And you're tuned into Off the Hook, the program about telephones, technology, and the abuses thereof and therein. Very good evening to you. This is Emmanuel Goldstein, and we have all kinds of things to talk about tonight. I'll give you a hint as to what one of them is going to be. Drake is bad. That's the hint, and that's all I'm going to say at this moment. Thank you. I actually liked it better at that speed. Jean-Michel Jarret, one of my favorites. But we have important things to look at tonight, including one thing that we promised we'd focus some time on, and that is the wonderful world of ATM fraud, automatic teller machines. And then we'll be taking your phone calls at 212-279-3400 a bit later. Yes, ATM fraud. A document which was passed on to us over at 2600 magazine, directly from the Secret Service. I don't think they were the ones, actually, that passed it to us, as it says in this document. This document is not intended for distribution outside those having a legitimate professional interest, and is not intended for release to the news media. So if there are any members of the press out there, anybody from the media, turn off your radio now, I mean it. Turn off your radio and turn back on in about 15 minutes, because this is not intended for the media. Just for average people out there, average people that need to know, average people that feel they have a right to this information, and don't feel that it should be kept from them. Okay, now we got all those media people out of here. They are something else, aren't they? We won't talk about them while they're not here. Let's get right into this story. Synopsis of an ATM Fraud Scheme On February 4th, 1989, U.S. Secret Service agents arrested four individuals in Los Angeles and one in Lincoln, Nebraska, for producing counterfeited automated teller machine debit cards and for possession of access device-making equipment. When the defendants in Los Angeles were arrested, they were in the process of encoding the counterfeit ATM cards with stolen bank account information. The group was planning to travel to a number of cities throughout the United States to make cash withdrawals from ATMs linked to a specific nationwide ATM network. They made plans to travel in teams to different geographic areas of the country and to use disguises to defeat ATM surveillance cameras, which, excuse me, while using each card to its daily maximum for three to five days. Each card, generally, depending on the bank, has a maximum withdrawal limit of between $200 and $500. Some of them have little tricks where you can withdraw $300 and then come back and withdraw $200. And they're different for just about every bank. And every bank machine, by the way, in case you don't know this, every bank machine does have a camera somewhere inside it, and it takes your picture or just records the whole transaction on videotape. In fact, they could even record sound. Who knows? But they take a very keen interest in that kind of a thing. You can rest assured of that. The counterfeit cards were constructed of poster board cut to the appropriate size and affixed with common magnetic tape. The tape was encoded with stolen cardholder account data on track 2 for use in ATMs. Seized concurrent with the arrests were a computer, an encoding device, and thousands of counterfeit ATM cards. The defendants intended to execute the scheme over a five-day period during February 1989. Test cards had been successfully used in at least three cities, which netted the defendants about $5,000. This case constitutes the first known attack of this magnitude on a major nationwide ATM network. Bank officials interviewed after the arrests confirmed that the account numbers used in this case would have given the defendants access to the checking accounts, savings accounts, and any line of credit available to the legitimate cardholders. An audit of those accounts revealed this scheme could have netted the defendants as much as $5.5 million had all gone according to plan and had the scheme gone undetected. Well, things didn't go according to plan, obviously. We wouldn't be reading this right now. One industry expert from outside the bank speculated that it is plausible someone could, using this scheme or one similar to it, access accounts and steal as much as $100 million have carried to the extreme and extended over a 30-day period with careful execution. And if they don't go around boasting about it in bars and things like that, I guess. It doesn't say anywhere here how they were caught. I'd love to know about that. In the city where this conspiracy began, several, known as La La Land, I think, several national and regional ATM networks share a single telecommunications carrier which routes transactions between ATMs and banks. In addition, the telecommunications company, which is generally rumored to be GTE, but again, that's only a rumor. That's why we asked the press people to leave because they take rumors the wrong way. The telecommunications company, through a subsidiary, maintains a number of ATMs in a proprietary network which they make available on a contractual basis for other networks to use as ATM outlets for their respective cards. Thus, the role of the subsidiary company is similar to that of any bank on the telecommunications network. The mastermind of this scheme was a computer programmer employed by a well-established software company specializing in the design and implementation of ATM network software. His company was contracted by the telecommunications company to update and expand the existing proprietary network. The primary defendant's function as a programmer was to implement software which drove ATMs and point-of-sale terminals, those are known as POS terminals, on the proprietary network in order to make information compatible with and therefore acceptable to the main electronic switch maintained for all of the participating networks on the communications system. His position required him to have access to most of the technical data pertaining to software for both the proprietary ATM network as well as the main communications system on which all of the networks were mixed. In keeping with established industry standards, the telephone carrier subsidiary in this case encrypted the personal identification numbers known as PINs used in conjunction with ATM cards. This was done prior to transmitting data from the ATM across the proprietary system to the electronic switch where the transaction would be routed to the appropriate bank. The system targeted in this case is typical of ATM networks found throughout the United States. When a cardholder accesses his account through use of a debit or credit card at an ATM machine, the customer is asked to key in his or her personal identification number. The PIN is encrypted using the Universal Data Encryption Standard known as DES, D-E-S. That particular method employing an encryption key known only to the owners of the proprietary system to which that ATM belongs. The account number and other Track 2 data from the ATM card, encrypted PIN, and information about the requested transaction are then transmitted electronically to a switch maintained by a designated communications carrier. At the electronic switch, messages from several proprietary systems are received and decrypted using the same DES key as was used to encrypt the data. At that point, the information is sorted by destination bank and encrypted with the proper DES key provided by the destination bank. The transaction is then transmitted across the main communications line to the appropriate bank. Theoretically, upon receipt at the bank, the information is once again decrypted using the key supplied to the communications network. However, in practice, this step may not actually take place as the recipient bank may elect to accept the encrypted version of the PIN and process it in its encrypted form. Upon receipt at the bank, the account is queried and a determination is made relative to authorization or denial of the requested transaction. The flow of information is reversed upon return of a message from the bank to the originating ATM. To illustrate, if Bank A issues ATM cards and maintains their own ATMs at various locations, they are running a proprietary system. A communications carrier must be employed to tie the system together, but since there are no other participating banks on the system, the sorting process at the previously described electronic switch need not take place. All transactions are directly between the ATMs and the bank. No NICE or Cirrus network floating around. Even on a closed system such as this, the industry encourages the use of PIN encryption. Furthermore, DES is the preferred standard when PIN encryption is employed. On the other hand, if Bank A elected to enjoy reciprocity with Banks B and C enjoy, I don't believe this, permitting transactions at all three banks' ATMs, in other words, have a little network like we have here in New York, then an electronic switch would be installed to sort and route transactions between all of the ATMs and Banks A, B, and C. The transactions destined for Banks B or C from ATMs owned and operated by Bank A would still be considered to be on the Bank A proprietary system until they reached the electronic switch where they would be mixed and sorted by the destination bank. At that point, the proprietary ATM networks from Banks A, B, and C combine to share a common communications carrier, but the networks remain independent and do not share encryption keys. The function of the electronic communication switch is to sort the transactions, determine which encryption key to use, and establish how to route the information to the destination. The system abused in the case in which these arrests were made was similar to that previously described with the communications carrier subsidiary functioning in the role of Bank A. specifically, the subsidiary owned a network of ATMs and through a contractual arrangement accepted debit and credit cards issued by various banks and honored by other networks. When a transaction was requested, the information was handled on the proprietary network until it reached a communications switch where it was decrypted, then encrypted with the proper key for the destination bank and fed into the main communications line used by all of the proprietary systems cooperating in this enterprise. As a part of their routine business practice, the subsidiary recorded all transactions on the proprietary network before those transactions reached the electronic switch. The intended purpose was to create a transaction log from which all activities could be reconstructed should a system or other failure occur. The pins remained encrypted in this recording process. Either while performing his job or merely by knowing where to look based on his intimate knowledge of the system, the scheme's mastermind discovered that the key used to encrypt pins on the proprietary network was a default key as opposed to a proprietary key selected by network officials. A default key in an ATM machine encryption device is analogous to a common computer password installed by a mainframe computer manufacturer. Its intended purpose is for testing during the installation phase and it is expected that the default password will be removed once the system is installed and accepted by the buyer. Well, guess again. Upon making this accidental discovery, the programmer realized the value of this information and was able to refer to various software manuals and textbook literature to decipher the key. The programmer knew data was routinely recorded to the transaction log and that he could access the data transmissions as they were being posted to the transaction log and thereby see all transactions on the proprietary network. It was there at the transaction log that he copied account numbers and the encrypted PIN offsets onto his personal computer. Now, while it is believed the information was copied in real time that is concurrent with it being posted to the transaction log, it could have just as easily been done using another method. The programmer could have electronically copied data from the computer tape containing the transaction log and extracted the same information. Either method would have netted the same result. At this point, the programmer made a conscious decision according to his post-arrest statement to use account numbers from only one major bank. He said he did so because he believed that once the crime was discovered, suspicion would center on an internal problem within that bank. After selecting a generous number of accounts from the targeted bank, the employee wrote a computer program to decrypt the PIN for each of those accounts. He was able to accomplish this using the default DESC key. It was later learned that accounts from other banks were also used during the testing phase of the scheme and that those accounts and PINs were obtained in the same manner. He also realized that the network would be reviewed for potential weaknesses once the crime was completed, so he reported the apparent oversight in using the default encryption key on the system and made recommendations to his superiors about how to remedy the situation. The remedies were put in place, ending his access to additional account data. He also accomplished his goal of shoring up the network so that there would be no apparent weakness in the system from which the information could have been obtained. As an aside, it was noted by the investigating agents that the network in this case had been in operation when purchased by the communications company subsidiary. At the time of this writing, it has not been established whether the default key was in use by the company from whom the subsidiary brought the network or whether a proprietary key had been in use. Next, the defendants constructed counterfeit cards using poster board cut to ATM card size to which magnetic tape was mounted. The programmer then wrote a program which he used in conjunction with a magnetic encoding device borrowed from his office to write the account number and other data to each of the counterfeit cards. The data was properly encoded in the appropriate positions on track two of the magnetic stripe. Among the data elements actually copied to the magnetic stripe were the primary account number it's known as PAN and the pin offset. In systems where the pin is assigned to a customer the pin is a direct derivative of the account number and the DES encryption algorithm and is referred to as a natural pin. In systems where the customer selects his own pin the customer selected pin would not match the natural pin so an offset number is used to resolve the difference. When the offset is added to the customer selected pin it will equal the natural pin and the verification is made. Thus, in this case an offset was necessary as the system was one in which the customers had selected their own pins. At the time of their arrests the defendants were in possession of more than 7,400 account numbers with pins and pin offsets all from the same bank. In fact, as previously mentioned they were in the process of actually encoding the cards when arrested. Among the items seized during the search and arrest were the programmer's personal computer an encoding device and several thousand counterfeit cards in various stages of construction from uncut poster board stock through finished encoded cards. Although a great deal of technology was compromised and used in the execution of this scheme in the end this crime was one in which a trusted employee exploited his knowledge and position to manipulate and misuse the system. the only true technical deficiency or error uncovered was that the default key was left in place when the proprietary network was absorbed. Presumably it had been in place since the system was first activated although that has not been established as fact. At the time of this writing it is unknown who should have been responsible for replacing the default key with an active proprietary key. Perhaps this oversight could have been prevented had a more thorough checklist been used by the communications company subsidiary when they absorbed the system or by the previous owner of the network. Regardless had the recognized protocol for securing their respective data been followed this crime would not have been possible. Human nature greed opportunity and a willingness by the defendants to commit larceny combined with human error and not properly installing and reviewing system safeguards account for the forming of this scheme. It is fortunate that the information came to light before the scheme was executed. The central figure in this case is a high school graduate and was gainfully employed with a substantial salary. He stated that he was motivated in part by his desire to purchase an expensive home and did not want to wait as many years as it would take to save before he could acquire the property he had in mind. His wife is a co-defendant and she too had been gainfully employed with a good salary. Another of the defendants is a graduate of the Air Force Academy and has a master's degree from a prominent university. You just never guess that such prominent people would commit a crime. Amazing. None of the defendants has a criminal record. Well, I imagine they do now, but they didn't before. All have been charged with several counts of violations of Title 18, United States Code, Section 1029, Access Device Fraud. As written, that law provides for substantial penalties. And no early withdrawals, I can tell you that much. Each count of producing or using counterfeit cards carries a maximum sentence of 15 years imprisonment and a fine of $50,000. Let's see here. They produced 7,400 cards there and each one of those cards carries a maximum of 15 years in jail. Well, they could be in for quite a while, actually, if the judge is in a bad mood that day. the same penalties apply to the possession of device making equipment. Possession of device making equipment. That's a phrase that has come up a few times in the hacker circles. Rather nebulous phrase, to say the least. The possession of 15 or more counterfeit cards carries a maximum penalty of 10 years imprisonment and a $10,000 fine. Ultimately, upon conviction of the defendants, the recently implemented federal sentencing guidelines were to determine the sentences. I don't have what the exact sentences actually turned out to be. That's the story as seen by the Secret Service. This is a document that was distributed within the banking community, a whole group of bankers who do nothing but talk about banks and how to protect them and things like that. Now, as I see some of our press people are beginning to rejoin us, you, the average person listening out there, knows a bit more about this, a bit more about how ATM fraud could work, how you could be victimized by it, how semi-wide open the systems can be if morons are running things and don't change default passwords, and how the whole thing works in the first place. I think that's essential to pass that kind of knowledge on. We'll be taking phone calls in just a little bit at 212-279-3400. The program is off the hook. This is Emmanuel Goldstein. We spend our time talking about technology, its abuses, and its oddities. It is. What did go at one time to WHO will run up to an detail. King and to pick up and test and look new and how and in case you missed the clue at the top of the hour I'll say it again Drake is bad real bad we'll unlock that door in just a couple of minutes again the phone number is 279-3400 and here's an interesting story from the Newark Star Ledger of December 15th H.J. Kohler, owner of an Elizabeth, New Jersey armored car service who pleaded guilty to illegally wiretapping his employees was placed on probation for five years fined $25,000 and ordered to perform 250 hours of community service Kohler, 61, his brother and New York electronics consultant Robert Schios all pleaded guilty last September Schios is awaiting sentencing Assistant U.S. Attorney John Lacey said the government found a pattern of illegal wiretaps over two decades by Kohler and people entrusted to him Rodriguez pointed out that corporate America must be told that illegally wiretapping employees is a crime for which they will be punished and now to to the lighter part of the program well, I shouldn't say lighter I mean, everything is really serious if you look at it in the right light but this is where we're going to unlock a door we did say that Drake is bad and we might just as well shorten that make it a contraction and just say Drake's bad you know Drake's bad doesn't mean a thing to a single person listening but in a few moments it could be a legend let's start by making a liar out of a long distance phone company I love doing that let's grab a dial tone here oh, thank you there's one let's call up a long distance company AT&T this is Stacy my goal is to give you excellent service how can I help you? yes, hello I was just curious about one thing I was thinking of getting AT&T as a phone company I've just arrived in the country and I'm not very familiar with the way things work here you can probably tell by the way I'm mangling the language what could I answer for you? well, I'm just curious is every telephone in the United States reachable directly by using AT&T? yes ok, that's all I wanted to know from anywhere ok, great thank you very much for your help that's all I wanted to know they've just made a terrible mistake now let's go back to Drake's bad here and see what we can find out about it and who better to go to than a trusting operator alright pick up the phone and whoops I don't know how that happened let's pick up the phone again I might hit one too many digits there oh, that doesn't sound like an AT&T operator uh, yes, hi is this AT&T? oh, no, I'm sorry I thought I was dealing with AT&T ok, so to reach AT&T free location please hang up and dial 10 2880 there's no 10 on my phone though I mean 1028 ah, ok thank you very much boy, I'm so stupid sometimes ok, let's let's do it the right way let's see if we can deal with AT&T now new york telephone this month may I help you? uh, yes can I have AT&T please? certainly thank you moment for an operator who can assist you thank you hey, they changed the voice AT&T, how can we help you? hi, I'm trying to find out an area code um, I believe it's in California and the name is Drake's Bad the area code there? you, uh, Drake's Bad, California? yeah have you ever heard of that? uh, I'll check it for you thank you D-R-A-K-E-S? yeah, uh, and a contraction apostrophe S ok, I have a lot of Drakes you have a lot of Drakes? you have Drake's Bad number 1 Drake's Bad number 2 Drake's Bad number 3 all the way up to 9 all the way up to 9 I wonder which one I need uh, you have them all the way up to number 17 uh-oh got them up to uh, 25 they're all the same area code 916 oh, they're all 916 ok alright, what is that? a special kind of uh well, I thought it was it was just a place but apparently this uh, how many of them did you say? I guess there's a lot of them you have a listing up to number 36 up to number 36 Drake's Bad number 1 number 2 all the way up to 36 boy, I guess they ran out of names for cities, eh? yeah, right ok, thanks for 916 for all of them 916 ok, thank you can you connect me to 916 information please? no problem, sir thank you if you're the AT&T have a good night you too ah, here we go this is, I mean what city please? uh, yes hello uh, is this the 916 area code? yes, sir hi, I'm trying to find the number for Drake's Bad California? yes ok, and what number did you need there? uh, well let's see um, I believe it's just listed as Drake's Bad you know, I don't I don't think it's anything more than that ok, sir then you need to call the operator first and ask for Drake's Bad Drake's Bad number 2 or else you could if there's no answer there, you could try this thank you for calling the number is 5-2-9-1-5-1-2 once again 5-2-9 I hope this isn't one of those ones that hangs up after they give you the number oh, it is one of the ones that hangs up ok, that's that's really horrible because if you have another question for the operator you have to pay another 60 cents to find out but, I guess life wasn't meant to be fair alright, well we know now that we have to pick up the telephone and ask the operator for Drake's Bad number 2 let's, uh let's give it a shot we seem to have lost that operator we're getting another one now uh, yes is this New York telephone? yes sir I'm trying to reach uh, Drake's Bad number 2 in California thank you hold for this assistance please one moment for an operator who can assist you thank you I think she just got slowed down or something agent, you how can we help you? uh, yes hello I'd like to place a call please to Drake's Bad number 2 California uh, that's it Drake's Bad number 2 one second okay come on I need your help he's calling Drake's Bad number 2 California how do you get that? yes one second one second one second sir oh, no hurry no hurry no hurry at all Drake's Bad oh, no hurry no hurry at all no hurry at all oh, no hurry at all oh, no hurry at all yes, that's 916 916-12-028 916-12-028 hello operator hello operator are you there don't know if the operator is still there still here ah, good I heard a different number there one second okay okay okay system bill inward may help you yes operator drakes bad california what's your number drakes bad operator uh sir what number uh i was trying to reach drakes bad number two certainly thank you how can i dial that direct pardon can i dial that direct no it's a toll station we have to key it in for you you mean there's still places in the united states you can't call direct oh boy direct all right uh-huh and that's it ringing now well i hope it's it ringing oh well i guess they're not home uh well so much for that drakes bad number two yes it is what is known as a toll station toll station what is a toll station well folks let's journey back to the 1930s or 1940s or whatever toll station is a telephone in a very very remote area so thinly populated that not even a small exchange can be maintained at least profitably maintained one two maybe three or four phones in the middle of nowhere literally the middle of nowhere they're from uh they're connected to a very far away exchange most of them are in uh places like nevada utah arizona and there are some in idaho and california as well and i'm told that uh you'll find them in places where the population of a town is about six or so this uh this particular explanation of a uh toll station comes from an electronic magazine called telecom digest non-dialable points they're referred to as non-dialable exchanges toll stations other strange things this person says i did a search of a bell core database about four years ago for points in north america with a non-dialable flag set and came up with 4589 of them i then excluded mexico and had 1657 left after excluding the caribbean and canada there were only 825 left and uh they're located in alaska arizona california idaho kentucky louisiana montana nevada oregon texas utah and washington most of them are toll stations a few are actual exchanges and for the doubting ones among you call 206-555-1212 and ask for the ross lake national recreation area in new hallam washington you will be told to dial your o operator and uh ask for new hallam 7735 this is an automatic exchange which cannot support incoming toll calls local calls are dialed on a four digit basis the incoming restriction may be due to a long-standing requirement that calls be dialable on a seven digit basis locally and uh more interesting though is the system in shoop idaho call 208-555-1212 and ask for the shoop salmon river store you'll be told to call shoop 24f3 that's right shoop 24f i gotta i gotta hear that one i gotta hear a letter in uh okay let's see if we can do this okay we are calling information in idaho and these phones keep disconnecting you know somebody out there a phone system they want to donate to wbai please do so at once uh-oh my secret code have to enter the secret code i'll do that off air okay this is connie uh hi okay yes okay uh yes i'm looking for the um this is idaho right yeah okay i'm looking for the uh shoop salmon river store that's s-h-o-u-p okay it's in north fork is the town is that it i believe so okay the number is three nine four two one well i guess it's outdated information then huh it must be okay well these things do change occasionally this is only uh only a few months old though boy that's sad to think that uh toll stations are slowly vanishing shoop 24f3 you can no longer dial that well you can dial 212-279-3400 but leave off the 212 if you're in town and uh any comments or questions about telephone related or atm related uh things and uh while you're racing to your phones i want to read a very brief piece that uh has just been put out about hackers and uh violation of privacy and that kind of thing so uh listen up and give us a call operations sun devil remember that that was the uh most massive raid of of hackers that uh since the spanish inquisition as far as i can tell arthur uh cussler's novel darkness at noon tells of the downfall of a bolshevik he is purged by the party charged with conspiring to assassinate stalin and i'm reading from uh a piece called the sanction of the victim by michael e marotta and this is being distributed electronically all throughout the computer underground um returning to the downfall of the bolshevik of course he did no such thing uh plotting to assassinate stalin uh he soon comes to understand the needs of his captors as a bolshevik he knows the theory of the centralized democracy and he comes to understand that merely questioning authority is no different than a physical assault on the leader the operant theory in this true-to-life example was later enunciated by ann rand in her novel atlas shrugged she called it the sanction of the victim in atlas shrugged the heroes are engineers and investors who learn to reject mysticism altruism and collectivism they learn to be proud of their own achievements they identify and reconcile the contradictions that tore them apart and allowed them to be regulated ruled taxed and vilified one of the highlights of this novel is the trial of hank reardon a steel industrialist who violated an equalization of equalization of opportunity law he tells the court that it can sentence him to anything and he is powerless to prevent that but he will not help them by participating he does not recognize their right to try him and he will not help them pretend that the trial is just he is acquitted if this seems too unreal consider the case of craig knight or in chicago and compare it to the trials of the legion of doom in atlanta if you've been listening to this program over the last few weeks you'll know that craig knight or was a hacker publisher a publisher of a hacker newsletter an electronic newsletter out of missouri and he was charged with with distributing a harmful document in the form of the emergency 911 document and the folks in atlanta georgia from the legion of doom were pretty much charged with the same thing although they were charged with actually logging into a computer and obtaining that document so those are the um the two uh cases here that we're referring to craig knight or stood his ground prepared a first amendment defense and asked for help from the pioneers on the electronic frontier the government dropped its charges in atlanta the hackers cooperated with the government informed on each other and even testified against craig knight or if and they were sentenced to prison knight or incurred legal expenses over a hundred thousand dollars this is also uh actually it's quite less than the fines that have to be paid by the legion of doom hackers in atlanta who uh according to who you talk to it's either two hundred and thirty three thousand dollars divided by three or two hundred and thirty three thousand dollars for each of the three i have yet to hear exactly what that is and of course the main difference is that neidorf is free and they will be going to jail the decision to go to trial rested on the premise that right makes might neidorf prepared a first amendment argument in point of fact victory hinged on the demolition of the government's evidence a suitable defense could have been created from any perspective the first amendment is a broad shield that protects religion speech and assembly in addition to writing the 10th amendment guarantees all those necessary and proper rights enjoyed by the people that are not specifically enumerated in the bill of rights neidorf could have claimed that he was performing a challenge commanded of him by the gods of olympus what counted most is that he felt that his accusers were morally wrong the legion of doom went down the drain in atlanta because they granted the moral high ground to the government they were wrong in their own eyes and they deserved punishment by their own standards their viewpoint and their standards were the same as the government's the question then becomes is hacking right unless you want to go to jail you better find a lot of reasons to believe that it is one hacking is against the law congress and the states have enacted duly constituted rules against unauthorized access to computers answer the laws are wrong slavery was once legal so what the opinions of a few hundred politicians do not change the reality of right and wrong historically freedom from the american revolution to solidarity is against the established laws it's true freedom is against most laws good point the laws change when the old kings and dictators are swept away by democratic forces hackers are radical information democrats they may not know it but they are two hackers violate privacy well the answer to that is there is no privacy privacy is what is in your head your heart and your home your genitals are your private parts anything on a computer especially a computer connected to other computers via telephone lines can be accessed by government employees corporate clerks even used car salesmen a major book publisher sells a cd-rom disk of 80 million customers nothing on a computer is private number three hackers violate property rights the answer that's another question what is property during the middle ages land was real property but books and tools were not today we still have real estate laws that require title searches as if land were granted by the king of country from the duke of earl to the baron of gray matter yet industrialism brought a new understanding a machine could be bought or sold independent of the land it rested on you did not perform a title search to buy a forklift today the cybernetic era rests on the fact that data processing is different than computing machinery the machine is one thing the information in it is another number four hackers cause damage answer this is the propaganda of a tottering regime disgruntled employees erase computer files because workers who feel mistreated will always strike back at the people they see as their oppressors also criminals who want to get their hands on money have learned to use computers as they previously learned to use guns and fountain pens this is not hacking hacking is what happens when someone who is interested in computers works to learn more about them there have been no documented cases of a hacker destroying data number five hackers threaten the money supply answer this is the reason that the united states secret service has been busting computerists but hackers are not interested in monetary gain the real threat to the economy i'm sorry to the economic well-being of america's government monetary and fiscal policy indeed excuse me oh boy indeed it is no accident that one of the biggest supporters of the government crackdown on hackers was arizona senator dennis deconsini the man who was bought by savings and lawn swindler charles keating the government has targeted hackers in order to cover up the fact that the entire financial fabric of the nation is coming unraveled and that uh that is a piece about operation sun devil written by michael e morata some uh food for thought there well let's uh turn to our phones and the time we have left 212-279-3400 good evening hmm you know it's sad when the people that call first just sort of fall asleep on the phone i don't think i was that boring good evening hello how you doing um i'm really intrigued by this whole hacker thing and you know i'm completely computer ignorant but i was wondering if you could you know like name a few like fun things you can do to um i don't know take it into like uh like the billing accounts for you know some of the conglomerates like the telephone or whatever you know just by simple computer hacking devices and screw things up well now the uh the goal of a hacker is never to screw things up that's a very important distinction we've got to make right here the joy of hacking and every hacker knows this every hacker has felt it and the people that have not felt it are usually the ones that uh are are after after the the strongest prosecution of of anybody who's using another system the thrill is exploration knowing that there's you onto something that there's something that nobody else has found yet just the thrill of the chase the thrill of finding something different and learning on the way you don't have to screw things up to learn things and it's uh that's a very basic rule and and i think it says something of uh of the hackers today that not a whole lot has been messed up and what has been messed up is because of uh of people like uh the ones we referred to earlier that want to steal money hackers don't want to steal money hackers want to penetrate systems see how far they can go see what they can find and what the uh the unfortunate case of the three lod members in atlanta what from what all accounts i've heard what they were doing was simply exploring a telephone company computer they found an interesting document and they read it and they distributed it and now they'll be going to jail for two years up to two years for that for exploring for being a little bit mischievous but again no damage was caused very important that uh aspiring hackers know that that's uh that's assumed that's assumed of you when you go out exploring things that you won't mess things up good evening good evening how you doing okay really enjoy your show can you tell me if uh if you have any information with regard to uh whether 9x is um in thinking about instituting the core identification number i know there are a couple of suits that were pending at one point well that's got to get by the psc the new york state public service commission um i don't see that happening real soon i do think though some form of caller id is inevitable and uh you know it's it rubs a lot of people the wrong way it rubs me the wrong way in in quite a few instances but it's also something that uh you can use to your advantage uh don't be uh fooled though new york state does have just like every state in the union has some form of identifying calls particularly if you if you uh call an 800 number uh many many times your number is displayed as you make the phone call it doesn't matter if the state that you're in has caller id or not and that's uh that's something that uh that i think a lot of people should become aware of well i meant for residential causes is there some reason why uh new jersey bell was able to institute so much faster they just happen to be first i i imagine because uh uh you know bell core is actually in new jersey they have a bit of of pull with the uh legislators and they're able to do things a little quicker maybe um again i feel i feel some form of caller id is inevitable how much of an invasion of privacy that's up to you that's up to the rate payers and how much of a of a noise they make you've gotta you've gotta press for uh suppression of caller id people say oh that defeats the whole purpose of it well uh you know privacy is something that we take for granted on the telephone i mean i don't know who you are i don't think i have the right to know what your phone number is i you know it's it's it's not something that you're used to when you're making phone calls of giving out all this information it's uh it's like what ed me says those who have nothing to hide have nothing to be afraid of and you know what i think of that statement it's garbage no i mean in talking to a person usually you do get their name or whatever um but i understand what you're saying and um you're most helpful thanks a lot thanks for calling okay and most of those caller id uh devices have a particular function where you dial a certain a certain combination of digits and you can institute a trace on a particular call whether you have caller id or not and i think that should be enough you know if somebody is harassing you okay you hit a certain button their number gets forwarded to the authorities and if you want to you file charges now i think that's a lot better than uh every time you make a phone call having all that information about you passed on or not passed on you never know do you good evening oops good evening well good evening to you too good evening hi how you doing hi how are you go ahead i'm enjoying your show um you understand that uh it and t is regulated by the government and therefore it comes on the auspices of the uh national reconnaissance office okay you're gonna have to you're gonna have to wrap this up uh you're referring to itt or at and i'll be i'll conclude uh as far as the privacy act we are always being supplied on because uh communication through the air or through uh long lines is monitored by the government and uh we take advantage of this service which is wonderful however that is why mr garty or mr noriego or anyone has problems because someone's always listening good very much good point thank you for calling and that's a a very good if somewhat uh pessimistic note to end on and that's going to uh just about bring our show to a close for this evening the uh computer show is next personal computer show that is and uh we'll be back again for another episode of off the hook we'll probably be talking about the rate increase of new york telephone next uh uh next show which will be in two weeks and while it may not be on your mind now i'm sure it's going to be on your mind then because it's very likely to be passed within the next two weeks so uh we will be back at you then until then emmanuel goldstein good night and happy holidays the telephone keeps ringing so i ripped it off the wall i cut myself while shaving now i can't make a call 99.5 fm wbai new york on may 17 1984 wbai fm was granted a license by the federal communications commission to serve the public interest as a public trustee until june 1st 1991 our license will expire on june 1st 1991. we must file an application for license renewal with the fcc by february 1st 1991. when filed a copy of this application will be available for public inspection during our regular business hours it contains information concerning this station's performance since our last license grant on may 17th 1984. individuals who wish to advise the fcc of facts relating to our renewal application and to whether this station has operated in a public interest should file comments and petitions with the fcc by may 1st 1991. further information concerning the commission's broadcast license renewal process is available at the offices of wbai fm 505 8th avenue 19th floor new york new york or may be obtained from the fcc washington dc 20554 99.5 fm wbai new york this is joe king and welcome to another edition of the personal computer show tonight steve terry the research director of electronic directions or wheeler hawkins whatever they're being called this week we'll find out in a few minutes is joining hanky and myself and we're going to be talking not about word processing not about the law we're going to be talking graphics because it's a graphics time of the year so stay tuned for another edition of the personal computer show