154 APPROACHING ZERO erably older than the 150 or so adolescent Olivers she gathered into her ring. As a woman, she has the distinction of being one of only two or three female hackers who have ever come to the attention of the authorities. In 1989 Doucette lived in an apartment on the north side of Chicago in the sort of neighborhood that had seen better days; the block looked substantial, though it was showing the first signs of neglect. Despite having what the police like to term "no visible means of support," Doucette was able to provide for herself and her two children, pay the rent, and keep up with the bills. Her small apartment was filled with electronic gear: personal computer equipment, modems, automatic dialers, and other telecom peripherals. Doucette was a professional computer criminal. She operated a scheme dealing in stolen access codes: credit cards, telephone cards (from AT&T, MCI, Sprint, and ITT) as well as corporate PBX telephone access codes, computer passwords, and codes for voice-mail (VM) computers. She dealt mostly in MasterCard and Visa numbers, though occasionally in American Express too. Her job was to turn around live numbers as rapidly as possible. Using a network of teenage hackers throughout the country, she would receive credit card numbers taken from a variety of sources. She would then check them, either by hacking into any one of a number of credit card validation computers or, more often, by calling a "chat line" telephone number. If the chat line accepted the card as payment, it was live. She then grouped the cards by type, and called the numbers through to a "code line," a hijacked mailbox on a voice-mail computer. Because Doucette turned the cards around quickly, checking their validity within hours of receiving their numbers and then, more importantly, getting the good numbers disseminated on a code line within days, they remained live for a longer period. It was a very efficiently run hacker service industry. To supplement her income, she would pass on card numbers to members of her rin~ in other cities, who would use them to buy Western Union money orders payable to one of Doucette's aliases. The cards were also used to pay for an unknown number of airline tickets and for hotel accommodation when Doucette or her accomplices were traveling. The key to Doucette's business was communication--hence the emphasis on PBX and voice-mail computer access codes. The PBXs provided the means for communication; the voice-mail computers the location for code lines. PBX is a customer-operated, computerized telephone system, providing both internal and external communication. One of its features is the Remote Access Unit (RAU), designed to permit legilimate users to call in from out of the office, often on a 1-800 nunlher. and access a long-distance line after punching in a short co~e Oll the telephone keypad. The long-distance calls made in this way are then charged to the customer company. Less legitimate users-- hackers, in other words--force access to the RAU by guessing the code. This is usually done by calling the system and trying different sequences of numbers on the keypad until stumbling on a code. The process is time-consuming, but hackers are a patient bunch. The losses to a company whose PBX is compromised can be staggering. Some hackers are known to run what are known as "call-sell" operations: sidewalk or street-corner enterprises offering passersby cheap long-distance calls (both national and international) on a cellular or pay phone. The calls, of course, are routed through some company's PBX. In a recent case, a "callsell" operator ran up $1.4 million in charges against one PBX owner over a four-day holiday period. (The rewards to "call-sell" merchants can be equally enormous: at $10 a call some operators working whole banks of pay phones are estimated by U.S. Iaw enforcement agencies to have made as much as $10,000 a day.) PBXs may have become the blue boxes for a new generation of phreakers, but voice-mail computers have taken over as hacker bulletin boards. The problem with the boards was that they became too well known: most were re~ularly monitored by law 156 APPROACHING ZERO enforcement agencies. Among other things, the police recorded the numbers of access device codes trafficked on boards, and as the codes are useful only as long as they are live--usually the time between their first fraudulent use and the victim's first bill--the police monitoring served to invalidate them that much faster. Worse, from the point of view of hackers, the police then took steps to catch the individuals who had posted the codes. The solution was to use voice mail. Voice-mail computers operate like highly sophisticated answering machines and are often attached to a company's toll-free 1-800 number. For users, voicemail systems are much more flexible than answering machines: they can receive and store messages from callers, or route them from one box to another box on the system, or even send one single message to a preselected number of boxes. The functions are controlled by the appropriate numerical commands on a telephone keypad. Users can access their boxes and pick up their messages while they're away from the office by calling their 1-800 number, punching in the digits for their box, then pressing the keys for their private password. The system is just a simple computer, accessible by telephone and controllable by the phone keys. But for hackers voice mail is made to order. The 1-800 numbers for voice-mail systems are easy enough to find; the tried-and-true methods of dumpster diving, social engineering, and war-dialing will almost always turn up a few usable targets. War-dialing has been simplified in the last decade with the advent of automatic dialers, programs which churn through hundreds of numbers, recording those that are answered by machines or computers. The process is still inelegant, but it works. After identifying a suitable 1-800 number, hackers break into the system to take over a box or, better, a series of boxes. Security is often lax on voice-mail computers, with box numbers and passwords ridiculously easy to guess by an experienced hacker. One of the methods has become known as finger hacking: punching away on the telephone keypad trying groups of numbers until a box and the appropriate password are found. Ideally, hackers look for unused boxes. That way they can assign their own passwords and are less likely to be detected. Failing that, though, they will simply annex an assigned box, changing the password to lock out the real user. VM boxes are more secure than hacker boards: the police, for a start, can't routinely monitor voice-mail systems as they can boards, while hackers can quickly move to new systems if they suspect the authorities of monitoring one they are using. The messaging technology of voice-mail systems lends itself to passing on lists of codes. The code line is often the greeting message of the hacker-controlled mailbox; in other words, instead of hearing the standard "Hello, Mr. Smith is not in the office. Please leave a message," hackers calling in will hear the current list of stolen code numbers. In this manner, only the hacker leaving the codes need know the box password. The other hackers, those picking up the codes or leaving a message, only need to know the box number. It was ultimately a voice-mail computer that led the authorities |~ to Doucette. On February 9, 1989, the president of a real estate | company in Rolling Meadow, Illinois, contacted the U.S. Secret Service office in Chicago. His voice-mail computer, he complained, had been overrun by hackers. The harassed real estate man became known as Source 1. On February 1 5th, two Secret Service agents--William "Fred" Moore and Bill Tebbe--drove from Chicago to the realtor's office to interview him. They found a man beset by unwanted intruders. The company had installed its voice-mail system in the autumn of 1988. The box numbers and passwords were personally asi signed by the company president. While the 1-800 number to i access the system was published, he insisted that the passwords were known only to himself and to the individual box users. In November 1988, during an ordinary review of the traffic on the system, he had been startled to discover a number of unexplained messages. He had no idea what they were about or who they were for; he thought they could have been left in error. 158 APPROACHING ZERO However, the number of "errors" had grown throughout Novem ber and December. By January 1989 the "errors" had become so frequent that they overwhelmed the system, taking over almost all of the voice-mail computer's memory and wiping out messages for the company's business. The Secret Service recorded the messages over a period from late February to March. Listening to the tapes, they realized they were dealing with a code line. The law on access devices prohibits the unauthorized possession of fifteen or more of such codes, or the swapping or sale of the codes "with an intent to defraud." (Fraud is defined as a $1,000 loss to the victim or profit to the violator.) On the tapes, the agents could identify 130 devices that were trafficked by the various unknown callers. They also heard the voice of a woman who identified herself alternatively as "Kyrie" or "long-distance information." It seemed as if she was running the code line, so they decided to focus the investigation on her. In March security officials from MCI, the long-distance telephone company, told the Secret Service that Canadian Bell believed "Kyrie" to be an alias of Leslie Lynne Doucette, a Canadian citizen who had been hacking for six or seven years. In March 1987 Doucette had been convicted of telecommunications fraud in Canada and sentenced to ninety days' imprisonment with two years' probation. She had been charged with running a code line and trafficking stolen access codes. Subsequently, the Canadians reported, Doucette had left the country with her two children. Later that month an MCI operative, Tom Schutz, told Moore that an informant had passed on the word that a well-known hacker named Kyrie had just moved from the West Coast to the Chicago area. The informant, Schutz said, had overheard the information on a hacker "bridge" (a conference call). At the beginning of April an MCI security officer, Sue Walsh, received information from another informant that Kyrie had a Chicago telephone number. By mid-month, Moore was able to get court authorization to attach a dialed-number recorder (DNR), to Doucette's phone. A DNR monitors outgoing calls, recording the number accessed and any codes used. From the surveillance, agents were able to detect a large volume of calls to various voice-mail systems and PBX networks. The authorities traced the other compromised voice-mail systems to Long Beach, California, and Mobile, Alabama. They discovered that Kyrie was operating code lines on both networks. It's not unusual for hackers to work more than one system; sometimes Hacker A will leave codes for Hacker B on a voicemail computer in, say, Florida, while Hacker B might leave his messages for Hacker A on a system in New York. By rotating through voice-mail computers in different states, hackers ensure that local law enforcement officials who stumble upon their activities see only part of the picture. The agents also realized that Kyrie was running a gang. From other sources they heard tapes on which she gave tutorials to neophyte hackers on the techniques of credit card fraud. Over the period of the investigation they identified 152 separate contacts from all over the country, all used as sources for stolen codes. Of the gang, the agents noted seven in particular, whom they identified as "major hackers" within the ring: Little Silence in Los Angeles; the ironically named FBI Agent in Michigan; Outsider, also in Michigan; Stingray from Massachusetts; EG in Columbus, Ohio; Navoronne, also from Columbus; and Game Warden in Georgia.4 DNRs were also attached to their telephones. The agents assigned to the case described the group, imaginatively, as "a high-tech street gang." By then the Secret Service had turned the enquiry into a nationwide investigation involving the FBI, the Illinois State Police, the Arizona Attorney General's Office, the Chicago Police Department, the Columbus (Ohio) Police Department, the Cobb County (Georgia) Sherifrs Office, the Royal Canadian Mounted Police, and the Ontario Provincial Police. Security agents from MCI, Sprint, AT&T, and nine Bell phone companies provided technical assistance. 160 APPROACHING ZERO On May 24th the Secret Service asked local authorities in six cities for assistance to mount raids on Doucette's Chicago apart ment and the addresses of the five other major hackers in the ring. Prior to the raids the authorities compiled a list of equipment that was to be seized: telephones and speed-dialing devices; computers and peripherals; diskettes; cassette tapes; videotapes; records and documents; computer or data-processing literature; bills, letters invoices, or any other material relating to occupancy; informa- tion pertaining to access device codes; and "degaussing" equipment.5 The raid on Doucette's Chicago apartment produced a lode of access codes. Moore found a book listing the numbers for 171 AT&T, ITT, and other telephone cards, as well as authorization codes for 39 PBXs. In addition, the agents found numbers for 118 Visa cards, 150 MasterCards, and 2 American Express cards. Doucette admitted that she was Kyrie. Later in the Secret Service offices, she confessed to operating code lines, trafficking stolen numbers, and receiving unauthorized Western Union money orders. She was held in custody without bond and indicted on seventeen counts of violating rederal computer, access device, and telecom fraud laws between January 1988 and May 1989. Estimates of the costs of Doucette's activities varied. On the day of her arrest, she was accused of causing "$200,000 in losses . . . by corporations and telephone service providers." Later it was announced that "substantially more than $1.6 million in losses were suffered" by credit card companies and telephone carriers. Doucette's was a high-profile arrest, the first federal prosecution for hacking voice-mail systems and trafficking in access devices. The prosecution was determined that she would be made an example of; her case, the authorities said, would reflect "a new reality for hackers" in the 1990s--the certainty of "meaningful punishment." If convicted of all charges, Doucette faced eightynine years' imprisonment, a $69,000 fine, and $1.6 million in restitution charges. The case was plea-bar~ained. Doucette admitted to one count; the other charges were dismissed. On August 17, 1990, Doucette, then aged thirty-six, was sentenced to twenty-seven months in prison. It was one of the most severe sentences ever given to a computer hacker in the United States.6 Willie Sutton, a U.S. gangster, was once asked why he robbed banks. "Because that's where the money is," he replied. Little has changed; banks still have the money. Only the means of robbing them have become more numerous. Modern banks are dependent on computer technology, creating new opportunities for fraud and high-tech bank robbery. Probably the best-known story about modern-day bank fraud involves the computation of "rounded-off" interest payments. A bank employee noticed that the quarterly interest payments on the millions of savings accounts held by the bank were worked out to four decimal points, then rounded up or down. Anything above .0075 of a dollar was rounded up to the next penny and paid to the customer; anything below that was rounded down and kept by the bank. In other words, anything up to three quarters of a cent in earned interest on millions of accounts was going back into the bank's coffers. Interest earned by bank customers was calculated and credited by computer. So it would be a simple matter for an employee to write a program amending the process: instead of the roundeddown interest going back to the bank, it could all be amalgamated in one account, to which the employee alone had access. Over the two or three years that such a scam was said to have been operational, an employee was supposed to have grossed millions, even billions, of dollars. The story is an urban legend that has been told for years and accepted by many, but there has not been a single documented case. However, it certainly could be true: banks' dependence on computers has made fraud easier to commit and harder to detect. Computers are impersonal, their procedures faster and more anonymous than paper-based transactions. They can move 162 APPROACHING ZERO money around the world in microseconds, and accounts can effortlessly be created and hidden from a computer keyboard. Like any corporate fraud, most bank fraud is committed by insiders, employees with access to codes and procedures who can create a "paper trail" justifying a transaction. In such cases the fraud is not really different from illegal transactions carried out in the quill-pen era: the use of a computer has simply mechanized such fraud and made it more difficult to track. The new threat to banks comes from hackers. In addition to the familiar duo of the bank robber and the criminal employee--the one bashing through the front door with a shotgun, the other sitting in the back room quietly cooking the books--banks now face a third security risk: the adolescent hacker with a PC, a modem, and the ability to access the bank's computers from a remote site. Unlike traditional bank robbers, hackers don't come through the front door: they sneak in through the bank's own computer access ports, then roam unseen through the systems, looking for vulnerable areas. Unlike crooked employees, hackers aren't a physical presence: they remain unseen and undetected until it's too late. Though banks spend millions protecting their computer systems from intruders, they aren't necessarily that secure. Bank employees, particularly those who work in dealing rooms, are notorious for using the most obvious passwords, generally those that reflect their own ambitions: Porsche and sex are perennial favorites. Sometimes even the most basic security precautions are overlooked. Recently two hackers demonstrated this point for a London newspaper. They targeted the local headquarters of "a leading American bank" one that was so well known for its laxity that its systems had become a training ground for neophyte hackers. The two had first hacked into the bank's computer in March 1988, and in October 1990 the pair did it again, using the same ID and password they had first employed in 1988. The bank hadn't bothered to modify its most basic procedures, and its first line of defense against hackers, for over two and a half years. Given such opportunity, it could be assumed that banks are regularlY being looted by hackers. The mechanics appear straightforward enough: operating from home a hacker should be able to break into a bank's central computer quite anonymously, access the sector dealing with cash transfers, then quickly move the moneY to an account that he controls. However, in practice the procedure is more complex. Banks use codes to validate transfers; in addition, transactions must be confirmed electronically by the recipient of the funds. Because of such safeguards, the plundering is probably limited.' But the threat from hackers is still real. There may be a hundred hackers in the United States with the necessary skills to break into a bank and steal funds, which is a sizable number of potential bank robbers. And of course it would be the dream hack, the one that justifies the time spent staring at a video terminal while learning the craft. The most successful bank robbery ever carried out by hackers mal have occurred two years ago. The target was a branch of Citibank in New York. The identity of the two hackers is unknown, though they are thought to be in their late teens or early twenties. The scheme began when the two became aware that certain financial institutions, including Citibank, used their connections on the various X.25 networks--the computer networks operated by commercial carriers such as Telenet or Sprint--to transfer money.8 (The process is known as Electronic Fund Transfer, or EFT.) The two decided that if the funds could be intercepted in mid-transfer and diverted into another account--in this case, a computer file hidden within the system--then they could be redirected and withdrawn before the error was noticed. The hackers began the robbery by investigating Telenet. They knew that Citibank had two "address prefixes" of its own--223 and 22~on the network; these were the prefixes for the sevendigit numbers (or "addresses") that denoted Citibank links to the 164 APPROACHING ZERO system. By churning through sequential numbers they found a series of addresses for Citibank computer terminals, many of which were VAXen, the popular computers manufactured by DEC. One weekend they hacked into eight of the VAXen and found their way to the Citibank DECNET, an internal bank network linking the DEC computers. From there they found gateways to other banks and financial institutions in the New York area. They ignored the other banks. What had particularly intrigued them were references in the computer systems to an EFT operation run by Citibank: in various files and throughout the electronic mail system they kept turning up allusions to EFT, clues that they were convinced pointed to a terminal that did nothing but transfer funds. They began sifting through their lists of computer access numbers, looking for one among hundreds that belonged to the EFT computer, and by a laborious process of elimination they whittled the lists down to five machines whose function they couldn't divine: Of those, one seemed particularly interesting. It could be entered by a debug port (a computer access port used for maintenance) that had been left in default mode--in other words, it could be accessed with the standard manufacturer-supplied password, because yet again no one had ever bothered to change it. The system they entered contained menus that guided them through the computer. One path took them directly into an administration area used by system operators. After an hour of exploration they found a directory that held a tools package, allowing them to create their own programs. With it, they wrote a procedure to copy all incoming and outgoing transmissions on the terminal into their own file. They named the file ".trans" and placed it in a directory they called "..- -" (dot, dot, space, space), effectively hiding it from view. What they had created was a "capture" file; from the transmissions that were copied, they would be able to divine the functions of the computer terminal. The capture file was created late on a Sunday night. At about nine P-M- on the next evening they logged on to the system again, and from the day's transmissions they could tell that the targeted machine was indeed an EFT terminal. They discovered that the computer began transactions by linking itself to a similar com~puter at another bank, waiting for a particular control sequence to be sent, and then transferring a long sequence of numbers and letters. They captured about 170 different transactions on the first day and several hundred more in the following week. At the end of the week they removed the ".trans" file and its directory, killed the capture routine, and went through the system removing any trace that they had ever been there. From the captured transmissions they were able to piece together the meaning of the control sequence and the transfers themselves. They also noticed that after the Citibank computer had sent its transfer, the destination bank would repeat the transaction (by way of confirmation) and in ten seconds would say TRANSACTION COMPLETED, followed by the destination bank ID. The two guessed that the bank IDs were the standard Federal Reserve numbers for banks (every bank in America that deals with the Federal Reserve system has a number assigned to it, as do several European banks). To confirm the hunch, they called up Citibank and asked for its Federal Reserve number. It was the same as the ID being sent by the computer. The two hackers then realized that they had collected all of the technical information they needed to raid the bank. They had discovered the codes and the procedures for the control sequence and the transfers; they knew what the bank IDs signified; and from the Federal Reserve itself they got a listing of all the national and international bank ID numbers. Now they had to organize the downstream: a secure process of getting money into their own pockets. One of the duo had a friend, an accountant of questionable moral character, who opened a numbered Swiss account under a false name for the two hackers. He had originally laughed at the idea, explaining that an initial $50,000 was required to open a 166 APPROACHING ZERO numbered account. But when he was told to get the forms so that the money could be wired to Switzerland, he began to take the scheme seriously. A few days later the accountant delivered the paperwork, the account number, and several transaction slips. He also raised his usual $1,000 fee to $6,500. The two hackers flew to Oklahoma City to visit the hall of records and get new birth certificates. With these they obtained new Oklahoma IDs and Social Security numbers. Then, using the false IDs, they opened accounts at six different banks in Houston and Dallas, with $1,000 cash deposited in each. The next day, armed with one Swiss and six American accounts, they began the attack. They rigged the Citicorp computer controlling the EFT transfers to direct all of its data flow to an unused Telenet terminal they had previously discovered. They took turns sitting on the terminal, collecting the transmissions, and returning the correct acknowledgments with the Federal Re- serve IDs. The transmissions each represented a cash transfer: essentially, the money was being hijacked. But by sending the required acknowledgments the hackers were giving Citibank "confirmation" that the transactions had reached the destination banks. By noon the two had $184,300 in their limbo account. The two then disabled the "data forwarding" function on the Citibank computer, taking control of the EFT machine themselves so that they could redistribute the captured funds. By altering the transmissions, they transferred the money to the Swiss account. To the Swiss, it looked like a normal Citibank transmis- sion; after all, it had come through the Citibank's own EFT computer. Once the two hackers had received the standard confirmation from the Swiss bank, they immediately filled out six withdrawal forms and faxed them to its New York branch, along with instructions detailing where the funds should be sent. They told the Swiss bank to send $7,333 to each of the six U.S. accounts. (The amount was chosen because it was below the sum requiring notification of the authorities.) They followed the same procedure for three days, leaving the Swiss account with a little over $52,000 remaining on deposit. Over the next week they withdrew $22,000 from each of the Dallas and Houston banks in amounts of $5,000 per day, leaving just under $1,000 in each account. At the end of the week they had each taken home $66,000 in cash. You can believe this story or not as you wish. Certainly Citibank doesn't believe a word of it; it has consistently denied that anything resembling the events described above have ever happened, or that it has lost money in an EFT transfer due to hacking. The only reason anyone knows about the incident is that the two hackers who did it--or say they did--posted the details on a pirate board called Black ICE. The board was used by the Legion of Doom, at one time the most proficient and experienced hacker gang in the United States, and the two hackers-cum-robbers are thought to be LoD members--or at least to consider themselves LoD members. Hackers are generally boastful. They gain credibility by exaggerating their abilities and glamorizing their exploits. It's the issue of identity: just as meek little Harvey Merkelstein from Brooklyn becomes the fearsome Killer Hacker when he gets loose on a keyboard, he also gains points with his peers by topping everyone else's last hack, and robbing a bank would be considered a pretty good hack. The report from the two hackers could have been a fantasy, a means of impressing other LoD members. But, if they had managed to pull the robbery off, they would still have wanted to boast about it. And the perfect crime is the one that even the victim doesn't realize has happened. In the report posted on Black ICE, one of the two "bank robbers" wrote, IT WILL BE INTERESTING TO SEE HOW THE CITICORP [CITI- BANK'S PARENT] INTERNAL FRAUD AUDITORS AND THE TREASURY DEPARTMENT SORT THIS OUT. THERE ARE NO 168 APPROACHING ZERO TRACES OF THE DIVERSION, IT JUST SEEMS TO HAVE HAPPENED. CITIBANK HAS PRINTED PROOF THAT THE FUNDS WERE SENT TO THE CORRECT BANKS, AND THE CORRECT BANKS ACKNOWLEDGMENT ON THE SAME PRINTOUT. THE CORRECT DESTINATION BANKS, HOWEVER, HAVE NO RECORD OF THE TRANSACTION. THERE IS RECORD OF CITIBANK SENDING FUNDS TO OUR SWISS ACCOUNT, BUT ONLY THE SWISS HAVE THOSE RECORDS. SINCE WE WERE CONTROLLING THE HOST [THE EFT COMPUTER] WHEN THE TRANSACTIONS WERE SENT, THERE WERE NO PRINTOUTS ON THE SENDING SIDE. SINCE WE WERE NOT ACTUALLY AT A TERMINAL CONNECTED TO ONE OF THEIR LINE PRINTERS, NO ONE SHOULD FIGURE OUT TO START CONTACTING SWISS BANKS, AND SINCE CITIBANK DOES THIS SORT OF THING DAILY WITH LARGE EUROPEAN BANKS, THEY WILL BE ALL TWISTED AND CONFUSED BY THE TIME THEY FIND OURS. SHOULD THEY EVEN GET TO OUR BANK, THEY WILL THEN HAVE TO START THE LONG AND TEDIOUS PROCESS OF EXTRACTING INFORMATION FROM THE SWISS. THEN IF THEY GET THE SWISS TO COOPERATE, THEY WILL HAVE A DEAD END WITH THE ACCOUNT, SINCE IT WAS SET UP UNDER THE GUISE OF A NONENTITY. THE ACCOUNTS IN DALLAS AND HOUSTON WERE ALSO IN FAKE NAMES WITH FAKE SOCIAL SECURITY NUMBERS; WE EVEN CHANGED OUR APPEARANCES AND HANDWRITING STYLES AT EACH BANK. I'M GLAD l'M NOT THE ONE WHO WILL HAVE THE JOB OF TRACKING ME DOWN, OR EVEN TRYING TO MUSTER UP PROOF OF WHAT HAPPENED. NOW WE WON'T HAVE TO WORRY ABOUT DISPOSABLE INCOME FOR A WHILE. I CAN FINISH COLLEGE WITHOUT WORKING AND STILL LIVE IN RELATIVE LUXURY. IT'S KIND OF WEIRD HAVING OVER SIX HUNDRED $100 BILLS IN THE DRAWER, THOUGH. TOO BAD WE CAN'T EARN ANY INTEREST ON IT! Needless to say, the anonymous authors of this report have never been traced. It wasnt until later that anyone in the LoD realized that Black ICF had been compromised. The board had been regularly monitorcd by the authorities, particularly the U.S. Secret Service, as part of a continuing investigation of the LoD, an investigation that was just about to blow open. The authorities tended to take reports of hacker exploits seriously. The various federal agencies, police forces, and prosecutors who had dealt with the computer underworld knew that computer security had been undermined by hacking. Everything was at risk: hackers had entered the military computer networks; they had hacked NASA and the Pentagon; they had compromised credit agencies and defrauded credit card companies; they had broken into bank systems; and they had made the telecom system a playground. But it wasn't just fraud that concerned the authorities. It was now also apparent that some hackers were selling their services to the KGB. Chapter 7 THE ILLUMINATI CONSPIRACY Karl Koch was last seen alive on May 23, 1989. That morning he had turned up to work as usual at the Hannover office of Germany's ruling Christian Democratic party. Just before twelve o'clock he drove off alone to deliver a package across town, but he never arrived. In the late afternoon his employers notified the police of his disappearance. Nine days later the police went to a woods on the outskirts of the small village of Ohof, just outside Hannover, on a routine enquiry. They were investigating a report of an abandoned car, its roof, hood, and windscreen thick with dust. In the undergrowth near the car, the police stumbled on a charred corpse Iying next to an empty gasoline can. The vegetation around the body was scorched and burned. The police noticed that the corpse was barefoot-- but no shoes were found in the car or in the surrounding area. The investigators were perplexed. There had been no rain for five weeks, and the undergrowth was as dry as matchwood. But the scorched patch around the body was contained, as if the fire that consumed the victim had been carefully controlled. The body was later identified as that of the twenty-four-yearold Karl Koch. The police assumed he had committed suicide. But still there were questions: principally, if Koch had killed himself, how had he been able to control the fire? Why had it not spread outside the confined perimeter? Then there were the shoes: Koch had obviously been wearing shoes when he left his office. If he had taken them off, what had he done with them? It seemed as if someone had taken them. But there were no clues to a killer, and the death was deemed to ke suicide. Four years previously Karl Koch had been the first hacker in Germany recruited by agents working for the KGB. At the time he was living in Hannover, a dropout from society and school who had recently squandered the small inheritance he had receivcd following the death of his parents. A small-time drug habit helped him through his bereavement, and beyond, but his life was going nowhere. Apart from drugs, Koch's only interest was hacking. His handle was Hagbard, an alias taken from the Illuminati trilogy by Robert Shea and Robert Anton Wilson. According to the books, the Illuminati is a secret cult that has been in existence since the beginning of time and has orchestrated every major crime, misfortune. and calamity. Only one man had ever emerged who could fight the cult: the hero, Hagbard Celine. Koch was drawn by the conspiracy theories nurtured in the books; he believed there were parallels in real life. That year Koch met an older man named Peter Kahl. Kahl was then in his mid-thirties, a small-time fixer who was looking for a big break. He worked nights as a croupier in a Hannover casino and during the day was occupied with putting together his latest scheme. Kahl's idea was simple: he planned to recruit a gang of hackers who could break into West European and American computer systems, particularly those on military or defense-industry sites. Then he would sell the data and information they had gathered to the KGB. Kahl first encountered Koch at a hacker's meeting in Hannover. The young man seemed an ideal recruit: malleable, drifting, amoral. Later, when Kahl explained his scheme to Koch, the 172 APPROACHING ZERO hacker appeared receptive. Two weeks later Koch agreed to become a member of the Soviet hacker gang. In 1985 the computer underworld was a growing force in Germany. Hacking had become prevalent at the beginning of the decade, as low-cost personal computers became increasingly available. It had grown in popularity with the release of War Games--the 1983 film in which Matthew Broderick nearly unleashes the next world war by hacking into NORAD which proved peculiarly influential in Germany. By the mid-1980s the Germans were second only to the Americans in the number of hackers and their audacity. The national computer networks had all been compromised; German hackers would later turn up on systems all over the world. The growth of the computer underworld was nurtured by sustained media coverage and the quasi-institutionalization of hacking. Nearly everything in Germany is organized, even anarchy. So, in a parody of Teutonic orderliness, hackers assembled into clubs: there was the BHP (the Bayrische Hackerpost) in Munich, Foebud-Bi in Bielefeld, Suecrates-S in Stuttgart, and HICop-CE (the Headquarters of the Independent Computer-Freaks) in Celle. Of course the most famous and best-organized of all was the Chaos Computer Club in Hamburg. Since its inception in 1981, it had spawned affiliates in other towns and cities, even a branch in France, and in 1984 hosted the first of its annual confer- ences, an event that served to keep the Chaos name in the press. In between the annual congresses, Chaos also held smaller hacker meets at the various computer conventions held around Germany. Whatever the event, the venue for the hacker meet was always next to the stand occupied by the Bundespost, the German Post Office, and the time was always four P.M. on the first Tuesday of the exhibition. Chaos was never a huge organization--even now it only has about 150 registered members--but it is very accomplished at self-promotion and zealous in disseminating information on hacking. It publishes a bimonthly magazine, Die Datenschleuder (literally, "the Distribution of Data by Centrifuge") with sixteen to twenty pages an issue. It also promotes Die Hackerbibel ("The Hacker Bible"), a two-part set of reference books detailing hacker techniques. Chaos first came to the notice of the general public in 1984, ~hen it hacked into the German computer information system, ,tx (Bildschirmtext).' Like all telephone and data services in Jermany, the system is run by the Bundespost, an unloved, lureaucratic institution that is obsessive in its attempts to control Jl national telecommunications links. The company added to its ~popularity with hackers when it began licensing telephone anwering machines and regulating the use of modems. At first, Chaos was just another "information provider" on ~tx. Subscribers to the service could dial up and read pages of nformation supplied by Chaos on their home computers. Users vere charged at a premium rate for the calls, with proceeds shared etween the Bundespost and Chaos. This seemed a good recipe or making money--until one of the computer wizards at Chaos liscovered that security on the system was hopelessly weak. He lized that if a hacker broke into Btx, he could get hold of the laos ID and password (used by the club to access and update ule information on its pages), then dial up other services and ~ddle Chaos with the cost. With a minimum of 10 marks per call, bout $6.80, the amount involved could soon become astronomi- Chaos's founder, Wau Holland, and a younger member of the club, Steffen Wernery, then aged twenty-two, decided to go public with the discovery. The two contacted Hans Gliss, the managing editor of the computer security journal Datenschutz-Berater ~"Data Security Adviser"). Gliss invited Holland and Steffen to attend an upcoming conference on data security and present their information. But at the meeting Bundespost representatives disputed the club's claims, unwisely stating that its Btx security was impenetrable. It was the cue for Chaos to demonstrate otherwise. 174 APPROACHING ZERO The Chaos team hacked into the Btx system and into the account of their local savings bank, the Hamburger Sparkasse. They then introduced a computer program they had written, causing the bank to call up the Chaos Btx pages repeatedly over a ten-hour period. The program was simple: it merely called the Chaos Btx number, waited for an answer and then hung up. Over and over again. After ten hours, the bill for the bank came to almost $92,000. But although the bill was never presented, the ensuing publicity carefully orchestrated by Chaos through the German press agency--forced the Bundespost to improve its computer security, and Holland and Steffen became national heroes. The publicity increased Chaos's notoriety; its first annual congress was organized as a result of the coverage engendered by the Btx hack. Chaos became a byword for high-tech mischief, and its congresses became an important breeding ground for the German computer underworld. These congresses were always held during the week after Christmas at the Eidelstedter Burgerhaus on Hamburg's Elbgaustrasse. The events lasted for three days, and press and visitors were welcome, provided they paid the entrance fee. In 1985 one of the paying visitors was Karl Koch. Steffen remembers seeing him there and being introduced briefly. He is also certain that they also met on one other occasion, at a hacker conference at an exhibition in Munich. Koch was an unmistakable figure: tall, emaciated, and invariably spaced out. For the next three years their lives would crisscross in a complex dance. If Koch had seen the pattern, he would have understood. It was the Illuminati, faceless, unknown, all-powerful, conspiring to take cs)ntrol of Steffen's life. Koch's purpose in visiting the 1985 Chaos congress was to seek out certain information on computer systems and networks. Despite his years of practice, he himself was a second-rate hacker. He had come to realize that he was not a born computer wizard; he needed assistance. He was coming under increasing pressure from Kahl to find and copy classified material from computers in the West, and his money was running out just as his dependency on drugs was increasing: from the relatively harmless hashish favored by many hackers, he had graduated to LSD and cocaine. At first the Soviets had seemed incredibly naive: Koch was able to pass Kahl public-domain software, programs he had simply downloaded for free from electronic bulletin boards. The KGB had accepted the software, and Koch had received payment. It seemed very simple, and he assumed he wasn't doing anything illegal: after all, public-domain software is freely available to anyone who wants it. But then the Soviets became more demanding. The KGB had produced lists of programs it wanted to obtain and sites it wanted cracked. They also wanted dial-ups, user IDs, passwords, and instructions on how to gain system-operator privileges in computer systems. In short, the KGB wanted to learn how to become hackers. The Soviet secret service's list of sites included the Pentagon, NORAD, the research laboratories at Lawrence Livermore and Los Alamos, Genrad in Dallas, and Fermilab in Illinois, as well as MIT, Union Carbide, and NASA's Jet Propulsion Laboratory. It was a shopping list of top-secret defense contractors and installations. The list continued with names of companies in the U.K. and Japan. The KGB stipulated that it was interested in micro- electronics projects for military and industrial purposes--specifically in programs for designing megachips, the electronic brains that were responsible for the military strength of the Western allies. Two French companies in particular attracted the KGB's attention: Philips-France and SGS-Thomson, both known to be involved in megachip research. Koch knew that on the sites picked by the KGB he would be confronted with VAX computers, which were made by DEC, but he had no experience with VMS, the proprietary operating system used by VAXen. It was VAX expertise he was hunting for at the Chaos congress: someone to make up for the skills he lacked. 176 APPROACHING ZERO It was lucky, then, that he met a seventeen-year-old hacker from West Berlin named Hans Hubner. Hubner, a tall, slender young man with the paleness that comes from staring at a computer screen too long, had been fascinated by computers since he was a child. He was also addicted to an arcade game that involved a little penguinlike character called Pengo. He liked it so much that he adopted Pengo as his handle. When he met Koch, Pengo was unemployed and desperately needed money. He also shared Koch's liking for drugs, but more important, he had experience with VMS. Since 1985 he had been playing on Tymnet, an international computer network run by the American defense contractor McDonnell Douglas, and had learned to use the VAX default passwords--the standard account names that are included with the machines when they're shipped out from the manufacturer. Pengo was also one of the first German hackers to break into CERN, the European Nuclear Research Center in Geneva, Switzerland, and was a caller to the Altos bulletin board in Munich--where, coincidentally, he had met Fry Guy, the Indiana hacker. Koch befriended the young Berliner, invited him to Hannover, and introduced him to Peter Kahl. Before long Pengo had become the second member of the gang, operating from what was then West Berlin, while Koch continued his activities in Hannover. Kahl later involved a contact in West Berlin, Dirk Brescinsky, whose job it became to run Pengo. Koch and Pengo had some early successes hacking into VAX machines. They discovered that DEC's Singapore computer center was exceptionally lax about security. From there they were able to copy a VMS program called Securepack, which allowed system managers to alter user status. It was a useful piece of software for the KGB. But it wasn't military data. To get into defense sites, Pengo and Koch knew they needed to find a more certain way into VAXen. They didn't have long to wait: within six months security on VAX systems worldwide would be blown wide open. Steffen Wernery became entangled in the conspiracy because of his peripheral involvement in compromising VAX security. In the autumn of 1986 Hans Gliss, the editor of Datenschutz-Berater who had been so helpful to Chaos over the Btx affair, contacted Steffen. Gliss needed help and told the young hacker the following story: Gliss had been working as a consultant for SCICON, one of the largest computer software companies in Germany. SCICON had been awarded a lucrative contract by the government for work that was "very important, high security, requiring maximum reliability." It involved three networked VAX computers in three locations, with the head office in Hamburg. During the final phase of testing SCICON was contacted by a computer manager in northern Germany and asked to explain the messages--short bursts of characters and digits in no discernable order--that had been seen on his computers. From the computerized routing information it was clear that the messages were emanating from SCICON in Hamburg, but they made no sense to him or anyone at his institute, or to anyone at SCICON. The SCICON researchers checked through their security logs--computer files that record all the comings and goings of users on the system--and quickly realized that the dated and timed messages had all been originated "out-of-hours," at times when no authorized users would be active. Further investigation showed that some new user IDs and passwords had been added to their system that no one could account for. The implications, Gliss said, were all too obvious: hackers had penetrated SCICON security and were using their computers as a launching pad to other systems. What Gliss now needed to know was if Steffen had any idea who might be involved. If SCICON couldn't guarantee the security of the system, the entire contract with the German government would be at risk. Gliss needed to find out who the hackers were, how they got on, and how to stop them. Contacting Steffen 178 APPROACHING ZERO was a long shot, but he was a leading member of Chaos and knew most of the hackers in Germany. Perhaps he could make some calls. Steffen thought about it: He reasoned that because the hackers were breaking into the SCICON site in Hamburg, they were probably based in the city. It made sense to call a nearby computer; that way the phone bills were cheaper. Two days later he called Gliss and said that he had identified the hackers--two Hamburg students. They had agreed to meet Gliss and help--provided that he promise not to prosecute, so Gliss gave his word. Later that week he met the two students, code-named Bach and Handel,2 in Hamburg. Their story was worrying: the two students had exploited a devastatingly simple flaw in the VMS operating system used on VAX. The machines, like most computer systems, required users to log in their ID and then type their password to gain access. If the ID or the password was wrong, the VMS system had been designed to show an "error" message and bar entry. But the two hackers told Gliss that if they simply ignored all the "error" messages, they could walk straight into the system--provided they continued with the log-on as though everything was in order. When confronted with the "error" message after keying in a fake ID, they would press Enter, which would take them to the password prompt. They would then type in a phony password, bringing up a second, equally ineffectual "error" message. By ignoring it and pressing Enter again, they were permitted access to the system. It was breathtakingly easy, and left the VAX open to any hacker, no matter how untalented. For SCICON staff the situation was disastrous. To deliver their contract on time, they would need to find the flaw in the operating system and fix it. At first they turned to DEC for help, but with time running out, SCICON's programmers began looking for a solution themselves, tearing apart the VAX operating system line by line. They were looking for a bug in the program that would prevent it from operating correctly,3 or an omission in the commands that would allow hackers to simply ignore the "error" message. To the SCICON team's surprise, they didn't find one. What they discovered instead was a piece of program code that appeared to have been deliberately added to the operating system to provide the secret entrance. To the SCICON researchers it looked like a deliberate "back door." Back doors are often left in computer programs, usually to facilitate testing. Generally, they allow writers of things like computer games to jump quickly through the program without having to play the game. For example, in the mid-1980s a game called - Manic Miner involved maneuvering a miner level by level from the depths of his mine up to the surface, the game becoming progressively harder at each level. The programmer whose job it was to test the game needed a shortcut between levels, so he introduced back doors that would take him directly to any one of his choosing. Inevitably, some players stumbled onto the hidden routes, which--ironically--increased the game's popularity. Often back doors, or "cheat modes," are deliberately built into games, encouraging the player to try to break the rules. Some computer magazines give tips on how to find the cheat modes; some games, such as the popular Prince of Persia, are said to be impossible to win without using them. Back doors might also be introduced for more mercenary reasons: legend has it that programmers include back doors on arcade games they create, and then supplement their incomes by playing the games at venues such as nightclubs and casinos, which offer prizes. Some arcade back doors are well known. Occasionally, players stumble across them by making some noninstinctive move: for example, on certain computer gaming machines the instinct is to "hold" two lemons (if three lemons wins a prize) and then spin for the third lemon. But this strategy almost never wins. However, if the player doesn't hold the two lemons and simply respins, the three lemons will automatically come up. On another arcade i80 APPROACHING ZERO game, one which offers a sizable jackpot, it is said that the player brave enough to refuse it and start the machine again will be rewarded by winning two jackpots. On a more sophisticated level, back doors are also provided on operating systems for emergencies. Access to these back doors is reserved for the computer manufacturer; procedures for gaining entry to the system from the emergency back doors are highly confidential, highly complex, and not the sort that could be stumbled over by accident. The back door on the VAXen, though, was out in the open. It wasn't simply for emergencies; its security was far too trivial. The VAX operating system, VMS, had been subjected to stringent tests and was supposed to comply with the exacting "orange book" security standards established by the U.S. Department of Defense.4 Under the orange-book testing program, technically qualified intruders attempt to break through the security features of a computer; the tests can take up to six months, depending on the level of security required. It strained belief that VMS could have gone through such testing without the back door being discovered.5 Responding to complaints from its users, DEC issued a "mandatory patch," a small program designed specifically to close the back door, in May 1987. But despite the "mandatory" order, many users didn't bother to install it, and for a short time, VAX computers across the world provided hackers with an open house if they knew about the security gap. Back doors are, of course, deliberate. They aren't simple bugs in the program or errors in the system: they are written by a programmer for a specific purpose. In the case of the VAX back door, the who and why remains mysterious, though it is clear that whoever created it had to have access to the VMS source code, its basic operating instructions. One rather farfetched, though not impossible, idea is that hackers broke into DEC and amended VMS to make it more hospitable. Or perhaps a programmer put the commands in without the knowledge of the company so that he could access VAX machines throughout the world without IDs or passwords. Another more intriguing theory is that the back door was built by the National Security Agency for its own use, though this presupposes that the NSA is in the business of spying on computer users. Yet some people do suppose precisely that. In their view it is a myth that the NSA is interested in protecting computer security. Instead, it may be actively engaged in penetrating computers or more bluntly, hacking--all over the world by exploiting back doors that only the agency knows about. It is likely, though, that had the NSA been involved in the VAX ~cheme, it would have chosen a more devious means of access. Whoever put the back door in, and for whatever purpose, it was probably not intended for Gerrnan hackers. But by 1986, when Koch and Pengo were trawling for information about VAX, the secret of the back door had traveled across the Atlantic and had become known by a small group of hackers in Germany. Bach and Handel, the two students who broke into the SCICON company's VAX, are generally thought to have been among the first to exploit the trick. It was later discovered that their mentor was a student at Karlsruhe University named Steffen Weihruch.6 That same year, Karl Koch made contact with Weihruch as well. He had managed to track down the VAX wizard to Karlsruhe and had prevailed on him to tell him his technique. It wasn't di~lcult: Weihruch was known to be obliging and was rather pleased that his discovery was useful. Weihruch had also perfected a "tool" to make hacking VAXen even easier. The problem with the back door was that it didn't entirely bypass all security checks: a would-be hacker still had to contend with the security log, which collated the IDs of all users as they entered the system. It was this log-- which was kept on a computer file and could be examined by the system operator- -that had alerted SCICON to Bach and Handel. A hacker coming in the back door would be conspicuous because the ID and pass- 182 APPROACHING ZERO word used--the ones entered in the log--could be any combina tion of random characters; they wouldn't necessarily be a real ID and password, and their inclusion in the log was a clear sign of an intrusion. The solution was to capture the identity of legitimate users, especially ones with high privileges. Then hackers could roam through the system secretly, masquerading as authorized users. To this end Weihruch had developed a special tool to capture IDs and passwords as they were entered. This tool--in reality, a program--replaced the real entry screen with a phony, a complete replica that was indistinguishable to a user. On seeing the screen, the unsuspecting user would enter his ID in the normal way, followed by his password. The program captured that information, saving it on a secret file. Then, because it wasn't able to allow entry, the phony screen displayed the message INVALID--PLEASE REENTER. The user would think he had simply miskeyed his password. For his next attempt, the user would be presented with the proper screen; if all was in order, he would be able to gain access. The hacker could then pick up the secret file, containing all the IDs and passwords that it had collected, on his next visit. It was like using traps to catch rabbits, except that the rabbit felt no pain. The program had automated hacking, and with legitimate IDs and the back-door entry system, hacking became simply a matter of finding VAX computers, going in through the back door, leaving the trap program to function until it had captured some legitimate identities, then taking the real IDs and passwords from the file. With the back door and the trap program, Pengo and Koch were able to supply the Soviets with better material. Koch passed Kahl computer log-ins and passwords to military systems. In return, Kahl passed back money. But despite the success with VMS, the KGB was upping the ante again. The Soviets wanted Koch and Pengo to hack into computers that used the UNIX operating system. UNIX was becoming increasingly popular because it could be used on a wide range of computers; many VAX users preferred UNIX to DEC's VMS. much to the computer giant's chagrin. However, neither Koch nor Pengo knew anything about UNIX; they needed to recruit yet another hacker to their team. Once again, Kahl and Koch made the rounds of various hacker meets. and soon found Marcus Hess, who at the time was working for a specialist UNIX systems company in Hannover. He was an ideal choice: local, experienced, and with an addiction almost as potent as drugs--he loved fast sports cars. Now they were three. Hess soon became invaluable; shortly after becoming a member, he was able to download a copy of the UNIX source code. Kahl took it to the Soviets, who seemed irnpressed; they paid Kahl DM25,000, about $16,000, the most he had ever received from them. Hess soon discovered that many American computer users were relaxed about security. Indeed, if their computers contained nothing secret or classified, some U.S. sites actually tolerated an occasional visiting hacker; sometimes system operators would even have time for a chat. In America, the nucleus of the mythical Worldnet, the concept of the "Global Village," where everybody would be friendly neighbors, courtesy of the computer networks, was born. It was easy to forget that computers, which themselves don't contain classified information, can provide entry points to a network with more interesting machines--and that was what Hess was looking for. He soon found a particularly hospitable computer in California, which contained no classified material but did provide a convenient launching pad to other systems. For the cost of a domestic phone call, Hess could hack into the University of Bremen, where computer security was slack, hop across the Atlantic by satellite at the university's expense, and due to the hospitality of the computers at Lawrence Berkeley Laboratories, at the University of California in Berkeley, travel to other sites. Some system operators tolerate hackers, some threaten them, bu~ most don't even know they've got them. Very few actually 184 APPROACHING ZERO chase them: it's a very time-consuming and generally unreward ing task. Clifford Stoll, the system administration manager at Lawrence Berkeley Laboratories, detected the activities of Hess in August 1986, after investigating a seventy-five-cent discrepancy in the accounting records of the lab's computers. (The seventy-five cent fee couldn't be attributed to an authorized user, so the charge had to have been run up by an outsider.) Other system operators might not have bothered, but Stoll was an astronomer by voca- tion and was only filling in time until grant money could be found to allow him to pursue his chosen career. To Stoll, chasing a hacker seemed exciting. Once he had detected Hess, he was faced with the classic dilemma: should he lock him out or watch him? If he were to lock him out, there was a chance that he might sneak in some other way and not be noticed; it was also likely that he might penetrate some other system. Stoll decided to keep a watch, setting up an intricate alarm system that would tip him offwhenever the hacker appeared. On some occasions, he even slept at the lab. His principal intruder was Hess, whom he knew only through his various aliases--but he also noted the presence of both Pengo and Hagbard (Koch) on other occasions. These two, with their interest in the VAXen that used VMS, would not be a major source of worry for Stoll on his UNIX site. It eventually became obvious that Lawrence Berkeley had nothing to interest Hess; it was just a convenient jumping-off place. Stoll tried to make things look a bit more exciting and concocted a "secret" file as bait, and the hacker gobbled it up. Stoll subsequently recounted his experiences in an academic paper ("Stalking the Wily Hacker," 1988) and a best-selling book, The Cuckoo s Egg (1989). He would record the heavy artillery that was eventually wheeled out to deal with his German hackers: the FBI, the CIA and, the superspooks themselves, the National Security Agency. The reaction of the various agencies at first ranged from apathy to annoyance. Stoll was hard-pressed to interest the authorities at all: losses in hacking incidents are generally estimated in nice large numbers, and chasing seventy-five cents seemed like a joke. But ~e persisted, and eventually the authorities became nervous and mounted an operation to catch the intruder. Finding him was a matter of tracing his calls back to their source. However, the calls were routed through several different computer networks, a practice known as network weaving, so that each time the authorities traced the calls back, they realized they had farther to go--from one network to another, across the country, and across the Atlantic. Slowly, the calls were traced back to Germany, down to the University of Bremen, across to Hannover, and eventually to Marcus Hess's address. Under pressure from the Americans, the German authorities arrested and questioned Hess in June 1987. The Germans had little to go on--the loss of seventy-five cents didn't appear to be an extraditable offense--but they decided to tap his phone just in case. But while the police were watching Hess, the Illuminati were moving in on Steffen Wernery. The saga began when Bach and Handel, the two student hack~ers who broke into the SCICON computer, decided to set up a hacker gang known as the VAXbusters. The team used the back~door technique to get into VAX computers throughout Europe ~and North America. They traveled on SPAN, NASA's Space Physics Analysis Network, which links computers involved in physics research around the world. From the ever-obliging Steffen Weihruch they were also able to get a copy of the "trap" program, giving them legitimate identities on the systems they hacked. For ten months the team wandered through VAX sites with impunity. Unlike Koch and Pengo, the VAXbusters weren't spying, nor were they interested in damaging hacked computers. They were just tourists, browsing through the network, looking for sites of interest. 186 APPROACHING ZERO Despite their precautions and their benign intent, no hack is entirely undetectable. In July 1987 the curtain came down on the VAXbusters. Roy Omond, the particularly diligent manager of a VAX system in Heidelberg, discovered from a routine scrutiny of his security logs that he had been hacked. Even though the hack ers had been using legitimate IDs, Omond guessed from the noc- turnal timings that many of the entries in his visitors' book had not been posted by authorized users. Furious, he mounted his own investigation, and by sounding out various people he believed might be in contact with the hackers, he discovered the real names of Bach and Handel. He immediately posted an electronic message to all other users on SPAN, and named the two students involved. Bach and Handel panicked. They assumed they would be prosecuted by the German authorities and called Steffen at Chaos for advice; Steffen who called Hans Gliss, who in turn contacted the Verfassungsschutz, the German secret service.' The agency said it would be interested in talking to the two hackers. Prior to meeting the agents, Bach and Handel prepared a report, dated August 17, 1987, detailing all the installations that had been penetrated by the VAXbusters. The list comprised 135 sites in total, all on SPAN, and included nineteen installations at NASA, including two VAX sites at their headquarters in Washington, D.C., six at the Goddard Space Flight Center, and ten at the Marshall Space Flight Center. It also included a large number of systems at CERN in Switzerland, and others at the European Space Agency in the Netherlands, the Meudon Observatory and the Institut d'Astrophysique in Paris, and various Max Planck Institute sites in Germany. There was a full exchange of information at the meeting, and in return for Bach and Handel's cooperation, the authorities declined to prosecute. The secret service then contacted the CIA in Bonn, as well as NASA, DEC, and other groups that the agency felt should be informed. In the hope of defusing the situation for the VAXbusters, it was decided that their story should be released to the press on September 15th. The delay, it was thought, would give all the affected sites enough time to repair their defenses. Gliss would cover the technical aspects in the Datenschutz-Berater and two journalists who were known to Wernery would handle the media. On the designated day, the journalists told the full story on the evening news; the next morning it made newspaper headlines around the country. A few days later the two journalists had a second chance at the story when it was realized that NASA had still not removed the VAXbusters' programs (the "trap" programs) from its two computers at its Washington headquarters. Nor had it installed the mandatory patches. So another event was staged for German television audiences. This time, in front of the cameras, Bach and Handel broke into the two NASA computers in Washington, D.C., and installed the mandatory patches that DEC had issued four months earlier. It took a matter of minutes in each case. The hackers had fixed the security flaw that NASA could not be bothered to fix for itself. A spokesman for NASA in Washington, D.C., was not impressed. The loophole in the operating system was not a "security flaw," he insisted. The information on the computers was not classified: it was just scientific data, for the use of scientists. The two computers were, he said, "like a public library." The VAXbusters knew differently. With the higher privileges they had been able to manipulate from the multitude of IDs and passwords they had copied, they had the authority of the chief librarian in NASA's library. They had roamed through the offlimits sections of the shelves; one of the files they had copied was a fifty-two-page document outlining the security within the entire NASA computer system. The story, despite the Americans' professed indifference, got heavy play. Steffen found himself on television more than once, explaining the arcana of hacking and his own role in the VAXbuster saga. Eventually the media interest waned; and that, Steffen assumed, was that. He was not aware of the Illuminati. 188 APPROACHING ZERO The French were less phlegmatic than the Americans They had been suffering some "very serious" hacking incidents that had begun in 1986 and were still continuing in 1987. The incidents included the theft and destruction of important programs and data from VAX computers at Philips-France and SGS-Thom son--the two French companies targeted by the KGB. Their total losses, they claimed, reached an astronomical level, some hundreds of millions of dollars. When the French authorities were told about the VAXbusters they became convinced that the German hackers were the culprits. The penetration techniques used on the French VAXen were the same as those described in the August report made by the German secret service. The same back door and the same sort of program to collect legitimate user IDs and passwords were used. At the instigation of the French, Germany's federal police raided the homes of a number of known Chaos Computer Club members in Hamburg on September 27th and 28th, impounding their computer equipment. Ironically, the police overlooked the VAXbusters, who were not Chaos members. To a large extent, Chaos had become a victim of its own publicity: the police, not aware the VAXbusters were a separate group, had simply raided the homes of the most notorious hackers in Germany. It was a case of rounding up the usual suspects--one of whom was Steffen Wernery, who told them about his own role in the matter and of his previous cooperation with the secret service. Within four months the police had completed their investigations. They concluded that Steffen was simply a "switching center"--a conduit for information--and nothing more. Neither he nor the other Chaos members were involved in hacking into the French computers. This information was passed to the French--who didn't believe it. The methods used to hack into the French sites were too similar to the techniques employed by the VAXbusters to be mere coincidence. And even though the gang's list of all the VAX computers it had hacked did not include either Philips-France or SGS-Thomson, the French authorities remained convinced that the trail from the two companies led back to Hamburg. At about the same time, the secret service contacted Hans Gliss about the incidents in France and asked if he could help. Gliss discussed the matter with Steffen, and suggested that they both go to Paris for the forthcoming annual Securicom conference, in March 1988, and present a report on computer security- -particularly VAX security. Securicom was the ideal forum: it attracted the top computer security specialists in the world. Steffen could tell the delegates about the back door on the DEC machines and how to fix it. Steffen acquiesced; he had found the limelight agreeable, and the visit to Securicom would give him another chance to bask in its glow. He arranged to go to Paris with a colleague from Chaos. Gliss would drive to Paris from his holiday home in the south of France. Steffen also offered to meet representatives of Philips-France, one of the companies hit by the unknown hackers. Philips agreed, and asked Steffen to confirm the names so that security passes could be arranged. Steffen arrived at Paris's Orly Airport on March 14th. He approached immigration control and handed his German passport to one of the officers on duty, a woman. She looked at the photo and his name and hesitated. 'There has been a problem," she said. "Please wait a moment." She reappeared a few minutes later with three men in civilian clothing who claimed to be from the Brigade Financiere, France's revenue service. Steffen now suspects that they were from French Intelligence. "Where is your friend?" they wanted to know. His friend, the colleague from Chaos, was coming in later by train. Steffen was immediately concerned: how did they know about his friend? And why should he tell them where he was? Steffen was arrested and taken to the police cells.8 Under French law an investigating judge can order the deten- 190 APPROACHING ZERO tion of a suspect for twenty-four hours and then for an additional twenty-four hours if necessary. During that period the suspect is not allowed to make contact with anyone at all, not even a lawyer. The police began interrogating Steffen: they asked him about Chaos, about the VAXbusters, and about the two sites in France. They also went through his belongings and papers, looking at names and addresses. In his diary they found the Paris contact address for Hans Gliss. Gliss had checked into the Pullman St. Jacques Hotel, having driven up from his house in the Dordogne. When he arrived at the hotel, he found three members of the "Brigade Financiere" waiting for him. Fortunately for Gliss he was with his wife, Ursula, who, seeing her husband arrested and escorted away, started telephoning for help. Gliss was taken to the police station, and his passport was impounded. The police began asking him about the Chaos Computer Club. Gliss, whose French is poor, demanded an interpreter. The police told Gliss they had arrested Steffen- -unnecessarily, as it happens, because Gliss could hear him being questioned in a nearby cell. Gliss was interrogated for two and a half hours before his passport was returned. Half an hour after that he was set free. On his return to the hotel, Ursula told him she had phoned their friends in Paris, who had contacted the German police, who in turn had called the secret service. The agency, it was presumed, had prevailed on the French authorities to release him. Steffen wasn't so lucky. He was held in the police cells for two days, under continuous interrogation. He says he was allowed to sleep for only three to four hours each day. Steffen told them all he knew, including the fact that a full list of computers penetrated by the VAXbusters had been presented to the German authorities and didn't include the two French sites. He also insisted that all Chaos members had stopped hacking. While Steffen was being interrogated, Gliss told the five hundred delegates at Securicom of his experience and of Steffen's incarceration. He also read Steffen's paper, which had been written to help the French improve their computer security. Later he contacted the German authorities on Steffen's behalf, but they were powerless to intervene: the French were holding Steffen as an ' accessory" to the break-ins at Philips-France and SGSThomson. Three times Steffen was brought before a judge, and each time he was remanded in custody for further questioning. The German foreign office discreetly pressured the French government over the case, until finally Steffen's dossier reached the desk of the French president. Mitterand presumably had enough problems: he ordered the German hacker's release. On May 20th, at five minutes past mid~night, Steffen was driven to the airport and unceremoniously ~bundled aboard the night plane to Hamburg. He had spent over F::two months in a French jail. While Steffen was incarcerated in Paris, the real culprits remained in Germany, safely beyond French jurisdiction. Despite the French authorities' suspicions about Chaos and the VAXbusters, despite the raids in Hamburg, it was in reality the Soviet hacker gang-- ensconced in Hannover and Berlin--who had penetrated the sites at Philips-France and SGS-Thomson. They were looking for information on megachip research, just as the KGB had requested. Surprisingly, in view of the importance the French authorities attached to the sites, Pengo remembers them as simple systems to get around in once they had been breached. Koch and Pengo had penetrated the security at Philips-France and SGS-Thomson using the back door and the trap program they had learned about from Weihruch, the Karlsruhe student. It was understandable that the French would blame the VAXbusters: both teams had used the same techniques, having learned them from the same source. Koch and Pengo had downloaded data from the two French 192 APPROACHlNG ZERO companies, and supposedly passed a computer tape to the KGB in East Berlin. Without revealing exactly what was on the tape, Pengo has suggested that it might have contained details of a design program for advanced microprocessors. But although the hackers were able to pass on the French material to their Soviet paymasters, the KGB was again demanding more. By the end of 1987 they wanted information on Western military computer networks, including the operating specifications of the interconnected machines. It appeared that the KGB wanted to infiltrate the military systems. However, the pressure was beginning to tell on Pengo and Koch, and the two had other things on their minds. They were frightened by the arrests of the Chaos members in Hamburg; they felt that it wouldn't be long before the police stumbled over their own operation. And they had also heard about Steffen's interrogation in Paris, which meant that the French were also chasing them. In the summer of 1988 both Pengo and Koch independently approached the authorities, hoping to take advantage of an amnesty provision in German espionage legislation. This provision guaranteed lenient treatment to those who had not previously been under suspicion and now confessed, provided they cooperated fully. The two confessed to espionage, the only offense covered by the amnesty. Paradoxically, confessing to any lesser offense could have resulted in a severer penalty. Both were interrogated regularly and at length by the authorities. By early 1989 the Germans felt that they had enough evidence to support a case against the other members of the Soviet hacker gang. On March 2nd, eighteen people were interrogated and eight arrested. The latter included Hess, Pengo, and Koch, as well as Dirk Brescinsky and Peter Kahl. The others were local hackers caught up in the wide-ranging investigation. All the hackers were released after a few days; Kahl and Brescinsky were dispatched to a high-security prison in Karlsruhe. Pengo and Koch could expect to escape prosecution due to their earlier confessions under the amnesty. Just two months after his arrest Karl Koch would be found dead, his burned body Iying in a wood on the outskirts of Hannover. In January 1990 Marcus Hess, Dirk Brescinsky, and Peter Kahl stood trial in Celle, in northern Germany. Clifford Stoll and Pengo were witnesses for the prosecution. The problem facing the court was establishing proof that anything of value had been sold to the KGB. That was compounded by the fact that the German police had neglected to apply for a judge's consent for the wiretapping of Hess. None of the material they had recorded "just in case" could be admitted in court. Without concrete proof that espionage on any significant scale had actually occurred, the sentences were light. Hess received twenty months plus a fine of about $7,000, Brescinsky fourteen months and about $3,500, and Kahl two years and about $2,000. All the jail sentences were suspended and substituted with probation. Steffen Wernery is now thirty, an intense, outspoken man. He is calm about the man whose activities caused him to spend sixty-six days in a French prison. His ire is reserved for the French authorities, who, he says, have "no regard for people's rights." His time in jail, he says, cost him $68,000 in lost income and legal fees--roughly what the Soviet hacker gang earned in total from the KGB. But he doesn't blame Koch, and he doesn't believe that he committed suicide either: Suicide did not make sense. It was unbelievable. Karl Koch had disclosed himself to the authorities and had cooperated fully. He had provided them with some good information and they had found him accommodations and a job with the Christian Democratic party. He was also getting help with his drug dependency and seemed on his way to rehabilitation. Murder seemed much more likely than suicide. And there were many people who could have had a motive. 194 APPROACHING ZERO There was much speculation. He was murdered to prevent him testifying; it was a warning to other hackers not to disclose themselves; perhaps it was even to embarrass Gorbachev, who was due for a visit. Or perhaps to protect people in high places. After the unification of Germany the authorities gained access to police files in what had been East Germany. According to Hans Gliss, who maintains close contacts with the intelligence services, there was "a strong whisper" that the Stasi--East Germany's secret service--was responsible for Koch's death. The motive remained a mystery, though there were any number of arcane theories: that the agency was jealous of Koch's ties to the KGB; that they were protecting the KGB from a source who was proving too talkative; that they wanted to embarrass the KGB; that they had also been getting information from Koch, and so on. The Staatssicherheit, or Stasi, has acquired a formidable reputation. Its foreign service, led by the legendary Marcus Wolf, was reported to have planted thousands of agents in West Germany's top political and social circles, most notoriously Gunther Guillaume, who became private secretary to Chancellor Willy Brandt. The revelation caused the fall of the Brandt government. The Stasi has become a convenient villain: since the collapse of East Germany the shadowy secret service's reputation for skulduggery has grown to mythic proportions. In mysterious cases, such as the death of Karl Koch, the sinister hand of Stasi will be detected by all those who want to see it. Nonetheless, murder can't be ruled out. There is the evidence--the missing shoes, the controlled fire--that suggests that another party was involved in Koch's death. Then there is the motive. Koch had little reason to kill himself. He had a job; he was getting treatment for his drug problem. He was in no danger of being prosecuted for his part in the "Soviet hacker" affair: like Pengo, he would have been a witness for the prosecution, protected from punishment by the terms of the amnesty provision. After the trial he would have resumed his life (like Pengo, who is now married and living in Vienna). Some who knew Koch think the young hacker got in over his head. He, Pengo, and Hess were pawns in the espionage game, amateur spies recruited by the Soviets to break into Western computers. It is now thought possible that the Soviets were running other hackers at the same time, testing one gang against the other. For the KGB, it was low-risk espionage: they paid for programs, documents, and codes that would otherwise have been inaccessible--unless of course their own operatives were prepared to sit for days or even weeks in front of a computer, learning the rudiments of hacking. It was an opportunistic intelligence-gathering operation. The Soviet hacker gang had quite literally walked through the KGB's front door, offering to sell military secrets. Given that the agency paid $68,000 for the data, it must be assumed they were satisfied with what they had received. Espionage is a curious trade. Those who claim to know how intelligence agencies work say that computer penetration has become a new and useful tool for latter-day spies. The Americans are said to be involved, through the NSA, as are the British, through GCHQ, the General Communications Headquarters, which gathers intelligence from diverse sources. Hacking, at this rarefied level, becomes a matter of national security. Of course the Americans and the British aren't the only ones suspected of involvement. Mossad, the Israeli secret service, is said to have penetrated the computer systems of French defense contractors who had sold weapons to its enemies in the Middle East. The Israeli service then altered some of the data for the weaponry, rendering it vulnerable to their own defense systems. In this case, the Israelis may have been merely copying the French. During the Gulf War it was widely reported that certain ~rench missiles--the Exocets, which had previously been sold to the Iraqis--included back doors to their computer guidance sys- 196 APPROACHING ZERO tems. These back doors would allow the French military to send a radio signal to the Exocets' on-board computers, rendering the weapons harmless. The scheme, neat as it appears, was never put to the test. The Iraqis never used their Exocets during the conflict--perhaps because they, too, had heard the stories. On the other hand, the entire scenario could well have been French disinformation. It was in this murky world of spying and double-cross that the Soviet hacker gang found itself. In the wider sphere of international and industrial espionage the Germans were ultimately only minor irritants. The technology now exists to access the computer systems of competitors and rivals, and it would be naive to presume that these methods are not being used. It is possible, for instance, to read a computer screen with a radio signal from a site hundreds of feet away. And, during the Cold War, a small truck believed to be equipped with such a device was shipped from Czechoslovakia to Canada. It entered the United States under the guise of diplomatic immunity and traveled, in a curious and indirect way, to the Mexican border. The route took the van close to a sizable number of American defense installations, where the driver would stop, often for days. It was assumed by the small army of federal agents following the truck that it was homing in on computer screens on the bases and sending the material on to the Soviet Embassy in Washington. It's not known if the Czechs and the Soviets found any information of real value, but with the increased use of technology, and the vulnerability of networked computer systems, it is probable that corporations and governments will be tempted to subvert or steal data from rivals. And, under these circumstances, there is inevitably another explanation for the break-in at Philips-France and SGS-Thomson. In 1986 and 1987 Mossad was becoming increasingly worried about deliveries of French weaponry to Iraq and other Arab states. Some of the electronic components for these weapons were designed at the two companies. The Israelis wanted to destroy or steal the data for these components, and to do so, hacked into the companies' computers, using the same techniques being used by the Germans. Mossad knew that the German hackers would get the blame. Indeed, they knew that Pengo and Koch were wandering about the same computers. But the two Germans wouldn't have destroyed information--that would have drawn attention to their activities; nor did they ever manage to steal anything worth hundreds of millions of dollars. That was Mossad. Koch, with his love of conspiracies, would have appreciated such a theory. The Illuminati--the French police, the KGB, the ~tasi and Mossad--were real after all. Chapter 8 CRACKDOWN The Soviet hacker gang wasn't the only reason for the ~ subsequent U.S. government crackdown on the com.~ ! puter underworld. But the threat of a Communist plot to steal top-secret military data was enough to focus the attention of the previously lethargic investigators. The federal authority's lack of urgency in dealing with what appeared to be a threat to national security had been documented by Clifford Stoll in The Cuckoo's Egg, and the diffidence displayed by the FBI and the Secret Service in that case had caused them a great deal of embarrassment. After Stoll's disclosures, the authorities began monitoring hacker bulletin boards much more closely. One of the boards staked out by the Secret Service was Black ICE, the Legion of Doom's favorite, located somewhere in Richmond, Virginia. On March 4, 1989, two days after the arrest of the Soviet hacker gang, intrigued Secret Service agents recorded the following exchanges: I SAW SOMETHING IN TODAY'S PAPER THAT REALLY BURNS ME, growled a Legionnaire known as Skinny Puppy, initiating a series of electronic messages.' He continued: SOME WEST GERMAN HACKERS WERE BREAKING INTO SYS- TEMS AND SELLING INFO TO THE RUSSIANS. IT'S ONE THING REINa A HACKER. IT'S ANOTHER BEING A TRAITOR. IF I FIND OUT THAT ANYONE ON THIS BOARD HAD ANYTHING TO DO WITH IT, I WILL PERSONALLY HUNT THEM DOWN AND MAKE THEM WISH THEY HAD BEEN BUSTED BY THE FBI. I AM CON- SIDERING STARTING MY OWN INVESTIGATION INTO THIS INCIDENT AND DESTROYING A FEW PEOPLE THE BKA [German federal police] DIDN'T GET. DOES ANYONE CARE TO JOIN ME ON THIS CRUSADE? OR AT LEAST GIVE SUPPORT? CAN I CLAIM AN ACT UPON THESE CREEPS AS LOD VENGEANCE FOR DEFILIN(I THE HACKERS IMAGE? An hour and a half later the Prophet uploaded his response: DON'T FROTH AT THE MOUTH, PUPPY; YOU'LL PROBABLY JUST ATTRACT THE ATTENTION OF THE AUTHORITIES, WHO SEEM TO HAVE HANDLED THIS WELL ENOUGH ON THEIR OWN. TOO BAD THE IDIOTS AT NASA AND LOS ALAMOS COULDN T HAVE DONE THE SAME. HOW MANY TIMES ARE THEY GOING TO ALLOW THEIR SECURITY TO BE PENETRATED? HOW DO YOU THINK THIS IS GOING TO AFFECT DOMESTIC HACKERS? MY GUESS IS, THE FEDS ARE GOING TO RF.AR DOWN ON IJS HARDER. The Highwayman, one of the bulletin board's system operators, suggested, LET'S BREAK INTO THE SOVIET COMPUTERS AND GIVE THE INFO TO THE CIA. I KNOW YOU CAN GET ON A SOVIET PSN [Public Switched Network, the public telephone system] FROM AN EAST CERMAN GATEWAY FROM WEST GERMANY. Other Legionnaires were less patriotic. Erik Bloodaxe said, UAKE MONEY ANY WAY YOU CAN! FUCK IT. INFORMATION IS A VALUABLE COMMODITY, AND SHOULD BE SOLD. IF THERE lS MONEY TO BE MADE, THEN MAKE IT. FUCK AMERICAN SECRETS. IT DOESN'T MATTER. IP RUSSIA REALLY WANTED SOMETHING, THEY WOULD PROBABLY GET IT ANYWAY. GOOD FOR WHOEVER SOLD IT TO THEM! The last message was posted late that same night. THIS GOVERNMENT DESERVES TO BE FUCKED, said the Urvile. I'M ALL FOR A 200 APPROACHING ZERO GOVERNMENT THAT CAN HELP ME (HEY, COMRADE, GOT SOME SE- CRETS FOR YOU CHEAP). FUCK AMERICA. DEMOCRACY lS FOR LOSERS. DICTATORSHIP, RAH! RAH! At this early date there were rumors that Chaos had been involved with the Soviet hackers, even that some of its members had been arrested. One of the Legionnaires tried calling up Altos--the board in Munich that had become an internationa hacker hangout--to find out what was going on, but the board was down due to some sort of technical fault. To the watching Secret Service agents, at least some of the messages suggested that American hackers might well follow in the footsteps of the Soviet hacker gang and go into business selling military or industrial secrets. It was disquieting--even if the characteristic hacker bravado was taken into account. But in reality, the Soviet hacker gang was only a momentary distraction for the Legion of Doom. By the next day the flurry of interest had died out; the bulletin board messages resumed the usual pattern--technical queries; reports on hacking sites; postings about police surveillance, about Secret Service monitoring, about the FBI and the CIA. Black ICE was the LoD's principal board, and was restricted to twenty users (mostly LoD members). It was accessed by remote call forwarding, which kept it- -or so it was believed--one step ahead of the law.2 The name Black ICE came from a novel by the science-fiction writer William Gibson. ICE, for Intrusion Countermeasures Electronics, was a program that kept watch for hackers; when it detected them, it literally "fried their brains"--the deadly "black" countermeasure. The author William Gibson is an icon in the computer underworld, and his imaginative sci-fi thrillers have acquired cult status. In his best-known book, Neuromancer (1984), Gibson created a world he called Cyberspace, populated by computer cowboys who roamed the space's electronic systems. Neuromancer forecast the world of hackers--the networks and communication links that they inhabit--and gave them an alternate, more glamorous identity. The networks became known as Cyberspace, and the hacker became a Cyberpunk. The conceit became common in the late 1980S. The Cyberpunk image complemented the secrecy and role-playing of handles, and it gave a whole new identity to fifteen-year-old computer wizards sitting in front of their computer screens. They weren't just teenagers, or even hackers--they were Cyberpunks, the meanest, toughest technology junkies in the world. The Legion of Doom was the best-known Cyberpunk gang in America; certainly it generated the most press. Like Chaos in ~Germany, the gang was conscious of the publicity value of a sinister, slightly menacing name. One of its members was once asked why they picked it: "What else could we have called our-selves?" he answered. "The Legion of Flower Pickers?" The LoD's origins go back to the summer of 1984, when a hacker named Lex Luthor set up one of the first specialist hacker bulletin boards, based in Florida. It was an elite, invitation-only board, with detailed files on hacking and related crafts, such as social engineering and dumpster diving. The first Legion of Doom had nine members, with handles such as Karl Marx, Agrajag the Prolonged, and King Blotto. The gang has been re-formed three times since. It went into decline when five of the original Legionnaires were busted, but bounced back in 1986 and again in 1988. The latest re-formation took place in late 1990. It was never a large group, and although the original LoD board had more than 150 users, admission to the bulletin board was not the same as gang membership.3 The LoD was the elite of the elite, a sort of inner circle. The real LoD generally hovered between nine and eleven members; it has never had more than twelve at any one time. Between 1984 and January 1992 there were only forty confirmed LoD members in total. The LoD was eulogized by the hacker bulletin PHRACK after one of its periodic demises: 202 APPROACHING ZERO LoD members may have entered into systems numbering in the tens of thousands, they may have peeped into credit histories, they may have snooped into files and buffered [stolen] interesting text, they may still have control over entire computer networks, but what damage have they done? The answer is none--well, almost none. There are the inevitable exceptions: unpaid use of CPU [Central Processing Unit] time and network access charges. What personal gains have any members gained? Again, the answer is none--apart from three instances of credit fraud that were instigated by three separate greedy individuals without group knowledge. The bulletin concluded, "The Legion of Doom will long be remembered as an innovative and pioneering force." But the LoD was not the only group on the electronic block: it had rivals, other high-tech gangs that contested LoD's reputation as the best hackers in Cyberspace. One of these other gangs was MoD--which, depending on whom you ask and what time of day it is, stands for either Masters of Destruction or Masters of Deception or sometimes Mom's on Drugs. The MoD membership was centered in New York; the gang included hackers such as Corrupt, Julio, Renegade Hacker, and, from Philadelphia, the Wing. But LoD's most serious rival was DPAC, a gang with members in both Maryland and New Jersey. The group had taken its name from a Canadian data communications system (a contraction of "Data Packet") and was led, off and on, by a hacker called Sharp. Membership in DPAC varied, but included Remob (after the device that allows phones to be tapped remotely), Meat Puppet, the Executioner, Supernigger, and GZ. Despite the handle, Supernigger wasn't black; and GZ, very unusually, was female. The LoD disparaged the abilities of DPAC members. One of the Black ICE sysops, the Mentor, messaged, SUPERNIGGER AND GZ ARE BOTH BLATANT IDIOTS VIHO LIKE TO SHOOT THEIR MOUTHS OFF. GZ DOES STUFF LIKE HACK MCI FOR DAYS FROM HER HOUSE. The Urvile, though, was less sanguine. In a message to Black ICE, he reported having received a phone call from someone named Mike Dawson, who claimed to be a special agent with the Secret Service, telling him that "We'll be visiting you tomorrow." The Urvile thought the voice sounded too young for a Secret Service agent; he was also bothered that Mike didn't know his address or last name. "Are your parents going to be home tomorrow between two and three?" Mike persisted. "Gee, I guess so." His parents probably would be home, he thought--but at their home, not his. The Urvile, at the time, was a university student and lived in his own apartment. When he asked if the agent knew how old he was, Mike answered, "All will be made apparent tomorrow. The next day the Urvile removed all his notes and files, just in case. But the Secret Service never appeared. "I'm betting five to one odds that it's DPAC, and I don't like it one bit," he said. Ordinarily the Urvile's concerns could be dismissed as just another bout of hacker paranoia. But by 1989 the LoD had become involved in a "hacker war" with DPAC and MoD--a fight for control of Cyberspace, over phone lines and computer tworks, with threatening messages left on bulletin boards or swering machines. In one case, an LoD member who worked ~80mewhat incongruously) for a telephone company's security department found taunting messages on his computer terminal at work. On a more serious level, there were attempts to reprogram switches to land opponents with astronomical phone bills; there was one instance of breaking into a credit bureau to destroy a gang member's credit rating. But while the three gangs were squabbling among themselves, the biggest crackdown on hacking in the United States had just begun. 204 APPROACHING ZERO The catalyst was an anonymous phone call to an unlisted residen tial number in Indianapolis at eight P.M. on June 29, 1989. As security manager for Indiana Bell, Robert S. was accustomed to anonymous calls: he was a prime target for hackers attempting to impress him with their ability to break into his system and find his home number. And the caller this night didn't seem much different from the others. He sounded like a young man trying to seem older, his voice a mix of swagger and menace. The caller presented his credentials by repeating Robert's credit history to him--which meant only that the anonymous hacker could also break into credit bureau computers. "Tell you something else, Bob--you don't mind if I call you Bob, do you? I'll tell you, somebody like me who really knows the phone systems could really fuck things up. I mean I could put your 5ESS's into an endless loop. You know what I mean? You know what that would do?" The 5ESS's were a type of electronic switching system. There were hundreds in Indiana Bell, thousands around the country. An endless loop is caused by changing the coding of the switch so that it no longer puts forward calls. The calls instead just loop around the switch, like a record needle caught in the same groove. The result would be paralysis: no calls from the switch could get out. "It could cause a lot of problems. Is that what you're threatening?" "Sort of. But I've made it better than that. I've planted computer bombs in some of the 5ESS's--time bombs--they're going to fuck up your switches. The game is to see if you can find them before they go off. And all I'm going to tell you about them is that they're programmed to blow on a national holiday. They could be anywhere in the country--it's sort of a competition, a security test, it'll give you something interesting to do for a change. You know what I mean?" The line went dead. Of all the hacker calls Robert had received--most a mix of braggadocio and hubris--this was one of the few he would think of as threatening. The threat was the bomb--a piece of computer programming, probably only a short program, that would be hidden among the thousands of instructions on any 5ESS switch, anywhere in the country. A computer bomb is a one-shot explosion. It could throw a switch into an endless loop, it could overload the system--or, indeed, it could create havoc by releasing a self-replicating program such as a worm, which would move through the network, knocking out switch after switch. In a nightmare scenario the country could effectively be closed down for days, leaving its citizens with no means of communication and cut off from emergency fire, police, and ambulance services. The cost in terms of lives would be unthinkable and the revenue losses would be incalculable: crime would soar and businesses could be forced to shut down. Robert couldn't know where the bombs had been hidden, nor did he know how many there were or what they would do when they went off. All he knew was that they had been set to explode on a national holiday--and five days later it would be Independence Day, the Fourth of July. He reported the call to his superiors at Indiana Bell and to Bellcore (Bell Communication Research), which coordinates network security. Given the imminence of the Fourth of July, Bellcore had little choice but to take the threat seriously. The company organized an alert, assembling a security task force consisting of forty-two full-time employees. They would work around the clock in two twelve-hour shifts examining the 5ESS's, checking through each and every program for a few lines of code that could cause disruption. The threat to the phone system was also reported to the United States Secret Service. The agency, part of the Treasury Department, had been assigned national responsibility for computer crime in 1984, after a long bureaucratic battle with the FBI. The limits of its responsibilities and those of the FBI have never been strictly defined; there have always been areas where the two agen- 206 APPROACHING ZERO cies overlapped. The Secret Service's responsibility is to investigate access device fraud that affects interstate and foreign commerce if there is a minimum loss of $1000. Their mandate, though, is subject to agreement between the secretary of the Treasury (their boss) and the Attorney General, who runs the FBI. The effect has been to leave the two agencies to fight out their responsibilities between themselves. The Secret Service was already in the midst of an in-depth investigation of the computer underworld. In 1988 the agency had become aware of a new proposal, one that seemed to signal an increase in hacker activity. Called the Phoenix Project, it was heralded in the hacker bulletin PHRA CK as "a new beginning to the phreak/hack community where knowledge is the key to the future and is free. The telecommunications and security industries can no longer withhold the right to learn, the right to explore, or the right to have knowledge." The Phoenix Project, it was announced, would be launched at SummerCon '88--the annual hacker conference, to be held in a hotel near the airport in Saint Louis. The Phoenix was the legendary bird that rose from its own ashes after a fiery death. To the hackers it was just a name for their latest convention. But to the telephone companies and the Secret Service, the Phoenix Project portended greater disruption--as well as the theft of industrial or defense secrets. The implications of "the right to learn, the right to explore, or the right to have knowledge" appeared more sinister than liberating, and the article was published just as the Secret Service was becoming aware of an upsurge in hacker activity, principally telecommunications fraud. The increase appeared linked to the hacker wars, then spluttering inconclusively along. Coincidentally, in May 1988, police in the city of Phoenix, Arizona, raided the home of a suspected local hacker known as the Dictator. The young man was the system operator of a small pirate board called the Dark Side. The local police referred his case to the district attorney for prosecution, and he in turn notified the secret service. No one was quite sure what to do with the Dictator--but then someone had the bright idea of running his board as a sting. The Dictator agreed to cooperate: in return for immunity from prosecution, he continued to operate the Dark Side as a Secret Service tool for collecting hacker lore and gossip and for monitoring the progress of the Phoenix Project. That the scheme to investigate the Phoenix Project was based in the city of Phoenix was entirely coincidental: it was established there solely because the local office of the Secret Service was willing to run an undercover operat ion. Dubbed Operation Sundevil, after the Arizona State University mascot, it was officially described as "a Secret Service investigation into financial crimes (fraud, credit card fraud, communications service losses, etc.) led by the Phoenix Secret Service with task force participation by the Arizona U.S. Attorney's office and t he Arizona Attorney General's office." The Arizona assistant attorney general assigned to the case was Gail Thackeray, an energetic and combative attorney who would become the focal point for press coverage of the operation. But the impetus for Operation Sundevil--the Dark Side sting--only provided the authorities with a limited insight into the computer underworld. Reams of gossip and electronic messages were collected, but investigators were still no nearer to getting a fix on the extent of hacking or the identities of the key players. They decided on another trick: they enlisted the Dictator's help in penetrating the forthcoming SummerCon '88, the event that would launch the Phoenix Project. Less a conference and more a hacker party, SummerCon '88 was held in a dingy motel not far from the Saint Louis airport. Delegates, usually adolescent hackers, popped in and out of one another's rooms to gossip and play with computers. The Dictator stayed in a special room, courtesy of the Secret Service. Agents next door filmed the proceedings in the room through a two-way mirror, recording over 150 hours of videotape. Just what was captured in this film has never been revealed (the Secret Service has declined all requests to view the tapes), but 208 APPROACHING ZERO cynics have suggested that it may be the most boring movie ever made--a six-day epic featuring kids drinking Coke, eating pizzas, and gossiping. Nonetheless, the intelligence gathered at SummerCon and through the Dark Side had somehow convinced the Feds that they were dealing with a national conspiracy, a fraud that was costing the country more than $50 million in telecom costs alone. And that, said Gail Thackeray (boo hiss bitch!), was "just the tip of the iceberg." Then the Phoenix Secret Service had a lucky break. In May 1989, just a year after ousting the Dictator, police investigating the abuse of a Phoenix hotel's private telephone exchange stumbled across another hacker. He was no small-time operator. Questioned by the Secret Service, he admitted that he had access to Black ICE. He wasn't an LoD member, he added, merely one of the few non-Legionnaires allowed to use the gang's board. Under pressure from the Secret Service, who reminded him of the penalties for hacking into a private telephone exchange and stealing services, he, too, agreed to become an informant. He would be referred to only as Hacker 1. A month later the Secret Service learned about the anonymous call to the Indiana Bell security manager and the threat to the telephone switches. At this stage there was still no evidence of an attack. Similar hoax calls are received every day by the phone companies. But then, on July 3rd, four days after the anonymous call, the Bellcore task force discovered that this wasn't just an idle threat. Three computer bombs were found, just hours before the Fourth of July public holiday. The bombs, as the caller had warned, were spread across the country: one was discovered in a switch in BellSouth in Atlanta, Georgia; another in Mountain Bell's system in Denver, Colorado; and the third in Newark, New Jersey. The devices were described by the Secret Service as "time bomb[s] . which if left undetected, would have compromised these computers (for an unknown period) and effectively shut down the compromised computer telephone systems in Denver, Atlanta. and New Jersey." In ~lainer lan~ua~e, had the bombs not been discovered and defused, they could have created local disasters. In the Secret Service offices in Phoenix, the interrogation of Hacker I acquired more urgency. The agents now knew that somewhere out there was a computer freak--or perhaps a gang of freaks--with the ability and inclination to plant bombs in the telephone system. It could happen again, and the next time there might not be any warning. The agents probed Hacker I about his contacts in the Legion of Doom, particularly those Legionnaires who might have access to the compromised phone companies. He told them about the Urvile, the Leftist, and the Prophet, three members who had the expertise to plant bombs, and were all based in Atlanta, the home of BellSouth. This information was enough for the Georgia courts to authorize the placing of Dialed Number Recorders (DNRs) on the three hackers' phone lines. For ten days the Secret Service monitored every call and recorded the hackers looping around the country to gain free telephone service and to avoid detection.4 The Atlanta hackers often started their loops by dialing into the computer system at Georgia Tech, using IDs and passwords provided by the Urvile, a student there. From Georgia Tech they could tour the world, if they felt the inclination, hopping from one network to another, wherever lax security or their own expertise permitted. With the evidence from the DNRs, the Secret Service executed search warrants on the three LoD members, and eventually raided their homes. The investigators uncovered thousands of pages of proprietary telephone company information, hundreds of diskettes, half a dozen computers, and volumes of notes. The three Legionnaires and their fellow hackers had been dumpster diving at BellSouth, looking for telco manuals. With the information gleaned, they had developed techniques for accessing over a dozen of BellSouth's computer systems, and from these they downloaded information that would allow them to get into other computer systems--including those belonging to banks, credit bureaus, 210 APPROACHING ZERO hospitals, and businesses. When the Leftist was interviewed, he nonchalantly agreed that the Legionnaires could easily have shut down telephone services throughout the country. Among the masses of information that the investigators found were files on computer bombs and trojan horses--as well as one document that described in detail how to bring down a telephone exchange by dropping a computer program into a 5ESS switch. The program simply kept adding new files to the switch's hard disk until it was full, causing the computer to shut down. What the investigators didn't uncover was any direct evidence linking the Atlanta Three to the computer bombs. Simple possession of a report that details how a crime could be committed does not prove that it has been. But they did find one document that seemed to portend even greater destruction: during the search of the Prophet's home they discovered something called the "E911 file." Its significance escaped the Treasury agents, but it immediately caused the technicians from BellSouth to blanch: "You mean the hackers had this stuff?" The file, they said, described a new program developed for the emergency 911 service: the E simply stood for enhanced. The 911 service is used throughout North America for handling emergency calls-- police, fire, and ambulance. Dialing 911 gives direct access to a municipality's Public Safety Answering Point, a dedicated telephone facility for summoning the emergency services. The calls are carried over an ordinary telephone switch; however, incoming 911 calls are given priority over all other calls. From the switch, the 911 calls travel on lines dedicated to the emergency services. In March 1988 BellSouth had developed a new program for enhancing the 911 service. The E911 file contained information relating to installation and maintenance of the service, and was headed, "Not for use or disclosure outside BellSouth or any of its subsidiaries except under written agreement." It had been stored in a computer in BellSouth's corporate headquarters in Atlanta, Georgia. While hacking into the supposedly secure system, the Prophet had found the file and downloaded it to his own PC. In the hands of the wrong people, the BellSouth technicians said, the critical E911 document could be used as a blueprint for widespread disruption in the emergency systems. Clearly, hackers were the wrong sort of people. According to BellSouth, "any damage to that very sensitive system could result in a dangerous breakdown in police, fire, and ambulance services." Mere computer bombs seemed childish by comparison. Just seven months later, on the public holiday in honor of Martin Luther King, Jr., the most sophisticated telephone system in the world went down for nine hours. At 2:25 P.M. on January 15,1990 the nationwide network operated by AT&T was hit by a computer failure. For the duration of the breakdown, the only voice responding to millions of long-distance callers was a recorded message: "All services are busy--please try again later." It was estimated that by early afternoon as many as half the long-distance calls being dialed in every major city were blocked. Some twenty million calls were affected, causing chaos in many businesses, especially those such as airlines, car rental companies, and hotels which rely on free 1-800 numbers. It was the most serious failure since the introduction of computer-based phone systems thirty years earlier. Robert E. Allen, AT&T chairman, emerged the following day to explain that "preliminary indications are that a software problem occurred, which spread rapidly through the network." Another spokesman said that while a failure in the software systems was probably to blame, a computer bomb could not be ruled out. The problem had been centered in what was called a signal node, a computer or switch attached to the network. According to AT&T, the errant system "had told switches it was unable to receive calls, and this had a domino effect on other switches." The effect was not dissimilar to the endless loop, which causes all incoming calls to circle idly around the switch. 212 APPROACHnNG ZERO Software problems are not uncommon, but few have such spectacular effects. And coming so soon after the computer bomb threat, rumors flourished that AT&T had been hit by hackers. In the course of researching this book, the authors were told more than once that the AT&T failure had been caused by a computer bomb. One source even claimed he could identify the culprit. The rumors continue to circulate, as they do about everything in the computer underworld. However, there is absolutely no proof that it was a computer bomb, and AT&T's final, official explanation remains that the shutdown was caused by an errant piece of software. The attack did not affect the emergency 911 numbers, which are handled by local carriers. Nor, even if it was a bomb, was it likely to have been linked to the previous incident. But it had taken place on a national holiday--Martin Luther King Day--and the coincidence bothered the authorities. On January 18th, three days after the AT&T system collapsed the Secret Service began a nationwide sweep, targeting hacker gangs--in particular the Legion of Doom--and anyone who appeared to be a threat to the phone system. Their first call was on Knight Lightning. The handle belonged to Craig Neidorf, a twenty-year-old prelaw student at the University of Missouri in Columbia, and one of the coeditors of the underground newsletter PHRA CK He was found in his room on the third floor of the Zeta Beta Tau fraternity house. Special Agent Tim Foley, who had been investigating the attacks on the telephone computer switches for seven months, and Reed Nolan, a security representative from Southwestern Bell Telephone, questioned Neidorf about an article in PHRACK on the electronic switching systems. They also brought up the E91 I document. They knew that Neidorf had received a copy of the file from the Prophet, and had published it in PHRACK in February 1989. According to Foley, Neidorf admitted knowing that the E911 tutorial had been stolen from BellSouth. The next day Foley returned with a search warrant and the local police. The ESS article had been forgotten; Neidorf was instead charged with ten felony counts centering on the publication of the E911 file in PHRACK If found guilty, he faced a sentence of up to sixty-five years in prison. On January 24, 1990, the Secret Service operation moved to Queens, New York, to the homes of several known hackers. The first target was a twenty-year-old known among the underground as Acid Phreak. When the Secret Service arrived, they told him that he was suspected of causing the AT&T crash nine days earlier. One of the agents pointed to his answering machine. "What's that for?" he asked. "Answering the phone," Acid Phreak said. He wasn't arrested, but instead was asked to accompany the agents to their headquarters in the World Trade Center, where he was questioned until the early hours of the morning. Phiber Optik, who also lives in Queens, was raided next. According to hacker lore, he was awakened in the middle of the night and confronted with nine loaded guns, which seems unlikely, as most other raids were conducted by one or two agents, usually accompanied by a telephone security man. Another New York hacker, the Scorpion, a friend of both Phiber Optik and Acid Phreak, was also raided on that day. On March 1st the action moved to Texas, with an almost comically aggressive bust of a games publishing company. The day started early, in Austin, with a dawn raid on the home of Loyd Blankenship. Loyd, known as the Mentor to colleagues in the Legion of Doom, was also sysop of an underground bulletin board, the Phoenix Project, and the author of a series of "hacker tutorials" in PHRACK He and his wife were roused from their bed by a team of six Secret Service agents, a local cop, and a representative from Bellcore. While his own computer and equipment were being seized, Loyd was driven to his office at Steve Jackson Games. The company specialized in publishing computer games, most of them involving role-playing of one sort or another. At the time it employed fifteen people and had a turnover of $500,000. Founded 214 APPROACHING ZERO by Steve Jackson, the company also ran its own, completely legiti mate bulletin board, which functioned as an information service for its customers. The only remarkable thing about the bulletin board was its name--Illuminati, after the secret, world-dominant sect that had so exercised the Soviet hacker gang. Computer enthusiasts the world over clearly read the same books. Steve Jackson himself arrived at the office just as the Secret Service agents were attempting to kick down the door. The agents were offered a key instead. They spared the door but did prefer to force open a locker and to cut the locks off of the outside storage sheds, despite being offered the appropriate keys. The agents seized all the computer equipment they could find. They also tore open cartons in the warehouse, looking for a handbook on computer crime that was in preparation: they intended to seize all copies before it could be distributed. The "handbook on computer crime" later turned out to be an innocent game about computers called GURPS Cyberpunk, published by Steve Jackson Games.s The mere fact that Loyd had chosen the name Cyberpunk had led the authorities to conclude that the program was part of a conspiracy to spread hacking techniques nationwide. The Secret Service seized all copies of the game at the company's premises and made doubly certain that they collected the data for Loyd's manual as well. Two months later Operation Sundevil struck again.6 On May 8th coordinated raids on hackers in fourteen cities were carried out. Over 150 Secret Service agents were deployed, teamed with numerous local and state law enforcement agencies. The agents served twenty-seven search warrants in Chicago, Cincinnati, Detroit, Los Angeles, Miami, Newark, New York, Phoenix, Pittsburgh, Plano (Texas), Richmond, San Diego, San Jose, and Tucson. Forty computers and 23,000 diskettes were seized. The official reason for the busts was telecommunications fraud. The raids were synchronized in order to completely surprise the hacker community and prevent important evidence from being destroyed. But that nearly happened anyway. As reports of the Atlanta and New York raids circulated, a number of hacker boards carried warnings that another "major bust" was imminent. (Captain Zap, the Philadelphia hacker arrested years before for theft, takes credit for the messages.) One of those who took the warnings seriously was Erik Bloodaxe, the LoD member who was so keen on selling U.S. military secrets to the Soviets. All his equipment, as well as any documents that could incriminate him, was hidden away before the raids. When the Secret Service and local cops burst in on him, he was the picture of innocence. With little to choose from, the agents considered taking away his PacMan game--then decided to take his phone instead. It was the only piece of hacker equipment they could find.' Others were less lucky. As the Secret Service raided homes of known hackers, carrying away boxes of diskettes and computer equipment, they were invariably asked, "When do I get my system back?" The authorities were well aware that confiscating equipment for use as evidence later--should there ever be a case-- was punishment in itself. During the raids half the members of the Legion of Doom were busted. MoD and DPAC were less affected than the Legion by the busts, but the aftershock would cause DPAC to split up, and MoD would come to grief the next year. The spluttering, intermittent hacker wars had ended in default. The Secret Service had broken the hacker gangs and brought law and order to Cyberspace. Or so it seemed. But support for hackers was building--unwittingly aided by the FBI, the Secret Service's rival in the bureaucratic battle for responsibility for computer crime. On May 1, 1990, an FBI agent named Richard Baxter, Jr., drove to Pinedale, Wyoming, for a meeting with John Perry Barlow. The two men came from different worlds. Barlow was a bundle of idiosyncrasies and contradictions, the sort of man who seems to survive only in the American West: aged forty-two, a former rancher, the Lyricist for the Grate- 216 APPROACHnNG ZERO ful Dead, and also the local Republican party county chairman he believed in the frontier, both the real one around Pinedale and the electronic one accessible through his computer. Barlow wasn't a hacker, but he was part of something called WELL--the Whole Earth 'Lectronic Link, the embodiment of the sixties counterculture surviving in the 1990s on an electronic bulletin board based in Sausalito, California. His philosophy was a mix of sixties liberalism leavened by a rancher's rugged individualism; he was a Republican hippie with a computer. Agent Baxter was a country boy who "didn't know a ROM chip from a vise grip," according to Barlow.8 He wanted to talk to Barlow about high-tech crime, although hackers were not his usual beat. Baxter was investigating the theft of the operating system source code for the Macintosh computer. According to Baxter, it had been stolen by a group that was threatening to destroy the American company by releasing the code to East Asian manufacturers of Apple clones. Briefed at length by his San Francisco office, Agent Baxter told Barlow that the FBI wanted to interview John Draper, the legendary Captain Crunch. Draper, the FBI believed, was a known member of the Hackers' Conference, an underground association with likely ties to those responsible for the theft. The FBI also believed that Draper was the chief executive of Autodesk, a software company with many top-secret government Star Wars contracts. Jurisdiction for this particular investigation had fallen to the FBI, not the Secret Service. It was one of the oddities of U.S. Iaw enforcement that even when the responsibilities of the two agencies overlapped, their intelligence and resources were almost never pooled. And in this case, Barlow knew that the FBI agent's information was almost completely wrong. Draper wasn't the chief executive of Autodesk, though he had worked there as a programmer at one time, and Autodesk was not a major Star Wars contractor, but a software developer. Also, the Hackers' Conference was not an underground association, but an annual gathering of the nation's brightest and most respected computer experts. As for the group that had supposedly stolen the Macintosh source code, Barlow presumed that the agent was referring to the self-styled nuPrometheus League, which had been circulating filched copies of the Macintosh code to annoy Apple. Opinion in the computer underground was that the code was probably picked up by kids who'd been dumpster diving. (The ethos at Apple had changed since 1979. Then it was a small company with roots in the hacker community; now a major corporation, it called in the FBI to chase down kids for dumpster diving.) The only thing that the FBI had gotten right, Barlow reckoned, was the address of Autodesk. So Barlow explained to Baxter what was really going on, spending most of the two-hour interview educating him about source codes. THINGS HAVE RATHER JUMPED THE GROOVE WHEN POTENTIAL SUSPECTS MUST EXPLAIN TO LAW ENFORCERS THE NATURE OF THEIR ALLEGED PERPETRATIONS, he said in his posting to the WELL about the incident. Barlow's message produced an unexpected response. A number of other WELL-beings--the users' excruciatingly cute name for themselves--had also been interviewed by the FBI. They had all heard pretty much the same garbled story. Baxter had only been repeating the information contained in the agency's files. The entire Bureau seemed to be working on erroneous data. It was enough to tweak the ideological hackles of any Republican hippie, particularly one who believed in the new frontier of the computer village. So, a week later, when news of the Secret Service crackdown broke, Barlow decided to investigate, to ensure that officialdom wasn't looking at the hacker threat through a haze of ignorance. Barlow had been inundated by messages, up to a hundred a day, after his posting to the WELL. Most had expressed indignation at the FBI's ignorance, and worries about the treatment of hackers who had been picked up in the dragnet. Barlow also met with 218 APPROACHING ZERO Mitch Kapor, another WELL-being and the coauthor of Lotus 1-2-3, a best-selling computer program. Kapor had been shrewd enough to sell his stake in Lotus at (or very near) the top. Among other things, his earnings enabled him to operate his own business jet, which he used to fly to Wyoming for the meeting. Both Kapor and Barlow empathized with the raided hackers though neither would ever condone criminal or malicious activity of any kind. Their concern was about whether the Feds knew what they were doing or were merely being pulled along by uninformed hysteria about hacking. Together, Barlow and Kapor agreed to set up the Electronic Frontier Foundation. Its purpose was not necessarily to protect hackers, but to extend the protection of freedom of speech, freedom of the press, and freedom of expression to computer-based media: bulletin boards, electronic publishing, computer conferencing, and so on. The foundation dedicated itself to six aims, all related to influencing future legislation so that the civil liberties of computer users, whether they were hackers or not, would not be ignored. It attracted the support of a number of affluent technocrats in the computer industry--including $150,000 from Steve Wozniak, one of the Apple founders. (Woz had remained faithful to the original ideals of Apple. He resigned his position at the company in the early 1980s when it became too "corporate" and busied himself promoting music festivals and teaching, among other things.) By the time the Foundation was established, the full force of the federal crackdown had already been felt. The New York hackers Acid Phreak, Phiber Optik, and the Scorpion had been raided; Craig Neidorf had been arrested; the Atlanta Three had been indicted; Loyd Blankenship (the Mentor) and Steve Jackson had been busted and their equipment confiscated; and the nationwide raids had rounded up LoD, MoD, and DPAC members, as well as an assortment of independent hackers. The catalog of charges ranged from wire fraud to handling stolen property, from unauthorized possession of access devices to misappropriating source codes. There were also allegations of credit card fraud, bank fraud, and altering hospital computer records, and references to specific incidents: dropping computer bombs in telephone switches and stealing the E911 documents. It had all of the makings of a nationwide conspiracy. The first case the Foundation took on was in Chicago. Assistant U.S. Attorney William Cook, who had earlier successfully prosecuted Kyrie--the "Fagin" of the stolen access code gang--and who had become something of an authority on computer crime, was now in charge of the case against PHRACK editor Craig Neidorf. Neidorf had been indicted for transporting the stolen E91 I document across state lines. He finally came to trial in Chicago on July 23rd. The prosecution's case was opened by Cook, who outlined the government claim of a conspiracy involving Neidorf and members of the Legion of Doom and asserted that the E911 file was "a highly proprietary and sensitive document" valued at $79,449. Four days later the case collapsed. The defense demonstrated that the same E911 information was available from local bookstores and in libraries. Furthermore, by dialing a free 1-800 number, two publications could be obtained from Bellcore for $34 which contained even more detailed information. Neidorf's lawyers also argued that, far from being the serious and imminent threat represented by Bellcore, the file had been published in PHRACK nearly a year before the telephone company bothered to do anything about it. Neidorf was cleared of all charges, but though he was helped by the foundation, he was still left with some $100,000 in legal costs. The E911 file, however, was to come up once again. On November 16, the Atlanta Three pleaded guilty to a number of charges variously described as computer fraud, wire fraud, access code fraud, and interstate transportation of stolen property--the latter referring to the E91 I document. Because the three agreed to guilty pleas the charges were reduced, but as a result no defense could be mounted. In the sen- 220 APPROACHING ZERO tencing memorandum, the prosecution said that Robert Riggs (the Prophet) had stolen the E911 file "containing the program for the emergency 911 dialling system," adding that "any damage to that very sensitive system could result in a dangerous breakdown in police, fire and ambulance services." The file's value, the prosecution added, was $24,639.05--the 5 cents presumably included to indicate that the figure had been very accurately determined. The memo also stated that the three had gained free telephone service and access to BellSouth computers. The Electronic Frontier Foundation was enraged. Although the plea bargaining precluded a formal defense, the Foundation said the claims about the E911 file were "clearly false. Defense witnesses . . . were prepared to testify that the E9 11 document was not a [computer] program, that it could not be used to disrupt 911 service, and the same information could be ordered from BellSouth at a cost of less than $20." The foundation also noted that the prosecution had begun its memorandum by detailing the planting of computer bombs. "Only after going to some length describing these allegations does the prosecution state, in passing, that the defendants were not implicated in these crimes [Foundation italics]." Despite the protests, Robert Riggs (the Prophet) was sentenced to twenty-one months and his two colleagues--Adam Grant (the Urvile) and Frank Dearden (the Leftist)--received fourteen months each. They also had to make restitutional payments of $233,000 for the value of the "access devices" found in their possession. The access devices were the IDs and passwords that they had collected from BellSouth during their various raids. There was no question that the Atlanta Three were hackers who had, without doubt, broken into BellSouth. But the valuation of the "access devices"-- computer codes, telephone card numbers--was highly questionable. As the foundation asked, how can a value be assessed when no loss can be demonstrated? But in the new climate engendered by the crackdown, everything associated with hacking was suspect. Every self-proclaimed hacker acquired a Secret Service dossier, irrespective of his activities; every hacker with a handle qualified for a bust; every busted hacker was suspected of belonging to the Legion of Doom; and the mere mention of the word Cyberpunk seemed enough to bring down the full force of the law. Under the circumstances, Steve Jackson had drawn a full house. Not only did he employ a known hacker--Loyd Blankenship, who had a handle and was even a member of the LoD--he was also engaged in producing a "hacker handbook" called Cyberpunk. During the raid on Steve Jackson Games, the Secret Service had confiscated much of the company's computer equipment, without which equipment the company could barely function. It took months, and the assistance of a foundation-supplied lawyer, before the Feds returned the equipment--some of it, according to Steve, damaged, with valuable data missing. The Secret Service kept the equipment as potential evidence for a "crime" that was never committed. For, while GURPS Cyberpunk does contain information on dumpster diving and social engineering, it is ultimately a game. It is no more a "handbook on hacking" than, say, this book is. (The game was finally published later that year, without causing any noticeable increase in hacking crimes.) Even though no charges were filed against Steve, his business suffered while the Secret Service held his computer systems. His turnover was down and half of his staff was laid off. He estimates his losses for the period at over $300,000. With the help of the foundation, he has since filed a civil suit against the Secret Service and two of its agents, Assistant U.S. Attorney William Cook, and a Bellcore security manager. At the time of writing, Loyd Blankenship (the Mentor) has not been charged with anything either, although he still has not received his computer equipment back. Given his background in the LoD, it is not thought likely that he ever will. As a known hacker, he is not pressing the Secret Service too hard; instead, said a friend, he's "Lying low." 222 APPROACHnNG ZERO The Electronic Frontier Foundation couldn't help everyone. Phiber Optik was sentenced to a period of thirty-five hours of community service for a relatively minor hacking offense. Even worse, he suffered the shame of being thrown out of the Legion of Doom--though that had nothing to do with his arrest. His crime, in the LoD's eyes, was that he and Acid Phreak (a non-Legionnaire) had demonstrated their hacking skills for a magazine article published in Esquire in December 1990. Although both he and Acid Phreak had kept their identities secret even using phony handles--the other Legionnaires felt that the young hacker was on "an ego trip," a charge confirmed for them when he appeared on a number of television shows. Phiber Optik, the other Legionnaires decided, had too high a profile for the Legion. Not being in LoD didn't stop him from hacking. He joined the MoD instead--but then he was busted along with four other MoD members: Outlaw, Corrupt, Renegade Hacker, and the Wing. These arrests were devastating to the gang, principally because their equipment was confiscated. (The MoD accused the Legion of turning them in as a last reprisal in the hacker wars, but this seems unlikely.) In July lg92 a federal grand jury indicted Outlaw, Corrupt, Phiber Optik, Acid Phreak, and Scorpion for breaking into telco and credit agency computers, and for stealing data. Given all the effort, this was a modest payoff--hardly justification for a massive crackdown. Even the Operation Sundevil busts of May 8th, which the foundation called a use of "force and terror which would have been more appropriate to the apprehension of urban guerrillas than barely postpubescent computer nerds," have yielded remarkably few indictments. Gail Thackeray, an attorney in Phoenix dealing with the aftermath of the Sundevil busts, notes that "80 percent of those arrested were adults [over eighteen years old]"-- hardly postpubescents. She says that more indictments are still being prepared, and that the delay was caused by the sheer weight of evidence: more than twenty thousand diskettes have been examined, which has taken the authorities over twelve months. But perhaps indictments were never the point. Sundevil was a search-and-seizure operation; the quarantined computers and diskettes will be held until the material can be analyzed. Only at that point will the indictments, if any, be handed down, and the authorities are in no rush. While the computers are in their possession, the Cyberpunks are out of action. As for the Phoenix Project, it, too, was probably a false alarm. The vaunted rebirth of hacking, which convinced the Secret Service that there was a nationwide conspiracy, may not have been what it seemed. After all, the Project's organizers had only exhorted hackers to welcome the new age "with the use of every legal means available." A sympathetic interpretation of the Phoe- nix Project would suggest that older hackers were simply counseling others not to break the law. It was a timely warning: the Computer Fraud and Misuse Act had entered the statute books two years previously, and some jail sentences had already been handed out. Hacking was no longer being viewed tolerantly, and the Phoenix Project's organizers expected a crackdown by the authorities. They got that right at least. However, there was yet another hacker swept up in the Secret Service busts, who, unlike the others, was unquestionably hacking for profit. In mid-June 1989 BellSouth had begun investigating two relatively minor incidents on one of its switches in Florida. In the first incident, on June 16th, an intruder had hacked into the switch and rerouted calls for the city offices of Miramar, Florida, to a long-distance information number. On the next day the same hacker (or so it was assumed) had also rerouted calls intended for the Delray Beach probation office. This time the hacker demonstrated an impish sense of humor: callers to the probation office instead found themselves connected to a Dial-a-Porn service in New York State. As a result of the two incidents, BellSouth had stepped up the monitoring of its switches. On June 21st, security agents were told that the monitors had detected a hacker loose in one of its computers. 224 APPROACHING ZERO The carrier put a trace on the call, following it back through a series of loops around the country. The hacker had tried to disguise his entry point into the system by first dialing into his local exchange, jumping to a connected switch on another network, then skipping from there to yet another network, and so on. Each time a loop was made through a network, it had to be traced to the entry switch. But the precautions must have given the hacker a false sense of security, because he stayed in the system too long, allowing the trace to be followed all the way through, from network to network, right back to a phone number in Indiana. BellSouth passed the number they had traced on to Bellcore, which began monitoring all outgoing and incoming calls. The telephone company agents had discovered a hard-core hacker: they watched as their target looped calls around the country, from system to system; they recorded him breaking into a credit agency computer in Delaware belonging to CSA; and they listened as he had money wired to Paducah, Kentucky, on a credit card number. Their target, of course, was Fry Guy, the fifteen-year-old Indiana hacker who had spent months perfecting his credit card scam. With evidence that the young hacker was committing fraud, the telco agents turned the details over to the Secret Service, which included him on the Atlanta Three's DNR request. The inclusion was mostly a matter of convenience, but the agents had noted a geographic coincidence that intrigued them: Fry Guy lived in Indiana, as did the recipient of the anonymous telephone call warning of the computer bombs in the switches; Fry Guy also knew his way around BellSouth, where one of the bombs had been planted--indeed, other hackers regarded it as his "sphere of influence." In mid-July the Secret Service recorded Fry Guy charging $500 to a stolen credit card number. With that piece of evidence (previous telco monitors had not been court-approved and therefore could not be used as evidence), the Secret Service was also able to include Fry Guy in the Atlanta Three search warrant. The house in Elmwood, Indiana, was raided the same day the three addresses in Atlanta were busted. Fry Guy awoke from his summer-long haze to find that he was suspected of the two Florida incidents, the anonymous telephone call to Indiana Bell's security manager, planting the computer bombs, and credit card fraud. Hackers are often victims of their own hype. The LoD was the principal target of the crackdown because it promoted itself as the biggest and meanest gang in Cyberspace--and because the authorities believed them. The computer underworld is a hall of mirrors. Reality becomes bent, the truth shrunken. The authorities who organized Operation Sundevil and its related investigations believed they were dealing with a nationwide conspiracy involving $50 million in telecommunications fraud alone. And that, they said, was only the tip of the iceberg. What they got in the end, notwithstanding the Atlanta Three's guilty pleas, were some relatively minor convictions. After the barrage of criticism from John Perry Barlow's Electronic Frontier Foundation, the investigators began to pull back. The Phoenix officials, such as Gail Thackeray, are now keen to distance both themselves and Operation Sundevil from the other antihacker actions that year. The wilder suggestions--that the AT&T incident had been caused by Acid Phreak; that hackers were looting banks; that hospital records were being altered, and patients put at risk--have been dropped. The word conspiracy is used less and less, and the computer bombs, the specific catalyst for the whole crackdown, have been quietly forgotten. No one has been officially charged with planting the bombs, and it is unlikely that anyone ever will be. Everyone in the underworld's hall of mirrors claims to know who did it, but they all finger different people. As for Fry Guy, he denies any responsibility for the bombs: "They're just pointless destruction. I can't understand why anyone would do it. I'm not malicious or destructive: I only do things for gain." 226 APPROACHING ZERO That was Fry Guy's downfall: he operated for gain. When he was raided, the Secret Service found more than a hundred "access devices" in his possession-- credit card numbers and telephone calling cards. He could never be charged with planting the bombs, and no one was able to pin the Florida incidents on him, but he was caught red-handed on the credit card fraud. Following his arrest, it was estimated that his little scam had netted him $6,000 that year. He is now on probation, his equipment confiscated, but if you ask him why he hacked, he still sighs: "It's the greatest thing in the world." New technology requires new approaches. The reactions of the authorities to the computer underworld show a dependence on old ideas. Hacking becomes "breaking and entering"; role-playing games become "conspiracies"; exploration becomes "espionage." The dated terms obliterate the difference between the "bad" hackers and the "good" hackers. And there is a difference. Society might tolerate some activities of the computer underground. Hackers are mostly explorers exercising intellectual curiosity. Undoubtedly, they will break into computers, sometimes causing ancillary damage or taking up system time, and they probably will exploit the telecom systems to do so. But their intent, for the most part, is not malicious. On the other hand, the black arts of virus writing or hacking to steal money are unjustifiable. Virus writers are electronic vandals; hackers who rob are high-tech thieves. The difference between the good and the bad is often blurred. The distinction is one of motive: the malicious and the criminal should be viewed differently from the merely clever or curious. Someday it may be possible to get a clearer picture of what the activities of the computer underground actually cost industry and telecom companies. Present estimates vary so widely as to be worthless. Figures seem to be plucked from the air: it is utterly impossible to verify whether the true cost in the United States is around $550 million each year (the Computerworld estimate), or whether total losses could actually amount to as much as $5 billion (as was estimated at a security conference in 1991). These exaggerations are compounded by the hackers themselves--who are only too willing to embellish their accomplishments. With both sides expounding fanciful stories and ever wilder claims, truth is lost in the telling. What is ironic is that the activities of the hackers are leading to a situation they would decry. Security managers have a clear responsibility to protect their sites from electronic intrusion. As hackers become bolder, security is becoming tightened, threatening the very "freedom of information" that hacking, in its benign form, is said to promote. Hackers are an engaging bunch, even the "bad" ones: bright, curious, technically gifted, passionate, prone to harmless boasting, and more than a little obsessed. They are usually creative, probing, and impatient with rules and restrictions. In character, they closely resemble the first-generation hackers. Computing has always gained from the activities of those who look beyond what is there, to think of what there might be. The final irony for the computer industry is that the hackers who are being shut out today will be the programmers, managers, and even security experts of tomorrow.