DefCon 34 - Stalking the Wily Hacker: 40 years later - Cliff Stoll
Watch on YouTubeVideo summary
Cliff Stoll recounts his famous 1986 experience at Lawrence Berkeley National Laboratory, where he discovered a $0.75 accounting error that turned out to be the work of a sophisticated hacker. At a time when the internet was a small, trusted playground with only thousands of users, Stoll noticed anomalies in his system logs and realized someone had gained root access to search for nuclear secrets like plutonium and ballistic missiles. Instead of immediately disabling the intruder's access or calling law enforcement who dismissed the low financial loss as unimportant, Stoll decided to track the hacker himself. He set up a makeshift monitoring station in the basement, sleeping under his router and wiring together printers and teletypes to capture every connection attempt, effectively creating one of the first honeypots in history.
The investigation led Stoll on an international chase that spanned from California to Northern Virginia and eventually across the Atlantic to East Germany. He utilized primitive but effective tools, such as a soldering iron, a pager modified to receive Morse code, and a written notebook to document his findings, as he noted that in computing, if it isn't written down, it didn't happen. By analyzing packet delays, he could estimate the hacker's location was near the moon, eventually narrowing it down to a military contractor in Hanover, Germany. To keep the hacker online long enough for German authorities to trace his phone line, Stoll employed game theory and created dozens of fake documents about strategic defensive initiatives, baiting the intruder into downloading them while police waited for the connection to time out.
Stoll's talk concludes with a powerful reflection on the evolution of cybersecurity and the human element behind it. He criticizes modern security questions that treat hackers as neutral "threat actors" or technical puzzles, arguing instead that they are real people making choices that cause harm. He contrasts the trusted network of the past with today's zero-trust environment, noting that while we now face nation-states and massive syndicates rather than a single individual, we also have a vast community to support us. Stoll encourages the audience to remain creative, enthusiastic, and emotionally invested in their work, urging them to chase down their own "75 cents" of curiosity and responsibility in the future, ensuring that the next generation continues to tell these stories with glee rather than just quoting him.
Read the full video transcript
Is everybody having a good Defcon?
[cheering]
Let's freaking go.
>> Go ahead.
>> Oh,
should I introduce you, Ringer?
Oh. Uh,
>> first first it's my honor and delight to
introduce the ringer to Oh, I'm being
Oh, I'll go fast. Here's
>> to me.
>> Go.
>> Well, now it is my honor and privilege
to introduce someone who absolutely
needs no introduction. So, without
further ado, Cliff
>> and [cheering]
Hot damn. Thank you, Mesley. Um
um before I even start, I'd like to say
thank you to Ayatsi Ayatsi Local 720 and
the Culinary Workers Union 226 who have
been cleaning up this dump and fixing
things. So, thank you. Thank you,
culinary workers. And especially thank
you to the one person in this logo in
the culinary workers union 226, my
cousin Lynn. So um [applause] I will I
will not point out who she is. Um
[applause]
having said that having said that it's
worth my time to point out to you I'm
going to be using an overhead projector
today. if you [cheering]
you know view graphs um from a talk I
gave at the NSA about 25 35 years ago.
If you don't know what this is, ask your
grandparents. Um [laughter]
at the same time, my talk is on the
bottom of my hand so those in the front
row can see what I'm going to say. Um um
worth mentioning also, you are welcome
to use your cameras during my talk. I
don't give a half darn. Um Um So having
said that, what I'd really like to talk
about,
show that thing that that that bottle.
Toss it over. Just throw it here. What
I'd like to talk about today are Klein
bottles, non-orientable surfaces. I'd
like to talk about
well I'd genuinely like to talk about
remmanium manifolds but unfortunately
um I'm not going to so I won't tell you
how tr how terrific these are um
um because today marks an anniversary
August 8th 1986
40 years ago today I stumbled into a
how should I put it I stumbled into a 75
cent accounting error. I'd been an
astronomer up at Lawrence Berkeley Labs
and
and we finished the optical design of a
big telescope, the Kek 10 meter. And so
I went down to the basement of building
50 where I started managing a bunch of
UIX boxes. Now this was in the old days
back when
back when the arpanet was growing really
fast. There were 400 500 maybe 700 nodes
online and the inter and the early
internet the early arponet was
I can't see anything
any rate the early internet was growing
gang busters there must have been it was
astonishingly crowded there was probably
4,000 maybe 8,000 people online and you
didn't worry much about it because the
it was a you trusted who was there. It
was a playground built on mutual trust.
Meanwhile, computing itself had value.
Is today you're walking around with a
supercomput in your pocket. Back then,
well, no. Um, we charged for CPU cycles
and we charged for compute time. So, I'm
there and
my second day on the job, our accounting
program goes belly up, dead in the
water.
And I'm I I look and I walk and say,
"Weird."
And I say, "Oh, this is cool. I can fix
it. It's probably a corrupt accounting
database or a problem in the account
system." You know, we had a new user who
had used 75 cents of time.
But they think, "Curious,
this is interesting.
I'm CIS manager. I'm the only one who
ought to be able to add a user to the
password file."
So, I look and think,
"Something's hanky here. Could somebody
be on my system?
How could I tell?"
And so I took advantage of one of the
very few things that I learned in
graduate school, namely that it's easier
to apologize later than to get
permission in advance.
>> [applause]
>> So I waited I waited around until
until
6:30 7 o'clock on a Friday afternoon
and I got one of these push cart lab
carts, you know, you know, one of these
lab carts. And so I sort of went from
office to office, door
door to door. Oh. Oh, this is the title
of my talk. Um, and that's the guy who's
doing the talk and all those other
addresses are wrong. This is who I am.
Um, and and so I went from office to
office and door to door liberating
people's printers and teletypes and and
decorators and putting them all on this
lab cart and pushing them from office to
office [laughter]
down to the basement of building 50.
Once I got to the basement of building
50, I got a um uh soldering iron and a
bunch of of Radio Shack clip leads. And
there I said, "Okay, I'll wire up all
these printers." I scatter them around
in a circle behind a bunch of vax
computers. I clip leaded them onto the
incoming modem bank so that every time
somebody connects into my system, I get
a print out. Got a sleeping bag, right?
Got a sleeping bag. Unrolled it behind
the router. Nice warm fan blowing across
me. Um, got a thermos of minestrroni.
Climbed in the sleeping bag and fell
asleep.
Next morning,
next morning at 7:30, 8 in the morning,
my boss Roy Kur comes by. I'm asleep in
this old uh sleeping bag. And he sort of
gently awakens me and I look up and he
says, "Cliff, I understand there's some
equipment missing from around the lab."
and I'm surrounded by two dozen printers
and teletypes and I say I haven't the
fadest idea
and he looks down and says it would be a
right neighborly thing if everything
were returned now.
So I go over push cart and gather up
some of these printers and decorators
and
and from what are these what decorators
and printers there's 10 meters there's
30 feet of yellow paper and I start
looking at it and I could see how
somebody has come into my system in the
middle of the night used a cron tab
script to get become to fire off a set
user ID to root
and then bumped himself up to root,
turned off the accounting program and
then went out over a local area network
through our router, the third router
that Cisco had ever built um through our
router onto what was then called the
Arpanet. And then he starts going out
through the milnet side, the military
side, 10.0.blit.blatz,
and he starts systematically knocking
into military computers on the milnet.
And when he gets in, he starts
he starts
he starts gpping for things like
ballistic missile, like plutonium,
nuclear.
Now,
this is I I'm looking at this and it's
triple weird because
we're in Berkeley, California on the far
left side of the continent.
So, you know, it's where great you might
find Grateful Dead concerts and and
street protests. Somebody might grep for
granola recipes, but they're not going
to be searching for nuclear espionage.
I'm looking at this saying, "This is
weird."
So,
so I knew that real soon there'd be
there'd be a meeting. And sure enough,
Monday morning, we had a departmental
meeting. So, what do you do?
Is this Is this Can you read this?
>> Can you read it now?
>> Good.
So, what do you do when you find
somebody breaking into your computer?
Seems to me, and these these are slides
that I, you know, um seems to me it's
obvious. You you make you disable their
access. Make sure that they can't get in
anymore. Change people's accounts,
change your passwords, tell your systems
users, and be quiet. Don't publicize it.
or do we
or do do we try to catch him? The lab
director was a guy named David Shirley.
Now Dave Shirley had his head screwed on
straight. He says, "Look, [snorts]
someone's messing with our files.
Someone's trying to commit espionage.
I want you to take all the equipment,
ALL THE TIME, ALL the resources you
need. catch the rodent. Take three weeks
if you have to catch them.
So,
so I rewrote the rules.
[cheering]
When when we find somebody breaking in,
[snorts]
when we find somebody breaking in,
we let the guy in.
We keep the hole wide open.
I want to make it look like we're
stupid, which is pretty easy to do. Um,
on the other hand, I want to monitor
everything. I want to see every
keystroke that's typed in. I want to see
every character that's echoed back.
At the same time, I want to find out
where this guy is coming from. I want to
trace things back and find out what the
connectivity is from over here to over
there and what's to be done about it.
[snorts]
I want to hold this guy in my hand.
I want to know who it is that's screwing
with my system.
Immediately
there was a problem.
[snorts]
[laughter]
[snorts]
We had no budget.
The entire hardware budget for this
one-year project was 0.
Adjusted for inflation. at $0 million.
We had no expertise,
no experience.
Nobody taught me what to do about this
in grad school or even in undergrad.
You know, there was no I couldn't go and
ask a question on Reddit.
[snorts]
Then there's no mandate. Nobody said,
"Look, it's your responsibility
to catch this guy." No. Several
organizations, including my funding
agency, which was a, you know, they're
the Department of Energy, said, "Don't
do this. If people find out there's a
hacker in a DOE computer, they'll cut
our funding." So,
what do you do?
What do you do when you're broke,
when you're stupid,
and you're discouraged?
[laughter]
[applause]
>> Welcome to research.
[cheering]
[applause]
Think of your own situation. It never
has happened that you've had too much
money. You're never know too much.
You never You never have too much
encouragement.
So what do you do?
You do what's cheap and primitive. You
take a screwdriver and you use it as a
chisel, a crescent wrench, you use it as
a hammer. And the result is you come up
with creative solutions on the fly.
That's mostly what I'll be talking about
today. So
um
we started out by calling, you know,
started out by calling the FBI.
They had a field office in Oakland about
5 10 kilometers south of us in Berkeley.
HEY FBI, SOMEBODY'S BREAKING MY
COMPUTER. THEY'RE GOING OUT OVER they
they rooted themselves using sec user ID
to root and fired off using crotab. They
went over the arponet into into the
milnet 10.0.lit.blast. They're going
over into systems and they're gripping
for nuclear and plutonium. Guy at the
FBI says, "OH MY GOD, THAT'S SERIOUS. I
MEAN,
HOW MUCH money did you lose?" I said,
'Well, we've lost about 75 cents.
[laughter]
Guy at the FBI says, "Um, call back when
you're down half a million dollars."
So, that didn't seem like fun.
So without the FBI's help and approval,
I decided to just sort of quietly track
the hacker across the networks,
I got
uh I borrowed a pullet hacker serial
line analyzer um which was uh and I
programmed it to call my pocket pager
every time it recognized the account or
the password that this guy was
and set it up in a way that the um uh I
got out the soldering iron and rewired
the Motorola page boy so I could send
Morse code to it using touchton tones uh
a protocol that's not very well known
anymore but um um oh yeah yeah um cool
uh mind you all these are from a talk I
gave in 1987 at the NSA so uh if they if
you can't read them That's okay. I can't
either. Um um so I began unwinding
connections first over a local area
network, then across the phone system.
And um early on I noticed whenever the
guy logs in, I'd look at the printout
when this guy's getting into it. And I
noticed that he'd right away type the
Unix PS command. Um, for those who are
not Unix jocks, everybody who knows Unix
knows the ps command process status. It
lists all the processes that are
running. So immediately he'd type ps and
this way he can tell who's on the system
and what processes are there. He's
looking over his shoulder to see who's
watching them.
And right away I notice something kind
of curious.
Now when I type PS
I type
is that visible.
>> I type PS dash AXU.
I want to look at
all the I want to look at all the the
processes. I want to see the long form
of them and I want to look at all the
users. You know, this is kind of, you
know, um what he was pretty doing was
he'd type PS-
GXUA.
Well, that's all the same. But this G
flag, that was the weird one. I looked
at it and I said, "Huh,
that G flag isn't in Berkeley Unix."
Hot damn.
THIS CLOWN IS A HERETIC. [laughter]
[applause]
He's He probably runs AT&T system 5.
[laughter]
A heathen.
[laughter]
So with that, the trail immediately left
Berkeley. Nobody in Northern California
would ever use anything other than BSD.
So, so we started tracing it across
North America and it goes east.
It gets all the way to Northern
Virginia. We get to Northern Virginia
and this this operator says, "You know,
I made the trace all right, but I can't
tell you
Um, but the operator says, "I can't tell
you the re response till you show me a
search warrant." And I say, "Well, look,
I don't have a search warrant. I'm just
a planetary astronomer out in Berkeley.
But what I do have is
some real nice pictures of Saturn and
the moon.
And and she laughed, but I pointed out
you could see the Cassini division, the
Yankee division, lunar highlands, Mari
uh the Sea of Tranquility, and Mari
Creium. And she said, "Well,"
so I put them all in the mail. A week
later, we got the phone trace
information. [laughter] Um
and [applause]
the problem was coming from a system at
a company called MITER. Now, MITER MITER
was MITER was this military contractor
who did governmental secret work and and
they're over someplace in Virginia,
right near like the East Coast and and
so I call him up and the guy at the um
at the CIS admin for them say, "It's
impossible for anyone to be breaking
into your system from us because we're
running a secure
computer.
WE HAVE CLASSIFIED INFORMATION on it
that no one on the outside could ever
see. And we have these special things
called air gaps. And and this means that
we're impervious to all this. But I
negotiate with them for 15, 20, 30
minutes and I say, "Uh, would you like
to see this in the newspaper?" And they
say, "Well, maybe we'll just pull the
plugs on all of these uh uh modems." And
from then on the guy, our hackers no
longer would break into our system by
way of of this and they would come in
through X25 links after MITER tightened
security and [snorts] um
Oh, cool, cool. Oh, neat, neat, neat,
neat. Um,
is that visible?
>> Um, people in the front, you could say
it's visible. People in the back, can
you read that?
Yes. Okay. Um, if not, go away. Um,
[laughter]
this is a copy of my lab notebook from
September 17, 1986.
Um, um, perhaps the most powerful tool
that I had in this research was just a
written notebook. Nobody in computing
ever writes things down.
So if you do, you will you'll amaze
everyone. The rule of thumb at an
observatory is if you don't write it
down, it didn't happen.
So keep a notebook. Any rate, this guy
was using Telnet. This is before the
days of SSH. And I got out an old fuel
hacker tectronics oscilloscope to
measure packet delay times between IP
packets going up to the guy reflecting
back and coming back. And so um I
averaged about a half dozen or so of
them to find that round trip from from
my system in Berkeley to wherever this
guy was was 2.84
seconds round trip.
>> [snorts]
>> So, let's see what that turns out into.
[laughter]
[cheering]
[applause]
Uh,
>> that is that in focus?
>> Good enough. Okay. 2.84.
One, two.
2.84 84 seconds divided by 2
is 1.4 something 1.4 1 point yeah 1.41
or 1.42 around let's call it 1.4 4 times
the speed of light. Let's call it 3 * 10
5 kilometers/s. Let's multiply by 3
to find at the speed of light. The
packets are coming from about 400,000
kilometers away. Well, you know, and I
know that the moon is 380,000 kilometers
out. So, the guys on the far side of the
moon or maybe a little bit beyond that.
So this is sort of a dead end but it
kind of gives you an idea of how a
physicist might approach this kind of
problem namely with his head up his
never mind. Um um so um so that happened
and so this was sort of a dead end. Then
a few a few weeks later, October of
2020, October of 1986,
I'm looking at the printout. The guy
comes through and he downloads
our Etsy password file.
Hey, downloads my password file. I look
at it and say, "Good luck, Charlie.
That's encrypted. You might as well have
downloaded a bucket of guacamole.
Three, four days later, he logs in on
new accounts.
Ouch. This guy's cracking our passwords.
So, I'm saying this is this is weird.
Um, and I I'm I'm sort of
Oh, cool. Yeah. Yeah. Yeah. Yeah. Yeah.
Yeah. Yeah. Um, meanwhile, I'm sort of
in an interesting position of we're down
here in Berkeley,
down here in Berkeley and watching this
guy go over the data defense network,
the defense data network, and he's
trying to get into literally hundreds of
defense contractors and military systems
and getting into about between five and
15% of them, depending upon what you
mean by getting into. Sometimes he'd be
rude, other times he's a guest, other
times he's in there and screwing around,
but it's hard to say what what his
privileges were. We're tracking things
through an X25 network called Timeet
into um across the Atlantic into Europe
from there into a microvax computer at
the University of Braymond back to the
German DEXP network in northern Germany
uh northwestern Germany. But there are
track stops and I'm there feeling like
um
I I'm feeling like I'm a puppet on the
strings of my page boy. Every time this
hacker breaks in, I have to go running
all over the place to try to find OUT
WHERE THIS GUY'S COMING FROM. And and
I'm saying I
so
>> [laughter]
>> So I'm there and meanwhile my pager
itself is on the strings of this hacker
wherever he is.
January 12, 1980
87.
It's been five months in. I'm getting
several nights of sleep every week. Um,
oh, cool. Can I have it?
Thank you.
This looks like one that I used to own.
[laughter] Um, so January 12, 1986,
hacker breaks in. By then, I'd bumped
into an FBI agent named Mike Gibbons,
who cared a lot about computing. in part
because he built his own in partly
because he's running a BB of bulletin
board at the time. And so um this guy
breaks in to my system in January 12,
1987. I call the FBI. FBI calls the
legal ates in Bond Germany. The American
legal ates who calls up the Buddhist
criminal. Buddhist criminal calls the
German Buddhist post. The Bundus Post
calls the Deutsche Telecom up in
Hanover, Germany. They send a a guy
driving as fast he can across downtown
um Hanover, Germany, gets to the
telephone switch system and the hacker
disconnects before a trace gets made.
>> And so I find out about it and I'm
feeling sorry as salty as a sack of
sauerkraut. And they tell me, "Look,
you're going to need to keep the hacker
on for an hour because this was in the a
few of you probably remember this was in
the days that telephones had tails. They
had these little things attached to them
called wires.
Remember?" Yeah. Yeah. Yeah. Of course,
you say. But, you know, they weren't
things that you carried around in a
pocket, you know, and and and
when you made a telephone call, no
kidding, you didn't ask Siri to do
something. You took your finger and put
it in a thing called the dial. And you
go
and because it had this wonderful wire
five 10 kilometers away from you,
there'd be a bunch of solenoids, relays,
crossbarss that would go.
And in order to make a phone trace,
someone had to count the number of boops
and and
they had to physically be there.
So we needed an hour, maybe two hours to
make this phone trace. So what do you
do?
>> Oh, that's the wrong one. You don't
It didn't work.
I'll try this one.
>> Yeah,
[laughter]
>> this one works.
[laughter]
[applause]
>> [laughter]
>> So,
so, so how do you keep a hacker spy
online
for a couple hours?
Well, I'm thinking about it and I
realize this is an ideal instance where
you apply mathematical game theory, a
very popular form of mathematics here in
Las Vegas. Um, game theory talks about
how opponents and adversaries sometimes
co collaborate, sometimes oppose one
another to make progress. So, um, and of
course, my form of game theory, I
figure, oh, would be
chess.
Now, wouldn't it be cool to be a really
good chess player, to have a rating
of,500,
1,800?
Well, this guy Arthur Bisquer is going
to show you and you too how to win at
chess.
And he's not your ordinary chess player.
He's a master chess player. And as
master chess players go, he's not your
ordinary master. He's a grandmaster.
And he's not your ordinary grandmaster
either. He's an international
grandmaster is Arthur Bisquer. He's
going to teach you and me how to always
win at chess.
And
it turns out all you need to know
is rule number two.
You want to win at chess,
make the best possible move.
[applause]
So in this case, what's the best
possible move? How much time do I have?
Quick.
>> What?
>> 15.
>> I'm way late.
15. So, somebody set up a clock here,
would you?
>> So, in the immortal words of the San
Francisco Chronicle, Stole and
Sweetheart were in the shower together.
We were conserving water. Um, when they
came up with the answer, which they
dubbed Operation Showerhead, they would
create a very large file full of
completely bogus documents that about
the things that we knew the hacker was
interested in. We the time that he spent
online would give the police time to
track him down. We tried to make the FI
look really bureaucratic and boring. His
girlfriend said if we had said, "Look
here, it's classified information. He'd
have caught on right away." The trick
worked. The hacker came across the file,
spent more than an hour downloading it,
and during that time, the German police
were able to trace his phone number.
Stole and his girlfriend celebrated
their triumphs with milkshakes made from
homegrown Berkeley strawberries.
[applause]
So these guys were looking for military
secrets.
13 minutes. Would somebody come up and
back up this clock? Please wind it
backwards. So we created a bunch of
files called about the strategic
defensive containing bureaucratic memos
crap like this. January 16 guy breaks in
and yep I call the FBI. The FBI calls
Germany and the trace gets made all the
way back to num apartment number four at
one Glocky Strasa in Hanover Germany.
And
this we've planted dozens of fake
documents. This is just one of them. And
I'd show you a magnified one, but I'll
just read it out. It's from SDI network
project 50351, Berkeley, California.
Name, address, city, state. This is a
pile of
hoie. Um, it's it's a form letter. Dear
sir, thank you for your inquiry about
SDI Net. We're happy to comply with
this. We'll send you the following
documents. 37.6 SDI network overview
description document functional
requirement document
um uh computer networks all this stuff
it's one of dozens and dozens of boy I
can't even read it on the screen tough
um
probably you can't either so I can't
find it anywhere tough on you guys um so
sincerely yours Mrs. Barbara Sherwin.
Some of you, any of you Unix jocks?
Well, for the two people who know Unix,
notice that there's a more command. You
don't use that command. You use the less
command. This was back when more was
around and less is more than never mind.
So, um, it's like dog and cat. Um um so
all of us celebrated, you know, I we're
in the backyard singing dingdong, the
witch is dead. But the Bundus Criminal
Lot doesn't arrest the hackers. They
wait a day. They wait a week. They wait
a month. They wait four months.
And while they were waiting to catch
these guys,
who's c who's did I just step on?
Uh, the screen is broken. I'm sorry.
Could you put another one up here,
though? [laughter]
Um,
so
so an even weirder thing happened while
during this time, namely
I get a letter in the mail. The post
brings a ma a letter to Mrs. Barbara
Sherwin at LBL Mailtop 50351
dated April 11th, 1987.
Some guy at 6512 Ventura Drive,
Pittsburgh, Pennsylvania
says, "Dear Mrs. Sherwin, I'm interested
in the following documents. Please send
me a price list." Llo J. Balo and he's
looking for document 37.6 6 SDI network
def um description document 41.7
functional requirements. This guy in
Pittsburgh is asking for all the crap
that these hackers wanted back in
uh uh what that were uploaded to
Hanover, Germany. So I'm looking at this
AND I DID EXACTLY WHAT YOU WOULD DO.
I called the FBI.
A guy at the FBI says, "Oh my god,
WHY? YOU GOT A POSTAL LETTER. Whatever
happens, DON'T TOUCH THAT LETTER.
It's got fingerprints on it.
Go get some latex gloves. Don't touch
this.
>> [applause]
>> Sorry.
>> Get some latex gloves
and a glassine envelope and send it to
us over here at the FBI crime
headquarters in Washington. So, latex
gloves are real easy to find at physics
labs. But someday you try to find an 8
and 1 half by 11 glassing envelope. Good
luck. So I'm there and get these gloves,
find this glassine envelope. I go over
to get this. Oh, you don't have it. It's
over here.
NO, DON'T YOU TOUCH IT. GOOD GOD, DON'T
TOUCH IT.
>> I'M A LAWYER.
>> DON'T TOUCH IT.
HERE, give me those gloves. LOOK, YOU
GOT TO put these gloves on and right,
you got this on and you put this on and
you got this glassy envelope and
and I'm there
and he says, "No, you can't just pick it
up, right? You have to pick it up from
around the You can't pick it up from the
edges. You have to pick it up from
around the middle because the
fingerprints are all around the edge.
So, I'm there.
I'm over there holding it like this,
fumbling it into a
piece, a glassy envelope like this. I
finally get it in. You try doing it
someday, wearing gloves that don't fit
you. And I get that far in and I get
into the FedEx box and I'm over in the
basement of building 50. And so I go
running over as fast as I can to get to
the 430 drop off in downtown Berkeley.
Right. So I'm running over to get over
to the
FedEx drop off box and entirely by
accident I bumped into a Xerox machine
which is why I've got a copy.
>> [applause]
>> This phone is broken again.
>> What?
>> I know I'm good, but the phone isn't.
Um, where's my pencil? Don't Don't take
that. Um
any rate the circle was closed.
Five
five hackers
East German Stacey Soviet KGB.
Um [snorts]
in exchange for Deutsch marks and
cocaine
they supplied passwords, accounts and
techniques for breaking into North
American military systems.
Um, Lazlo turns out that he was a
he was a little he was a little guppy.
He was a small the the FBI told me he
worked for the um
Set it backwards. Set it to 15 minutes.
Change it to 15. He's not looking. Just
set it back to 15 minutes. Um um
[cheering]
uh [applause]
um
the FBI told me that he was working for
the Bulgarian embassy. He was a small
cog in a much bigger machine. Meanwhile,
what started out in the basement of
building 50 up at Lawrence Berkeley Labs
turned into something way bigger and way
farther. I must have talked to about a
dozen three-letter agencies. Some of
them were absolutely wonderful people
who wouldn't lift their fingers. Others
were jerks that wouldn't lift their
fingers. Most of them were somewhere in
between kinds of people that wouldn't
lift their fingers. Um the FBI started
out saying, "Go blow it out your
whatever." And but finally came around
the NSA. Oh, the NSA, they wanted to
know all the details of everything. They
wanted to know timing. They wanted to
have copies of my log book. They wanted
to know, "Oh, tell us what these network
user IDs are." Well, I call them up and
say, "Hey, can you help? Can you sort of
uh help us get a phone trace? Can you
interpret what these network user IDs
are?" They said, "Look, we can't even
confirm that we're talking to you, let
alone help you." [laughter]
Oh. Oh, cool. the CIA um call up the CIA
and they send these two guys in suits
and ties out to talk to me in Berkeley.
And we went over to Blondiey's Pizza in
Berkeley uh where they're hanging out
with all these long hairs and they were
um how should I say they were their
camouflage was not very evident. Um
[laughter]
um but the cool thing was they invited
they said look we don't think this is
very important. Um,
>> no, no, no. Back it off. 10 minutes.
Three minutes. I can't do three minutes.
Come on. Um. Um. Uh. So, they invited me
out to the CIA to do a talk. And I got
the coolest thing you can imagine.
Something that nobody else here has.
I got a V front visitors VIP parking
permit.
good for three hours. I can block I can
park right next right at the front
headquarters at the steps and it's good
any time I want as long as it's
September 5th, 1987. Um,
so in retrospect,
we were accidentally inventing intrusion
detection, honeypotss, operational
security, the stuff you'd imagine. I
just didn't know it at the time. As the
investigation wound up, the NSA asked me
to give a talk at Fort me, which is
where most of these slides came from.
[snorts]
And in advance, they gave me seven
questions to ask. Would you please
address these things because we don't
want our audience asking questions.
These questions cheesed me off. Look at
them and see if you can see what's wrong
with these questions. What's why was I
upset with these questions?
How was a penetrator tracked? What
auditing features exist? How do you
audit somebody with system level
privileges? Please supply tech details
on penetrating computers. How were
passwords obtained for the Livermore
craze? How were super user privileges
obtained? Did the penetrator guard
against detection? Well, I looked at
these and I said, "These bother me and
they bother me significantly."
And this morning when I was up in the
speaker prep room, I scribbled down
what's wrong with them.
What's wrong with these questions?
They're detached.
They're third person passive voice.
They're disconnected from the people
involved.
There's a neutral
penetrator.
There's a someone.
There's an unnamed actor.
There's no judgment.
There's no ethical frame of reference.
[laughter]
There's no thought. There's no thought
of who's being exploited,
who's being hurt.
You ask questions like
these
and the hunt becomes a technical puzzle.
You check in at 9 in the morning, YOU
CLOCK OUT AT 5. You call it
incident response.
>> [applause]
>> DAMN IT ALL. THAT ain't me.
I slept under my router.
I WATCHED LOGS SCROLL BY AT 3 IN the
morning.
I unwound twisted pairs one hop at a
goddamn time.
I can't sit back and say
access was obtained. No,
a person broke in.
A person made stole passwords. A person
made choices.
You don't stay neutral after that.
I'm involved.
It brings judgment.
It brings the uncomfortable clarity that
this isn't a systems problem.
It's a human one.
Neutrality.
You spend a year of your life
chasing somebody down
after 12 phone traces and a dozen pots
of coffee.
And God knows how many missed nights of
sleep.
You stop saying
threat actor.
[laughter]
So I took those questions
[snorts]
and I recast them for the NSA.
How did this how did this skunk guard
against break into computers? What
systems did the snake slither into? How
did this scoundrel become super user?
How did this rodent
get cray passwords?
Did this rap scallion guard against
detection?
Did this HOW DO YOU AUDIT A varmint
whose systems manager?
[snorts]
How do you trace an egg sucker back to
their roost?
>> [snorts]
>> and especially why are we working on
this when there ain't nobody lifting a
finger to help? And the answer is all
everybody in the room already knows. But
when you're emotionally invested,
hold on, they're waving something at me.
[laughter]
[applause]
>> [cheering]
>> When you're emotional
when you're emotionally invested, your
questions change both in direction and
tone.
You're not satisfied until you
understand.
It's like the mathematician David
Hilbert said, "We must know. We will
know.
We caught the hacker, but I never quite
caught my breath.
Four decades later today, I can still
feel my outrage. SHOULD I SHUT UP?
[cheering]
>> Should I shut up?
>> Wrap it up. [cheering]
Well, I will wrap it up then.
>> Okay, I'll I'll move ahead 40 years. 40
years later today, well, 40 years ago,
there was no cyber security industry.
There were no bug bounties.
There was no defcon.
>> We did have good chocolate chip cookies.
[cheering]
[applause]
>> But we were making up as we went along
in return for going over. You can have
half half my cookie.
>> [applause]
>> Compare 1986 to today.
Back then there were thousands of nodes.
Today there's billions.
I chased a halfozen hackers. You
You're facing whole nation states, crime
syndicates, maybe even a teenager. Um,
I was one guy alone.
Look to your left, look to your right,
look in front of you, and look behind.
You've got colleagues, you've got
friends. There are any number of
websites, books, and conferences you can
attend.
You're not alone.
I was in a trusted, friendly network.
Today, there's zero trust.
And your Defcon badge cost 700 times
what we invested in this.
[applause]
>> I'll shut up. I know you're pissed off.
I'll shut up. You're not pissed off. Oh,
[laughter]
>> you've been listening to a 76-year-old
hacker.
[cheering]
[applause]
>> [cheering]
[applause]
>> I am
[applause]
I'm
[applause and cheering]
I'm [applause]
I'm tickled. I'm tickled to be a member
of this tribe. I'm honored to rub
shoulders with the goons.
I'm [applause]
after 40 years, I have not yet closed my
last shell script. I'm not yet ready to
log out.
You'll still
[applause]
you'll still find you'll still find this
tired old greybeard studying planets,
tracking packets, making Klein bottles.
But as I
but as I tiptoe off stage with a
shepherd's crook around my neck, notice
how the gray beards are trying to do
that. Uh,
I pass the soldering I pass the
soldering iron to you. Don't burn your
fingers. [laughter]
Stay creative.
Stay enthusiastic.
Tell your stories with glee.
[applause]
40 years from now.
40 years from now, may you
be up here at this podium
at Defcon 74.
You will be talking about
that wonderful simple antique time
of 2026
and comparing it to the bewilderingly
fantastically advanced universe of 2066.
And if I've done my job right,
you won't be quoting me.
No, you'll be chasing down your own 75
cents.
[cheering]
[applause]
>> [applause]
[music]