A cancer diagnosis changes everything.
At Kansas City Proton Institute, we combine expert physicians with advanced proton therapy technology.
Our cutting edge imaging and high intensity proton beams target cancer precisely while minimizing damage to healthy tissue.
That means better outcomes, fewer side effects, and faster recovery.
If you have prostate breast, head and neck or brain cancer, proton therapy may be a better option than traditional radiation therapy.
Get a second opinion today.
Visit kcpi.com and take the next step toward healing with precision.
I'm Scott Hanson, host of NFL Red Zone.
Lowe's knows Sundays are for football.
That's why we're here to help you get your next DIY project done, even when the clock isn't on your side.
Whether that's a new Filtrete filter or Bosch and Cobalt power tools, Lowe's has everything you need to feel like the MVP of DIY.
So get it done and earn your Sunday.
Shop now in-store and online.
Lowe's, official partner of the NFL.
The History Channel, original podcast.
History This Week, September 10th, 1986.
I'm Sally Helm.
It's 7.51 a.m., a quiet morning in Berkeley, California.
Cliff Stoll wakes up.
His pager is ringing.
For a while now he's been monitoring the computer system at Lawrence Berkeley Lab, where he works as a systems administrator.
His main concern is keeping the computers running 24-7 so that scientists at the lab can use them for research.
But today, he's on a different mission.
He's tracking a computer user who has been breaking into the network.
A hacker.
Cybersecurity isn't his job.
In fact, the term hasn't even been invented yet.
Regardless, Cliff is on the case.
He's not sure what this hacker is up to.
Could be harmless.
But he wants to find out.
And today, his beeping pager tells him that hacker is back.
Stoll heads to his office at the lab.
And there he learns that when the intruder logged in this time they used a connection in the lab's network to access another computer network over 2000 miles away near Huntsville Alabama, at the US.
Army's Redstone missile complex.
And this hacker wasn't just browsing.
They'd exploited a bug to become a super user likely, able to insert their own programs into the code at this military installation.
Stoll immediately dials the security team at Redstone to let them know.
As it turns out, they already do know.
They've been monitoring this hacker's activity on their network for four months.
And Cliff Stoll is like, what?
Some hacker is running freely through a highly sensitive military computer network and they're just allowing it.
It turns out, Redstone had called both the FBI and the Army's Criminal Investigation Division, but neither was interested in pursuing the case.
Not only is cybersecurity not really a thing, but neither is cybercrime.
The consensus was that this was probably some harmless kid.
Maybe a high school student who's good at computers.
Probably just curious.
Nothing to see here.
But Cliff Stoll can't accept that.
Something isn't right.
Today, Cliff Stoll versus the Hanover Hacker.
How did a 75-cent bookkeeping error lead him to uncover an international espionage operation?
And how did this shape the future of cybersecurity?
So it's 1986.
I was working at the Keck Observatory designing an off-axis hyperbolic segment.
That is Cliff Stoll.
He is now 75 years old. talking to us from his makeshift lab.
He's got long, wild white hair, looks a little like Doc Brown from Back to the Future.
And as excited as Doc Brown was about time travel.
That's how Cliff Stoll gets about his specialties.
My background's in astronomy, computing, and physics.
Back in 1986, to design a telescope.
The astronomy group at Lawrence Berkeley Labs.
But then his grant money runs out.
So I looked around and said, well, I'd better figure out what to do now.
He ends up in the basement of the same lab, in the computer center.
So I went down and started working on just being a sysadmin.
That's a systems administrator.
This is the person responsible for the configuration and security of computer networks.
And just two days into the job, something weird happens.
Somebody calls us and says, hey, Cliff, the accounting system has crashed.
The accounting system accounts for each user's time on the computer.
They're charged by the second.
So if you want to use our computers, you're going to pay for it.
This was 40 years ago when computers were not yet commonplace.
They were quite rare.
And Cliff Stoll's lab is connected to a very primitive version of the internet.
You used something called a modem and a telephone.
And telephones were connected with these things called wires.
You'd have a dedicated pair of copper wires going from the phone over here along the wall out up to the telephone pole, from that telephone pole to a central office, from that central office through a switch connecting to the long distance line.
But again, to get onto the Internet, you'd need to be one of the few people on Earth with access to a computer.
Really, it was military installations, higher education institutions performing research.
Those were the ones that were on the backbone of the Internet.
That is cybersecurity expert J.J.
Widener.
He said, if you did have a computer, you'd still need a login, a username and password for the network you're trying to access.
As you may know, people often use very guessable passwords.
Oh my goodness, like don't make them your kids' names, one, two, three, four, five.
If you're really secure, you put an exclamation mark at the end, because everybody knows that exclamation mark is going to protect you to the nth degree.
And once you had a password, everything was kind of up for grabs.
Whenever you logged in, you could almost communicate with anything that was on there, kind of like it is now.
I can hop on the internet and I can start communicating.
If you don't have a good firewall, you know, if it's wide open.
Okay.
So Cliff Stoll is told that this accounting system that tracks all the network activity at Lawrence Berkeley Labs and charges money for it has crashed.
Turns out the error is caused by a 75 cent discrepancy on the balance sheet.
And that seemingly tiny fact means that a mystery user had logged in to the network.
A user had been added to one of the computers without being added to the accounting system.
This person had used 75 cents worth of computer time.
There could be legitimate causes for this 75-cent error.
Like, say you were a researcher working on a paper about orbital dynamics.
You might dial into the Lawrence Berkeley Lab Computer Center and take a quick look at their database.
So maybe this was legitimate, but it could be something else.
This is interesting.
My curiosity-o-meter moved into the yellow zone.
It started out saying it's probably somebody at my laboratory, Lawrence Berkeley Labs, yanking my chain.
Maybe it's some high school student.
Yep, that's a possibility too.
At this stage of the internet.
Many users are curious young people exploring this new world of networked information, sometimes with unintended consequences.
Now, of course, the last possibility is that this could be something really illegitimate, some kind of hacker with a nefarious purpose in mind.
Stoll finds the account with a 75 cent charge and deletes it.
If someone had been sneaking in to use the system, they'd have to find another account to use.
The next day, Stoll gets an email from a company that provides network services to sensitive government agencies.
And this networking company says hey, overnight someone from your network tried breaking into our network.
Stoll looks at the logs and finds that only one user was logged in at the time, Sventec.
And Joe Sventec was a real person.
A well-known computer jock that used to work at Lawrence Berkeley Labs.
But Sventec wasn't there anymore.
He had moved out a year earlier and probably had never disabled his account.
Had Sventec reactivated his account after a year away from the lab and then used it to try to break into a government network?
Highly unlikely.
So Cliff Stoll sets up a trap.
On this show we spend a lot of time talking about how people in history dealt with stress, upheaval and uncertainty.
Imagine if they had therapy.
I'll be honest, therapy has been a big help in my own life.
Having a space to work through stress or burnout has made me more grounded, and I know a lot of people could benefit from that too.
But here's the challenge.
Finding a therapist is hard, and finding one who takes your insurance?
Almost impossible.
Most online platforms don't work with insurance at all, which means you're left paying full price out of pocket or signing up for an expensive subscription.
That's why I really like Rula.
They do things differently.
Rula partners with over a hundred insurance plans, so the average copay is just 15 a session, sometimes even zero.
That's real therapy with licensed professionals at a price that actually makes sense.
And it's not random matching.
Rula considers your goals, your preferences, your background.
They connect you with a curated list of in-network therapists who are actually aligned with what you need.
No wait lists, no frustrating back and forth.
Appointments are often available as soon as the next day.
And Rula doesn't disappear once you've matched.
They stay with you on your journey, checking in to make sure your care is helping you move forward.
Thousands of people are already using Rula to get affordable, high-quality therapy that's actually covered by your insurance.
Visit Rula.com slash HTW to get started.
After you sign up, you'll be asked how you heard about them.
Please support our show and let them know we sent you.
That's R-U-L-A dot com slash HTW.
You deserve mental health care that works for you, not against your budget.
In 2013, two brutal murders left the city of Davis, California paralyzed in fear.
The victims were an elderly couple.
It was up close and personal.
I'm 48 Hours correspondent Erin Moriarty.
I thought I had seen it all, until I encountered the mastermind behind those murders.
He's a, I think the word is psychotic...
This is 15 Inside the Daniel Marsh Murders.
Follow and listen to 15 Inside the Daniel Marsh Murders on the free Odyssey app or wherever you get your podcasts.
Abercrombie denim is everything right now.
Denim should feel like this.
Confident, easy, like your butt has never looked better.
If you didn't know, Abercrombie's Curve Love denim went viral in 2019 for eliminating waist gap and it's still a game changer.
Between that and their classic fits with a straighter line from waist to hip, the perfect denim does exist.
Shop Abercrombie denim in the app, online, and in-store.
September 1986.
Cliff Stoll has a plan.
He's now getting alerts every time this rogue user Sventec logs into the Lawrence Berkeley Labs network.
Because what is Sventec up to?
He wants to find out.
The way to do it is to print out traffic.
All the information coming in, all of it going out.
The labs network is connected to the outside world through 50 different phone lines, each with their own stream of activities.
Which means Stoll needs 50 printers to print a record of every keystroke, every command entered on each of those 50 phone lines.
One of the very few things I learned in graduate school was that it's a lot easier to apologize afterwards than to get permission in advance.
So I waited around until 5.30 or 6 on a Friday afternoon.
Then I went around with one of these push carts, going from office to office, liberating people's critters and carrying them down to the basement of North Berkeley Labs, and hooked them up so that every time somebody would connect into the machine it would print out whatever they were typing.
All of this network activity is being printed out in real time and Stoll wants to be there to catch Spentec in the act.
So I just rolled out a sleeping bag, got some foam rubber under me.
Remember, this is 1980s, when one computer took up four or five rack panels filled with fans.
And there are fluorescent lights overhead because they don't want any incandescent to poison the atmosphere.
And every now and then there were these things called teletypes that would go.
It was like trying to sleep in a noisy room where there's a lot of traffic next to you.
Eventually, you get tired enough that you're able to sleep.
Next morning I wake up and look over at my printers and I'll be damned.
One of them has 10 20, 30 feet of printout coming out of it.
I'm looking at this printout and I could see somebody connecting into our computer, shutting off the local accounting system and then going out over our internet connection, trying to break into 20 or 30 military computers across what was then known as the mill net.
This is kind of the worst case scenario.
Sventec, or whoever is pretending to be Sventec, is using Lawrence Berkeley's network to break into the US military's computer network.
This is not what you expect to find on a physics computer in Berkeley.
I mean, it's Berkeley.
I figure somebody might be searching for things like granola recipes.
But no, they're searching for things like nuclear bomb secrets.
And Cliff Stoll now has access to all of Sventec's activities, which he reads through page by page.
I'm looking at this and I could see how they're doing it.
They're logging in as guests.
They're logging in as anonymous.
Sometimes they log in with already known usernames and passwords.
He was able to use that account and then pivot and use a vulnerability on the system to escalate his privileges.
And once he escalated his privileges, meaning he was like an administrator of the system.
Now he started planting these little eggs everywhere on the system and other systems to make sure he had an established presence.
So if one account got turned off, he would have another account.
I'm like stunned.
I mean, I get pissed off.
So naturally, we did what any other bureaucracy would do.
We held a meeting.
Cliff shows all of these printed out records to his boss, Dave Shirley.
Dave says to us, look, this guy is a threat to what we're doing.
He has no authority to be there.
I want him caught and shut down.
I want you to nail the bastard.
Cliff gets the green light to spend more time tracking Sventec.
The lab's attorney also escalates the case and contacts the FBI office in Oakland.
The FBI says, oh my God, that's serious.
How long has it been going on for?
How much money have you lost?
I said, well, we've lost about 75 cents in computing time.
And the guy says, right now, it ain't worth my time to even listen to you.
When you lose half a million dollars, call me back.
They are able to get local law enforcement on board, the Oakland District Attorney.
And to work with them, Stoll, of course, sets up a system.
I built an alarm system so that every time this guy would come into my system it would call out on a Radio Shack dialer.
Call my pocket pager.
I'd get a beep, beep, beep.
I'd look at it.
I'd say, ah, Sventec is active.
Every time Spentec logs on, Stoll calls the Oakland police.
I'd run over to the nearest pay phone, throw a quarter in, and call my local police.
And they would call a telephone company.
They, in turn, would send a technician through to read off what line is connected to what and figure out what number it's coming from.
It wasn't simple.
The whole process might take half an hour, might require two hours.
Phone traces were really complex.
They would have to start the physical trace, you know, on the phone line.
So he was persistent.
It was like almost the same day over and over and then just logging what he learned.
This goes on for weeks.
Cliff meticulously records each network intrusion.
In physics, if you don't write it down, it didn't happen.
So I keep a notebook.
Every time this hacker comes in, I write down date time, what do I observe, what's happening, and so on.
Then Stoll gets an unexpected call from the National Security Agency, the NSA, the big guns.
Somebody from the NSA calls me and says, I hear you've got some computer security problems.
They say, can I have a copy of your notebook?
So I go to the photocopier, copy it, send it off to the NSA.
Stoll hopes they're finally taking this seriously, that they're going to do something.
But then he realizes, maybe not.
He says, look, we're at the NSA.
I can't even confirm that I'm talking to you.
They wanted to know what was happening, but help me?
No, come on.
They've got other fish to fry.
Then another phone call from the CIA.
They sent some agents out to talk to me.
It's bizarre.
We go over to Blondie's Pizza and there are these two CIA agents wearing suits and ties when everybody else is wearing, you know, flannels and Grateful Dead t-shirts.
But the CIA?
Also just curious.
They don't want to participate.
This investigation isn't getting any help from the feds.
And at this point, Stoll's mission to find the hacker has been going on for months.
The hard part for me was to convince my boss to allow me to continue to work on this.
My boss kept saying, we have no budget for computer security.
So you can do this as a hobby as long as you keep doing your system manager stuff.
So Cliff Stoll keeps his two jobs systems admin and cyber detective filling up his logbook every time Sventec logs in, tracking his activity.
Until one day, a breakthrough.
Up until now, he'd had no idea where Sventec might have been logging in from.
They found that the connection came from Lawrence Berkeley Labs through Oakland's switching system across North America over from a place in northeastern Virginia called MITRE.
Mitre Incorporated is a defense contractor.
So I call up their sysadmin and they say it's impossible that anyone could possibly break into your computer from our system because we have a secure computer.
We have passwords.
We have users and accounts that are secure.
It's impossible.
I said, look at the logs of your outbound modems.
And they did and said, uh-oh, we have a problem.
This is serious stuff.
The records showed that someone was logging into MITRE's systems and using their outbound modems to access computers across the US.
And they shut off all incoming and outgoing traffic in and out of MITRE.
And then, Sventec goes dark.
It worked.
For a week, nobody broke into our systems.
And then, bam, here they come again.
The hacker has adapted.
They've gone digital.
No phone lines.
They're coming over a very primitive, early digital system called TimeNet.
And because TimeNet is a digital service, the process of completing a trace is streamlined.
They're able to just trace the digital information.
And that trace leads well outside the United States.
By December of 1986, four or five months into this whole project, they're able to identify it as coming from the city of Hanover.
Hanover, Germany.
Across the ocean in a country currently split in two by the Cold War.
This lone hacker trying to obtain American military secrets might be connected to something much, much bigger.
This episode is brought to you by State Farm.
Checking off the boxes on your to do list is a great feeling.
And when it comes to checking off coverage, a State Farm agent can help you choose an option that's right for you.
Whether you prefer talking in person, on the phone or using the award winning app, it's nice knowing you have help finding coverage that best fits your needs.
Like a good neighbor, State Farm is there.
Running a business comes with a lot of what-ifs.
But luckily, there's a simple answer to them.
Shopify.
It's the commerce platform behind millions of businesses, including Thrive Cosmetics and Momofuku.
And it'll help you with everything you need.
From website design and marketing to boosting sales and expanding operations, Shopify can get the job done and make your dream a reality.
Turn those what-ifs into...
Sign up for your $1 per month trial at Shopify.com slash special offer.
This episode is brought to you by Indeed.
When your computer breaks, you don't wait for it to magically start working again.
You fix the problem.
So why wait to hire the people your company desperately needs?
Use Indeed's sponsored jobs to hire top talent fast.
And even better, you only pay for results.
There's no need to wait.
Speed up your hiring with a $75 sponsored job credit at Indeed.com slash podcast.
Terms and conditions apply.
By January of 1987, with the revelation that Sventec is based in Germany, the FBI has finally joined the investigation.
If you bother somebody often enough, eventually they'll learn your name.
You'll annoy them enough that their no will morph into a maybe.
And if you apply enough pressure, that maybe you can squeeze out into sort of a yes.
The FBI works with the German phone company to trace Sventec's origins.
The hacker had gone digital, but they still had to use a phone line from their point of origin.
They're able to get the Bundespost, the German telephone operator, to begin making phone traces.
Cliff Stoll works with the FBI to set up yet another phone tracking system.
This time, whenever Stoll is notified on his beeper that Svendek has accessed the Lawrence Berkeley Lab network, he has to call the FBI, who calls the German police, who calls the German phone company.
Then they have to send out a technician to manually track the signal.
Some guy had to take his pajamas off and put on clothing.
Drive downtown, go up to the third floor of the switching system in Hanover, Figure out what number was going out and trace backward to see where it was coming from.
This whole process can take several hours.
And if Sventec logs off, they lose the trace.
So Stoll gets good at keeping the hacker entertained.
How do I get the hacker to stay on my system for an hour, two, three hours?
We know that he's looking for defense-related stuff.
He's looking for nuclear information.
He's looking for things related to rocket launching and missile data.
So I know what to do.
I'll build collection of completely bogus files about a military network called the Strategic Defense Initiative Network SDI Net.
Tons and tons of stupid bureaucratic memos, so that it would take him a couple hours to download it all.
Today, cybersecurity experts would call that a honeypot.
You put a pot of honey out there so that people will go in and have all the food they want.
Meanwhile, you are tracing them backwards.
The honeypot works.
After a few weeks, they have an address.
Number 16 Lachse Strasse in Hanover, Germany.
And eight months after a 75 cent accounting error, they have their hacker.
My sweetie and I are dancing in the backyard singing ding dong the witch is dead.
The powers that be have figured out who's responsible for it.
Presumably they'll bust them and everything will be fine.
But the German Bundeskriminalamt, the German version of the FBI, says, let's wait a while.
Let's just watch and see.
Another government agency that wants to wait.
So Stoll keeps adding to the honeypot, generating more files for the fake Strategic Defense Initiative network.
And they keep swallowing it all.
A week goes by, two, three weeks.
A month, two, three months goes by.
Stoll thinks they're wasting their time.
But then... I'll be damned.
A letter comes in.
Not from Germany.
It comes in from Pittsburgh, Pennsylvania.
Huh?
A letter from someone named Laszlo Bailow asking for more information on Cliff Stoll's entirely made-up SDI net.
The only place they could have found out about this completely fictitious network was the files that were sent from Berkeley and wound up in Hanover, Germany.
Whoever this Laszlo Bailo was, he's somehow connected to this hacker in Germany.
So I did exactly what you would do.
I say, OK, hot damn.
I call up the FBI and say, some guy wrote Laszlo Bailo, Pittsburgh, Pennsylvania.
And the guy at the FBI says, whatever you do, whatever you do, don't touch that piece of paper.
It's got fingerprints on it.
Laszlo Bailo is a bit of a man of mystery, claiming at various points to have been a Hungarian refugee, a diamond dealer, a CIA hitman.
He'd most recently showed up in the newspaper as an FBI informant on an unrelated case.
And turns out, Laszlo Bailo is connected to the KGB.
The Soviet spy agency had used him to verify the information passed along by a hacker in Hanover Germany, named Markus Hess aka.
Svantec.
These hackers were by no means just a bunch of kids fooling around, but were on the puppet strings of Eastern European, East German and Bulgarian and Russian intelligence organizations.
Marcus Hess is part of a ring of hackers who had broken into nearly 400 computers around the world to steal information which they had then sold to the KGB.
The Hanover hacker affair becomes a watershed moment in the history of computing and cybersecurity.
Before this...
Even though it was almost exclusively used by research institutions and government agencies transmitting sensitive information, the internet wasn't really seen as a place that law enforcement would need to patrol.
But now?
This little special area has become a place that governments and spy agencies have discovered and are beginning to sniff around.
It was the end of innocence of the internet.
It took about a year from detecting these people breaking into our computers in August of 1986 to arresting them in summer of 1987.
Cliff Stoll testifies against the Hanover hackers at their trial in Germany.
In the end, only one of the hackers was convicted, Marcus Hess.
He was given a suspended sentence of 20 months.
The Berlin Wall had just come down, and Cold War mania was fading away.
But Cliff Stoll is invited to testify before the U.S.
Senate about his entire investigation.
His dogged pursuit and the legal precedent set by this case serve as a wake-up call.
He was taking in logs, he was looking at connectivity patterns.
He was looking at what systems are connecting to what systems, what accounts are being utilized.
All that stuff is exactly what the Cybersecurity Defense Operations does.
Yeah, he definitely wrote the book on some of this stuff, man.
Soon, federal agencies were spinning up dedicated cybercrime units.
And around the world, countries started working together like never before to track hackers across borders.
All because of 75 cents.
When something's there and you can't figure it out, it's not a problem.
It's an opportunity.
Thanks for listening to History This Week, a Backpocket Studios production in partnership with the History Channel.
To stay updated on all things History This Week, sign up at historythisweekpodcast.com.
And if you have any thoughts or questions, send us an email at historythisweekathistory.com.
Special thanks to our guests.
Cliff Stoll astronomer, teacher and author of The Cuckoo's Egg Tracking a Spy Through the Maze of Computer Espionage.
And JJ Widener, cybersecurity expert currently serving as director of cybersecurity architecture at Kimberly-Clark.
This episode was produced and sound designed by Dan Rosato.
It was also produced by me, Sally Helm.
For Back Pocket Studios, our executive producer is Ben Dickstein.
From the History Channel, our executive producers are Eli Lehrer and Liv Fidler.
Don't forget to follow, rate, and review History This Week wherever you get your podcasts.
And we'll see you next week.