TK0JUT2%MVS.CSO.NIU.EDU@UICVM.uic.edu (06/11/91)
**************************************************************************** >C O M P U T E R U N D E R G R O U N D< >D I G E S T< *** Volume 3, Issue #3.20 (June 10, 1991) ** **************************************************************************** MODERATORS: Jim Thomas / Gordon Meyer (TK0JUT2@NIU.bitnet) ARCHIVISTS: Bob Krause / / Bob Kusumoto GUINNESS GURU: Brendan Kehoe +++++ +++++ +++++ +++++ +++++ CONTENTS THIS ISSUE: File 1: Moderator's Corner File 2: From the Mailbag File 3: Bay Area Archive Site File 4: Top Ten Fallacies about SJG Raid File 5: Hacking and Hackers: The Rise, Stagnation, and Renaissance File 6: EFFector Online 1.07: S.266 Loses First Round File 7: How to get WATCH.EXE +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ USENET readers can currently receive CuD as alt.society.cu-digest. Back issues are also available on Compuserve (in: DL0 of the IBMBBS sig), PC-EXEC BBS (414-789-4210), and at 1:100/345 for those on FIDOnet. Anonymous ftp sites: (1) ftp.cs.widener.edu (192.55.239.132); (2) cudarch@chsun1.uchicago.edu; (3) dagon.acc.stolaf.edu (130.71.192.18). E-mail server: archive-server@chsun1.uchicago.edu. COMPUTER UNDERGROUND DIGEST is an open forum dedicated to sharing information among computerists and to the presentation and debate of diverse views. CuD material may be reprinted as long as the source is cited. Some authors, however, do copyright their material, and those authors should be contacted for reprint permission. It is assumed that non-personal mail to the moderators may be reprinted unless otherwise specified. Readers are encouraged to submit reasoned articles relating to the Computer Underground. Articles are preferred to short responses. Please avoid quoting previous posts unless absolutely necessary. ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ DISCLAIMER: The views represented herein do not necessarily represent the views of the moderators. Contributors assume all responsibility for assuring that articles submitted do not violate copyright protections. ******************************************************************** >> END OF THIS FILE << *************************************************************************** ------------------------------ From: Moderators Subject: Moderator's Corner Date: June 10, 1991 ******************************************************************** *** CuD #3.20: File 1 of 7: Moderators Corner *** ******************************************************************** A few quick notes: INFO ON BBS CRASHING WANTED: We have had a few queries about the prevalance, methods, and nature of ways to crash BBSs. We are looking for information on ways this has been done (not a "how to" description, but just a simple summary such as the Telegard bug that contained the zipfile bug), on BBS software that have been particularly prone to destructive invasion, or for other information that we can use to put together an article on invasions that allow penetration into they system itself. +++++++++++++++++++++++++ COMPUSERVE CuDS MOVED: The CUD issues on CompuServe have been shuffled around a bit. Recent issues can be found in DL0 of the IBMBBS SIG and in DL1 of LAWSIG. Back issues can be found in DL4 of the IBMBBS SIG. LAWSIG will one day have all the back issues as well, when I or some other brave soul takes the time to upload them. Cooperation between forums, to the extent of copying the files from IBMBBS to LAWSIG, is apparently not possible. +++++++++++++++++++ LOSING YOUR ACCOUNT? Be sure to let us know if you do so we can unsub you from the mailing list. ++++++++++++++++++++ NEWSPAPER ARTICLES WANTED: Readers have been quite good about sending along news articles from major outlets, but *please* also send along stories from the local papers that you might come across, or let us know the issue it's in and we'll try to dig up a copy. ******************************************************************** >> END OF THIS FILE << *************************************************************************** ------------------------------ From: Various Subject: From the Mailbag Date: 9 June, 1991 ******************************************************************** *** CuD #3.20: File 2 of 7: From the Mailbag *** ******************************************************************** From: mpd@ANOMALY.SBS.COM(Michael P. Deignan) Subject: Re: Dutch Crackers as opposed to Graham Crackers Date: Fri, 07 Jun 1991 00:34:29 GMT >The techniques they've >used have been simple, well-known and uncreative, and they've found >the job an easy one, say sources. "These are not skilled computer >geniuses like Robert Morris," said Cliff Stoll, author of The Cuckoo's >Egg, who said he's been in contact with some Dutch crackers who may >have committed the break-ins. "These are more like the kind of hacker >I caught, sort of plodding, boring people." Stoll's 1989 book >concerned his pursuit of a cracker. Many times, this is the result of sloppy system administration. Recently, one site I FTP'd into had the contents of /etc/passwd readable by any FTP user. Makes you wonder about the rest of their system security... ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ From: Visualize Whirled Peas <brewer@ACE.ENET.DEC.COM> Subject: Article on Kevin Poulsen arrest Date: Wed, 5 Jun 91 20:18:29 PDT (The following is a bit old, but some may have missed it first time around): "Acting on a tip from an "associate" of the 25 year old computer hacker, Pacific Bell investigator Terry Atchley was staking out the market (grocery store). He'd warned employees on the night shift that Poulsen wanted by the FBI, might show up. When Poulsen, with bleached hair and dressed in black jeans, t-shirt and leather jacket walked in, packing clerk Dave Hernandez seized the slender 5-foor-8 suspect and bear-hugged dim until Atchley handcuffed him." Now when the hell did Pac Bell get granted arrest powers, including Deputizing 'packing clerks'....??? The rest of the article (Knight Ridder News Service) goes on to sensationalize the case. Also arrested was Mark K Lottor who evidently was him roomate... ******************************************************************** >> END OF THIS FILE << *************************************************************************** ------------------------------ From: "Chas. Dye -- Solarsys Mechanic" <chas@SOLUTION.COM> Subject: Bay Area Archive Site Date: Thu, 6 Jun 91 23:16:37 PDT ******************************************************************** *** CuD #3.20: File 3 of 7: Bay Area Archive Site *** ******************************************************************** Bay Area Document Archives Available for Anonymous UUCP Download ~~~ ~~~~ ~~~~~~~~ ~~~~~~~~ ~~~~~~~~~ ~~~ ~~~~~~~~~ ~~~~ ~~~~~~~~ The solarsys site (SYSOP: Chas. Dye) has CuD archives and other documents available for anonymous uucp download. All materials may be downloaded for the cost of your phone call to Oakland, California. To access this site from your unix box set up with uucp, follow these steps: 1. Put a line in your /usr/lib/uucp/Systems ( or L.Sys) file like this: solarsys Any ACU 9600 14153396540 ogin: archinfo sword: knockknock 2. From your OS prompt, type your uucp request: $ uucp solarsys~/ls-lR.Z /tmp/ls-lR.Z If you need more detailed information about how to configure uucp, try the Nutshell book "Managing uucp and Usenet" We are using a Telebit T2500 modem, which supports speeds up to 9600 baud, plus PEP (which is auto-detected if you dial in with a Telebit). If you're having trouble with the chat script, try adding a couple of breaks. You can also send mail to the Sysop: chas@solution.com or chas@solarsys.solution.com You can also login interactively using the username/password of guest/telebit This service is available every night between the hours of 11:00pm and 8:00am PDT The file ls-lR.Z is a listing of all files currently archived; the listing updated daily. All files are compressed using the unix compress utility; if you don't have it, you can download compress.tar ( $ uucp solarsys~/compress.tar /tmp/compress.tar ) ******************************************************************** >> END OF THIS FILE << *************************************************************************** ------------------------------ From: sjackson@TIC.COM(Steve Jackson) Subject: Top Ten Fallacies about SJG Raid Date: Sun, 12 May 91 13:17:16 cdt ******************************************************************** *** CuD #3.20: File 4 of 7: Top Ten Fallacies about SJG Raid *** ******************************************************************** THE TOP TEN MEDIA ERRORS ABOUT THE SJ GAMES RAID updated 5-12-91 As this story has developed, occasional errors creep into news stories - and many of them have taken on a life of their own. Some reporters, working from their clipping files, have turned out stories that are almost 100% free of facts. There are a lot of those floating around . . . but here are our Top Ten. 10. Steve Jackson Games is a computer game company. No we're not. None of our games are computer games. We use computers to WRITE the games, like every other publisher in the '90s. And the game that was seized, GURPS CYBERPUNK, was about computers. But we're not a computer game company any more than George Bush is a gardener. 9. GURPS Cyberpunk is a computer game. No it's not. Aieeeeee! It's a roleplaying game. It is not played on a computer. It's played on a table, with dice. 8. We're out of business. No we're not. It's been reported that we are bankrupt, or filing for bankruptcy. It was very close, and we're not out of the woods by any means - we did have to lay off half our staff . . . but we're not dead yet. 7. We were raided by the FBI. No we weren't. We were raided by the US Secret Service. The FBI had nothing to do with it. (In fact, when Bill Cook, the assistant US attorney named in our suit, was doing his "research," he talked to the FBI. They told him he didn't have a case. We have this from FBI sources!) 6. Some of our staff members were arrested by the Secret Service and charged with hacking. No they weren't. No member of our staff was arrested, indicted, or charged. Nobody was even QUESTIONED after the day of the raid. 5. This was part of Operation Sun Devil. No it wasn't. Sun Devil was a totally separate project, aimed at credit card fraud. Because it had a neat name, it got a lot of headlines. Since computers were involved, some reporters got the two confused. The Secret Service helped the confusion along by refusing to comment on what was, or wasn't part of Sun Devil. Sun Devil was not a "hacker" investigation. So says Gail Thackeray, who was its spearhead. 4. The raid was after GURPS Cyberpunk. No it wasn't. The Secret Service suspected one of our staffers of wrongdoing, using his computer at home. They had nothing connecting his alleged misdeeds with our office, but they raided us anyway, and took a lot of things. One of the things they took was the GURPS Cyberpunk manuscript. Their agents were very critical of it, and on March 2 in their office, one of them called it a "handbook for computer crime." Since their warrant was sealed, and they wouldn't comment, our best guess was that they were trying to suppress the book. They did suppress it, but apparently it was through bureaucratic inertia and stonewalling rather than because it was a target of the raid. 3. There was a hacker threat to sabotage the 911 system. No there wasn't. This story has been cynically spread by phone company employees (who know better) and by Secret Service spokesmen (who probably believe it, because they still don't understand any of this). They're using this story to panic the media, to try to justify the illegal things they've done and the huge amount of money they've spent. What happened was this: A student got access to a phone company computer and copied a text file - not a program. This file was nothing but administrative information, and was publicly available elsewhere. Bell South tried to value it at $79,000, but in court they admitted that they sold copies for under $20. There was no way this file could be used to hurt the 911 system, even if anybody had wanted to. To say otherwise shows an incredible ignorance of the facts. It's as though a banker claimed "This criminal made an illegal copy of the list of our Board of Directors. He can use that to break into our vault." 2. GURPS Cyberpunk was written by Lloyd Blankenship. He spells his name Loyd, with one L. And the Number One "false fact" ever reported about this story . . . 1. Steve Jackson Games is the second largest game company in the USA. Don't we wish! ******************************************************************** >> END OF THIS FILE << *************************************************************************** ------------------------------ From: an288@CLEVELAND.FREENET.EDU(Mark Hittinger) Subject: Hacking and Hackers: The Rise, Stagnation, and Renaissance Date: Wed, 3 Apr 91 00:00:29 -0500 ******************************************************************** *** CuD #3.20: File 5 of 7: Hacking and Hackers *** ******************************************************************** Hacking and Hackers: The Rise, Stagnation, and Renaissance. Copyright(C) 1991 By Mark Hittinger (an288@freenet.cleveland.edu, #60 on Blitzkrieg) This document may be freely reproduced so long as credit to the author is maintained. It doesn't take a rocket scientist to figure out that the publicity afforded to hacking has risen to peak levels within the last year. As one would expect, the political attention being paid to the subject of hackers has also risen to peak levels. We are hearing more about hackers each day. The newspapers have articles about alleged computer crime and phone fraud almost weekly. The legal system is issuing indictments, the secret service is running around with wildcard search warrants, and captured naive hackers are turning on each other. Some well known computer people have formed a lobby called the "Electronic Frontier Foundation". Fox TV has news people on the scene during a bust of an alleged "hacker" who was invading their own doofus system! Non-computer "lay" people have been asking me a lot of questions. So who am I? I'm just another computer bum. I got into computers in the early seventies during high school. I've witnessed computing's rise as something social outcasts did to something everybody wanted to be a part of. Babes looked at us with disgust as we grabbed our data on 110 baud teletypes and paper tape. Rolls of paper tape and access to timeshared basic was so great that we didn't even think that it could get better. Well guess what? Computers and our social position kept getting better. It got so good that pretty soon everybody wanted to ask us questions. These days we are like doctors at a cocktail party, we are always getting hit on for free computer consulting! Even from the babes! You've come a long way baby! Later I got into the professional side, that is, systems programming, systems management, and software development. I've worked with GE, Xerox, IBM, Digital, CDC, HP, Prime, anything I could get my hands on. I dearly loved the DEC-10, learned to live with VAX/VMS, and now grit my teeth when I work with Unix/MS-DOS. My hobby became my career, and they paid me money for it. My chosen hacking name is "bugs bunny" and you can find me on some bulletin boards as user "bugs". Bugs was always creating virtual rabbit holes out of thin air and dodging in and out of them. True hackers love to find and fix software "bugs". Yea!! I'm 34 now and a dad. Being involved in computers for a long time gives me a better perspective than most. Over the years there would sometimes be a major media coverage of some computer crime event. As a local computer "heavy", there were always questions coming my way about what these things were all about. Lately, the questions are more frequent and more sophisticated. All these big highly publicized busts are opening a lot of issues. I didn't have answers to some of these questions so I sat down and did some thinking. Writing this article is an outgrowth of that. I am not a writer so grant me some journalistic slack. Back in the early seventies hacking was quite free. Most of the important stuff was running on batch mainframes that had no connection to the outside world. The systems that we played with were not really considered critical by anyone. We were allowed to play to our hearts content, and nobody really worried about it at all. This period is what I like to think of as the "rise of hacking". You can read about some of it in the first section of Levy's book, "HACKERS". I love that section and read it when current events depress me. In those days the definition of hacker was clear and clean. It was fun, it was hi-tech, it was a blast, and it was not a threat. There were no big busts, very few people understood computing, and the public had no interest in it. We hacked for the sheer love of it. How can I describe the depth of interest that we had? We were not concerned with our image or our "identity". We wrote games, wrote neat hacks, and learned the strengths or weaknesses of each system. We were able to obtain access to a broad range of systems. Consider teenage boys comparing and contrasting the systems designed by older engineers! We eventually reached a point where we decided how a system should be set up. At this point we began to make an annoyance of ourselves. In all instances the various administrations considered us minor annoyances. They had much more pressing problems! New users began to show up in the labs. They reluctantly wanted to get something done that absolutely had to be done on the computer. In many cases they had no idea how to start, and were left to their own devices. Centralized data processing management (MIS) didn't want to deal with them. Often, they saw us playing around, joking, laughing, carefree, and not at all intimidated by the computer. They, on the other hand, were quite intimidated. We helped these people get started, showed them were the documentation was, and explained various error conditions to them. We quickly developed reputations as knowing how to get something to work. One of the people I helped made a remark to me that has stuck with me for a long time. He said, "I am trained as a civil engineer, so I don't have a feel for this. But you, you are pure bred. You've gotten into this fresh and taught yourself from the ground up. You haven't been trained into any set doctrine." Phar out man! This is an important point. There were no rules, guidelines, or doctrines. We made our own up as our experiences dictated. As time wore on, the new user pool began to grow more rapidly. The computers began to creak and groan under the work loads that were being placed upon them. During the day time, we came to the computer area to find it packed. We could no longer access the computers during the day. After all, we were just playing! That was OK with us. Soon we were there at night and on weekends. We obtained the off-hour non-prime time access, but this put us further away from the mainstream. These new guys liked the timeshared computers much more than their mainframe batch machines. They started to move their darn *important* crud from the mainframe machines to "our" timesharing computers. Pretty soon the administrations started to think about what it meant to have payroll or grades on the same computers that had "star-trek version 8", "adventure", or "DECWAR version 2.2". They were concerned about security on the timesharing systems, but due to their budget constraints, most of the centralized MIS shops still had to give priority to their batch mainframes. We continued to play, but we cursed at the slow systems when the important stuff was running. I got off "tuning" systems to make them run faster or more efficiently. Interactive response time became the holy grail. The "rise of hacking" was beginning to run out of steam. The timesharing systems had been expanded as much as technology and budgets would allow. We had learned the various systems internals inside and out. We now knew much more about the systems than the "official" maintainers did, and these maintainers perceived us as a threat to their positions. The computers were still overloaded. The nasty politics of access and resources began to rear their head. A convenient scapegoat was to eliminate access to games. Eliminate the people that were just playing. Examine all computing activity and bill for it. This didn't solve any of the problems (we all knew payroll and grades wouldn't fit in!) but it did raise the issue of the hackers to the surface. All of a sudden we became defined as a problem! We were soon getting shut out of various systems. New kids began to show up and pretend to be hackers. They would do anything to show off, and created large problems for "us". At this point the "stagnation" period was beginning. These were hard days for us. Many of my friends quit what they were doing. Many of us got real jobs on the computers we played with as a dodge. Centralized MIS departments began to be placed between the rock and hard place of limited budgets and unlimited customers. The new kids, the overloaded systems, the security concerns for the important applications, and the political situation all resulted in the stagnation of hacking. "Hacker" took on a bad connotation. I saw all kind of debates over what "hacker" meant. Some claimed it was a compliment, and should only be awarded to those bit twiddlers that were truly awesome. Many claimed that hackers were the scum of the earth and should be totally decimated! What could you do but stay out of the way and let things take their course? I realize now that it was in the MIS departments' *VESTED INTEREST* to define the term "hacker". Centralized MIS did not have the courage to fight for larger budgets. Upper level administrators who just approved the budget would freak out when they saw kids playing games on the computers in the library. MIS had to define this as bad, had to say they would put a stop to it. MIS had to look like they were managing the computer resources responsibly. Any unusual or politically unacceptable computer event that couldn't be covered up was caused by "hackers". It was a dodge for MIS! I am not saying that some questionable stuff didn't go down, I am just saying that it was logical to call anything "bad" by some sort of easily accepted label - "hackers". Of course, when the unusual computing event took place your budding journalists were johnny on the spot. You don't climb that journalist ladder by writing about boring stories. Wild computer stories about hacking captured the public interest. I suppose the public liked to hear that somebody could "beat" the system somehow. Journalists picked up on this and wrote stories that even I found hard to believe. The new kids, even when not asked, would blab all day long about the great things that they were doing. And don't you know, they would blab all day long about great hacks they heard that you pulled! Stories get wilder with each re-telling. I realize now that it was in the journalists' *VESTED INTEREST* to define the term "hacker". The public loves robin hood, the journalists went out and found lots of pseudo-robin hoods. More and more stories began to hit the public. We heard stories of military computers getting penetrated. We heard stories of big financial rip-offs. We heard cute stories about guys who paid themselves the round-off of millions of computer generated checks. We heard stories of kids moving space satellites! We heard stories of old ladies getting their phone bills in a heavy parcel box! As an old timer, I found a lot of these stories far fetched. It was all national inquirer type stuff to me. The public loved it, the bureaucrats used it, and the politicians began to see an opportunity! The end of the "stagnation" period coincides the arrival of the politicians. Was it in the *VESTED INTEREST* of the politicians to define the term "hacker"? You bet! Here was a safe and easy issue! Who would stand up and say they were FOR hackers? What is more politically esthetic than to be able to define a bad guy and then say you are opposed to it? More resources began to flow into law enforcement activities. When actual busts were made, the legal system had problems coming up with charges. The legal system has never really felt comfortable with the punishment side of hacking, however, they LOVE the chase. We didn't have guns, we were not very dangerous, but it is *neat* to tap lines and grab headlines! What a dangerous time this was. It was like a feedback loop, getting worse every week. When centralized MIS was unable to cover up a hacking event, they exaggerated it instead. Shoddy design or poor software workmanship was never an issue. Normally "skeptical" journalists did not ask for proof, and thrilled at the claims of multi-million dollar damages. Agents loved to be seen on TV (vote for me when I run!) wheeling out junior's Christmas present from last year, to be used as "evidence". The politicians were able to pass new laws without constitutional considerations. New kids, when caught, would rabidly turn on each other in their desperation to escape. Worried older hackers learned to shut up and not give their side for fear of the feeding frenzy. Hackers were socked with an identity crisis and an image problem. Hackers debated the meaning of hacker versus the meaning of cracker. We all considered the fundamental question, "What is a true hacker?". Cool administrators tried to walk the fine line of satisfying upper level security concerns without squelching creativity and curiosity. So what is this "renaissance" business? Am I expecting to see major hacker attacks on important systems? No way, and by the way, if you thought that, you would be using a definition created by someone with a vested interest in it. When did we start to realize that hacker was defined by somebody else and not us? I don't know, but it has only been lately. Was it when people started to ask us about these multi-million dollar damage claims? I really think this is an important point in time. We saw BellSouth claim an electronically published duplicate of an electronic document was worth nearly $100,000 dollars! We later saw reports that you could have called a 1-800 number and purchased the same document for under twenty bucks. Regular non-computer people began to express suspicion about the corporate claims. They expressed suspicion about the government's position. And generally, began to question the information the media gave them. Just last month an article appear in the Wall Street Journal about some hackers breaking in to electronic voice mail boxes (fancy answering machines). They quoted some secret service agent as saying the damages could run to the tens of millions of dollars. Somebody asked me how in the world could screwing around with peoples answering machines cause over 10 million dollars in damages? I responded, "I don't know dude! Do you believe what you read?" And when did the secret service get into this business? People say to me, "I thought the secret service was supposed to protect the president. How come the secret service is busting kids when the FBI should be doing the busting?" What can I do but shrug? Maybe all the Abu-Nidals are gone and the president is safe. Maybe the FBI is all tied up with some new AB-SCAM or the S&L thing. Maybe the FBI is damn tired of hackers and hacking! In any event, the secret service showed it's heavy hand with the big series of busts that was widely publicized recently. They even came up with *NEAT* code names for it. "Operation SUNDEVIL", WOW! I shoulda joined the secret service!!! Were they serious or was this their own version of dungeons and dragons? In a very significant way, they blew it. A lot of those old nasty constitutional issues surfaced. They really should define clearly what they are looking for when they get a search warrant. They shouldn't just show up, clean the place out, haul it back to some warehouse, and let it sit for months while they figure out if they got anything. This event freaked a lot of lay people out. The creation of the Electronic Frontier Foundation is a direct result of the blatantly illegal search and seizure by the secret service. People are worried about what appears to be a police state mentality, and generally feel that the state has gone to far. I think the average American has a gut level feel for how far the state should go, and the SS clearly went past that point. To be fair, there aren't any good guidelines to go by in a technical electronic world, so the secret service dudes had to decide what to do on their own. It just turned out to be a significant mistake. I saw Clifford Stoll, the author of the popular book "Cuckoos Egg" testify on national C-SPAN TV before congress. His book is a very good read, and entertaining as well. A lot of lay people have read the book, and perceive the chaos within the legal system. Stoll's book reveals that many systems are not properly designed or maintained. He reveals that many well known "holes" in computer security go unfixed due to the negligence of the owners. This book generated two pervasive questions. One, why were there so many different law enforcement agencies that could claim jurisdiction? Lay people found it amazing that there were so many and that they could not coordinate their efforts. Two, why were organizations that publicly claimed to be worried about hackers not updating their computer security to fix stale old well known problems? If indeed a hacker were able to cause damage by exploiting such a well known unfixed "hole", could the owner of the computer be somehow held responsible for part of the damage? Should they? We all watched in amazement as the media reported the progress of Robert Morris's "internet worm". Does that sound neat or what? Imagine all these lay people hearing about this and trying to judge if it is a problem. The media did not do a very good job of covering this, and the computing profession stayed away from it publicly. A couple of guys wrote academic style papers on the worm, which says something about how important it really was. This is the first time that I can remember anyone examining a hacking event in such fine detail. We started to hear about military interest in "worms" and "viruses" that could be stuck into enemy computers. WOW! The media accepted the damage estimates that were obviously inflated. Morris's sentence got a lot of publicity, but his fine was very low compared to the damage estimates. People began to see the official damage estimates as not being very credible. We are in the first stages of the hacking renaissance. This period will allow the hackers to assess themselves and to re-define the term "hacker". We know what it means, and it fits in with the cycle of apprentice, journeyman, and master. Its also got a little artist, intuition, and humor mixed in. Hackers have the chance to repudiate the MISs', the journalists', and the politicians' definition! Average people are questioning the government's role in this and fundamental rights. Just exactly how far should the government go to protect companies and their data? Exactly what are the responsibilities of a company with sensitive, valuable data on their computer systems? There is a distinct feeling that private sector companies should be doing more to protect themselves. Hackers can give an important viewpoint on these issues, and all of a sudden there are people willing to listen. What are the implications of the renaissance? There is a new public awareness of the weakness in past and existing systems. People are concerned about the privacy of their electronic mail or records on the popular services. People are worried a little about hackers reading their mail, but more profoundly worried about the services or the government reading their stuff. I expect to see a very distinct public interest in encrypted e-mail and electronic privacy. One of my personal projects is an easy to use e-mail encrypter that is compatible with all the major e-mail networks. I hope to have it ready when the wave hits! Personal computers are so darn powerful now. The centralized MIS department is essentially dead. Companies are moving away from the big data center and just letting the various departments role their own with PCs. It is the wild west again! The new users are on their own again! The guys who started the stagnation are going out of business! The only thing they can cling to is the centralized data base of information that a bunch of PCs might need to access. This data will often be too expensive or out-of-date to justify, so even that will die off. Scratch one of the vested definers! Without centralized multi-million dollar computing there can't be any credible claims for massive multi-million dollar damages. Everyone will have their own machine that they can walk around with. It is a vision that has been around for awhile, but only recently have the prices, technology, and power brought decent implementations available. Users can plug it into the e-mail network, and unplug it. What is more safe than something you can pick up and lock up? It is yours, and it is in your care. You are responsible for it. Without the massive damage claims, and with clear responsibility, there will no longer be any interest from the journalists. Everybody has a computer, everybody knows how much the true costs of damage are. It will be very difficult for the journalists to sensationalize about hackers. Scratch the second tier of the vested definers! Without media coverage, the hackers and their exploits will fade away from the headlines. Without public interest, the politicians will have to move on to greener pastures. In fact, instead of public fear of hackers, we now are seeing a public fear of police state mentality and abuse of power. No politician is going to want to get involved with that! I expect to see the politicians fade away from the "hacker" scene rapidly. Scratch the third tier of the vested definers! The FBI and the secret service will be pressured to spend time on some other "hot" political issue. So where the heck are we? We are now entering the era of truly affordable REAL systems. What does REAL mean? Ask a hacker dude! These boxes are popping up all over the place. People are buying them, buying software, and trying to get their work done. More often than not, they run into problems, and eventually find out that they can ask some computer heavy about them. Its sort of come full circle, these guys are like the new users of the old timesharing systems. They had an idea of what they wanted to do, but didn't know how to get there. There wasn't a very clear source of guidance, and sometimes they had to ask for help. So it went! The hackers are needed again. We can solve problems, get it done, make it fun. The general public has the vested interest in this! The public has a vested interest in electronic privacy, in secure personal systems, and in secure e-mail. As everyone learns more, the glamour and glitz of the mysterious hackers will fade. Lay people are getting a clearer idea of whats going on. They are less willing to pay for inferior products, and aren't keen about relying on centralized organizations for support. Many know that the four digit passcode some company gave them doesn't cut the mustard. What should we hackers do during this renaissance? First we have to discard and destroy the definition of "hacker" that was foisted upon us. We need to come to grips with the fact that there were individuals and groups with a self interest in creating a hysteria and/or a bogeyman. The witch hunts are over and poorly designed systems are going to become extinct. We have cheap personal portable compatible powerful systems, but they do lack some security, and definitely need to be more fun. We have fast and cheap e-mail, and this needs to be made more secure. We have the concept of electronic free speech, and electronic free press. I think about what I was able to do with the limited systems of yesterday, and feel very positive about what we can accomplish with the powerful personal systems of today. On the software side we do need to get our operating system house in order. The Unix version wars need to be stopped. Bill Gates must give us a DOS that will make an old operating system guy like me smile, and soon! We need to stop creating and destroying languages every three years and we need to avoid software fads (I won't mention names due to personal safety concerns). Ken Olsen must overcome and give us the cheap, fast, and elegantly unconstrained hardware platform we've waited for all our lives. What we have now is workable (terrific in terms of history), but it is a moral imperative to get it right. What we have now just doesn't have the "spark" (I am not doing a pun on sun either!!!). The hackers will know what I mean. If we are able to deal with the challenges of the hacking renaissance, then history will be able to record the hackers as pioneers and not as vandals. This is the way I feel about it, and frankly, I've been feeling pretty good lately. The stagnation has been a rough time for a lot of us. The stock market guys always talk about having a contrarian view of the market. When some company gets in the news as a really hot stock, it is usually time to sell it. When you hear about how terrible some investment is, by some perverse and wonderful force it is time to buy it. So it may be for the "hackers". We are hearing how terrible "hackers" are and the millions of dollars of vandalism that is being perpetrated. At this historic low are we in for a reversal in trend? Will the stock in "hackers" rise during this hacking renaissance? I think so, and I'm bullish on the 90's also! Party on d00des! ******************************************************************** >> END OF THIS FILE << *************************************************************************** ------------------------------ From: ckd@EFF.ORG(Christopher Davis) Date: Fri, 7 Jun 91 17:42:51 -0400 Subject: EFFector Online 1.07: S.266 Loses First Round ******************************************************************** *** CuD #3.20: File 6 of 7: S.266 Loses First Round *** ******************************************************************** EFFector Online|EFFector Online|EFFector Online|EFFector Online Volume 1 Issue:1.07 Friday June 14, 1991 SENATE ANTI-ENCRYPTION BILL WITHDRAWN WILL BE REPLACED BY A NEW OMNIBUS CRIME BILL -- S.1241 SENSE OF CONGRESS LANGUAGE RESTRICTING ENCRYPTION REMOVED When Senate Bill 266 was proposed, some of its provisions would have restricted the rights of individuals to secure online communications through the use of encryption programs. The specific language was: "It is the sense of Congress that providers of electronic communications services and manufacturers of electronic communications service equipment shall ensure that communications systems permit the government to obtain the plain text contents of voice, data, and other communications when appropriately authorized by law." Let stand, this language would have a chilling effect on encryption. It would inevitably compromise individual privacy in telecommunications. The Electronic Frontier Foundation and several other groups determined to oppose this provision. In the last issue of EFFector Online, we reported we would register our opposition to this clause. In this case, Senator Patrick Leahy (D. Vermont), who chairs the sub-committee on Technology and the Law --a sub-set of the Senate Judiciary Committee-- was the key to this issue. This week the EFF met with Leahy's staff to present our reasons for the removal of the language dealing with encryption. Today, we were informed that the encryption clause has been eliminated from the new crime bill which replaced the bill originally known as S.266. In addition, Leahy's sub-committee on Technology and the Law has undertaken to study the issues of encryption and telecommunications technology. To continue this dialogue, Computer Professionals for Social Responsibility, the Electronic Frontier Foundation, and RSA will be holding an invitational workshop on privacy and encryption in Washington later this month. Following the workshop, a press conference will be held to announce a set of policy recommendations on cryptography. The conference will take place on Monday at 2:00 at the National Press Club (14th & Pennsylvania Avenue N.W.). All interested parties are invited to attend. Please direct all mail regarding EFFector Online to: editors@eff.org ******************************************************************** >> END OF THIS FILE << *************************************************************************** ------------------------------ From: Eric_R_Smith@CUP.PORTAL.COM Subject: How to get WATCH.EXE Date: Sun, 9 Jun 91 11:55:17 PDT ******************************************************************** *** CuD #3.20: File 7 of 7: How to get WATCH.EXE *** ******************************************************************** Because of a misunderstanding, readers were invited to receive a UUencoded version of Eric Smith's Watch program directly from his mailbox at PORTAL. Readers may receive a UUencoded version of the program and brief documentation from the CuD ftp site. It is assumed that users who can manage the ftp will also have a uudecoding program. Therefore, the program is provided in uue format only, not in the BASIC format offered in the article. [The BASIC code required to create the Watch archive was over 70k long. The uue file is about 12k!] Eric Smith also notes: Some users of FluShotPlus and PRODIGY have questioned if PRODIGY was disabling FSP's actions. They base this fearon the fact that under PRODIGY, FSP's "+" indicator is missing from the upper right corner of the screen. "+" indicates that FSP is loaded and is active. A "-" indicates that FSP is loaded but has been deactivated. HOWEVER, these users are forgetting that PRODIGY operates in a graphics screen mode, while FSP is a text-mode program. Thus, FSP IS writing the "+" or "-" in the corner of the screen, but the character is either not visible of has been reduced to a few lit pixels, rather than a full character. Users of FSP can confirm that it is still loaded and active by removing one of the PRODIGY files from the FLUSHOT.DAT file. When PRODIGY accesses that file, users will see a smudge of pixels light in the middle of their screens and will hear FSP's alarm go off. While it is technically possible for PRODIGY to "jam" a tsr's operation, there is absolutely no evidence that PRODIGY is doing this. As I note in the docs to Watch, the program is useful for watching any program's behavior. It is in no way restricted to calls performed by PRODIGY: the behavior it monitors is used by all DOS applications. For most purposes, you will not want a record of the DOS calls. Therefore, the "write calls to the screen" version is the more appropriate. Writing to the screen certainly is faster than "log to a disk file" method: open the log file, write the information to that file, and then close the file. The latter method is only appropriate or necessary when you wish to preserve a record of a program's behavior or when you are unable to view the screen (as when the screen is in graphics mode). It normally takes a few days to get a program up to the ftp sites, so wait a few days before trying, or contact the moderators. ******************************************************************** ------------------------------ **END OF CuD #3.20** ********************************************************************