I hope that's understood I hope that's understood And a very good evening to one and all The program is Off the Hook And this is Emmanuel Goldstein Taking a look at technology and the law Through the eyes of the individual We're going to be talking tonight With Sheldon Zenner An attorney out in Chicago Who represented Craig Neidorf In his recent case Of 911 intrigue And that kind of thing And we'll be speaking to him just a little bit On the program tonight I want to congratulate anyone that tuned in on their own accord Because we haven't been here in quite a while And it's kind of hard to figure out when the show is on And when it isn't But for now We can say Without a doubt This program is on every two weeks Wednesday nights from 9 to 10 Stay with us We'll be having a minute We'll be speaking to you We'll be speaking to you Thank you. Thank you. Thank you. All right, enough of that. We're going to take a very quick look at what's going on in the world in the inimitable style of ours. I don't know why they always give the exact address in newspapers, but... She became short of breath and fell to the kitchen floor and called to her son, Michael, for help because she could not get up. Michael Morris, who lived with his mother, dialed the 911 emergency telephone number three times before an ambulance was dispatched. City documents show that after Dorothy Morris' death, city officials tried to pinpoint the cause of the delay. They interviewed dispatchers and checked car records and tapes of 911 phone calls. They also interviewed Michael Morris. Records indicated they discovered an internal audit or logging program designed to track messages through the city's new computer-aided dispatch system. And that had not been installed as promised by the software vendor, PRC, Public Management Services of McLean, Virginia. The new $760,000 system called CADMAS, which somehow seems appropriate, has been online since May 1st. The omission was the latest problem encountered with the system and with PRC. That, according to Martin Mendelsohn, director of the city's Department of General Services, he said the problems which appeared after CADMAS was installed included too much computer downtime, difficulties with the backup computer, which repeatedly failed to kick in automatically. I mean, they always fail to kick in automatically. And, uh, that's just one of the, uh, one of the things going on in the world. When the, uh, first computer crash, turnovers, conflicts with, uh, PRC, project managers occurred. But the most disturbing problem was the tendency for some messages to disappear after they were entered into CADMAS, city officials and dispatchers have said. When you call 911, that's just not good for that to happen, for, uh, for messages to disappear. You ever had a message disappear on you? It's happened to me a lot of times where someone leaves me an electronic message and it just sort of vanishes into thin air and you don't know where it's gone. It's all the more comforting to know that emergency systems and hospitals and all that kind of thing are using the same technology blindly. Nothing wrong with using technology, but when you use it blindly, man, you're asking for trouble. The, um... I'm going to skip this one. This one's way too long. Way too long here. We don't have much time, so, um, we want to get to the interesting things. Uh, no, we don't want that one either. Cellular phones. We're not going to listen to cellular phones tonight. However, if anyone out there has, uh, cellular conversations that they can access, we want to hear about it. Write to us here at Off The Hook. Care of WBAI, 505, 8th Avenue, New York, New York, 10018. And, uh, we'll be happy to share the information that you send us because information, my friends, is power. And information is also free. So, send it in to us and we'll be happy to, uh, to share it with the listeners. Well, uh, even when her cupboard was bare during the Depression, 76-year-old Faye Starman always paid her electricity bills. That was before Tuesday when she opened her $6.3 million Cleveland Electric Illuminating Company bill. It's a good thing I'm a calm person because I could have had a heart attack or a stroke, perhaps, said Starman of Newbury Township. The bill, payable last, uh, November 9th, actually, also gave her the option of making a $300,021 budget payment, far more than her home on Raveena Road is worth. CEI spokesman Mike Lump said the company's records were corrected immediately after her complaint and blamed the slip on mistakes made during a switch to a new computer billing system. The employee had tried to enter $63 in our computer, made a mistake, and the computer filled in the extra zeros automatically. People are learning the new system and there are bound to be one or two mistakes, especially when you send out 750,000 bills every month. The company also has heard from an Ashtabula County family, that's, uh, in Ohio somewhere. Uh, they received a $2 million bill, and he said he hoped we don't have any more of those floating around out here. If you get a $2,000 bill, or, no, a $2 million bill, or a $60 million bill, send that in to us as well. We'll be happy to do all kinds of fun things with it. Uh, this is about New York City. Uh, freedom of information request for statistical info on real property in New York City. Uh, the city resisted by offering the information in a million sheets of hard copy form for about $10,000. A million sheets. A court, however, has ruled that New York City has to provide it on MagTape at a cost under $100. For many years, New York City has been making property transaction records available quarterly on MagTape to anyone who will pay the nominal copying fee. They are used on PC-based, Novell network-type systems, and others, no doubt, by people who do many title searches for themselves or as a service for fee for others. The, uh, manual searching of titles and file cabinets at City Hall would be prohibitively expensive considering the size of the database. A manual title search involves beginning from the most recent deed and tracing the sequence of sales as far back as possible. Um, and it's, uh, according to the Risks Digest, which is an internet publication, it's difficult to imagine how, in a city the size of New York, such a necessary activity could be carried out without the widespread use of automated searches. It's equally difficult to imagine that the manual, labor-intensive method would be less prone to make undetected errors than would the computerized system. And, oh, that sounds like Albanian folk music. Oh, they must be doing something next door. Uh, anyway, U.S. Sprint has just announced that they are beta-testing a new phone-calling card system that will use voice-spoken card numbers, and no card number entries will be able to be entered by touch-tone keys. This presents the risk of the person at the next payphone to you overhearing your calling card number as you speak it, and be able to write it down and distribute it to other people, as has happened all over the country, all over the world, in fact. To make the matters worse, nine of the digits in the voice card are your social security number. Or to make it nice and simple for everybody. And finally, fine, actually two things. Two things I want to leave you with. This is also from the Risk's Digest on internet, from a person who works in an office, relating their experience. I was asked to change the paper on our fax machine today. I took a kit we have for this purpose and saw that I also had to change the toner roll. This is a roll of carbon paper, sort of, that actually prints the message on the plain paper. This is not one of these regular fax machines, it's a plain paper fax machine. Anyway, I saw that all messages printed on the fax are also burned in the carbon paper. That means that even if I stand next to the machine to receive a private message, people can later just open the fax machine and read the message. Even worse, since people are not aware of this copy on the toner roll, they just dispose of the roll in the garbage can. I wonder how many people are aware of this feature. And finally, from an advertisement in Newsweek, November 5th, 1990, information is your company's best protection from liability. Get it fast, without leaving your desk. Think about it. Know your potential employees. Verify the business credits of new accounts. Or check out your new vendors. Just hit a few keystrokes on your personal computer and you've got it. Information from UCC, civil and criminal record filings, secretary of state, and more allow you to uncover bankruptcies. Thank you, guys. Pending litigation and a wealth of information that may protect your company from liability or even loss. All you need is a personal computer and existing software. That's right. View it. Print it. Store it. Trade it. Like baseball cards. CDB Infotech's investigative information system is an online database designed to prove access, I'm sorry, provide access, I can't spell there either, to public record information for company security, credit personnel, and management departments. Not only is CDB Infotech's online service one of the most comprehensive in the industry, it's easy to use and fast. Before you make a decision, check the records, check with CDB Infotech. Need I say more? Need I say more indeed? Well, a lot has happened in the, what is it, five years since we've been on the air here? It's been a while, a few weeks anyway, maybe I exaggerate. A lot has happened. Some folks in Atlanta, Georgia, you may have heard about this computer hackers who were alleged to have broken into some computer systems belonging to Bell South. They were sentenced. Their sentencing came up. They had pleaded guilty and the three people that were sentenced actually were sentenced to prison time. We have on the phone with us Sheldon Zenner in Chicago. Mr. Zenner, are you there? Yes, I am. Oh, great. Sheldon Zenner is Craig Neidorf's lawyer. If you recall, a few weeks ago, actually a couple of months ago, we did a program about Craig and about his trials and tribulations. Craig was a publisher, an electronic publisher, who printed an article or a document that Bell South did not like. And Bell South, well, Sheldon, why don't you take the story from here and tell us exactly what happened with Craig's case? Sure. Oh, let's see. There was a text file or a document that dealt with administrative procedures that Bell South would use with regard to their emergency 911 system. Craig, who was the publisher of an electronic newsletter called Frack, received a copy of that document, which another fellow named Robert Riggs had accessed from a Bell computer. Riggs sent it to Craig for purposes of publication in Frack. Craig edited it down and published it in Frack by, you know, using computer methodology. And he got indicted for that. He was indicted for interstate transportation of stolen property, wire fraud, and computer fraud and abuse. The government dropped the computer fraud and abuse charges after we filed some motions challenging the constitutionality of that. They persisted in the interstate transportation of stolen property and the wire fraud counts. We filed some motions to try to get those dismissed. We lost on those motions. We went to trial and after four days of trial for lots of reasons the government ended up kind of throwing the towel in and dismissed the charges against Craig. So he has now returned to his life as a college student at the University of Missouri and that's how that case ended. Its relationship to the Atlanta fellas is that actually all three of the guys who were charged and convicted in Atlanta were cooperating with the government and were set to testify against Craig. One of them did, Robert Riggs. The other two were waiting in the government waiting room on the day that the government dismissed the indictment but they were to be testifying that day. they were charged with the actual break-in into the Bell computer system and getting the 911 document among others only Robert Riggs actually accessed the 911 document the other two fellows accessed other Bell South computer information. So that's the that's a real short version of the story. Well so the case against Craig was for all intents and purposes dropped, correct? That's correct. Alright now the three kids in Atlanta who had actually accessed the computer. They were sentenced last month and Robert Riggs received 21 months in jail the other two received 11 months each. Did that surprise you? Yeah it did. I had been in touch with some of their lawyers during the pendency of their action. They all pled guilty they all cooperated with the government that means provided information about other quote hackers unquote were prepared to testify in Craig's case. They might end up testifying in other cases for all I know. Given all of that and given the youth of all three of these fellas I was really quite surprised at the severity of the sentence. I really did not anticipate the judge hitting them as hard as he did and I don't think their lawyers anticipated that they would be hit as hard as they were. Well I know they didn't anticipate it either because judging from the reaction it's a shock to actually be sent to prison for that kind of thing. Have you heard any kind of indication and what frustrates me the most is that we don't really know what happened they're not telling us what happened. Have you heard any indication that there was any damage caused at all? Well of course Bell is kind of quick and liberal about their imputation of how much damage was caused by these break ins but my experience with Bell in this regard is that they're perhaps a little too liberal in attributing a dollar amount to the damage caused. I'll give you a quick example. Yeah good example. Yeah and in our case when Craig was first indicted they said that the value of the E911 text file that was published was I don't have the exact figure here but I think about $78,000 thereabouts. They actually had it down to the penny of some sort. $79,000 I think something like that. Yeah. Just under $80,000. Right. And not a penny more as John Barlow said. When we started to challenge that and told them what we thought of that number and they started to tell us how they calculated the number around the same time they did that they superseded Craig's indictment which meant filed essentially an amended indictment. Changed some things. one of the things they changed was what the value of this document was and it dropped to like $24,000. So the market in E911 text files dropped significantly over a few months. Ultimately we were able to prove at trial that comparable information was published by Bellcore, a Bell affiliate company, and could be purchased by someone who would call an 800 number right away for it for about $14. So I don't have a great deal of faith in the way that Bell assesses what the value of some of their property is or how much loss they suffered. It was obviously in their interest to try to hype the numbers, make it seem like it was a very significant loss. That kind of activity causes a judge to look at a defendant a lot more seriously than they otherwise would. But as I say, I don't have a great deal of faith in the numbers that Bell uses. I know when I saw the press accounts of the sentencing, they had some dollar amount that Bell claimed to have been harmed by the break-in that these guys caused. It may well be that what they did is calculate how much it cost them in man-hours to either catch them or to go back and try to find out where their system was flawed, which some people would argue was doing them a favor. I've got a list, actually, of what the cost they claim. All right. Yeah, something like, well, in addition to the prison time, they have to pay something like $233,000 in restitution. Yeah, I was going to say, that would be the number that Bell said was what they were out due to the break-in. Well, they described it as they stole $233,000 worth of logins and passwords. Now, I don't know what that means, how you can possibly put a price on logins and passwords. The other number they came up with was $1.5 million to find these three people. I don't know how it would cost the phone company $1.5 million to find three people. It doesn't seem very efficient to me. And the other figure was $3 million for security. And it seems to me if they had sprung for that security in the first place, maybe none of this would have happened. Now, I was wondering if it seemed as if the... You know, Riggs went in on an unpassworded account. He went in on... Yeah, I heard the same thing, that there was no password attached to that account whatsoever. Right, I mean, that's what he testified to in our trial. So, you know, how much of a genius do you have to be to get in on an unpassworded account? Well, that's just it. You don't have to be a genius. And that's something the media can't seem to let go of. But it's as if the judge in Atlanta was believing everything that Bell South had said, that they had indeed stolen a document worth $80,000, that they had caused Bell South to spend $1.5 million to fine them. Is that your impression that the judge believed everything Bell South said? That's certainly my impression. Again, I wasn't there and I have not actually talked firsthand to any of the participants, so I'm left to speculate. But the severity of the sentence suggests that the judge did accept not only Bell's representation, but my presumption is that the government adopted wholeheartedly Bell's dollar estimates. And made it their own. So you have the government and the quote, victim, unquote, Bell going to the judge saying that this is what our out-of-pocket is because of these guys' misdeeds, you know, send them to the moon. Well, my question to you, Sheldon, as an attorney, and after this perhaps you can take some phone calls, how is it that Craig's case was dismissed? He was found... Well, he wasn't found. He wasn't found not guilty, that's correct, but the case was dropped. How is it that that was possible, that the document was found to be worth $14, yet just a couple of hundred miles away in Atlanta, it's found that these people are guilty of something, as if they had stolen something worth $80,000? Why don't the same rules apply? Yeah, it's hard to give you a simple answer to that. I think there are a lot of different factors that come into play. Craig was charged with a really distinctly different crime than the Atlanta Three. No one's referred to them as that before. They were charged with breaking into the system. Craig was charged with, in effect, republishing something that they, or at least one of them, found. And those are different kinds of crimes. Well, one isn't a crime at all, is it? Well, alleged crimes, thank you. You know, what they claimed Craig was doing is some kind of a wire fraud scheme, although we were able to prove to them that because the 911 document did not qualify as a trade secret, it really wasn't property that could, be stolen, or the subject of a fraud scheme. Therefore, their case falls. That's why they dropped the charges. The charges against the guys in Atlanta were different because their activity was different. You know, under the Computer Fraud and Abuse Act, what those guys did, theoretically, was criminal. And, I mean, given the fact that they pled guilty to it, it suggests maybe it was. It also suggests maybe they didn't want to go through the ordeals of a trial. Well, again, you get a combination of circumstances working when somebody is facing these kinds of charges. They are not easy to beat, at least so far as I know. You know, Craig's case was the only one in the country to date where someone has successfully defeated a government prosecution alleging computer hacking-related crimes. And that was at an enormous expense to Craig and his family. I mean, that took months and months of lots of people's work, and in addition to the volunteer help of some wonderful people who were computer experts who gave of their time and energy to help me understand why the government was just dead wrong in this case, because it's difficult for those of us who are not computer savvy to really understand the defenses that exist in some cases like this. Well, you know, I think you put your finger right on the button there, because the key here is people that don't understand what it is they're doing. The people that come and conduct the raids of young computer hackers, not knowing what it is they're looking for, taking telephones, thinking that there's secrets stored in there, right down to the prosecutor and to the judge that has no idea what really went on. And that's what I'm trying to stress here, is the fact that these three in Atlanta are going to prison. They're going to prison, and nobody really knows what it was they did. Did they just call a computer and play around a little bit and not destroy anything, and they're going to go to jail for over a year for that? Yeah, I certainly have the impression that those guys did not go in and destroy anything. that the assessment of damage done to Bell's system, according to Bell, is not based on going in and destroying some program or some hardware or anything like that, but rather their numbers come from talking about how much it costs to catch them, things like that. So I think you're right. I think you are right, and I think that you do correctly focus on one of the most serious problems in these kinds of cases, which is that the government does not fully understand what they're looking at. The juries certainly have a hard time. The prosecutors don't fully understand, I think, though some of them are becoming much more computer-sophisticated. And a judge ends up relying all too often in sophisticated cases of this sort, relying on the government's word, or on the government's representations, and the government ends up just parroting what Bell tells them. Right. Yeah, that's the problem that occurred this summer, was that the government believed everything that Bell's South said. And, you know, over at 2600 we had a little bit of fun with this. We looked at the exaggeration factor, as we called it, with Bell's South claiming that $14 document was worth over $79. $1,000. And we applied that exaggeration factor to Robert Riggs' sentence of 21 months in jail. And we said, okay, if we put the exaggeration factor on that, how long should Robert Riggs really serve? And the amount of time we came up with was just over two hours. Yeah, well that, you know, Riggs is a sad case, and to, I don't know, I guess to be fair all around, I understand why he was sentenced to more time than the others. As I recall, he had two prior convictions for computer tampering related crimes. And in, anytime somebody is sentenced and they are a recidivist, they're going to face a more serious response from a judge. judge, so the fact that he received a more severe sentence than Darden and Grant doesn't surprise me. I am surprised at the totality of the sentences and the amount of time they did, or they are going to do. You know, Riggs was just a very sad, sad case. He had miserable family life, home life, I mean, just tragedy after tragedy. And I mean, I had to cross-examine him. He was testifying against us, but it was, he was pitiful. I'll tell you one quick story about that trial and Robert, who I actually kind of came to like, even though he was a witness against us, and we were cross-examining him. I think he was truthful and trying to tell the truth on the stand. We had a court reporter during the trial who was an older woman, very, very nice, sweet person. And when the government dismissed our indictment, and we came back to the office and were kind of celebrating and getting phone calls from people and telling people what had happened, it was a very nice time. I get a call, and I was getting some calls from media, and I get a call, and it's Agnes, the court reporter from the judge's courtroom. And she was calling to congratulate, but that really wasn't the upshot of what she had to say. She said, you know, this is good for Craig, and I'm glad for him, and all of that. And then she goes, but what's going to happen to poor Robert? I'm so worried about poor Robert. I mean, this was just the sweetest woman in the world who saw this really pitiful fellow up on the stand and hoped that he would not end up being punished beyond what was appropriate for the wrongdoing. And clearly, at least in my view, he was punished well in excess of what he did. So I guess the question that we're going to be asking our listeners tonight is, should computer hackers be sent to jail? What good will it do to send these people to jail? What can they learn there? And what kind of penalty is appropriate? If not jail for crimes of hacking. Our number is 212-279-3400. We're speaking with Sheldon Zenner, an attorney in Chicago. Go ahead. Yeah, the only point that I'd make to you is, I know what the government says in not only computer cases, but almost every other kind of case. And that is that they say we've got to send a message to the community. We've got to let people out there who are thinking about engaging in this kind of activity, know that if they do it, if they get caught, there is going to be hell to pay. And I have no doubt, even though I wasn't there and haven't looked at the transcript, that the prosecutor in Atlanta talked about sending a message to the hacker community, because if these kids think they can go on doing this, breaking into other people's systems, wrecking havoc, doing mischief, and that that will go unpunished with any jail time, we are sending the worst kind of message to that community. My guess is that's what the judge heard. As an attorney, is that effective, sending a message when you're, I hear that a lot in the media these days, sending a message when they sentence people. Does it work? Does it actually send that message and prevent other people from doing the same thing? You know, there's very little empirical data on that, but it fits into some of the traditional sentencing theory that you read in social science work. There are a number of different goals that are intended to be served by a criminal sentence. One is just retribution. One is specific deterrence, which means to make sure that that individual doesn't do it again. And a third one is called general deterrence, and that's the message to the community stuff. That's, you know, in sentencing person X, we are trying to deter others who might be like-minded. And I guess in my view, and as you know, others probably don't, I'm a former federal prosecutor, so I'm familiar with the speeches. I think the message to the community speech is terribly overused. The community doesn't know or care about 99.9% of the sentences that are handed down every day. And we're talking about teenage kids here. Well, the, you know, just maybe for purposes of conversation, I think there are certain discrete communities where you can send a message in the right case. If it's a high profile case within that community, if the word is going to get out within that community, then it may have some deterrent impact on others who might be considering doing the same thing. I'll give you an example that's outside of the computer sphere. I always believed when I prosecuted certain political corruption or police corruption cases, for instance, or vote fraud. I did a bunch of vote fraud cases early in my career as a prosecutor, people who were paying money to stuff the ballot box. This is Chicago, of course, and we do have some fine traditions. That within that community, if you give people who are committing vote fraud heavy sentences, you will probably deter some people from doing that, because the precinct captains and the political fixers and such who are out there and who might be tempted to do this, will know that Joe went away for five years for doing it. And I think in those kinds of instances you will have a deterrent effect. As it turns out, that's kind of timely here in Chicago. I just read in the paper this morning that someone who was convicted in that series of vote fraud prosecutions back in 1984 just landed a real plum job with the city aviation department. is going to be running one of the airports, which would make you all feel real good, and that he's had a variety of city jobs ever since he was convicted and just got kind of a six-month probationary slap on the wrist for vote fraud. There's the old prosecutor in me coming out. But there is an argument that can be made that says in the computer hacker community, which is a discreet community and which has high degree of communication within that community, the sentence that Riggs and Grant and Darden received is one that will be well-publicized, you know, on the nets and on the lines or on programs such as yours, and perhaps will impact what some people do. That's certainly the position the government would take. Well, we're going to take some phone calls, 212-279-3400. First, it's kind of a sobering predicament here. I really think it's useful to understand where the other side comes from on this stuff. Oh, yeah. And since you once were a prosecutor, that's... And that's their perspective, that if you whack Robert Riggs and Darden and Adam Grant, so that you some of the good that you do is that some kid sitting in his room reading over the wires or the net that these guys got hit with two or, you know, so years in jail may think twice before he starts playing around that night and trying to see what he can get into. That's what they're counting on. That's the theory of general deterrence. Okay, we've got one open line, so let's get those lines full. There's one story I just want to throw by you to see if you've heard this one before and also to the listeners. It concerns a happening in Staten Island last month during November. Two Staten Island youths were arrested on charges of invading and disrupting the computerized voice mailbox system of a Massachusetts firm, costing the company $2.4 million, and that's according to officials on November 6th. State police senior investigator Donald Delaney said as a result of the hacker operation, the International Data Group of Framingham, Massachusetts, lost scores of these messages. Delaney said an intensive two-month investigation led police and U.S. Secret Service agents to the two individuals in Staten Island, whose names we're not going to release over the air. He said exhaustive experimentation by the two suspects enabled their home computer to dial into the system and obtain the password to use it. The youths then changed the passwords for various units in the system, which resulted in the loss of many important messages. In addition, says Delaney, the company had to shut down the system for 18 days to revamp it. He added that the teenagers made bomb threats and other harassing messages to the company, and when they were in contact with women employees, they made sexually explicit remarks to them. Now, this whole thing is completely crazy as far as I'm concerned. We're dealing with a 17-year-old and a 14-year-old here. 17-year-olds and 14-year-olds do this kind of thing in various ways. Now, using computers is something fairly new, but they do make an occasional prank phone call. They will vandalize things on occasion. This all stemmed from the company not sending them something that the company was supposed to send them. I'm not saying that's right, that they should be doing this, but to threaten these kids with four years in prison as a result of this, and throwing at them that they've caused $2.4 million in damage, that's just wrong, and it's completely false as well because for them to cause $2.4 million in damage, I mean, they would have to set out intentionally to do something like that. And what actually happened, if I'm familiar with this voicemail system, the company left all of the passwords in the default. In other words, all the passwords, instead of being 24 digits long with three digits long, and they were all the same. So anybody could get in, anybody could change anything, anybody could listen to anything. How in the world was this company able to let this go on for so long so that their estimation of $2.4 million in damage actually became a reality, if it's even a reality? How are such things possible? The media, the newspapers, the TV reporters, they don't look at it from that point of view. They see kids breaking into a system and causing $2.4 million in damage. They don't see the other side of this, that it's gross incompetence that leads these systems to be opened in the first place. Now, we've got two kids that are probably scared to death now of going to jail and being fined an amazing amount of money just for being kids. They did something stupid, no question about it. But, you know, I think we're letting this whole thing go crazy as far as the kind of sentencing we're handing out, the way that we're treating this as some major crime. It's not a major crime. It doesn't take a genius to do it. It's, you know, it's something rather minor, rather trivial. It should be dealt with, but not in this way. Okay. That's my speech. The phone number is 212-279-3400. We have on the line Sheldon Zenner, attorney for Craig Neidorf, whose the case against him was dropped for publishing a document that Bell South did not want him to publish. Let's take some calls. Good evening. Hi, good evening. I had a question. I hope it's not redundant because I missed a little bit of the conversation, but it was about the value that was placed on the 9-1-4 information. 9-1-1 information? Yes, excuse me, the 9-1-1 information. Hope you don't have an emergency. Okay, go ahead. Now, I guess that the theory behind that is that this information, due to the fact that it was created by people in the field was in a sense like something they synthesized, something they curated, and that public knowledge of this information would negate its value? Is that the... Well, they didn't even really say that. The way they went about trying to come up with a dollar amount of value on it was to just do a man-hour study. how many people worked on putting the information together and compiling it in one place, but none of the information... But when this person obtained this information, did he remove the... Did he remove the... Did he get a copy of this information? Yeah. Or did he actually remove all the files that they... No, no, no, got a copy. There has never, to my knowledge, been an indication of a hacker removing copies of something. All of this concerns copying. Copying, right. In fact, there was a case... To me, the whole concept of theft is a little... I mean, nobody... When the Pentagon papers came out, nobody started running around circles and said, well, look how much it took us to put these Pentagon papers... Right. You know, we agree completely, and one of the arguments that was made consistently in our case was that copying something without permission was the crime, and the government kept calling it stealing, and I kept saying, you can't steal something that the person still has. You know, if they stole it from Bell South, then Bell South doesn't have it anymore. But Bell South still has it and uses it and used it for years after it was stolen. So how could it be stolen? It's not stolen. It's copied. And copying is not a crime. Now, if this manual, which I've heard something about this before in a Village Voice article, which actually wasn't even impossible to obtain by other means, from what I heard. Now, if this information became... I mean, after it became public information, it did not render the system useless. It had no impact on the system's functioning. And was this information, was that something that they wanted to market? Nope. They didn't sell it. They've never sold it. They had no intention of selling it. And in fact, the way that this was brought out in the media in the first few days of everything, it made it seem as if the kids that had logged into this computer were controlling the 911 system and could disrupt it and could actually... ...virus into it so people couldn't... Exactly. And it was completely distorted, and I think that might be some of the reaction that you're seeing now in Atlanta at the sentencing, that judge might very well believe that they were manipulating the 911 system, not just reading an occasional text file or two. Yeah, I didn't respond to that. The press release that the government put out when the indictments came out said that what Riggs had... said that Riggs had stolen a computer program which would allow for the disruption or halting of the emergency 911 system for the entire southeastern United States. Or when you put that kind of language... That was a press release. And that was absolutely wrong. It wasn't a computer program. It was an administrative procedures manual for Bell South, and you and everyone else in the world could have it, and all it would tell you how to do is who, if you're a Bell South employee, you go to if somebody's got a problem with their system, and who you send copies to of memos, and, you know, it's just nuts what they... But it's not unlike a plumbing diagram of an office building. Yeah, I mean, it was a bureaucratic, gobbledygook docent document about how a bureaucracy functions. It, you know, not... And it wasn't copyrighted. Oh, certainly not copyrighted. Barely legible. Not legible, but barely understandable. The juror just didn't respond. Right. Okay, we're going to move on to a couple more calls. Thanks very much for calling in. Speaking, though, of the Bell South document, and just to sort of make a point here, the next issue of the Hacker Quarterly 2600 is going to have something in there about Bell South. Another document, another document that I think makes the 911 document pale by comparison, was leaked 2600, and we did quite an interesting story on it. And we'd love to see what kind of reaction this is going to get, because there's all kinds of things that they're up to, and this is something I think will interest the average person a lot more. And that will be available at our next meeting, which is coming up this Friday at the City Corps Center, Friday from 5 to 8. Well, I'm sure the Secret Service will be there. The Secret Service is always there. In fact, it's interesting you mention that. I just referred to Don Delaney, New York State Police. He has gone on record as admitting that he has sent people to our meetings with cameras and tape recorders to spy on us. Now, imagine the absurdity of having an open meeting right smack in the middle of Midtown Manhattan in a public lobby, and having these guys with sunglasses running around taking pictures of you. It's the craziest thing you ever want to see, but, you know, if they have fun doing that. We took pictures, we took videotapes of them, actually, so we had more fun, I think. 212-279-3400. Good evening. 212-279-3400. Good evening. Okay, that's, someone's got the radio on. Well, we can't have the radio on. Turn your radio down when you call in, folks. Good evening. Yes, I called a few weeks ago, and I asked about any information you might have on this ATM hack I heard about. And whether or not you heard anybody know anything about it or anything else, because that's a serious piece of business right there. Well, you know, it's interesting. Are you referring to the GTE case out in California? No, it's something I read in Mondo 2000 a month or so ago. They said that somebody had sent them an article on a hack for ATM systems that people could, you can get into people's account. You can't create your own fictitious account, but somehow there's a way to get into somebody's account and withdraw certain amounts of money. And so I don't know if anything's happened yet. So you apparently... Well, in two weeks, sir, when we're on next week, we will be reading an excerpt from the latest 2600 that deals with just that. It's a document, another leaked document to us concerning ATM fraud. And that's something that's going to cause quite a stir, too, I think. Okay. I'd like to make a comment about the whole thing with kids breaking into somebody's computer systems. It is a very difficult problem because the computers give those kids a lot of power that the kids either don't understand or don't appreciate. And they have the capacity, perhaps, to do a lot of damage. But maybe the instances we're talking about here, they haven't. But, I mean, I understand the fear that these people have because, you know, in a way, it's sort of like you almost sound sometimes like the burden of proof in a way is contingent upon the person that owns the system to make it secure enough to keep casual pilferage out. And there's a lot to be said for that argument. But the fact remains, nobody has the right to screw around with my computer system, even if I am not smart enough to secure it properly, which a lot of these guys maybe aren't. You know what I'm saying? Well, I've heard that phrase before, but keep in mind that hackers don't go around invading people's personal computers. They go around exploring huge computer systems. That's what I'm talking about. I'm talking about if I were a corporation. You'd think they'd have more on the ball, but apparently some hackers do have ways to, you know, get passwords and things. It's not so casual as you make out sometimes. Well, don't you want to know that it's that easy to get in? It's that easy to find out information and to get your credit report and your arrest record and all that? Well, you can do that, like you say, without even hacking. All you've got to do is pay a fee and you can get information from credit bureaus and a lot of other kinds of databases, you know, so it's not that big a deal. Yes, I mean, I agree, but the fact remains that these things are criminal because it's basically like if I don't have such a good lock on my door and you're an excellent locksmith and you can pick your way in, that doesn't give you the right to poke around in my house. And I should be able to do something about it if I catch you. You know, so, and I'm a computer lover, too. It's not like I'm one of these, you know, Luddites who hates the whole idea of people wanting to fiddle around with systems because I imagine it's challenging, but I don't have a whole lot of sympathy for people who try to see what kind of mischief they can do in big computer systems. Okay, well, let me use your logic then. If somebody breaks into your house and looks around, doesn't steal anything, just wanders around your house a little bit, would you send them to jail for two years for that? Yeah. As a matter of fact, I would because it's an invasion of my privacy. It just, it gives me the creeps to have the, to think about it. Why should somebody have the right to come into my house? I would, and the reason I would send them to jail for that amount of time is precisely what that lawyer was talking about, to, to, to disincline them to do it again. I think there is a retribution aspect to this punishment. I don't say that those sentences are right for those kids, but as he, as he pointed out, one of them has done this before, so I don't feel too bad for him. He should know what the deal is. It's almost, it's a few orders of magnitude different, but now we're talking about, people are trying to consider what do they do about these teenage drug kids who go around shooting people up with automatic weapons. They can't try them as adults yet, but now they're trying to figure out what do you do when somebody has the power to murder someone? And it's maybe not, I'm not going to compare those, they're apples and oranges, but the, the question is we have to, you know, jiggle with the laws a little bit. How do you, how do you punish somebody who's underage and may not be totally competent, but they have a lot of power in their hands? Okay, I'm going to let Sheldon answer some of those questions. Thanks so much for calling. Thank you. Well, you know, I am somewhat sympathetic to, to what the caller was talking about just from a visceral level. I don't think anybody wants to, to feel like they've got their privacy violated. I sure wouldn't want somebody rummaging through my house and looking through my drawers, even assuming they didn't take anything, you know, merely because I, I don't have a good lock on the door. By the same token, I don't think that the appropriate sentence for someone who does that is two or three years in jail. I, I just, my view of the criminal justice system is you send people to jail for long periods of time for more serious crimes. And similarly, my feeling is with, with regard to hackers is that if you got people who have come in and who really have not done anything malicious to damage the system, but have basically followed their, I'll be a little generous with it, and just say their creative instincts and wandered around out of a little more than curiosity about what is in a system and how things work and methods used and then leave without doing any damage. I don't think those should be felonies. I don't think those should be jailable offenses. If, you know, if indeed they are crimes, they should be treated as, as trespass. And that's what it would be in the real world. If somebody kind of wanders in to your open door, wanders around or your, you know, your apple field or something. You know, if you're Farmer Jones and you've got that apple field and some kid climbs over your fence to get into the apple field, you don't send the kid to jail for two or three years because he wanted to see what was there. Oh yeah, some farmers would shoot though. You didn't steal anything of yours, but just wandered in and kind of invaded your property. That's trespass. And in most of the 50 states, trespass is a misdemeanor and nobody goes to jail for trespass. Yeah, exactly. A lot of people get very emotional about this when they think of their home being invaded by somebody and someone walking around looking at their personal items. I don't think it's the case here. I think it's completely different because you have, you know, you have a big organization. I think, I think the, the equivalent, the test of equivalency here is you have a file cabinet. The file cabinet is in a hallway in an office building and it says Authorized Personnel Only. And that's it. Now, if somebody opens that file cabinet and looks inside and looks at the files, you know, that's the equivalent to logging into a computer system. The only thing there is a little sign that says Authorized Personnel Only. You can get by it very easily and it's wide open. I don't think it's the same as having something behind a private problem. Well, I agree with you, actually. And that's why I think those who, who advocate, you know, hackers' rights should be wary of the home invasion analogy. I don't think it's an appropriate analogy because it really is different. And I think your example is probably closer to it, although the people who own the systems don't see it that way. But it's an interesting problem trying to use the right analogy that non-computer users will latch on to and find understandable. Sheldon, we have a full switchboard, only about a minute left, so I'm going to pick a call at random here and that'll be our last call. Good evening. Hello. Go ahead. Hello. Oh, hi, hi. Am I only here? Go ahead. Yes, you are. My name is Nicky. I'm a patient at Manhattan Psychiatric Center. Oh, it's terrible. I've been here eight and a half years, except twice I ran away. Okay, I'm going to make an exception. Go ahead. You're on the air. Hello? Yeah, go ahead. Somebody else is on the air, yes? No, don't worry about them. You're on the air now, but you won't be very much longer, so please make your comment. I just wanted to know about something you said earlier. It's not for your guest. It's about the, you mentioned that the New York City real estate records is now on tape and or disc. It's supposedly available on mag tape instead of on a million sheets of paper. It's supposed to be less than a hundred dollars. Right. I believe there was an article in the New York Times a few weeks ago. We are out of time, so thanks so much for calling in. Thank you, Sheldon Zenner, for being with us tonight, and best of luck to you in the future. Thanks. My pleasure. Okay, and we'll be talking to you again probably when other hacker cases make the front pages. All right. Thanks again. And that's our show for this week. We'll be back again in two weeks. Stay tuned for the personal computer show here on WBAI New York. Season's greetings from all your friends at WBAI New York. On Monday, December 10th at 9pm, Soundscape. Explorations in radio, sound, and security.