[HN Gopher] The KGB, the Computer and Me - The Cuckoo's Egg Stor...
       ___________________________________________________________________
        
       The KGB, the Computer and Me - The Cuckoo's Egg Story (1990)
       [video]
        
       Author : Prcmaker
       Score  : 130 points
       Date   : 2024-01-26 11:12 UTC (1 days ago)
        
 (HTM) web link (www.youtube.com)
 (TXT) w3m dump (www.youtube.com)
        
       | th0ma5 wrote:
       | Mr. Stoll I believe eventually spent some time listening to the
       | community, but for a while he had some contradictory views along
       | the lines of the white, black, grey hat or perhaps what we would
       | now call red team. For comparison here is a video from 1989 with
       | a lot of risk management type language from the US government
       | that seems boring and perfectly normal today
       | https://www.c-span.org/video/?7596-1/computer-viruses
        
         | bemusedthrow75 wrote:
         | Mr Stoll internationally traced a KGB-affiliated hacker when
         | almost nobody had heard of the internet[0], more or less
         | invented the long-game honeypot to catch him, and testified at
         | his trial.
         | 
         | One hopes "the community" listened at least as much to him,
         | considering the internet security community apparently was
         | hardly worth a damn before all this happened.
         | 
         | [0] and was, coincidentally, basically the first person to use
         | the term "The Internet" (proper noun, emphasis on The) in
         | widely read non-fiction, outside of a training manual and
         | research document or two.
        
           | th0ma5 wrote:
           | He spent a long time on Slashdot and other places speaking
           | out against hackers of all types and it wasn't until maybe
           | 1999 or 2000 until he seemed to concede that some aspects of
           | hacking, such as the bug bounties of today, were valuable.
           | Dissent around Mr. Stoll at the time is evident in Phrack and
           | other material from the time. I have the highest respect for
           | the gentleman of course, I'm just trying to raise awareness
           | that he was very much against messing with systems at all,
           | even for exploration or testing, and spent a lot of time in
           | the early to late 90s telling non-computer people to be
           | suspicious of anyone who seems to know too much about
           | computers. It was very offensive to me at the time, but I do
           | know that he did eventually see the light.
           | 
           | From Phrack #32
           | 
           | ``The Cuckoo's Egg'' captures many of the popular stereotypes
           | of hackers. Criminologist Jim Thomas criticizes it for
           | presenting a simplified view of the world, one where
           | everything springs from the forces of light (us) or of
           | darkness (hackers) (Thomas90). He claims that Stoll fails to
           | see the similarities between his own activities (e.g.,
           | monitoring communications, ``borrowing'' monitors without
           | authorization, shutting off network access without warning,
           | and lying to get information he wants) and those of hackers.
           | He points out Stoll's use of pejorative words such as
           | ``varmint'' to describe hackers, and Stoll's quote of a
           | colleague: ``They're technically skilled but ethically
           | bankrupt programmers without any respect for others' work --
           | or privacy. They're not destroying one or two programs.
           | They're trying to wreck the cooperation that builds our
           | networks,'' (Stoll90, p. 159). Thomas writes ``at an
           | intellectual level, it (Stoll's book) provides a persuasive,
           | but simplistic, moral imagery of the nature of right and
           | wrong, and provides what -- to a lay reader -- would seem a
           | compelling justification for more statutes and severe
           | penalties against the computer underground. This is
           | troublesome for two reasons. First, it leads to a mentality
           | of social control by law enforcement during a social phase
           | when some would argue we are already over-controlled. Second,
           | it invokes a punishment model that assumes we can stamp out
           | behaviors to which we object if only we apprehend and convict
           | a sufficient number of violators. ... There is little
           | evidence that punishment will in the long run reduce any
           | given offense, and the research of Gordon Meyer and I
           | suggests that criminalization may, in fact, contribute to the
           | growth of the computer underground.''
           | 
           | http://phrack.org/issues/32/3.html
        
             | bemusedthrow75 wrote:
             | > Dissent around Mr. Stoll at the time is evident in Phrack
             | 
             | You don't say!
        
               | th0ma5 wrote:
               | I mean, you got a guy going on Geraldo and such fear
               | mongering and accusing the government of doing nothing
               | while the most senior level of the US government as
               | public as possible describes modern sounding risk
               | management ideals... And people forget that security
               | through obscurity was a deeply prized thing, and all of
               | this was before firewalls.
               | 
               | If you were to tell Mr. Stoll and his audience that that
               | in the future one of the most popular information places
               | would be called Hacker News they would get the opinion
               | very quickly that the good guys apparently lost in the
               | future. I guess I can't really describe it, but this
               | mindset would've been very bad had it survived, but
               | thankfully it hasn't, and couldn't.
               | 
               | This would've been impossible probably, but ideally Mr.
               | Stoll should've worked to explain in detail the
               | vulnerabilities and mitigations and tried to explain
               | those things as making crime inevitable. That's what we
               | do today, but for a long time people thought that was
               | just giving bad people ammunition instead of how we see
               | it today as part of a whole arsenal of perspectives and
               | strategies.
               | 
               | In the late 90s during several Q&As Mr. Stoll came around
               | to agree with many of our modern concepts of security,
               | once he understood more of the game mechanics and some
               | other understandable confusion stuff... He wasn't as
               | online perhaps as many people are today, and to my
               | understanding never formally worked in security nor
               | wanted to.
        
       | Thri4895o wrote:
       | This guy wrote book in 1989. There is a section, where he asks
       | some NSA guy about project Echolon, and if they recorded some
       | phone call he needs for investigation. 25 years before Snowden!
       | Always cracks me up :)
        
         | neilv wrote:
         | I found the Snowden thing funny-odd...
         | 
         | Echelon was something a lot of online techies had heard of by
         | 1989. (I was just a teen, and I'd heard of it.) There was at
         | least one book about it.
         | 
         | It was so well-known, and joked about, for so long, that one
         | time I made a nerdy joke referencing Echelon to an ex-NSA
         | person. When they responded simply, "What's Echelon?", I
         | realized I'd put my foot in my mouth, by rudely putting them in
         | an awkward position. I guess that they still weren't allowed to
         | talk about even long-public information about it.
         | 
         | Before the Snowden disclosures there were all these
         | capabilities and methods that you would've come up with, if
         | you'd taken a smart techie and asked them, "If it was your job
         | to build out surveillance capability, with NSA scale of
         | resources, what kinds of things would be possible with what you
         | know of computer-ish technology today?"
         | 
         | After all the decades of jokes and speculation, it was still
         | funny-odd to see that, yes, it's for real.
         | 
         | Not entirely like Galaxy Quest, but at least the dorky parts:
         | https://www.youtube.com/watch?v=nF_6OfgbF7c
        
           | A4ET8a8uTh0 wrote:
           | I think the issue is that while even techies, who were not
           | part of IC instinctively knew that the story as presented to
           | the general population simply did not add up and explanations
           | like 'we are only grabbing x out of y' are unlikely, the
           | general population either did not understand or did not want
           | to understand what it meant.
           | 
           | It took the more salacious variants of those stories like nsa
           | people spying on exes[1] to get public mildly interested.
           | 
           | The sad thing is you are not wrong; as little as I knew back
           | then in an irc channel. I remember after a particularly
           | questionable comment I made a follow up with comment
           | basically telling nsa its a joke. Then again, today people
           | seem to add 'fbi agent' trope.
           | 
           | [1]https://www.reuters.com/article/idUSBRE98Q14H/
        
           | cpach wrote:
           | Yeah we knew (or strongly suspected) that long before
           | Snowden, NSA had massive capabilities.
           | 
           | I think one reason that this knowledge faded into the
           | background is that in the 80s/90s it was mostly tech geeks
           | who where concerned. Many people didn't use computers or
           | Internet at all back then. So to them it all probably felt
           | very abstract. And then people forgot about it. Until Snowden
           | revealed what he had found.
        
           | michaelcampbell wrote:
           | Same here; I'm probably MIS-remembering, but I "remember"
           | well before the Snowden leaks reading about the mysterious
           | room at AT&T that was suspected to be where "someone" kept
           | all the equipment for tapping.
           | 
           | IIRC (and I likely don't), what I read was some employee that
           | saw people coming in and out with equipment, some of which he
           | recognized as storage and other data-reading stuff, and a lot
           | he didn't, and he was made VERY aware that he was not to talk
           | about this, or even be in the area any longer or ever again,
           | for any reason.
           | 
           | My recollection was that I did this reading in the mid 90's.
           | But the wikipedia article for that room dates later, so this
           | is the cause of my apprehension of placing the exact time.
        
             | er4hn wrote:
             | Are you thinking of Room 641A?
             | https://en.wikipedia.org/wiki/Room_641A
        
             | ertian wrote:
             | There were a few days back in the 90s where all the tech
             | sites would run a campaign where everybody was supposed to
             | send emails full of red flag words: "bomb" and
             | "assassinate" and "terrorism" and what have you. It was
             | specifically to mess with NSA surveillance operations.
        
               | neilv wrote:
               | Forever, there was a file included in stock Emacs,
               | `spook.el`, which could be hooked up to automatically add
               | random strings of "interesting" keywords to each of your
               | email or Usenet messages (in signatures, or in headers
               | like `X-Spook`).
               | 
               | https://www.gnu.org/software/emacs/manual/html_node/emacs
               | /Ma...
               | 
               | Looks like copyright date of 1988:
               | 
               | https://github.com/emacs-
               | mirror/emacs/blob/master/lisp/play/...
               | 
               | https://github.com/emacs-
               | mirror/emacs/blob/master/etc/spook....
               | 
               | Try `M-x spook RET` in an Emacs buffer.
        
           | aksss wrote:
           | It could be dismissed as a crazy conspiracy theory pretty
           | easily until Snowden, imo.
        
       | buildbot wrote:
       | Everyone should read the book! (The Cuckoo's Egg) - it's really
       | awesome.
        
         | ackbar03 wrote:
         | There's quite a few interesting cameo's, including Robert
         | Morris (Morris Worm) and Paul Graham himself.
        
           | cpach wrote:
           | pg too? I had totally forgotten about that.
        
         | EvanAnderson wrote:
         | Cliff is on HN, too.
         | https://news.ycombinator.com/user?id=CliffStoll
         | 
         | The Cuckoo's Egg was formative in my youth. Great book.
        
         | forinti wrote:
         | I read the book a long long time ago (highly recommend it) and
         | only now, watching the video, recognized Stoll as the Klein
         | Bottle guy.
        
         | atribecalledqst wrote:
         | I read the Cuckoo's Egg when I was in like 6th grade, and even
         | though I didn't REALLY understand what was going on at the
         | time, I've always wondered if it subconsciously influenced me
         | towards becoming more computer-savvy, to my present day form as
         | a command line junkie ;)
         | 
         | IIRC I randomly picked it out from the local Borders too
         | (realize I'm dating myself with that one) so that's some real
         | "Dalai Lama reincarnation" stuff going on there. Like it was
         | fated...
        
         | fullspectrumdev wrote:
         | One security company I worked at had it as required reading for
         | new hires - you were given a copy as part of onboarding.
         | 
         | I honestly think that was an excellent idea - there's a good
         | amount of valuable lessons for an analyst to glean from reading
         | it.
         | 
         | I can think of very few other books in the IT security field
         | that are as well written and as compelling besides maybe
         | Silence on the Wire, The Tangled Web, or Innocent Code.
        
       | lukeh wrote:
       | I remember reading an excerpt of this book in Australian Personal
       | Computer magazine when I was a kid, and then the book some years
       | later. Was a great story.
        
       | drewcoo wrote:
       | Bought a klein bottle from Cliff Stoll a few years ago.
       | 
       | https://www.kleinbottle.com
       | 
       | He enclosed a really nice brief note. Amazingly nice guy!
        
         | Y_Y wrote:
         | I've gotten a couple of things from his shop. I was genuinely
         | shocked at how friendly and helpful he was. It was probably the
         | best "customer service" interaction I've ever had.
        
       | ulysse_mn wrote:
       | I love Cliff, This Story about His Elementary School's Teacher
       | teaching him about Matrices cracks me up every time (From a
       | Numberphile podcast)
       | 
       | https://www.tiktok.com/t/ZT8tfa5wN/
        
         | kekebo wrote:
         | That was wholesome, thanks for linking
        
         | erk__ wrote:
         | The full podcast can be found here and is well worth a listen:
         | https://www.numberphile.com/podcast/cliff-stoll
        
           | fsckboy wrote:
           | this numberphile/Cliff Stoll video is on a different topic,
           | klein bottles... or maybe more the travelling
           | salesman/knapsack problem, but it's a must see. Cliff is a
           | cool guy (whose geewhiz excitement I can only take in small
           | doses but) he's worth following
           | 
           | https://www.youtube.com/watch?v=-k3mVnRlQLU
        
       | strawberryfie wrote:
       | It's a great story, and a fun book to read. However, while I can
       | see the thrill of the chase, I can't help but think Stoll's
       | superiors had the correct, pragmatic response more suited to the
       | future of the internet - "close the loophole and move on".
        
       | ndsipa_pomu wrote:
       | I've given up trying to find the old "Science Fiction" series
       | shown on ITV in the UK: https://www.imdb.com/title/tt1380838
       | 
       | The first episode is "Spycatcher" and based on The Cuckoo's Egg,
       | so I wonder how similar it is to the other productions.
       | Unfortunately, I can't find it in the usual places and "Yorkshire
       | Television" who owns the footage doesn't exist anymore.
        
       | doener wrote:
       | There is also a 1998 German movie told from the other side of the
       | story:
       | 
       | https://en.wikipedia.org/wiki/23_(film)
       | 
       | https://www.youtube.com/watch?v=JUDWU4RBtds
        
       | WelcomeShorty wrote:
       | This really made my day, what a fantastic blast from the past.
        
       | Simulacra wrote:
       | Cliff Stoll is a hero of mine. I grew up reading his books, and
       | the Cuckoo's Egg is very close to my heart. Really opened my eyes
       | to the Internet and the birth of modern technology. I remember
       | when I was a kid I looked his phone number up, and he just happen
       | to be listed in the book, so I called him up. He could not have
       | been more kind.
        
       | hnthrowaway0328 wrote:
       | What happened to Markus afterwards? The sentence seems to be
       | pretty light so I guess maybe the USSR had a hand in it. With his
       | skills he could definitely do a lot in the computer industry.
        
         | p_l wrote:
         | Pengo had been quite successful, from what I've seen.
         | 
         | Definitely felt more successful than me even before I heard
         | (through alternate means) who I talked with XD.
         | 
         | Never seen anything about what happened to Markus afterwards
         | and seemed gauche to ask.
        
         | s3krit wrote:
         | After doing some internet sleuthing, I'm about 95% sure I know
         | what he's doing today, and if it who I suspect, he has had a
         | decent career in IT. Would rather not post my findings to
         | respect the man's privacy.
        
       | dobin wrote:
       | I am currently reading "CYBERPUNK: Outlaws and Hackers on the
       | Computer Frontier" and can recommend it if interested in
       | pre/early computer hacking (Phreaking, BBS, VAX/Digital). First
       | third is about Mitnick and friends, second about Pengu and CCC
       | friends.
        
       | bdcravens wrote:
       | The Cuckoo's Egg was a fantastic read to me back in the mid-90s
       | as my worldview was shaping up. (among other, like Soul of a New
       | Machine, Hackers by Steven Levy, Masters of Deception, etc)
        
       | Beta-7 wrote:
       | I've recently read The Cuckoo's Egg and as a person that has been
       | born into technology it's really interesting how Cliff goes to
       | explain concepts that these days are understood as common
       | knowledge.
        
       | kjqgqkejbfefn wrote:
       | Here's what happened to me:
       | 
       | - Reached out to a Russian troll on twitter via DM to discuss
       | some specific topic he had mentioned. I try to engage the
       | conversation on this topic which requires "blowing up his cover".
       | 
       | - The shill gets angry and asks me to imagine what he would do to
       | me.
       | 
       | - My reply convince him I'm a US intelligence officer. After some
       | nervous back and forth between blocking and unblocking me,
       | someone else seems to be on the other side of the line and asks
       | me to talk to my manager/officer, using some spy scheme from a
       | movie. I back the fuck out.
       | 
       | - About a week later, I realize there is an "iCloud" segment in
       | my finder left vertical bar. All the sync settings are ticked,
       | including stuff I do not use. I go check the sync folders' last
       | modified time: a mere two hours after I had this conversation on
       | Twitter.
       | 
       | - Go back on twitter to see what the shill is up to. He's
       | complaining about suffering a breach of his iCloud account and
       | blames some intelligence service in Frankfurt, providing a
       | picture of the building.
       | 
       | I have no idea what I have stepped into. Was it some counter-
       | intel honey pot ? Then it was pretty well made. Or are these
       | people genuinely working for some russian service ? If so, then
       | they are batshit crazy, arrogant and not as professional as one
       | may expect.
       | 
       | As a result I nuked my github and stopped using my phone, my
       | watch, youtube account, etc. I was promised open brain
       | surgery/interrogation by people that are allegedly expert doxxers
       | and torturers and thought I was an intelligence soldier fighting
       | against them.
        
         | labrador wrote:
         | I had a similar experience many years ago and learned my lesson
         | and stopped engaging this way with people I didn't know. Later
         | I learned just how easy it is to dox people using stylometry
         | (see: how Ted Kaczynski was caught) or by finding a careless
         | mistake (see: how Dread Pirate Roberts was caught). I was glad
         | then that I learned to be cautious.
        
           | kjqgqkejbfefn wrote:
           | This is exactly how I "blew up" his cover. The fact he used
           | low quotation marks "disproved" the claim he was from western
           | europe (mostly). I have no certitude though. This could well
           | be intentional if this was a counter-intel honey pot, in
           | which case I kneel. Would you mind sharing your anecdote,
           | keeping things blurry as I did ?
        
             | labrador wrote:
             | I shared some info then deleted it. Best not poke that
             | sleeping dog.
        
       ___________________________________________________________________
       (page generated 2024-01-27 23:01 UTC)