
Cliff Stoll’s 1986 Hacking Investigation Uncovered Soviet Espionage via Early Internet
The video recounts Cliff Stoll’s 1986 investigation into a 75-cent accounting discrepancy at Lawrence Berkeley Labs, which revealed a hacker exploiting Unix systems to access military networks via the ARPANET and MILNET. The intruder used a cron tab script to escalate privileges to root, disabled accounting software, and searched for terms like 'nuclear' and 'plutonium' across defense contractors. Stoll traced the hacker’s origin through packet delay measurements (2.84-second round-trip time) and phone traces, ultimately identifying the source as an apartment in Hanover, Germany, linked to East German and Soviet operatives trading secrets for Deutsch marks and cocaine. Techniques included rewiring printers to log keystrokes, creating fake 'SDI network' documents to delay the hacker, and collaborating with agencies like the FBI and CIA, though many initially dismissed the threat due to its low financial impact. Stoll’s improvised tools—such as a soldering iron, Radio Shack clip leads, and a pager modified to receive Morse code—highlighted the lack of formal cybersecurity protocols at the time. The case led to the accidental invention of intrusion detection and honeypots, with Stoll emphasizing the human element over technical neutrality in security investigations. The talk reflects on the evolution from a trusted 1980s internet of ~8,000 users to today’s zero-trust landscape with billions of nodes.