Within Case Comparison
How Ordinary Computers Reached Military Networks
Vulnerable systems, weak passwords and interconnected networks let outsiders with ordinary home computers reach sensitive American targets.
On this page
- The insecure architecture of early government networks
- Compromised machines as stepping stones
- Why simple failures created outsized access
Page outline Jump by section
Introduction
Gary McKinnon, Mathew Bevan and Richard Pryce are often remembered as unusually capable hackers who reached sensitive American military and research systems from ordinary home computers. In reality, the most important common factor was not exceptional technical sophistication but exceptionally weak security. Across both the mid-1990s Rome Laboratory intrusions involving Bevan and Pryce and McKinnon’s later campaign in 2001–2002, insecure network design, weak or absent passwords, poor monitoring and extensive trust relationships between connected systems allowed relatively simple intrusion techniques to produce disproportionate results. Contemporary government investigations repeatedly concluded that basic security failures—not advanced exploitation—gave the attackers access to systems that should have been far harder to reach.[govinfo.gov]govinfo.govGAOREPORTS AIMDINFORMATION SECURITY: Computer Attacks at Department of Defense Pose Increasing Risks GAO/AIMD-96-84May 26, 2026…
The insecure architecture of early government networks
The internet-connected research and military networks of the 1990s and early 2000s were designed during a period when collaboration often took precedence over hostile-threat assumptions. Organisations such as the US Air Force, NASA, universities and defence contractors routinely exchanged information across interconnected networks. Once an attacker entered one poorly protected system, those trusted connections frequently opened paths to many others.
The 1994 Rome Laboratory incident illustrates this clearly. Rome Laboratory collaborated extensively with universities, commercial research organisations and defence contractors over the internet. Investigators found that attackers who gained an initial foothold were able to establish persistent control over parts of the network and use that access to move through connected systems rather than repeatedly breaking into each target independently. The value of the compromise therefore came less from the initial intrusion than from the network’s interconnected design.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…
McKinnon’s later intrusions followed a similar pattern. Although he targeted a different generation of systems, many government computers remained internet-accessible and inadequately protected. Later audits by the US Government Accountability Office found that NASA continued to struggle with basic access controls, user authentication, network boundary protection, auditing and configuration management years after McKinnon’s activity, showing that the underlying institutional weaknesses extended well beyond a single incident.[GAO]gao.govInformation Security: NASA Needs to Remedy Vulnerabilities in Key Networks | U.S. GAO…
Compromised machines became stepping stones
Neither Bevan and Pryce nor McKinnon needed to attack every target directly. Once inside one vulnerable machine, compromised computers became platforms for reaching additional systems.
During the Rome Laboratory investigation, attackers routed activity through numerous intermediate computers across multiple countries before entering Air Force systems. After obtaining access, they installed password-sniffing software and other tools that captured legitimate user credentials. Those stolen credentials allowed movement into additional Air Force computers, NASA facilities, defence contractors and other connected organisations without requiring a fresh technical breakthrough for every system encountered.[fas.org]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…
This “pivoting” effect multiplied the impact of each successful compromise. Instead of confronting isolated computers, investigators faced a chain of trusted systems in which one compromised machine could authenticate to another. The attackers’ apparent reach therefore reflected weaknesses in the surrounding infrastructure as much as their own technical ability.
McKinnon likewise described moving between connected government machines after identifying systems that accepted remote administration with weak or absent authentication. His account consistently portrays a search for exposed systems rather than the defeat of sophisticated defensive technology. While some details of his personal narrative remain disputed, the broad picture—that weak authentication substantially expanded his reach—is consistent with subsequent official findings about deficiencies in government network security.[GAO]gao.govInformation Security: NASA Needs to Remedy Vulnerabilities in Key Networks | U.S. GAO…
Why simple failures created outsized access
Several recurring security weaknesses appear across the cases.
Weak or missing passwords. McKinnon repeatedly stated that numerous systems accepted blank or trivial administrator passwords. Later government audits documented that NASA had continued to encounter weak password policies, inadequate authentication and even devices requiring no password in some circumstances, demonstrating that credential management remained an institutional problem rather than an isolated anecdote.[GAO]gao.gov10-4, Information Security: NASA Needs to Remedy Vulnerabilities in Key NetworksGAO-10-4, Information Security: NASA Needs to Remedy Vulnerabilities in Key Networks…
Excessive trust between systems. Networks often assumed that users who had authenticated once could be trusted elsewhere. This meant that stolen credentials or a compromised administrator account could unlock resources across multiple organisations rather than remaining confined to one machine.[Intelligence Resource Program]irp.fas.orgIntelligence Resource Program GAOIntelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks…
Limited monitoring. The Rome Laboratory investigation showed that attackers operated for extended periods before detection. A US Government Accountability Office review noted that the Air Force initially remained unaware of the intrusion, allowing the attackers time to establish persistence, copy information and explore additional systems.[GovInfo]govinfo.govGAOREPORTS AIMDINFORMATION SECURITY: Computer Attacks at Department of Defense Pose Increasing Risks GAO/AIMD-96-84May 26, 2026…
Poor configuration management. Later NASA reviews identified inconsistent implementation of access controls, incomplete patching, inadequate auditing, weak boundary protection and ineffective configuration management. These findings reinforce the conclusion that many successful intrusions stemmed from routine administrative shortcomings rather than novel attack techniques.[GAO]gao.govInformation Security: NASA Needs to Remedy Vulnerabilities in Key Networks | U.S. GAO…
Why the hackers appeared more capable than they really were
Public discussion often portrays these cases as demonstrations of extraordinary hacking skill. The historical record suggests a more nuanced explanation.
Bevan and Pryce certainly displayed persistence, familiarity with internet infrastructure and the ability to conceal parts of their activity through intermediary systems. McKinnon also possessed practical knowledge of remote administration tools and network reconnaissance. However, none of the three cases depended primarily on discovering revolutionary vulnerabilities or defeating state-of-the-art defensive systems.
Instead, their successes illustrate a broader principle of cyber security: an attacker’s effectiveness is determined as much by the defender’s weaknesses as by the attacker’s sophistication. Basic failures—including weak passwords, insufficient monitoring, excessive trust relationships and insecure default configurations—allowed individuals using ordinary home computers and consumer internet connections to reach systems that appeared highly secure from the outside.[govinfo.gov]govinfo.govGAOREPORTS AIMDINFORMATION SECURITY: Computer Attacks at Department of Defense Pose Increasing Risks GAO/AIMD-96-84May 26, 2026…
The lasting lesson from all three cases
The common mechanism linking McKinnon, Bevan and Pryce is therefore not a shared organisation or uniquely advanced hacking techniques, but an environment in which government and research networks were insufficiently prepared for hostile internet access. Once initial entry was achieved, interconnected systems, captured credentials and inadequate security controls amplified relatively straightforward intrusions into incidents affecting numerous military and research organisations.
For that reason, these cases remain significant in cyber-security history. They demonstrated that spectacular breaches do not always require spectacular exploits. Sometimes the decisive factor is simply that ordinary computers encounter extraordinary weaknesses.[govinfo.gov]govinfo.govGAOREPORTS AIMDINFORMATION SECURITY: Computer Attacks at Department of Defense Pose Increasing Risks GAO/AIMD-96-84May 26, 2026…
Amazon book picks
Further Reading
Books and field guides related to How Ordinary Computers Reached Military Networks. Use these as the next step if you want deeper reading beyond the article.
Ghost in the Wires: My Adventures as the World's Most Wanted...
In this "intriguing, insightful and extremely educational" novel, the world's most famous hacker teaches you easy cloaking and counter-me...
Countdown to Zero Day: Stuxnet and the Launch of the World's...
Top cybersecurity journalist Kim Zetter tells the story behind the virus that sabotaged Iran’s nuclear efforts and shows how its existenc...
Dark Territory: The Secret History of Cyber War
“An important, disturbing, and gripping history” (Kirkus Reviews, starred review), the never-before-told story of the computer scientists...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromvintage computer mouse oneBay.co.uk.
Endnotes
1.
Source: govinfo.gov
Title: GAOREPORTS AIMD 96 84
Link:https://www.govinfo.gov/content/pkg/GAOREPORTS-AIMD-96-84/pdf/GAOREPORTS-AIMD-96-84.pdf
Source snippet
INFORMATION SECURITY: Computer Attacks at Department of Defense Pose Increasing Risks GAO/AIMD-96-84May 26, 2026...
Published: May 26, 2026
2.
Source: gao.gov
Link:https://www.gao.gov/products/gao
Source snippet
Information Security: NASA Needs to Remedy Vulnerabilities in Key Networks | U.S. GAO...
3.
Source: gao.gov
Title: 10-4, Information Security: NASA Needs to Remedy Vulnerabilities in Key Networks
Link:https://www.gao.gov/assets/a296860.html
Source snippet
GAO-10-4, Information Security: NASA Needs to Remedy Vulnerabilities in Key Networks...
4.
Source: phrack.org
Link:https://phrack.org/issues/49/16
Source snippet
Phrack.:: Phrack Magazine...
5.
Source: oig.nasa.gov
Link:https://oig.nasa.gov/office-of-inspector-general-oig/ig-11-017/
Source snippet
Security Practices Expose Key NASA Network to Cyber Attack (IG-11-017) - NASA OIGMarch 28, 2011 — 1 min read INADEQUATE SECURITY PRACTICE...
Published: March 28, 2011
6.
Source: gao.gov
Link:https://www.gao.gov/assets/a311584.html
Source snippet
For example, it has developed a policy for granting or denying access rights to its resources, employs mechanism...
7.
Source: nodis3.gsfc.nasa.gov
Title: display CA.cfm
Link:https://nodis3.gsfc.nasa.gov/displayCA.cfm?Internal_ID=N_PR_28100001&page_name=Chapter4
8.
Source: nodis3.gsfc.nasa.gov
Title: display CA.cfm
Link:https://nodis3.gsfc.nasa.gov/displayCA.cfm?Internal_ID=N_PR_28100001&page_name=AppendixA
9.
Source: gao.gov
Link:https://www.gao.gov/products/t-imtec
10.
Source: all.net
Link:https://all.net/books/iw/iwarstuff/www.af.mil/news/airman/0496/hacker.htm
11.
Source: irp.fas.org
Title: Intelligence Resource Program GAO
Link:https://irp.fas.org/gao/aim96084.htm
Source snippet
Intelligence Resource ProgramGAO - Information Security: Computer Attacks at Department of Defense Pose Increasing Risks...
12.
Source: oversight.gov
Link:https://www.oversight.gov/reports/audit/final-report-vulnerability-assessment-and-penetration-testing-nasas-financial-5
Source snippet
NASA - IG17001 - 4 | Oversight.gov...
13.
Source: irp.fas.org
Link:https://irp.fas.org/congress/1996_hr/s960605b.htm
Additional References
14.
Source: nsarchive.gwu.edu
Link:https://nsarchive.gwu.edu/document/21406-document-10a
Source snippet
National Security ArchiveGovernment Accounting Office, GAO/AIMD- 96-84, Information Security: Computer Attacks at Department of Defense P...
15.
Source: cyberdefensereview.army.mil
Link:https://cyberdefensereview.army.mil/CDR-Content/Articles/Article-View/Article/1136118/the-number-one-vulnerability-in-the-future-of-cyber-security-a-critical-lesson/
Source snippet
This came with significant limitations and prevented access to the various directories they needed and to the commands they...
16.
Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon? | Nord VPN
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ
Source snippet
Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub...
17.
Source: youtube.com
Title: Who Is The Most Dangerous Hacker Ever? (Tier List) | Sumsub
Link:https://www.youtube.com/watch?v=z7OjzYT_-Zo
Source snippet
Matthew Bevan y Richard Pryce- Hackers Famosos...
18.
Source: youtube.com
Title: The Man Who Hacked the U.S. Government
Link:https://www.youtube.com/watch?v=ND0zQX1rGdg
Source snippet
Hacking for UFOs and fighting for his life. Who is Gary McKinnon? | NordVPN...
19.
Source: kujimedia.com
Link:https://www.kujimedia.com/articles/
20.
Source: nature.com
Title: Rome “could host European mouse laboratory” | Nature
Link:https://www.nature.com/articles/369699a0
21.
Source: issues.org
Title: An Electronic Pearl Harbor? Not Likely
Link:https://issues.org/smith-2/
22.
Source: youtube.com
Title: UK hacker’s extradition to US blocked
Link:https://www.youtube.com/watch?v=v4Js8DF80HY
23.
Source: nsarchive.gwu.edu
Title: 21407 document 10b
Link:https://nsarchive.gwu.edu/document/21407-document-10b



