We at WBAI will present a 24-hour tribute to Tito Puente beginning at 5 p.m. Saturday February 8th and ending at 5 30 p.m. Sunday February 9th. We'll offer 24 hours of music including some very rare recordings, interviews with yesterday's legends and today's stars, as well as some very interesting surprises. So don't forget this very special 24-hour tribute to Tito Puente beginning February 8th at 5 p.m. Come celebrate the king and enjoy on listener-sponsored WBAI 99.5 FM. And this is WBAI in New York. The time now is nine o'clock and that means it's time for Off The Hook. And a good evening to one and all. This is Emmanuel Goldstein. The program is Off The Hook. We're on the air until 10 o'clock and tonight we're going to be discussing something that might be a cause for concern, perhaps even pessimism. And that is the possible end of Paradise. Yeah, that would be a cause for concern, wouldn't it? Stay with us. We'll give you all the details. We'll be taking phone calls and having all kinds of fun. Well, this is the first edition of Off The Hook in quite some time actually, in about three weeks or so. I've been away, I've been overseas in the wonderful small country of Holland, also known as the Netherlands, where things just are not as they are here. And it's kind of hard to explain that to someone who has never actually experienced it for themselves. So I'll try my best, but if you don't quite feel the spirit, I think the only solution is for you to go over there and experience it for yourself. Now, you realize that things are kind of messed up in the United States. Well, you can realize that by listening to WBAI. You can realize that if you're really smart by reading the newspapers and occasionally a strange magazine or two. But it really becomes emphasized when you see how other cultures handle things. You realize how materialistic we are here, how we're so into the military, how we're so into laws and obeying things and writing everything down and having kind of a strict order to things. It's most fascinating when you hold up another culture to our culture. It's not all bad, but there's a lot of bad and a lot that we don't see. Now, I think the country of Holland in particular is rather magical because they have such a contempt for authority. And I mean contempt not in a particularly nasty way, but just kind of a way where authority says one thing and people just naturally do something else. Kind of the individualistic spirit. For instance, mass transit in Amsterdam. People are supposed to pay when they get on, but they don't always pay when they get on. In fact, most times they don't pay at all. Most people don't pay because the system is such where you pay if you want to, but if you don't want to, you can easily get away with it. And so there's this kind of alliance between all the people that have not paid. They're watching for the ticket inspectors, the people that occasionally get on trains and check people's tickets. They don't get on very often. And when they do get on, it's quite obvious. A gang of six uniformed people getting on a train at once is usually a good clue that someone is going to ask for your ticket. So the first person that sees a ticket inspector coming alerts the others who he's never met before. And I was involved in one such instance. I won't say whether or not I paid or not. I don't think that's relevant. A bunch of ticket inspectors got on the train, and I would say about two-thirds of the train got off. That's just the way things are. Here in this country, we worry a lot about the law, about whether something is legal, without really thinking, is it all that important? Whether it's riding the subway or hacking into a computer. It's the bigger picture which has to be looked at, the intent. What is it that you are really after? And the way things have been in Holland, at least up until this point, is that if somebody enters a computer system that doesn't belong to them, that doesn't belong to them, what people really look at is what they do. Do they do destructive things? Do they make a profit somehow? And if the answer to these questions is no, well then, what's the problem? Can these intrusions perhaps be solved by simply strengthening security? And the average person in Holland would agree that prosecuting computer hackers is detrimental to that individual spirit. The same individual spirit that is constantly eluding authority. Now, why do the Dutch have this contempt for authority? Well, I think Nazi invasion would have something to do with it. I think the invasions over the centuries would have quite a bit to do with it. And there are many, many instances that you can look at. But you don't see that here. You don't see contempt for authority because we are the authority. And there's no reason to be suspicious of us unless you're suspicious yourself. Well, enough with the mysticism here. Let's see what's been going on. We're looking now at an internet news group called alt.security where they discuss security issues, they discuss hackers, and in fact they're rather crazy about this. They will not say the word hacker unless they're referring to a programmer. They will insist upon calling people that we call hackers crackers. And we can talk about that for hours. But what it really boils down to is that they want to save the nobility of the word hacker for themselves and create an artificial term known as cracker for all the rest. Well, it doesn't fly in this camp, but we'll read it as they have it written. And when I come across the word cracker, you might notice a kind of sarcasm in my voice. That's just the way it is. Anyway, according to Dutch TV and newspaper reports, the Amsterdam police have arrested two computer crackers and seized their equipment. A press conference was held on Friday the 31st. The two made a full confession. I was in Amsterdam when this happened, although not one word of this was known to anybody until the 31st, last Friday. So they did a pretty good job keeping a secret of this. This is the first time that computer hackers, or crackers as they may say, have been apprehended over there. Now the reports state that over the past four months, someone known only as R.J.M., age 25, a computing science engineer, and H.W., age 21, a computer science student, installed so-called Trojan horses on a computer system of the Amsterdam Free University and used that same system to break into computer systems in the U.S., Canada, and several European countries who wish to remain anonymous. According to a Dutch police spokesman, the two had no intentions of damaging or stealing information, but were doing it just for kicks. Dutch law on computer crime is still in preparation. Apparently the charges are based on existing law, falsification, corrupting systems files in order to get privileges, destruction of property, rendering a computer system unusable, and fraud using stolen passwords. So whether or not they need additional laws to prosecute these people is, I guess, one of the things that will be found out real soon. Now the university is claiming $50,000 in damages. According to one contributor on the Alt.Security system, known as Roger Wolff, he's from the Netherlands, when I read this, or when I read this actually, I thought, well, these hackers must have been very aggressive. However, when I read on, it seemed that they were naming these costs as the cost to check that all systems that were cracked are clear from trap doors. I don't think they can make this stick in court. Just ask the hackers, who seem to be very cooperative. They confessed, after all. If a university makes the decision to keep user partitions world-mountable, they cannot reasonably be expected to spend $50,000 to check for trap doors. I hope for the hackers' sake that they go free from having to pay the damages. And now we get into a rather interesting response to this from a gentleman known as Mark Crispin, who comes from the United States, who responds to Roger Wolff's statement, I hope for the hackers' sake that they go free from having to pay the damages. He says, I hope for the sake of the rest of us that the crackers, not hackers, please, get the book thrown at them. Significant fines and preferably jail time. An example has to be made. Maybe if a couple of these children end up getting sodomized by AIDS-infected convicts, they'll get the idea. It'll help reduce the excess population and get rid of faulty genes that lead to such behavior, too. The day when computers were few and far between and unique resources were found only in one place are history, thank goodness. There is no necessity to go visiting other systems these days to get computer cycles. There is no longer any moral justification to visit a system that has not expressly extended a welcome. I'm sorry, leaving the door unlocked is not enough. Believe it or not, system managers and system owners have other things to do than play security god. It seems to me that the security gods and the crackers need each other to justify their own existence. The problem is with the crackers themselves and the presumption that when a computer is broken into, it is the victim who is to blame or the owner of the means used by the criminal to break in who is to blame. Blame is being assessed everywhere except where it belongs, on the crackers. Needless to say, this has generated quite a response, particularly the AIDS remark. In fact, since Mr. Crispin leaves his phone number as part of his public posting, I see no problem posting it here. He's in Washington, the state of Washington, area code 206-842-2385 or 543-5762, perhaps. Some of you might wish to discuss these issues with him, and if not in person, try his fax machine, 206-543-3909. This is all public, as it was posted on alt.security, and his suggestion that a couple of these children end up getting sodomized by AIDS-infected convicts, it will, in fact, accomplish something. Well, some of the response to that from the Netherlands, from Guido Van Rouge. Anyone stating this sort of thing is nothing better than a criminal. I don't hope you'll get AIDS, but you are really disgusting. And this contributor from France says, while we're at it, let's push for summary execution at the roadside for illegal parking, speeding, and making funny faces at the nice officer. If your machine slash network is so sick that you can't protect resources with minimum effort, then it is not fit to be used for the purposes for which you are using it. It's as simple as that. Too many people use computers for unsuitable uses. Fix the machines and networks and the problem will go away. And Lance Brown of the United States says, I wholeheartedly feel that computer systems should be secure, but making them secure is not going to cause the cracking problems to disappear. That is an unrealistic expectation. Until all people learn to respect the rights of others, we're going to have crackers, and we need a means of defending against them. The legal system is that means. If we do not punish crackers, then there is no incentive for the crackers to stop. God, I hate that word. I hate that word. Unless you have a means of making an Internet Unix site totally secure, we are going to have to use the law to help defend our systems, and presumably lock people away in various federal institutions. And another response to the aide's remark. My apologies to Mr. Crispin, but I guess the point of this message was something along the lines of I don't have a clue as to the relevancy of the original message. To speak of blame and morality and ethics in the same sentence as computer is to do a great damage to the machine, the machine that really doesn't give a damn about blame or morality or ethics, which is the appeal, the allure. If this were truly a debate about morality, wouldn't we first have to question why it is that these wonderful beastie machines now are programmed to launch bombs, destroy cities, kill people, violating Asimov's laws. This should be the first major concern to anyone interested in the morality behind computers. Some lowly hacker isn't really a very dangerous threat to global existence, except in the mind of movie script writers. Also, if you must force the issue of hackers slash crackers and ethics, I would tend to think that to keep a hacker, or for that matter anyone interested in learning about computers, to keep a hacker out of your system would be just as unethical as keeping the homeless out of your home. Interesting analogy. Besides, as it can be shown in the original posting, Mr. Crispin isn't a very moral or ethical guy. If he truly believes that aides should infect the unworthy, then he can't be a very happy person inside. If he really believes this, then he's got a lot of emotional problems, and he really needs the helping hand of someone close in order to get rid of this self-hatred. If you are a friend of Mr. Crispin and are reading this, please give him some extra love and affection during this, which surely must be a trying time for him. I extend that to anybody who might be calling him right now after listening to this. The comments go on and on. There's almost an amazing response to all of this. Mr. Crispin also posted something in addition. This is kind of the hacker versus cracker fight, which has been going on now for quite some time. The old lecture. I was a hacker back when you were still wetting your diapers. You have a distorted notion of what it was all about then. Among other things, we worked our asses off to make things better and more useful for the users who paid for the computers. It was one of the reasons why they were happy to give us free computer time and at times even pay us for what we did. We did not go looking for ways to annoy our hosts, and we were careful not to tread where we weren't wanted. The world has changed since then. Computers are no longer counted in the dozens, they are now counted in the millions. Only a handful of individuals are writing useful freeware anymore. We've gone from the days when students would beg us to be allowed to work on a project for free just to get computer time to the days when relatively high-paying work-study programming jobs go begging due to lack of interest and talent. What's more, hacking was a meritocracy. It wasn't how much of an annoyance you could make of yourself, but rather a can-you-top-this of producing useful software. 99.9% of today's crackers can't write a program to save their lives. Whatever gave you the fantastic notion that it is incumbent upon anyone to allow Jay Random Hacker to use his computer or to allow Jay Random Homeless into his house? Some leftist professor at the University of Florida? Or maybe it was the funny high school social studies teacher? If so, there is hope you may grow out of that idealistic, socialistic crap-trap. Until then, why don't you give away all of your property to the homeless? Why don't you tell your mommy and daddy to let some homeless person use your room in their house and all your possessions? Furthermore, since you seem to think that there is no right to private property, why stop there? Why not go all the way to the brave new world, as described by Huxley, where everyone belongs to everyone else? Is that right? Don't you agree that anyone who wants your sister should have her, that her feelings don't count? After all, when it comes down to it, one's own body is merely a form of property. One more thing. Just how is the ability to access a privately owned computer in another state or country that is a carbon copy of tens of thousands of other machines of the slightest educational use to someone interested in learning about computers? For crying out loud, you can easily buy your very own without causing trouble to some other human being. You hear all you people out there? You can easily buy your own computers. Bet you didn't know that. Even if you don't want to buy one, there are so many computer systems that will give free accounts. There is no need to go where you are not wanted. I submit that the only time a cracker learns a damn thing from having broken into a computer system is when he gets busted and goes to jail. Those are the thoughts of Mark Crispin, speaking to us from another century. And we're not going to give out his phone number again because AT&T doesn't like it when the lines get clogged. But we will give out our phone number, which is area code 212-279-3400. We're ready to take your phone calls on this issue. Is paradise over? Is Holland going to fall and become more restrictive in their rules and regulations and other things like that? And is that a good thing? Is the existence of Holland, as it is now, a good thing? Well, we're going to go to the phones. 279-3400, area code 212. Let's first hear a news story, which comes from the Dutch magazine Haktik, on the events of the past few days. At 10.30 in the morning of Monday, January 27, 1992, Dutch police searched the homes of two hackers in the city of Roermond. The parental home of the 21-year-old student, known only as H.W., was searched. And in Nuenen, the same happened to the parental home of R.N., a computer science engineer, age 25. Both were arrested and taken into custody. At both sites, members of the Amsterdam police pilot team for computer crime were present, alongside local police officers and representatives of the national organization CRI, Criminal Investigations Agency. It doesn't spell CRI because it's done in another language, so don't be confused. Both suspects were transported to Amsterdam. The brother of one of the suspects was told the suspects could receive no visits or mail. All of this happened more than a week ago. The two are still in jail as we write this. Actually, I was in touch with some people over there, and they were released today. So they were in jail for more than a week. Now, what were the charges? A break-in supposedly occurred at the bronto.go.vu.nl site at the VU University in Amsterdam. This Unix system running on a sun station, their Internet address 130.37.64.3, has been taken off the net, at least for the duration of the investigation. I tried it earlier today, and it was not available, not around at all. The plug has been pulled. What happened to the actual hardware is unknown at this time. The formal charges are forgery, racketeering, and vandalism. The police justify the forgery part by claiming that files on the system have been changed. The vandalism charge is valid because the system had to be taken off the net for a period of time to investigate the extent of the damage. Now, by pretending to be regular users or even system management, the hackers committed racketeering, the police say. Both suspects, according to the Dutch police, have made a full statement. According to a police spokesman, the motive was fanatical hobbyism. Spokesperson Slort, for the CRI, speaks of the kick of seeing how far you can get, perhaps similar to that challenge that Mr. Crispin says no longer exists, the challenge of trying to top this. On the issue of damages, according to J. Renkema, head of the geophysics faculty at the VU, the university is considering filing a civil lawsuit against the suspects. The system was contaminated because of their doing and had to be cleaned out. This costs months of labor and 50,000 guilders, which is about 30,000 US dollars. Registered users pay for access to the system and these hackers did not. Result? Tens of thousands of guilders in damages. Renkema also speaks of a moral disadvantage. The university lost trust from other sites on the network. Renkema claims the university runs the risk of being expelled from some networks. He also claims the hackers were discovered almost immediately after the break-in and were monitored at all times. This means all the damages had occurred under the watchful eyes of the supervisors. All this time, no action was taken to kick the hackers off the system. According to Renkema, all systems at the VU were protected according to guidelines as laid down by CERT and Surfnet BV. Surfnet is the company running most of the inter-university data traffic in Holland. Now, what really happened? The charge of adapting system software could mean that the hackers installed backdoors to secure access to the system or to the root level, even if passwords were changed. New versions of Telnet, FTP, rLogin and other programs could have been compiled to log access to the networks. What really happened is anybody's guess. One point is that even the CRI acknowledges that there were no bad intentions on the part of the hackers. They were there to look around and play with the networks. In the past, we have warned that new laws against computer crime can only be used against hackers which are harmless. Against the real computer criminals, a law is useless because they will probably remain untraceable. The CRI regularly goes on the record to say that hackers are not the top priority in computer crime investigation. It seems, though, that hackers are an easy target when something has to be done. And something had to be done. The pressure from especially the United States to do something about the hacking problem was so huge that it would have been almost humiliating for the Dutch not to respond. It seems as if the arrests are mainly meant to ease the American fear of the overseas hacker paradise. The VU has launched the idea that system security on their system was only needed because of these two hackers. All costs made in relation to system security are billed to the two people that just happened to get in. For people that like to see hacking in terms of analogies, well, it's like walking into a building full of students, fooling around, and then getting the bill for the new alarm system that they had to install just for you. System security is not... I'm sorry, system security is a normal part of the daily task of every system administrator. Not just because the system has to be protected from break-ins from the outside, but also because the users themselves need to be protected from each other. The Bronto management has neglected some of their duties, and now they still have to secure their system. This is not damage is done, it's work long overdue. It sounds extremely familiar to us here in the United States because they try to pull this on just about every hacker prosecution that has taken place here. They try to make it seem as if no security was necessary until the hacker came along and figured out a way around it. Therefore, any security costs are part of a penalty. We saw that in Atlanta most recently, where three hackers were sent to prison for logging into a system that didn't even have a password, and then they were billed something on the order of $250,000 for security that had to be installed. If, continuing with the article, if restoring backups cost tens of thousands of guilders, something is terribly wrong at the VU. Every system manager that uses a legal copy of the operating system has a distribution version within easy reach. Months of tedious labor following the hackers around in the system. It would have been much easier and cheaper to deny the hackers access to the system directly after they had been discovered. Moral damages by break-ins in other systems would have been small. The VU chose to call the police and trace the hackers. The cost of such an operation cannot be billed to the hackers. Using forgery and racketeering makes one wonder if the OVJ, which is the district attorney in Holland, can come up with a better motive than they did it for kicks. If there is no monetary or material gain involved, it is questionable at best if these allegations will stand up in court. As far as the vandalism goes, there have been numerous cases of system management overreacting in a case like this. A well-trained system manager can protect a system without making it inaccessible to normal users. Again, the hackers have to pay for the apparent incompetence of system management. This does not mean that having hackers on your system cannot be a pain. The Internet is a public network, and if you cannot protect the system, you should not be on it. This is not just our statement, it is the written policy of many networking organizations. And one more metaphor. It's like installing a new phone switch that allows direct dial to all employees. It's not to be overly loose-lipped to strangers. It's not the caller's fault if some people can be hacked. If you tie a cord to the lock and hang it out the mail slot, people will pull it. If these people do damages, you should prosecute them, but not for the cost of walking after them and doing your security right. Now, if these suspects are convicted, the VU makes a good chance of winning the civil case. Furthermore, this case is of interest to all other hackers in Holland. In fact, it's of interest to a great many hackers around the world. Their hobby is suddenly a crime, and many hackers will cease to hack. Others will go underground, which is not beneficial to the positive interaction between hackers and system management, or the relative openness in the Dutch computer security world. If you're not a student at some big university, or work for a large corporation, there is no real way for you to get on the Internet. As long as there is no way for some people to connect to the Net, there will be people that hack their way in. Whether this is good or bad is beside the point. If there is no freedom to explore, some hackers will become the criminals that government wants them to be. That's from a couple of Hacktic writers over in Holland on the developing situation involving the first computer prosecution, I guess, prosecution of a computer hacker in Holland, and we're following that situation very closely here in the United States. Now we'd like to hear from you. The phone number is 212-279-3400. The program is off the hook. We'll be on the air until 10 o'clock tonight, talking about what's going on overseas. Perhaps the situation in Holland is an unhealthy one, where people are kind of encouraged to question authority. 212-279-3400. Good evening. Go ahead, you're on. Oh, thanks a lot. I've been listening to your stories now for a little while, and while I'm really not too enthralled with that character out in Washington and the way he puts things, as a system manager myself, I do wonder whether you're actually condoning the practice of hacking into a computer system. Well, it depends what your definition of hacking into a computer system is. If it involves any kind of destruction or erasing of things or altering things, no, I do not condone that. But if somebody who otherwise would have absolutely no access to the networks is using a weakness in your system as kind of a springboard to explore the whole Internet or your particular type of computer system, while technically in the American sense that might be illegal and subject to all kinds of fines and prison terms, I don't see the harm, I see benefit in that. Yeah. To a certain extent, I certainly... Gosh, it's really gotten a little out of hand as to what the authorities are doing to crack down on these people. I certainly don't believe that the punishment is everyday meeting the crime. However, the point is that I do have legitimate users who do need to use the system and to steal cycles, and people who are actually paying for them is something that I do have a problem with. Well, is that kind of thing going on in your system? No, it's not, and not to my knowledge, and I don't expect it will. And of course, you take precautions about things, and you set your system up properly, I think, as you've pointed out, that that's very important. You see, in the vast majority of cases that I've studied, the accounts that are being used are accounts that otherwise would be unused, and people are very rarely locked out of their own systems. So if you have adequate security on your computer system, you really don't have much to worry about. No, I agree with you. It's just this concept of people... I certainly don't want to condone the practice of people using facilities that they're really not paying for. If you can lock them out, fine, but you do have people that are paying for it, and they're the ones who should have priority to it. Yeah, I don't think anybody's going to argue that point. I think what we're talking about, basically, is what do you do when you find out who is using your system without authorized access? Do you lock them out, or do you lock them up? I think that's what we're talking about here. Thank you very much. All right, thanks for calling. 212-279-3400. Hey, what's going on here? We have open lines? That's never happened before. Good evening. Hello, good evening. I wanted to know if you could talk about the young man who was going to Cornell, whose father is, I guess, a computer engineer for NASA, but who was put in jail or fined very heavily for hacking into a telecommunications system. First of all, you're on a cordless phone, are you not? Beg your pardon? You're on a cordless phone, right? Yes, I do. Are you aware that people can be listening in on your conversations? I am aware, because it's on an FM frequency. Okay, well, right now you're on 99.5 FM, but that's something else. Okay. So you're probably referring to Robert Morris, right? That's correct. Yeah, now he didn't invade any telephone system or anything like that, nor did he wind up in jail. He propagated what was known as the Internet Worm, which caused quite a bit of well, I don't know if damage is the right word, but certainly a slowdown and a lot of confusion and, yes, a bit of expense because people had to figure out how to get around it. However, this was not, again, done out of maliciousness. This was done out of not being able to program correctly, and something went wrong in the program that he was using to explore the Internet in some way. Apparently he solved a bug that he had in his program, but by the time he got to the system to debug the system, it was too late or something. Basically, once it was unleashed, there was nothing he could do. That's correct. He was really punished because his father had such a high level of clearance and they were expecting him to follow in his father's footsteps, and therefore, since he dared to invade a system or did put a worm into a system, they felt that they should use him as an example. Of course, we know that Robert Morris Sr.'s position, long-standing relationship with the NSA and other high-ranking agencies had nothing to do with the fact that Robert Morris was not sent to prison. We know that. However, it is interesting that in this particular case, while he was subjected to a trial, which he probably shouldn't have been subjected to, a lot of people understood that there was no malice intended. Why not in all these other cases where it's quite obvious that there's no malice intended? Is it not assumed? He was not sent to jail. How did he pay a fine? He had to pay a fine. I'm not sure exactly how much it was, but I don't think it was that... I know they wanted to charge him for all the fees that the company incurred for taking the worm out of the system and debugging the system, and I don't know if that was the case. Well, again, the bug that allowed this worm to propagate was well-known to a lot of system administrators, and nothing had been done about it. So, I find it hard to believe that you could actually blame somebody for taking advantage of something that was so well-known. It should have been fixed from the start. I think if you have adequate system security, you won't have these problems. You'll always have people exploring computer systems, and if you don't like that aspect, then you shouldn't run a computer system, because you're going to get people exploring it. I mean, I've got people exploring my answering machine, because that's sort of like a, you know... Yeah, it's on a frequency, and they'll explore it. People are going to do things like that. If you don't like it, you've got to change something, either change your line of work or change the kind of machine that you have so that nobody can call into it. Right. It should be looked upon as human nature, and not as a crime. When you start looking at it as a crime, it turns into a crime, and people start acting like criminals. I think you guys are doing a wonderful job, and you should continue looking into these cases. It's very important, especially in a field where young people are getting into it heavily, and they have to experiment. I mean, you know, from day one, they're giving a Nintendo game or some kind of game where they have to beat the system, or try to beat the system, you know. So, for them to be punished because of somebody else's faulty or negligence is so depressing. Yeah, and I think you'll find that the people that want to send these folks to jail are the ones that really have something to hide. Yeah. Alright, thank you. Thanks for calling. 279-3400. Good evening, you're on the air. Hello? Yeah, go ahead. Okay, let me just turn you down. Well, don't turn me down, turn... Yeah, I know what you mean. We're down, we're down. I want to send you an article. Where do I mail it to? Ah, for the magazine. Ah, well, you can make that decision. Okay. Well, you can send it directly to the magazine's editorial department, which is 2600... Well, will you get it, will you read it yourself? If you address it to my attention, I will read it myself, yes. M-A-N-U-L... M-A-N-U-E-L in the Goldstein. Right, you got it. That's, ah, you can mail it to 2600, P.O. Box 99, Middle Island, New York, 11953. Middle Island is two words. 11953? Right. And if other people have things to mail in, they can mail it here to the radio station as well, off the hook, care of WBAI, 505 8th Avenue, New York, New York, 10018. Another question. Yeah. I missed the show that you were... When people are talking on cordless phones, they can basically be listened into across the country, right? Ah, well, it depends. I'm not quite sure how you mean that. Across the country, you can listen in, but somebody in San Francisco can't listen to your cordless conversation here in New York. That's not that powerful. Because I thought I once saw something in the, ah, Wall Street Journal where it was talking about some guy in, ah, gosh, maybe in the West who was listening in on conversations in the East. Well, if something is done, say, on a satellite, of course you can do that. And lots of our phone calls do use satellites and they're not scrambled or anything like that. So, yeah, that is, that is certainly possible. But barring some kind of, ah, some kind of radio skip of some sort, there's no way you can, ah, you can listen to a, a cordless conversation for any great distance. Is there a typical, ah, scenario that involves satellite transmission? I'm sorry? Is there a typical transmission that usually goes by satellite barring, say, international communication? Ah, some, some of those new phone companies do use satellites. Ah, not very much for, for domestic use. Ah, there was a company called SBS once, Satellite Business Systems, that insisted on using satellites for calls no matter where you went. Right. Ah, they found that people got very annoyed with the, ah, with the one second delay that took place because they were going about 100,000 miles up into the air. Um, so that's, um, it's something that I think you'll be seeing less of, actually, for phone calls. And usually... To be replaced by, by microwaves, fiber optics mostly. Ah, you use just a scanner to pick up the, ah, the cordless conversations? Ah, the cordless conversations can be picked up on, ah, depending on, on what kind of cordless phone. Ah, some cordless phones can be found at the very end of the AM dial, believe it or not, the old ones. Um, other ones are, um, are found different frequencies. I don't have the exact frequencies, um, on me. But they're very easy and they're very commonly available. Well, they're not on the typical, ah, radio, are they? Ah, no, but you can find them on, on, you know, a scanner of sorts. Sure. Ah, and as far as cellular calls, although, remember, because cellular calls, ah, are used by people of a higher income bracket, it's illegal to listen to cellular calls. Not illegal to listen to, ah, to cordless, but cellular is illegal. But they can be found up in the 800 megahertz area. That's a great segue for you to read this article. I'm going to send it to you. Okay. Okay, thanks very much. Thank you. Good show. 279-3400 is our telephone number. Good evening. Hi. Um, a few quick questions. Yeah. Ah, the first is, ah, regarding the use of caller identification. Now, I know that caller identification is not approved in the, ah, New York area. With the exception, perhaps, of Jersey. But are there commercial devices out that would allow you, um, via what we know as caller identification or through some other means to localize the source of a call coming in? Ah, well, first of all, to strengthen the topic just a little bit, but, ah, well, I guess I'll let you get away with it. Ah, in New York, as, as you say, there is no such thing yet as caller ID. I believe it's being tested up in the Poughkeepsie area. Ah, now, if you were to buy a device, I think you, you're probably seeing advertisements for devices that allow you to, ah... Well, no, I'm not. I'm, I'm asking. I haven't seen it yet. Ah, well, there, there are advertisements for those. Ah, for the most part, such devices are, are pretty useless, ah, in an area that does not have caller ID. Ah, but there are certainly ways of finding out, ah, where the call is coming from. You can, you can pinpoint, say, a trunk group, which, ah, will, will tell you the general area that a call is coming from. But, ah, you have to have pretty sophisticated equipment to be able to do that. Also, if you have an 800 number, of course, you can get any from that, which will give you the exact phone number. Ah, so there are ways, other than caller ID, yes. Yes. Yeah, and probably you're running a, a PBX of some sort, you know, being a large institution. And, you know, that will tell you the neighborhood that the call comes from, or at least the direction that the call comes from. You know, there, there are several ways into an institution, usually. Um, I had another question with regard to, ah, not so much telephones, but, ah, use of, ah, electromagnetic devices. I was told that there are devices on the market which enable you to avoid your voice being transcribed onto magnetic tape. I'm not quite sure how such a device would work, but, ah, the practical application of such a device would allow you effectively to be in a room where tape recording is being made and to have your conversation or your voice not appear or not appear, um, audibly or understandably on the tape. Is that possible? Well, ah, if something like that is possible, I'd sure like to know about it. And, ah, I'm, I'm sure if it were possible, it would be, ah, well out of the reach of just about anybody listening. But if you, I'll tell you what, if, if, if you want a good story about that kind of thing, contact somebody like the spy shop people or something. I think they're in New York, and they can probably tell you all kinds of things that you never knew were available that, that might be available. All right? Enjoy the program. All right, thanks for calling. Bye-bye. 279-3400, good evening. Hello? Yes, go ahead. Yeah, um, I was curious about how pagers work. Well, we seem to be talking about just about everything except the, ah, the Dutch hackers here. Okay, well, how do pagers work? Ah, well, basically you call a, a telephone number. Right. You enter your telephone number on a touch-tone keypad or you simply enter a voice message of some sort. Okay. And then, ah, through a central computer, a, um, a little message is sent out through various, ah, coding routines and all that kind of thing. You have a special, um, a special frequency that, ah, your pager is always tuned to. I'm, I'm trying to make this as, ah, as simple as possible to, ah, to explain. How many pagers are in New York City? Oh, God, ah, so many that they have to assign a whole new area code to handle them and cellular phones and all that, the 9-1-7 area code. When is that going to happen? Ah, this year. In a couple of months, in fact. In fact, 9-1-7 already can be dialed from many places. You can experiment with that. And what exactly does 9-1-7 give you? Ah, well, what they are going to do is they're going to move every single pager in the, ah, 2-1-2 and 7-1-8 area codes into the 9-1-7 area code and also every single cellular phone, ah, phone number. And, um... Great. No, not, not, not fax machines, no, because they can't tell if you have one. But I think that's, that's it for now. It's going to be a very interesting area code for hackers. And how, when somebody pages you, how long does that take to... It depends on the company. Um, some are very quick, some are not very quick. Some can take up to 10 minutes or even longer. There are no, there's no, for example, you know, I don't know, some big, huge company that does a lot of paging... There's lots of companies. Like that. There's lots of companies. Just look in the yellow pages under, ah, you know, under pagers or beepers. Okay. And, ah, you'll see that there's, there's quite a market out there. Okay. Alright? Thanks a lot. Okay. Bye-bye. 2-1-2, 2-7-9, 3-4-100. How long? Okay, it's a legitimate question, I guess. What I'm going to do now is, I've got my beeper here. I'm going to call my beeper number and see just how long this, ah, this takes. I'll see if I can actually, you can hear it in the distance there. Okay, now we're going to beep this beeper. There, I've beeped myself. We'll see how long it takes for the actual beep to come through. Our number is 2-1-2, 2-7-9, ah, that was fast, wasn't it? 2-1-2, 2-7-9, 3-4, that's not the number I put in. 2-1-2, 2-7-9, 3-4-100. Of course, when you're doing this and talking on the radio at the same time, I guess you can make dialing errors. Good evening. Hi. Talking about these computer networks, I'm a manager of a large network for a bank in New York. We have some 90 minis and 2,000 PCs. They're all networked together, mainframes also. We have client server software. It's an expensive system. The potential is tremendous. Whether people state their intentions are harmless or they're curious or clever, this is not something that's to be played with. It is private domain. It's solely funded. It's privately funded. And it has the responsibility for running this network is to the people at bank with us. We do everything we can to keep it secure. But because someone has left the latch unlocked inadvertently, let me tell you, we go through great pain to secure it. That's not license for people to play. I understand some of what you're saying. I'm from the same ilk. I love to play, too. But there are certain things you don't play with, and those laws are put in place so people like me and other people at work there don't have to decide on a case-by-case basis. I have had viruses. In the development site where we developed the software for this network, we've picked up viruses. It's taken a tremendous amount of man hours and effort to track down those viruses and eliminate them. And when you deal with high-technology software, peer-to-peer processing, hundreds of thousands of lines of code, it's hard enough to keep the thing going on its own because it's so tricky. You have to have that confidence that you can keep as many people, everyone off. It doesn't belong there. So you know that your problems are either self-generated or some bug or something like that. Do you follow me? Yes. Now, of course, with a virus, it's impossible to figure out who started it, where did it come from. We feel we have a good idea. One of our people brought it in. We don't feel that somebody called up and stuck it on our system. However, it's hard enough to control things with the clever people who we pay to develop this stuff. Right. You can't leave the back door open for people to play, and that's why these laws are coming about. Well, now, it sounds like you run a responsible system and you're aware of the potential threat. Now, have you ever had a hacker on your system at all? Only people that work for us. Okay. Now, if you were to do something stupid one day and, say, leave a system wide open somehow so that somebody could get in, which would you prefer, somebody that was simply looking around, that was curious, or somebody that wanted to steal money? Well, from my standpoint, sure, I don't want anyone to do anything malicious and I don't mind somebody poking around. However, you have to understand the information that we store on those computers can be used for many devious purposes. I mean, there is a lot of information out there. We're not just talking about, you know, dumping a file. There is information that is critical. For instance, you may have a file cabinet at home and you may have a lock on it. Shouldn't, you know, are people licensed to go in there and look at that? The information can, in fact, be far more damaging than somebody who goes in there and messes up your compiler or something. Right, but I think we have to look at the fact that over the years, there's really not been one documented case of a computer hacker that did anything for evil reasons. Just curiosity seems to be the basic common denominator. I mean, I'm not sure how you define hacker, but there were people who were changing credit card accounts and ordering things on other people's... I can't give you all the specifics, but I do recall there was a group that was doing nefarious things. Uh-huh. And, you know, I mean, okay, I'll open my system and let's hope everyone's okay. We can't have that kind of exposure, is what I'm getting at. Right, and the thing is, you have to be responsible. You have to protect the people who have bits of information about them on your system. You have a responsibility to them. Absolutely. And, you know, of course, that's something that you've got to watch out for, but... I don't feel comfortable having your, you know, anyone in your audience out there poking around in our system, you know, perusing files. It's not what it's for. It's private information. We're paid to store that information and to guarantee exclusivity, and we spend a fortune to guarantee that. And, you know, I loved when we had dial-back modems, but they took dial-back modems out and they gave us this little calculator-type smart giz where I call up and the computer gives me a number and I give it a number, and then, you know, we go back and forth a few times. All right, now, a question is, you say you have this secure system. You're confident that it's secure, okay? Do you think it would be wrong if I were to take you up on that and say, well, I'll bet I can get in and try and let you know if I did get in? Do you think that would be bad? Unless you're paid by us, absolutely. I feel it would be terribly wrong. Even to try? Excuse me? Even to try? Yeah, I do. I think there's a certain responsibility. It's, you know, they build vaults. I think if you try to enter a vault, just to say, I can do it, I don't think anyone would understand that, and this is not much different. In fact, it is no different. Well, I mean, if the vault was just sitting there in the middle of the woods and nobody was watching it, I think quite a few people would probably try it, but since, you know, most likely it has armed guards around it, it's going to be very difficult. Yeah, but I don't, you know, in the legal world and in the world of data processing, professional data processing, I don't think you'll find, I can speak for myself, I won't speak for the rest, from a professional standpoint, I wouldn't agree with you. You know, we know what we're doing when we call those numbers, and we know what we're trying to get into, and we know it's a computer on the other end, and we know it's a vault, and we don't know whether it's Joe with a PC down the street that I've called into, or whether it's a huge conglomerate, but it is a privacy issue, and especially if safeguards are in place, and you can demonstrate that you've tried to keep people out. You know, I would agree, you know, if you leave your system wide open, you deserve what you're going to get, but I don't think that's licensed for someone to try. Right, well, I think if, you know, if hackers were malicious people, there was so much damage that could have been done by now, and I think that it's been proven over and over again that they're not malicious, that they're simply persistent and very curious, which I agree, in some cases, is not a good thing, you know, for people that are trying to keep people out, but I think you're in much better shape if you have some kind of a bug in your system, if the first person that finds it is a hacker rather than a criminal. Right. When you're a bank, you're a target. Everyone wants to steal money from you. There's a large percentage of people who would like to steal from them. Yes, but as far as damage being done by hackers, it's a kind of a crime that doesn't leave a trail, usually. I could go to work right now, and I could do something that would, you know, mess some things up. I'm not that kind of person, and I believe in what I do, and I, you know, it's not the way I operate, but if I did and we came in in the morning and nothing worked, we would, of course, you know, go back to backups and try and do things to repair, and there would be a large loss of money doing that. But it's the kind of a thing that doesn't really leave a clear trail. We have things go wrong all the time, and I'm on a development site with several minis hooked together in a network, and things go wrong all the time. I don't know how many of those were caused by my own people dabbling. I know a few have been, for sure. It's hard to say across all the computers in America. You see, I think you've touched upon something here. I think a lot of the backlash against hackers is because people are thinking about what they could possibly do, not what they have done. It's fear of the unknown. You cannot say how much has been caused by that. It's an unknown, and I agree with you. Yes, there is a fear, because we know how hard those in the industry know how hard it is to keep these things running right. They get so complicated after a while that there is a great fear, and that fear can turn out to be hundreds if not thousands of man hours to try and make sure everything is okay, comparing things. There is a lot of expense. Some of those bills that were slapped on those people, I'm sure were inflated, but there is actually a huge cost involved with the maintenance of the equipment, the software licenses, the support licenses, everything to keep that shop running. If you pick up the tab for an hour of downtime, the true tab is tremendous. Right, but there is really no way to impress that upon a kid that knows nothing about the corporate world. He just knows that there is something out there that is interesting, and if he has been brought up properly, he will know not to damage things or invade people's privacy by reading mail and things like that. I think basically what we have to say here is that since there is a lot of the unknown, a lot of fear that we not base our laws and the way we handle people once we find out what they are doing, we don't base that on fear, we base that on the facts. And I'm afraid we are going to have to stop there because we are clear out of time. But thanks very much for calling in. Most interesting phone call there. And that is going to just about do it for us here tonight. The program is off the hook, and we will be back again next week at 9 o'clock for another, I'm sure, controversial discussion about some element of the computer underground. Stay tuned now for the Personal Computer Show here on WBAI, New York. I hope that's understood, but didn't it know? Hi, I'm Jenny Bourne at the WBAI Evening News. And I want to thank all of you who called in to pledge your support during our fundraising drive and to offer a gentle reminder. Please remember...