Robert Tappan Morris and the First Internet Worm
Abstract
On the evening of November 2, 1988, a 22-year-old Cornell graduate student named Robert Tappan Morris released a self-replicating program onto the internet. He meant it to be a quiet experiment, a way to measure how big the network was by counting the machines it could reach. Instead, a single mistake in his replication logic turned it into the first internet worm to cause widespread damage: it reinfected machines over and over until they buckled under the load, knocking an estimated 10% of the roughly 60,000 computers then connected to the internet out of service. The cleanup gave rise to the first Computer Emergency Response Team. The prosecution made Morris the first person convicted under the 1986 Computer Fraud and Abuse Act. And in one of the field’s stranger second acts, the man who wrote the worm went on to become an MIT professor and a co-founder of Y Combinator, the most influential startup incubator in technology. His worm is the dividing line between the internet as a trusting research commons and the internet as a place that needs defending.
A Computing Bloodline
Robert Tappan Morris was born on November 8, 1965, into one of computing’s quiet dynasties. His father, Robert Morris Sr., was a Bell Labs cryptographer who co-wrote early Unix, designed the password-hashing scheme that protected Unix login credentials, and later became chief scientist at the National Computer Security Center, the public-facing arm of the NSA. The younger Morris grew up around Unix internals the way other children grow up around a family business. By the time he reached graduate school at Cornell in 1988, he understood the network’s plumbing (its mail transport, its remote-login trust relationships, its daemons) at a level few people anywhere matched.
That fluency is the necessary background to what happened next. The worm was not the work of an outsider guessing at vulnerabilities. It was the work of an insider who knew exactly where the soft spots were.
The Worm
Morris’s stated goal was modest and even scholarly: he wanted to gauge the size of the internet by writing a program that would copy itself from machine to machine and tally where it landed. To spread, the program exploited three weaknesses he knew well:
- a debug mode left enabled in the
sendmailmail-transfer program, which let a remote sender execute commands; - a buffer overflow in the
fingerddaemon (the service that answered “who is logged in” queries), one of the first famous uses of that technique in the wild; - and weak or guessable passwords on the
rexec/rshremote-login services, which Morris’s code attacked with a built-in dictionary and the network’s web of mutual trust between machines.
To keep the experiment from being traced back to Cornell, Morris released the worm from a machine at MIT on the night of November 2, 1988.
The Fatal Reinfection Bug
Morris had anticipated that system administrators might try to defeat his census by running fake copies of the worm. To prevent that, the worm was supposed to check whether a machine was already infected and, if so, not infect it again. But a program that always declined to reinfect could be neutralized trivially. So Morris added a rule: even if a machine claimed to be infected, the worm would reinfect it anyway one time in seven. He badly misjudged the math. With the worm spreading fast across a densely interconnected network, machines were hit again and again, each new copy spawning more processes, until infected computers ground to a halt under their own load. The program that was meant to count the internet instead denial-of-serviced it. The damage was an accident of a single probabilistic constant.
Within hours, machines across the internet were collapsing. Administrators, unable to diagnose the cause and unable to easily communicate (mail servers were among the casualties), began cutting their sites off from the network entirely, which slowed the spread but also fractured the very channels needed to coordinate a response. Roughly 6,000 machines were significantly affected, on the order of 10% of the ~60,000 hosts then on the internet. Damage estimates were notoriously soft, ranging from a few hundred to tens of thousands of dollars per machine in lost productivity and cleanup, with aggregate figures cited as high as $10 million.
Morris, alarmed at what he had unleashed, asked a friend to post an anonymous message explaining how to kill the worm and apologizing, but the network was so degraded that the message did not propagate in time to help.
CERT and the End of the Trusting Internet
The most lasting institutional consequence of the worm was defensive. In the immediate aftermath, DARPA funded the creation of the CERT Coordination Center at Carnegie Mellon University, the first Computer Emergency Response Team, a model since copied by governments and companies worldwide. Before November 1988, the internet had no standing body whose job was to coordinate the response to a security incident. After it, that absence was obviously untenable.
More broadly, the worm punctured a culture. The research internet had been built by and for people who trusted one another; sendmail’s debug mode and the rsh trust model existed because, in a community of colleagues, convenience mattered more than defense. The Morris Worm demonstrated, vividly and at scale, that a single actor could weaponize that trust. It is the conventional marker for the moment the network stopped being a pure commons and started being something that had to be secured.
The First CFAA Conviction
Morris was identified quickly, partly because his father’s prominence and his own known activities narrowed the field, and partly because journalists, notably John Markoff at The New York Times, connected him to the worm within days. He was indicted in 1989 under the Computer Fraud and Abuse Act of 1986, a then-new statute that had never been tested at trial. Morris became the first person convicted under the CFAA.
In December 1990 he was sentenced not to prison but to three years of probation, 400 hours of community service, and a fine of $10,050 plus the costs of his supervision. The relative leniency reflected the court’s acceptance that Morris had not intended to cause damage. But the conviction stood, and it set the template for three decades of computer-crime prosecution built on the CFAA’s central, elastic concept of “unauthorized access.”
Myth: Morris released the worm “to expose security flaws” / it was the first computer worm ever
Two things get garbled. First, Morris’s own account (accepted by the court) was that he was trying to measure the internet’s size, not to vandalize it or make a security statement; the damage came from a bug, not a payload. Second, the Morris Worm was not the first self-replicating program (academic worms and the earlier “Creeper” experiment predate it), but it was the first to spread across the internet and cause widespread real-world disruption, which is why it is remembered as a first. See Myths and Misconceptions.
The Second Act
What makes Morris singular among the figures in this section is that his crime was a footnote to a distinguished career, not the other way around. After completing his sentence, he co-founded the online-store software company Viaweb with Paul Graham in 1995; Yahoo bought it in 1998 for stock worth roughly $49 million, and it became Yahoo Store. Morris earned a PhD at Harvard in 1999 and joined the faculty of MIT’s Computer Science and Artificial Intelligence Laboratory, receiving tenure in 2006. In 2005 he and Graham, with Jessica Livingston and Trevor Blackwell, founded Y Combinator, the seed-stage startup accelerator that would help launch Airbnb, Dropbox, Stripe, and hundreds of others. In 2019 he was elected to the National Academy of Engineering.
The arc is its own kind of commentary. The act that made Morris briefly the most notorious programmer in America (and that gave the security industry its founding trauma) barely dented a life otherwise spent inside the field’s most respectable institutions. The worm endured as a warning; its author endured as an architect of how the modern technology industry is funded.
📚 Sources
- The Morris Worm — FBI History
- Robert Tappan Morris — Wikipedia
- Morris worm — Wikipedia
- United States v. Morris (1991), 928 F.2d 504 — the appellate CFAA ruling
- Spafford, Eugene H.: “The Internet Worm Program: An Analysis” (Purdue Technical Report, 1988)
- CERT Coordination Center — Carnegie Mellon SEI
- Image: Robert Tappan Morris.jpg by Trevor Blackwell (CC BY-SA 3.0), via Wikimedia Commons