Technology · 2026-08-27 · 7 MIN

One in Seven

In November 1988 a graduate student's program walked through four unlocked doors and stopped several thousand computers. It deleted nothing. The number everybody quotes for how many it reached is not a number anyone actually counted.

At about half past nine on the evening of Friday 4 November 1988, the Washington Post telephoned the Cornell news office. That call was how the university found out that one of its graduate students might have written the program which had spent the previous two days stopping computers across the United States.

The student was Robert Tappan Morris, in his first term of a doctorate in computer science. His father, also Robert Morris, had spent twenty six years at Bell Labs, where he worked on the password system and the encryption functions that Unix used, and by 1988 he was chief scientist at the National Security Agency's National Computer Security Center. One of the four ways his son's program got into a machine was by guessing passwords.

What it was

The program was released on the evening of 2 November from a computer at MIT, a few hundred miles from where its author was enrolled. The first machine it took was a VAX 11/750 in the same building.

It was a worm rather than a virus, and the difference matters. A virus attaches itself to a program and generally waits for a person to run it. A worm carries everything it needs and waits for nobody. This one moved between VAX and Sun-3 machines running Berkeley Unix, which in 1988 was most of what the network was made of.

It had four ways in. Sendmail, the program that handled mail, shipped with a debugging mode left switched on that let a distant machine hand it commands. The finger daemon, which answered the question of who was logged in, could be given more characters than the library routine collecting them expected, at which point the surplus ran past the end of its box and became instructions. The rsh and rexec services let machines that had been told to trust each other skip the password step entirely. And failing all that, the worm tried a list of likely passwords it carried with it, 432 words, most of them ordinary English words or proper names.

None of this was secret knowledge. Cornell's inquiry noted afterwards that at least one of the flaws was already known to a number of people, as was the method behind others.

The one in seven

Morris did not intend the thing to pile up. Each machine it reached was asked whether a copy was already running there, and if the answer came back yes it was supposed to stop. He also assumed that administrators would work this out and simply answer yes to keep it away, so he told it to ignore the answer one time in seven.

The Second Circuit put the consequence plainly. "Morris underestimated the number of times a computer would be asked the question, and his one-out-of-seven ratio resulted in far more copying than he had anticipated."

Machines filled up with copies of the worm competing for the processor until they could do nothing else. It destroyed nothing. Cornell's commission recorded that the worm did not modify or destroy any system or user files or data, and Donn Seely, taking the code apart at the University of Utah, found it removed only the files it had created itself. The damage was that thousands of computers were too busy to be used and the people who ran them had to drop everything.

How many

The received figure is six thousand machines, about ten per cent of the internet. It is worth knowing where that does not come from. Cornell's commission wrote that several thousand computers were infected and said in terms that it "has not systematically attempted to estimate the exact number infected", adding that many thousands more had to be tested and patched whether they were infected or not. John Markoff, who covered it at the time, later put it as more than ten per cent of roughly fifty thousand machines. The appeal court heard evidence of costs at individual sites ranging from 200 dollars to more than 53,000.

Most computers were clear within 48 to 72 hours. Getting there was harder than it should have been, because administrators cut their sites off the network to stop the worm arriving, which also stopped the fixes arriving. Teams at Berkeley and MIT ended up passing code to each other through people they happened to know.

The first conviction

The Computer Fraud and Abuse Act had been on the books since 1986 and had never been used for anything like this. Morris was the first person convicted under it. The argument on appeal in 1991 was about what the government had to prove: whether it needed to show he intended to cause damage, or only that he intended access he had no authorisation for. The court held it was the second, and upheld the conviction. He was sentenced to three years of probation, 400 hours of community service, a fine of 10,050 dollars, and the costs of his own supervision.

What Cornell concluded

The commission reported in February 1989. Morris had worked alone, nobody at Cornell knew beforehand, and he had made "only minimal efforts to halt the worm once it had propagated, and did not inform any person in a position of responsibility as to the existence and content of the worm."

On the question everyone wanted answered, whether this was brilliance, the commission was unimpressed. "Although the worm was technically sophisticated, its creation required dedication and perseverance rather than technical brilliance."

Then it reached for an analogy, and it is the best thing in the report. "This was not a simple act of trespass analogous to wandering through someone's unlocked house without permission but with no intent to cause damage. A more apt analogy would be the driving of a golf cart on a rainy day through most houses in a neighborhood. The driver may have navigated carefully and broken no china, but it should have been obvious to the driver that the mud on the tires would soil the carpets and that the owners would later have to clean up the mess."

The same passage makes the point that gets forgotten. A community of scholars, it said, should not have to build walls as high as the sky to protect a reasonable expectation of privacy, because such walls would block the free movement of information just as effectively as they blocked an intruder. The network ran on trust between people doing research, and that had produced a great deal.

After

DARPA asked the Software Engineering Institute at Carnegie Mellon to set up a computer emergency response team. That became CERT, run by Richard Pethia from 1988 until 2016, and every national response team since is built on the same idea: a neutral party that competing vendors can all talk to about the same hole.

Morris finished his doctorate at Harvard and is now a professor of computer science at MIT, which is the institution whose computer he borrowed to let the worm out.

Sources

  • Ted Eisenberg and others, Communications of the ACM, "The Cornell Commission: On Morris and the Worm" (Morris working alone; the worm not modifying or destroying files or data; several thousand computers infected and the commission's statement that it had not attempted to estimate the number; the minimal efforts to halt it; the finding on dedication and perseverance rather than technical brilliance; the golf cart analogy and the walls as high as the sky passage; and the Washington Post telephoning the Cornell News Service at about 9.30 p.m. on 4 November 1988).
  • United States Court of Appeals for the Second Circuit, "United States v. Robert Tappan Morris, 928 F.2d 504" (the release from a computer at MIT on 2 November 1988; the four methods of entry; the one in seven ratio and the court's finding on why it went wrong; costs per installation of 200 dollars to more than 53,000; the intent question on appeal; and the sentence of three years probation, 400 hours of community service, a 10,050 dollar fine and the costs of supervision).
  • Donn Seely, University of Utah, "A Tour of the Worm" (the 432 word password list; the worm running on VAX and Sun-3 machines under Berkeley Unix; the first infection at MIT; the one in seven rule in the code; and the worm removing only the files it created itself).
  • J. Reynolds, RFC 1135, "The Helminthiasis of the Internet" (the worm unleashed on the evening of 2 November 1988; the sendmail debug route and the buffer overflow through the gets routine in fingerd; and most computers being cleared within 48 to 72 hours, with Berkeley and MIT exchanging code informally).
  • John Markoff, New York Times News Service, "Robert Morris, a pioneer in computer security, dies at 78" (Morris senior's work at Bell Labs on the Unix password system and encryption functions; his post as chief scientist of the NSA's National Computer Security Center; and the estimate of more than ten per cent of roughly fifty thousand computers).
  • Carnegie Mellon University Software Engineering Institute, "Fostering Growth in Professional Cyber Incident Management" (DARPA asking the SEI to establish a computer emergency response team after the November 1988 worm, and its role as a neutral third party able to work with competing vendors).
  • Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, "Robert Morris" (his present professorship).

Delvewire