Kevin Poulsen: The Phone Hack, the Porsche and the Newsroom
On the morning of June 1, 1990, Los Angeles radio station KIIS-FM played "Escapade," then "Love Shack," then Prince's "Kiss," and every listener in town grabbed a phone. The 102nd caller would win a Porsche 944 S2.
A man calling himself Michael B. Peters made that call, because he'd just seized all 25 of the station's phone lines and locked everyone else out. His real name was Kevin Poulsen, and he was the most wanted hacker in America.
By day, Poulsen had tested Pentagon computer security for a defense contractor. By night, as Dark Dante, he roamed Pacific Bell's switches at will. The strangest part of his story isn't the Porsche, the espionage charge or the record sentence, but what he did when he got out.
Kevin Poulsen at a Glance
- Born in Pasadena in 1965 and raised in North Hollywood, Poulsen found his people on Los Angeles party lines at 13 and taught himself the phone system from a TRS-80.
- At 17, under the handle Dark Dante, he broke into ARPAnet through UCLA. The FBI came calling, but he was a minor and no charges were filed.
- SRI International hired him in 1985 with a security clearance to test military computer security, while he kept breaking into Pacific Bell offices on the side.
- A 1988 storage locker he forgot to pay for spilled his secrets, and a 19-count indictment followed in November 1989. He'd already vanished.
- As a fugitive he rigged radio contests, winning two Porsches, $50,000 in cash and trips to Hawaii, before NBC's Unsolved Mysteries and a supermarket stakeout ended his run in April 1991.
- Charged under an espionage statute and held for years without trial, he pleaded guilty to seven counts in 1994 and in April 1995 drew 51 months, then the longest hacker sentence ever.
- Released in June 1996 and banned from the internet for three years, he became a reporter, joining SecurityFocus in 2000 and Wired in 2005.
- His code caught sex offenders on MySpace, his sources broke the Chelsea Manning story, he wrote Kingpin, and with Aaron Swartz he built what became SecureDrop.
The Life of Kevin Poulsen
Poulsen's Early Years
Kevin Lee Poulsen was born in Pasadena, California, in 1965 and grew up in North Hollywood, the son of an auto mechanic and a schoolteacher who had no idea what he did with the TRS-80 they bought him.
Like a lot of shy, gifted kids of his generation, he found human contact through the telephone. On the jammed Los Angeles party lines of the late 1970s, a 13-year-old Poulsen talked Tolkien for hours with a girl his age, then pedaled over on his bicycle and could barely look her in the eye.
The phone system itself soon became the obsession. He never finished high school, but as a teenager he burrowed into Pacific Bell's switching networks until, as a federal indictment later put it, he could create, change and maintain phone service at will.
Dark Dante Meets ARPAnet
In 1983, at 17 and now calling himself Dark Dante, Poulsen teamed up with an older hacker to break into ARPAnet, the Pentagon-organized network linking researchers and defense contractors. The FBI showed up, but he was a minor, so no charges were filed.
Then came the twist that still astonishes people. In 1985, SRI International, the Menlo Park think tank and government contractor, hired the teenage intruder as an assistant programmer, gave him a security clearance and put him to work on military contracts, including a test of Pentagon computer security.
By day, Poulsen hacked to protect government secrets. By night, prosecutors would later say, he turned into something closer to a werewolf.
The Storage Locker
Between 1985 and 1988, according to the Justice Department, Poulsen burglarized or talked his way into Bay Area phone company offices with fake IDs, collecting equipment and the access codes that let him monitor calls and alter Pacific Bell records.
It all unraveled over an unpaid bill. In 1988 the owner of a Menlo Park storage facility snipped the padlock on Poulsen's locker and found an extraordinary cache of telephone gear, along with a set of secret orders from a military exercise called Caber Dragon 88.
In November 1989, a San Jose grand jury returned a 19-count indictment naming Poulsen and two associates, including his former roommate Mark Lottor. By then Poulsen had slipped away to Los Angeles, inventing new aliases at will.
Win a Porsche by Friday
Being a fugitive is expensive, and Poulsen had a plan. KIIS-FM was giving away a Porsche a week, worth about $50,000 each, to the 102nd caller after a particular sequence of songs, and he and his friends could make the phone lines do whatever they wanted.
On June 1, 1990, the moment "Kiss" hit the air, he took over the station's 25 lines, blocked every call but his own and dialed in as caller 102. By the time it was over, he and his accomplices had won two Porsches, two $20,000 giveaways, a $10,000 prize and at least two trips to Hawaii from KIIS-FM, KPWR-FM and KRTH, according to prosecutors.
Poulsen was also hunting his hunters. In August 1989 he'd broken into a Pacific Bell computer to look up the FBI's wiretaps on him, and prosecutors said he could compromise the Bureau's undercover lines and front businesses.
Unsolved Mysteries
NBC's Unsolved Mysteries aired his story, and a tip followed. A Pacific Bell investigator staked out a suburban Los Angeles supermarket where the fugitive shopped, and in April 1991, after 17 months on the run, Poulsen was arrested.
He was held without bail, and the case got heavier. In December 1992, prosecutors in San Jose added a charge of gathering defense information over the Caber Dragon orders, making Poulsen one of the first hackers ever charged under an espionage statute.
Civil libertarians were appalled. Mike Godwin of the Electronic Frontier Foundation called the move "brain-damaged," and Poulsen's lawyer argued the orders had been declassified by the time his client had them.
Jonathan Littman's 1993 Los Angeles Times Magazine profile, The Last Hacker, captured a man who'd taken an innocent obsession over the line, and a government determined to make an example of him.
The Longest Hacker Sentence
In June 1994, Poulsen pleaded guilty in Los Angeles to seven counts of conspiracy, fraud and intercepting wire communications over the contest scheme. Asked why, he answered: "Because I am guilty."
On April 10, 1995, a federal judge sentenced him to 51 months in prison, more than $58,000 in restitution and three years of supervised release during which he couldn't touch a computer without his probation officer's permission. The guidelines called for three years; the judge added 15 months for the magnitude of the crimes.
"The sentence was the longest ever doled out to a computer hacker," said Assistant US Attorney David Schindler. The national-security charges, in Poulsen's own words, were ones he was cleared of.
Having been in custody since 1991, Poulsen walked out of the federal prison in Dublin, California, on June 4, 1996, after a little over five years inside, and bought a change of clothes at a church thrift store. He later wrote that he was the first American released from prison with a ban on using the internet.
From Hacker to Reporter
Poulsen's first magazine feature appeared in Wired in 1998, and in 2000 he joined the security news site SecurityFocus as editorial director. In 2005 he moved to Wired, where he founded the Threat Level blog that won the 2008 Knight-Batten Award for innovation in journalism.
His best stories came from code. In 2006 he wrote a script that scoured MySpace's 100 million profiles for registered sex offenders, confirmed 744 of them and watched police arrest one, a serial child molester caught soliciting boys on the site. MySpace changed its policies and Congress wrote legislation.
In 2010 a May profile Poulsen wrote about the hacker Adrian Lamo was read by an Army analyst in Iraq, who contacted Lamo and confessed to leaking to WikiLeaks. On June 6, 2010, Poulsen and Kim Zetter broke the news of Chelsea Manning's arrest, and the chat logs Lamo handed over became the most argued-over documents in journalism that year.
In 2011 he published Kingpin, the story of the hacker who took over the carding underground. And with Aaron Swartz he designed DeadDrop, an anonymous submission system for sources that The New Yorker launched as Strongbox in May 2013 and the Freedom of the Press Foundation relaunched as SecureDrop that October.
Poulsen Today
SecureDrop now runs in newsrooms around the world, which is a strange legacy for a man once banned from going online. Poulsen went on to The Daily Beast as a senior national security correspondent, and in December 2019 joined the Wall Street Journal's investigations team.
His bio these days reads simply "journalist/technologist." He lives in San Francisco with his wife and two children, and he still writes about the people who do what he used to do.
Kevin Poulsen: Caller Number 102
There's a version of this story where the Porsche is the punchline, a cocky kid outsmarting a radio station. The real one is darker and better: a hacker so good that the defense industry hired him, so reckless that it charged him with espionage, and so stubborn that he served the longest sentence anyone had ever drawn for the crime.
What he built afterward matters more. The reporter who hunted predators with a script, broke the Manning story and gave whistleblowers a safe door is the same person who once wiretapped his own pursuers.
Poulsen made the 102nd call once. He's spent the decades since picking up when sources dial in.
QUOTE:
"Amateurs hack systems, professionals hack people."