That was one scary exciting day (source: was running machines at MIT at the time)
Not much was happening in the Eng and CS buildings on campus (except for those that had to deal with the worm).
11–20 of 200 posts
That was one scary exciting day (source: was running machines at MIT at the time)
Not much was happening in the Eng and CS buildings on campus (except for those that had to deal with the worm).
It's a little shocking to me that there haven't been more things like this. While we're much more conscientious and better at security than we were way back then, things are certainly not totally secure. The best answer I have is the same as what a bio professor told me once about designer plagues: it hasn't happened because nobody's done it. The capability is out there, and the vulnerability is out there. (Someone w…
It's most obviously paralleled by Samy Kamkar's MySpace worm, which exploited fairly similar too-much-trust territory.
I find it funny that: 1) He released it from MIT to avoid suspicion. 2) After he was convicted, he went from Cornell to Harvard to complete his Ph.D. 3) He became an assistant professor at MIT after that. He had to be really spectacular/have crazy connections to still be able to finish his training at a top program and get a job at the institution he tried to frame.
MIT really respects good hacks and good hackers. It was probably more effective than sending in some PDF of a paper.
Since it's all locked up, I just reboot the big vax single user - that takes about 10 minutes so I also start on a couple of the suns. You have to realize that everything including desktops runs sendmail in this era, and when some of these machines come up they are ok for a sec and then sendmail starts really eating into the cpu.
I'm pretty bleary eyed but I walk around restarting everything single and taking sendmail out of the rcs. The TMC applications engineer comes in around 7 and gets me a cup of coffee. He manages to get someone to pick up in Cambridge and they tell him that's happening everywhere.
It's a little shocking to me that there haven't been more things like this. While we're much more conscientious and better at security than we were way back then, things are certainly not totally secure. The best answer I have is the same as what a bio professor told me once about designer plagues: it hasn't happened because nobody's done it. The capability is out there, and the vulnerability is out there. (Someone w…
I find it funny that: 1) He released it from MIT to avoid suspicion. 2) After he was convicted, he went from Cornell to Harvard to complete his Ph.D. 3) He became an assistant professor at MIT after that. He had to be really spectacular/have crazy connections to still be able to finish his training at a top program and get a job at the institution he tried to frame.
> tried to frame. MIT really respects good hacks and good hackers. It was probably more effective than sending in some PDF of a paper.
Oooof in light of Aaron Swartz. He plugged directly into a network switch that was in an unlocked and unlabelled room at MIT so he could download faster and faced "charges of breaking and entering with intent, grand larceny, and unauthorized access to a computer network".
MIT really didn't lift a finger for this either.
>Swartz's attorneys requested that all pretrial discovery documents be made public, a move which MIT opposed
It's a little shocking to me that there haven't been more things like this. While we're much more conscientious and better at security than we were way back then, things are certainly not totally secure. The best answer I have is the same as what a bio professor told me once about designer plagues: it hasn't happened because nobody's done it. The capability is out there, and the vulnerability is out there. (Someone w…
https://en.wikipedia.org/wiki/Botnet#Historical_list_of_botn...
It's a little shocking to me that there haven't been more things like this. While we're much more conscientious and better at security than we were way back then, things are certainly not totally secure. The best answer I have is the same as what a bio professor told me once about designer plagues: it hasn't happened because nobody's done it. The capability is out there, and the vulnerability is out there. (Someone w…
To a fairly significant extent, the Morris worm is why there haven't been more; it did prompt something of a culture shift away from trusting users to trusting mechanisms, mostly by prompting people to realise that the internet wasn't only going to be in the hands of a set of people who were one or two degrees of separation apart. It didn't make sense to assume people would treat it with reverence like a giant beauti…
I find it funny that: 1) He released it from MIT to avoid suspicion. 2) After he was convicted, he went from Cornell to Harvard to complete his Ph.D. 3) He became an assistant professor at MIT after that. He had to be really spectacular/have crazy connections to still be able to finish his training at a top program and get a job at the institution he tried to frame.
You know his dad ran research at the NSA right? His dad's also a badass and super fun to talk to. Never talked to the son though, but I'd love to some day.
Wikipedia says the Morris worm went out on 1998 Nov 2. No idea why they would publish the article on 2025 Nov 4 with that title.
https://en.wikipedia.org/wiki/Morris_worm 1988
- a github repo containing "the original, de-compiled source code for the Morris Worm" - see https://github.com/agiacalone/morris-worm-malware
- a high level report about the worm - see https://www.ee.torontomu.ca/~elf/hack/internet-worm.html