On Saturday, April 27th, the conference will begin at 10 a.m. Special guest speaker will be Shokwe Lumumba. The event will take place at the Harriet Tubman School, 250 West 127th Street in Harlem. For tickets, journal ads, vendor space, please call 212-222-9640. This has been a public service announcement for the New African People's Organization. The conference will be held at the Harriet Tubman School, 250 West 127th Street in Harlem. This has been a public service announcement for the New African People's Organization. All right, all right, we're here. Sorry for all the delays and dead air. This is Emanuel Goldstein with Off The Hook. And we have a special program for you tonight. And as part of a clue, here's a bit of music. We'll be back in a couple of minutes. Uh-huh. What's your reaction to those people that want to prosecute you here in this country that say, well, you're invading U.S. military computers and you shouldn't be able to get away with that? What do you say to that? I think that's bullshit, because a lot of the systems I've been on either had poor security or they even had a guest account open. And as the name implies, I mean guest, the guest account is for guests. And when I consider myself guest on the system, then I don't consider myself a criminal. So I shouldn't be prosecuted. Now, these are accounts where the username was guest and the password was guest as well. Yeah, right. And that makes you a guest of the system. But you had full privileges? You could wander anywhere you wanted? Not in the beginning, no. Uh-huh. You were able to modify things so you could wander? Yeah, I worked off my privilege. But that doesn't mean that I... That's what I like to set straight, too. Some people said that we were destroying or deleting things. Well, in all the time that I've hacked, I've never destroyed or deleted data from computer systems. Uh-huh. Now, as far as the kinds of computers that you used, which would you say is the most insecure? Is there any particular kind? UNIX systems or VAX systems or what? I specialize in UNIX systems, so, yeah, they're insecure. Uh-huh. And have things gotten any tighter over the last couple of years, or is it just as wide open as it was years ago? Well, not really. I mean, they have been tighter on password security a bit. But you still have systems where the account guest-guest is open or where people log in with a username and password. Uh-huh. We've got a question for you here. Do you use the SurfNet directories, which are directories available in Holland, public directories? What do you mean with using them? Using the link, you mean? Yes. Yes? Okay, use that as a link then. Yes, I did, yeah. I see. Could you explain how that works for us over here in America? What is SurfNet? What exactly does it do? SurfNet is a university network. It's a connection between all kinds of Dutch university computers, and it gives students the opportunity to communicate with other universities all around the world. Uh-huh. Now, you're over there in Holland. You don't have any laws against hacking. Do you envision that going on for much longer? You mean that no hacking laws are set up? Right. I think so. I don't understand how the United States can prohibit hacking. You mean prohibit hacking in our country? Yeah, in your country. Well, it's done under the guise of wire fraud, of saying that you're somebody you're not when you're logging into a computer system, crossing state lines, making a federal law. Yeah, well, if I am logging in as a guest, for example, I'm identifying myself as a guest, and I'm not committing any phone fraud, and I'm certainly not making somebody believe that I'm somebody I'm not. What if you look at classified data? What's your view about that? The fact that it's wide open, does that change anything? Yeah, I think it's pretty stupid to put classified data on a computer that's hooked up to a network, a public network. Uh-huh. I mean, if it's so classified, they should keep it away from the network. Give us a sense of how much information you were privy to. What kind of things could you have seen? What kind of things did you see? Yeah, so all kinds of things. Memos from different users, sometimes corporations, private stuff. Name it. Uh-huh. And if you were a nasty hacker, if you were somebody that destroyed systems, what do you think you could have done? Well, first of all, a nasty hacker isn't a hacker for me, because somebody who destroys things isn't a hacker. But if I wanted to, I could have, for example, wiped out several army computers. I could have wiped out entire universities. I could have wiped out all kinds of experimental data on army computers. Uh-huh. You see, in this country, things have changed quite a bit. It's kind of a feeling of fear here if you access even the wrong system once that you'll be going to jail. And a lot of the hacking world has gone underground as a result. There's no real indication that it's stopped, that it's not still going on, that the systems are not as wide open as they were before. But the mood has definitely changed to one of fear rather than one of adventurism. Are you afraid of something like that happening there, and what can you do to prevent it? A bit, yeah. And I still think it's not a solution to prohibit hacking, because, as you already said, then the people will only go underground. I experienced it for myself in the beginning when I hacked a system. And a few days or a few weeks later, if I contacted the system administrator, the first few times you try to contact the system administrator to tell him how you hacked the system, what you did exactly. But since, especially in America, they're not interested how you did it or what happened to the system or if the system is secure or whatever. They're just interested in calling the FBI, a plain detective or something. So you don't see a genuine interest in actually securing the systems? No, not at all. Did you ever contact somebody and say, hey, your system is wide open and be met with a less than enthusiastic response? Yeah, in the beginning when I was hacking, I contacted a few system administrators, like, your system is not completely safe, there's a bug there and there, and I came in via their net account. Sometimes they reacted okay, but most of the times they were just only interested in trying to bust me or something. I even, with some systems, where I got a bad reaction from the system administrator, the system was still wide open a few months later. Now how widespread is this in Holland? How many people do you think are involved in this kind of thing? I'm not very sure. Like I said before, it's not a group that's doing it. There are some people which are very loosely connected. I think that in Holland maybe five or six people are doing it. Only five or six? Yeah, well, on that particular part of the Internet. I mean a little bit more in general. How many people are out there exploring the vast universe of computer systems tied to the Internet? I think a few hundred. Do you think Holland is very unique as far as being the only country that does this, or are people in Germany, England, are they doing it too? Yeah, people in Germany are doing it too, and I think there are some people in England who are also doing it. Now there's a big difference there because there are pretty strict laws in Germany and England. Am I right? Yeah, right. But I think that in those countries hacking is going more and more underground. I mean in Holland it's much more open, and for people who are interested in it it's much more easy to get information on it from both sides, from system administrators' sides, and from hackers' sides. Now if it was suddenly outlawed tomorrow in Holland, would you be able to continue doing what you're doing? Do you have enough knowledge to be able to just keep doing it underground and not be caught? Yeah, I think so. But I think it would be a very bad thing when it would be outlawed. Uh-huh. Now I've got a specific question here. It's alleged that you became a root, which is kind of a technical term for people that might not be fully into all this, at a particular academic computer. Are you at liberty to tell us which one that was? Yeah, which one do you mean? You became root at several then? Yeah. Okay. You want to name one or two? That would be fine. I'm not sure. I'm not familiar with the names of the computers. Uh-huh. Let's see. I've been root on one in Los Angeles, I think. One in Los Angeles run by the military? No, no. That was just a university. Oh, a university. All right. Yeah, well, several. I mean, not just universities, but also like NEC computers. I'm not very good at names, but... Uh-huh. Well, now, just for the benefit of our non-technical listeners, if you become root at a particular computer, what does that enable you to do? Everything. When you're root, you can do everything. You can change everything. You can see everything. You can do everything with a system that the system operator can do, too. So if you gain root access to a particular computer system, you can see every bit of data on that computer? Yes, I could. Okay. We want to open up the telephone lines to American hackers, I guess, who have specific questions for our Dutch friends here. Now, I'm not 100% certain that everybody's going to be able to hear each other, so we're going to try this out and see if it works. Our number is 212-279-3400. If you have a particular question for hackers over there in Holland, give us a call now, and we'll try to get you on. While we're waiting for that, though, is there a message that you, Bart, or any of the other hackers over there or people here in this country that are interested in hacking in general? Yeah, when you're interested in hacking in general, you should try to explore the computer systems you're interested in. I think it's a bad thing that it's illegal in the States, and I think that you should decide for yourself whether it's illegal or not. Because I think a lot of knowledge now in America is hidden because people are not allowed to use it. They're not allowed to use computer systems. And I've heard that even some people are afraid to use computer systems in a legal way because they're afraid they might get busted because people are thinking, or even if they're associated with hackers. And we've seen that happen over the last year, certainly. Now, for those of us that have never hacked, for those of us that have never actually logged into another computer system and explored, why don't you give us a step-by-step synopsis of what you would do. Now, you pick up your phone over there in Amsterdam or wherever you happen to be, and you make that phone call, and you get connected to a computer. What happens next? Well, first you try some default logins. Whenever a computer is installed at a site, there are always some default passwords in it. Okay, we're talking at the local level for you, though. Is there sort of a network that you can tie into just by calling up? Yeah, the Surfnet. Okay, so you call up the Surfnet. And are you able to subscribe to that? Is that open to everybody? It's open to everybody. You don't even have to subscribe. You just dial in, and you're in. Okay, so you dial in, and then what does it prompt you for? Destination. Okay. So you give it the destination PAP, which stands for Packet Samware Network or something. Okay. Then you're on the touch Surfnet, and you can connect to all kinds of touch computers by just typing in an address. And if you type Connect Help, you'll get a complete guide of how to use the touch Surfnet and a complete guide of the touch Surfnet addresses. So you're able to connect basically to computers all over the world through the Surfnet, and once you connect to one of those computers, you just simply pound away at it until you get in? Sometimes, yeah. A better way to do it is gain access to one computer first, a touch computer, for instance, then enter the Internet, and use the Internet to get onto other computers. And the Internet opens the door to a vast array, I would imagine. Pardon? The Internet opens the door to a lot more computers. Yes, it does. Okay, one more question before we go to the phone calls here. What would you consider to be your biggest triumph as far as hacking into a system? Was there something that you were trying to do and it was thought to be impossible, but you did it anyway? I think the biggest triumph would be hacking myself into the computer, which I wasn't even an expert on. That was AVAX of the local telecom. Uh-huh. And what would that enable you to do is logging into that particular system? Can you say that again, please? What would that enable you to do, being able to get into that system? Not very much. I could look at the data files of the Dutch telecom. There wasn't very much interesting stuff on it, but I was very happy to get in anyway because telecom computers are generally better protected than the other computers. But not entirely protected. Let me ask one more question, then we'll go to the phones. Have you found any particular system or group of systems that you find to be well protected? Yeah. Some of the military computers are relatively good protected. Some of the... Mostly computers that have been hacked a lot. Most of them are better protected than the average system. But some of those systems will never learn because they get hacked over and over again. And I don't know, they just keep themselves open. Let us know one of the ones that keeps getting hacked over and over again. Who are some of the people that never learn? Well, most of them are universities. Some of them are military. I don't know if they're strictly military, but they're the military type of computers. Okay. We're speaking with Bart, who is a Dutch hacker over in Holland. And he's one of the folks behind the front page story in the New York Times on Sunday concerning Dutch hackers getting into American computer systems, both academic and military. And it's something that is likely to continue for quite some time and perhaps get even more widespread as computer holes are opened even wider. We have phone lines open, 212-279-3400. I'm asking people who call in to please limit your discussion to particular questions that you would like to ask Bart and any other particular topics that you have on your mind, we'll just get to on another program, okay? Okay. 212-279-3400. And let's see if we can all hear each other. Go ahead. You're on the air. Warren, did you define root? You said that a lot of people would not know what it meant and you were right. And the second thing is, where does the term hacker come from? What's the origin of it? Well, that's an interesting question because right now the term hacker is being debated left and right. There's a bunch of people in the computer industry that are trying to create a new word called cracker for the people that break into computer systems. And I don't really know anybody that calls themselves a cracker. Hacking is basically something where you keep trying to get into something. It doesn't even have to be a computer. It could be anything technological. It doesn't even have to be technological, though. It just has to indicate persistence on your part, refusal to take no for an answer, and willingness to learn. That's my definition of hacking. There's a lot of definitions floating around. With regard to your first question regarding root, I'd like to pass that on to Bart, and maybe you could explain it better than I could. You want to know what root is? Yeah, and we'll go on to the next call. Root is the highest level you can get on a computer system. Basically, it's got all the privileges you can get, and it even overrules some of the privileges people put on their files or whatever. If they don't allow anybody to see it, then still root can see everything. Now, root is a term for Unix systems, but every computer system has the equivalent of root? Yeah. Okay. Now, it's supposed to be the most secure of all the accounts there. Yeah. Have you found that to be so? Well, mostly it's a lot more secure than the other accounts, but it can still be hacked. How is it more secure? Longer passwords? Yeah, yeah. Mostly, root has got a better password, and its file protections are better. Normal people don't really have very good file protections. But once you gain access to root, you're at the top of the mountain, right? Yeah, right. Okay, let's go to another call. Good evening. Good evening. Hmm, there seems to be something wrong with this phone line over here. I'm hearing all kinds of weird flashing sounds, but I'll go to another call. Good evening. Oh, hello. Were you able to uncover any information that's of political or, you know, great political or social or international significance? Or, you know, is it just a lot of details about this little project here, you know, that little thing there? Is it really worth a while to go digging into those systems of the government and military? Most of the times when I get into a system, I'm not very interested on the stuff they store on there. I just like the system. I don't think that even if there were files with very interesting political or weapons data or whatever, I don't think I would be able to spot them. I'm not going on a system just to spend 12 or 15 hours to browse through all the files and look if there's interesting information in it. I just go on it to look at the system, see if it has connections to other systems, and then I'll move on. That's something that a lot of hackers try to get people to understand. They're not in it for a particular cause. They're not in it to destroy the world or to save the world. They're in it out of curiosity, period. And I know the feeling, you know, when you're after something and you think you're only one step away and you just keep at it all night long until you figure it all out. It's a tremendous feeling. And I think if hackers as a rule were evil people, we would certainly see some horrible things happening by now. I would say, let's take what the people here are saying as a warning, a warning that these systems are incredibly easy to get into, and if somebody evil does get into them, we could all be in a lot of trouble. Does that make sense to you? To me? Yeah. Yeah, yeah, certainly. I mean, you can make a UNIX system as secure as you want it yourself, but people don't really care about that. That's a sad fact. Okay, we are having some technical difficulties with the telephone here, so this is how we're going to fix it, folks. I'm going to pick up a call here, all right? And if you are not the person that I pick up the call for, I want everybody to hang up and dial a different number because we seem to be having trouble with the first line. So instead of dialing 279-3400, hang up and dial 279-3401, and that way you'll skip over that bad line, which apparently we're having trouble with. That's only if you're not the person that we pick up on next. Okay, so give us a call, 279-3401. Speak to the Dutch hackers who are causing quite a bit of consternation all over the place, I'm sure. Good evening. Hello? Yes, go ahead. Hi. I wanted to ask your guest, what's the difference between what he does, which I understand he does in goodwill and to satisfy intellectual curiosity, and, for example, someone who, out of just curiosity, wanted to see if they could get by the security system of a bank, you know, of a physical building. You know, just wanted to see if they could break in and then broke in, but didn't take anything and then just left. I mean, I don't understand what the difference is. Okay, we're going to get into analogies, so let's ask our Dutch friend what analogies he goes by. Thanks for calling. I think it's pretty stupid to compare breaking into a bank with breaking into a computer system. I mean, you're talking about breaking into a computer system, but it's very different than breaking into a bank. I mean, in Holland, breaking into a bank is a crime, and breaking into a computer system is not. Furthermore, I think it's relatively, it's not good to compare a computer with a bank. I mean, a computer can be used by anybody. I think a bank, I don't think you can compare that to a computer system. And computers have all kinds of information that people really don't know, that they have no idea what that information is. Have you found things about personal files, that kind of thing, when you were wandering around our computer systems? Yeah, I sometimes find personal files or memos or whatever. But you see, the fact is that I'm just not interested in it. I'm interested in the system, and I'm not going all over, looking all over the system for files where somebody's writing love letters to somebody else or something. I'm not interested in that. It's interesting, though, because that's always the analogy that's brought up. It's always, well, if somebody broke into your house, you'd feel violated. But that's what you're not interested in. You're not interested in people's personal lives, but what you're finding are personal items about people in these huge mainframe computers. Is that correct? Yeah, that's right. And I think, furthermore, it's very dangerous to compare breaking into a computer with breaking into a house or breaking into a bank, because that's the same thing as when you're looking at somebody else's files, to compare it with peeking through somebody's window when he's taking a shower or something. Yeah, I think it's pretty stupid. Sorry. Let me ask you one question, then we'll go on to another call. Why did you go to the press? Why did you go to the media? I didn't go to the press. The press came to me. Well, why is that? How did they know? They found out via a friend of a friend of a friend of a friend. Are you happy with the fact that they found out? Well, not happy, but also not sad. They asked me if they could film something, and I agreed. And what kind of response do you get from non-hackers who know what you're up to? Generally, most of them don't quite understand what I did, but they do seem to like it. I think that the Dutch people in general are different than the Americans. The Dutch are interested. They want to know how I did it and if it's difficult and what kind of users you got for it. I think that as far as I've heard from the Americans, they're more interested in how much of a crime it is or something. Well, Dutch culture, correct me if I'm wrong here, but Dutch culture is pretty much geared for individuals, an anti-authority kind of value system. Is that correct? Yeah, you can say that. I'm not saying that every Dutchman is like that. Well, certainly a lot more than here in this country. I think so, yeah. Okay, let's go to another call. Good evening. Good evening. I've been a programmer analyst for about eight years. I've got to disagree with this man completely. It is the same thing. It is like breaking into somebody's house. If you don't have permission to go there, you can't go there. If you come into my house just to see if you can figure out a way to get through the locks and you're not interested in my stuff but you find out where my diary is and you don't look at it, I don't feel good. You can't do that. I don't think the comparison is for real. I think it is for real. Okay, let's hear what he has to say. Well, I mean, if somebody's going into my house, I would be very scared, too. But if I had a computer and somebody else was wandering around in that, I wouldn't really mind at all. Except when he starts to go deleting files and stuff. And furthermore, I mean, just like I just said, you can't compare a computer to a house. I agree with you. No, I think you can. Well, what if I go into your house and I don't delete your diary? In other words, I don't burn it. Is that okay? Oh, there you go again. You compare a computer to a house, and I think that's a bad comparison. The reason my house is important is because it's mine. I value it. Computer yours? Is the computer mine? Yeah. The house I live in isn't mine. I rent. But you're still not allowed to break into it. Okay, so... Maybe we should move this analogy to office analogy, since we're dealing with mostly businesses and corporations and things like that. Would you feel as violated if somebody broke into a particular part of your office building that wasn't necessarily yours? Would I feel as violated? Yes. No. Okay. Now, I think that might be a closer analogy, because what we're talking about are these huge computer systems where there are hundreds of users and not a personal computer in your house somewhere. I mean, if somebody calls up your personal computer and breaks into that, that's closer to that analogy, I think. That would not make it any less wrong, just because I didn't feel as abused or violated. It would still be unethical and immoral. Well, now, what do you say... Because if someone breaks into another apartment in my complex, I might not feel as violated if he went into my complex, but that person still feels violated, or I would imagine would, and it would still be unethical and immoral. Now, what do you say our Dutch friend here says that he was able to get in using guest accounts? I'm unfamiliar with the meaningfulness of that. Okay. Thanks for calling. Okay. Thanks. Let's go to another call. Good evening. Yes. This is John from Woodside. I'd like to know, with Bart, I access various international conference boards of Fidonet and RelayNet, and I would like to know, Bart, which ones you get on and what name do you use so I could leave messages to you from here? Well, you don't have to give out that info if you don't want it, Bart. I don't know if you're comfortable with... I mean, do you use a fake name or something that... If you want to leave messages or something, you can always leave messages to Eric. I will contact him sooner or later so we can forward them. Is there any particular Relay or Fidonet that you get on? I know there's one that I've been getting on locally for shortwave listeners, and it goes all across the globe. Well, I believe if you just wander around enough and speak about hacking, I think you'll run into somebody from Holland, possibly this very caller here, without much of a problem. Thanks for calling. We have time for one more phone call. Good evening. Yes, I'd like to ask Bart how old he is and what the average age of those hackers are. Okay, good question. Bart? Well, I'm 24, and I think that... I'm not sure. I haven't met very much hackers person to person, but what I've heard about the average hacker age in Holland is about 21, 22. Uh-huh. We find here in the United States, at the 2600 meetings, for instance, we get people from all different ages, people up into their 60s and 70s even, and people below 10. So the interest, and I'm sure if you go through our listening audience right now, you'll find all kinds of deviations from that. Yeah. There's a lot of interest in this, and it's something that is not as hard to get into as people seem to think it is. It's not... And that's why it's such a shock, really, because it's so frightfully easy to get into these computer systems and to find out all these bits of information that really should be kept secret. I mean, do you believe that the information you see really shouldn't be as open as it is? Can you say that again? I didn't quite get it. Well, the information that you are able to see, do you believe that it should be as wide open as it is, or do you believe people should be trying to protect it? Yeah. Well, I think that if something is really not for the public to see, then they should at first protect it better. Uh-huh. And on the other hand, there's a lot of information that should be made public that is being kept secret, and that's a whole other thing about what's being stored inside computers. We are out of time. The Personal Computer Show is on next. I want to thank Bart from Holland for getting in touch with us, and hopefully you'll stay safe over there and won't cause World War III or anything like that. Again, are there any... well, you have a magazine over there called Hacktic. Do you want to give the address for that? The address for Hacktic? Yes. People are interested in that. Yeah, okay. Just hold on one second. Okay. While you're getting that, I can remind the folks that we'll be having another 2600 meeting, 5 p.m. a week from this Friday at the City Corps Center in the lobby area. That's for American hackers only, please. And there'll be... oh, who knows what we'll be doing. We'll be passing out information, giving codes, whatever. Whatever you desire us to do, we'll probably do somehow. Okay, you got the address? Yeah. Go ahead. PO 22953. Zip code? 22953, and that's in Amsterdam. And the zip code is what? Zip code is 1100DL. 1100DL. It's David Lawrence. Okay. Thanks very much, Bart, for being a guest here on Off The Hook. We're not going to be here in two weeks. We're not going to be here in four weeks. We will be here in six weeks. Don't ask me why. That's just the way things work here. And there'll also be a six-hour special. We're not quite sure what the subject is going to be. That's on May 22nd from 12 midnight to 6 a.m. Emanuel Goldstein for Off The Hook. Good night. Off The Hook