Within Early Insecurity
Why One Trusted Computer Could Unlock Many More
Early networks often treated traffic from recognized machines as safer, allowing a captured host to approach systems that blocked direct outsiders.
On this page
- How early networks distinguished internal traffic
- Why administrator access changed an attacker's position
- How trusted pathways enabled lateral movement
Page outline Jump by section
Introduction
One of the most important reasons early government network intrusions could spread beyond a single computer was that many organisations treated their own internal networks as inherently more trustworthy than the public internet. Once an attacker gained administrator access to one recognised machine, that computer often occupied a very different security position from an unknown external system. Instead of repeatedly confronting strong perimeter controls, the attacker could communicate from a location that many internal systems already regarded as relatively trustworthy.
This mechanism helps explain why incidents associated with UFO hackers such as Gary McKinnon were potentially more significant than the compromise of one isolated computer. The danger was not simply that one machine had weak security. It was that internal trust relationships could amplify that initial compromise, allowing a captured host to become a stepping stone towards other systems before modern identity-centred security practices became widespread. Contemporary US government audits repeatedly warned that weaknesses in access controls, privilege management and network architecture allowed attackers who established an initial foothold to threaten wider federal systems.[GAO]gao.govCritical Infrastructure Protection: Significant Challenges in Safeguarding Government and Privately Controlled Systems from Computer-B…
How early networks distinguished internal traffic
Many government and enterprise networks of the 1990s and early 2000s were designed around a strong perimeter model. Firewalls attempted to block outsiders, while computers inside the network were often permitted to communicate with one another far more freely.
This did not necessarily mean every internal computer was automatically trusted. Rather, many security decisions relied heavily on factors such as:
- whether a connection originated from an approved internal address;
- whether the requesting computer belonged to a recognised network segment;
- whether administrators assumed internal users had already been vetted;
- whether previous network relationships had already been established between systems.
The underlying assumption was understandable for its time. Organisations expected most threats to originate outside their networks, while internal users were generally viewed as authorised employees or contractors. As networks expanded and internet connectivity increased, that assumption became much riskier because an external attacker who compromised a single internal computer could inherit many of the advantages associated with that machine.
Government Accountability Office (GAO) reports from this period consistently found that agencies suffered from weaknesses in access controls, inconsistent security management and insufficient protection of privileged functions across interconnected federal systems.[gao.gov]gao.govCritical Infrastructure Protection: Significant Challenges in Safeguarding Government and Privately Controlled Systems from Computer-B…
Why administrator access changed an attacker’s position
Administrator privileges affected far more than the compromised computer itself.
Administrative accounts typically allowed users to install software, manage services, inspect configuration information and interact with network resources that ordinary users could not access. In the McKinnon case, US authorities alleged that he installed remote administration software after obtaining privileged access, enabling continued control of compromised machines. That allegation illustrates why administrator access was strategically important: persistence on a trusted internal computer was often more valuable than repeatedly attacking from the public internet.
Once operating from inside an organisation, an attacker could often:
- view network configuration information unavailable to outsiders;
- identify additional systems intended only for internal use;
- use existing authenticated sessions or administrative relationships;
- communicate through network paths that external firewalls blocked.
Importantly, these possibilities depended on the specific design of each network. They should not be understood as automatic capabilities or as evidence that every internal machine provided unrestricted access. The broader point is that administrator control over one recognised host frequently changed an attacker’s starting position within the network, reducing the number of security barriers separating them from other systems.
How trusted pathways enabled movement inside networks
The concept now commonly described as lateral movement refers to progressing from one compromised system to additional systems within the same organisation.
Although the terminology became standard later, the underlying mechanism already existed during the period of the McKinnon intrusions. A compromised internal computer could act as a launch point for exploring neighbouring systems that were never intended to accept direct internet connections.
Several design choices contributed to this risk:
Internal services assumed known users. Many management interfaces, file-sharing services and administrative tools were intended for internal staff rather than anonymous internet users. Once an attacker reached the internal environment, those services became visible.
Network segmentation was often incomplete. Different departments frequently operated on interconnected networks with varying security standards. A weakly protected workstation or server could therefore provide access to systems administered by different teams.
Trust accumulated over time. Legacy administrative relationships between servers sometimes remained in place long after the original operational need had disappeared. Each trusted relationship represented another possible route through the network if one endpoint became compromised.
Modern cybersecurity literature identifies this pattern as a major enterprise security challenge because attackers exploit legitimate trust relationships rather than breaking every security control independently. The principle remains relevant today even though defensive technologies have evolved considerably.[arXiv]arxiv.orgEnterprise Cyber Resiliency Against Lateral Movement: A Graph Theoretic ApproachMay 3, 2019…
Why this mattered in the McKinnon case
Gary McKinnon’s case is often remembered because of his stated interest in UFO-related material and the lengthy legal proceedings that followed. From a network security perspective, however, the more enduring lesson concerns architecture rather than motive.
The significance of the alleged intrusions did not depend solely on finding one computer with poor password protection. Their potential impact increased because compromised systems could become trusted platforms within larger government environments. That possibility explains why investigators viewed administrator-level access so seriously even when no evidence suggested that every machine contained highly sensitive information.
The distinction is important:
- A vulnerable standalone computer presents a local problem.
- A vulnerable computer that occupies a trusted position within an interconnected network presents a systemic problem.
Government audits from the same period repeatedly warned that federal agencies lacked consistent enterprise-wide controls over privileged access, authentication and network security, making it possible for isolated weaknesses to have much broader operational consequences.[GovInfo]govinfo.govGAOREPORTS GAOGAO-01-615 - Information Security: Weak Controls Place Interior's Financial and Other Data at Risk - GAOREPORTS-GAO-01-615 | Conte…
The shift away from implicit internal trust
The experience of large government and commercial network compromises gradually reshaped security thinking.
Rather than assuming that location inside a network implied legitimacy, organisations increasingly adopted measures such as stronger identity verification, least-privilege administration, tighter network segmentation, multi-factor authentication and continuous monitoring of authenticated users. Later US federal initiatives also sought to reduce reliance on broadly trusted internal networks by consolidating and better securing internet connections across agencies.[GAO]gao.govInformation Security: Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies | U.S. GAO…
The broader lesson from the era is that security based primarily on network location can magnify the consequences of a single successful compromise. Once one trusted computer is lost, every security decision that assumes “inside means safe” becomes another opportunity for an attacker to move further than the original breach alone would otherwise permit.
Amazon book picks
Further Reading
Books and field guides related to Why One Trusted Computer Could Unlock Many More. Use these as the next step if you want deeper reading beyond the article.
Security Engineering
Rating: 4.5/5 from 7 Google Books ratings
Now that there's software in everything, how can you make anything secure? Understand how to engineer dependable systems with this newly...
Where Wizards Stay Up Late
Rating: 3.8/5 from 11 Google Books ratings
In 1990, the ARPANET itself was shut down, fully merged by then with the Internet it had spawned.
The Hacker Playbook 2
Just as a professional athlete doesn't show up without a solid game plan, ethical hackers, IT professionals, and security researchers sho...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromRoswell UFO poster oneBay.co.uk.
Endnotes
1.
Source: gao.gov
Link:https://www.gao.gov/products/gao-01-1168t
Source snippet
Critical Infrastructure Protection: Significant Challenges in Safeguarding Government and Privately Controlled Systems from Computer-B...
2.
Source: gao.gov
Link:https://www.gao.gov/products/gao-01-1132t
Source snippet
Critical Infrastructure Protection: Significant Challenges in Protecting Federal Systems and Developing Analysis and Warning Capabilit...
3.
Source: govinfo.gov
Title: GAOREPORTS GAO 02 231T
Link:https://www.govinfo.gov/app/details/GAOREPORTS-GAO-02-231T
Source snippet
GAO-02-231T - Computer Security: Improvements Needed to Reduce Risk to Critical Federal Operations and Assets - GAOREPORTS-GAO-02...
4.
Source: govinfo.gov
Title: GAOREPORTS GAO 01 615
Link:https://www.govinfo.gov/app/details/GAOREPORTS-GAO
Source snippet
GAO-01-615 - Information Security: Weak Controls Place Interior's Financial and Other Data at Risk - GAOREPORTS-GAO-01-615 | Conte...
5.
Source: arxiv.org
Link:https://arxiv.org/abs/1905.01002
Source snippet
Enterprise Cyber Resiliency Against Lateral Movement: A Graph Theoretic ApproachMay 3, 2019...
Published: May 3, 2019
6.
Source: gao.gov
Link:https://www.gao.gov/products/gao
Source snippet
Information Security: Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies | U.S. GAO...
7.
Source: gao.gov
Link:https://www.gao.gov/products/gao-22-104560
Source snippet
Cybersecurity: Internet Architecture is Considered Resilient, but Federal Agencies Continue to Address Risks | U.S. GAO...
8.
Source: files.gao.gov
Link:https://files.gao.gov/reports/GAO-26-107668/index.html
Source snippet
gao.govGAO-26-107668, TELECOMMUNICATIONS: Selected Agencies Have Taken Steps to Address Risks of Equipment Linked to ChinaMay 19, 2026 —...
Published: May 19, 2026
9.
Source: gao.gov
Link:https://www.gao.gov/products/gao-24-106896
Source snippet
April 16, 2024 — HOMELAND SECURITY: DHS INTERNAL ENTITIES FACILITATE INFORMATION SHARING IN KEY AREAS AND COLLABORATE AS NEEDED GAO-24...
Published: April 16, 2024
10.
Source: gao.gov
Link:https://www.gao.gov/assets/a322911.html
11.
Source: gao.gov
Title: GA O-09-232G, Federal Information System Controls Audit Manual (FISCAM)
Link:https://www.gao.gov/assets/a77155.html
12.
Source: gao.gov
Link:https://www.gao.gov/assets/a259389.html
13.
Source: govinfo.gov
Title: GA O-06-675
Link:https://www.govinfo.gov/app/details/GAOREPORTS-GAO
14.
Source: gao.gov
Link:https://www.gao.gov/assets/a244657.html
15.
Source: govinfo.gov
Title: GA O-04-375
Link:https://www.govinfo.gov/app/details/GAOREPORTS-GAO
16.
Source: gao.gov
Title: gao 02 24
Link:https://www.gao.gov/products/gao
17.
Source: govinfo.gov
Title: GA O-01-822
Link:https://www.govinfo.gov/app/details/GAOREPORTS-GAO
18.
Source: govinfo.gov
Title: GAOREPORTS GAO 01 1073T
Link:https://www.govinfo.gov/app/details/GAOREPORTS-GAO-01-1073T
19.
Source: govinfo.gov
Title: GAOREPORTS GAO 01 1004T
Link:https://www.govinfo.gov/app/details/GAOREPORTS-GAO-01-1004T
20.
Source: gao.gov
Link:https://www.gao.gov/products/gao-01-769t
21.
Source: ncsc.gov.uk
Title: Preventing Lateral Movement | National Cyber Security Centre
Link:https://www.ncsc.gov.uk/guidance/preventing-lateral-movement
Additional References
22.
Source: youtube.com
Link:https://www.youtube.com/watch?v=b5afwWUYWVQ
Source snippet
Dan Bull - Free Gary [an open letter to the Home Secretary]...
23.
Source: youtube.com
Title: Gary Mc Kinnon wins extradition battle
Link:https://www.youtube.com/watch?v=y4lecD44F5E
Source snippet
[Gary McKinnon Case]({{ 'mc-kinnon-case/' | relative_url }}) (Interview from 2009)...
24.
Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ
Source snippet
UK hacker's extradition to US blocked...
25.
Source: youtube.com
Title: UK hacker’s extradition to US blocked
Link:https://www.youtube.com/watch?v=v4Js8DF80HY
Source snippet
Gary McKinnon wins extradition battle...
26.
Source: gao.justia.com
Title: internet infrastructure gao 06 672
Link:https://gao.justia.com/department-of-homeland-security/2006/6/internet-infrastructure-gao-06-672/
27.
Source: gao.justia.com
Title: information technology gao 04 375
Link:https://gao.justia.com/department-of-homeland-security/2004/9/information-technology-gao-04-375/
28.
Source: gao.justia.com
Title: information security gao 10 237
Link:https://gao.justia.com/executive-office-of-the-president/2010/3/information-security-gao-10-237/
29.
Source: youtube.com
Title: Dan Bull
Link:https://www.youtube.com/watch?v=p6fYMzKvXxg



