the Cuckoo's Egg
loresecurityops culture
Cliff Stoll's 1986 hunt for a hacker that began with a 75-cent accounting error.
An astronomer turned sysadmin at Lawrence Berkeley Lab, Stoll noticed a tiny billing discrepancy and traced it to an intruder selling stolen military data to the KGB, ultimately identifying Markus Hess in Germany. His book is a foundational text of intrusion detection and one of the first real accounts of digital counter-espionage.
Clifford Stoll's 1989 book began with an accounting discrepancy of seventy-five cents. An astronomer managing computers at Lawrence Berkeley Lab, he refused to write off the difference, traced it to an unauthorized account, and spent the next year following an intruder who turned out to be selling data to the KGB.
What makes the book endure is that it is the first real account of incident response as a practice. Stoll had no tools, no playbook and no institutional support, so he improvised: printers wired to capture sessions, a fabricated department full of fake classified documents to keep the intruder online long enough to trace, and a running notebook that reads as the ancestor of every incident log since. The honeypot concept is in there before it had a name.
The parts that are dated are worth reading anyway. Agencies did not know whose problem it was, nobody could agree whether a crime had occurred, and Stoll spent as much energy on jurisdictional confusion as on the technical hunt. That institutional vacuum is exactly what the Morris Worm would rupture a year later, and reading the two together shows a field being forced into existence by events it was unprepared for.
Also known as: Cliff Stoll, Markus Hess, the 75-cent hack
Sources
- Stoll, 'The Cuckoo's Egg' (1989)