People
The people the corpus records — the ones who wrote the tools everyone still runs, founded the conferences, went to prison, testified before senates, or connected a country. Each name links to its entry.
75 people
1800s
- 1800Alessandro VoltaThe physicist whose 1800 pile - stacked zinc and copper discs separated by brine-soaked cloth - produced the first steady electric current.Static electricity had been known for centuries and was useless for communication: a discharge is an event, not a signal. The pile gave a current that keeps flowing, and only then is there something to modulate, switch or send. Everything on this timeline after him depends on that one change of kind, from a spark to a supply. His name became the unit, which is a rarer honour than a prize.
1820s
- 1820Hans Christian ØrstedThe Danish physicist who observed in 1820 that a current-carrying wire deflects a compass needle, showing electricity and magnetism to be one phenomenon.Every motor, every transformer and every read head over a disk platter is this observation applied on purpose. So is every signal induced onto the wrong pair in a cable bundle: crosstalk is Ørsted's experiment happening when nobody asked for it. Cable design has spent two centuries arranging conductors so that his effect helps rather than interferes.
1830s
- 1831Michael FaradayThe experimenter who showed in 1831 that a changing magnetic field induces a current - the reciprocal of Ørsted, and the basis of generation and of every inductive coupling problem since.It is also, directly, why twisted pair works. Twist the two conductors and the interference induced into each is roughly equal; the receiver reads the difference between them, and the difference is largely clean. A cabling standard is Faraday's law turned into a manufacturing tolerance. He had almost no formal mathematics, which did not stop him from being right, and Maxwell spent the next three decades writing his results down as equations.
1840s
- 1843Ada LovelaceThe 19th-century mathematician often called the first programmer for her notes on Babbage's Analytical Engine.In 1843 she translated a paper on Charles Babbage's proposed machine and added notes far longer than the original, including what is often described as the first published algorithm intended for a computer. She also grasped that such a machine could manipulate symbols, not just numbers - an insight ahead of its time.
1850s
- 1854George BooleThe mathematician who in 1854 built an algebra of logic, ninety years before anyone had a machine to run it on.He was describing reasoning, not circuits. The connection was made by Shannon in 1937, and the gap between the two is the point: a piece of pure mathematics sat unused for three generations and then turned out to be the exact description of how switches behave. Every conditional, every access-control rule and every packet filter is his algebra with an implementation.
1860s
- 1865James Clerk MaxwellThe theorist whose 1865 equations described electricity, magnetism and light as one field, and predicted that electromagnetic waves travel at the speed of light.The order matters: the prediction came two decades before anyone demonstrated it. Radio existed on paper long before it existed in a laboratory, which is worth remembering whenever a standard is dismissed for having no implementations yet. Every wireless specification is an engineering treatment of this result, and propagation, attenuation and antenna design are applied Maxwell whether the engineer knows it or not.
1880s
- 1887Heinrich HertzThe physicist who in 1887 built a spark-gap transmitter and a loop receiver and demonstrated the waves Maxwell had predicted, turning radio from mathematics into an engineering problem.He reportedly saw no use for the result, which is the most useful thing about the story: the distance between a demonstration and an application is not a measure of the demonstration. Within fifteen years the same effect was carrying messages across the Atlantic commercially. His name is the unit every spectrum plan, channel width and clock rate is quoted in.
1900s
- 1901Guglielmo MarconiThe engineer and entrepreneur who turned Hertz's laboratory effect into a transatlantic service, claiming reception of a signal across the Atlantic in 1901.His technical contribution is contested and his commercial one is not: he built the company, the shore stations and the ship contracts that made wireless a business rather than a demonstration. The pattern is familiar to anyone who has watched a standard win - the person who makes something deployable is frequently not the person who made it work. The claim about the 1901 signal has been questioned on physical grounds ever since, which the record should carry rather than smooth over.
1930s
- 1936Alan TuringThe mathematician whose 1936 paper defined what computation is, and what no machine can compute - the boundary every computer since has been built inside.The paper was about the limits, not the possibilities: he described a machine in order to prove that some questions have no algorithmic answer. That the description turned out to be a blueprint is one of the field's larger accidents. His wartime cryptanalysis is better known publicly and less foundational technically, and the treatment he received afterwards is part of the record too.
1940s
- 1945John von NeumannThe mathematician whose 1945 EDVAC draft set out the stored-program architecture - instructions held in the same memory as data - that almost every computer still follows.The draft circulated with his name alone on it, which is why the architecture carries it; the EDVAC group's work is in there too, and the attribution has been argued over ever since. The design decision that matters is the one people forget is a decision: code and data share a memory, which is what makes software possible and what makes buffer overflows possible, and the same property does both.
- 1948Claude ShannonThe author of the 1948 paper that founded information theory, and, a decade earlier, of the thesis showing that Boolean algebra describes switching circuits.Two contributions, either of which would have been a career. The 1937 thesis made digital logic a design discipline rather than a craft. The 1948 paper defined information as a measurable quantity and gave the ceiling on what any channel can carry given its bandwidth and noise - which is why capacity planning is arithmetic rather than opinion, and why every claim about a faster link eventually meets a number Shannon wrote down. Compression, error correction and modulation are all consequences.
1950s
- 1952Grace HopperThe mathematician and US Navy rear admiral who built one of the first compilers, coined the word, and drove the English-language programming that became COBOL.Born in 1906, she joined the Naval Reserve in 1943 and was assigned to Harvard's Mark I, then wrote the first computer manual in 1946 - the first extensive treatment anywhere of how to program a machine. At Eckert-Mauchly from 1949 she designed a compiler and named the category; her 1957 division produced Flow-Matic, the first English-language data-processing compiler, which is the direct ancestor of COBOL. The argument she had to win was not technical but cultural: that a machine could usefully translate words into instructions, and that programmers need not be mathematicians. She retired from the Navy in 1966, was recalled in 1967, and retired again in 1986 as the oldest officer on active US naval duty, aged 79.
1960s
- 1961Leonard KleinrockThe queueing theorist whose early-1960s work on delay in networks of nodes underpinned ARPANET performance analysis, and whose UCLA laboratory hosted the first node.His mathematics is what lets anyone reason about waiting: how long a queue grows, what delay a given load produces, and why a link at ninety per cent utilisation behaves nothing like one at fifty. Every capacity conversation is downstream of it. His claim to have originated packet switching is disputed - by Baran, by Davies and by historians who note that the early reports address queueing and delay rather than message blocks - and the honest record keeps the dispute rather than resolving it in either direction.
- 1964Paul BaranThe RAND engineer who designed the distributed network - no central switch, messages cut into blocks routed independently - in studies published from 1960 and collected in 1964 as On Distributed Communications.He was asked to find a way for communications to survive a nuclear attack, and the answer he reached was to remove the thing that could be destroyed: the centre. He described taking inspiration from a brain routing around damaged tissue. Two details are worth carrying. The idea was resisted by the telephone company's circuit-switching engineers, who regarded it as unworkable, so the network that replaced theirs was rejected by them first. And the survivability argument is why the internet has no master switch, which is the same property that makes it hard to shut down and hard to govern.
- 1965Gordon MooreThe Fairchild and later Intel co-founder whose 1965 article observed that the number of components per integrated circuit was doubling on a regular cadence.It was an observation about economics with a horizon of about a decade, and it became a planning assumption for fifty years - and then, quietly, an industry roadmap that vendors organised themselves to meet, which is a different thing from a law of nature. The useful reading for anyone sizing infrastructure is that the curve was always about cost per transistor rather than speed, and that the two stopped moving together long before anyone announced it.
- 1967Donald DaviesThe National Physical Laboratory scientist who arrived at the same idea independently in the mid-1960s, named it packet switching, and built a working network at NPL to prove it.Baran had the concept and Davies gave it the word, which is not a small contribution: the term packet is what let engineers, funders and standards bodies talk about the thing without arguing about what to call it. He also did what the theory needed - an actual node, running, at Teddington - and the ARPANET design took from both men, with the terminology coming from him and the resilience argument from Baran. Independent arrival at the same answer, on two continents, is the strongest evidence that the idea was ready rather than lucky.
- 1967Larry RobertsThe ARPA programme manager who decided in 1967 that the network would be packet switched, then funded, designed and managed it into existence.The decision is the contribution. Two people had proposed the technique and neither could deploy it; Roberts chose it over circuit switching, coordinated the contractors who built the hardware and the university that hosted the first node, and revised the design to take from both proposals rather than picking a camp. This is the role that rarely gets a monument: not the person who has the idea, and not the person who writes the code, but the one who selects among ideas and then carries the consequences of the choice.
1970s
- 1970James EllisThe GCHQ researcher who conceived non-secret encryption around 1969-70, several years before the public discovery of public-key cryptography, and could tell nobody.The idea existed inside a British intelligence agency and did nothing, because a classified insight changes no protocol, ships in no product and teaches no one. The comparison is the argument for open research stated as an experiment that actually ran: two groups had the same idea, one could publish and one could not, and the entire public-key infrastructure descends from the one that could. Recognition came only after declassification in the late 1990s, by which time he had died.
- 1973Bob MetcalfeThe inventor of Ethernet, at Xerox PARC in 1973, and recipient of the 2022 Turing Award for its invention, standardization and commercialization.The 1973 memo described a broadcast communication network for connecting PARC's Alto computers, and the first Ethernet ran at 2.94 Mbps - roughly ten thousand times faster than the terminal networks it replaced. The word that mattered was in the name: Metcalfe wrote of communication over an ether, which left the medium unspecified and is why the same design later survived twisted pair, fibre and radio. David Boggs, who died in 2022, co-invented it and co-authored the 1976 paper. The third word in the citation is the one engineers skip: after leaving Xerox, Metcalfe drove DEC, Intel and Xerox to a shared 10 Mbps specification rather than keeping it.
- 1973Clifford CocksThe GCHQ mathematician who in 1973 worked out an implementation of Ellis's idea - equivalent in substance to what became RSA - four years before RSA was published.He is reported to have done it in an afternoon and then filed it, because there was nothing else to do with it. The work stayed secret until the late 1990s, so it influenced nothing: no standard cites it, no library implements it, and the industry that grew up around the same mathematics grew up entirely on the published version. The episode is the cleanest available answer to whether secrecy or publication produces more capability, and it is not close.
- 1974Bob KahnThe co-designer of TCP/IP with Vint Cerf, and the 2004 Turing Award co-recipient, cited for the design and implementation of the internet's basic communications protocols.The Turing citation is specific about what the pair actually did: they formulated the design principles of internetworking, specified TCP/IP against those requirements, prototyped it, and coordinated the early implementations. That last verb matters more than it looks. A protocol that one team implements is a program; a protocol several teams implement compatibly is a standard, and getting there is coordination work rather than design work. Kahn's later decades went into the institutions around the technology rather than the technology itself, which is the less celebrated half of why any of it still functions.
- 1974Ralph MerkleThe third name on the public-key patent with Diffie and Hellman, who arrived at the idea independently as a student, and the inventor of the hash tree that carries his name.His undergraduate project proposed a way for two parties to establish a secret in public, and was rejected by a reviewer who did not believe the problem was worth solving. The Kanellakis award in 1996 lists him with Diffie, Hellman, Rivest, Shamir and Adleman for the conception and first effective realisation of public-key cryptography. The tree structure he described later became the standard way to prove that one item belongs to a large set without shipping the set, which is why it turns up in certificate transparency, in backups and in ledgers.
- 1974Vint CerfThe co-designer, with Bob Kahn, of TCP/IP - the protocols that turned separate networks into one internet - and joint recipient of the 2004 Turing Award for the work.Cerf and Kahn did not invent a network; they invented the agreement that lets networks that were never designed for each other exchange packets, which is why the citation reads for internetworking rather than for a protocol. Born in New Haven in June 1943, Cerf has had a hearing impairment since early life and has attributed part of his interest in networking to its promise as another channel for people who cannot use a telephone easily - a detail worth keeping, because the most consequential communications protocol of the century was partly motivated by someone who found the existing one hard to use. He has spent the decades since as the most public advocate the internet has, which is a job nobody appointed him to.
- 1976Martin HellmanCo-author of New Directions in Cryptography and of the key-exchange method that carries his name with Diffie's; joint recipient of the 2015 Turing Award.His citation is worth reading closely: it credits inventing AND promulgating, which is the pair of verbs this history keeps requiring. The exchange lets two parties agree a shared secret over a channel someone else is listening to, and it is still the thing happening at the start of a TLS session decades later - which is why forward secrecy is available at all. He spent much of his later career on nuclear risk rather than cryptography, which the record should mention rather than tidy away.
- 1976Whitfield DiffieCo-author, with Martin Hellman, of the 1976 paper New Directions in Cryptography, which proposed public-key cryptography and digital signatures; joint recipient of the 2015 Turing Award.Before that paper, encryption assumed the two parties had already met, or that a courier had. The paper's move was to separate the key that locks from the key that unlocks, which makes it possible to communicate privately with a stranger - the requirement every subsequent commerce protocol rests on. It described the idea without a practical construction; three people at MIT supplied one the following year. He later spent decades arguing the policy side in public, testifying to both houses of the US Congress on cryptography.
- 1977Adi ShamirThe S in RSA, joint recipient of the 2002 Turing Award, and the author of the secret-sharing scheme that splits a key so that any k of n holders can reconstruct it.The RSA work is what he is cited for, and the secret sharing may be the more widely deployed idea: it is how a root key can exist without any one person holding it, which is the arrangement used at the ceremonies that sign the DNS root. He also did foundational work on differential cryptanalysis, which is the other half of a cryptographer's job - the field advances as much by breaking constructions as by proposing them.
- 1977Leonard AdlemanThe A in RSA and joint recipient of the 2002 Turing Award, later the founder of DNA computing.His role in the trio was largely to attack the constructions the other two proposed, which is how the surviving one earned confidence: the published algorithm is the one that outlasted its own co-author trying to break it. That division of labour - propose, attack, keep what survives - is the method the whole field runs on, and it is easier to describe than to practise inside a group of three people who have to agree on a paper afterwards.
- 1977Ron RivestThe R in RSA: co-author of the 1977 paper that turned public-key cryptography from a proposal into something implementable, and joint recipient of the 2002 Turing Award.Diffie and Hellman had described what was needed and said plainly that they had no realistic way to build it. Rivest, with Shamir and Adleman at MIT, produced one within a year, and the trio founded RSA Data Security in 1982 - which is how the algorithm reached the products rather than the journals. The Turing citation is precise about the contribution: making public-key cryptography useful in practice. He also wrote the MD and RC families of algorithms, several of which the field later had to retire.
1980s
- 1980Jon PostelThe RFC Editor from 1969 until his death in 1998, author or editor of the RFCs that define IP, ICMP and TCP, and the first director of IANA - a job he volunteered for and at first did by hand.For almost three decades one person shepherded the documents that define the internet, and the numbering authority that keeps addresses and protocol parameters unique began as him keeping a list. That is the part worth sitting with: the global registry now argued over by governments started as a volunteer's clerical habit. His most quoted line, from the 1980 IP specification, is the robustness principle - be conservative in what you send, liberal in what you accept - which shaped protocol design for forty years and has since been argued against from inside the IAB, on the grounds that tolerated errors become entrenched and eventually become the specification.
- 1981Wau HollandThe co-founder of the Chaos Computer Club in 1981 and the author of its ethic - Levy's hacker principles extended with two German additions: do not litter in other people's data, and use public data, protect private data.Holland's club proved its point by doing rather than saying: in 1984 the CCC exploited the Btx videotext system to transfer 134,000 Deutschmarks from a Hamburg bank overnight, then returned it in public with the press watching, forcing the Bundespost to admit a flaw it had denied. That is the CCC method still - technical proof deployed as civic argument - and it is why Germany's hacker scene has spent forty years closer to constitutional politics than to the underground.
- 1983Richard Stallman (rms)The MIT AI Lab hacker who, watching the lab's culture dissolve into proprietary software in the early 1980s, launched the GNU Project in 1983, founded the Free Software Foundation in 1985, and wrote the four freedoms and the GPL.The origin story is a printer: denied the source code to fix a jam notification, he concluded that a program you cannot change is a program that controls you. He then wrote foundational software - GCC, GNU Emacs, GDB, much of the toolchain the world compiles with - which is why the argument had teeth. Uncompromising to the point of alienating allies, and controversial in later years over public remarks, he remains the reason the movement is framed as ethics rather than engineering convenience.
- 1984Emmanuel Goldstein (Eric Corley)The editor of 2600: The Hacker Quarterly since 1984, host of the radio programme Off The Hook, and founder of the HOPE conferences - the closest thing the American underground has to a permanent institution, named for Orwell's fictional dissident.2600 published what the mainstream press would not, organised the monthly Friday meetings that gave isolated teenagers a physical community in dozens of cities, and paid for its principles in court: the magazine was sued by the film industry for linking to DeCSS, losing a landmark case on whether a hyperlink is speech. Corley's constant argument across four decades is that the right to understand technology is not conditional on permission from its owners.
- 1985Radia PerlmanThe engineer who invented the spanning tree algorithm at Digital in the 1980s, making bridged Ethernet survivable, and who wrote the algorithm's poem.Her 1985 paper let bridges of arbitrary topology agree on a loop-free tree without a central authority, and the IEEE standardised it in 802.1D in 1990. Every switched network since has run a descendant. She wrote the specification with a poem attached, Algorhyme, whose first lines answer Joyce Kilmer: I think that I shall never see a graph more lovely than a tree. She also did the link-state work behind IS-IS. The nickname she is given, mother of the internet, obscures the actual contribution: not that she connected things, but that she made a redundant network safe to build, which is a different and harder problem.
- 1986The Mentor (Loyd Blankenship)The Legion of Doom member who, hours after his 1986 arrest, wrote the short essay published in Phrack as The Conscience of a Hacker - universally known as the Hacker Manifesto - and who later, by coincidence of employment, wrote the cyberpunk game manual the Secret Service seized in the Steve Jackson Games raid.The Manifesto is the most reprinted text the culture produced: a defence of curiosity as a crime of the mind, written by a teenager and quoted ever since in films, talks and courtrooms. Blankenship's second brush with the law is the more instructive one - his GURPS Cyberpunk manuscript was confiscated as a supposed hacking manual, and the fiasco helped bring the Electronic Frontier Foundation into existence.
- 1988Liane TaroucoThe researcher who built the Rede Sul de Teleprocessamento, the first initiative to connect Brazilian universities, wrote the first book on computer networks published in Brazil, and contributed to the country's first internet backbone. Inducted into the Internet Hall of Fame in 2021.Her inclusion corrects a familiar distortion. Founding histories are usually told through the people who negotiated with ministries; Tarouco's work was the teaching and the regional plumbing - the textbook a generation learned from and the southern network that proved inter-university connection was practical before there was a national one. She spent her career at UFRGS, and the education side of her contribution is why the field in Brazil had trained people ready when the backbone arrived.
- 1988Paul VixieThe engineer behind BIND and much of the operational practice around DNS, founder of the Internet Systems Consortium, author of Vixie cron, and creator of the first successful commercial anti-spam service.Born in 1963, he has spent a career on the parts of the internet that only get attention when they break. BIND is the name server most of the internet ran on; Vixie cron is on nearly every Unix system alive; and the anti-spam reputation lists he built established the pattern - a list distributed as DNS, so it needed no new software anywhere - that later produced response policy zones, which he specified with Vernon Schryver in 2010. The through-line is the same each time: put the new capability inside machinery operators already run, because the adoption problem is harder than the design problem.
- 1988Van JacobsonThe author of Congestion Avoidance and Control, the 1988 work that gave TCP the algorithms - slow start, congestion avoidance, fast retransmit - that stopped the internet collapsing under its own load.In the mid-1980s the network suffered congestion collapse: throughput between two sites fell by three orders of magnitude, because every sender responded to loss by retransmitting harder. His fix was to make each sender infer the state of a network it cannot see, from the only evidence it has - the timing and loss of its own packets - and to back off. That inference is still what every TCP connection does. It is also why a link can be busy while nothing feels fast, and why bufferbloat took decades to be recognised as the same problem wearing a different hat.
- 1989Tadao TakahashiThe founder of Brazil's National Education and Research Network (RNP) and the coordinator who turned scattered academic links into a national backbone - inducted into the Internet Hall of Fame in 2017. He died in April 2022.His decisive move was political as much as technical. When the state telecommunications monopoly proposed becoming the single access point for all Brazilian users, with everyone holding one company's email address, Takahashi and colleagues argued the government into a hierarchical, many-provider model instead. That argument is why Brazil got a competitive internet rather than a state portal, and it was won in 1995 in a meeting rather than in a protocol.
- 1989Tim Berners-LeeThe author of the 1989 CERN proposal that became the World Wide Web, and of the first browser, server and page - and the 2016 Turing Award recipient for it.He wrote three things that had to exist together for any of them to be useful: an addressing scheme, a transfer protocol and a markup language. The decision with the longest consequences was not technical: CERN put the specification into the public domain in 1993, and the web spread because nobody had to ask permission or pay a licence. Compare any contemporary networked hypertext system that did neither, and the difference in outcome is almost entirely that.
1990s
- 1990Kevin PoulsenThe hacker who seized a radio station's phone lines to be caller 102 and win a Porsche, then became a security journalist.In June 1990, Poulsen and friends took over the incoming lines of Los Angeles station KIIS-FM so that he would be precisely the 102nd caller, winning a Porsche 944 S2; his deeper exploits against phone-company systems earned him years as a fugitive and, after capture, one of the era's heaviest hacking sentences. Barred from computers on release, he reinvented himself as an investigative journalist and became a senior editor at Wired, breaking major cybercrime stories. The full arc, phreak to felon to Fourth Estate, made him the redemption template his generation cites.
- 1991Demi GetschkoThe engineer on the team that made Brazil's first internet connection, at FAPESP in São Paulo, and the person most associated with the country's naming and governance ever since - administrative contact for the .br domain since 1989, member of the Brazilian Internet Steering Committee since its creation in 1995, later an ICANN board member and chief executive of NIC.br.He was inducted into the Internet Hall of Fame in 2014, the first of seven Brazilians so far. His durable contribution is structural rather than technical: he helped define the shape of the .br name tree and the rules of the registry, and then stayed for three decades to operate them. When people ask why Brazil's internet governance looks unusual - multi-stakeholder, with the registry, the incident response team and the exchange points under one civil body - the answer runs through the choices this generation made and defended.
- 1991Phil ZimmermannThe author of PGP, who released strong encryption free to the public in 1991 and spent three years under US criminal investigation for munitions export because the software left the country.His defence became a landmark of legal creativity: since exporting a book is protected speech, PGP's source code was published as a printed volume by MIT Press, exported lawfully, and scanned back in abroad. The investigation was dropped in 1996 without charges. Zimmermann's stated motive was never commercial - he built it for activists and for people who should not have to justify wanting a private letter, an argument he has repeated for three decades.
- 1992Carlos Afonso and AlternexThe co-founder, with sociologist Herbert de Souza (Betinho) and Marcos Arruda, of the Brazilian Institute of Social and Economic Analyses (IBASE), and the man behind Alternex - the first internet service in Brazil open to the public, years before commercial providers existed. Inducted into the Internet Hall of Fame in 2021.Alternex came out of civil society rather than industry or academia, which is the point: Brazil's first public network access was built by an organisation whose purpose was social justice, and it served non-governmental organisations before it served anyone else. Its defining moment was the 1992 Earth Summit in Rio, where Alternex, riding infrastructure assembled with the nascent RNP, provided internet mail to conference participants - the country's first large public demonstration that the network was for everyone.
- 1992Jude Milhon (St. Jude)The self-taught programmer and civil-rights activist who helped build Community Memory - the first public computerised bulletin board, in 1970s Berkeley - coined the word cypherpunk, and wrote as St. Jude in Mondo 2000.Milhon insisted that hacking was 'the clever circumvention of imposed limits', a definition that covers code, bodies and laws with equal force, and she spent her life pushing back on the scene's boy-club default - her advice to women entering it was blunt, funny and widely reprinted. She is the corrective to a history told as a list of young men: the culture's vocabulary, its earliest public network and a good part of its politics came from her.
- 1993Jeff Moss (Dark Tangent)The founder of DEF CON, which began in 1993 as a farewell party for a friend's bulletin-board network and became the largest hacker gathering in the world, and of Black Hat, its commercial sibling for the people who had to expense the trip.Moss's real achievement was building an institution that the underground would still accept: DEF CON is deliberately cash-only at the door, structurally suspicious of surveillance, and run by unpaid Goons rather than an events company. He later served on the US Homeland Security Advisory Council and as ICANN's chief security officer, becoming the field's most credible translator between hackers and governments - the same bridge the L0pht walked into the Senate in 1998.
- 1994Bruce SchneierThe cryptographer and writer whose 1994 book Applied Cryptography taught a generation of programmers how ciphers work, who designed Blowfish and Twofish, and who then spent decades arguing that the hard problems in security are human and economic rather than mathematical.He gave the field several of its most-used ideas: security theatre for measures that perform safety without providing it, the observation that security is a process and not a product, and Schneier's law - anyone can design a cipher they themselves cannot break. His newsletter has run since 1998 and remains one of the few places where the policy, economic and technical sides of the field are argued together.
- 1995Kevin MitnickThe 1990s hacker whose social-engineering exploits made him the era's most famous computer intruder.Mitnick broke into corporate networks largely by manipulating people rather than machines, became a fugitive, and was arrested in 1995 after a high-profile hunt. He later reinvented himself as a security consultant and author, making 'the human is the weakest link' a lasting lesson.
- 1995Tsutomu ShimomuraThe San Diego Supercomputer Center researcher whose own machines were broken into on Christmas Day 1994 using TCP sequence-number prediction and IP spoofing - and who then led the technical hunt that ended with Kevin Mitnick's arrest in February 1995.The intrusion itself was a landmark: a textbook demonstration that a TCP connection could be hijacked by guessing the sequence numbers of a trusted host, which is why sequence-number randomisation exists today. The chase, written up with journalist John Markoff as Takedown, made both men famous and remains fiercely disputed - Mitnick's supporters read it as self-mythologising and see the press coverage itself as part of the punishment.
- 1996Solar Designer (Alexander Peslyak)The Russian researcher behind John the Ripper, the password cracker that has been the standard auditing tool since 1996, and behind Openwall - along with early defensive work on non-executable stacks and the return-to-libc attack that showed why that defence alone is not enough.He is the clearest example of a researcher who moves attack and defence in the same career: publishing the technique that defeats a mitigation, then shipping hardening that addresses it. He also runs the oss-security mailing list, which is where a large share of the open-source world's vulnerabilities are coordinated in public. Quiet, rigorous, and enormously influential without the conference-stage persona.
- 1997Fyodor (Gordon Lyon) and NmapThe author of Nmap, published in Phrack in 1997 and still the standard port scanner and host-discovery tool - the program that taught the industry what its own networks actually expose.Nmap's contribution goes beyond scanning: OS fingerprinting by TCP/IP stack quirks, service and version detection, and a scripting engine that turned it into a small vulnerability scanner. It is also a rare piece of security software with cultural reach - it appears on screen in The Matrix Reloaded, which Fyodor documents proudly on the project's Movies page. He also maintains the seclists archives, where much of the field's public discussion has been preserved for decades.
- 1997Nelson MuriloThe author of chkrootkit, the rootkit detector that has been part of the Unix security toolkit since the late 1990s, and one of the three founders of the ISTS podcast and the YSTS conference.Very few conference founders anywhere have their own code still installed on other people's servers decades later. chkrootkit is still being released - version 0.57 shipped in January 2023 - which is an unusual thing to be able to say about any security tool, let alone one written before the industry had a name for the category. He is also one of the three voices on the podcast that has been recording since 2006, and the event grew out of that rather than the other way round.
- 1998Mudge (Peiter Zatko)The L0pht member who wrote L0phtCrack, published early and widely read work on buffer overflows, and led the 1998 Senate testimony - later a DARPA programme manager, and head of security at Google's Motorola division and at Twitter.Mudge is the clearest single example of the underground-to-institution arc: the same person who told senators under a handle that seven people could take the internet down in half an hour later ran DARPA's Cyber Fast Track, funding hacker-scale research on hacker-scale timelines. In 2022 he became a whistleblower against his own employer, telling US regulators that Twitter's security was misrepresented - the hacker ethic of disclosure applied, at personal cost, at the top of the industry.
- 1998Space Rogue (Cris Thomas)The L0pht member who founded the Hacker News Network, testified alongside the rest of the crew before the US Senate in 1998, and has spent the decades since as one of the field's most consistent public voices on research ethics and vendor behaviour.HNN mattered because it was journalism by practitioners at a moment when mainstream coverage of hacking was mostly panic; it set the tone for the security press that followed. He later wrote the L0pht's own history, arguing against the tidy legend the industry prefers, and remains a fixture at DEF CON and Black Hat - proof that the underground's institutional memory is carried by people, not archives.
- 1999DVD Jon (Jon Lech Johansen)The Norwegian teenager who in 1999 co-released DeCSS, the program that decrypted DVD content scrambling so films could be played on Linux, and who was prosecuted twice in Norway and acquitted both times.The case became the defining fight over whether code is speech: DeCSS circulated as a haiku, a T-shirt, a dramatic reading and a prime number, precisely because the courts were being asked to ban a number. Johansen's defence - that he was making a legally purchased disc play on his own computer - is the ancestor of every right-to-repair and interoperability argument since, and the affair fixed reverse engineering as the pivotal issue in the digital-rights debate.
2000s
- 2000Mafiaboy (Michael Calce)The alias of Michael Calce, the Montreal fifteen-year-old whose February 2000 denial-of-service spree - Project Rivolta - knocked Yahoo!, Amazon, eBay, CNN, Dell and E*Trade offline using university machines he had compromised.The attacks landed at the peak of dot-com optimism and detonated it: the idea that a teenager with borrowed computers could switch off the internet's biggest brands reached the White House, drove emergency summits and helped make distributed denial of service a permanent line item in every risk register. Calce was sentenced in youth court to eight months of open custody, and, in the pattern the field keeps repeating, grew up into a security consultant and author.
- 2001Aaron SwartzThe programmer and activist who co-authored the RSS 1.0 specification as a teenager, helped build Reddit and the Creative Commons technical infrastructure, co-created SecureDrop, and led the campaign that stopped the SOPA copyright bill - and who took his own life in 2013 at twenty-six while facing federal charges.The charges followed his bulk download of academic articles from JSTOR over the MIT network. JSTOR declined to pursue it; prosecutors did not, bringing multiple counts under the Computer Fraud and Abuse Act with a threatened sentence out of all proportion to the conduct. His death turned the CFAA's elasticity from a researchers' grievance into a public scandal, produced repeated attempts at reform known as Aaron's Law, and remains the strongest argument in the field for prosecutorial restraint. Note: this entry touches on suicide; the topic is handled here only as historical record.
- 2001Federico KirschbaumCo-founder of Ekoparty (2001) and, with Francisco Amato, of Infobyte - the Argentine research company behind Faraday, the collaborative penetration-testing platform.Kirschbaum represents the pattern that makes the Argentine scene distinctive: the conference and the research companies grew from the same group of people, so talks, tooling and commercial work reinforce each other instead of competing. He has continued presenting original research internationally, including at Black Hat, which is the practical rebuttal to the assumption that serious offensive research happens only in the northern hemisphere.
- 2001Francisco AmatoCo-founder of Ekoparty and of Infobyte, and the author of Evilgrade - the framework that demonstrated how software update mechanisms could be abused to deliver attacker-supplied code to a victim who was doing exactly what security advice told them to do.Evilgrade landed at the point where the industry was telling everyone to keep software updated, and showed that an update channel without signature verification is a distribution system for whoever controls the network path. The work is a good example of research from the region setting an international agenda: update integrity is now assumed, and part of the reason is that someone built the tool that made the failure undeniable.
- 2001Leonardo PigñerCo-founder and chief executive of Ekoparty, the Buenos Aires conference that became Latin America's largest hacking event - one of the five who started it in 2001, alongside Juan Pablo Daniel Borgna, Federico Kirschbaum, Jeronimo Basaldua and Francisco Amato.Pigner is the founder who stayed operational: he runs the conference as an organisation rather than an annual event, with year-round community programmes, a publishing arm and training. With Basaldua he also built the security firm Base4. The Ekoparty model - a commercially sustainable conference that never stopped being a hacker gathering - is the template most Latin American organisers now study, and it is why the region has an independent circuit rather than franchised editions of northern events.
- 2003HD MooreThe creator of Metasploit, the open-source exploitation framework released in 2003 that turned exploit development from artisanal one-off code into a shared platform with modules, payloads and a common interface.Metasploit did for offence what a package manager did for software distribution, and the argument about it has never fully settled - it lowered the barrier for defenders and attackers on the same day. Moore also ran the Month of Browser Bugs, publishing a flaw a day to force vendors to move, and later scanned the entire public IPv4 internet repeatedly to measure what was actually exposed. Both projects share his method: make the uncomfortable truth impossible to ignore.
- 2006Luiz Eduardo dos SantosThe founder whose idea the ISTS podcast was, and who spent months insisting the three of them record a pilot; co-founder of the YSTS conference that grew out of it.The detail worth keeping is the insistence. The three worked in information security, lived in different cities - he in a different country - and had an affinity for the subject that sometimes converged and sometimes did not. Nothing about that arrangement produces a podcast without somebody pushing, and he pushed for months. Nearly twenty years of continuous recording, and one of the most selective conferences in Latin America, exist because of that.
- 2007George Hotz (geohot)The New Jersey teenager who in 2007, at seventeen, performed the first unlock of the original iPhone from AT&T, and who in 2010 published the root keys of the PlayStation 3 after Sony removed its Linux feature.Sony's lawsuit against him produced one of the largest backlashes in the history of the industry: Anonymous launched Operation Sony, and the PlayStation Network breach that followed weeks later cost the company a hundred million accounts and a reported hundreds of millions of dollars. Whatever the direct causal chain, the episode is the standard case study in how suing a researcher can cost far more than the bug ever would. Hotz went on to work in artificial intelligence and self-driving cars.
- 2007Max Butler (Iceman)The security researcher turned card thief who, as Iceman, hacked and forcibly merged the rival carding forums of the mid-2000s into his own CardersMarket - a hostile takeover of an entire criminal marketplace - before receiving a thirteen-year sentence in 2010.His arc is the field's sharpest cautionary tale because both halves were real: he wrote intrusion-detection signatures and ran a respected security list while also stealing roughly two million card numbers. Kevin Poulsen's book Kingpin reconstructs it in detail. The case is also where the underground economy's structure became legible to outsiders - forums, reputation systems, escrow, vendor ratings - which is the moment researchers stopped treating cybercrime as hacking and started treating it as an industry.
- 2007Rodrigo Rubira Branco (BSDaemon)The Brazilian vulnerability researcher who has led malware and vulnerability research at Qualys, headed research at Check Point in Israel, worked on IBM's Advanced Linux Response Team, and has published dozens of flaws in widely used products - one of the country's most visible names on the international conference circuit.His significance for Brazil is the demonstration effect: low-level security research - kernels, firmware, exploit mitigation - was assumed to happen elsewhere, and a generation of Brazilian researchers followed a path he helped make visible. The local conference culture that grew alongside it, notably the Hackers to Hackers Conference in São Paulo, is where much of that community still meets.
- 2007Willian CaprinoOne of the three organisers who created You Sh0t the Sheriff, and the person who has most often explained the event's history and its unusual format in public - a career of more than twenty years in Brazilian information technology and security.The YSTS founders describe the origin as a reaction: Brazilian security events were becoming either vendor showcases or purely technical gatherings, and they wanted the room where the two audiences argue with each other. Deliberately capping attendance was the mechanism. Caprino is the clearest example of the organiser-as-infrastructure that this scene runs on - people who keep an event alive for two decades while holding a full-time job elsewhere.
- 2008Dan KaminskyThe researcher who found the 2008 DNS cache-poisoning flaw that affected every resolver at once, and then coordinated the simultaneous multi-vendor patch rather than publishing it.The weakness was in the protocol, not in one product: DNS matched answers to questions using a 16-bit query identifier, and he showed how to win that race reliably. What makes the episode a landmark is the handling. He was 29, working as a penetration tester, and he took the finding to competing vendors, who shipped a coordinated patch on 8 July 2008 - a month before he presented the detail at Black Hat. Source-port randomisation was the mitigation; DNSSEC was always the real answer. The uncomfortable footnote is that the fix had been proposed years earlier and not adopted, and that patched resolvers were shown to be poisonable in hours. He died in 2021.
2010s
- 2010Barnaby JackThe New Zealand researcher whose 2010 Black Hat talk 'Jackpotting Automated Teller Machines' made two ATMs spray cash across the stage on command - the single most-cited demonstration in conference history, and the origin of jackpotting as a term.He went on to show that insulin pumps could be commanded from hundreds of feet away and that implantable defibrillators could be made to deliver a lethal shock - work that pushed medical-device security into regulation and reportedly influenced how the US Vice President's own device was configured. He died in 2013, days before a DEF CON talk on pacemakers, at thirty-five. The showmanship was the method: he proved that a stage demo moves an industry that a hundred advisories cannot.
- 2010Julian Assange (Mendax)The Australian hacker who as a teenager, under the handle Mendax, was part of the International Subversives and pleaded guilty in 1996 to intrusions including Nortel - later the founder of WikiLeaks and the most disputed figure of the disclosure era.Before WikiLeaks he co-authored the cryptographic deniable-storage tool Rubberhose and researched the book Underground, which remains the definitive account of the Australian scene. His later career - the 2010 military and diplomatic leaks, the Ecuadorian embassy, extradition proceedings and a 2024 plea deal - divides the hacker community as sharply as any subject in it, along the same fault line the culture has argued since the 1980s: whether releasing information is inherently a public good.
- 2010Rodrigo Montoro (Sp0oKeR)Brazilian researcher known as Sp0oKeR, long associated with intrusion detection and detection engineering, and the author of one of the two 2010 lists - his own roster of Brazilian security people on Twitter - that first mapped the community.He belongs to the detection side of the field rather than the offensive one, which is under-represented in hacker history everywhere: the people who write the rules that catch the attack rarely get the conference legend treatment. His long presence in the Brazilian scene, and the fact that two independent practitioners felt the need to index the community in the same month of 2010, says something about how invisible the scene was to itself before that.
- 2011Anchises MoraesOne of the founders of Garoa Hacker Clube, Brazil's first hackerspace, where he holds the ceremonial title of Supreme Chancellor; founder and organiser of Security BSides Sao Paulo; director of the Brazilian chapter of the Cloud Security Alliance; and author of the long-running blog AnchisesLandia.He is the connective tissue of the Brazilian scene rather than a researcher known for one finding: the hackerspace, the free community conference, the professional association chapter, the threat-intelligence work and two decades of writing that documents the local calendar year by year. Communities need someone who keeps the record and introduces people to each other, and in Brazil that role has largely been his - which is why his blog is a primary source for the history of these events.
- 2011Deviant OllamThe physical security researcher and TOOOL member whose lockpicking talks put the discipline in front of network audiences that had never considered the door.At the fifth edition of YSTS, in May 2011, he opened the event with the basics of lockpicking and sold kits to the room afterwards - which is the whole argument in one gesture, since a lock is a control whose failure mode you can hold in your hand. Physical access defeats most of what the rest of a security programme buys: a server room door, a rack lock and a badge reader sit underneath every network control, and they are usually the least examined part of the estate.
- 2011Fabio AssoliniThe Brazilian malware analyst on Kaspersky's Global Research and Analysis Team whose published work is the main public record of how Brazilian banking fraud actually operates - boleto manipulation, overlay attacks and the families that became known as the Tetrade.His significance is documentary. Brazilian banking malware was for years a phenomenon everyone in the region experienced and almost nobody outside it could read about, because the analysis existed only in Portuguese or not at all. Publishing that research in English, with samples and technique names, is what turned a local nuisance into an internationally understood threat class - and it is why the rest of the world eventually recognised Brazilian crews as innovators rather than imitators.
- 2011Nelson BritoThe creator of T50, the packet injection and stress-testing tool, and the only Brazilian to have presented at PH-Neutral in Berlin, in 2011.T50 is the kind of tool that gets used far beyond the people who know who wrote it, which is the usual fate of a good one. His research has been published under names like Permutation Oriented Programming and SQL Fingerprint, and his speaking record runs through the Brazilian circuit - IME, CNASI, CONIP, SERPRO, ITA, H2HC, BSides Sao Paulo and YSTS - as well as that one Berlin appearance, which is worth noting because PH-Neutral was small and did not hand out invitations widely.
- 2013Michal Zalewski (lcamtuf)The Polish researcher who wrote American Fuzzy Lop, the coverage-guided fuzzer that made automated bug-hunting genuinely effective, and the books Silence on the Wire and The Tangled Web on passive reconnaissance and browser security.AFL changed the economics of finding memory-corruption bugs: instrument the target, mutate inputs, keep whatever reaches new code, and let a laptop discover crashes that skilled humans missed for years. Nearly every modern fuzzer descends from it, and large parts of open source were audited by it before anyone was paid to. His writing has the same quality as his tools - patient explanations of how information leaks from systems that look silent.
- 2017Marcus Hutchins (MalwareTech)The young British researcher who stopped WannaCry in May 2017 by noticing an unregistered domain in the malware and buying it for about ten dollars - which turned out to be the worm's kill switch, halting a global outbreak within hours.Three months later he was arrested in Las Vegas leaving DEF CON, charged over banking malware he had written years earlier as a teenager. He pleaded guilty, and in 2019 a judge sentenced him to time served, explicitly weighing what he had since done for the world against what he had done as a kid. The arc - accidental hero, defendant, and now respected researcher - is the most modern version of the field's oldest story, and it is why the community argues so hard about second chances.