36 APPROACHING ZERO mailbox, saying, I DO SO ENJOY PUZZLES AND GAMES. TA. TA. PIP! PIP! HRH ROYAL HACKER. Then they modified the foreign-exchange page on Prestel, provided by the Financial Times, so that for a few hours on the second of November the pound-to-dollar exchange rate was a glorious fifty dollars to the pound. Triludan himself capped all the tricks: when subscribers dial into Prestel, they immediately see page one, which indexes all other services. Only the system manager can alter or update listings on this page, but Triludan, exploiting his sysman status, made a modest change and altered the word Index to read Idnex. Though it was perfectly harmless, the change was enough to signal to Prestel that its security had been breached. The other pranks had been worrisome, but altering the first page was tantamount to telling Prestel that its entire system was insecure. The company reacted quickly. It notified all its customers to change their passwords immediately, and then altered the sysman codes, thus stopping Triludan and his friends from tampering with the system again. Six months later Triludan was arrested. Though he had lost sysman status, he had continued hacking the system, using other four-digit combinations. He even continued to leave messages for the system manager, just to prove that he could still gain access, and his games had badly embarrassed Prestel and its owner, British Telecom. The revelation that hackers had penetrated the Prestel system and broken into Prince Philip's mailbox had proved irresistible to the British press, which had cheerfully hyped the story into page-one news. The royal connection ensured that the item got international coverage, most of it implying that hackers had breached royal security systems and read Prince Philip's private and confidential electronic mail.2 To catch their hacker, Prestel put monitors on the incoming lines. These filtered all calls to the system, looking for unusual activity such as users trying different passwords or repeatedly failing to key in correct IDs. After watching the lines for a month, tht~ nhorities were convinced that they had two intruders, not one. The first was calling from London; the second appeared to be dialing in from Sheffield. British Telecom traced the two callers and put supplementary monitors on their home lines. Despite the fact that the company had evidence from the messages to the system manager that Triludan was still breaking into the system, they needed hard evidence, so they continued monitoring the lines in London and Sheffield, carefully noting the times the two callers dialed into Prestel. Finally they decided to mount simultaneous raids. On April 10, 1985, a posse of three British Telecom investigators and four policemen raided the north London address. Just after ten P.M. the police knocked on the door, which was opened by a young man who was six feet four inches tall with thick black hair. His name was Robert Schifreen, and yes, he was Triludan the Warrior--as well as Hex and Hexmaniac, two other hacker aliases that had appeared on Prestel. He was arrested and his equipment confiscated. The police were civil and polite, and they allowed the suspect to bring his bottle of antihistamine tablets with him. Its brand name was Triludan. Schifreen was taken to Holborn police station to spend the night in the cells. He was charged and released on bail the next day. At the same time Schifreen was arrested, another raid was taking place in Sheffield at the home of Schifreen's friend and companion, Steve Gold. Gold had also continued to hack Prestel. Along with Schifreen, he had been the most excited by the chance to play with the system. Gold remembers the knock on his door as coming at eight minutes past ten P.M. When he answered, he found three policemen and three British Telecom investigators, who read him his rights and promptly took him down to the local police station, where he spent an uncomfortable night. At nine the next morning he was driven down to London to be charged. Because there were no laws in Britain addressing computer hacking at the time, the two were charged with forgery--specifically, forging passwords. Five specimen charges were listed in the 38 APPROACHINC ZERO warrant for Schifreen, four for Gold. The charges involved a total loss of about $20 to the Prestel users whose IDs had been hacked. What became known as the Gold and Schifreen case was Britain's first attempt to prosecute for computer hacking. The case was tried before a jury some twelve months later. At the beginning of the trial the judge told counsel: "This isn't murder, but it's a very important case. It will set a very important precedent." After nine days the two were found guilty. Schifreen was fined about $1,500, Gold about $1,200; they had to pay the court almost $2,000 each for costs. The duo appealed the verdict, and after another twelve months the case was heard in Britain's highest court of appeal by the Lord Chief Justice, Lord Lane, who ruled that copying an electronic password was not covered by the Forgery Act, and overturned the jury's verdict. The prosecution appealed that decision, and after another twelve-month delay, the House of Lords--which carries out many of the functions of America's Supreme Court--upheld Lord Lane's decision. Gold and Schifreen were acquitted. Since then, Gold and Schifreen have both gone on to respectable careers in computer journalism. And from time to time they still meet in Chinese restaurants, though neither continues to hack. But their case, which cost the British taxpayers about $3.5 million, gave a misleading signal to the country's hackers and phreakers. Because Gold and Schifreen had admitted hacking while denying forgery, it was assumed that the courts had decided that hacking itself was not against the law. That's certainly what Nick Whiteley believed. Briefly, in 1990, Nick Whiteley was the most famous hacker in Britain. A quiet, unremarkable young man with a pedestrian job at a chemical supplies company, by night he became the Mad Hacker and roamed through computer systems nationwide. To the alarm of the authorities, he was believed to have broken into computers at the Ministry of Defense and MI5, Britain's counterintelligence security service. More troublesome still, there were messages sent by the Mad Hacker that strongly suggested he had evidence that some type of "surveillance" had been carried out against the opposition Labor party, the Campaign for Nuclear Disarmament (CND), and even the British Cabinet. It was unclear who was supposed to be carrying out the surveillance, but it was presumed to be MI5. When Nick was arrested in 1988, he was interviewed for up to six hours by agents he believes were from the Ministry of Defense and MI5. They were accompanied by an expert from International Computers Limited (ICL), at the time Britain's only independent mainframe computer manufacturer (the company is now controlled by Fujitsu of Japan). Nick was passionate in his admiration for ICL computers; he never hacked anything else, and both the MoD and MI5 use them. Whiteley's ambition was to buy his own ICL: he especially coveted the 3980, their top-of-the-line mainframe. In his daytime job, he worked on an ICL 2966, a smaller model, but still a formidable mainframe. Whenever Nick felt his fellow workers were making fun of him--which he believed they did because he was only an operator, rather than a real programmer--he would fantasize about the 3980. It was twenty times faster than the 2966 and could support far more individual users. But he had to admit that on his salary it would take a long time to earn the down payment on the almost $2 million purchase price. Nick had originally wanted to be a computer programmer or to work in technical support. But without a university degree his chances of becoming a programmer were limited: he would need to go back to college to get the qualifications. So instead he became an operator, or "tape monkey," employed to ensure that there was enough computer tape in the drive and enough paper in the printer to keep the machinery running. Though he had been offered a promotion to senior operator, he had turned it down against a vague promise of a job in technical support sometime in the future. 40 APPROACHING ZERO Then nineteen years old, Nick lived with his parents in their home in Enfield in north London. He was affable, intelligent, and articulate, was generally casually dressed--sweatshirt, jeans, sneakers--and had nicotine-stained fingers. Nick's life became consumed by his passion for the ICL. He was fascinated by its operating system and by the language--called SCL (System Control Language used to write its programs. Of course he had to admit that his ambition to buy an ICL 3980 was pretty unrealistic. Even if he had enough money to buy one, he would certainly have no use for a computer that was designed for large businesses. But then he would begin to worry about what would happen if he lost his job or had to leave the company. Where would he go to work on an ICL then? In his bedroom in his parents' house Nick had a personal computer, a Commodore Amiga 1000, equipped with a modem. He had intended to use the modem to dial in to electronic bulletin boards--specialist data and information services, like Prestel but generally run by private individuals. It was never his intention to start hacking, he says; he thought it would be boring. Nonetheless, he started reading a guide called The Hacker's Handbook. The Handbook had been written by a British hacker known as "Hugo Cornwall" and achieved instant notoriety when it was first published in March 1985. Guided by the Handbook, he began dialing into more bulletin boards. (He found that about 20 percent of them had hacker sections.) With the information he obtained from the Handbook and the bulletin boards he learned how to find the access phone numbers for other computers, and how to deal with IDs and passwords. The Handbook was especially useful: it contained a list of phone numbers that gave access to JANET. JANET is the earnestly friendly acronym for the Joint Academic Network, a system that links computers in eighty to ninety universities, polytechnics, and research centers throughout the United Kingdom. Because it is designed to be used by students and researchers. the network needs to be relatively open, and tries to present a friendly face to users: hence the feminine acronym and the useful tutorial and guide provided by the system when a user types HELP- The network's various data banks also contain a wealth of inforrnation on subjects as dissimilar as military research and theoretical physics. For Nick, however, the chief appeal of JANET was that it linked a number of ICLs on different sites around the country. By accessing JANET he could play around on his favorite computers from his home, just by using his little Commodore. Nick attempted his first hack in January 1988. He first dialed up a number for the computer center at Queen Mary College, where he knew there was an ICL 2988. Because Queen Mary is not far from Nick's home, the telephone charges would be lower; also, most colleges are easy targets because they generally have weak security. He got the dial-up from The Hacker's Handbook--but that, as he knew, would only get him to the front door. Access to the QMC computer would be like gaining entry to the Prestel system. To get inside, Nick would need both a user-name--a log-in or ID--and a password. The user-name at QMC is an individual seven-character ID; the password is a one-way encrypted code. (One way means the code can only be encrypted once and is entirely random; if the user forgets the password, a new one needs to be created.) That was the theory, anyway. But Nick knew that some software supplied by ICL includes a standard, or default, "low-security" user-name, one that doesn't require a password. Nick had barned the default user-name from his job and his constant reading of ICL promotional material, manuals, and security informa- tion. And because Queen Mary College had never changed its ~ default user-name, it had left its back door wide open, making it k easy for Nick to walk right in to the college's mainframe ICL on his first try. The sole drawback from Nick's point of view was that the low-security user-name gave him only restricted access to the computer. The QMC computer had a strict hierarchy of user 42 APPROACHING ZERO status, and the environment of low-security users--the areas on the computer they could enter--was severely limited. Most ordinary users had higher status, though their environment was usually restricted by the nature of their tasks. At the apex of the hierarchy, as with Prestel, was the systems manager, who had access to everything. At QMC the sysman is in complete control of the computer, assigning status to other users, overseeing the functioning of the system, and managing the programs and data. Nick's objective was to capture sysman status. Without it his options were too limited, his environment too restricted. He began searching through the files, using his knowledge of the minutiae of ICL operating systems to find his way through the electronic pathways of the QMC computer. He ran into walls or traps designed to keep him out of restricted areas, but he kept trying. Nick's hobby, his only one, was collecting unlisted commands for ICL computers. These are keyboard operations that the company doesn't document, which can be discovered by experimentation. Sometimes these got him around the traps and farther into the system. Slowly he moved through the back alleys of the QMC systems until finally he was able to access the operator libraries, the collection of programs that manage the computer. He knew that the keys to raising his status lay among the programs. He had been hacking for hours by then, but he didn't notice the time or his own tiredness. He played with commands, his little PC sending signals from his bedroom in Enfield through the telephone lines to the mainframe at QMC. He went through the programs sys- tematically, coaxing the ICL, trying to outsmart the security systems that had been put in place precisely to stop someone like him. Eventually the machine yielded. On his first hack Nick had managed to capture system-manager status. He decided not to play with the QMC computer too much--the capture of sysman status was too valuable to lose by leaving obvious evidence; also, he needed QMC as a jumping-off point for other computers on JANET. He roamed about the QMC computer for a bit, looking at electronic mailboxes and assessing different files. Then he used his sysman status to create four new user-names, OLAD011, OLAD024, OLAD028, and OLAD059, which would allow him continual entry to the QMC machine. He assigned the four user-names to Alan Dolby. The best part of the JANET network, from Nick's point of view, was that it was a freeway: entry into one point on the system gave a direct route to other points. That meant that he could dial into QMC and then link into other ICLs at other sites. Conveniently, the ever-friendly network listed the sites on the system by computer manufacturer, so he knew just where to go to find more ICLs. One of Nick's targets was an ICL at Glasgow University in Scotland. Eventually he linked into Glasgow by logging in as a guest user. He used the same technique to break into the ICL at Hull University and others in Nottingham, Belfast, and Bath. Nick saw hacking as simply a means to play on ICLs. He wasn't interested in stealing information from the network, and in fact, he had no real purpose at all. He was hooked on ICLs and wanted only to be able to work on them, to play around on the operating system, to explore the complexities of the network. He told his parents there wasn't anything illegal in what he was doing, and technically he was correct: at the time there were no laws in the U.K. that specifically addressed hacking, and the Gold-Schifreen case had seemed to make the practice beyond the law. Once Nick had started hacking the Whiteley family phone bills soared from around $100 a quarter to over $1,600. But Nick always paid his share. He could afford to do so because he had no other social life: no expensive habits, no girlfriends. He went to work came home, and started hacking. He hackea at night because it fit into his schedule, and also because the phone rates were cheaper, there was less line noise, and the target computers would be unmanned. The trick was, he said later, to stay awake; sometimes he hacked all through the night and then had to go to 44 APPROACHINC ZERO work the next morning. His "day" could stretch to twenty-eight hours: first eight hours at work, then a night spent hacking, then another eight hours at work trying to stay awake while keeping the printer stuffed with paper and the tape running in the drive. After a marathon stretch like that he would take the next night off and go to bed early. "It was obsessive," Nick later explained. "Five or six hours can seem like five minutes." He drank coffee and Coke and ingested caffeine tablets to keep going. "When you get into a system, you must keep going. It might take four or five hours to penetrate the defenses and another four or five hours to protect the position that has been established. If protection isn't put into place, then the earlier work could be wasted." The challenge was in beating the system; success came from staying awake. It gave him a feeling of power: he enjoyed knowing that while the designated sysman thought he controlled the computer, in fact it was himself, Nick, who had manipulated system-manager status and was really in control. Nick compared hacking to a game of chess, a battle of wits between himself and the system, nothing criminal, just a game: The excitement comes from knowing that a computer in the bedroom at home can be used to break into multimillion-dollar installations. There's the thrill of exploration, of going around the world electronically. The objective is to try to gain the highest status within the system, that of system manager, and once there, to begin making the rules instead of following them. If the system manager blocks one way in, then you find another. It becomes a game with the systems manager; the hacker's goal is simply to try to persuade the computer that he should have increased privile~es. One person who didn't see it as a game was Bob Jones, the chief programmer at Queen Mary College. A tall, well-built man with beard and ~lasses and an academic uniform that sometimes runs to jeans and T-shirts, he had been at the college since 1968, first as a physics student, then staying on to work full-time at the QMC computer center after earning his degree in 1971. He worked out of a large office on the top floor of the computer science block, a nondescript concrete shell of a building in east London. His office was near the computer center, a cramped room packed with mainframes, some of them ICLs. In the room's center were eight consoles set up on adjoining desks, which al- lowed the activities of the mainframes to be monitored but were usually unmanned, particularly at night. Jones first realized that the QMC system had been breached by 1 a hacker on February 19, 1988. He had heard reports from colL bagues at the Universities of Glasgow and Hull that their own systems had been hacked by someone calling himself Alan Dolby. What he saw on his computer was a series of files that had been incorrectly stored in the memory, one of which had been labeled AD. He began searching for signs of further tampering, and he soon found it: the four OLAD user files Nick had created to give himself a smooth path into the QMC computer. The files appeared to have been created a month previously. Jones immediately reported the intrusion to his superior, Jeremy Brandon, the director of the computer center, although it was clear that their options were limited. They could attempt to lock their hacker out by closing all of the OLAD files, but that might force the hacker to try more devious back-door methods to regain access. If he entered the system through such a method, they might not be able to find him again--and he might do some real damage. Instead, they decided to leave the files as they were and watch him, although they did remove the Mad Hacker's sysman status. When Jones came into the office on the morning of March 30th, he found that there had been no work processed on the computer since about two A.M., when the scheduler (the program listing the priority of jobs) had failed. Its failure coincided with a successful hack of the system made by OLAD028. Jones and Brandon decided to record future intrusions on a 46 APPROACHING ZERO dedicated journal within the computer. They also decided to wipe out three of the user-names, leaving only OLAD028, the one the hacker had consistently employed. It would be easier to track him this way. By this time the hacking incidents had been reported to QMC's head of security, who passed on the information to Scotland Yard's Computer Crime Unit. Although established in 1971, the CCU had until 1985 consisted of only one officer. Then, as computer crime escalated and the government became concerned about the vulnerability of its own systems, it was eventually enlarged to four officers-- still not a big force, given that Scotland Yard can be called in on cases anywhere in Great Britain. The unit is headed by John Austen, who was the officer assigned to investigate the Mad Hacker affair. Austen knew that the only way to catch the hacker was to monitor the lines, the same time-consuming process used to track down Triludan the Warrior. That meant involving British Telecom, which needed to assign an engineer to trace calls. And because the Mad Hacker worked at night, that would involve overtime. For the first few days the investigation was bogged down over the overtime question: neither British Telecom nor QMC nor Scotland Yard were willing to pay. Eventually the phone company gave in and set up a twenty-four-hour trace, to be activated whenever the hacker was detected on the QMC system. As the Mad Hacker gained confidence and experience, his activities took on a new twist. To Bob Jones it seemed malicious, as if the hacker had declared war on the system. One night the Mad Hacker ordered the QMC computer to print, I THINK YOU SHOULD KNOW I AM MAD . . . I AM ALSO DEPRESSED, over and over. To Hull University he sent a message saying, I AM TAKING UP THE CHALLENGE, then loaded a "rabbit" onto the system. A rabbit is a piece of software that orders a computer to perform useless tasks endlessly, multiplying ever more work orders until they finally overwhelm the computer and it can cope with nothing else. The Hull computer was down for ten hours after this particular rabbit began breeding. THAT WILL FILL UP YOUR SODDING SYSTEM, another message said. He then dropped a rabbit into the Glasgow computer. But this time, it didn't work. As he was on-line, the computer operator discovered him and sent him a message demanding that he call the operations department. ALAN DOLBY DOESN T MAKE CALLS, he wrote back. Glasgow was where Dolby had first been rumbled, three months previously, when a file he had created as a back door had been discovered. It was Glasgow that had alerted the rest of the system operators on JANET that there was a hacker. So there may have been an element of revenge when, one night, the Glasgow system manager, Dr. Roger MacKenzie, tried to access the mainframe from his home PC and found that he had been "locked out"--barred from his own computer. It was later discovered that the Mad Hacker had captured sysman status that night and instructed the mainframe to kick out MacKenzie. At QMC an increasingly irritated Bob Jones was watching as intrusion after intrusion was recorded in the computer journal. At first these were just messages left for the sysman, schoolboyish nonsense such as WILL ET PLEASE PHONE HOME and WILL NORMAN BATES PLEASE REPORT TO THE SHOWER ROOM. But then things became more serious: the Mad Hacker instructed the QMC computer to generate copies of reports from its memory, which prevented it from processing necessary work, and on more than one occasion his intrusions caused the computer to crash. It seemed as if the Mad Hacker had become vindictive and malicious. Once, he left a message asking, WHY DON'T YOU LOCK ME OUT? It was obvious to Jones that his hacker wanted to play, but he ignored the messages. Monitoring the lines was slowly getting results. When the Mad Hacker was spotted making an unusual daytime appearance, Bob Jones called the twenty-four-hour emergency number at British 48 APPROACHING Z~RO Telecom--which rang and rang. In frustration he gave the receiver to someone else to hold while he called a contact at British Telecom direct. "There's no one answering my emergency call," he shouted. "Well, yes," the Telecom man said patiently. "The service doesn't start until five P.M." As they spoke, an assistant passed him a note saying that the hacker had left the system. Jones, still steamin~, explained the precise meaning of "twenty-four-hour service. The monitoring intensified. In early July the engineers at tne telephone office nearest QMC finally traced the hacker back to a telephone in Enfield. Another monitor was placed on the suspect number to record all future activity. On July 5th Jones came in to work to find that the computer journal recording the Mad Hacker's intrusions had been wiped out. That could only have happened if the hacker had captured sysman status again. He also found this message: THIS INSTALLATION HAS BEEN HACKED BY ALAN DOLBY. ALAN DOLBY IS A REGISTERED MEMBER OF HACKING INC. (ICL DIVISION), WHICH IS A SUBSIDIARY OF HACKING INTERNATIONAL. THIS HACK IS ~) 1988 BY ALAN DOLBY (THE MAD HACKER). The announcement was followed by a message for Marlyn, a computer operator previously employed by QMC and mistakenly believed bY the Mad Hacker to be the sysman: NOW MARLYN IS PROBABLY THINKING, !~£?$ (SH*T) HOW THE HELL DID HE GET IN THIS TIME? . . . I BETTER HAVE A LOOK AT WHERE I KEEP HIS JOURNALS. OH SHIT, SHE SAYS, THEY ARE NOT THERE ANYMORE. !~£?$ NOW, MARLYN, IT'S GETTING PRETTY BORING HAVING TO KEEP ON TEACHING YOU MANNERS. I'D RATHER BE AT MY OTHER SYSMAN HACK SITES. SO I HOPE YOU HAVE LEARNED (EXCEPT HOW I DID IT) FROM THIS, MARLYN, AND REPLY TO MY MESSAGES; OTHERWISE YOU WILL MAKE ME VERY VERY ANGRY, AND ROGER WILL TELL YOU ONE THING, YOU WON'T LIKE IT WHEN l'M ANGRY. The reference was to the Mad Hacker's successful lockout of Roger MacKenzie from his own system. The message continued: STILL, DON T GET TOO DESPONDENT MARLYN, I MEAN WHAT DID YOU EXPECT? IF I CAN HACK ROGER S PLACE TWICE, THEN ANYTHING ELSE IS JUST A PIECE OF CAKE, AND I MEAN YOU'RE NO GURU, MARLYN. ROGER IS THE GURU, HE WRITES PROGRAMS, HE DOESN T PHONE UP SAYING, OH, ROGER, HELP ME, ROGER. HAVE I WOUND YOU UP ENOUGH, MARLYN? YOU WON'T BELIEVE HOW I GOT IN, MARLYN HAHAHAHAHAHAHAHAHAHAHHAAAA YOURS HACKINGLY, ALAN DOLBY . . . THE MAD HACKER!!! THE MAD HACKER THE MAD HACKER ALAN DOLBY ALAN DOLBY . . . Though the Mad Hacker had destroyed the journal when he hacked in to QMC that night, he didn't destroy the evidence. Like most computer users, QMC keeps backup copies of files, so the record of the Mad Hacker's intrusions still existed. But it was becoming evident that eventually real damage to the system could be caused if the hacking continued. It had already become very frustrating to Jones, who was spending more and more time cleaning up after the Mad Hacker and less time doing his real work. But even worse, Scotland Yard had become concerned about hints that were contained in some of his computer messages ~,~ that Alan Dolby was hacking into the Ministry of Defense com~4 puter, also an ICL. The break-ins might still be a game to the Mad Hacker, but it was becoming deadly serious to everyone else. 50 APPROACHINC ZERO They decided to go for a bust that very evening. An arrest for computer hacking is not a straightforward affair. To make the charge stick, the police would have to arrest the Mad Hacker while he was actually in the middle of a hack, with the unauthorized dial-up on his computer screen and his fingers on the keyboard. Evidence that the hacking had been committed from his phone number was not sufficient: it could, after all, have been done by his mother. The team assembled for the bust was enormous. There were four policemen from the Computer Crime Unit, two technicalsupport specialists, two experts from ICL, a police photographer, two British Telecom engineers, and a phalanx of uniformed policemen. In addition Jones had to monitor the QMC computer to alert the team when the Mad Hacker broke in. He was joined in his vigil by the managers at other ICL sites on the JANET network, as well as by internal British Telecom staff to monitor the phone lines. In total the team numbered forty people. As luck would have it, however, on that evening nothing happened; the Mad Hacker simply went to bed early. But the next night, he decided to dial in to QMC once more to see if anyone had replied to his message. According to the computer record, he logged on at 7:48 P.M. Just a few minutes before 8:00 P.M. the Whiteley family heard a knock on the door. The police later described it as a gentle tap; to Nick, upstairs in his bedroom, it sounded like loud banging. He thought it odd: why didn't they use the doorbell? Then he walked to his window and saw four men approaching the door. He said later that he could tell from their appearance that they weren't Jehovah's Witnesses, and for one awful second he thought they might be Mafia. Downstairs Nick's father was at the door bewilderedly reading a warrant presented to him by the policemen. Nick sat down on his bed. He thought that perhaps they were after a spy or a murderer. They couldn't be after him: he was nineteen years old and liked to play games with computers, that was all. The police moved upstairs to arrest Nick. By this time, there were twelve members of the team in the tiny house, communicating by portable phone to their colleagues outside. John Austen from the CCU told Nick he was being arrested for "criminal damage." Nick looked at him incredulously, then burst out laughing. He thought it must be a mistake. Though hacking wasn't illegal at that time, the case against Whiteley had been put together around the concept of criminal damage, which boiled down to loss of data and denial of computer service as a result of his hacks. QMC alone had valued the downtime to fix its computers at $48,000. Police photographers moved in to record the computer screen, keyboard, and modem. Every inch of the room was photographed: Nick's files, the books on his bookshelf, the posters on the wall. The police stayed until midnight: they confiscated Nick's Commodore and all the other equipment, loading the evidence into bags; they removed from Nick's room books, blank paper, empty folders, even the posters; and they interviewed Nick's older brother, Christopher. Nick's mother, who was out when the raid began, came home to find the team searching Nick's car. Nick was still stunned: he was convinced it was all a mistake and that soon the police would apologize and go away. He presumed that he had never been locked out of the QMC mainframe because the systems manager wanted him to test the security, that , he was playing the game too. Nick was the stereotypical hacker: a kid who wanted to play a big-time computer game to demon8trate how clever he was. He didn't want to damage anything, although he did enjoy playing a few malicious pranks from time to time. When he was busted, Nick had only been hacking for six months. Two days after the raid, he was taken to Bow Street magistrate's court and charged with having caused a total of $115,000 damage to computer hardware and disks. But what concerned the authorities the most were the suggestions that Nick had been hacking into MoD and MI5; in his room they found a little red 52 APPROACHING ZERO notebook with dial-ups for ICLs operated by government agencies. They also wanted to know about the messages that had been left by Nick on the QMC computer alleging that he had knowledge of "surveillance" of the Labor party, CND (the Campaign for Nuclear Disarmament) and the Cabinet. Nick told the police, and later two agents he presumed to be from the MoD and MI5, that he had never used the numbers in his book; they were for future reference. As for the messages about surveillance, they were fantasy, part of the games he was playing with the sysman at QMC.3 The police were unimpressed. Nick was released on bail, but only after promising not to continue hacking. In May 1990, almost two years after the incidents took place, he was tried for criminal damage at London's Southwark crown court. The defense accepted the prosecution's charges, but argued that there had been no real criminal damage. Nick's lawyers were confident of getting him off, but it's said that he made a bad impression as a witness in his own defense: he was too sure of himself, too clever. Bob Jones later described him as "flippant and sneering." Nick himself thinks he was destined for a harsh sentence from the start. "They wanted to make an example of me," he said. "They'd have sent me to jail for a parking ticket." In the end, amid a flurry of national publicity, he was cleared of causing criminal damage to computer hardware, but convicted on four counts of damaging disks. After the verdict, defense counsel asked for but were refused bail. Whiteley was sentenced to a year's imprisonment, but eight months were suspended, and with good behavior in jail, he was paroled after serving only two months. He was released in March 1991. Nick was the first person in Britain to be convicted of offenses relating to hacking. The overtones in his case--and the allegations of MI5 snooping and break-ins at the MoD--were enough to bring pressure on Parliament to propose a new computer crime law. The Computer Misuse Act came into effect in 1990: it made any attempt, successful or otherwise, to alter computer data with criminal intent an offense punishable by up to five years in jail. It could be called Nick Whiteley's legacy. The contrast between Nick--generally polite, easygoing, and articulate--and his alter ego, the Mad Hacker, impressed everyone who met him. Nick Whiteley would never leave messages redolent with sexual aggression for Marlyn: that was the Mad Hacker, or Alan Dolby. Nick Whiteley wouldn't cause damage to an ICL: again, that was the Mad Hacker. Like so many hackers, Nick played out his fantasies on the computer keyboard. He was no longer Nick Whiteley from Enfield when he was hacking, he was the Mad Hacker, the Mr. Hyde of QMC, Hull, Glasgow, and JANET. With a computer he could become anyone he wanted to be; without it he was just Nick Whiteley. Even when the computer underground was in its infancy, in the United States back in the early sixties, the use of aliases was symbolic of the growing subculture. Early phreakers had names such as Cheshire Catalyst, Dr. No, Midnight Skulker, and of course Captain Crunch. Hackers continued to use aliases to hide their identities--and more often than not to disguise their real selves behind a fearsome mask. Later, aliases became known as handles, after CB slang. A handle with high-tech allusions (Fiber Cables, Apple Maniac, Byte Ripper) or suggesting personal instability (Perfect Asshole, the Prisoner, Right Wing Fool) is considered perfectly acceptable. Some hackers opt for fiercer handles (Knight Stalker, Scorpion) or just co-opt the names of celebrities (there are hackers called Pink Floyd and Robin Williams). Behind these sometimes demonic handles often lurks a fourteen- or fifteen-year-old boy who is hooked on technology and spends hours alone in his bedroom, hacking into remote computers. Armchair psychology suggests that the fiercer the handle, the meeker the kid behind it. There is a huge element of role-playing in hacking, a need to be accepted among the community, not as the person one really is 54 APPROACHING ZERO but as the person suggested by the handle. Hacking brings out the Mr. Hyde in all the little technological Dr. Jekylls. Adopting a handle is essential for a novice to be accepted on pirate hacker boards, where he can access information about his hobby and pass on messages to other hackers. The computer underground is amorphous; any structure it does have is provided through communication within the community via the boards and a variety of other technical modes electronic and voice mailboxes, conference bridges, and even loop-around-pairs, the old phreaker technology. A handle is a hacker's badge of belonging, his calling card; the pirate boards serve as electronic meeting places, the high-tech equivalent of hanging out at the mall. Boards are simply computers loaded with some specialist software and linked to a modem. They are generally owned and operated by a single person, who becomes the system operator and controls access. There may be hundreds in existence-- the majority are in North America--and they come and go, as does their status within the hacker community. At any given time there may be only two or three "hot boards" that attract the top hackers. Getting access to one of these boards is a sign of having arrived in the computer underground, a mark of respect. Belonging to a particular board means belonging to the group that uses the board: it means becoming part of what one U.S. attorney called a high-tech street gang. Hacker boards are never publicized. Obtaining the dial-up number is itself a sign that a potential member has some credibility within the community, but that alone is not enough; no selfrespecting pirate systems operator wants his board cluttered up with "lamers," kids who pretend to be hackers but don't really have what it takes. The registration procedure on pirate boards is a careful process. First-time callers are met with a request for their user-name and their phone number. Lamers who enter their real name and real phone number have already blown it. The correct procedure is to enter a handle and a fake phone number--a healthy dose of paranoia is a good sign that a caller is a real hacker. The next step is to provide personal references, which will determine the level of access to the pirate board. Hacker boards often have several grades of users, and only the most trusted callers are able to access the "good stuff." The reference query is designed to elicit the names of other pirate boards the caller has access to, his level of access on those boards, and the handles of any other trusted hackers he may know. If the references prove satisfactory, the caller will be granted leave to use the board. Some boards go a step farther: they ask the caller to write a short statement explaining his reasons for wanting access, or to complete a questionnaire, to test his technical expertise. Some operators, particularly on "cracker" boards (those used by software pirates to swap "cracked"--illegally copied--programs) demand that a caller prove himself by supplying what is called warez--for wares, or pirated software. Complementing the boards is a sporadically functioning electronic underground press--newsletters, most distributed electronically, that contain articles about busts, tips on hacking and phreaking, and technical descriptions of computer operating systems. The oldest is PHRACKInc. (the name is an amalgamation of phreak and hack), which was available off and on from 1985 until 1990. Others that have appeared from time to time include the Legion of Doom: Hackers Technical Journal, Phreakers/ Hackers Underground Network, and the Activist Times. A traditional, printed, publication, 2600 The Hacker Quarterly, has been published since 1987, and is available on some newsstands. The 2600 in its title is a bow to the infamous frequency tone used by phreakers to make toll-free long-distance calls. Membership in the computer underground simply means belonging to a self-selected group of high-tech junkies. Some individual hackers--generally members of a particular bulletin board--work as a group and acquire a gang handle. In 1982 the Inner Circle was the first group to claim credit for breaking into the U.S. military computer network. The 414 gang, named after 56 APPROACHING ZERO its local Wisconsin area code, specialized in cracking telephonecompany systems. The telephone company, or "telco," as it is called, is still a favorite target for many hackers. Those who specialize in exploring the telco system are sometimes called phreakers like their predecessors Captain Crunch and Joe Engressia. In words that echo Joe Engressia, one telco phreak wrote, "The phone system is the most interesting, fascinating thing I know of. There is so much to know. I myself would like to work for the telco, doing something interesting, like programming a switch--something that isn't slave labor bullshit. Exploring the system is something that you enjoy, but have to take risks in order to participate in, unless you are lucky enough to work for the telco. To have access to telco things, manuals, etc., would be great." If there is a credo that unites all members of the computer underground, it is probably the one first expounded by Steven Levy in his 1984 book, Hackers: "Access to computers, and anything that might teach you something about the way the world works, should be unlimited and total." This belief implies a code of ethics that, put simply, boils down to "Look, but don't touch." Hackers, according to this code, may break into computers or computer networks with impunity, but should not tamper with files or programs. In the real world it rarely works like that. Though hackers see themselves as a useful part of the system, discovering design flaws and security deficiencies, the urge to demonstrate that a particular computer has been cracked tempts hackers to leave evidence, which involves tampering with the computer. The ethical code is easy to overlook, and sometimes tampering can become malicious and damaging. For the authorities, the whole thing is a giant can of worms. Patrolling the access points and communications webs that make up Worldnet is an impossible task; in the end, policing in the information age is necessarily reactive. Adding to the problems of the authorities is the increasing internationalization of the computer underground. Laws are formed to cover local conditions, in which the crime, the victim, and the perpetrator share a common territorY- International crime, in which the victim is in America, say, and the perpetrator in Europe, while the scene of the crime--the computer that was violated--may be located in a third country, makes enforcement all the more difficult. Police agencies only rarely cooperate internationally, language differences create artificial barriers, and the laws and legal systems are never the same. Still, the authorities are bound to try. The argument that began as the information age dawned, encapsulated in Stephen Levy's uncompromising view that access to data should be "unlimited and total," has never ended. The government, corporations, and state agencies will never aliow unlimited access for very obvious reasons: state security, the privacy of individuals, the intellectual property conventions . . . the list goes on and on. In all western countries, hacking is now illegal; the theft of information from computers, and in some cases even unauthorized access, is punishable by fines and jail sentences. The position is rigid and clear: the computer underground is a renegade movement, in conflict with the authority of the state. But there are still good hackers and bad hackers. And it is even true that sometimes hackers can be helpful to the authorities--or at least, it's happened once. A hacker named Michael Synergy (he has legally changed his name to his handle) once broke into the computer system at a giant credit agency that holds financial information on 80 million Americans, to have a look at thenpresident Ronald Reagan's files. He located the files easily and discovered sixty-three other requests for the president's credit records, all logged that day from enquirers with unlikely names. Synergy also found something even odder--a group of about seven hundred people who all appeared to hold one specific credit card. Their credit histories were bizarre, and to Synergy they all seemed to have appeared out of nowhere, as if "they had no previous experience." It then occurred to him that he was almost certainly looking at the credit history--and names and ad- 58 APPROACHINC ZERO dresses--of people who were in the U.S. government's Witness Protection Program. Synergy, a good citizen, notified the FBI about the potential breach of the Witness Program's security. That was hacker ethics. But not every hacker is as good a citizen. Chapter 3 DATA CRIME Pat Riddle has never claimed to be a good citizen. He is proud of being the first hacker in America to be prosecuted. Even now, as a thirty-four-year-old computer security consultant, he is fond of describing cases he has ~vorked on in which the law, if not actually broken, is overlooked. "I've never been entirely straight," he says. As a child growing up in a suburb of Philadelphia, he, like most hackers, was fascinated by technology. He built model rockets, played with electronics, and he liked to watch space launches. When he became a little older, his interests turned to telecommunications and computers. Pat and his friends used to rummage through the garbage left outside the back doors of phone company offices for discarded manuals or internal memos that would tell them more about the telephone system--a practice known as dumpster diving. He I earned how to make a "butt set," a portable phone carried by phone repairmen to check the lines, and first started "line tapping"--literally, listening in on telephone calls--in the early 1970s, when he was fourteen or fifteen. The butt set he had built was a simple hand-held instrument with a dial on the back and two alligator clips dangling from one end. All the materials he used were purchased from hardware and electronics stores. To line-tap, he would search out a neighbor- 60 APPROACHING ZERO hood telephone box where the lines for all the local phones come together. Every three-block area, roughly, has one, either attached to a telephone pole or freestanding. Opening the box with a special wrench--also available from most good hardware stores--he would attach the clips to two terminals and listen in on conversations. Sometimes, if the telephone box was in a public area, he would run two long wires from the clips so that he could sit behind the bushes and listen in on conversations without getting caught. To find out whose phone he was listening to, he would simply use his butt set to call the operator and pretend to be a lineman. He would give the correct code, which he had learned from his hours of dumpster diving, and then ask, "What's this number?" Despite being fourteen, he was never refused. "So long as you know the lingo, you can get people to do anything," Pat says. The area where he grew up was a dull place, however, and he never heard anything more interesting than a girl talking to her date. "It was basically boring and mundane," he says, "but at that age any tittle-tattle seemed exciting." Pat learned about hacking from a guy he met while shoplifting electronic parts at Radio Shack. Doctor Diode, as his new friend was called, didn't really know much more about hacking than Pat, but the two of them discovered the procedures together. They began playing with the school's computer, and then found that with a modem they could actually call into a maintenance port--a dial-up--at the phone company's switching office. The phone company was the preferred target for phreakers-turned-hackers: it was huge, it was secretive, and it was a lot of fun to play on. Breaking into a switch through a maintenance port shouldn't have been easy, but in those days security was light. "For years and years the phone company never had any problems because they were so secret," Pat says. "They never expected anyone to try to break into their systems." The switch used an operating system called UNIX, designed by the phone company, that was relatively simple to use. "It had lots of menus," recalls Pat with satisfaction. ~enus are the lists of functions and services available to the computer user, or in this case, the computer hacker. Used skillfully, menus are like a map of the computer. As Pat learned his way around the switch, he began to play little jokes, such as resetting the time. This, he says, was absurdly simple: the command for the clock was Time. Pat would reset the clock from a peak time--when telephone charges were highest--to an off-peak time. The clock controlled the telephone com' pany's charges, so until the billing department noticed it was out of kilter, local telephone users enjoyed a period of relatively inex~pensive calls. He also learned how to disconnect subscriber's phones and to manipulate the accounts files. The latter facility enabled him to "pay" bills, at first at the phone company and later, he claims, at the electric company and at credit card offices. He would perform this service for a fee of 10 percent of the bill, which became a useful source of extra income. He also started to play on the Defense Department's Advanced Research Projects Agency (ARPA) computer network. ARPANET was the oldest and the largest of the many computer nets--webs of interconnected mainframes and workstations--that facilitated the Defense Department's transfer of data. ARPANET was conceived in the 1950s--largely to protect the ability of the U.S. military to communicate after a nuclear strike--and finally established in the late 1960s. It eventually linked about sixty thousand computers, or nodes, and interacted with other networks, both in the United States and elsewhere in the world, making it an integral part of Worldnet. Most universities, research centers, defense contractors, military installations, and government departments were connected through ARPANET . Because there was no "center" to the system, it functioned like a highway network, connecting each node to every other; accessing it at one point meant accessing the whole system. Pat used to commune regularly with other hackers on pirate bulletin boards, where he exchanged information on hacking sites, known computer dial-ups, and sometimes even stolen IDs 62 APPROACHING ZERO and passwords. From one of these pirate boards he obtained the dial-up numbers for several ARPANET nodes. He began his hack of ARPANET by first breaking into Sprint, the long-distance phone carrier. He was looking for long-distance access codes, the five-digit numbers that would get him onto the long-distance lines for free. In the old days he could have used a blue box, but since then the phone system had become more sophisticated. Blue boxes were said to have been killed off once and for all in 1983 when Bell completed the upgrading of its system to what is called Common Channel Interoffice Signaling (CCIS). Very simply, CCIS separates the signaling--the transmission of the multifrequency tones--from the voice lines.' To get the codes he wanted, Pat employed a technique known as war-dialing, in which a program instructs the computer to systematically call various combinations of digits until it finds a "good" one, a valid access code. The system is crude but effective; a few hours spent war-dialing can usually garner a few good codes. These long-distance codes are r.ecessary because of the timeconsuming nature of hacking. It takes patience and persistence to break into a target computer, but once inside, there is a myriad of menus and routes to explore, to say nothing of other linked computers to jump to. Hackers can be on the phone for hours, and whenever possible, they make certain their calls are free. Pat's target was an ARPANET-linked computer at MIT, a favorite for hackers because at that time security was light. In common with many other universities, MIT practiced a sort of open access, believing that its computers were there to be used. The difficulty for MIT, and other computer operators, is that if security is light, the computers are abused, but if security is tight, they become more difficult for even authorized users to access. Authorized users are given a personal ID and a password, which hackers spend a considerable amount of time collecting through pirate bulletin boards, peering over someone's shoulder in an office, or "dumpster divin~." But exploitin~ a computer's default log-ins and passwords can often be even simpler--as Nick Whiteley discovered when he hacked in to the QMC computer for the first time. A common default is "sysmaint," for systems maintenance, used as both the log-in and the password. Accessing a machine with this default would require no more than typing "sysmaint" at the log-in prompt and then again at the password prompt. Experienced hackers also know that common commands such as "test" or "help" are also often used as IDs and passwords. Pat first accessed ARPANET by using a default code. "Back then there was no real need for security," he says. "It was all incredibly simple. Computers were developed for human beings to use. They have to be simple to access because humans are idiots." ARPANET became a game for him--he saw it as "a new frontier to play in." He jumped from computer to computer within the system, accessing everything from the main computers regulating the network to mainframes at the Pentagon, air force, and army installations and research centers. "It was like going through an electronic road map, trying to get somewhere, without knowing where," he says. Pat talks in vague terms about downloading information from the computers he accessed, but is evasive about what he did with it. He says that some of it was sold, although what he sold and to whom and for how much remains unclear. It is more likely that selling the data was of secondary concern; he was merely "fascinated" by the intricacies of the new technol gY- "This is the information age," he says. "Knowing about ~_omputers made me feel more intelligent. Very few people had access to them, and even fewer understood them." At about the time that he was first hacking into ARPANET, a new program called Super Zap appeared which could bypass copy protection2 on IBM PC-type software. Pat thought that its function mirrored his own activities, so he decided to call himself Captain Zap. 64 APPROACHING ZERO By 1980 Captain Zap was becoming more and more adventurous He had learned the dial-ups for the White House computer network, which he accessed regularly over the next year, and had also dialed directly into the Pentagon. He was going for prestige hacks. He used to download information from the White House, reams and reams of computer paper, and bring it home to his wife. "Look what I've found!" he would shout, but she was less interested in what he had found than in the fact he could get caught. And whatever it was that he had discovered, he himself can't remember. "There was all sorts of bullshit," he says. Some of it was encrypted, some not, but none of it seems to have been very memorable. There was another use for the White House phone number, however. He would sometimes call the central operator number--a voice number, not a dial-up--and in his best bureaucratic style say something like, "This is Mr. McNamara, admin counsel. I need a secure line to the American embassy in Germany." He swears that the operators would patch him through, and that once connected to the American embassy--on a secure line, from the White House--he could request another secure line to whatever local number he wanted to call. He claims that Mr. McNamara was just a name that he had made up, and that whether or not there was such a person, the operators never turned him down. Captain Zap was a believer in "knowing the lingo"--the lingo being the language necessary, whether computer-speak, telcospeak, or even bureaucratese--to obtain information or to persuade people to help you. This practice, known as social engineering, is a by-product of hacking, simply getting information from someone by pretending to be someone else. It works like this. Say you need the dial-up for a particular computer. You call the voice number of the target company and ask to speak to the computer operator. When you get through, you put on your best telco repairman's accent and say, "We're doing a few repairs on the computer lines in your area. Have you been having trouble with your terminal?" The answer is invariably yes. "Yeah, I thought so," you say. "Look, we need to check the line. Can you start up your system and run me through it? What's your dial-up?" And so on. In most cases the operator will volunteer not only the dial-up, but the log-in and password as well. Social engineering takes a lot of the hassle out of hacking, ~nd for adolescent hackers it has an additional attraction: it gives them a chance to put one over on an adult. Deceiving ~rown-ups has always been a youthful pastime; social engineerg demands it. While Captain Zap was hacking the White House and the entagon, he was also putting his skills to a more profitable se--theft. He and his friend, Doctor Diode, had learned how to rack the sales and invoicing systems of a number of large comuter companies and equipment wholesalers. The system they ad worked out was surprisingly simple. First they would create ummy corporations by hacking into a credit agency, listing their company on the register, and giving it a "triple-A" credit rating--the highest.3 Then they would hack into a supplier's computer and create a real-paper trail: they would connect themselves to the sales department and cut an order, jump to the accounts department and "pay" the invoice, then skip over to shipping and write out a delivery manifest. The delivery address would be a mail drop the address of an answering service, say, which would also receive all documentation from the target company. From the supplier's point of view the paper trail was complete: they had an order, a paid invoice, and a delivery manifest. The paperwork made sense. If they checked with the credit agency, they would find that the buyer had a triple-A credit rating. Of course the company didn't actually have the money to cover the equipment it had just delivered, but that wouldn't be discovered until they tried to balance their books. The supplies that Captain Zap and his friend ordered included 66 APPROACHINC ZERO portable terminals, a Hewlett-Packard computer, peripherals, cameras, walkie-talkies, and other supplies. According to the authorities, the total amount of goods stolen in the scam amounted to over $500,000. Pat insists that hacking into the supplier's computers was simple: "There was no security," he says. Using guesswork and knowledge of the default settings, they could make their way past the log-in and password prompts. For more recalcitrant computers they rigged up an adapted "war-dialing" system that would keep pounding at the door with one ID and password combination after the other until they got in. Even if a computer operator has assiduously removed default codes, there are still common combinations that people use over and over. There are said to be just a few of these combinations--such as name and surname, or company name and department--that, in a large system, someone will use. Knowing the names of employees and where they work greatly speeds up the process of hacking. People pick simple combinations for an obvious reason: they need to remember them. Choosing something completely off-the-wall increases the chance of forgetting the ID or password just as the prompt is flashing. And writing them down defeats the object. The surveillance of Captain Zap began in May 1981. Pat knew he was being watched because he noticed a van with two men in it outside his apartment. By then his unorthodox buying spree had gone on for almost two years. Though each "order" was relatively small, the companies that had been robbed had been able to isolate the accounts that appeared to be paid but for which there was no corresponding check. Then they called the police. There was a trail of connections the authorities could follow, which led from the companies that had sold the goods to the mail drops, and from there to Pat and the others he worked with. The bust came at ten A.M. on July 2, 1981. Agents from the FBI accompanied by state police from the White Collar Crime Unit, Bell Security representatives and two military policemen raided Pat's parents' home. The maid answered the door. He lived in one of the wealthiest suburbs of Philadelphia; the homes are substantial, the residents well established. Pat's father owned and managed one of the largest and oldest shipping companies on the East Coast. When the newspapers carried the ~tory, Pat and his friends would be castigated as "children of privilege." The FBI presented Pat's mother with a thirty-seven-page document. "We have a search warrant," they said. "For what?" "For Pat. He's accused of computer fraud." His mother looked aghast. "He couldn't pass mathematics. You're telling me he's a computer genius?" The agents proceeded to tear apart Pat's room. They packed up dl the computers, modems, and communications gear they could ~,find. They went through the files, stuffing them in boxes. When ~Pat came home that night, he found that all of his eqllipment had t~been taken away. Pat was indicted on September 21 in both Harrisburg, Pennsyl~ania, and Washington, D.C., for a number of offenses, including theft of equipment--the $500,000 worth of computers and supplies--and theft of telephone services. He was twenty-four years old at the time. In 1981 there was no comprehensive computerfraud law, so Pat was "shoehorned"--his expression--into the existing criminal statutes. There are advantages to being a child of privilege. Though Pat's colleagues were also arrested (there were five arrests in total, including Pat and Doctor Diode) and some turned state's evidence in exchange for a light sentence, Pat's father's money bought him the services of two of Philadelphia's biggest law firms. After looking at the evidence, one of the lawyers turned to Pat and said, "No jury will ever understand what you did and no jury will ever convict you for ripping off the phone company." The lawyer's words were not put to the test. The charges against Pat were plea-bargained down to a $1,000 fine and two and a half years' "phone probation"--meaning that Pat had to 68 APPROACHING ZERO report to his probation officer by calling in. He still finds it ironic that a convicted phreaker and hacker was required to report in by telephone. In the wake of the Captain Zap case the American authorities quickly woke up to the threat of computer hacking. By the mid1980S almost every state had criminalized "theft by browsing"--that is, hacking into computers to see what's there. The first federal law on computer crime, the Computer Fraud and Abuse Act, was passed in 1986. The contrast between the leniency shown Captain Zap in the U.S. courts for what was, in the end, hacking for profit, and the judgment given to Nick Whiteley in England for schoolboyish pranks nine years later is illustrative of the changes in the authorities' perception of hacking over the decade. In 1981, when Cap- tain Zap was arrested, his lawyer was probably correct in assuming that no jury would have understood the prosecution's case. In 1990, however, Nick was almost certainly right in saying the courts were determined to throw the book at him. Over the course of a decade, both the authorities' awareness of hacking and the technological underground that committed this crime had grown. Hacking--though probably only dimly understood by most of the public--had become a fashionable threat, explained in long, analytical newspaper articles and described in detail by stylish magazines. Computer security experts (and some hackers) were invited onto TV talk shows to paint the threats to computer security in lurid terms. The sense of impending technological apocalypse was heightened by a number of well-publicized hacking cases during the 1980S, of which the best known was probably the Kevin Mitnick affair. Mitnick was said to be obsessed with computers. In 1979 he and a friend had successfully hacked into the NORAD (North American Air Defense command) mainframe in Colorado Springs. Mitnick has since said that they didn't tamper with anything, but simply entered the system, looked around, and got out. He first ran afoul of the law in 1981, when he and three friends were arrested for stealing technical manuals from the Pacific Telephone Company: he was convicted and served six months. In 1983 he was caught by the University of Southern California while trying to hack one of their computers. Later, he was accused of breaking into a TRW computer (the TRW Credit Information Corporation holds data on 80 million Americans nationwide). In 1987 he was arrested for stealing software from a southern California company and sentenced to thirty-six months' probation. Mitnick belonged to a group of Los Angeles-area hackers called the Roscoe Gang. He and the gang allegedly used PCs to harass their victims, break into Defense Department computers, and sabotage businesses. He was also accused of breaking into a National Security Agency computer and stealing important information. More seriously, he was charged with defrauding the computer company Digital Equipment Corporation (DEC) and the long-distance phone company MCI, and with transporting proprietary software across state lines. The software was alleged to be a copy of DEC's Security Software System, which made it possible for Mitnick to break into DEC's computers and cause $4 million worth of damage. Mitnick was again arrested in late 1988. He was refused bail by several federal judges, who said there would be no way to protect society if he were freed. He was also denied access to a phone while in jail, for fear that he may have preprogrammed a computer to remotely trigger off damaging programs. In 1989 he was sentenced to two years in prison. The decision to deny Mitnick access to a phone was greeted with alarm by an increasingly nervous hacker community. "We must rise to defend those endangered by the hacker witch-hunts," wrote an unnamed contributor to 2600, the hacker journal. The U.S. Attorney's office in Chicago, then in the midst of its own hacker case, responded by saying it intended to prosecute "aggressively." The Chicago case, though less publicized than the Mitnick 70 APPROACHINC ZEUO affair, was the first test of the federal Computer Fraud and Abuse Act. In 1987 local law enforcement agencies began watching a sixteen-year-old hacker and high school dropout named Herbert Zinn, Jr., who used the handle Shadow Hawk. The law enforcement officials spent two months investigating Zinn, auditing his calls and monitoring his activities on computers. He was subsequently accused of using a PC to hack into a Bell Laboratories computer in New York, an AT&T computer in North Carolina, another AT&T computer at Robbins Air Force Base in Georgia, an IBM facility in New York, and other computers belonging to the Illinois Bell Telephone Company. He was also accused of copying various documents, including what were called highly sensitive programs relating to the U.S. Missile Command. Shadow Hawk was arrested in a raid involving the FBI, AT&T security representatives, and the Chicago police. He was eventually sentenced to nine months in prison and fined $10,000. The Mitnick and Shadow Hawk cases fueled the growing concern among U.S. Iaw enforcement agencies about hacking. By the end of the decade, the Secret Service--which is now charged with investigating computer crime, a responsibility partly, and not entirely amicably, shared with the FBI--was said to have established a unit for monitoring pirate bulletin boards. A number of state and local police forces had organized their own computer crime sections, while separate investigations of the underground were mounted by U.S. Attorneys' offices and local prosecutors. By the beginning of the 1990s, American law enforcement agencies had begun paying extraordinary attention to computer crime. Across the Atlantic, away from the prying eyes of the American authorities, the biggest international gathering of hackers ever organized took place in Amsterdam in early August 1989. The assembly was held in the seedy confines of the Paradiso, a former church that had been turned into a one-thousand-seat th~t~r. The Paradiso was the home of Amsterdam's alternative culture; it specialized in musical events, underground exhibits, and drug parties. The Galactic Hacker Party--or, more grandly, the International Conference on the Alternative Use of Technol- gy~brought together some 400 to 450 hackers, hangers-on, journalists, and, inevitably, undercover cops, to swap stories, refine techniques, gather information, or simply enjoy themselves. The conference took place on all three floors of the Paradiso. On the top floor, above what had been the nave of the church, participants were provided with computers to play with. (Their popularity decreased after one wag programmed them to flash, THIS MACHINE IS BEING MONITORED BY THE DUTCH POLICE, when they were turned on.) The ground floor, the theater itself, was reserved for speakers and demonstrations; across the back of the stage drooped a white banner emblazoned with the words GALACTIC HACKER PARTY. The crypts in the basement of the Paradiso were reserved for partying. At ten A.M. on Tuesday, August 2nd, the opening day, a large monitor displayed a computer-generated image of a head of a hacker. "Keep on hacking," urged the head in an American accent, as the multinational gathering milled about in the disorganized way of a crowd that clearly lacked a common language. Then, a bearded, bespectacled, balding figure shuffled unheralded onto the stage. He was the keynote speaker, the man who, more than anyone, had given rise to the whole hacking phenomenon. At forty-six, Captain Crunch looked strangely out of place among the younger hackers. It had been eighteen years since he had first come to symbolize the new technological underground, ten years since he had last been jailed for a second time for phone phreaking. And here he was in Amsterdam, on a month's vacation in Europe, still spreading the word. He began with a rambling discourse in English about the phone system in the former Soviet Union, information gleaned on an earlier visit there. Their phone network, the Captain reported, was old, of mixed origin, and, he suspected, had been continuously monitored by the KGB. He then began the slow process of 72 APPUOACHING ZERO demonstrating the newly established Sov-Am Teleport Union, a telephone link that connected San Francisco to Moscow via satel lite. Using a phone on the stage the Captain first dialed San Francisco, where he linked to the Teleport, and then jumped via satellite to Moscow. Unusually for the Captain, he had a purpose to his call. He dialed a number in Moscow, where a group of ten hackers were waiting to address the conference about the underground in Russia. The Russians then joined a multilingual babble of hackers on the line from a number of other countries, including Germany, France, Kenya, New Zealand, and the U.S. The Captain, reveling in his role as prophet for the whole movement, fielded calls about technology and the ethics of hacking--one caller wanted to know if it would be right to hack into South African computers at the behest of the African National Congress--and then related his own phreaking experiences. The Captain was in Amsterdam representing what has been called the second generation of hackers. The kids he was talking to, the visitors to the Galactic Hacker Party, were dubbed the fourth generation. Though they had been separated by more than a decade in time and by thousands of miles in geography, the Hacker Party was their meeting place. The concept of hacker generations was first suggested by Steven Levy, the man who also outlined the philosophy of "hacker ethics." In his book Hackers, he argued that the first generation of hackers was a group of students at MIT in the 1960s who had access to big, expensive mainframes; worked together to produce useful, new software; and, in doing so, bent the rules of the university. More than anything, they believed in freedom of information and unfettered access to technology. They abhorred security to the extent that they made sure they could pick every lock in the building they worked in. The second generation of hackers, according to Levy, were people like Captain Crunch and Steve Wozniak, as well as the other members of the Bay Area's Personal Computer Company and its successor, the Homebrew Computer Club. These were the people who intuitively believed that the way to drive technology forward was to make the specifications for their machines freely available, a concept known as open architecture. They were hardware hackers, and their achievement can now be seen everywhere in the generality of the ubiquitous PC standard. Each decade has brought a different twist of geography and h motivation to the various generations of hackers: the 1960s hackers, the first generation, were based on the East Coast, developing software; the second-generation, 1970s hackers were on the West ~Coast, developing hardware. The next generation, the third, was based both in North Amer~ica and Europe. These were the kids who had inherited the gift of ~the personal computer and were copying and selling the first ~computer games. Their motivation was often a fast buck, and their instincts entirely commercial. The Captain's audience, the fourth generation, had inherited a world in which technology was rapidly converging around the new standard-bearer, the IBM PC. This new generation shared the same obsessions as their predecessors, but now that they had everything that technology could offer, they hacked merely for the sake of hacking. Hacking had become an end in itself. For many of the fourth generation, technology was merely a relief from boredom and monotony. Hacking was a pastime that varied the routine of school or university, or a dead-end job. To become proficient, they would typically devote most of their wak~ng hours--80 to 100 hours a week was not uncommon, more time than most people give to their jobs--to working on PCs and combing the international information networks. Hackers, for the most part, are not those with rich and rewarding careers or personal lives. Of course, hacking is also a form of rebellion--against parents, schools, authority, the state, against adults and adult regulations in general. The rebellion is often pointless and unfocused, often simply for the sake of defying the system. Ultimately there may 74 APPROACHING ZERO be no point at all; it has simply become a gesture to ward off boredom or, perhaps, the banality of ordinary life in a structured society. The higher principles of hackers were summed up in a draft declaration prepared by the Galactic Hacker Party's organizers and circulated among delegates for their signatures. "The free and unfettered flow of information is an essential part of our fundamental liberties, and shall be upheld in all circumstances," the document proclaimed. "Computer technology shall not be used by government and corporate bodies to control and oppress the people." The language echoed the beliefs of the second generation of hackers. But the conversation among the kids in the crypt and in the halls belied the rhetoric of the organizers. For Lee Felsenstein, an American visitor, it was a disturbing experience. Lee was a confirmed second-generation hacker, one of the original founders of the Homebrew Computer Club. He remained a staunch believer in freedom of speech and an avid supporter of individual rights. But he felt that the fourth-generation hackers were "underage and underdeveloped"; they displayed "negative social attitudes." Hacking, he said, had degenerated from being a collective mission of exploration into an orgy of self-indulgence. For Lee, evidence of degeneracy included the hackers who boasted about breaking into American computers to steal military information and then selling it to the KGB. He was also disheartened to learn about the exploits of the VAXbusters, a German group that had broken into NASA and over a hundred other computers worldwide by exploiting a loophole in the operating system of Digital Equipment Corporation's VAX computers. The VAX, very powerful but small machines, are widely used in science laboratories, universities, and military installations. More to the point, from Lee's point of view, the fourth generation of hackers was becoming involved in a new facet of computer programming, one that threatened everything he believed in. Far from increasing access and creating freedom for computer users, this new development could only cause the door to be slammed shut on access, for freedom to be replaced by fortresslike security. During the Galactic Party, a number of hackers had been demonstrating new programs called computer viruses. Lce left Amsterdam muttering about Babylon and ancient Rome. John Draper, alias Captain Crunch, was less bothered. He spent the remainder of his vacation traveling around Germany, taking his hacking road show to eighteen different cities. There was, in fact, nothing new about computer viruses except their existence. Viruses had been foreseen in science fiction; the rliest use of the term has been traced to a series of short stories itten in the 1970s by David Gerrold. In 1972 Gerrold employed virus theme for a sci-fi potboiler called When HARLIE Was. HARLIE was an acronym for Human Analogue Robot Life nput Equivalents computer, which meant simply that the ficional creation could duplicate every function of the human ain--a sort of mechanical equivalent of Dr. Frankenstein's onster. This robot could also dial up other computers by teleone and reprogram them or modify data. In so doing, ARLIE was emulating a computer program called simply irus, which dialed up telephone numbers at random. When it und another computer at the end of the line, it loaded a copy ' itself onto the new machine, which started dialing other comlters to transfer copies of the program, and so on. Soon hundreds of computers were tied up randomly calling numbers. The Virus program was fictional, of course, and simply part of ~rrold's convoluted plot, but the concept of a computer program reproducing itself had been foreseen as early as 1948. In that John van Neumann, a Hungarian-born mathematician and computer pioneer who had designed one of the world's first comruters, quaintly called Maniac, began theoretical work on what was then thought of as electronically created artificial life, which he termed automata. He predicted that the reproduction process for such automata would be fairly simple. 76 APPROACHING ZERO Later, in the 1960s, before the advent of computer games, university engineering students sometimes amused themselves by seeing who could write the shortest program that could reproduce an exact copy of itself. These were called self-replicating programs, but van Neumann would have recognized them as versions of his concept of electronic automata. The first attempts to use self-replicating programs for something useful were made at Xerox's Palo Alto Research Center in the late seventies. Two researchers, John Shoch and Jon Hupp, devised what they called a worm program to help with the management of the center's computer network, which linked over one hundred medium-sized machines. They envisaged the program working automatically, archiving old files, making backup copies of current files, and running routine diagnostic checks; they hoped that it would be able to perform the endless housekeeping tasks that the researchers at Palo Alto were too busy to keep up with. They named the new program a worm, the two later said, in honor of their inspiration--another work of science fiction by the English writer John Brunner called The Shockwave Rider, published in 1975. Brunner's book heralded the existence of a computer program, which he called a "tapeworm," that reproduced itself endlessly and couldn't be killed. Something very similar happened to Shoch and Hupp. Their worm program was expected to sit quietly on one computer during the day, then emerge at night to roam the computers in the research center, carrying out housekeeping chores.4 Because it worked only at night, skeptical colleagues nicknamed it the vampire program. In their first test, Shoch and Hupp left the worm program "exercising" on half a dozen designated machines in the lab. It wasn't programmed to do anything; it was just expected to travel to the designated machines and leave copies of itself. The next morning, though, when the two arrived back at their office, they found that the worm had escaped and had rampaged through all the hundred-plus networked computers in the center. More disturbing~ it had reproduced so quickly that it had brought every machine to a halt, seemingly strangling them by taking up all i available space in the computers' memory. Worse, when they attempted to restart one of the computers, the worm was reactivated and proceeded to strangle the machine again. To destroy the worm, they had to write another pro- gram--a killer program. Fortunately, unlike Brunner's tapeworm, their program was not indestructible, but Shoch and Hupp later called its behavior "rather puzzling," and simply abandoned the experiment, leaving unsolved the problem of "controlling [its] growth while maintaining stable behavior." In the early 1980s a number of computer science students suc- - ceeded in writing self-replicating programs for the new Apple II computers. Joe Dellinger, a student at Texas A&M University at the time, became intrigued by the idea that computer programs could become modified when copied. He had no trouble writing a self-replicating program for the Apple II, even though he didn't consider himself a particularly clever programmer. His biggest problem was in writing a program that wouldn't cause damage; he was surprised at how quickly the program could propagate, moving rapidly from computer to computer by diskette, eventually traveling to machines outside the A&M campus. Though Dellinger was intrigued by the notion that programs change as they replicate and travel from computer to computer, there is nothing metaphysical about it. It is simply a computer error. The longer and more complex a program is, the more likely that a line of instruction, a command within the program, will be skipped or altered in the copying process. These tiny modifications rarely cause problems, but the potential for error is there. What is more important is that Dellinger discovered that any self-replicating program, no matter how benign, carried with it the potential for damage, just as a fly buzzing about a room carries the possibility of disease. Unlike the software sold by commercial houses, self-replicating programs are untested, un- tried and generally unstable. The changes created when these 78 APPROACHING ZERO programs transfer themselves from machine to machine can cause them to be damaging, and their very presence on a computer is inherently risky. Equally intriguing is the speed at which they propagate. In an environment like a university campus, where anyone has access to any computer and programs are routinely carried from machine to machine on diskette, they can multiply exponentially. They are, after all, designed to replicate, so that one copy quickly becomes two, two become four, four become eight, and so on. Dellinger found that once let loose, the program's spread was almost unstoppable. It was another four years, however, before self-replicating programs became "viruses." In 1983 and 1984 a graduate student at the University of Southern Califomia named Fred Cohen was experimenting with these programs and, at the suggestion of his adviser, decided to call them computer viruses. It was a catchier name, and also became the title of his 1985 doctoral thesis, in which he offered an explanation of viruses. A virus, he wrote, is "a program that can infect other programs by modifying them to include a slightly altered copy of itself." Further, "every program that gets infected can also act as a virus and thus the infection grows." Cohen also indicated that viruses presented a threat to computer security and could modify or damage data. The thesis did not break any new ground in terms of computer science: in essence, Cohen took the known characteristics of selfreplicating programs and renamed them viruses. The term itself suggests that the programs are created in some kind of wild electronic biosphere and are capable of spreading incurable diseases from computer to computer--the high-tech equivalent of the biological viruses to which they are often compared. The sensationalistic use of the word would later prove to be fortuitous to computer security experts and have an irresistible appeal to rogue computer programmers. Though the word was perhaps chosen innocently, the metaphor was not entirely apt. Computer viruses, like biological viruses, are spread unknowingly, and they can mutate while spreading, but they are not created in the same way. Biological viruses are carried by small, natural organisms, over which man has little control; computer viruses, however, are simply programs--and computer programs are written by people. Cohen's work quickly attracted attention, not least from a German computer system engineer named Ralf Burger. At the time, Burger was twenty-six and living in a small town near the Dutch-German border, not far from the city of Bremen. Burger became fascinated by the concept of viruses, and in July 1986 he had succeeded in creating his own, which he called Virdem. It was, to all intents and purposes, a simple self-replicating program, but with a small twist. For Burger, the "primary function of the virus is to preserve its ability to reproduce." After being loaded onto a computer, Virdem was programmed to hunt down and infect other files in the machine. When there were no more files to infect, the virus would begin "a randomly-controlled gradual destruction of all files." In December 1986 Burger decided to attend the annual convention of the Chaos Computer Club in nearby Hamburg. The club had been founded in 1981 by Herwart Holland-Moritz--who prefers to be known as Wau Holland--and is a registered nonprofit organization. Holland, who was a thirty-two-year-old computer programmer at the time, set up the club as a hobby; despite the sinister implications of the name, it was chosen only because "there is a lot of chaos in the application of computers." According to the club's constitution, it is dedicated to freedom of information. Since its foundation the club has proven itself adept at organizing media events, and this ability together with the connotations of its name have given the group a high profile. Like many clubs, Chaos unites people with a wide range of interests: there are members who see computers as a weapon for sociological change, others who simply want to play computer games, those who want t o know how computer systems work, and those concerned with making a fast buck, legally or illegally. The Chaos members refer 80 APPROACHING ZERO to themselves as data travelers, rather than hackers, but they all share the same obsession with computers and all vaguely subscribe to a vague notion of "hacker ethics." Their own unique understanding of that term is that they have a mission to test, or penetrate, the security of computer systems. Early Chaos Clubbers were allied with the VAXbusters, the group that sought to break through the security of VAX computers around the world The club's first brush with notoriety, though, occurred in 1984, when they broke into Btx, or Bildschirmtext, an on-line text and information service patterned after Britain's Prestel. In 1986 they captured the media's attention again when, after the meltdown of the Soviet nuclear reactor in Chernobyl, they provided alternative information on contamination levels by hacking into government computers and releasing the data that they found. Their findings were sufficiently at odds with official reassurances to make them the darlings of Germany's Green movement. The annual conferences of the Chaos Club were held in Hamburg, always in December. They attracted the cream of the German hacker community, as well as observers from throughout Europe and elsewhere; were always well covered by the media; and, without a doubt, were carefully watched by the local police. Each conference was given a theme that was designed to excite media attention, and in 1986 the theme was computer viruses. Even though little was known about viruses at the time, the conference organizers hoped piously that the publicity given to the subject would help dispel myths. The organizers also declared: "The problem isn't computer viruses, but the dependence on technology," and they blamed the writing of viruses on "bad social condition(s) for programmers." The star performer at the conference was Ralf Burger, simply because he had actually written a virus, which in those days was something of a feat. To prove that his virus, Virdem, would work, Burger handed out copies to some two or three hundred interested delegates. He said it would "give users a chance to work with computer viruses." Technically, any virus is little more than a self-replicating program with a sting in its tail. This sting, usually known as the payload, is what the virus actually does to the computer, which is often nothing at all--apart from replicating, or performing a harmless joke, such as making a ball bounce around the screen or instructing the computer to play a tune. At another level, how- ever, the payload can cause the destruction of data. Computer viruses are carried from computer to computer by iiskette or, in networked computers, by the wires that link them. rhey can also be transmitted on telephone lines, through ~odems, like ordinary computer programs. Viruses do not fly through the air and cannot jump from computer to computer vithout being carried by a physical medium. Moreover, all viruses are man-written: they aren't natural, or caused spontaneously by computer technology. The only "artificial life" inherent in a virus is its tendency to modify itself as it is copied, but that's possible with any computer program. This explanation may seem simple to the point of absurdity, but when viruses first began to garner mentions in the press, and breathless reporters began to write lurid stories about "technological viruses," their properties were exaggerated into the realm of science fiction. Viruses made a good story--even when there was no evidence that they had actually damaged anything. In 1986, when Burger made his presentation to the Chaos conference, there were almost no viruses in existence. Few people in the computer industry had ever seen one, despite increasing interest in the subject from security experts, who were touting them as the next big threat to computer systems. The simple fact was that Burger's Virdem was probably the only virus that most of them had even heard about. The properties of viruses and the damage that they could cause were widely known, however. Even the nightmare scenario had been posited: that a plague of viruses would move swiftly through the computers of the world, wiping out data and devastating 82 APPROACHINC ZERO corporations, government agencies, police forces, financial institutions, the military, and, eventually, the structure of modern society itself. By 1986, however, actual attacks by viruses on computer systems had yet to occur. The next year, 1987, Burger's book about computer viruses Das Grosse-computervirenbuch, was published by Data Becker GmbH of Dusseldorf.5 In the book Burger warned: "Traveling at what seems the speed of moving electrons, comical, sometimes destructive programs known as viruses have been spreading through the international computer community like an uncontrollable plague." There was in fact no hard evidence for this statement, and later in the book, contradicting the apocalyptic tone of the first section, Burger admitted: "So far it has been impossible to find proof of a virus attack." Later that year, two new viruses appeared. The first was created by the Greek computer magazine Pixel, which had hired a local computer wizard named Nick Nassufis to write one. The magazine published the virus as a list of BASIC-language instructions in the April 1987 issue. Readers who keyed in the instructions found themselves with a fully functioning virus on their comput- ers. It didn't do much apart from replicate, but from time to time it would display a poorly written English language message on the computer screen: PROGRAM SICK ERROR: CALL DOCTOR OR BUY PIXEL FOR CURE DESCRIPTION. Three months later Pixel published instructions for wiping it out. Then, as Burger was preparing the second edition of his book he received a copy of a virus found in Vienna by a local journalist. This virus, now known as Vienna, was said to have appeared at a local university in December 1987. Its writer is unknown, as are the writers of most viruses. Burger described Vienna as "extremely clever." But by the standards of virus writing today, it wasn't, though it was certainly the most advanced virus in existence at the time. Vienna is known as a file virus because it attaches itself to what are known in the computer industry somewhat tediously as executable files (i.e., the software, such as a word-processing program, that actually enables a computer to do something useful). When an infected program is loaded onto a computer from a diskette (or transferred through a network), Vienna comes with it and slips itself into the computer's memory. It then looks for other executable files to infect, and after infecting seven it damages the eighth, simply by overwriting itself onto the program code. Although the payload of the Vienna virus was destructive--the eighth program that was damaged was irreparable--by presentday standards it wasn't particularly malicious. More dangerous was Burger's decision to publish a reconstruction of the Vienna program code in the second edition of his book. It became the recipe for writing viruses. Programmers with access to the code could quite easily adapt it for their own purposes--by altering the payload, for instance. That's what eventually happened with Vienna.6 Though Burger had deliberately altered his reconstruction to make it unworkable, programmers had little trouble finding their way around the alterations. Variants of Vienna have been found all over the world: in Hungary, a Vienna clone carries a sales message that translates roughly as POLIMER TAPE CASSETTES ARE THE BEST. GO FOR THEM. A Russian version was adapted to destroy the computer's hard disk, the internal memory and storage area for programs, after infecting sixty-four files. A Polish variant displays the message MERRY CHRISTMAS on infected computers between December 19th and 31st. A version from Portugal carries out the standard overwriting of the eighth program, but also displays the word AIDS. In the US a group of unknown American virus writers used Vienna as the basis for a series of viruses called Violator, all intentionally damaging to computer systems. It is ironic that a book written to warn about the dangers of viruses should be the medium for distributing the recipe for writing them. But even though no one had yet documented a proven virus attack on a computer system anywhere in the world, and the predicted plague of computer viruses had not yet materialized, the 84 ~ APPROACHING ZERO potential threat of viruses was being aggressively hyped by computer engineers like Burger and by a small group of computer security consultants in America-- and many people appeared remarkably eager to believe them. In what was probably the first press report of viruses, in February 1987, the editor of the interna- tional computer trade journal Computers de Security wrote, "Computer viruses can be deadly.... Last year a continuousprocess industry's computer crashed causing hundreds of thousands of dollars' damage. A post mortem revealed that it had been infected with a computer virus. Another nationwide organization's computer system crashed twice in less than a year. The cause of each crash was a computer virus.... A computer virus can cause an epidemic which today we are unable to combat." It has never been possible to trace either the "continuousprocess" corporation or the "nationwide organization" whose computers had been so badly damaged by viruses. Like so many aspects of computer viruses, investigation only reveals myth and legend, rarely fact. But myth is self-perpetuating, and prophecies are often self-fulfilling. Chapter 4 VIRUSES, TROIANS, WORMS, AND BOMBS The first documented computer virus attack was recorded on October 22,1987, at the University of Delaware, in Newark, Delaware. According to a spokesperson for the Academic Computer Center at the university, the virus infected "several hundred disks, rendering 1 percent of them unusable, and destroying at least one student's thesis." Later a news report appeared in The New York Times that claimed, "Buried within the code of the virus . . . was an apparent ransom demand. Computer users were asked to send $2,000 to an address in Pakistan to obtain an immunity program." But that wasn't quite true. Researchers using specialized software were later able to call up the actual operating program of the virus onto a computer screen. Within the mass of instructions that controlled the bug, they found the following message: WELCOME TO THE DUNGEON (C) 1986 BASIT & AMJAD (PVT) LTD. BRAIN COMPUTER SERVICES 730 NIZAB BLOCK ALLAMA IQBAL TOWN LAHORE--PAKISTAN PHONE: 430791, 443248, 280530. BEWARE OF THIS VIRUS . . . CONTACT US FOR VACCINATION . . . 86 APPROACHING ZERO There was no ransom demand. Computer researchers now know the virus as Brain, though at the time it didn't have a name, and it was later discovered to have been programmed only to infect the first sector on a diskette. Diskettes are divided into sectors invisible to the naked eye, each holding 512 bytes (or characters) of information, equivalent to about half a page of typewritten material. The first sector on a diskette is known as the boot sector, and its function is something like that of the starter motor on a car: it kicks the machine into operation (hence the expression "booting up," or starting up, a computer). When a computer is switched on, the machine bursts into life and carries out some simple self-diagnostic tests. If no fault is found, the machine checks to see if there is a diskette in the disk drive. The disk drive, acting like a record player with the diskette as its record, begins to rotate if a diskette is in place, and the boot sector of the diskette directs the computer to the three actual start-up programs that make the computer operational. The Brain virus was designed to hide in the boot sector waiting for the computer to start up from the diskette so that it can load itself into the computer's memory, as if it were a legitimate startup program. But at around 2,750 bytes long, it is much too big to fit entirely within the boot sector, and instead does two things: it places its first 512 bytes in the boot sector and then stores the rest of its code, together with the original boot-sector data, in six other sectors on the diskette. When the computer starts up, the head of the virus jumps into memory, then calls up its tail and the original boot sector. Brain is one of the most innocent viruses imaginable, though that wasn't known at the time. The University of Delaware spent a full week and considerable manpower cleaning out its computer system and destroying infected diskettes, only to find that the virus's payload is simply the tagging of infected diskettes with the label "Brain." A label is the name a user can give to a diskette, and is of no real importance. Most users don't even bother to label their diskettes, and if a virus suddenly names it for them, thev are unlikelv to notice or care. However, like all viruses, Brain can cause unintended damage. If a diskette is almost full, it is possible for some sectors to be identally overwritten while the virus is attaching its tail, ~ereby wiping out all the data contained there. Also, copying can render the virus unstable, and could unintentionally overwrite ystems areas (the sectors on diskettes that enable their use by Computers), thus rendering them useless. Paramount to the viability of a computer virus is an effective infection strategy. Brain was viable because it didn't do anythingdeliberately dangerous or even very obvious, so it wasn't likely to get noticed. Therefore, when it climbed into the computer memory, it could stay there until the computer was switched off targeting any other diskettes that were introduced into the com- puler during that session. Brain also contained a special counter, which permitted it to infect a new diskette only after the computer operator had accessed it thirty-one times. Thereafter, it infected at every fourth use. Yet another, particularly ingenious, feature was its ability to evade detection. Normally the boot sector, where the virus hides, can be read by special programs known as disk editors. But if someone tried to read the boot sector to look for it, Brain redirected them to the place where the original boot sector had been stored, so that everything looked normal. This feature, which now takes other forms, has become known as stealth, after the Stealth bomber that was designed to evade radar detection. It wasn't difficult to trace the writers of Brain, since they had conveniently included their names, telephone numbers, and address on their virus. The programmers were nineteen-year-old Basit Farooq Alvi and his twenty-six-year-old brother, Amjad Farooq Alvi. Together they run a computer store in Lahore, Pakistan, called Brain Computer Services. They wrote the virus in 1986, they said, "for fun," and it was in all probability the first virus ever to be disseminated internationally. Shortly after writing Brain, Basit had given a copy of the virus to an unidentified friend, and it traveled from Pakistan to North America via an unknown route, finally reaching the University of 88 APPROACHING ZERO