Mysterious Sleeping Bag

Categories: Personal

Set the Wayback Machine to February 1995, and let’s head back to the Netcom offices. I’d been promoted from tech support to email administration by now, so I was no longer trailing into the office at 5 PM — which is not to say I was an early riser by any means, so that day I got in around 10 AM or so. Either way, I was completely weirded out to see a total stranger sacked out in a sleeping bag under Robert Hood’s desk over in the network administrator bullpen.

I was a vaguely responsible human being and well aware that our entire data center was in that office so I found someone in management and asked what the hell was going on. Maybe we should call our owner Bob Rieger or the police or something? Nope. Don’t bother that dude, and don’t ask any questions about what’s going on, because it’s a secret.

Okay, fine. I went back to my project of the moment, which was trying to make our sendmail more efficient. This was a long time ago so we didn’t really have any alternatives to sendmail for sending and delivering email, and we didn’t really need one, but certainly some of our use cases were unusual. For example, we were probably managing email for more incoming domains than almost anyone else in the world at the time, because we were one of the few ISPs with a cheap way for people to register domains which could receive email.

So when I took over email, I meticulously read the entire sendmail configuration file to figure out what we were doing. I also read the entire O’Reilly book on sendmail, affectionately known as the Bat Book because it had a nice picture of a bat on the cover. O’Reilly was the one true source of knowledge at the time and the first thing I did when I got the new role was buy that book and spend a week reading through over eight hundred pages of dense information.

Worth it, because I figured out that instead of adding five or six lines to the sendmail config every time we got a new domain registration, I could just add an entry to a Berkeley DB database (which is essentially just a very fast on-disk hash table). This made the sendmail config much more readable and, more importantly, reduced the in-memory size of each sendmail process by like… well, my ego wants to say 90%, but really I just remember that it was significant.

And we processed a lot of email at the time. So worth spending some time on this even if I was really confused by the mystery of the sleeping guy.

Eventually he woke up — I pretended not to notice — and wandered over to huddle with Robert Hood. Robert Hood, aka hoodr, was our lead network administrator and all around lead engineer. We didn’t have the concept of principal engineers back then but he would have been one for us. They were talking very intensely. I kept pretending I wasn’t noticing.

When I left around 6:30 PM, the mysterious guy was still at it. Someone had apparently given him access to our systems. Really weird.

He was gone the next morning and I didn’t find out what happened for a week or so, after Kevin Mitnick was arrested in Raleigh, North Carolina for various computer fraud charges. This was a huge deal: the FBI had been hunting Mitnick for more than two years and it made front page news when they finally caught him. He was one of the most infamous figures in computer security in the 1990s.

The mysterious sleeper was, as you may have guessed if you know this bit of history, Tsutomu Shimomura. After Mitnick broke into Shimomura’s computers down in San Diego, Shimomura — working with law enforcement — embarked on a multi-week effort to track Mitnick down, which led him from the public access site The WELL in Sausalito to Netcom and ultimately to figuring out Mitnick’s physical location.

In theory Shimomura didn’t have to come down to the Netcom offices but it was convenient for coordination and probably a bit faster. At the time, management told us that Mitnick used our servers as a place to stash a file full of credit card numbers temporarily. The actual truth is that Netcom’s security was terrible and Mitnick got his hands on 20,000 Netcom customer credit card numbers. You could get away with not admitting details like that in public back then.

These days there’s some dispute over whether or not the charges against Mitnick reflected the severity of his actions, and whether Shimomura was acting ethically in his pursuit. I have no insight into those two specific questions. I do know that nobody at Netcom had any issues with what happened once the fuller story came out and we all knew who the dude in the corner was; I also know it was obvious that Mitnick shouldn’t have access to those credit card numbers, even if he didn’t use them. Beyond that I’m not ready to form judgement. One of these days I’ll read the three key books on the events: Shimomura’s Takedown, written with John Markoff; Jonathan Littman’s The Fugitive Game, written in cooperation with Mitnick; and Mitnick’s autobiography, Ghost in the Wires.

Much much later I was doing the really dull mandatory security trainings at work, produced by a company called KnowBe4, and a pal said “hey, you know who’s behind that company, right?” That’s how I learned what Mitnick did with his life after getting out of prison. Cool enough, although man I think there’s room for a more engaging competitor in that space. You want those to be effective these days? Tailor them to be company-specific and actually voice clone your CEO, or train an LLM to emulate her email style. Make it feel realer. Mitnick was known for his social engineering, so that’d even be a cute homage as well as being effective. Hm, I’ve got spare time…

Nah.