Underground: Hacking, madness and obsession on the electronic frontierDreyfus, Suelette
Science
Underground: Hacking, madness and obsession on the electronic frontier
Dreyfus, Suelette
Computer crimes -- Australia; Computer hackers -- Australia -- Biography; Computer security -- Australia
Cracking passwords took time and computer resources. Even a moderately
powerful university machine would grunt and groan under the weight of
the calculations if it was asked to do. But the Deszip program could
change that, lifting the load until it was, by comparison,
feather-light. It worked at breathtaking speed and a hacker using
Deszip could crack encrypted passwords up to 25 times faster.
Zardoz, a worldwide security mailing list, was also precious, but for
a different reason. Although the mailing list's formal name was
Security Digest, everyone in the underground simply called it Zardoz,
after the computer from which the mailouts originated. Zardoz also
happened to be the name of a science fiction cult film starring Sean
Connery. Run by Neil Gorsuch, the Zardoz mailing list contained
articles, or postings, from various members of the computer security
industry. The postings discussed newly discovered bugs--problems with
a computer system which could be exploited to break into or gain root
access on a machine. The beauty of the bugs outlined in Zardoz was
that they worked on any computer system using the programs or
operating systems it described. Any university, any military system,
any research institute which ran the software documented in Zardoz was
vulnerable. Zardoz was a giant key ring, full of pass keys made to fit
virtually every lock.
True, system administrators who read a particular Zardoz posting might
take steps to close up that security hole. But as the hacking
community knew well, it was a long time between a Zardoz posting and a
shortage of systems with that hole. Often a bug worked on many
computers for months--sometimes years--after being announced on
Zardoz.
Why? Many admins had never heard of the bug when it was first
announced. Zardoz was an exclusive club, and most admins simply
weren't members. You couldn't just walk in off the street and sign up
for Zardoz. You had to be vetted by peers in the computer security
industry. You had to administer a legitimate computer system,
preferably with a large institution such as a university or a research
body such as CSIRO. Figuratively speaking, the established members of
the Zardoz mailing list peered down their noses at you and determined
if you were worthy of inclusion in Club Zardoz. Only they decided if
you were trustworthy enough to share in the great security secrets of
the world's computer systems.
In 1989, the white hats, as hackers called the professional security
gurus, were highly paranoid about Zardoz getting into the wrong hands.
So much so, in fact, that many postings to Zardoz were fine examples
of the art of obliqueness. A computer security expert would hint at a
new bug in his posting without actually coming out and explaining it
in what is commonly referred to as a `cookbook' explanation.
Public-domain text, read in full here on John Shaqi.
Reviews
Reviews
No reviews yet
Be the first to share your thoughts on this work.
Elsewhere in the archive
Join the Discussion
Join the discussion
Sign in to leave a comment or review.
Sign InorCreate an account