Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • I expected some info on its functioning. The goal was to gauge the size of the Internet, how? Why did it fail? I guess Wikipedia for the rescue.
  • I was a student part-time administrator/systems programmer at the Purdue Engineering Computer Network at the time. Our OS installs had enough local mods (and we had enough non-VAX, non-Sun architectures) that we were immune to some of the worm's modalities, but the sendmail debug mode exploit at least still caused a lot of consternation.
  • Was KSB there at the time? That dude was fun.
  • Diversity is security! I wish more people understood that. It may be more difficult to manage a bunch of diverse systems, but they are much more resilient to attacks.
  • The term "worm" came from the 1975 (sci-fi) novel The Shockwave Rider:

    * https://en.wikipedia.org/wiki/The_Shockwave_Rider

  • The worm in shockwave rider released secret information to the public. Turns out a worm was not needed for this, just wikileaks.
  • From the Wikipedia article:

    Clifford Stoll, author of The Cuckoo's Egg, wrote that "Rumors have it that [Morris] worked with a friend or two at Harvard's computing department (Harvard student Paul Graham sent him mail asking for 'Any news on the brilliant project')".

    Has pg commented on this?

  • Would you?
  • A bit of an aside from The Cuckoo’s Egg;

    It’s been a long time since I read the book, but IIRC Cliff visited with Robert Morris (rtm’s dad) at the NSA when he traveled to Washington DC, and I think the worm and rtm are mentioned after he meets with the elder Robert.

  • He's referred to it a few times in essays:

    https://www.google.com/search?q=site%3Apaulgraham.com+%22mor...

  • PG spoke about the worm a bit in an interview here: https://aletteraday.substack.com/p/letter-85-paul-graham-and...

    Some quotes from that:

    > The worm, no one would have ever known that the worm existed, except there was a bug in it. That was the problem. The worm itself was absolutely harmless. But there was a bug in the code that controlled the number of copies that would spread to a given computer. And so the computer would get like 100 copies of the worm running on it, back in the day, when having 100 processes running on your computer would be enough to crash it.

    >he called me and told me what had happened.

  • I'm pretty sure Paul Graham was directly involved in this story (not in any bad, culpable way, but enough that, were a film to be made about it, a well-known actor would be cast for his part).

    https://news.ycombinator.com/item?id=38020635

  • Out of curiosity, why do you think this?
    by neom
  • That was one scary exciting day (source: was running machines at MIT at the time)
  • WPI was immune, the main machines on the net at time were an Encore Multimax and a DEC-20.
  • Good times, good times. I was in a Stanford computer lab when everything started to get very, very slow.
  • I remember that day was sooooooooooo quiet on Usenet.

    Not much was happening in the Eng and CS buildings on campus (except for those that had to deal with the worm).

  • That day our tech chief at the time came running and told us about the worm, and that apparently our country managed to avoid it because the news spread quickly enough that one guy simply unplugged the whole country from the Internet - there was only a single connection back then. (!)
    by Tor3
  • The 10% number is completely made up. According to Paul Graham, "I was there when this statistic was cooked up, and this was the recipe: someone guessed that there were about 60,000 computers attached to the Internet, and that the worm might have infected ten percent of them."
  • That figure is probably UUCP mostly not live connected hosts. I could be wrong, but 60k hosts that you could telnet to sounds like a lot of ducking hosts back then. I was there too, in my late teens. God bless PG.
  • When i worked at Convex, there was an unnatural mania that fingerd be disabled and all sendmail patches be applied as quickly as possible. When I asked why, the answer started with "well... a couple of years ago there was this guy from the east coast who worked here for a year..."
  • A good account is With Microscope and Tweezers: The Worm from MIT's Perspective [1], published in CACM a few months after the event. Notice it was the worm.

    I was an intern at IBM in '88 and they shut-down the (iirc) two internet getaways to their corporate network (vnet) while people figured out what was going on. News moved slowly back then, and the idea of self-replicating software was unusual. Although IBM had had its own replicator the previous year [2].

    [1] https://www.cs.columbia.edu/~gskc/security/rochlis89microsco...

    [2] https://en.wikipedia.org/wiki/Christmas_Tree_EXEC

  • >the idea of self-replicating software was unusual

    floppy based viruses were well established and quite common

  • I assume you all know that Robert Morris is one of the YC (and Viaweb) cofounders? [1] Together with Paul Graham, Jessica Livingston, and Trevor Blackwell.

    [1] https://en.wikipedia.org/wiki/Robert_Tappan_Morris

    by wslh
  • and his dad was head of computer security at the NSA for a while
  • I did not know this.

    I knew Robert Morris was the financier of the Revolution. I know it's a plucky university outside of Pittsburgh with basketball and hockey programs that punch above their weight. I know there's a pastor in Texas who is...in some legal trouble...with the same name.

    Now I have another one to remember!

  • He also is (or was) an HN user. No comments in quite some time though. I wish he did post here more.

    https://news.ycombinator.com/user?id=rtm

  • I followed his course 6.5840 on distributed systems (https://pdos.csail.mit.edu/6.824/, YouTube videos at https://youtube.com/playlist?list=PLrw6a1wE39_tb2fErI4-WkMbs...) and completed the labs. One day, out of curiosity, I looked up his name. Then I realized what a legend he is.

    Great course by the way.

  • I am also doing the course now in my freetime. Even I wasn't aware who he is.

    On a sidenote, what did you do after the course?

    It is an amazing course though!

  • Would be cool if he adds a session on how to hack distributed system in 1988...