What was the case all about?
In November 1988, a Cornell graduate student wrote a program that led to unprecedented interruption of computers around the country.
After unleashing the worm onto ARPANET, from an MIT computer, it is estimated that the worm infected atmost 6000 comouters (according to Legal Affairs). At that time, 6,000 was about 1/10th of all internet connected computers worldwide.
Robert had created the worm in an attempt to get a measurement of how big the ARPANET was. He claimed that there was no malicious intent behind the worm’s creation, and this was believed because of his fast actions as soon as the infections got out of hand. The issue was a coding misstep.
One method it used to attempt access was to log in using what we would now call a dictionary attack; that is, it had an embedded list of "popular" passwords. Robert was based at Cornell, but he started the worm going from a computer at MIT to attempt to hide its source. The code also attempts to thwart one possible mechanism of stopping it. All this demonstrates that even if there is no payload, clearly Morris knew he was breaking surreptitiously into other people's computers whether they likes it or not. There's no way Morris was young and inexperienced enough to mistake the fact that what he was doing was wrong.
The source code also shows that Morris attempted to keep the spread of the worm under control, but he was more confident in his code than he should have been. Bugs in the code caused it to crash many systems, basically all SunOS systems, and to execute more than once on many other systems, devouring system resources.
Morris had overlooked two factors:
The software replicated at an erratic rate, far beyond the intentions of Robert.
The software did not check a system for previous downloads, before downloading itself onto a system.
This caused thousands of computers to slow down to such a speed, they were virtually unusable. Morris, Jr. and his colleague attempted to contact system administrators around the nation with instructions on how to disarm the worm, but they’re efforts were too late.
Who were the parties involved?
Robert Tappan Moris, Jr. The then-23-year-old graduate student from Cornell University, NY, USA.
Paul Graham. A colleague of Morris in Cornell University.
Andrew Sudduth. A staff member at Harvard University.
Did any prosecution result? If so, what were their outcomes?
Yes. In 1990, Morris was convicted by a jury. Sentencing guidelines recommended 15 to 21 months in prison. Instead, Judge Howard Munson sentenced Morris to serve three years of probation, to do 400 hours of community service and to pay a $10,000 fine.
Morris's lawyers tried to convince the courts that Morris's conduct didn't fall within the definition of the crime he was charged with. The CFAA made it a felony to intentionally gain unauthorized access to a "federal interest computer" and to cause damage as a result. Morris's legal team argued that the statute required the government to prove that both the access and the damage were intentional. The judge rejected that argument, holding that the government needed only to show that Morris intended to gain unauthorized access, not that he intended to cause harm. Morris's arguments were rejected by an appeals court in 1991.
What ethical issues are raised by the case?
The opinions of the computer science community, particularly the student community, vary considerably from regarding the launching of the worm as an heroic act that heightened awareness of computer security; to regarding it as an immoral and possibly illegal act that caused millions of dollars of damage. The consensus, however, appears to be that the act was clearly wrong and under no circumstances should have been carried out. At the same time, the community appears to recognize that there are few clear guidelines or applicable laws in this regard.
Regardless of legal and policy considerations, the basis for considering the act to be wrong is that it presumed upon the time of countless individuals without their consent. As such, it was a selfish act.
It was also a juvenile act. In an adult community, one does not need policies or laws or procedures to know that acts have consequences and that one is largely responsible for the consequences of ones' acts; or that those consequences should be assessed before initiating the acts.
There is also the matter of whether it is wrong to intrude into other peoples’ computer accounts without their consent. Since, in this case, there appears to have been no evidence of any intent to cause damage, this particular incident has been likened to the act of trespassing in someone's house, rather than breaking and entering. The former is regarded generally as a misdemeanor in law rather than a felony, as is the act of usurping someone's automobile without their consent, taking it for a joyride, and returning it undamaged.
There is also the matter of reasonable expectation of privacy. Passwords on computers are not used to guarantee security against determined intruders. They are there to Page 40 41 serve notice to one and all that this is private space and entry is unwelcome without possession of a search warrant. People generally do not lock their houses with the fortitude of Fort Knox — the locks used are sufficient to deter all but determined intruders and exist to serve clear warning: "Keep Out".










