the L0pht testimony
lorehackingsecuritygovernance & risk
The 1998 Senate hearing where seven hackers testified they could take down the Internet in thirty minutes.
In May 1998 the members of the Boston hacker collective L0pht appeared before a US Senate committee under their handles, Mudge, Weld Pond, Space Rogue and the rest, and told the senators the Internet's core protocols were so fragile the group could disable it in about half an hour. It was the moment hacker expertise entered the policy room as testimony rather than threat. Several of them, notably Mudge, went on to senior roles in government and industry security.
In 1998 the members of L0pht, a Boston hacker collective, testified before a United States Senate committee under their handles rather than their names, and told the senators they could take down the internet in thirty minutes. The claim was about routing vulnerabilities, and it was broadly credible.
What makes the moment historically significant is the venue. A legislature invited people it could reasonably have prosecuted, and listened. That established a channel between the security research community and policymakers that had not previously existed, at a point when neither side had any established way to talk to the other, and several of those present went on to shape government security practice directly.
The specific warning was about the routing system's dependence on mutual trust, which is the same fragility that RPKI addresses partially today. Twenty-eight years later the honest assessment is that the vulnerability class they described has been mitigated rather than removed, and that the more durable outcome of the testimony was institutional: it made the idea of consulting hackers about security normal rather than scandalous.