On the evening of 2 November 1988, Robert Tappan Morris, a 23-year-old graduate student in computer science at Cornell, connected to a machine at the MIT Artificial Intelligence Laboratory and released a small self-replicating program written in C onto the network. Its core was famously terse, just 99 lines. He had written it, he later told investigators, to measure the size of the internet by quietly copying itself from computer to computer and counting where it had been.
It did not stay quiet. Within hours, administrators at Berkeley, MIT, Stanford, NASA Ames and dozens of other sites watched their VAX and Sun workstations slow to a crawl, spawn hundreds of processes, and fall over. By the next morning, roughly 6,000 of the estimated 60,000 machines then connected to the network were either crippled or disconnected, and the era in which computer security was a hobby had ended.
A worm, not a virus
What Morris released is now remembered as the Morris worm, and the distinction from a virus matters. A virus needs a host program and human help to spread. A worm is a standalone process that copies itself across a network under its own steam.
Morris’s program exploited three then-obscure weaknesses in Berkeley Unix: a buffer overflow in the fingerd daemon that reported who was logged in, a debug mode left enabled in the sendmail mail server, and weak passwords guessed from a built-in dictionary of 432 words plus the system’s own user list. Once inside a new machine, it would try to spread again.
The program’s fatal flaw was a design choice meant to make it harder to stop. Morris knew administrators might try to inoculate their systems by creating a fake copy of the worm to fool the real one into thinking a machine was already infected. To defeat that, he programmed the worm to reinfect a host anyway, one time in seven.
In practice, that ratio was catastrophic. Infected machines were hit again and again, each reinfection spawning new processes until the load averages climbed past 20, 50, 100 and the systems became unusable. The technical report by Eugene Spafford of Purdue, written in the weeks after the incident, remains the definitive dissection of how the code worked and where it broke.
The night the network went dark
Morris launched the program from the MIT machine at around half past eight in the evening. Within a couple of hours, workstations across the country were spawning runaway processes and grinding to a halt. By late that night, staff at Berkeley and MIT were reverse-engineering captured copies of the binary.
Just after midnight, a systems programmer named Andy Sudduth at Harvard posted an anonymous warning to a mailing list, saying there might be a virus loose on the internet, along with terse instructions on how to block it. The network was so congested that the message crawled and did little good.
Because the worm spread across the same network that administrators used to warn each other, defenders were flying blind. Some sites disconnected entirely from the ARPANET, which had the perverse effect of prolonging the outbreak: nobody could tell them the fix. A mailing list called phage, hastily set up at Berkeley, became the closest thing to a war room.
By the morning of 3 November, teams at Berkeley, MIT and Purdue had independently identified the three attack vectors and were circulating patches. By 8 November, the network was largely back.
Three days after the launch, on 5 November, The New York Times named Morris on its front page, tipped off by a family friend who had let slip the author’s initials to a reporter. The headline made the detail the press could not resist: the culprit was the son of Robert H. Morris Sr., the chief scientist at the National Security Agency’s National Computer Security Center. A longer family portrait followed on the paper’s front page on 11 November.
The birth of a field
Within weeks, the Defense Advanced Research Projects Agency had funded a coordination centre at Carnegie Mellon University’s Software Engineering Institute to respond to future incidents of this kind. The CERT Coordination Center, established in November 1988, was the first Computer Emergency Response Team, and the model has since been copied by nearly every country and large enterprise on Earth. Before the worm, there was no central place to report a security incident affecting the internet; after it, there was.
The legal consequences were also new. Morris was the first person tried under the 1986 Computer Fraud and Abuse Act. In January 1990 a jury in Syracuse convicted him of a felony; he was sentenced to three years’ probation, 400 hours of community service, and a fine of $10,050.
He appealed, arguing that he had not intended damage, only measurement. The Second Circuit disagreed. United States v. Morris stood for years as the precedent that intent to cause damage was not required under the statute, merely intent to gain unauthorised access.
What the worm actually taught
The technical lessons of November 1988 have never really gone away. Buffer overflows, the flaw that let the worm hijack fingerd, remained the most common class of serious security bug for the next two decades and are still exploited today.
Services shipped with debug modes enabled, the sendmail DEBUG hole, became a template for a category now called insecure defaults. And the dictionary attack on weak passwords is, in a slightly more sophisticated form, still how most account breaches begin.
More importantly, the worm forced a change in how the community thought about trust. Early internet software had been written by researchers for other researchers on the assumption that everyone on the network was known and broadly cooperative. Morris’s program demonstrated, in a single night, that this assumption no longer held.
It is not a coincidence that the years immediately after 1988 produced the first commercial firewalls, the first serious work on cryptographic authentication for network protocols, and the first widespread use of the word hacker in its modern, adversarial sense in the mainstream press.
The internet the worm exposed was small and legible in a way that is difficult to picture now. There were roughly 60,000 hosts on 2 November 1988; a recent count puts the number of people online at more than five billion.
The Domain Name System was two years old. There was no web. The idea that a single self-replicating program could, in a few hours, disrupt significant fractions of the whole was not obvious to anyone before Morris demonstrated it, and after him it became foundational.
Afterlives
In 1995 Morris co-founded the online store builder Viaweb with Paul Graham and Trevor Blackwell; Yahoo bought it in 1998 for about $49 million in stock and renamed it Yahoo Store. He finished his doctorate at Harvard in 1999. He later co-founded Y Combinator, the startup accelerator behind Airbnb, Dropbox and Stripe, and became a professor at MIT’s Computer Science and Artificial Intelligence Laboratory, the same institution whose machines he had used as a launch point in 1988. He rarely speaks publicly about the worm.
A 3.5-inch floppy disk holding a decompiled copy of the worm’s source code sits in the collection of the Computer History Museum in Mountain View. It is small, black, and unremarkable, the kind of artefact that gives no hint that the program it preserves taught an entire civilisation, over the course of a single week in November, that its new nervous system was fragile.
