https://boards.straightdope.com/u/Zabali_Clawbane)\
**Post date:** [August 2, 2005, 3:27pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/17 "2005-08-02T15:27:47Z")

</div>

Could they be listening at the vents for the central air system maybe though? 😕 I think you ought to bring in an expert, just so you can be absolutely certain. As other posters have pointed out, if you are being spied on, not only is the information lost, but money has been mis-spent if you buy a device that can’t detect the bug.

---

<div class="post-metadata">

**Author:** ![picker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/picker/32/13969_2.png) [@picker](https://boards.straightdope.com/u/picker)\
**Post date:** [August 2, 2005, 3:41pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/18 "2005-08-02T15:41:36Z")

</div>

Why don’t you try a deliberate misinformation campaign - discuss a different piece of really juicy and irrestible info that will cause whomever is at the other end to reveal themselves inadvertently?

Don’t catch the device, catch the user.

---

<div class="post-metadata">

**Author:** ![vibrotronica](https://avatars.discourse-cdn.com/v4/letter/v/a9a28c/32.png) [@vibrotronica](https://boards.straightdope.com/u/vibrotronica)\
**Post date:** [August 2, 2005, 4:24pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/19 "2005-08-02T16:24:36Z")

</div>

The misinformation option worked like a charm at the [Battle of Midway](http://www.history.navy.mil/faqs/faq81-3.htm).

> [@](#):
>
> What caused Admiral Nimitz to decide so quickly in favor of Midway? One explanation may simply be that OP-20-G provided enough decryption intelligence to convince the Admiral that AF was Midway. Another, more dramatic possibility is that, at this crucial point, the Navy, by using radio deception, tricked the Japanese into revealing the identity of AF. The exact date has never been precisely documented, but according to both Rochefort and Layton, sometime in mid-May, they approached Admiral Nimitz with a plan to proved whether or not AF was Midway. The idea was to send a message, via the cable to Midway, to the Commanding Officer of the Naval Base instructing him to:
> 
> . . . send a plain language message to Com 14 (Commandant 14th Naval District) stating in effect, that the distillation plant had suffered a serious casualty and that fresh water was urgently needed–to which Com 14 would reply, (also in plain language), that water barges would be sent, under tow, soonest . . . .
> 
> Hopefully, Japanese radio intelligence would intercept these messages and the information would then be disseminated from Tokyo in the Japanese Daily Intelligence Reports which OP-20-G would, in turn, intercept, and determine if the water situation at Midway was referenced. Admiral Nimitz agreed to the plan and the message was sent. The Japanese did pick it up and Tokyo did include, in an intelligence report, the statement that “AF is short of water.”

Good enough for Nimitz, good enough for **Bongmaster**!

---

<div class="post-metadata">

**Author:** ![Inigo\_Montoya](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/inigo_montoya/32/124_2.png) [@Inigo\_Montoya](https://boards.straightdope.com/u/Inigo_Montoya)\
**Post date:** [August 2, 2005, 4:39pm UTC](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575/20 "2005-08-02T16:39:33Z")

</div>

Nuke the suspect from orbit. It’s the only way to be sure.

Or have him monitored while you have your meeting. Not effective if he’s recording and listening later though.

Or do the disinformation thing.

Or keep important stuff “eyes only.”

Got moles?

[Next page](https://boards.straightdope.com/t/counterspying-how-to-detect-a-bug/314575.md?page=2)
