
J. KEVEN HOFELING, ESQ.
JFK ASSASSINATION RESEARCH • DISTRIBUTION LIST WORK PRODUCT
Salt Lake City, Utah · j.keven.jd@jkhofelinglaw.org · https://jkhofelinglaw.org/
A COINTELPRO/JTRIG EXPANDED FIELD MANUAL FOR THE BONA FIDE RESEARCHER
— PART I OF III
Diagnosis — Conduct, Not Identity
Why “Is He Paid?” Is the Wrong Question, and What to Ask Instead
J. KEVEN HOFELING, ESQ. • AUGUST 2026
A companion volume to “A Spectre Is Haunting the JFKA Research Community”
| THIS SERIES
Part I — Diagnosis — Conduct, Not Identity (this installment) Part II — Engagement — The Demonstration Doctrine Part III — The Record, the Remedies, and the Community Each installment stands alone. Together they are the working companion to “A Spectre Is Haunting the JFKA Research Community,” Part III of which introduces this manual. |
| CONTENTS OF PART I
I. The Question You Cannot Answer, and Why Asking It Costs You II. The Attribution Pyramid III. What Is Actually Observable IV. The Inversion — Measuring Effects Instead of Identities V. What the Published Record Actually Establishes Sources for Part I (Hyperlinked) |
| WHAT THIS MANUAL IS, AND WHAT IT IS NOT
The three installments of A Spectre Is Haunting the JFKA Research Community set out a documented record: the counterintelligence doctrine the United States and its allies have published about themselves,
my own account of being worked by it,
and the case of Gary Webb, who paid the ultimate price.
This companion is the practical residue of that record — what I would actually do, and actually not do, having read it. It is written under one governing constraint, and I want to state it before anything else. Nothing in this manual will tell you whether the person you are arguing with is a paid disinformation agent. That question cannot be answered from a forum thread, the attempt to answer it produces mostly false accusations, and the attempt is itself one of the more reliable ways to destroy a research community from the inside. Everything here is built to be useful without answering it. Where a technique rests on a published document, I cite the document. Where it rests on peer-reviewed evidence, I cite the study, including where the evidence is weaker than I would like. Where it rests on nothing but my own thirty-five years of doing this, I say so and you may weigh it accordingly. |
I. The Question You Cannot Answer, and Why Asking It Costs You
Begin with arithmetic, because the arithmetic is not intuitive and it governs everything that follows.
Suppose you are on a forum with two thousand active participants. Suppose — generously, and far above any figure anyone has ever documented for a niche historical forum — that two percent of them are conducting some form of inauthentic disinformation operation. That is forty people. Suppose you have a behavioral screen that is genuinely good: it catches eighty percent of the real operators, and it wrongly flags only ten percent of the innocent.
Run it. Your screen flags 32 of the 40 real operators. It also flags 196 of the 1,960 ordinary members. You have 228 flagged people, of whom 196 are innocent. Eighty-six percent of your accusations are wrong.
And that is the flattering case. Drop the assumed prevalence to a still-substantial one percent and hold specificity at ninety percent, and better than nine in ten of your accusations are false. Even a screen with 99.5 percent specificity — an instrument that wrongly flags only one ordinary member in two hundred — still leaves you wrong about one accusation in four. To get below one in five you would need better than 99.6 percent. No behavioral screen described in any literature, government or academic, comes close to that.
TABLE 1 — WHAT A TRAIT SCREEN ACTUALLY PRODUCES ON A 2,000-MEMBER FORUM (SENSITIVITY FIXED AT 80%)
| Assumed prevalence | Specificity | Real operators caught | Innocent members flagged | Share of your accusations that are FALSE |
|---|---|---|---|---|
| 5% (100 people) | 90% | 80 | 190 | 70.4% |
| 2% (40 people) | 90% | 32 | 196 | 86.0% |
| 1% (20 people) | 90% | 16 | 198 | 92.5% |
| 2% (40 people) | 95% | 32 | 98 | 75.4% |
| 2% (40 people) | 99% | 32 | ~20 | 38.0% |
| 2% (40 people) | 99.5% | 32 | ~10 | 23.4% |
Standard positive-predictive-value arithmetic; every cell is reproducible with a calculator. The lesson is not that operators do not exist — Part I of the main series documents that they do, in the operators’ own words. The lesson is that a screen aimed at identifying individuals will, on any realistic assumption, still accuse innocent people, and that this remains true even when the screen is good and the underlying phenomenon is real.
| THE CONSEQUENCE, STATED PLAINLY
A community that adopts individual-identification as its practice does not catch operators. It generates suspicion at a rate the real phenomenon cannot support, and then it turns that suspicion on itself. This is not a hypothetical failure mode. It is the documented objective of the programs this series is about. The Church Committee found that the Bureau’s Counter Intelligence Program worked precisely by promoting factionalism — by circulating anonymous letters and “snitch-jackets” designed to make activists believe their colleagues were informants. You do not need an operator on your forum to get that result. You only need a membership that has decided operator-hunting is a legitimate activity. The apparatus can retire and leave the work to you. |
| DEMONSTRATIVE EXHIBIT D-1
Why agent-hunting accuses the innocent — the base-rate chart Table 1 rendered as a chart, with the hero figure stated: on the most plausible assumptions, 86 percent of the accusations a trait screen produces are false. Every value is standard positive-predictive-value arithmetic at sensitivity 80% and population 2,000, and every one is reproducible with a calculator. |
II. The Attribution Pyramid
Replace the question who is this person with the question what can I actually establish, and at what level. The following ladder is the single most useful organizing device I have found. Each tier has its own evidentiary predicates. Most of what you will ever observe on a forum lives in the bottom two tiers, and almost nothing lives above the middle.
TABLE 2 — THE ATTRIBUTION PYRAMID: SIX TIERS, AND WHAT EACH ACTUALLY REQUIRES
| Tier | What is claimed | What you must have to claim it | How often you will have it |
|---|---|---|---|
| 6 | State-directed operation | Orders, funding records, official documents, an admission, a whistleblower, or lawful technical proof linking a specific government actor to a specific instruction to a specific account | Essentially never, from a forum |
| 5 | Institutional or contractor nexus | Contracts, employment records, corporate filings, or disclosure tying accounts to an organization with an interest | Rarely, and usually from journalism or litigation, not from you |
| 4 | Organized campaign | Sustained cross-platform coordination, shared assets, a common content pipeline, evidence of direction | Occasionally, and normally established by platforms or researchers with data you do not have |
| 3 | Coordinated inauthentic behavior | Synchronized timing in narrow windows, identical uncommon text, shared infrastructure or administrators, persona anomalies, mutual amplification, rotation patterns | Sometimes — and this is the highest tier you can realistically reach |
| 2 | Bad-faith or disruptive conduct | A record of non-responsive replies, moved goalposts, procedural motions substituted for rebuttal, refusal to address a cited primary document | Often, and it is fully documentable |
| 1 | Ordinary disagreement, or ordinary human rigidity | Nothing. This is the default and it is where the great majority of your opponents actually are | Most of the time |
| Do not accuse where you can demonstrate. Do not infer where you can document.
The operating rule of this entire manual |
The pyramid does the work of protecting you from yourself. A claim at Tier 2 — this person has been asked the same evidentiary question four times across three months and has not answered it once — is checkable by anybody, cannot be defamatory because it is a description of the public record, and is devastating to the person it describes. A claim at Tier 6 is unfalsifiable, unprovable, actionable, and will get your thread locked. The lower claim is the stronger claim. That is counterintuitive and it took me a long time to learn.
| DEMONSTRATIVE EXHIBIT D-2
The Attribution Pyramid — six tiers of claim, and what each one actually requires Tier definitions adapted from published platform-integrity practice; see the EU DisinfoLab / veraAI detection tree and Nimmo, “The Breakout Scale.” |
III. What Is Actually Observable
The professional literature on this problem long ago made the same move I am urging, and for the same reason. Platform integrity teams cannot read minds either. What they can do is measure whether the distribution of a message was organic. The EU DisinfoLab and the EU-funded veraAI project publish a Coordinated Inauthentic Behaviour detection tree built on four branches — Coordination, Source, Impact and Authenticity — and their framing is worth adopting verbatim: the object of inquiry is the “falsification of content distribution and amplification in a coordinated, non-organic way,” and while CIB “cannot be diagnosed instantly, a collection of symptoms can indicate its presence.”
Note what that definition does. It says nothing about who anyone is. It is entirely about observable behavior of accounts over time, which is exactly the evidence a forum member actually has.
Ben Nimmo’s Breakout Scale (Brookings, September 2020) makes the same discipline explicit, insisting on data that are “observable, replicable, verifiable, and available from the moment they were posted.” Adopt that as your standard of proof and you will never publish something you cannot defend.
TABLE 3 — INDICATORS, THEIR REAL EVIDENTIARY WEIGHT, AND THE INNOCENT EXPLANATION YOU MUST RULE OUT FIRST
| Observable indicator | Weight | What to preserve | What it also looks like — rule this out first |
|---|---|---|---|
| Shared infrastructure: common administrators, linked recovery details, same posting client fingerprints | High | Platform notices, message headers, anything produced in discovery | A shared household, office, or organization — which is not itself illegitimate |
| Identical uncommon phrasing across accounts inside a narrow window | Moderate–high | Exact text, URLs, timestamps to the minute, account identifiers | Everyone copied the same press release, post, or talking-points page |
| Coordinated mass reporting of one member’s content | Moderate–high | Complaint identifiers, timestamps, the notices themselves | A genuinely offensive post that many people independently reported |
| A persona using stolen or synthetic profile photographs | Moderate–high | Reverse-image results with dates, archived profile snapshots | Ordinary pseudonymity for privacy, which is legitimate and common |
| Dormant accounts activating together on one topic | Moderate | Join dates, last-active dates, the triggering thread | A topic that genuinely brought lapsed members back |
| Sequenced arrival: the same several accounts appearing in the same order across many threads | Moderate | Thread URLs, post ordinals, timestamps | Friends who actually agree, and who have a long visible history together |
| Refusal to address a cited primary document, repeated over months | Moderate, and fully documentable | The exhibit, and every non-response quoted in place | Genuine conviction that your document is irrelevant — ask them to say why |
| Posting clustered into working hours with weekends off | Very low — never use alone | Nothing; do not build this case | Shift workers, retirees, insomniacs, people in other time zones, people with jobs |
| Hostility, sarcasm, condescension, refusal to concede | None | Nothing unless it becomes harassment | Ordinary human behavior on the internet |
| THE HARD NEGATIVES — THINGS THAT ARE NOT EVIDENCE OF ANYTHING
Being a lone-gunman advocate. Being a defender of the Central Intelligence Agency. Being an institutional historian. Being rude, being arrogant, being wrong, being wrong loudly, or being wrong for thirty years. These are positions and personalities. Positions are not assignments. I include this list because I have watched this community treat every item on it as probative, and because I have caught myself doing it. The most disciplined thing in this manual is the willingness to say that the great majority of the people who infuriate you are exactly what they appear to be: people who disagree with you. |
IV. The Inversion — Measuring Effects Instead of Identities
Here is the most useful single document I encountered in preparing this manual, and I do not believe it has been used this way before.
In March 2011 the Defence Science and Technology Laboratory produced a report by Dr Mandeep K. Dhami titled Behavioural Science Support for JTRIG’s Effects and Online HUMINT Operations, published from the Snowden material. It describes JTRIG’s work in terms of techniques to “discredit, disrupt, delay, deny, degrade, and deter” — six verbs, not the four commonly quoted, and they come from this document rather than from the better-known “Art of Deception” slide deck.
But § 2.11 is the part that matters. It sets out how JTRIG proposed to measure whether an online effects operation was actually working — counting views, checking whether a message had been “attended to, understood, accepted,” counting the friends an alias had accumulated, counting how often a human source initiated contact with an alias.
Turn that list around. If those are the adversary’s success metrics, then the observable state of your own community is the readout. You do not need to identify an operator to notice that a productive researcher has stopped posting, that a thread which used to argue about evidence now argues about procedure, that a body of work is now discussed exclusively through a characterization of its author. Those are measurable, they are visible to everyone, and they are the effects the doctrine says the work is for.
| Stop trying to identify operators, which you cannot do. Start measuring what is happening to your community, which you can — and which is the thing the operators are paid to change.
The Dhami inversion |
This is the move that rescues the whole enterprise. It is honest, it requires no accusation, it produces a record anybody can check, and it addresses the actual harm. A community that tracks its own degradation — who left, what stopped being discussable, which exhibits went unanswered — has a defensible evidentiary practice. A community that maintains a list of suspected agents has a witch hunt.
| DEMONSTRATIVE EXHIBIT D-3
The Dhami Inversion — the adversary’s success metrics, read backwards Primary source: Dhami, DSTL, 10 March 2011, § 2.11 — https://nsarchive.gwu.edu/document/22372-document-07-mandeep-k-dhami-defence-science-and |
V. What the Published Record Actually Establishes
One more discipline before Part Two. Be precise about what your own sources prove, because the fastest way to lose an argument is to be caught overclaiming a document your opponent can open.
TABLE 4 — CLAIM DISCIPLINE: WHAT EACH PRIMARY SOURCE DOES AND DOES NOT ESTABLISH
| Source | What it establishes | What it does NOT establish — do not claim this |
|---|---|---|
| CIA Dispatch 1035-960 (1 April 1967) | That the Agency instructed stations to use “propaganda assets” and “friendly elite contacts (especially politicians and editors)” against Warren Report critics, and supplied a five-point template for discrediting them | That the Agency invented the phrase “conspiracy theory.” It did not — the term is attested in the New York Times in 1863. Claim the deployment, which is documented; not the coinage, which is false |
| Church Committee, Book III (1976) | That the FBI ran a domestic program to “expose, disrupt, misdirect, discredit or otherwise neutralize” dissenters, and that in the Committee’s words “the Bureau took the law into its own hands, conducting a sophisticated vigilante operation against domestic enemies” | That any such program is operating against you now. Quote p. 27 exactly; a paraphrase inside quotation marks is the error this manual warns about |
| Sunstein & Vermeule (2008) | That two prominent legal academics, one later head of OIRA, proposed “cognitive infiltration of extremist groups,” including participation under anonymous or false identities | That the proposal was adopted, funded, or implemented. It is a working paper. Its significance is that it was thinkable and publishable, which is significant enough |
| GCHQ / JTRIG (2011–2014) | That a signals-intelligence agency of a Five Eyes partner maintained a unit whose published training material covers honey traps, false-flag postings, fake victim blogs, and reputation destruction | That it was directed at American JFK researchers. It establishes capacity, doctrine and institutional interest — not individualized attribution |
| DARPA SMISC (2011) | A substantial state investment in detecting and characterizing influence campaigns at scale | That it was a domestic xxxxx program. DARPA’s own program page describes countering adversaries’ campaigns, closed networks of consenting participants, and a bar on collecting personal information from U.S. participants. Anyone can fetch that page in thirty seconds. Do not build on this |
| “Managing a Nightmare” (CIA, 1996; released 2014) | That the Agency’s own internal history describes working the press during the Dark Alliance controversy, credits “a ground base of already productive relations with journalists,” and treats the outcome as a success | That the CIA ordered the Post, the Times or the Los Angeles Times to attack Gary Webb. The document does not say that. It says the Agency participated in the environment in which his ruin occurred — which is damning enough, and defensible |
Every row in that table is a place where I have seen this community — and in two instances, my own drafts — claim more than the document supports. The corrected version is in every case still strong. You lose nothing by being exact, and you lose everything by being caught overstating the record.
| END OF PART ONE
Part Two takes up engagement: the doctrine that you argue for the benefit of the silent reader rather than to persuade your opponent, the empirical evidence that this actually works, and the time discipline that keeps it from consuming your life. To be continued in a day or two. |
Keven
J. Keven Hofeling, Esq. • Thursday, August 27, 2026 • Salt Lake City, Utah • http://www.jkhofelinglaw.org/
Sources for Part I (Hyperlinked)
| Item | URL (spelled out) |
|---|---|
| Mandeep K. Dhami, Behavioural Science Support for JTRIG’s Effects and Online HUMINT Operations, Defence Science and Technology Laboratory (10 Mar. 2011) — the source of the six-verb vocabulary and of the § 2.11 effectiveness metrics inverted in § IV | https://nsarchive.gwu.edu/document/22372-document-07-mandeep-k-dhami-defence-science-and |
| The same report, OCR text | https://nsarchive.gwu.edu/media/22372/ocr |
| EU DisinfoLab / veraAI, “Coordinated Inauthentic Behaviour detection tree” — the four-branch framework adopted in § III | https://www.disinfo.eu/publications/coordinated-inauthentic-behaviour-detection-tree/ |
| Ben Nimmo, “The Breakout Scale: Measuring the Impact of Influence Operations,” Brookings (Sept. 2020) — the evidentiary standard: observable, replicable, verifiable | https://www.brookings.edu/articles/the-breakout-scale-measuring-the-impact-of-influence-operations/ |
| Meta, Inauthentic Behavior policy — the platform’s own definition, which turns on deception and fake accounts rather than on opinion | https://transparency.meta.com/policies/community-standards/inauthentic-behavior/ |
| CIA Dispatch 1035-960, “Countering Criticism of the Warren Report” (1 April 1967) — History Matters archive, RIF 104-10406-10110 | https://www.history-matters.com/archive/jfk/cia/russholmes/104-10406/104-10406-10110/html/104-10406-10110_0002a.htm |
| The same dispatch, Internet Archive mirror (note: the History Matters index renders the date as “1/4/1967”; the document face reads 1 April 1967) | https://archive.org/details/CIADOC1035960 |
| Church Committee, Final Report, Book III (1976) — the “sophisticated vigilante operation” finding at p. 27 | https://www.intelligence.senate.gov/sites/default/files/94755_III.pdf |
| Cass R. Sunstein & Adrian Vermeule, “Conspiracy Theories” (2008) — the “cognitive infiltration” proposal | https://chicagounbound.uchicago.edu/cgi/viewcontent.cgi?article=1118&context=law_and_economics |
| DARPA, Social Media in Strategic Communication — the program page, which describes countering adversaries’ campaigns, consenting participants, and a bar on collecting personal information from U.S. participants | https://www.darpa.mil/research/programs/social-media-in-strategic-communication |
| CIA, “Managing a Nightmare: CIA Public Affairs and the Drug Conspiracy Story” — Reading Room document 0001372115, six pages, published 23 Oct. 2006 | https://www.cia.gov/readingroom/docs/DOC_0001372115.pdf |
| Amanda Kunda [Ziva Kunda], “The Case for Motivated Reasoning,” Psychological Bulletin 108(3):480–498 (1990) — the ordinary explanation for intransigence that any diagnostic must first rule out | https://psycnet.apa.org/record/1991-06436-001 |
| EXPANDED FIELD MANUAL — PART I OF III • NEXT: PART II — ENGAGEMENT — THE DEMONSTRATION DOCTRINE |
—
J. KEVEN HOFELING, ESQ.
JFK ASSASSINATION RESEARCH • DISTRIBUTION LIST WORK PRODUCT
Salt Lake City, Utah · j.keven.jd@jkhofelinglaw.org · https://jkhofelinglaw.org/
A COINTELPRO/JTRIG EXPANDED FIELD MANUAL FOR THE BONA FIDE RESEARCHER
— PART II OF III
Engagement — The Demonstration Doctrine
Writing for the Silent Reader, Under Time Discipline, Without Being Drained
J. KEVEN HOFELING, ESQ. • AUGUST 2026
A companion volume to “A Spectre Is Haunting the JFKA Research Community”
| THIS SERIES
Part I — Diagnosis — Conduct, Not Identity Part II — Engagement — The Demonstration Doctrine (this installment) Part III — The Record, the Remedies, and the Community Each installment stands alone. Together they are the working companion to “A Spectre Is Haunting the JFKA Research Community,” Part III of which introduces this manual. |
| CONTENTS OF PART II
I. The Doctrine, and the Objection to It II. Why the Demonstration Works — The Inoculation Evidence III. Label the Move, Never the Man IV. Sixteen Moves, and the Counter to Each V. The Three-Move Rule VI. The Thread Displacement Scale VII. Predicting the Next Move, in Public, With a Falsification Clause VIII. Three Precedents Worth Keeping in Front of You IX. The Stable Evidence Page X. The Evidence Base, Annotated Sources for Part II (Hyperlinked) |
| WHERE WE ARE AND WHERE WE HAVE BEEN
Part One of this expanded field manual argued that you cannot identify operators, that trying produces mostly false accusations, and that the defensible practice is to document conduct and measure effects rather than to attribute employment. That leaves an obvious question: if you are not going to unmask anyone, why engage at all? This installment answers it. The short version is that engagement is not an attempt to persuade your opponent. It is primarily a demonstration staged for the people reading silently, and there is now a substantial experimental literature establishing that such demonstrations confer real and durable resistance on the audience. The rest of Part Two is about doing it under time discipline, so that the demonstration costs the demonstrator less than it costs the other side. WHAT THIS MANUAL IS, AND WHAT IT IS NOT The three installments of A Spectre Is Haunting the JFKA Research Community set out a documented record: the counterintelligence doctrine the United States and its allies have published about themselves,
my own account of being worked by it,
and the case of Gary Webb, who paid the ultimate price.
This companion is the practical residue of that record — what I would actually do, and actually not do, having read it. It is written under one governing constraint, and I want to state it before anything else. Nothing in this manual will tell you whether the person you are arguing with is a paid disinformation agent. That question cannot be answered from a forum thread, the attempt to answer it produces mostly false accusations, and the attempt is itself one of the more reliable ways to destroy a research community from the inside. Everything here is built to be useful without answering it. Where a technique rests on a published document, I cite the document. Where it rests on peer-reviewed evidence, I cite the study, including where the evidence is weaker than I would like. Where it rests on nothing but my own thirty-five years of doing this, I say so and you may weigh it accordingly. |
I. The Doctrine, and the Objection to It
My position, stated flatly: online disinformation operatives should be engaged, not ignored, because the audience needs to see the illegitimacy of their claims demonstrated rather than merely asserted or appearing to have been suppressed. But the engagement must be conducted skillfully, or the operative wins by a different route — by consuming the researcher’s time and attention until the probative evidence never gets published at all.
There is a serious case on the other side and I want to put it fairly, because I held the opposite view myself for a period and because the best statement of it came to me privately from a researcher I respect.
NATO’s Strategic Communications Center of Excellence published a study of hybrid trolling in Latvia in January 2016 whose operational tutorial runs: identify, check, label, and then ignore. Its reasoning is not foolish. The more users engage, the more credible a xxxxx appears to inexperienced readers; replies generate reach; and “any reaction can serve for provocation in the future,” since selectively excerpted responses can be recycled as propaganda. A senior researcher put the same point to me in blunter terms in May:
“It was never about the logic behind the arguments. It was about arguing… I think your posts are just pouring gasoline on a dumpster fire.”
I take that seriously and I have not adopted it, for a reason I can now state with evidence rather than temperament.
That study is worth more than the one recommendation people quote from it, because it also did the empirical work. Its authors read a large sample of comments on Latvian news portals and classified them, and they arrived at two figures that ought to discipline everybody in this field, my own thesis included: hybrid trolling accounted for 1.45 percent of all comments, and 3.72 percent of comments on those articles that were actually being targeted. That is a real phenomenon and a small one — and it is almost exactly the prevalence assumption that makes the arithmetic in Part I, Table 1, come out the way it does.
Their typology is the other thing worth taking. It is a vocabulary for what arrives, and one of its five categories names something I had encountered for years without having a word for it.
TABLE 5 — THE FIVE MESSAGE TYPES NATO STRATCOM FOUND IN THE FIELD
| Type | How it works | What it is for |
|---|---|---|
| The conspiracy xxxxx | Long, pseudo-logical arguments attributing every phenomenon to a single actor | Dilutes a narrow empirical claim by lumping it in with a grand theory that is easy to dismiss. Your careful finding is discredited by the company it is made to keep |
| The “bikini” xxxxx | An attractive or synthetic profile image and naïve, oversimplified questions | Draws the target into a common-sense discussion that pivots steadily back toward the sanctioned narrative |
| The aggressive xxxxx | Overt threats, insults, polarizing language | Destroys decorum and triggers what the study calls a spiral of silence — the ordinary members stop posting |
| The Wikipedia xxxxx (rated the most dangerous) | Reposts genuine, sourced material stripped of its context | Borrows the authority of a real source to carry a reader to a manufactured conclusion. Hardest of all to answer, because every individual fact checks out |
| The attachment xxxxx (also rated dangerous) | Very short text plus an external link to manufactured video or documents | Bypasses text-based moderation entirely; the payload is never on the page being moderated |
NATO Strategic Communications Center of Excellence, Internet Trolling as a Hybrid Warfare Tool: The Case of Latvia (Riga, 25 January 2016), prepared with the Latvian Institute of International Affairs and Rīga Stradiņš University — https://stratcomcoe.org/publications/internet-trolling-as-a-hybrid-warfare-tool-the-case-of-latvia/160. The study concerns pro-Kremlin trolling of Latvian news portals. I use its typology as a vocabulary, not as a finding about any other country or community; the claim that these categories “map perfectly” onto an American research forum is one I have seen made and would not make.
The Wikipedia xxxxx is the one I want to draw out, because it is the category that describes the hardest problem in our field. Real sources, accurately quoted, stripped of the context that gives them their meaning, assembled into a conclusion the sources do not support. Every individual link checks out. The whole is false. There is no rebuttal short of doing the work again from the beginning, which is precisely the cost the technique is designed to impose.
II. Why the Demonstration Works — The Inoculation Evidence
The mechanism I am relying on has a name and a research literature. It is inoculation, and it goes back to William McGuire’s work in the early 1960s: exposing a person to a weakened form of a persuasive attack, together with a refutation, confers resistance to the full-strength attack later — on the analogy of a vaccine.
The modern application to online manipulation is called prebunking, and the crucial development for our purposes is the distinction between issue-based and technique-based inoculation. Issue-based inoculation immunizes against one specific falsehood. Technique-based inoculation immunizes against the manipulative move itself — and therefore transfers to claims the audience has never seen before.
This matters enormously to a researcher bound, as I am, by a forum rule against alleging that named members are agents. You cannot tell your audience who someone is. You can absolutely show them how a move works — and the evidence says that showing them the move is the intervention that generalizes.
TABLE 6 — THE EVIDENCE THAT A DEMONSTRATION CONFERS RESISTANCE
| Finding | What was shown | Where |
|---|---|---|
| Inoculation confers resistance | Pre-exposure to a weakened attack plus a refutation makes people more resistant to the full attack later — the foundational result, replicated for sixty years | McGuire (1964); modern review at Traberg, Roozenbeek & van der Linden, ANNALS of the AAPSS 700(1) (2022) |
| Technique-based inoculation transfers | Teaching people to recognize a manipulation technique improves their discernment on material they have never encountered — unlike fact-by-fact correction, which does not generalize | Roozenbeek, van der Linden et al., Science Advances 8:eabo6254 (2022) — a field study on YouTube |
| It works in a live social-media feed, and it lasts | A 19-second prebunking video on Instagram left treated users 21 percentage points better than controls at identifying manipulation in a headline — and the effect was still measurable five months later | van der Linden, Louison-Lavoy, Blazer, Noble & Roozenbeek, HKS Misinformation Review 7(1) (2026) |
| Correction does not backfire | Twenty-two researchers, including several of the scientists whose earlier work created the worry, concluded: “Recent evidence provides no reason to avoid debunking for fear of a backfire effect.” | The Debunking Handbook 2020, Lewandowsky, Cook, Ecker et al., 22 authors |
| But misinformation persists after correction | The “continued influence effect”: misinformation “often continues to influence people’s thinking even after they receive and accept a correction” — which is precisely the argument for getting there first | The Debunking Handbook 2020, Lewandowsky, Cook, Ecker et al., 22 authors |
One more thing belongs in this section, and it cuts against me. The observation I opened Part I with — that genuine people move and the other kind do not — has an ordinary psychological explanation that has nothing to do with anybody’s employment. Ziva Kunda’s “The Case for Motivated Reasoning”, Psychological Bulletin 108(3):480–498 (1990), is the canonical statement of it: people reason toward conclusions they are motivated to reach, and they do so while sincerely believing themselves to be weighing evidence. A person whose identity is fused to a position will exhibit exactly the intransigence I described, indefinitely, for free. Any diagnostic that cannot separate that person from an assigned operative — and none can — has to be used as a signal about your own time rather than as a finding about his or hers.
| THE HONEST LIMITS OF THIS EVIDENCE
I am not going to oversell it. Effect sizes in this literature are moderate, not transformative — the Instagram field study measured improvement in recognizing a technique, not in changing anyone’s beliefs about a contested historical question, and its authors say so plainly: “technique identification is just one (first) step in the resistance process.” Effects decay. Studies with differential attrition may overstate persistence. And essentially all of this work is on general audiences and consumer-grade misinformation, not on a specialist forum arguing about a 1963 homicide. What the literature does establish, and establishes well, is the proposition my doctrine actually needs: a demonstration aimed at an onlooker measurably improves that onlooker’s later resistance, and correcting the record does not backfire. That is enough. It converts “engage for the audience” from a preference into a practice with evidence behind it. |
Notice what this does to the NATO StratCom recommendation. Their third step is label — publicly name the tactic for the benefit of vulnerable readers — and only their fourth is ignore. On the evidence above, step three is the one doing the work, and it is the one my doctrine keeps. Where I part company is on step four, and only in a specific circumstance: where there is a durable public record and a silent readership whose judgment is in play, the labelled demonstration is worth more than the silence. Where the exchange is ephemeral, unwitnessed, or on ground the adversary controls, StratCom is right and I am wrong.
III. Label the Move, Never the Man
The practical form of technique-based inoculation on a forum is to name the argumentative move being made, accurately, with a citation, and then return to your evidence. Naming a move is fair comment on an argument. Naming a person as an agent is an allegation about a human being that you cannot prove and that your forum rules likely forbid. The distinction is the whole ballgame, and the vocabulary below exists precisely so you can do the first without doing the second.
TABLE 7 — A NAMED VOCABULARY FOR BAD-FAITH MOVES, WITH ITS ACTUAL PROVENANCE
| The move | What it looks like | Where the name comes from | The counter |
|---|---|---|---|
| Sealioning | Relentless, superficially courteous demands for evidence and explanation, indefinitely repeated, calibrated to exhaust rather than to learn | David Malki, Wondermark #1062, “The Terrible Sea Lion” (19 Sept. 2014); analyzed in Amy Johnson, “The Multiple Harms of Sea Lions,” Perspectives on Harmful Speech Online (Berkman Klein Center, 2017) | Answer once, fully, in writing. Then link that answer and stop composing new ones |
| Gish gallop | A rapid volley of many weak assertions, too numerous to answer in the time available, where the volume is the argument | Named by Eugenie C. Scott, “Debates and the Globetrotters,” National Center for Science Education, for the creationist debater Duane Gish | Refuse the volley. Ask which single objection they consider strongest, and answer only that one — on the record |
| Motte-and-bailey | An exciting, weakly defensible claim is advanced; when challenged, the arguer retreats to a modest claim nobody disputes, then re-advances the first once you leave | Nicholas Shackel, “The Vacuity of Postmodernist Methodology,” Metaphilosophy 36(3) (2005) — open access: “a central core of defensible but not terribly interesting or original doctrines surrounded by a region of exciting but only lightly defensible doctrines” | Quote both versions side by side with their timestamps. Ask which one they are asserting |
| Just asking questions | Insinuation delivered in interrogative form, so that nothing is ever asserted and nothing can ever be rebutted | Long-standing rhetorical description; no single scholarly origin — attribute it as a common label, not a finding | Convert it to a proposition: “I take you to be asserting X. Are you?” Then address X, or note that they declined to assert it |
| The procedural objection | A complaint to moderation, a rules citation, or a demand for sanction offered in place of a rebuttal | My own term for a pattern documented in the Education Forum record of 2025–26 | Comply without argument, and preserve the thread state before moderation acts. Compliance is part of the record |
| Brandolini’s asymmetry | Not a move but the structural fact that makes the moves work: refuting nonsense costs an order of magnitude more effort than producing it | Alberto Brandolini (2013), an aphorism rather than a study; the case for correcting anyway is put in Phil Williamson, “Take the time and effort to correct misinformation,” Nature 540, 171 (2016) | This is why you need a reply cap and a stable evidence page. See § IV |
| THE ONE THING YOU MUST NOT DO WITH THIS VOCABULARY
“That is a straw man” is fair comment. “That is a straw man, which is technique four on the JTRIG slide” is an allegation of state sponsorship against a named person, delivered with deniability, and it is worse than saying it outright because it cannot be answered. Name the move. Cite the primary document for the doctrine separately, in general terms, where it belongs. Do not weld the two together over an identifiable human being. |
IV. Sixteen Moves, and the Counter to Each
Table 7 names the classical forms. What follows is narrower and, I think, more useful: the actual sequence I documented on one research forum between October 2025 and March 2026, in the order it arrived, when a particular body of forensic evidence was put on the table.
I set it out for two reasons. The first is that a named move loses much of its power — that is the inoculation finding of § II, applied to the specific case. The second is what the sequence demonstrates when read as a whole. Not one of these sixteen moves is an argument about the evidence. Every one of them is an argument about the poster, the format, the procedure, or the rules. A body of work that draws sixteen consecutive procedural objections and no substantive rebuttal has not been refuted. It has been conceded, and the concession is on the record in sixteen documented steps.
TABLE 8 — SIXTEEN DOCUMENTED MOVES, AND THE COUNTER TO EACH
| # | The move | What it asserts | The counter |
|---|---|---|---|
| 1 | The word-count attack | That the length of a substantive post is itself disqualifying | Answer the volume charge once, with arithmetic, then never again. Length is not a proposition and cannot be rebutted as one |
| 2 | The “AI slop” smear | That a long, well-organized post is presumptively machine-generated and so dismissible | Ask which sentence is wrong. Provenance is not an argument; a citation is either accurate or it is not, whoever typed it |
| 3 | The peer-review red herring | That research not yet peer-reviewed may not be discussed on a research forum | Note that the standard is being applied to one side only, and ask when it was adopted |
| 4 | The copy-paste error attack | That a formatting or transcription slip impeaches the substance | Correct it, thank them, and restate the exhibit. A corrected error strengthens you |
| 5 | Selective epistemology | Memory-fallibility frameworks applied rigorously to your witnesses and not at all to theirs | Apply their own framework to their own witnesses, in public, once |
| 6 | Misdirection | A live but peripheral dispute substituted for the dispositive one | Name the dispositive question in one sentence and repost it unchanged |
| 7 | The anonymous-expert attack | That credentialed evidence cannot be acknowledged until the expert self-identifies publicly | Point out that this makes disclosure the price of being heard, and that the demand is never made of their own sources |
| 8 | Methodology smear by rhetorical question | A cumulative implication — concealed settings, wrong instruments, withheld source files — none of it asserted | Convert each question into the proposition it implies, and answer that. An insinuation that will not become a claim cannot be rebutted, and should be named rather than chased |
| 9 | The strawman maximalist | Your claim restated in its most absurd possible form | Quote your own claim beside their version of it. Let the two sit together |
| 10 | The personal-derogation frame | A witness relitigated through a demeaning characterization rather than through the evidence | Return to what the witness said and what corroborates it |
| 11 | Selective deployment | One recollection of a witness used to destroy another recollection of the same witness | Ask which of the two they accept, and why the same standard does not apply to both |
| 12 | The impossible-completeness demand | That you name every participant in an operation while the state withholds the documents | Name the standard. A demand that cannot be satisfied by anyone is not a standard of proof; it is a bar |
| 13 | The drive-by endorsement | A member who has not engaged the evidence appears solely to endorse an ally’s attack | Record it. Do not answer it. It is not addressed to you |
| 14 | The distribution procedural front | That forwarding public links with commentary is itself misconduct | Cite the rule as written. If the conduct is not prohibited, say so once and continue |
| 15 | The researcher-contact demand | A claimed entitlement to your sources’ direct contact details | Refuse, in writing, and say why. Your sources did not consent to be handed to a stranger, and their willingness to talk to you depends on that |
| 16 | The “spam” procedural front | A request that moderation reclassify substantive research as spam, under a rule that did not exist when the posts were made | Comply with whatever is ordered, preserve the thread state first, and note the retroactivity in the record |
Compiled from my own contemporaneous log of a single forum, October 2025 to March 2026. I name no member and no thread here, and the manual’s rule in Part I § V applies: this is a catalogue of moves, not an allegation about any person’s employment. Several of these have perfectly innocent explanations in isolation. It is the sequence, and the complete absence of substantive engagement across it, that carries the meaning.
| DEMONSTRATIVE EXHIBIT D-4
Sixteen moves, and not one of them about the evidence From the author’s contemporaneous log, October 2025 – March 2026. |
The one that is worth more than the other fifteen
Move 8 — the methodology smear delivered entirely in questions — is the one I would single out for a reader who is going to remember only one thing from this section. It is the most efficient technique on the list because an insinuation that never becomes an assertion cannot be answered, and every hour spent trying to answer it is an hour not spent on the archive.
The counter is mechanical and it works: convert the question into the proposition it implies, state that proposition in your own words, and answer that. If the proposition is one your interlocutor will not adopt when it is written out plainly, the exchange is over and the silent reader has watched it end.
V. The Three-Move Rule
Here is the discipline that makes all of this survivable. It is a hard cap, and its purpose is to make the demonstration cost you a bounded, budgeted amount rather than an unbounded one.
| 1. | Move one — answer on the merits. State the proposition precisely. Link the primary document. Say what it does establish and, just as importantly, what it does not. This is the reply the silent reader will actually read. |
| 2. | Move two — identify the non-response. If the reply did not address the argument or exhibit, say so specifically, quote the part that stands in place of an answer, and restate the unresolved question in one sentence. Ask them for a specific contrary source. Do not re-argue. |
| 3. | Move three — summarize and exit. Write for the reader, not the antagonist. State the argument or exhibit, state that it was provided three times, state what came back instead, and stop. Then leave the thread. |
The only exception is materially new evidence. If your opponent produces a document, a citation, or a fact you did not have, the count resets and you engage it gratefully and in public. That exception is not a loophole; it is the entire reason the practice is honest. A researcher who will not update on new evidence is committing the error he accuses others of.
| “I have asked the same question three times: [exhibit], at [link]. The replies have addressed the length of my posts, my motives, and the forum’s rules. None has addressed the document. I am leaving it here for other readers to weigh, and I will pick it up again if anyone brings evidence bearing on it.”
— A disengagement script. Use it, adapt it, keep it this short. |
That paragraph is not a concession and no reasonable reader will take it as one. It is the demonstration completing itself. The record now contains an unanswered exhibit and three documented non-answers, and it will still contain them in five years.
| DEMONSTRATIVE EXHIBIT D-5
The Three-Move Rule — engagement as a procedure, not a mood |
VI. The Thread Displacement Scale
The Three-Move Rule governs an exchange with one person. This governs the thread. Every level is defined by a dateable event you can point to, not by an inference about anyone’s character — which is what makes it usable and what keeps it out of trouble.
TABLE 9 — THREAD DISPLACEMENT: SEVEN LEVELS, EACH KEYED TO AN OBSERVABLE EVENT
| Level | What has happened | What you do |
|---|---|---|
| 0 | Your exhibit was answered on the merits; disagreement persists | Continue. Nothing here is an operation. This is what a research forum is for |
| 1 | Your exhibit was ignored and the thread drifted | Repost the primary document once, with no commentary. Leave. If your instinct is to start a log at this level, the instinct is the problem |
| 2 | Ridicule, or an appeal to authority, from a single account | Answer once, on the merits, for the reader. Do not answer twice |
| 3 | Two or more accounts in rotation inside a narrow window, with an evident division of labor | Stop engaging. Begin the private log. This is the first level that is worth recording |
| 4 | A procedural motion — moderation complaint, rules citation, demand for sanction — substituted for rebuttal | Log it. Preserve the thread state before moderation acts. Comply without arguing |
| 5 | The thread is locked, the post removed, or the account sanctioned | Republish the document somewhere you control. Log the removal with hashes and timestamps |
| 6 | A characterization of you or your work propagates off the forum | The only level at which a public response is worth its cost. Respond once, in your own venue, to the characterization — never to the person |
| DEMONSTRATIVE EXHIBIT D-6
The Thread Displacement Scale — seven levels, each keyed to a dateable event |
VII. Predicting the Next Move, in Public, With a Falsification Clause
This is the single most effective instrument I have found, and I have never seen it described anywhere else, so I will set it out carefully.
When a pattern of the kind catalogued in Table 8 has established itself, name in advance, in public, what will happen next — and attach to the prediction a condition under which you will withdraw it.
| “I am identifying this pattern in advance so that, when it occurs, the silent readers of this thread, the two hundred-plus researchers and scholars on my distribution list, and the Forum’s administration, may recognize it for what it is… The fact that the prediction will be borne out by the subsequent posts on this thread is itself substantive evidence of the coordinated character of the rotation’s tactics.”
“If, contrary to this prediction, the next several posts… substantively engage the analytical points… then I will gratefully and openly retract this Step 7 prediction.” — from my own post of May 2026 |
Consider what that construction does. It is falsifiable, which is more than can be said for most of what is written in this field, including some of what I have written. It costs the person making it something real: if the next replies engage the evidence, he has publicly lost and must say so. And it converts the ordinary experience of being worked — which is otherwise invisible and sounds like complaint — into a dated, public, testable claim about the future.
It also solves the hardest problem in this whole subject, which is that a pattern is only visible longitudinally and nobody has the patience to look. A prediction collapses the longitudinal into the immediate. The reader does not have to trawl three months of threads; he has to wait a day.
| THREE RULES FOR USING IT
Predict moves, never people. “The next reply will address length rather than the exhibit” is a prediction about the thread. “X will post next” is an accusation about a person, and it is also a much worse prediction. Attach the retraction clause every time, and mean it. The clause is not decoration. It is the thing that makes the prediction evidence rather than rhetoric, and the first time you decline to honor it the instrument is dead. Use it rarely. Once in a thread, at most. A researcher who predicts constantly is not doing forensics; he is performing, and the audience you are writing for can tell the difference. |
VIII. Three Precedents Worth Keeping in Front of You
A closing section for the installment, and the reason I do not accept the counsel of silence even on the days when it is obviously the cheaper course.
Mill, on what silencing assumes
John Stuart Mill’s On Liberty (1859), chapter II, contains the sentence that ought to be pinned above every moderation queue in the world:
| “All silencing of discussion is an assumption of infallibility.”
— J. S. Mill, On Liberty, ch. II |
And a second passage, less quoted and more useful, because it disposes of the comfortable belief that none of this finally matters:
| “But, indeed, the dictum that truth always triumphs over persecution, is one of those pleasant falsehoods which men repeat after one another till they pass into commonplaces, but which all experience refutes. History teems with instances of truth put down by persecution. If not suppressed for ever, it may be thrown back for centuries.”
— J. S. Mill, On Liberty, ch. II |
That is the answer to why bother. Not because truth will out — Mill says flatly that it often does not — but because whether it is thrown back a decade or a century depends on whether anybody kept the record.
Semmelweis, on being rebutted procedurally
Ignaz Semmelweis established in the 1840s that hand-washing between the dissection room and the delivery ward collapsed maternal mortality. His documentation was, in substance, unanswerable. So it was not answered in substance. The Vienna medical establishment rebutted him procedurally instead: his manner was obsessive, his tone was intemperate, his insistence on repeating the same data was inappropriate, and his failure to publish in the accepted form disqualified him from being heard.
Every single one of those is a move in Table 8. Set the sixteen against the Semmelweis file and the overlap is close to complete — the word-count attack, the strawman maximalist, the personal-derogation frame, the impossible-completeness demand. The technique is not new and it is not digital. What is new is that it can now be executed at scale by people who have never read the work they are objecting to.
I keep the case in front of me for a reason that has nothing to do with self-flattery. Semmelweis was, by most accounts, difficult, repetitive, and increasingly intemperate as he was ignored — which is exactly what the establishment said about him, and exactly what the record shows the process does to a person. Being right is not a defense against becoming insufferable, and becoming insufferable is not evidence of being wrong. Both halves of that sentence are worth holding on to.
Galileo, on the flood
The third I offer with a caveat about its sourcing. In a letter of 1635 to the French antiquary Nicolas-Claude Fabri de Peiresc, written after the general prohibition of his works — omnia et edenda, everything published and everything he might yet publish — Galileo is quoted as writing that it was left to him only “to succumb in silence under the flood of attacks, exposures, derision, and insult coming from all sides.”
I have not been able to verify that English wording against a scholarly edition of the correspondence, and I flag that rather than let it stand unmarked. The prohibition of 1633 and the Galileo–Peiresc correspondence of 1635 are both matters of record; the translation is what I cannot presently source. Treat the sentiment as attributed rather than quoted until someone does the work — and if a reader of this manual has the Favaro edition to hand, I would be glad of the citation.
I include it anyway, caveat and all, because the phrase names the thing exactly: to succumb in silence is a decision, it is available every day, and it is what the doctrine in Part I is designed to produce. It is also the one outcome that no amount of evidence can reverse afterwards.
| DEMONSTRATIVE EXHIBIT D-7
Rebutted procedurally instead — three cases, one technique |
IX. The Stable Evidence Page
The single highest-leverage habit in this manual, and the cheapest. Every exhibit you will ever have to produce twice belongs on a permanent page you control, with a stable URL, a date, and the underlying documents.
The reason is Brandolini’s asymmetry. If refuting nonsense costs ten times what producing it costs, then your only structural defense is to pay the cost once. The seventh time you are asked to justify a claim, your reply is a link, not an essay. That converts an unbounded drain into a fixed one, and it is the reason a well-organized researcher can sustain this for decades while an unorganized one burns out in two years.
It has a second function, which is evidentiary. A dated page with the documents on it is a contemporaneous record. Everything I have been able to prove about my own experience — and the whole of Part II of the main series rests on this — I can prove because I wrote it down at the time and kept it somewhere I control.
TABLE 10 — THE STABLE EVIDENCE PAGE: WHAT GOES ON IT, AND WHAT EACH ELEMENT DOES
| Element | What it is | What it does for you |
|---|---|---|
| A stable URL that you control | Your own domain, or a page on a platform you can export from. Not a forum post. Not a social-media thread | A link you can still paste in five years. Every element below is worthless without this one, because a citation to a dead page is worse than no citation |
| A visible date of first publication, and a dated revision note for every change | Not a silent edit. “Revised 12 March 2026 — added the third exhibit; no earlier text altered” | Converts the page into a contemporaneous record. A page that changes without saying so proves nothing about what you believed when |
| The primary documents themselves, hosted, not linked | The scan, the PDF, the transcript — with the archival source and identifier printed beside each | Removes the last excuse. The reader who says he cannot check your claim now has to say instead that he will not |
| The exact quotation, in quotation marks, with the page or timestamp | And where you are paraphrasing, the words in substance outside the quotation marks | The single discipline that separates this from the material it is arguing against. Paraphrase inside quotation marks is the failure mode |
| A stated scope — what the page does not establish | One short paragraph. “This page establishes that the witness said X on date Y. It does not establish that X is true” | The cheapest credibility in the document, and it removes the most common objection before it is raised |
| An archive link for every external source you cite | Wayback or archive.today, captured on the day you cited it, printed beside the live URL | Your citations survive the other side’s link rot — which, in this field, is not always accidental |
| A canonical answer to each question you have answered more than twice | Written once, carefully, at length, and never rewritten in a thread | This is the whole economic point. The seventh time you are asked, your reply is a link, not an essay |
| A plain-text or PDF mirror of the whole page | Regenerated whenever the page changes, and kept off the host | Insurance against the platform, the takedown, and yourself. A page that exists in one place exists conditionally |
None of this is expensive. The whole of it is perhaps a weekend to build and twenty minutes a month to maintain, and it is the difference between a body of work that can be checked and a body of work that has to be believed. Build it before you need it, because the moment you need it is the moment you will not have time to build it.
| A TIME BUDGET, SINCE NOBODY ELSE WILL GIVE YOU ONE
Decide, in advance and in writing, how many hours a week this work gets. Mine is roughly eight, and the discipline is that argument time comes out of the same budget as research time. Every hour spent on a third reply is an hour not spent on the archive. This is the operational content of the counter-argument I quoted at the start. My correspondent was not wrong that the exchanges cost something. He was wrong that the cost buys nothing — the evidence in § II says otherwise. But the cost is real, it is denominated in the only currency you have, and the adversary’s stated objective, in his own doctrine, is attrition. A researcher too exhausted to publish has been defeated without ever being refuted. |
X. The Evidence Base, Annotated
A field manual that cites eleven sources and explains none of them is asking its reader to take the citations on trust, which is the opposite of the discipline this manual recommends. So here is the working table I use, and it has a column that matters more than the other three.
The third column is what each source will not carry. Every one of these has a limit, and a hostile reader will find the limit faster than you will. Knowing it in advance is the difference between a citation that survives being checked and one that becomes the story.
TABLE 11 — THE EVIDENCE BASE, ANNOTATED: WHAT EACH SOURCE WILL AND WILL NOT CARRY
| Source | What it establishes | What it will NOT carry | Why you would cite it |
|---|---|---|---|
| McGuire (1961–64) — the original inoculation experiments | That pre-exposure to a weakened attack, together with a refutation, confers measurable resistance to the full attack later | Anything about the internet, about state actors, or about contested historical questions. It is 1960s persuasion research on cultural truisms | To establish that the mechanism is sixty years old and not an invention of the misinformation industry |
| Roozenbeek & van der Linden, Science Advances 8:eabo6254 (2022) | That technique-based inoculation delivered by short video improves recognition of manipulation on material the viewer has never seen. A field study, on YouTube, at scale | That anyone changed their mind about anything. It measured recognition of a technique, not belief revision | This is the load-bearing citation for the whole doctrine. It is the one that says teaching the move generalizes where correcting the claim does not |
| van der Linden et al., HKS Misinformation Review 7(1) (2026) | A 19-second prebunking video on Instagram left treated users 21 percentage points better at identifying manipulation — and the effect was still measurable five months later | Multi-technique inoculation, or any claim about durability beyond five months. The authors flag differential attrition at follow-up themselves | For durability. The commonest objection to this literature is that the effects wash out in a week; this is the answer to it |
| Traberg, Roozenbeek & van der Linden, ANNALS 700(1) (2022) | The state of the field as of 2022, including the limits, the modest effect sizes, and the open questions | A strong claim of any kind. It is a review, and a properly hedged one | Cite this when you are challenged, not when you are asserting. A reader who checks it will find you have not oversold the literature |
| The Debunking Handbook 2020 — Lewandowsky, Cook, Ecker and nineteen others | A twenty-two-author consensus that “recent evidence provides no reason to avoid debunking for fear of a backfire effect,” and the fact-myth-fallacy-fact structure for a correction | That correction is easy or that it fully undoes the damage. The same document sets out the continued-influence effect, which cuts the other way | The single best answer to the counsel of silence — and it comes from several of the researchers who created the backfire worry in the first place |
| Kunda, Psychological Bulletin 108(3) (1990) | That people reason toward conclusions they are motivated to reach while sincerely believing they are weighing evidence | Nothing about anyone being paid. It is the innocent explanation | Cite it against yourself, in the same breath as the intransigence observation. It is the reason that observation is a signal and not a finding |
| NATO StratCom COE (Riga, 2016) | A five-type field typology, and measured incidence: 1.45% of all comments, 3.72% on targeted articles | Anything about the United States, or about a JFK research forum. It studied pro-Kremlin trolling of Latvian news portals | For the vocabulary, and for the incidence figures — which discipline your own prevalence assumptions and happen to support the arithmetic in Table 1 |
| Malki (2014) and Johnson (2017) — sealioning | The origin of the term, and a scholarly treatment of the harm it does | That any particular person is doing it deliberately | So you can name the move with a citation instead of an epithet. A cited name is fair comment; an epithet is an insult |
| Shackel, Metaphilosophy 36(3) (2005) — motte-and-bailey | A precise philosophical definition of the manoeuvre, in a peer-reviewed journal | Anything about online behavior; Shackel was writing about postmodernist methodology | Because it is the only item in the bad-faith vocabulary with a genuine academic pedigree, and it survives a hostile reader |
| Scott, National Center for Science Education — the Gish gallop | The naming of the technique, by the person who named it, for the debater it was named after | A study. It is an account by a practitioner who spent years on the receiving end | To make clear the term is descriptive and has a history, rather than something you coined to dismiss an opponent |
| Brandolini (2013), with Williamson, Nature 540, 171 (2016) | The asymmetry as an aphorism, and a published argument in Nature that scientists should spend the effort correcting anyway | Any quantification. There is no study behind “an order of magnitude” — do not present it as one | Brandolini names the problem your reply cap and your evidence page exist to solve. Williamson is why you do not simply give up |
| Mill, On Liberty (1859), ch. II | “All silencing of discussion is an assumption of infallibility,” and that truth suppressed “may be thrown back for centuries” | Anything empirical. It is an argument, and it is 166 years old | For the answer to why bother — which is not that truth will out, since Mill says flatly that it often does not |
| HOW TO USE A TABLE LIKE THIS
Read down the third column before you cite anything. If the proposition you want to advance is in that column rather than in the second, you do not have the citation you think you have — and the fastest way to lose a thread is to be shown that by somebody else. Two of these are worth knowing cold, because they are the ones you will need under pressure. The Science Advances study is the reason the technique-level demonstration is worth staging at all. The Debunking Handbook is the answer to the person who tells you that engaging only spreads the falsehood — a twenty-two-author consensus, several of them the very researchers whose earlier work created that worry. And one is worth citing against yourself. Kunda supplies the innocent explanation for the intransigence you are observing. Put it in front of the reader before an opponent does, and the rest of what you say becomes more believable, not less. |
| END OF PART TWO
Part Three covers the record — how to preserve material so that it survives hostile examination, using the standards professionals actually use — together with an honest assessment of the legal remedies, including the ones that do not work, and what to ask of the forums we all depend on. To be continued. |
Keven
J. Keven Hofeling, Esq. • Friday, August 28, 2026 • Salt Lake City, Utah • http://www.jkhofelinglaw.org/
Sources for Part II (Hyperlinked)
| Item | URL (spelled out) |
|---|---|
| McGuire (1961–64) — the original inoculation experiments, and the analogy that gives the whole field its name | https://en.wikipedia.org/wiki/Inoculation_theory |
| Ignaz Semmelweis — the case of a substantively unanswerable finding rebutted on procedure, manner and form instead | https://www.britannica.com/biography/Ignaz-Semmelweis |
| Ziva Kunda, “The Case for Motivated Reasoning,” Psychological Bulletin 108(3):480–498 (1990) — the ordinary explanation for intransigence, and the reason no behavioral screen can separate a true believer from an assigned operative | https://www.craiganderson.org/wp-content/uploads/caa/Classes/~SupplementalReadings/Attribu-Decision-Explanation/90Kunda-motivated-reasoning.pdf |
| John Stuart Mill, On Liberty (1859), chapter II — “All silencing of discussion is an assumption of infallibility,” and the passage on truth thrown back for centuries. Project Gutenberg text | https://www.gutenberg.org/files/34901/34901-h/34901-h.htm |
| Nicolas-Claude Fabri de Peiresc — Galileo’s correspondent of 1635. The English wording quoted in § VIII is attributed, not verified; see the caveat there | https://en.wikipedia.org/wiki/Nicolas-Claude_Fabri_de_Peiresc |
| Sander van der Linden, Louison-Lavoy, Blazer, Noble & Jon Roozenbeek, “Prebunking misinformation techniques in social media feeds: Results from an Instagram field study,” HKS Misinformation Review 7(1) (2026) — the 19-second video, the 21-point effect, and the five-month persistence | https://doi.org/10.37016/mr-2020-193 |
| Roozenbeek, van der Linden, Goldberg, Rathje & Lewandowsky, “Psychological inoculation improves resilience against misinformation on social media,” Science Advances 8 (2022) — the YouTube field study establishing that technique-based inoculation transfers | https://doi.org/10.1126/sciadv.abo6254 |
| Cecilie S. Traberg, Jon Roozenbeek & Sander van der Linden, “Psychological Inoculation against Misinformation: Current Evidence and Future Directions,” ANNALS of the AAPSS 700(1) (2022) — the review, including the limits | https://journals.sagepub.com/doi/full/10.1177/00027162221087936 |
| Stephan Lewandowsky, John Cook, Ullrich Ecker et al. (22 authors), The Debunking Handbook 2020 — “Recent evidence provides no reason to avoid debunking for fear of a backfire effect” | https://digitalcommons.unl.edu/cgi/viewcontent.cgi?article=1247&context=scholcom |
| NATO Strategic Communications Center of Excellence, Internet Trolling as a Hybrid Warfare Tool: The Case of Latvia (25 Jan. 2016) — the five-type typology and the identify / check / label / ignore procedure | https://stratcomcoe.org/publications/internet-trolling-as-a-hybrid-warfare-tool-the-case-of-latvia/160 |
| David Malki, Wondermark #1062, “The Terrible Sea Lion” (19 Sept. 2014) — the origin of the term | https://wondermark.com/1k62/ |
| Amy Johnson, “The Multiple Harms of Sea Lions,” in Perspectives on Harmful Speech Online, Berkman Klein Center for Internet & Society, Harvard University (14 Aug. 2017) | https://cyber.harvard.edu/story/2019-03/sealioning-common-trolling-tactic-social-media-what-it |
| Nicholas Shackel, “The Vacuity of Postmodernist Methodology,” Metaphilosophy 36(3) (2005) — the Motte and Bailey Doctrine, defined at p. 3 | https://onlinelibrary.wiley.com/doi/abs/10.1111/j.1467-9973.2005.00370.x |
| The same paper, open-access copy (Cardiff University ORCA) | https://orca.cardiff.ac.uk/id/eprint/50091/ |
| Eugenie C. Scott, “Debates and the Globetrotters,” National Center for Science Education — the naming of the Gish gallop | https://ncse.ngo/debates-and-globetrotters |
| Phil Williamson, “Take the time and effort to correct misinformation,” Nature 540, 171 (2016) — the published case for correcting anyway | https://www.nature.com/articles/540171a |
| EXPANDED FIELD MANUAL — PART II OF III • NEXT: PART III — THE RECORD, THE REMEDIES, AND THE COMMUNITY |
—










First Installment of the Expanded Field Manual to be Posted in a Day or Two
J. KEVEN HOFELING, ESQ.
JFK ASSASSINATION RESEARCH • DISTRIBUTION LIST WORK PRODUCT
Salt Lake City, Utah · j.keven.jd@jkhofelinglaw.org · https://jkhofelinglaw.org/
A SPECTRE IS HAUNTING THE JFKA RESEARCH COMMUNITY
— A RESPONSE IN THREE PARTS — PART III OF III
The Ultimate Price, and a Field Manual
Gary Webb, the Agency’s Own Account of His Destruction, and How to Recognize What Is Being Done to You
J. KEVEN HOFELING, ESQ. • AUGUST 2026
Part I — The Apparatus and Its Published Doctrine
Part II — My Own Account
Part III — The Ultimate Price, and a Field Manual (this installment)
Each part stands alone; together they answer the whole question. The three installments are being circulated a day apart.
I. Gary Webb: What It Costs When You Make It Accessible to the Masses
II. The Human Toll, Closer to Home
III. A Field Manual for the Bona Fide Researcher
IV. Conclusion — The Spectre, and What to Do About It
Sources for Part III (Hyperlinked)
The Working Library — The Complete Series
Part I set out the apparatus and its published doctrine — Dispatch 1035-960, the Church Committee’s Book III, Sunstein and Vermeule’s “cognitive infiltration,” DARPA’s SMISC, and the GCHQ JTRIG deck — and made the point that the whole enterprise has been outsourced until it is perfectly deniable.
https://educationforum.ipbhost.com/topic/32227-jfk-assassination-researchers-have-you-ever-been-spied-on-wiretapped-or-harassed-by-the-american-government-in-your-years-of-jfk-research/page/2/#findComment-602240
Part II was my own account measured against that doctrine: a recruitment approach at twenty-one, a corroborated CIA reporting relationship on the part of the man who made it, a keylogger and a legend-switching contact in 2016, and a documented destruction of ten years of work in 2025. All of it survivable.
https://educationforum.ipbhost.com/topic/32227-jfk-assassination-researchers-have-you-ever-been-spied-on-wiretapped-or-harassed-by-the-american-government-in-your-years-of-jfk-research/page/2/#findComment-602281
This installment is about the case that was not — and about what to do with what the first two parts have shown.
I. Gary Webb: What It Costs When You Make It Accessible to the Masses
Everything in Parts I and II is survivable. I want to close with the case that is not — because it defines the outer boundary of this subject, and because no researcher should work in this field without having looked at it squarely.
On August 18–20, 1996, the San Jose Mercury News published “Dark Alliance,” a three-part series by Gary Webb (b. August 31, 1955) reporting that a Bay Area drug ring had sold cocaine to Los Angeles street gangs and funnelled millions in profits to the CIA-backed Nicaraguan Contras. Webb was not a freelancer or an outsider. He had shared in the Mercury News staff’s 1990 Pulitzer Prize for General News Reporting. And the series did something no previous account of Contra-cocaine had done: because the Mercury News put the underlying documents on the web, ordinary readers could check the reporting themselves. Webb had made it accessible to the masses. That, I am convinced, is what could not be permitted to stand.
The counterattack came not from the government but from the profession. In early October 1996 the Washington Post ran a front-page piece by Roberto Suro and Walter Pincus holding that the available information did not support the series. In mid-October Tim Golden in the New York Times called the evidence “thin.” On October 20–22 the Los Angeles Times — which had missed the story in its own city — published a three-part rebuttal researched by seventeen reporters. Within two months, the Los Angeles Times alone devoted more words to dismantling the series than the series itself contained. Webb’s own editor, Jerry Ceppos, published a partial retraction on May 11, 1997. Webb was transferred to a suburban bureau, given routine assignments and a long commute, and resigned in late 1997. He never worked at a daily newspaper again.
The Agency’s own account of it
Here is the part that ought to end the argument, and that most people in this field still do not know exists.
The CIA’s internal history of the episode was written by Agency staffer Nicholas Dujmovic under the title “Managing a Nightmare: CIA Public Affairs and the Drug Conspiracy Story.” It was declassified and released in 2014, and it sits today in the CIA’s own reading room at https://www.cia.gov/readingroom/docs/DOC_0001372115.pdf; The Intercept’s reporting on it, by Ryan Devereaux, is at “How the CIA Watched Over the Destruction of Gary Webb” (Sept. 25, 2014).
In it, the Agency concedes that the story posed “a genuine public relations crisis for the Agency,” and then explains how the crisis was managed. Note that the mechanism it credits is not a denial, an operation, or a threat. It is a relationship:
— CIA, “Managing a Nightmare: CIA Public Affairs and the Drug Conspiracy Story”
The document singles out the Washington Post’s “national reputation” as “especially useful,” observing that its critical articles were picked up elsewhere and helped create what the Associated Press called a “firestorm of reaction” against the Mercury News. And it closes with a line that should be carved above the door of every journalism school in the country: “In the world of public relations, as in war, avoiding a rout in the face of hostile multitudes can be considered a success.”
Now put that beside Part I. Read Dispatch 1035-960 from 1967 and “Managing a Nightmare” from 1996 side by side. They are the same document. Thirty years apart, in two different decades of American life, the Agency describes the identical mechanism — “friendly elite contacts (especially politicians and editors)” in one; “a ground base of already productive relations with journalists” in the other — and it describes it, both times, as a public affairs function performed on behalf of the United States. This is the single most important pair of citations in this series.
And then the record shifted under his critics
Between 1997 and 1998, CIA Inspector General Frederick Hitz produced a two-volume investigation. The reports found no evidence that any CIA employee had direct dealings with the traffickers Webb wrote about — the finding that generated the headlines. But Hitz’s testimony also conceded that “there were clearly allegations of … CIA [contacts] being involved with drugs”; that there was “an inconsistency in guidelines given to the field to deal with drug allegations,” and indeed “no directorate of operations instruction about how to deal with drug allegations” throughout the Contra period; and — the detail that matters most — that a 1982 memorandum of understanding between the Attorney General and the Director of Central Intelligence had omitted narcotics from the categories of crime the Agency was obliged to report to the Department of Justice. See the summary of Hitz’s findings and testimony at PBS Frontline.
In other words: the Agency had a standing arrangement relieving it of the duty to report drug trafficking by its non-employee assets, and no instruction to the field on what to do with drug allegations when they arose. Webb’s central charge — that the Agency looked away — was substantially conceded in the Agency’s own inspection record, at the very moment the profession had finished agreeing that he was a fabulist.
December 10, 2004
Gary Webb was found dead in his home in Carmichael, California on December 10, 2004. He was 49. He had two gunshot wounds to the head. Sacramento County Coroner Robert Lyons ruled the death a suicide, and when asked about the second shot said: “It’s unusual in a suicide case to have two shots, but it has been done in the past, and it is in fact a distinct possibility.” A note was found. His ex-wife has said publicly that she believes it was suicide, citing his despair at being unable to get hired at a daily paper; he had sold his house the week before because he could not afford the mortgage.
I am a lawyer, and I will not tell you I know what happened in that room. I will tell you three things I do know, and let each researcher weigh them.
And here is why I set down that 2016 email at the end of Part II, and why I have never been able to read Webb’s file without a particular chill. Eight years after Gary Webb died of two gunshot wounds to the head, a middle-aged lawyer in Utah who had done nothing more dangerous than post statutes to a Facebook group sat down and wrote privately to one friend that if something happened to him, he did not want it to look like a suicide. I did not write that because I had read about Gary Webb. I wrote it because that is what the situation produces in a person’s mind — and the fact that an ordinary researcher’s mind goes there, unprompted, is itself a measure of what has been done to this country.
Gary Webb (1955–2004) — “Dark Alliance,” and the Agency’s account of its management
https://www.cia.gov/readingroom/document/0001372115
https://theintercept.com/2014/09/25/managing-nightmare-cia-media-destruction-gary-webb/
https://www.britannica.com/biography/Gary-Webb · https://spartacus-educational.com/JFKwebbG.htm
https://www.democracynow.org/2014/10/6/inside_the_dark_alliance_gary_webb
Webb is not an anomaly in the literature of this field; he is the most recent, best-documented instance of a pattern this community has catalogd for sixty years. Mr. Simkin has assembled the earlier chapters of it on the Education Forum (Topic 32198) — Bill Hunter, shot dead in a Long Beach police pressroom in April 1964, five months after searching Jack Ruby’s apartment; Jim Koethe, killed in his Dallas apartment in September 1964 while writing a book on the assassination; Dorothy Kilgallen, who interviewed Ruby, told friends she could “break the case wide open,” and was found dead in November 1965. Mr. Simkin is a careful historian and is rightly sceptical of the inflated mysterious-death lists that have circulated in this field. He is right to be. Gary Webb requires no list. His destruction is documented by the institution that carried it out. (Also see Intelligence Service Murdering Americans.)
II. The Human Toll, Closer to Home
I do not want to leave this as a catalog of documents, because the thing itself is not a document. There is an immense human toll — what it does to us as individuals, and what it has done to the country. Consider Doug Horne, who did as much serious work on the medical evidence as anyone alive. On May 20, 2025 he was still at it, submitting written testimony to and giving testimony before the House Task Force on the Declassification of Federal Secrets. Nine months later he was gone. On February 8, 2026 he wrote to a dozen colleagues under the subject line “Now Retired from All JFK Assassination Public (and Private) Activity,” and I reproduce the heart of it because no summary of mine would be as good.
“I have found out, to my dismay, that it is not possible to be ‘mostly’ retired, or only ‘partially’ retired. I simply do not have the time or energy to keep responding to the new ‘findings’ or interpretations or speculations of others.”
“Remaining ‘just a little bit involved’ means constant bombardment with emails and stimuli from others. This, in turn requires huge amounts of time, to decide whether these stimuli are worth responding to, and/or what my response should be.”
“I don’t want to do this anymore. I can’t let this subject eat up the rest of my life. The arguments and new interpretations and (yes, outrageous) new speculations will go on, and on, and on. They will never stop.”
“I value the friendships and partnerships I have had with many in the research community more than you can know. But it is time for me to step away from the never-ending-battle over what to believe, or not to believe… I’m done, spent, and am exiting by choice.”
— Douglas P. Horne, February 8, 2026
Twenty days later, when a distribution of mine reached him, he replied twice in a single afternoon: “Please remove me from all of your JFK email communications. I have retired from all public JFK activity,” and then, a few minutes later, “Stop sending me emails. I am retired from all this now.” I removed him, and I have not written to him since.
I want to be careful about what that letter does and does not establish, because the discipline I am about to recommend in § III forbids me from being careless here.
It does not establish that Doug Horne was driven out by anyone. He does not say that. He alleges no harassment, names no antagonist, and states plainly that he is exiting by choice. Anyone who quotes his letter as proof of a campaign against him is doing the very thing this series argues against (though it should also be noted that Doug has, over the years, wrote of circumstances and individuals suggesting covert ops directed at him).
What it establishes is something I find more useful, and more disturbing. Horne describes, in the first person and without attributing it to anybody, precisely the outcome that the published doctrine names as its objective. The Defence Science and Technology Laboratory’s 2011 report on JTRIG describes the unit’s work in terms of techniques to discredit, disrupt, delay, deny, degrade, and deter. Nowhere in that vocabulary is the word refute.
You do not have to disprove a man’s findings if you can make the cost of maintaining them exceed what he has left to spend. Horne’s letter is a description of that cost being reached — “huge amounts of time, to decide whether these stimuli are worth responding to” — written by one of the most consequential researchers this field has produced.
Whether any part of the bombardment he describes was caused by inauthentic actors, I do not know and cannot show, and I am not going to pretend otherwise. That is the whole reason for the field manual that follows. The identity question is unanswerable. The effect is documented, dated, and in his own words. And the effect is what the doctrine is for.
Then consider how much further the investigations of political assassinations and of other high-level government crimes would have progressed by now had the COINTELPRO programs targeting researchers and activists never existed — which is, of course, precisely the objective of those programs.
In May of this year a JFKA scholar whose name I will not use wrote to me privately, in words I have kept:
“I think you’re wasting your time on the EF … I just don’t think you can fathom the level of close-mindedness and pure folly … I think your posts are just pouring gasoline on a dumpster fire.”
He may well be right about the tactics. He is wrong, I think, about the audience. I am not writing for the xxxxx. I am writing for the reader who has not yet decided, and for the record.
I should also state plainly what I am not able to state here. If it were not against the rules of the Education Forum, I could list many, many experiences I have had on it — patterns of coordinated procedural attack, of administrative complaint deployed in place of evidentiary rebuttal, of the same handful of charactors arriving in rotation whenever a particular body of forensic evidence is put on the table — that I strongly suspect are attributable to the apparatus described in Part I. I abide by those rules and I will not name anyone. But I ask every member reading this to do one thing: the next time a substantive evidentiary post is answered not on the evidence but with a procedural objection, note the date, note the sequence, and keep the record. The pattern is only visible longitudinally, which is precisely why it works.
III. A Field Manual for the Bona Fide Researcher
I promised at the end of Part II that this installment would close with the one diagnostic that has never failed me. I am going to keep that promise, and then I am going to qualify it in a way I would not have thought necessary a month ago, because the qualification is what makes it usable by anybody other than me.
The diagnostic, stated honestly
Here is the thing that took me longest to accept and that I still regard as the most useful single observation I have. Ordinary people — including ordinary people who are badly wrong, stubborn, vain, or hostile — can be moved. Present a genuine person with sustained, documented, probative evidence over a long enough period and something happens. A concession. A narrowing. A change of subject. An exit. Not agreement, necessarily; but movement.
Total intransigence across years, in the face of accumulating evidence, with no concession of any kind ever — that is a different thing, and in my experience it is very rare among people who are simply mistaken.
Now the qualification, which I have put first in the extended edition of this manual and which I want on the record here. This observation identifies a pattern of conduct. It does not identify an employer, and it cannot. A person whose identity has fused with a position produces exactly the same output as an assigned operative, and no amount of watching will separate them. Treat the observation as what it actually is: a signal about how to spend your own time, not a finding about someone else’s.
Take a forum of two thousand people. Assume — far more generously than any documented figure — that two percent are running some form of operation. Give yourself a screen that catches eighty percent of them and wrongly flags only one ordinary member in ten. Run it, and eighty-six percent of the people you accuse will be innocent. At one percent prevalence it is better than ninety percent wrong.
That is not an argument that operators do not exist. Part I of this series documents that they do, in their own words. It is an argument that a practice aimed at identifying individuals will overwhelmingly accuse some of the wrong people — and the Church Committee record tells you what a community full of manufactured mutual suspicion is worth to the people who built the programs. They do not have to infiltrate a forum that has decided to hunt for infiltrators. We would be doing the work for them, for free.
What to do instead: document conduct, and measure effects
Two moves replace agent-hunting, and both are things you can actually do.
Document conduct. Whether an exhibit was addressed is a fact. Whether the same question went unanswered four times across three months is a fact. Whether a rebuttal was replaced by a moderation complaint is a fact. These are checkable by anyone, they cannot be defamatory because they describe the public record, and — this is the part that surprised me — they are more damaging to the person they describe than any accusation would be. The lower claim is the stronger claim.
Measure effects. In March 2011 the Defence Science and Technology Laboratory produced a behavioural-science report for JTRIG whose § 2.11 sets out how the unit proposed to measure whether an online operation was working. Invert that list and you have a diagnostic that requires no accusation at all. You do not need to know who anyone is to notice that a productive researcher has stopped posting, that a thread which used to argue about evidence now argues about procedure, or that a body of work is now discussed exclusively through a characterization of its author. Those effects are the thing the doctrine says the work is for, and they are visible to everybody.
The doctrine: engage, but for the audience, and on a clock
I do not accept the counsel of silence, and I want to say why in terms that do not depend on my temperament.
The mechanism I am relying on has a name and a research literature. It is inoculation, running from William McGuire’s experiments in the early 1960s to the current work on prebunking — and its central modern finding is that inoculating an audience against a technique transfers to material the audience has never seen, in a way that correcting individual falsehoods does not. A field study on Instagram published in January 2026 found that a nineteen-second video left treated users twenty-one percentage points better at spotting manipulation in a headline, and that the effect was still measurable five months later. And the twenty-two authors of The Debunking Handbook 2020— several of whom created the original worry — concluded that “recent evidence provides no reason to avoid debunking for fear of a backfire effect.”
That is why the demonstration is worth staging. Not to move the person in front of you. To inoculate the people reading silently, against the move rather than against the man. And it is why the rule is name the move, never the man: I cannot tell you who anyone is, the forum rules rightly forbid me from trying, and the evidence says the technique-level demonstration is the one that generalizes anyway.
But it has to be done on a clock, because the adversary’s stated objective — in his own doctrine — is attrition, and a researcher too exhausted to publish has been defeated without ever being refuted. So:
The only thing that resets the count is materially new evidence. If your opponent produces a document or a fact you did not have, engage it gratefully and in public. That is not a loophole; it is the whole reason the practice is honest. A researcher who will not update is committing the offense he accuses others of.
TABLE 5 — NAME THE MOVE, NOT THE MAN: A VOCABULARY WITH PROVENANCE
A caution that matters more than the table. “That is a straw man” is fair comment on an argument. “That is a straw man, and it is technique four on the JTRIG slide” is an allegation of state sponsorship against a named person, delivered with deniability — which is worse than saying it outright, because it cannot be answered. Name the move. Cite the doctrine separately, in general terms. Do not weld the two together over an identifiable human being.
The three habits that matter more than any of it
What you have just read is the compressed version. The full Bona Fide Researcher’s Field Manual — Extended Edition runs to three further installments and takes up what there is no room for here: the attribution ladder and what each tier actually requires; the indicator table with the innocent explanation attached to every row; the thread-displacement scale; preservation to the standard of the UN’s Berkeley Protocol and Federal Rules of Evidence 902(13)–(14); the legal remedies assessed honestly, including the several that do not work and the two cases that do the work people wrongly ask Murthy to do; and six things worth asking of any forum that hosts serious research.
I will circulate it over the coming days, in the same three-part form, in its own dedicated thread, and if Robert Morrow explicitly authorizes it, to this thread as well. It is a working document rather than an argument, and I would welcome correction of any part of it.
IV. Conclusion — The Spectre, and What to Do About It
So: has the government spied on me or harassed me?
I cannot prove a wiretap and I will not claim one. What I can say is that at twenty-one I was approached by a man who opened with the philosophy of an organization I had just founded, who volunteered a five-hour biography establishing his CIA bona fides and his victimhood at the Agency’s hands, who offered within hours a paid trip to Washington and an introduction to his lonely young wife, whose business card said family therapist, and who — his childhood friends independently told me years later — was in a regular reporting relationship with the Central Intelligence Agency. I can say that in 2016 my machine was keylogged and I was worked by a Facebook account that switched legends under questioning and volunteered that man’s name. And I can say that thirty-odd years after the pool hall, a decade of research archive and eight communities of five thousand people were erased by three button-presses inside a three-minute window; that I invoked the federal statute written for exactly that abuse, in writing, as a lawyer, with citations; and that nothing whatsoever happened in response.
To Mr. Simkin’s supposition — that perhaps the ruling elite do not think our work important enough to discredit us — I would answer with the Agency’s own two sentences, thirty years apart. In 1967 it instructed its stations to work “friendly elite contacts (especially politicians and editors).” In its internal history of 1996 it credited “a ground base of already productive relations with journalists” with preventing a reporter’s story from becoming an unmitigated disaster for the Agency. It has never at any point regarded this work as unimportant. It has simply found cheaper ways to handle it than kicking in doors — and the cheapest of all is to persuade the people doing the work that no one is watching them.
That is the spectre. Not a man in a raincoat. A settled, comfortable, professionally reinforced conviction, held by serious researchers, that clandestine political operations are a thing that happens in films. Every hour that conviction survives is an hour the apparatus does not have to spend.
So my ask of this community is small and concrete. Keep contemporaneous records — I would have nothing to show you today but a story if I had not written that email in 2016. Read the primary documents linked across these three installments rather than the summaries of them, including mine. Learn the intransigence test and apply it patiently and in public. Assume you are interesting; the assumption costs you nothing and it is very probably correct. And do not let the word “paranoid” do work that evidence should be doing — that usage has a documented origin, and the origin is a 1967 CIA dispatch.
The apparatus has not gone away. It has been outsourced, automated, and made deniable. It no longer needs to break into your house. It needs only to make sure that what you found there is never read by anyone.
Which is, in the end, why I keep writing at this length, and why I am grateful to Robert for asking the question.
A note on method: every external source cited across these three installments was retrieved and checked on August 26, 2026. Where I have relied on my own contemporaneous records, I have said so and dated them. Where I have drawn an inference rather than stated a fact, I have marked it as an inference. Nothing in this series names any member of the Education Forum as an agent of any service, and nothing in it is intended to.
First Installment of the Expanded Field Manual to be Posted in a Day or Two,
Keven
J. Keven Hofeling, Esq. • Wednesday, August 26, 2026 • Salt Lake City, Utah • http://www.jkhofelinglaw.org/
Sources for Part III (Hyperlinked)
• CIA Dispatch 1035-960 (1967) — https://www.history-matters.com/archive/jfk/cia/russholmes/104-10406/104-10406-10110/html/104-10406-10110_0002a.htm · https://archive.org/details/CIADOC1035960
• Church Committee, Final Report, Book III (1976) — https://www.intelligence.senate.gov/sites/default/files/94755_III.pdf
• Carl Bernstein, “The CIA and the Media” (1977) — https://goodtimesweb.org/industry-govt-agents/rs-bernstein-cia-media-oct-20-1977.html
• Project MK-ULTRA, Joint Senate Hearing (Aug. 3, 1977) — https://www.intelligence.senate.gov/wp-content/uploads/2024/08/sites-default-files-hearings-95mkultra.pdf
• Sunstein & Vermeule, “Conspiracy Theories” (2008) — https://chicagounbound.uchicago.edu/cgi/viewcontent.cgi?article=1118&context=law_and_economics · https://chicagounbound.uchicago.edu/law_and_economics/119/
• DARPA, Social Media in Strategic Communication (2011) — https://www.darpa.mil/research/programs/social-media-in-strategic-communication
• Greenwald, “How Covert Agents Infiltrate the Internet …” (2014) — https://theintercept.com/2014/02/24/jtrig-manipulation/
• GCHQ/JTRIG, “The Art of Deception” — https://theintercept.com/document/art-deception-training-new-generation-online-covert-operations/ · https://www.aclu.org/documents/art-deception-training-online-covert-operations · https://www.documentcloud.org/documents/1021430-the-art-of-deception-training-for-a-new/
• “Online Government Trolls Have Infiltrated the Internet” (video) — https://rumble.com/v6ztjoy-online-government-trolls-have-infiltrated-the-internet.html
• Priest & Arkin, “Top Secret America” — https://secure.afa.org/edOp/2010/Washington_Post_Intelligence_Series.pdf
• CIA, “Managing a Nightmare” (Dujmovic) — https://www.cia.gov/readingroom/docs/DOC_0001372115.pdf
• Devereaux, “How the CIA Watched Over the Destruction of Gary Webb” — https://theintercept.com/2014/09/25/managing-nightmare-cia-media-destruction-gary-webb/
• CIA IG Hitz — findings and testimony — https://www.pbs.org/wgbh/pages/frontline/shows/drugs/special/hitz.html
• Gary Webb — biography — https://www.britannica.com/biography/Gary-Webb · https://spartacus-educational.com/JFKwebbG.htm
• 1990 Pulitzer Prize, General News Reporting — https://www.pulitzer.org/winners/staff-26
• Murthy v. Missouri, 603 U.S. 43 (2024) — https://supreme.justia.com/cases/federal/us/603/23-411/
• 17 U.S.C. §512 — https://www.law.cornell.edu/uscode/text/17/512
• Gary Mack — biography — https://spartacus-educational.com/JFKmack.htm
• Business Plot / Paul Comly French — https://en.wikipedia.org/wiki/Business_Plot · https://en.wikipedia.org/wiki/Paul_Comly_French
• Glaspie–Hussein transcript (July 25, 1990) — https://www.rapeutation.com/transcr.meeting.htm
• Rep. Howard C. Nielson (R-Utah) — https://en.wikipedia.org/wiki/Howard_C._Nielson
• Morrow thread (EF Topic 32227) — https://educationforum.ipbhost.com/topic/32227-jfk-assassination-researchers-have-you-ever-been-spied-on-wiretapped-or-harassed-by-the-american-government-in-your-years-of-jfk-research/
• Simkin on the deaths of journalists (EF Topic 32198) — https://educationforum.ipbhost.com/topic/32198-the-jfk-assassination-and-the-link-with-other-political-conspiracies-1963-2026/page/3/#findComment-601651
• Sweeney, “Twenty-Five Rules of Disinformation” (archived) — https://blog.cyberwar.nl/2019/06/twenty-five-ways-to-suppress-truth-the-rules-of-disinformation-h-michael-sweeney-1997-2001/
—
Edited by Keven Hofeling