Submind YouTube summaries
Thumbnail for DefCon 34 - Stalking the Wily Hacker: 40 years later - Cliff Stoll

DefCon 34 - Stalking the Wily Hacker: 40 years later - Cliff Stoll

Watch on YouTube

Video summary

Cliff Stoll recounts his famous 1986 experience at Lawrence Berkeley National Laboratory, where he discovered a $0.75 accounting error that turned out to be the work of a sophisticated hacker. At a time when the internet was a small, trusted playground with only thousands of users, Stoll noticed anomalies in his system logs and realized someone had gained root access to search for nuclear secrets like plutonium and ballistic missiles. Instead of immediately disabling the intruder's access or calling law enforcement who dismissed the low financial loss as unimportant, Stoll decided to track the hacker himself. He set up a makeshift monitoring station in the basement, sleeping under his router and wiring together printers and teletypes to capture every connection attempt, effectively creating one of the first honeypots in history. The investigation led Stoll on an international chase that spanned from California to Northern Virginia and eventually across the Atlantic to East Germany. He utilized primitive but effective tools, such as a soldering iron, a pager modified to receive Morse code, and a written notebook to document his findings, as he noted that in computing, if it isn't written down, it didn't happen. By analyzing packet delays, he could estimate the hacker's location was near the moon, eventually narrowing it down to a military contractor in Hanover, Germany. To keep the hacker online long enough for German authorities to trace his phone line, Stoll employed game theory and created dozens of fake documents about strategic defensive initiatives, baiting the intruder into downloading them while police waited for the connection to time out. Stoll's talk concludes with a powerful reflection on the evolution of cybersecurity and the human element behind it. He criticizes modern security questions that treat hackers as neutral "threat actors" or technical puzzles, arguing instead that they are real people making choices that cause harm. He contrasts the trusted network of the past with today's zero-trust environment, noting that while we now face nation-states and massive syndicates rather than a single individual, we also have a vast community to support us. Stoll encourages the audience to remain creative, enthusiastic, and emotionally invested in their work, urging them to chase down their own "75 cents" of curiosity and responsibility in the future, ensuring that the next generation continues to tell these stories with glee rather than just quoting him.
Read the full video transcript
Is everybody having a good Defcon? [cheering] Let's freaking go. >> Go ahead. >> Oh, should I introduce you, Ringer? Oh. Uh, >> first first it's my honor and delight to introduce the ringer to Oh, I'm being Oh, I'll go fast. Here's >> to me. >> Go. >> Well, now it is my honor and privilege to introduce someone who absolutely needs no introduction. So, without further ado, Cliff >> and [cheering] Hot damn. Thank you, Mesley. Um um before I even start, I'd like to say thank you to Ayatsi Ayatsi Local 720 and the Culinary Workers Union 226 who have been cleaning up this dump and fixing things. So, thank you. Thank you, culinary workers. And especially thank you to the one person in this logo in the culinary workers union 226, my cousin Lynn. So um [applause] I will I will not point out who she is. Um [applause] having said that having said that it's worth my time to point out to you I'm going to be using an overhead projector today. if you [cheering] you know view graphs um from a talk I gave at the NSA about 25 35 years ago. If you don't know what this is, ask your grandparents. Um [laughter] at the same time, my talk is on the bottom of my hand so those in the front row can see what I'm going to say. Um um worth mentioning also, you are welcome to use your cameras during my talk. I don't give a half darn. Um Um So having said that, what I'd really like to talk about, show that thing that that that bottle. Toss it over. Just throw it here. What I'd like to talk about today are Klein bottles, non-orientable surfaces. I'd like to talk about well I'd genuinely like to talk about remmanium manifolds but unfortunately um I'm not going to so I won't tell you how tr how terrific these are um um because today marks an anniversary August 8th 1986 40 years ago today I stumbled into a how should I put it I stumbled into a 75 cent accounting error. I'd been an astronomer up at Lawrence Berkeley Labs and and we finished the optical design of a big telescope, the Kek 10 meter. And so I went down to the basement of building 50 where I started managing a bunch of UIX boxes. Now this was in the old days back when back when the arpanet was growing really fast. There were 400 500 maybe 700 nodes online and the inter and the early internet the early arponet was I can't see anything any rate the early internet was growing gang busters there must have been it was astonishingly crowded there was probably 4,000 maybe 8,000 people online and you didn't worry much about it because the it was a you trusted who was there. It was a playground built on mutual trust. Meanwhile, computing itself had value. Is today you're walking around with a supercomput in your pocket. Back then, well, no. Um, we charged for CPU cycles and we charged for compute time. So, I'm there and my second day on the job, our accounting program goes belly up, dead in the water. And I'm I I look and I walk and say, "Weird." And I say, "Oh, this is cool. I can fix it. It's probably a corrupt accounting database or a problem in the account system." You know, we had a new user who had used 75 cents of time. But they think, "Curious, this is interesting. I'm CIS manager. I'm the only one who ought to be able to add a user to the password file." So, I look and think, "Something's hanky here. Could somebody be on my system? How could I tell?" And so I took advantage of one of the very few things that I learned in graduate school, namely that it's easier to apologize later than to get permission in advance. >> [applause] >> So I waited I waited around until until 6:30 7 o'clock on a Friday afternoon and I got one of these push cart lab carts, you know, you know, one of these lab carts. And so I sort of went from office to office, door door to door. Oh. Oh, this is the title of my talk. Um, and that's the guy who's doing the talk and all those other addresses are wrong. This is who I am. Um, and and so I went from office to office and door to door liberating people's printers and teletypes and and decorators and putting them all on this lab cart and pushing them from office to office [laughter] down to the basement of building 50. Once I got to the basement of building 50, I got a um uh soldering iron and a bunch of of Radio Shack clip leads. And there I said, "Okay, I'll wire up all these printers." I scatter them around in a circle behind a bunch of vax computers. I clip leaded them onto the incoming modem bank so that every time somebody connects into my system, I get a print out. Got a sleeping bag, right? Got a sleeping bag. Unrolled it behind the router. Nice warm fan blowing across me. Um, got a thermos of minestrroni. Climbed in the sleeping bag and fell asleep. Next morning, next morning at 7:30, 8 in the morning, my boss Roy Kur comes by. I'm asleep in this old uh sleeping bag. And he sort of gently awakens me and I look up and he says, "Cliff, I understand there's some equipment missing from around the lab." and I'm surrounded by two dozen printers and teletypes and I say I haven't the fadest idea and he looks down and says it would be a right neighborly thing if everything were returned now. So I go over push cart and gather up some of these printers and decorators and and from what are these what decorators and printers there's 10 meters there's 30 feet of yellow paper and I start looking at it and I could see how somebody has come into my system in the middle of the night used a cron tab script to get become to fire off a set user ID to root and then bumped himself up to root, turned off the accounting program and then went out over a local area network through our router, the third router that Cisco had ever built um through our router onto what was then called the Arpanet. And then he starts going out through the milnet side, the military side, 10.0.blit.blatz, and he starts systematically knocking into military computers on the milnet. And when he gets in, he starts he starts he starts gpping for things like ballistic missile, like plutonium, nuclear. Now, this is I I'm looking at this and it's triple weird because we're in Berkeley, California on the far left side of the continent. So, you know, it's where great you might find Grateful Dead concerts and and street protests. Somebody might grep for granola recipes, but they're not going to be searching for nuclear espionage. I'm looking at this saying, "This is weird." So, so I knew that real soon there'd be there'd be a meeting. And sure enough, Monday morning, we had a departmental meeting. So, what do you do? Is this Is this Can you read this? >> Can you read it now? >> Good. So, what do you do when you find somebody breaking into your computer? Seems to me, and these these are slides that I, you know, um seems to me it's obvious. You you make you disable their access. Make sure that they can't get in anymore. Change people's accounts, change your passwords, tell your systems users, and be quiet. Don't publicize it. or do we or do do we try to catch him? The lab director was a guy named David Shirley. Now Dave Shirley had his head screwed on straight. He says, "Look, [snorts] someone's messing with our files. Someone's trying to commit espionage. I want you to take all the equipment, ALL THE TIME, ALL the resources you need. catch the rodent. Take three weeks if you have to catch them. So, so I rewrote the rules. [cheering] When when we find somebody breaking in, [snorts] when we find somebody breaking in, we let the guy in. We keep the hole wide open. I want to make it look like we're stupid, which is pretty easy to do. Um, on the other hand, I want to monitor everything. I want to see every keystroke that's typed in. I want to see every character that's echoed back. At the same time, I want to find out where this guy is coming from. I want to trace things back and find out what the connectivity is from over here to over there and what's to be done about it. [snorts] I want to hold this guy in my hand. I want to know who it is that's screwing with my system. Immediately there was a problem. [snorts] [laughter] [snorts] We had no budget. The entire hardware budget for this one-year project was 0. Adjusted for inflation. at $0 million. We had no expertise, no experience. Nobody taught me what to do about this in grad school or even in undergrad. You know, there was no I couldn't go and ask a question on Reddit. [snorts] Then there's no mandate. Nobody said, "Look, it's your responsibility to catch this guy." No. Several organizations, including my funding agency, which was a, you know, they're the Department of Energy, said, "Don't do this. If people find out there's a hacker in a DOE computer, they'll cut our funding." So, what do you do? What do you do when you're broke, when you're stupid, and you're discouraged? [laughter] [applause] >> Welcome to research. [cheering] [applause] Think of your own situation. It never has happened that you've had too much money. You're never know too much. You never You never have too much encouragement. So what do you do? You do what's cheap and primitive. You take a screwdriver and you use it as a chisel, a crescent wrench, you use it as a hammer. And the result is you come up with creative solutions on the fly. That's mostly what I'll be talking about today. So um we started out by calling, you know, started out by calling the FBI. They had a field office in Oakland about 5 10 kilometers south of us in Berkeley. HEY FBI, SOMEBODY'S BREAKING MY COMPUTER. THEY'RE GOING OUT OVER they they rooted themselves using sec user ID to root and fired off using crotab. They went over the arponet into into the milnet 10.0.lit.blast. They're going over into systems and they're gripping for nuclear and plutonium. Guy at the FBI says, "OH MY GOD, THAT'S SERIOUS. I MEAN, HOW MUCH money did you lose?" I said, 'Well, we've lost about 75 cents. [laughter] Guy at the FBI says, "Um, call back when you're down half a million dollars." So, that didn't seem like fun. So without the FBI's help and approval, I decided to just sort of quietly track the hacker across the networks, I got uh I borrowed a pullet hacker serial line analyzer um which was uh and I programmed it to call my pocket pager every time it recognized the account or the password that this guy was and set it up in a way that the um uh I got out the soldering iron and rewired the Motorola page boy so I could send Morse code to it using touchton tones uh a protocol that's not very well known anymore but um um oh yeah yeah um cool uh mind you all these are from a talk I gave in 1987 at the NSA so uh if they if you can't read them That's okay. I can't either. Um um so I began unwinding connections first over a local area network, then across the phone system. And um early on I noticed whenever the guy logs in, I'd look at the printout when this guy's getting into it. And I noticed that he'd right away type the Unix PS command. Um, for those who are not Unix jocks, everybody who knows Unix knows the ps command process status. It lists all the processes that are running. So immediately he'd type ps and this way he can tell who's on the system and what processes are there. He's looking over his shoulder to see who's watching them. And right away I notice something kind of curious. Now when I type PS I type is that visible. >> I type PS dash AXU. I want to look at all the I want to look at all the the processes. I want to see the long form of them and I want to look at all the users. You know, this is kind of, you know, um what he was pretty doing was he'd type PS- GXUA. Well, that's all the same. But this G flag, that was the weird one. I looked at it and I said, "Huh, that G flag isn't in Berkeley Unix." Hot damn. THIS CLOWN IS A HERETIC. [laughter] [applause] He's He probably runs AT&T system 5. [laughter] A heathen. [laughter] So with that, the trail immediately left Berkeley. Nobody in Northern California would ever use anything other than BSD. So, so we started tracing it across North America and it goes east. It gets all the way to Northern Virginia. We get to Northern Virginia and this this operator says, "You know, I made the trace all right, but I can't tell you Um, but the operator says, "I can't tell you the re response till you show me a search warrant." And I say, "Well, look, I don't have a search warrant. I'm just a planetary astronomer out in Berkeley. But what I do have is some real nice pictures of Saturn and the moon. And and she laughed, but I pointed out you could see the Cassini division, the Yankee division, lunar highlands, Mari uh the Sea of Tranquility, and Mari Creium. And she said, "Well," so I put them all in the mail. A week later, we got the phone trace information. [laughter] Um and [applause] the problem was coming from a system at a company called MITER. Now, MITER MITER was MITER was this military contractor who did governmental secret work and and they're over someplace in Virginia, right near like the East Coast and and so I call him up and the guy at the um at the CIS admin for them say, "It's impossible for anyone to be breaking into your system from us because we're running a secure computer. WE HAVE CLASSIFIED INFORMATION on it that no one on the outside could ever see. And we have these special things called air gaps. And and this means that we're impervious to all this. But I negotiate with them for 15, 20, 30 minutes and I say, "Uh, would you like to see this in the newspaper?" And they say, "Well, maybe we'll just pull the plugs on all of these uh uh modems." And from then on the guy, our hackers no longer would break into our system by way of of this and they would come in through X25 links after MITER tightened security and [snorts] um Oh, cool, cool. Oh, neat, neat, neat, neat. Um, is that visible? >> Um, people in the front, you could say it's visible. People in the back, can you read that? Yes. Okay. Um, if not, go away. Um, [laughter] this is a copy of my lab notebook from September 17, 1986. Um, um, perhaps the most powerful tool that I had in this research was just a written notebook. Nobody in computing ever writes things down. So if you do, you will you'll amaze everyone. The rule of thumb at an observatory is if you don't write it down, it didn't happen. So keep a notebook. Any rate, this guy was using Telnet. This is before the days of SSH. And I got out an old fuel hacker tectronics oscilloscope to measure packet delay times between IP packets going up to the guy reflecting back and coming back. And so um I averaged about a half dozen or so of them to find that round trip from from my system in Berkeley to wherever this guy was was 2.84 seconds round trip. >> [snorts] >> So, let's see what that turns out into. [laughter] [cheering] [applause] Uh, >> that is that in focus? >> Good enough. Okay. 2.84. One, two. 2.84 84 seconds divided by 2 is 1.4 something 1.4 1 point yeah 1.41 or 1.42 around let's call it 1.4 4 times the speed of light. Let's call it 3 * 10 5 kilometers/s. Let's multiply by 3 to find at the speed of light. The packets are coming from about 400,000 kilometers away. Well, you know, and I know that the moon is 380,000 kilometers out. So, the guys on the far side of the moon or maybe a little bit beyond that. So this is sort of a dead end but it kind of gives you an idea of how a physicist might approach this kind of problem namely with his head up his never mind. Um um so um so that happened and so this was sort of a dead end. Then a few a few weeks later, October of 2020, October of 1986, I'm looking at the printout. The guy comes through and he downloads our Etsy password file. Hey, downloads my password file. I look at it and say, "Good luck, Charlie. That's encrypted. You might as well have downloaded a bucket of guacamole. Three, four days later, he logs in on new accounts. Ouch. This guy's cracking our passwords. So, I'm saying this is this is weird. Um, and I I'm I'm sort of Oh, cool. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Um, meanwhile, I'm sort of in an interesting position of we're down here in Berkeley, down here in Berkeley and watching this guy go over the data defense network, the defense data network, and he's trying to get into literally hundreds of defense contractors and military systems and getting into about between five and 15% of them, depending upon what you mean by getting into. Sometimes he'd be rude, other times he's a guest, other times he's in there and screwing around, but it's hard to say what what his privileges were. We're tracking things through an X25 network called Timeet into um across the Atlantic into Europe from there into a microvax computer at the University of Braymond back to the German DEXP network in northern Germany uh northwestern Germany. But there are track stops and I'm there feeling like um I I'm feeling like I'm a puppet on the strings of my page boy. Every time this hacker breaks in, I have to go running all over the place to try to find OUT WHERE THIS GUY'S COMING FROM. And and I'm saying I so >> [laughter] >> So I'm there and meanwhile my pager itself is on the strings of this hacker wherever he is. January 12, 1980 87. It's been five months in. I'm getting several nights of sleep every week. Um, oh, cool. Can I have it? Thank you. This looks like one that I used to own. [laughter] Um, so January 12, 1986, hacker breaks in. By then, I'd bumped into an FBI agent named Mike Gibbons, who cared a lot about computing. in part because he built his own in partly because he's running a BB of bulletin board at the time. And so um this guy breaks in to my system in January 12, 1987. I call the FBI. FBI calls the legal ates in Bond Germany. The American legal ates who calls up the Buddhist criminal. Buddhist criminal calls the German Buddhist post. The Bundus Post calls the Deutsche Telecom up in Hanover, Germany. They send a a guy driving as fast he can across downtown um Hanover, Germany, gets to the telephone switch system and the hacker disconnects before a trace gets made. >> And so I find out about it and I'm feeling sorry as salty as a sack of sauerkraut. And they tell me, "Look, you're going to need to keep the hacker on for an hour because this was in the a few of you probably remember this was in the days that telephones had tails. They had these little things attached to them called wires. Remember?" Yeah. Yeah. Yeah. Of course, you say. But, you know, they weren't things that you carried around in a pocket, you know, and and and when you made a telephone call, no kidding, you didn't ask Siri to do something. You took your finger and put it in a thing called the dial. And you go and because it had this wonderful wire five 10 kilometers away from you, there'd be a bunch of solenoids, relays, crossbarss that would go. And in order to make a phone trace, someone had to count the number of boops and and they had to physically be there. So we needed an hour, maybe two hours to make this phone trace. So what do you do? >> Oh, that's the wrong one. You don't It didn't work. I'll try this one. >> Yeah, [laughter] >> this one works. [laughter] [applause] >> [laughter] >> So, so, so how do you keep a hacker spy online for a couple hours? Well, I'm thinking about it and I realize this is an ideal instance where you apply mathematical game theory, a very popular form of mathematics here in Las Vegas. Um, game theory talks about how opponents and adversaries sometimes co collaborate, sometimes oppose one another to make progress. So, um, and of course, my form of game theory, I figure, oh, would be chess. Now, wouldn't it be cool to be a really good chess player, to have a rating of,500, 1,800? Well, this guy Arthur Bisquer is going to show you and you too how to win at chess. And he's not your ordinary chess player. He's a master chess player. And as master chess players go, he's not your ordinary master. He's a grandmaster. And he's not your ordinary grandmaster either. He's an international grandmaster is Arthur Bisquer. He's going to teach you and me how to always win at chess. And it turns out all you need to know is rule number two. You want to win at chess, make the best possible move. [applause] So in this case, what's the best possible move? How much time do I have? Quick. >> What? >> 15. >> I'm way late. 15. So, somebody set up a clock here, would you? >> So, in the immortal words of the San Francisco Chronicle, Stole and Sweetheart were in the shower together. We were conserving water. Um, when they came up with the answer, which they dubbed Operation Showerhead, they would create a very large file full of completely bogus documents that about the things that we knew the hacker was interested in. We the time that he spent online would give the police time to track him down. We tried to make the FI look really bureaucratic and boring. His girlfriend said if we had said, "Look here, it's classified information. He'd have caught on right away." The trick worked. The hacker came across the file, spent more than an hour downloading it, and during that time, the German police were able to trace his phone number. Stole and his girlfriend celebrated their triumphs with milkshakes made from homegrown Berkeley strawberries. [applause] So these guys were looking for military secrets. 13 minutes. Would somebody come up and back up this clock? Please wind it backwards. So we created a bunch of files called about the strategic defensive containing bureaucratic memos crap like this. January 16 guy breaks in and yep I call the FBI. The FBI calls Germany and the trace gets made all the way back to num apartment number four at one Glocky Strasa in Hanover Germany. And this we've planted dozens of fake documents. This is just one of them. And I'd show you a magnified one, but I'll just read it out. It's from SDI network project 50351, Berkeley, California. Name, address, city, state. This is a pile of hoie. Um, it's it's a form letter. Dear sir, thank you for your inquiry about SDI Net. We're happy to comply with this. We'll send you the following documents. 37.6 SDI network overview description document functional requirement document um uh computer networks all this stuff it's one of dozens and dozens of boy I can't even read it on the screen tough um probably you can't either so I can't find it anywhere tough on you guys um so sincerely yours Mrs. Barbara Sherwin. Some of you, any of you Unix jocks? Well, for the two people who know Unix, notice that there's a more command. You don't use that command. You use the less command. This was back when more was around and less is more than never mind. So, um, it's like dog and cat. Um um so all of us celebrated, you know, I we're in the backyard singing dingdong, the witch is dead. But the Bundus Criminal Lot doesn't arrest the hackers. They wait a day. They wait a week. They wait a month. They wait four months. And while they were waiting to catch these guys, who's c who's did I just step on? Uh, the screen is broken. I'm sorry. Could you put another one up here, though? [laughter] Um, so so an even weirder thing happened while during this time, namely I get a letter in the mail. The post brings a ma a letter to Mrs. Barbara Sherwin at LBL Mailtop 50351 dated April 11th, 1987. Some guy at 6512 Ventura Drive, Pittsburgh, Pennsylvania says, "Dear Mrs. Sherwin, I'm interested in the following documents. Please send me a price list." Llo J. Balo and he's looking for document 37.6 6 SDI network def um description document 41.7 functional requirements. This guy in Pittsburgh is asking for all the crap that these hackers wanted back in uh uh what that were uploaded to Hanover, Germany. So I'm looking at this AND I DID EXACTLY WHAT YOU WOULD DO. I called the FBI. A guy at the FBI says, "Oh my god, WHY? YOU GOT A POSTAL LETTER. Whatever happens, DON'T TOUCH THAT LETTER. It's got fingerprints on it. Go get some latex gloves. Don't touch this. >> [applause] >> Sorry. >> Get some latex gloves and a glassine envelope and send it to us over here at the FBI crime headquarters in Washington. So, latex gloves are real easy to find at physics labs. But someday you try to find an 8 and 1 half by 11 glassing envelope. Good luck. So I'm there and get these gloves, find this glassine envelope. I go over to get this. Oh, you don't have it. It's over here. NO, DON'T YOU TOUCH IT. GOOD GOD, DON'T TOUCH IT. >> I'M A LAWYER. >> DON'T TOUCH IT. HERE, give me those gloves. LOOK, YOU GOT TO put these gloves on and right, you got this on and you put this on and you got this glassy envelope and and I'm there and he says, "No, you can't just pick it up, right? You have to pick it up from around the You can't pick it up from the edges. You have to pick it up from around the middle because the fingerprints are all around the edge. So, I'm there. I'm over there holding it like this, fumbling it into a piece, a glassy envelope like this. I finally get it in. You try doing it someday, wearing gloves that don't fit you. And I get that far in and I get into the FedEx box and I'm over in the basement of building 50. And so I go running over as fast as I can to get to the 430 drop off in downtown Berkeley. Right. So I'm running over to get over to the FedEx drop off box and entirely by accident I bumped into a Xerox machine which is why I've got a copy. >> [applause] >> This phone is broken again. >> What? >> I know I'm good, but the phone isn't. Um, where's my pencil? Don't Don't take that. Um any rate the circle was closed. Five five hackers East German Stacey Soviet KGB. Um [snorts] in exchange for Deutsch marks and cocaine they supplied passwords, accounts and techniques for breaking into North American military systems. Um, Lazlo turns out that he was a he was a little he was a little guppy. He was a small the the FBI told me he worked for the um Set it backwards. Set it to 15 minutes. Change it to 15. He's not looking. Just set it back to 15 minutes. Um um [cheering] uh [applause] um the FBI told me that he was working for the Bulgarian embassy. He was a small cog in a much bigger machine. Meanwhile, what started out in the basement of building 50 up at Lawrence Berkeley Labs turned into something way bigger and way farther. I must have talked to about a dozen three-letter agencies. Some of them were absolutely wonderful people who wouldn't lift their fingers. Others were jerks that wouldn't lift their fingers. Most of them were somewhere in between kinds of people that wouldn't lift their fingers. Um the FBI started out saying, "Go blow it out your whatever." And but finally came around the NSA. Oh, the NSA, they wanted to know all the details of everything. They wanted to know timing. They wanted to have copies of my log book. They wanted to know, "Oh, tell us what these network user IDs are." Well, I call them up and say, "Hey, can you help? Can you sort of uh help us get a phone trace? Can you interpret what these network user IDs are?" They said, "Look, we can't even confirm that we're talking to you, let alone help you." [laughter] Oh. Oh, cool. the CIA um call up the CIA and they send these two guys in suits and ties out to talk to me in Berkeley. And we went over to Blondiey's Pizza in Berkeley uh where they're hanging out with all these long hairs and they were um how should I say they were their camouflage was not very evident. Um [laughter] um but the cool thing was they invited they said look we don't think this is very important. Um, >> no, no, no. Back it off. 10 minutes. Three minutes. I can't do three minutes. Come on. Um. Um. Uh. So, they invited me out to the CIA to do a talk. And I got the coolest thing you can imagine. Something that nobody else here has. I got a V front visitors VIP parking permit. good for three hours. I can block I can park right next right at the front headquarters at the steps and it's good any time I want as long as it's September 5th, 1987. Um, so in retrospect, we were accidentally inventing intrusion detection, honeypotss, operational security, the stuff you'd imagine. I just didn't know it at the time. As the investigation wound up, the NSA asked me to give a talk at Fort me, which is where most of these slides came from. [snorts] And in advance, they gave me seven questions to ask. Would you please address these things because we don't want our audience asking questions. These questions cheesed me off. Look at them and see if you can see what's wrong with these questions. What's why was I upset with these questions? How was a penetrator tracked? What auditing features exist? How do you audit somebody with system level privileges? Please supply tech details on penetrating computers. How were passwords obtained for the Livermore craze? How were super user privileges obtained? Did the penetrator guard against detection? Well, I looked at these and I said, "These bother me and they bother me significantly." And this morning when I was up in the speaker prep room, I scribbled down what's wrong with them. What's wrong with these questions? They're detached. They're third person passive voice. They're disconnected from the people involved. There's a neutral penetrator. There's a someone. There's an unnamed actor. There's no judgment. There's no ethical frame of reference. [laughter] There's no thought. There's no thought of who's being exploited, who's being hurt. You ask questions like these and the hunt becomes a technical puzzle. You check in at 9 in the morning, YOU CLOCK OUT AT 5. You call it incident response. >> [applause] >> DAMN IT ALL. THAT ain't me. I slept under my router. I WATCHED LOGS SCROLL BY AT 3 IN the morning. I unwound twisted pairs one hop at a goddamn time. I can't sit back and say access was obtained. No, a person broke in. A person made stole passwords. A person made choices. You don't stay neutral after that. I'm involved. It brings judgment. It brings the uncomfortable clarity that this isn't a systems problem. It's a human one. Neutrality. You spend a year of your life chasing somebody down after 12 phone traces and a dozen pots of coffee. And God knows how many missed nights of sleep. You stop saying threat actor. [laughter] So I took those questions [snorts] and I recast them for the NSA. How did this how did this skunk guard against break into computers? What systems did the snake slither into? How did this scoundrel become super user? How did this rodent get cray passwords? Did this rap scallion guard against detection? Did this HOW DO YOU AUDIT A varmint whose systems manager? [snorts] How do you trace an egg sucker back to their roost? >> [snorts] >> and especially why are we working on this when there ain't nobody lifting a finger to help? And the answer is all everybody in the room already knows. But when you're emotionally invested, hold on, they're waving something at me. [laughter] [applause] >> [cheering] >> When you're emotional when you're emotionally invested, your questions change both in direction and tone. You're not satisfied until you understand. It's like the mathematician David Hilbert said, "We must know. We will know. We caught the hacker, but I never quite caught my breath. Four decades later today, I can still feel my outrage. SHOULD I SHUT UP? [cheering] >> Should I shut up? >> Wrap it up. [cheering] Well, I will wrap it up then. >> Okay, I'll I'll move ahead 40 years. 40 years later today, well, 40 years ago, there was no cyber security industry. There were no bug bounties. There was no defcon. >> We did have good chocolate chip cookies. [cheering] [applause] >> But we were making up as we went along in return for going over. You can have half half my cookie. >> [applause] >> Compare 1986 to today. Back then there were thousands of nodes. Today there's billions. I chased a halfozen hackers. You You're facing whole nation states, crime syndicates, maybe even a teenager. Um, I was one guy alone. Look to your left, look to your right, look in front of you, and look behind. You've got colleagues, you've got friends. There are any number of websites, books, and conferences you can attend. You're not alone. I was in a trusted, friendly network. Today, there's zero trust. And your Defcon badge cost 700 times what we invested in this. [applause] >> I'll shut up. I know you're pissed off. I'll shut up. You're not pissed off. Oh, [laughter] >> you've been listening to a 76-year-old hacker. [cheering] [applause] >> [cheering] [applause] >> I am [applause] I'm [applause and cheering] I'm [applause] I'm tickled. I'm tickled to be a member of this tribe. I'm honored to rub shoulders with the goons. I'm [applause] after 40 years, I have not yet closed my last shell script. I'm not yet ready to log out. You'll still [applause] you'll still find you'll still find this tired old greybeard studying planets, tracking packets, making Klein bottles. But as I but as I tiptoe off stage with a shepherd's crook around my neck, notice how the gray beards are trying to do that. Uh, I pass the soldering I pass the soldering iron to you. Don't burn your fingers. [laughter] Stay creative. Stay enthusiastic. Tell your stories with glee. [applause] 40 years from now. 40 years from now, may you be up here at this podium at Defcon 74. You will be talking about that wonderful simple antique time of 2026 and comparing it to the bewilderingly fantastically advanced universe of 2066. And if I've done my job right, you won't be quoting me. No, you'll be chasing down your own 75 cents. [cheering] [applause] >> [applause] [music]