The KGB, the Computer and Me – The Cuckoo's Egg Story (1990) [video]
youtube.com
youtube.com
So Bob Morris's son froze two thousand computers. Why? To impress his dad? As a Halloween prank? To show off to a couple thousand computer programmers?
Whatever his purposes were, I don't believe he was in cahoots with his father. Rumours have it that he worked with a friend or two at Harvard's computing department (Harvard student Paul Graham sent him mail asking for "Any news on the brilliant project"), but I doubt his father would encourage anyone to create a virus. As Bob Morris Sr, said, "This isn't exactly a good mark for a career at NSA."
The Cuckoo's Egg was formative in my youth. Great book.
IIRC I randomly picked it out from the local Borders too (realize I'm dating myself with that one) so that's some real "Dalai Lama reincarnation" stuff going on there. Like it was fated...
I honestly think that was an excellent idea - there’s a good amount of valuable lessons for an analyst to glean from reading it.
I can think of very few other books in the IT security field that are as well written and as compelling besides maybe Silence on the Wire, The Tangled Web, or Innocent Code.
The first episode is "Spycatcher" and based on The Cuckoo's Egg, so I wonder how similar it is to the other productions. Unfortunately, I can't find it in the usual places and "Yorkshire Television" who owns the footage doesn't exist anymore.
He enclosed a really nice brief note. Amazingly nice guy!
Echelon was something a lot of online techies had heard of by 1989. (I was just a teen, and I'd heard of it.) There was at least one book about it.
It was so well-known, and joked about, for so long, that one time I made a nerdy joke referencing Echelon to an ex-NSA person. When they responded simply, "What's Echelon?", I realized I'd put my foot in my mouth, by rudely putting them in an awkward position. I guess that they still weren't allowed to talk about even long-public information about it.
Before the Snowden disclosures there were all these capabilities and methods that you would've come up with, if you'd taken a smart techie and asked them, "If it was your job to build out surveillance capability, with NSA scale of resources, what kinds of things would be possible with what you know of computer-ish technology today?"
After all the decades of jokes and speculation, it was still funny-odd to see that, yes, it's for real.
Not entirely like Galaxy Quest, but at least the dorky parts: https://www.youtube.com/watch?v=nF_6OfgbF7c
It took the more salacious variants of those stories like nsa people spying on exes[1] to get public mildly interested.
The sad thing is you are not wrong; as little as I knew back then in an irc channel. I remember after a particularly questionable comment I made a follow up with comment basically telling nsa its a joke. Then again, today people seem to add 'fbi agent' trope.
I think one reason that this knowledge faded into the background is that in the 80s/90s it was mostly tech geeks who where concerned. Many people didn’t use computers or Internet at all back then. So to them it all probably felt very abstract. And then people forgot about it. Until Snowden revealed what he had found.
IIRC (and I likely don't), what I read was some employee that saw people coming in and out with equipment, some of which he recognized as storage and other data-reading stuff, and a lot he didn't, and he was made VERY aware that he was not to talk about this, or even be in the area any longer or ever again, for any reason.
My recollection was that I did this reading in the mid 90's. But the wikipedia article for that room dates later, so this is the cause of my apprehension of placing the exact time.
https://www.gnu.org/software/emacs/manual/html_node/emacs/Ma...
Looks like copyright date of 1988:
https://github.com/emacs-mirror/emacs/blob/master/lisp/play/...
https://github.com/emacs-mirror/emacs/blob/master/etc/spook....
Try `M-x spook RET` in an Emacs buffer.
We are 30 (I guess?) years after that book, and I still have nothing better to recommend.
Definitely felt more successful than me even before I heard (through alternate means) who I talked with XD.
Never seen anything about what happened to Markus afterwards and seemed gauche to ask.
- Reached out to a Russian troll on twitter via DM to discuss some specific topic he had mentioned. I try to engage the conversation on this topic which requires "blowing up his cover".
- The shill gets angry and asks me to imagine what he would do to me.
- My reply convince him I'm a US intelligence officer. After some nervous back and forth between blocking and unblocking me, someone else seems to be on the other side of the line and asks me to talk to my manager/officer, using some spy scheme from a movie. I back the fuck out.
- About a week later, I realize there is an "iCloud" segment in my finder left vertical bar. All the sync settings are ticked, including stuff I do not use. I go check the sync folders' last modified time: a mere two hours after I had this conversation on Twitter.
- Go back on twitter to see what the shill is up to. He's complaining about suffering a breach of his iCloud account and blames some intelligence service in Frankfurt, providing a picture of the building.
I have no idea what I have stepped into. Was it some counter-intel honey pot ? Then it was pretty well made. Or are these people genuinely working for some russian service ? If so, then they are batshit crazy, arrogant and not as professional as one may expect.
As a result I nuked my github and stopped using my phone, my watch, youtube account, etc. I was promised open brain surgery/interrogation by people that are allegedly expert doxxers and torturers and thought I was an intelligence soldier fighting against them.
One hopes “the community” listened at least as much to him, considering the internet security community apparently was hardly worth a damn before all this happened.
[0] and was, coincidentally, basically the first person to use the term “The Internet” (proper noun, emphasis on The) in widely read non-fiction, outside of a training manual and research document or two.
From Phrack #32
``The Cuckoo's Egg'' captures many of the popular stereotypes of hackers. Criminologist Jim Thomas criticizes it for presenting a simplified view of the world, one where everything springs from the forces of light (us) or of darkness (hackers) (Thomas90). He claims that Stoll fails to see the similarities between his own activities (e.g., monitoring communications, ``borrowing'' monitors without authorization, shutting off network access without warning, and lying to get information he wants) and those of hackers. He points out Stoll's use of pejorative words such as ``varmint'' to describe hackers, and Stoll's quote of a colleague: ``They're technically skilled but ethically bankrupt programmers without any respect for others' work -- or privacy. They're not destroying one or two programs. They're trying to wreck the cooperation that builds our networks,'' (Stoll90, p. 159). Thomas writes ``at an intellectual level, it (Stoll's book) provides a persuasive, but simplistic, moral imagery of the nature of right and wrong, and provides what -- to a lay reader -- would seem a compelling justification for more statutes and severe penalties against the computer underground. This is troublesome for two reasons. First, it leads to a mentality of social control by law enforcement during a social phase when some would argue we are already over-controlled. Second, it invokes a punishment model that assumes we can stamp out behaviors to which we object if only we apprehend and convict a sufficient number of violators. ... There is little evidence that punishment will in the long run reduce any given offense, and the research of Gordon Meyer and I suggests that criminalization may, in fact, contribute to the growth of the computer underground.''
You don’t say!
If you were to tell Mr. Stoll and his audience that that in the future one of the most popular information places would be called Hacker News they would get the opinion very quickly that the good guys apparently lost in the future. I guess I can't really describe it, but this mindset would've been very bad had it survived, but thankfully it hasn't, and couldn't.
This would've been impossible probably, but ideally Mr. Stoll should've worked to explain in detail the vulnerabilities and mitigations and tried to explain those things as making crime inevitable. That's what we do today, but for a long time people thought that was just giving bad people ammunition instead of how we see it today as part of a whole arsenal of perspectives and strategies.
In the late 90s during several Q&As Mr. Stoll came around to agree with many of our modern concepts of security, once he understood more of the game mechanics and some other understandable confusion stuff... He wasn't as online perhaps as many people are today, and to my understanding never formally worked in security nor wanted to.