In 1988, a 23-year-old Cornell graduate student named Robert Morris released a self-replicating program to measure the size of the internet — within hours it had crashed roughly 6,000 of the 60,000 machines then online, and computer security became a field

In 1988, a 23-year-old Cornell graduate student named Robert Morris released a self-replicating program to measure the size of the internet — within hours it had crashed roughly 6,000 of the 60,000 machines then online, and computer security became a field

On the evening of 2 November 1988, Robert Tappan Morris, a 23-year-old graduate student in computer science at Cornell, connected to a machine at the MIT Artificial Intelligence Laboratory and released a small self-replicating program written in C onto the network. Its core was famously terse, just 99 lines. He had written it, he later told investigators, to measure the size of the internet by quietly copying itself from computer to computer and counting where it had been.

It did not stay quiet. Within hours, administrators at Berkeley, MIT, Stanford, NASA Ames and dozens of other sites watched their VAX and Sun workstations slow to a crawl, spawn hundreds of processes, and fall over. By the next morning, roughly 6,000 of the estimated 60,000 machines then connected to the network were either crippled or disconnected, and the era in which computer security was a hobby had ended.

A worm, not a virus

What Morris released is now remembered as the Morris worm, and the distinction from a virus matters. A virus needs a host program and human help to spread. A worm is a standalone process that copies itself across a network under its own steam.

Morris’s program exploited three then-obscure weaknesses in Berkeley Unix: a buffer overflow in the fingerd daemon that reported who was logged in, a debug mode left enabled in the sendmail mail server, and weak passwords guessed from a built-in dictionary of 432 words plus the system’s own user list. Once inside a new machine, it would try to spread again.

The program’s fatal flaw was a design choice meant to make it harder to stop. Morris knew administrators might try to inoculate their systems by creating a fake copy of the worm to fool the real one into thinking a machine was already infected. To defeat that, he programmed the worm to reinfect a host anyway, one time in seven.

In practice, that ratio was catastrophic. Infected machines were hit again and again, each reinfection spawning new processes until the load averages climbed past 20, 50, 100 and the systems became unusable. The technical report by Eugene Spafford of Purdue, written in the weeks after the incident, remains the definitive dissection of how the code worked and where it broke.

The night the network went dark

Morris launched the program from the MIT machine at around half past eight in the evening. Within a couple of hours, workstations across the country were spawning runaway processes and grinding to a halt. By late that night, staff at Berkeley and MIT were reverse-engineering captured copies of the binary.

Just after midnight, a systems programmer named Andy Sudduth at Harvard posted an anonymous warning to a mailing list, saying there might be a virus loose on the internet, along with terse instructions on how to block it. The network was so congested that the message crawled and did little good.

Because the worm spread across the same network that administrators used to warn each other, defenders were flying blind. Some sites disconnected entirely from the ARPANET, which had the perverse effect of prolonging the outbreak: nobody could tell them the fix. A mailing list called phage, hastily set up at Berkeley, became the closest thing to a war room.

By the morning of 3 November, teams at Berkeley, MIT and Purdue had independently identified the three attack vectors and were circulating patches. By 8 November, the network was largely back.

Three days after the launch, on 5 November, The New York Times named Morris on its front page, tipped off by a family friend who had let slip the author’s initials to a reporter. The headline made the detail the press could not resist: the culprit was the son of Robert H. Morris Sr., the chief scientist at the National Security Agency’s National Computer Security Center. A longer family portrait followed on the paper’s front page on 11 November.

The birth of a field

Within weeks, the Defense Advanced Research Projects Agency had funded a coordination centre at Carnegie Mellon University’s Software Engineering Institute to respond to future incidents of this kind. The CERT Coordination Center, established in November 1988, was the first Computer Emergency Response Team, and the model has since been copied by nearly every country and large enterprise on Earth. Before the worm, there was no central place to report a security incident affecting the internet; after it, there was.

The legal consequences were also new. Morris was the first person tried under the 1986 Computer Fraud and Abuse Act. In January 1990 a jury in Syracuse convicted him of a felony; he was sentenced to three years’ probation, 400 hours of community service, and a fine of $10,050.

He appealed, arguing that he had not intended damage, only measurement. The Second Circuit disagreed. United States v. Morris stood for years as the precedent that intent to cause damage was not required under the statute, merely intent to gain unauthorised access.

What the worm actually taught

The technical lessons of November 1988 have never really gone away. Buffer overflows, the flaw that let the worm hijack fingerd, remained the most common class of serious security bug for the next two decades and are still exploited today.

Services shipped with debug modes enabled, the sendmail DEBUG hole, became a template for a category now called insecure defaults. And the dictionary attack on weak passwords is, in a slightly more sophisticated form, still how most account breaches begin.

More importantly, the worm forced a change in how the community thought about trust. Early internet software had been written by researchers for other researchers on the assumption that everyone on the network was known and broadly cooperative. Morris’s program demonstrated, in a single night, that this assumption no longer held.

It is not a coincidence that the years immediately after 1988 produced the first commercial firewalls, the first serious work on cryptographic authentication for network protocols, and the first widespread use of the word hacker in its modern, adversarial sense in the mainstream press.

The internet the worm exposed was small and legible in a way that is difficult to picture now. There were roughly 60,000 hosts on 2 November 1988; a recent count puts the number of people online at more than five billion.

The Domain Name System was two years old. There was no web. The idea that a single self-replicating program could, in a few hours, disrupt significant fractions of the whole was not obvious to anyone before Morris demonstrated it, and after him it became foundational.

Afterlives

In 1995 Morris co-founded the online store builder Viaweb with Paul Graham and Trevor Blackwell; Yahoo bought it in 1998 for about $49 million in stock and renamed it Yahoo Store. He finished his doctorate at Harvard in 1999. He later co-founded Y Combinator, the startup accelerator behind Airbnb, Dropbox and Stripe, and became a professor at MIT’s Computer Science and Artificial Intelligence Laboratory, the same institution whose machines he had used as a launch point in 1988. He rarely speaks publicly about the worm.

A 3.5-inch floppy disk holding a decompiled copy of the worm’s source code sits in the collection of the Computer History Museum in Mountain View. It is small, black, and unremarkable, the kind of artefact that gives no hint that the program it preserves taught an entire civilisation, over the course of a single week in November, that its new nervous system was fragile.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Make Tech Easier Editorial Team Avatar

Read next

In July 2026, Psy’s Gangnam Style passed six billion YouTube views, fourteen years after its horse-riding dance became the platform’s first billion-view video and long after engineers had replaced a counter designed to stop at 2,147,483,647
Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
A Japanese man named Jiroemon Kimura, who lived to 116, was born in 1897 when Queen Victoria still ruled and died in 2013, meaning a single human life personally overlapped with the invention of the airplane, the atomic bomb, the internet, and Instagram
The Hollywood sign originally read HOLLYWOODLAND when it was built in 1923 as a real estate advertisement for a housing development, and it was only meant to stand for 18 months, but nobody ever got around to taking it down and the city eventually adopted it as a landmark
Almost all of the world’s internet traffic does not travel by satellite but through fibre-optic cables lying on the ocean floor, a hidden web of wires crossing the deepest parts of the sea to connect the continents.
People who flip their phone face down on every table aren’t being secretive. They figured out that staying interruptible meant handing their time to whoever rang first
Twitch vs. Facebook Gaming vs. YouTube Gaming: What’s the Best Live Game Streaming Platform?