Steve Gibson
Abstract
Steve Gibson (born 1955) has run a one-man software company from Laguna Hills, California, since 1985, writing everything in assembly language, and has been the personal-computer world’s loudest amateur security researcher for most of that time. SpinRite (1988) recovered data from failing hard disks and paid for everything else. ShieldsUP! (1999) let anyone test whether their PC was visible to the Internet and told millions of people for the first time that it was. OptOut (1999–2000) was one of the first programs to remove what he defined, in the sense the word now has, as spyware. He was attacked for two weeks in 2001 by a thirteen-year-old with a botnet, wrote it up, and warned that Windows XP’s raw sockets would make such attacks universal, a prediction the industry mocked and then quietly agreed with. Since 2005 he has explained security to a large audience every week on Security Now!, which passed a thousand episodes in 2024.
Berkeley and the Light Pen
Steve Maury Gibson was born in Dayton, Ohio, on March 26, 1955, and grew up in California. At fifteen he had a job at the Stanford Artificial Intelligence Laboratory; he studied electrical engineering and computer science at Berkeley. In 1980 he worked on copy protection at California Pacific Computer, the publisher that sold Richard Garriott’s Akalabeth (see Richard Garriott), and from 1981 to 1983 ran Gibson Laboratories, whose product was a light pen for the Apple II and the Atari 8-bit machines: point at the screen and the software knew where. It sold, and then it did not, and he moved to software.
SpinRite
Gibson Research Corporation was founded in Laguna Hills in 1985, and its product since 1988 has been SpinRite, a program that reads a hard disk sector by sector, rewrites each one with fresh magnetic signal, and uses the drive’s own error-correction and repeated reads to recover data from sectors that have begun to fail. It is written entirely in x86 assembly, which Gibson says is why it is small, fast, and works on machines that will boot nothing else, and it has been sold, updated and supported by him alone for nearly forty years. It funded the rest, which has been free. From 1986 to 1993 he also wrote the “Tech Talk” column in InfoWorld, in which he took public positions on the industry’s engineering that the trade press’s editors usually did not, and in 1998 his diagnosis of the Iomega Zip drive’s “click of death” was more useful than the manufacturer’s (see The Click of Death).
ShieldsUP! and Spyware
By 1999 home PCs were on always-on cable and DSL connections, running Windows with file sharing switched on by default, and their owners had no idea. ShieldsUP!, a web page on grc.com launched that year, scanned the visiting computer’s ports from outside and reported, in plain language, whether it was answering the Internet’s knocks. For a large share of visitors the answer was yes, and the page, which has run tens of millions of scans, did more than any product to create the market for personal firewalls.
In late 1999 Gibson found that a program on his own machine was reporting home over his Internet connection without asking. He wrote a definition, software that uses a user’s connection in the background without their knowledge or explicit permission, attached it to the word spyware, which had been used loosely since 1995 and which Zone Labs was also using that year, and released OptOut, a free program that found and removed the Aureate/Radiate advertising component then bundled into hundreds of shareware programs. It was among the first anti-spyware tools, alongside Lavasoft’s Ad-Aware, and an industry followed. The word, in the meaning he fixed, is now in every dictionary; the history of the malware that followed is in The Antivirus Industry.
The Attack
In May 2001 grc.com was knocked off the Internet for most of two weeks by a distributed denial-of-service attack from several hundred infected Windows machines. Gibson traced it, made contact with its author, who turned out to be thirteen, and published the whole exchange as “The Strange Tale of the Denial of Service Attacks Against GRC.com”, one of the first detailed public accounts of a botnet from the receiving end. He drew a conclusion: Windows XP, then in beta, was about to give every home PC full “raw socket” access, which would let infected machines forge the source addresses of their packets and make such attacks untraceable, and he asked Microsoft to remove it. Microsoft declined; the security profession, which regarded Gibson as a self-promoter who had discovered things it had known for years, said the feature was irrelevant because attackers had other tools. Windows XP shipped with raw sockets in October 2001; Blaster, Sasser and the botnet era followed; and Service Pack 2 in 2004 restricted the feature. His 2006 claim that a flaw in Windows Metafile handling had been an intentional backdoor was wrong and he withdrew it.
Security Now!
In August 2005 Leo Laporte, the broadcaster who had built the TWiT podcast network, asked Gibson to do a weekly show. Security Now! has run every week since, two hours of Gibson explaining the week’s vulnerabilities, the mathematics of cryptography, how TCP works, why passwords fail, and whatever he has been building, to an audience that includes a large fraction of the people who administer the systems he describes. Episode 1,000 aired in November 2024, well past the number at which he had said he would stop (see The Podcast Revolution). His side projects have kept coming from the same office: Password Haystacks (2011), an argument about password length; SQRL (2013–2019), a login scheme that replaces passwords with a public key held by the user’s own device, which nobody adopted and which anticipated the passkeys everyone now uses; and DNS Benchmark and a dozen other free utilities, all in assembly, all his.
📚 Sources
- Steve Gibson (computer programmer) — Wikipedia
- Spyware — Wikipedia, history of the term (the 1995 Usenet use, Zone Labs in 2000, Gibson’s definition and OptOut)
- Gibson, Steve — “The Strange Tale of the Denial of Service Attacks Against GRC.com”, grc.com, 2001 (archived copy; the page has since been removed from grc.com)
- Gibson, Steve — “Windows XP Raw Sockets”, grc.com, 2001 (archived copy)
- ShieldsUP! — grc.com
- SpinRite — grc.com
- Security Now! — TWiT.tv
- Steve Gibson — attrition.org errata page (the critics’ case)