Chapter 20 of 20 · 21683 words · ~108 min read

Chapter 11

, executive keyboards can ease the transition in the future to telecommuting.

So don’t impose your own work habits on a junior executive with fast fingers. Why shouldn’t he or she have a deluxe keyboard if it helps him serve your company better? And you yourself shouldn’t feel awkward with at least a good board for quick memos.

Mysteriously, IBM forsook the Selectric tradition in designing the keyboard of its original Personal Computer, where the left shift key, oddly, isn’t immediately next to the “Z.” The deviation left some computer magazine editors flabbergasted. Companies even started making keyboards for the PC—at several hundred dollars apiece—that retained the traditional layout.

“They’re not like normal keys,” my consultant friend Michael Canyes complained of the ones on the PC itself. “They click on and off like switches.

“A good key,” he said, “gets stiffer as you press down. But the IBM’s are either up or down.”

Some cynics have a theory. Maybe IBM didn’t want the PC to steal too many customers away from the Displaywriter costing several thousand dollars more. Yes, keyboards are a matter of taste, and unlike Michael, I can stomach the switchlike =tactile feedback=. But the shift location is inexcusable. IBM in effect admitted its goof; the IBM AT, a more powerful cousin of the IBM PC and XT, appeared with a much-improved keyboard.

At least the original IBM PC’s keyboard surpassed that of the tiny, chiclet keys on the first PC_Jrs._ Reluctantly—after sales were flagging—IBM replaced the chiclet-style boards with more conventional ones.

Pity us “users.” Even terminals intended for mainframes and minis can be turkeys. I actually favor my Kaypro board over a terminal—from Digital Equipment Corporation—which Waters once was using with a big mini at work. Blame the old-style programmers who didn’t grow up with word processing. “Most can’t type like a secretary,” says Canyes, “so the manufacturers often skimp on the touch.”

And isn’t it strange? You can buy an electric typewriter with adjustable touch for $200 but not get it in a computer costing fifty times as much.

I asked David Eisen why he hadn’t raised the touch issue. Wouldn’t bad keyboard matches hurt productivity?

“That’s more the companies’ problem,” he said. “We’re more worried about health.” He can’t recall a flood of complaints from Guild members about keyboards with the wrong touch.

Union people, however, have talked about another change, flat keyboards, now popular in Europe. The tops of U.S. boards commonly slant at fifteen degrees. And Waters tells of an experiment where, given the ability to change the angle, most participants settled for the fifteen-degree one. A caveat, however, is in order. Maybe the people ultimately would have done better with a flat board and plenty of practice on it. Perhaps you want an adjustable board. But for me, anyway, it won’t matter as much as touch.

Another issue is the QWERTY keyboard versus the more modern layouts.

“QWERTY” means the first six letters found on the boards of nearly all American computers and typewriters. It’s a nineteenth-century legacy—a bad one. The early typewriters couldn’t keep up with the nimbler typists, so the machines’ designers thwarted the humans. QWERTY isn’t alphabetical, it doesn’t bring together commonly used letters like “t,” “h,” and “e,” nor does it use finger muscles properly. The Dvorak board and other latecomers should work better. In practice, though, they might confuse typists, so here’s a solution. Let us old-fashioned people QWERTY away. But think about buying machines you can switch over for people trained on more efficient layouts. A program like Smartkey—which electronically changes the keyboard—might be the answer if you also relabel keys on machines used by Dvorak typists. The Apple II(c) even has a switch on the top of the machine to go from QWERTY to Dvorak. Some say the Dvorak improvement is dramatic. Waters isn’t so sure. He says some studies have indicated that the Dvorak board offers as little as a 5 percent increase in speed and little reduction of errors. “So in the end,” says Waters, “most people in the industry have decided not to tinker with the key arrangement.”

No matter how they’re arranged, your keys shouldn’t be shiny; a matte surface is good. So are neutral colors rather than black and white, except, says Eisen, for function keys. My Kaypro sins. Its keys, like those on Digital Equipment’s VT100, are a gleaming black, which, however, doesn’t matter that much to me, since I can control my lighting and normally don’t look down at the board when I’m typing. (Some other Kaypros have black matte keys.)

Function keys—the ones that let the operator delete a word or add a paragraph with a single touch—should ideally be a different color from the main keyboard’s. The same for number pads. The function keys if possible should have labels indicating their purpose. If not, a chart near the function keys might show, for instance, that “P1” “Deletes Word.”

Some people, however, say that function keys really slow you down, that they make you take your fingers off the main keyboard. I basically agree. The same would hold true for the use of Macintosh-style mice.

SPECIAL ERGONOMIC FEATURES

A dream VDT tilts. It swivels. It can move up and down on a pedestal. It helps you avoid back strain, stiff necks, glare, and headaches. It adjusts, so you don’t have to. A good VDT can help compensate somewhat if you lack ...

Good Furniture

“People will adapt very nicely to automation,” an IBM official once said, “if their arms are broken, and we’re in the twisting stage now.”

That was in 1975. Since then, however, in a literal way, some computer makers have been gentler with people’s arms—and wrists and backs.

A variety of good computer furniture exists now, some in walnut, some in formica. With all the trimmings, you can vary:

1. The heights of the keyboard and of the computer or terminal.

2. How far the keyboard platform protrudes from the platform on which the computer rests.

3. The tilt of the computer—a useful glare-reducing feature.

4. The angle at which the screen faces you. You can swivel away to your heart’s content to suit your posture or cut back on glare.

5. The height of your chair. You don’t of course need high-tech furniture to do that—just common sense. For a computer operator, says David Eisen of the Newspaper Guild, a straight-back chair can become “a ticket to the orthopedic ward.”

You might also shop for a palm rest and, if you’re short, a leg rest.

An easellike copy holder could help as well.

And so can enough desk surface, shelves, or file cabinets for your paperwork. Why buy a detachable keyboard if you can’t move it around because your desk is too cluttered?

Jon Ryburg, an ergonomics expert with the Facility Management Institute, a Michigan think tank owned by Herman Miller furniture, says computer gear may take up as much as 40 percent of a desktop. And yet does the space requirement for paperwork decline by that percentage? Hardly. So unless you enjoy seeing chairs used as desks, you’d better plan your furniture well.

Not that all improvisation is bad, especially if you’re a professional or small businessman working at home. My Kaypro, for instance, rests atop an old carton from a toy store, and I’ve bought some little gray legs, the color of the case, to tilt the screen back.

That takes care of my ergonomics. Of course, my requirements in this case aren’t the same as those of a company with dozens of VDT users.

Joan’s old supervisor at the insurance company might scowl at this haywire, but so far I’m comfortable. I would be much less casual about buying furniture for others. For example, I’d make certain that the chairs and tables would be not just adjustable but easily so—and understandably so. Even an IBM salesman couldn’t puzzle out all the ways to adjust the ergonomic furniture on which a Displaywriter sat. Despite such a flaw, however, special computer furniture isn’t just a frill. An ergonomic desk and chair might cost several hundred dollars more than an ordinary set—even a lesser-known brand may—but your furniture could be good for a decade. And just a 5 percent increase in a cleric’s productivity may pay back the extra investment in less than two years.

At the least, buy an adjustable chair and, ideally, a table of variable height. “A very short woman,” argues Bob Waters, “may sit with her eyes almost a foot closer to the floor than a six-foot-two-inch man’s.” The home-row keys on the keyboard—the row including the letters A, S, D, and so on—could be twenty-nine or thirty inches above the floor in a _typical_ case.[43] Other measurements? Upper screen-eye distance: 17¼ to 19¾ inches. Center of the screen: 10-20 degrees below the horizontal plane of the operator’s eyes. Angle between upper and lower arms: between 80 and 120 degrees. Wrist angle: 10 degrees or less. The keyboard is at or below elbow height, and the table allows enough room for your legs.

Footnote 43:

The advice on keyboard height is from Military Standard 1472C, _Human Engineering Design Criteria for Military Systems Equipment and Facilities_, published by the army in May 1981 and summarized in the July 1982 _Popular Computing_.

Your goal, of course, isn’t to make anyone fit the charts showing average distances. It’s just to keep people productive and comfortable.

Above all, when shopping around to do this, be skeptical. “A lot of so-called ergonomic things,” says Waters, “aren’t ergonomic at all.” He grimaces when he sees $300 wooden tables with fixed-level platforms for computer monitors. They’re an expensive way to strain your neck. “The normal line of sight for human beings is fifteen degrees below horizontal,” Waters says. “People normally look slightly down even when they hold their heads up.” Needless to say, you and your neck will come out ahead if, using an old Apple II, you don’t set the monitor atop disk drives resting on the computer. Ignore the ads showing this compact pile. Their purpose is to sell computers, not save necks.

Lighting

Bright fluorescents are to computer users’ eyes what a _drip, drip, drip_, is to the foreheads of Chinese water-torture victims.

They’re rude, persistent distractions.

And as with the water torture, the fluorescents’ victims may be captives of sorts. How many people can dictate the lighting in their companies’ offices? Many. But not all. So the letters and numbers on their screens, the facts they need to do their jobs, may compete with the glare beamed off the glass.

What’s more, the culprit needn’t be just the fluorescents that light so many American offices.

“The window with sunshine streaming in may still be a psychologically gratifying link with the outside world,” says Eisen, “but it spells plain eyestrain and perhaps headache for every VDT operator within range of the glare.” Even brightly painted walls can sin here.

So can glossy paper. In fact, _any_ paper is bad in one over-powering way. The proper lighting level for paperwork is much higher than for computer work. And yet most computer operators have yet to see the much-touted paperless office. How do you keep eyes comfortable with both paper and computer screens?

Here are some _possible_ solutions to the lighting problem:

1. Removing half the tubes from existing fluorescent fixtures. You’ll want, however, to make certain that some areas of the room aren’t still overlit while others are light starved. Be skeptical. This is the miser’s solution. If you can get away with it, fine. But don’t count on it. Remember, the women at the insurance company in New York say they still suffered glare afterward.

2. Parabolic fluorescent fixtures with baffles to keep the light out of the places where it can cause glare.

3. Parawedge louvers, which, according to Eisen, “have been particularly effective on a number of newspapers.” Small plastic cells turn light downward, so that, ideally, you can barely notice it at desks just a few feet from the one you’re illuminating. “Light should be cut off,” Eisen suggests, “outside a line emanating at a forty-five-degree angle from the fixture.”

4. Desk and floor lamps. You might buy rheostats you can plug in between them and the outlet to adjust the light level. And be careful otherwise. Shield your lamps so they don’t glare off nearby computer screens. Properly used, however, they could be a godsend for people doing both computer work and paperwork.

5. Indirect lighting. The disadvantage is the expense. You may have to repaint walls and ceilings and pay for a consultant to select the right tones. Moreover, indirect lighting may be hard to install in rooms with ceilings lower than nine feet. Used well, however, this is one of the best solutions.

As a general rule, think about a lighting level between 300 and 500 =lux=—between 32 and 53 =footcandles=. A lux tells how much light is hitting a certain area, and 9.5 lux would equal 1 footcandle. For rough measurements you might borrow a good lightmeter from a photographer. Don’t aim directly at the light. Sample, instead, desk and computer surfaces, among others, though not the screens themselves. For more detailed measurements and advice, hire a consultant or call your state labor department. Make certain you‘re in touch with the consulting rather than the enforcement branch. Yes, any contact with officialdom has its risks. But they’re low here. And you’re strengthening your hand in labor relations by documenting your concern for your workers’ eyes.

In fact, before you place your order for lighting, ask if your supplier can run a test in your office. Or can you at least visit offices using the product?

Also, all along, worry about glare as well as lighting levels. You might try the mirror test suggested by a veteran ergonomics expert. Place a mirror over the face of a computer screen. Then you can see where the glare is coming from—which window, which lamp; for all you know, the source could be a brightly colored painting or a glassed-in print.

Try to rid your office of glare instead of using a filter. “I believe in avoiding a broken arm rather than putting a splint on it afterward,” says Harry Snyder. If you need a filter, however, here are possibilities:

1. Coatings or etching applied during manufacture of the video displays. They needn’t harm the viewing quality noticeably.

2. Coatings put on after manufacture. Generally, but not always, they don’t work out.

3. “Colored plastic panels and etched faceplates,” which, says Eisen, “have such damaging effect on brightness and clarity of the characters that they should be avoided.”

4. Micromesh filters, favored by German ergonomists. Eisen says U.S. opinion of them “is mixed. They do a good job of reducing reflections, but the mesh makes for a restricted viewing angle, absorbs some of the light from the display, and scatters some of the rest, degrading the image.”

5. Polarizing filters. They may reduce brightness and shorten tube life, since you must crank up the tube to compensate; at $100 or more, they are more expensive than the other add-ons. But they give you a better image than other filters. The contrast especially can be impressive.

Noise Reduction

Don’t just buy the fastest, the cheapest, printer. Look for one with good manners toward the humans nearby—a _quiet_ printer.

A daisy wheel can be a real offender. What more can you expect of a machine with a metal hammer constantly striking away? And dot-matrix printers often make a higher-pitched sound that mercilessly cuts through walls.

So ask your printer supplier for noise figures if you think this will be a problem. Military standards say that for work needing heavy concentration—in areas like libraries and conference rooms—the sound level must be no more than 45 decibels on the dB(A) scale, which allows for sensitivity of the ear at various sound pitches. Otherwise, aim for a level less than 65 decibels. You may be able to rent the necessary meter from a scientific instrument store. Measure the sound from the distance someone’s head would be when he was working. Here again, you might ask the supplier for a look-see at an existing installation.

Put your printers if necessary inside padded wooden boxes; carpet; drape walls; install sound-muffling panels on ceilings and walls, perhaps.

The less echoey and factorylike your office is, the more productive it will be.

Air Conditioning, Heat, And Ventilation

Around the first week of January 1983, when _Time_ honored the computer as the “Machine of the Year,” a Commerce Department computer ungratefully stopped working and delayed the release of an important government report.

The reported cause was nothing more than a dehumidifier motor out of whack; perhaps the room got too moist for the computer sensor.

If so, I wasn’t surprised. Computers and related machinery can sometimes be quirky about their surroundings. My old Anderson Jacobson daisywheel printer, later sold, wouldn’t run unless the room temperature was above fifty degrees. Since I was comfortable at seventy degrees, I obliged the AJ.

In our attentiveness to machinery, however, let’s not forget the people nearby.

“You can see the heat wafting out the backs of our VDTs,” said a woman with the northeastern insurance office—and yet the firm didn’t turn up the air conditioning. “What might happen,” said Waters about a hot insurance office, “is the [overheated computers] may go down and they’ll pay out extra money, anyway.”

Look inside a VDT and you’ll very likely find an orange glow in the neck of the tube. The heat there may be no more than a light bulb’s, but on a hot day, with more than one machine in the same room, you’ll want your air conditioning to be up to the job.

At the same time, having a room too cool—even in just a few places—can harm productivity. An employee in the insurance office said her coworkers, when not using the terminals, sometimes wore gloves.

As for bad ventilation, it, too, can jinx production and add to sick leave, and in recent years, especially, it’s been a problem, as companies tightened up their buildings to save energy. People in high-paced jobs or those requiring concentration may suffer the most.

Healthy Honesty

When Laura Moore was pregnant, she neither smoked nor drank—not even coffee.

She did, however, operate a computer terminal for a telephone company in Renton, Washington, near Seattle, and she was one of three VDT operators there with problem pregnancies within a year and one-half.[44]

Footnote 44:

The facts of the Renton, Washington case come from Laurie Garrett’s National Public Radio interview with Laura Moore, which aired August 12, 1982.

Laura Moore, after nineteen hours of labor, gave birth to a son with a birth defect called spina bifida. “We didn’t see it at first,” she said. “We saw a larger head and a foot that was a little odd and distorted. But when the nurse picked him up, then we saw this huge opening in his back, which is a spina bifida.” Laura was “devastated. Just devastated. We—I went through a severe depression afterward.”

Moore is just one of many people worried about VDTs. In Massachusetts a pregnant journalist, fearing radiation, wore a leaded apron. (A leaded apron’s weight on the mother might itself harm an unborn child.) At the _New York Times_ two young editors developed cataracts and filed for workers compensation, blaming their computer screens.

“We’ve heard of cases of everything from bad dreams of computers chasing people to psychic distress where people have attacks of depression,” says Michael Smith, the ex-NIOSH man. “But it can’t be linked specifically to the VDT.” And yet NIOSH as of this writing was continuing safety studies. “We might find that it has nothing to do with the video tubes,” Smith says of problem pregnancies among terminal operators. “It could be part of the circuitry.... It may be from job stress.” Meanwhile, proven problems—like eyestrain—bedevil men and women on the tube. When 1,236 secretaries and word processing-operators replied to a survey done for a major disk-maker, almost 70 percent worried about potential health complication. Some 63 percent told of eyestrain, and 36 percent reported backaches. Almost 80 percent wanted better lighting and more time to rest their eyes.

So, regardless of how your equipment supplier vouches for your computers’ safety, keep two facts in mind:

1. There is a possibility, extra-slim, but still there, that low-frequency radiation from computers can seriously threaten the health of workers like Laura Moore and their unborn children.

2. More minor physical and mental problems from computers definitely do exist. You and your people, however, can either overcome them or at least live with them. Don’t shrug the problems off. If you do, you’ll only ruin your credibility when you and your employees discuss radiation and other possible hazards.

Most people, however, accept the inevitability of computerization. Employees usually know you need your machines to keep up with your competitors. So do unions. They have computers of their own. The major labor-management issues aren’t over whether to computerize: they’re over how to be safe and humane about it.

And often, by agreeing to requests like those for eye examinations, you’ll be helping your company along with the workers.

Here is a summary of expert thinking about actual and possible health threats of computers:

RADIATION

Could low-frequency radiation from VDTs indeed endanger the unborn? Or might it cause cataracts? And what about x-rays?

A computer user sits much closer to the screen than most TV-watchers do; might this increase the danger? After all, a typical computer, like a TV, uses a cathode ray tube with a high-voltage charge. An electron gun fires these subatomic particles toward the phosphor coating on your screen. Toward you, in other words. Wouldn’t x-rays created by this process be dangerous?

Well, throw away your $50 lead-impregnated acrylic shield! Experts feel that x-ray are a nonissue here.

The x-rays aren’t strong enough; besides, there’s too much leaded glass in the computer screen itself for you to suffer harm. I’d worry more about the chemicals in my typewriter cleaning fluid than about x-rays from my green screen.

Then again, some respected scientists _wonder_ about low-frequency radiation given off by computer monitors. Until researchers can absolve computers of blame in cases like Laura Moore’s, the VDT safety issue will remain legitimate.

“The wild cards in the VDT debate are the eleven clusters of problem pregnancies and miscarriages among women who work on or nearby VDTs,” says Louis Slesin, editor of _Microwave News_ and publisher of the sister publication _VDT News_.[45] Some computer industry spokesmen and federal officials think the clusters show up by chance. Slesin, however, while noting that the “normal” miscarriage rate in the U.S. is almost 20 percent, says: “The incidence of birth defects is harder to account for.” And he says similar clusters haven’t popped up among women tapping away on typewriters.

Footnote 45:

The Slesin quotes come from his article in _Columbia Journalism Review_, November 1984. The _Review_ correctly says Slesin’s newsletter “has taken no sides in the VDT story while keeping up with all relevant developments.” It appears monthly. The _Microwave News_’s address is P.O. Box 1799, Grand Central Station, New York, N.Y. 10163. Subscriptions are $200 a year. _VDT News_, a bimonthly, costs $42 a year.

These clusters—found in widely scattered offices in the U.S. and Canada—may result from causes other than radiation. Some VDT operators feel less in control of their jobs than do traditional typists; and a remote possibility exists that this additional stress could take its toll on the unborn children. Slesin says fear of VDTs may itself increase the stress—a Catch-22 if ever one existed.

Seeking a definitive answer on the birth-defect and miscarriage questions, NIOSH in 1984 was planning a study of about 5,000 pregnancies in a two-year period. Perhaps one-half of the women would use terminals. And the study would tell if they had more miscarriages and children with birth defects than did the other mothers. It would not pinpoint the cause, however—justification for further study.

A possible culprit here is =very low frequency= (=VLF=) =radiation= from the flyback transformer.

The transformer whips the cathode ray tube’s electron beams from one side to the other of the phosphor-coated screen, then back again. Typically a flyback transformer gives off radiation pulses at the rate of about 16,000 cycles a second, far below the AM radio broadcast band—hence, the term VLF. Could pulses at this frequency have biological effects?

We don’t know about VLF. But a Spanish scientist named Jose Delgado says even very weak pulses of =extremely low-frequency radiation= (=ELF=), the term for below 300 cycles a second, have damaged chick embryos. Some authorities question the “Delgado effect”; still, scientists in both the U.S. and Europe are undertaking similar experiments. Trying to gauge the possible risks from ELF, researchers may face certain technical complexities. Some scientists talk about “windows” of power and frequency. Just a slightly lower or higher frequency, for instance, might mean the difference between safety and danger for expectant mothers.

Like it or not, the jury is still out on the low frequency issue, and some companies may want to protect themselves legally—just in case—by transferring pregnant women from VDTs. Ideally you’d coordinate this policy with those regarding maternity leaves and other health benefits; then a woman would feel free to tell you immediately about her pregnancy instead of disguising it for as long as possible.

Even if radio frequency radiation is a culprit, there is some hope. Slesin notes that the flyback transformer is on the side or back of a computer monitor rather than in the front near the operator. That isn’t the best news for someone sitting near the flyback transformer of a coworker’s machine, but perhaps the VLF threat isn’t so great to someone without any other VDTs nearby. “With the right office layout,” says Mark Pinsky, editor of _VDT News_, “you might be able to greatly reduce exposure to VLFs fields. And obviously the risk to home computer users might be less without another machine around.”

Although VDTs have yet to be proven free of radiation risks, please note that groups like 9 to 5 and the Newspaper Guild have been using at least a few computers in their offices for several years. Don’t lie to your people that there’s nothing to worry about; do point out that the risks are low enough to justify computerization’s benefits.

“Can computer screens cause cataracts?” some employees might also ask.

Probably not. A NIOSH study at the Baltimore _Sun_ found no greater number of cataracts among VDT users than nonusers (although the researchers noted that the employees on VDTs averaged less than four years at the tube—perhaps not long enough to suffer the cataracts).

To be sure, strong microwave radiation indeed can lead to cataracts. But VDTs don’t give off microwaves, and no one has suggested that ELF and VLF are responsible for cataracts. Maybe there are other causes. Regardless, a certain percentage of people, some in their 30s or even late 20s, will always develop cataracts—whether or not they work in front of a tube.

BACK AND MUSCULAR PROBLEMS

They _are_ common—because, as mentioned earlier, some terminals force you to choose between the best hand-keyboard distance and the optimal eye-screen one.

_And for the most part, the pains are avoidable._

Etienne Grandjean tells of a study in which 11 percent of fifty-three people on data-entry terminals suffered neck problems; 15 percent, shoulder troubles; 15 percent, problems in their right arms; and 6 percent, problems in their right hands. The study also included fifty-five people in traditional office work. No more than 1 percent suffered neck, shoulder, or right arm pains, and none had problems with the right hand. Olov Ostberg and Ewa Gunnarsson, two other European ergonomics experts, likewise documented the frequent muscular pains from computer-related jobs. They found that almost two-thirds of some fairly young clerks with a Scandinavian airline reported such problems. In the United States, NIOSH, in its 1981 report, also said terminal users endured more muscular and skeletal pain.

The outrage is that it’s unnecessary, almost always, now that ergonomic furniture and detachable keyboards are on the market.

Don’t blame your people for their pain. Buy truly ergonomic products.

And don’t just buy for male executives or female typists, especially in this age when more women are working.

PSYCHOLOGICAL COMPLAINTS

NIOSH’s 1981 report observed that VDT operators showed dramatically more anxiety and depression than people not on the tubes. The researchers qualified their finding, however. They noted that many terminal operators were in jobs more routine than those of the non-VDT people, increasing psychological problems.

Could the machines themselves, however, have made some work more routine?

For me computers mean less typing and more writing. For a data-entry clerk, however, they may mean becoming part of what Grandjean calls “a man-machine-system.” Not all workers object. Some, as Grandjean says, “are proud to be included in the new work of modern technology.” But most people would still favor the human touch, with or without a computer. “The computer,” it’s been said, “is the ultimate unsupportive boss.” A Cleveland office worker observed that another woman was “fast as the wind” on a computer keyboard after ten years at it. “But,” said the worker, “it’s really affected her personality. I used to wonder if something was wrong—she had no exuberance. Once she said to me, ‘Rose, as soon as I sit down at that machine in the morning, I feel I’m going to cry.’”[46]

Footnote 46:

The quote from the Cleveland office worker and from the two examples immediately after it come from _Warning: Health Hazards for Office Workers_, published in 1981 by the Working Women Education Fund, 1224 Huron Rd., Cleveland, Ohio 44115.

“You know,” said a worker at an accounting firm, “when the boss brings new clients through the office to show them around, he’ll point right to me working at the word processor and say, ‘Here we have our wonderful new LEXITRON,’ and then move right on. He doesn’t bother to introduce me—just the machine!” Mightn’t he also have bragged about the operator? Can you dismiss her as a whiner? Is it any surprise that on most days the woman and two colleagues suffered headaches, shaky hands, jittery stomachs? “The place looks gorgeous,” said a worker, “and that’s where the management’s priorities lie. They’re not really as interested in efficiency as they are in using people up and pushing them out the back door.”

According to Grandjean, psychological reactions to computers will differ depending on:

▪ The type of work. ▪ The way the job is organized. ▪ The way it is introduced. ▪ Various personal attitudes.

To his list I would add “Surroundings.” A newspaper installed dark blue panels, six feet high, around some VDT operators. The dark blue may have cut down the glare, but at a cost. “All we see is the walls around us,” lamented one, “and sometimes the supervisor. The isolation is terrible.” Some employees might welcome isolation at times, especially a chance to work at home; but here management seems to have unwittingly created high-tech solitary cells.

EYESTRAIN

“I wore glasses before I came in,” said a claims processor with the northeastern insurance office mentioned earlier, “and now I need a stronger prescription. And I can’t even read a book anymore. Before I used to enjoy reading,” she told me, “but now I can barely glance at newspapers.”

Many computer-ergonomics experts would scoff at the idea that the woman’s work is blinding her. No one has convincingly shown that the terminals cause a permanent deterioration in eyesight. There is, however, some uncertainty. “We don’t know,” said my ophthalmologist when I asked during an eye examination about long-term effects—and also when he prescribed new glasses.

Most ergonomics experts would be more reassuring. They would say, for instance, that, first, people’s eyes weaken naturally as they age, and you can’t automatically blame the terminals. Second, terminals place more demands on your eyes than reading does. VDTs, however, don’t permanently harm eyes, according to a twelve-member panel of the prestigious National Research Council (NRC) which is connected with the National Academies of Science and Engineering. The NRC study, released in 1983, said no evidence existed that VDTs could cause “anatomical or physiological damage ... to the visual system.” The panel felt that the VDT controversy should be a productivity issue rather than a health one. At the very least, however, it’s a comfort one. Harry Snyder, the Virginia Polytechnic Institute expert, in 1983 said that three-fifths of VDTs then on sale were not even reasonably comfortable. Just consider, if nothing else, the resultant productivity losses!

Even if the computer isn’t permanently blinding the northeastern claims processor, it’s in a sense shortening her life. She has less time for the reading she loves. Presumably, she would agree with the findings of a NIOSH-sponsored study of San Francisco clerical workers. Ninety-one percent of the ones on terminals reportedly complained of eyestrain, while only 60 percent of the nonterminal users did.

How to reply to such complaints? Follow the lighting and glare suggestions outlined earlier and consider rest breaks or alternating VDT and non-VDT tasks. And educate your workers—ideally before you hire them.

Let them know you’re doing all you can to reduce the risks. “I have a selfish interest in this, too, you know,” you can tell them once they’re working for you. “The lousier your eyes get, the more errors you’ll make. Which hurts _me_.”

Then hand them cards with a good ophthalmologist’s name on it—or perhaps several possibilities—and say: “Make an appointment. We’ll pay for it.” Why should a company invest thousands or millions of dollars in computer maintenance without worrying about other work tools—employees’ eyes? Have new employees’ eyes checked in these NIOSH-approved ways, among others, during thorough examinations:

1. Refraction 2. Accommodation 3. Acuity 4. Color vision function 5. Degree of opacity of the lens 6. The possibility of a detached retina

Yearly, the doctor should test for refraction, acuity, and accommodation.

Make sure your health insurance covers bifocals and other glasses that your employees wouldn’t need except for your CRT.

CRTs: Should They Go Down the Tube?

Yes. Not immediately. But sooner or later. CRTs are harder on the eye than the better flat screens will eventually be, and although scientists haven’t proved that CRTs are a radiation threat, the small possibility remains.

These bulky antiques, however, have been to the computer establishment what gas guzzlers were to Detroit. The CRT isn’t the most promising kind of computer screen—just the most entrenched.[47]

Footnote 47:

Information on flat-screen displays comes from _InfoWorld_, May 7, 1984, and other micro magazine articles; the _Washington Post_ of April 29, 1984; George Weiss, director of computer systems studies with Quantum Science Corp., New York; and Kenneth Bosomworth, president of International Resource Development, Inc., a market-research firm in Norwalk, Conn.

Admittedly, CRTs have improved to the point where some pocket-sized TVs can use them. But in compactness and low-power consumption, CRTs will never rival the flat-screen displays.

“People will begin using flat-screen portables as regular desktops,” a New York researcher correctly says.[48] Flat-screen computers may not be as viewable now as the best CRT displays, but this may quickly change. What’s more, flat-screen machines don’t hog desks as the Kaypro II-style portables can. After all, the flat screens are essentially—flat. They don’t need hefty transformers, moreover, and don’t burn out like old vacuum tubes. CRTs _are_ vacuum tubes. Low voltage is still another plus of most flat screens. Not that CRTs are normally a shock hazard, but you’ll presumably feel safer if you didn’t sit near a 20,000-volt gizmo flinging electrons around inside some glass.

Footnote 48:

The “people will begin using” quote is from a Weiss interview with _USA Today_.

Also, as David LaGrande, an official with the Communications Workers of America notes, flat screens may “eliminate the radiation danger, reduce the risks for pregnant women.” And unless you spray a flat display with radioactive material, it just won’t give you cancer.

Again, no one’s proved that CRTs will turn people’s bodies into tumor farms. But why gamble? Your caution won’t hurt labor relations.

Flat screens, also, don’t flicker tiresomely as many CRTs do, and someday they may boast more fully formed images than those from the CRTs. So you might make fewer errors reading material from the screen.

The word “might” is important. Many =liquid-crystal displays=—=LCD=s, like the wristwatch kind—showed much cruder images in 1984 than did typical CRTs. The broken-up letters might bother you just like those from the cheap dot-matrix printers.

Also, some LCDs offered horrid contrast between the screen background and your typing.

That was as of late 1984. Even cheap LCDs in the future could do away with the breakup and contrast problems. Already the Japanese are selling color TVs with LCDs.

Perfected, LCDs could make computerized offices brighter and cheerier. They don’t glow. Rather, they reflect light, just like paper, so you needn’t darken the office. In fact, light helps.[49]

Footnote 49:

For a reminder of the advantages of LCDs in avoiding a dark office, I’m grateful to Bert Vorchheimer, a corporate communications specialist, who, as a sideline, wrote some farsighted articles on office ergonomics.

And if LCDs don’t fully pan out? There’s yet another choice—=electropheretic= screens, which may offer decent contrast and even beat CRTs’ sharpness. Here’s the theory. A magnetic charge pushes tiny particles to the surface of the screens, and patterns of particles form images.

These gizmos will tax your battery less than some other flat-screen displays do. And listen to this: when you turn an electropheretic off, it _remembers_. The images on your screen don’t vanish.

Now, combine that wrinkle with memory chips that use next to no power and can be running all the time. And what do you have? A computer that will automatically shut off without harm if you didn’t tap a key after a certain stretch of time. Just like a calculator. So—battery makers, beware!

There are still other alternatives to CRTs. One is the =electroluminescent= screen—used on the Grid Compass portable—which glows and is sharper than the LCD. Electroluminescents in 1984, however, were far too expensive for the average computer buyer; the Grid was selling for $4,250, and much of that was the cost of the display. A second failing of electroluminescent screens is that they’re electricity hungry. You can’t operate them with miniature batteries.

Another LCD alternative is the =plasma panel=, which glows with a gas mixture consisting mainly of neon. Plasmas don’t flicker. The characters are sharp; the contrast, excellent. But backup circuitry has been expensive; and even small plasmas, with the accompanying electronics, cost several thousand dollars in 1984—a far cry from a $150 CRT monitor.

To sum up, the main advantages of flat screens are their lightness, low power consumption in most cases, safety, lack of flicker, and very likely a better view in the long run. As of late 1984 the trade-offs (at least in the case of LCDs) were:

▪ The broken-up, somewhat fuzzy letters and the low contrast between them and the background.

▪ The need to have the display at just the right angle from you to get the sharpest picture. This could get in the way if you were moving the LCD to reduce glare.

▪ The comparatively slow speed with which letters or numbers appeared on an LCD after you’ve typed.

▪ The general lack of full-sized 24-line screens with 80 columns. The Data General portable debuted with 24 lines and a screen measuring 11 inches diagonally—a welcome exception, even if the quality of the characters still wasn’t good enough for heavy use.

Since many flat screens were on portables, there were other ergonomic problems not related to the display technology per se. In late 1984, most flat-screen portables lacked detachable keyboards. But the limitations of LCDs were the main problems.

A reporter friend, banging out stories for his paper at times in the field, told me he’s survived the 40-column, 8-line screen of the Radio Shack Model 100 very well. But I’m not surprised. He’s also brooked that clunky Select software, which gets in the way of corrections and insertions. Gene, you see, apparently knows what he’s going to write—he needn’t watch the screen as much. I wish I were as decisive. At any rate, what was right for Gene wouldn’t necessarily be right for a clerk who’ll be at the keyboard seven or eight hours a day.

No matter what hardware and software you end up with, don’t lose sight of three goals, among others:

1. Getting the most work out of your people 2. Keeping them happy 3. Guarding your electronic files

Sometimes, alas, the easiest-to-use computers may be the ones most vulnerable to computer crime and loss of important information—the subjects of the next chapter.

Backups:

◼ IX, Window Shopping, page 343.

◼ X, Of Mice and Men—and Touch Pads, Touch Screens Etc., page 346.

10 ❑ Jewels that Blip

The words have a nasty metallic ring, as if to suggest helmeted policemen with black jackets and billy clubs. Watch out: the “data security” troopers are at the front door.

But a small business on the East Coast nowadays wishes it had enjoyed more “data security.”

A fire melted its computer disks into plastic globs. The firm just missed bankruptcy after losing several hundred thousand dollars’ worth of information—everything from accounts receivable to tax records. Scrambling to recover, salesmen leaned on customers for copies of old bills.

Arson? Maybe. A disgruntled worker _may_ have short-circuited some tangled wiring. Proof never came.

Either way, however, the incident was a powerful argument for “data security”—the right kind.

It’s nothing more than trying to make sure that your computer and its information are safe. This isn’t to advocate overkill. Don’t overprotect nonsecrets or facts that you can easily duplicate; for instance, instead of buying costly fireproof cabinets, you might simply keep backup disks at another location—perhaps a more secure approach, anyway.

Why, however, do I say “trying” to make your computer and its information “safe”? An ex-hacker, Ian (“Captain Zap”) Murphy, now a computer security consultant, wisely observes: “You’re safe from average crooks—they don’t envision a nice, mild-mannered human being working at anything more than a souped-up typewriter. But you can never, never be able to 100 percent secure a computer system. Even the most trusted user could say, ‘F— the damn payroll,’ and destroy your records.”

But in the best of all worlds, your electronic files are safe, accurate, and if need be, tamperproof and confidential. The equipment is sound. And so are you and others working with it. You’ve shown good judgment. You’re ideally safe not only from crooks but also your own blunders. You know you often can’t keep paper copies of all your electronic jewels, your treasured business files, at least not without giving up the conveniences of computerization. You have faith, then, that your green screen, at your command, will display the right blips. I’m stretching the meaning of the word “blips” to emphasize the transitory nature of what you see on the screen. Without your stashing it away on a disk or otherwise—and without your making an electronic backup—it may be lost forever.

The unlucky owner of the East Coast company will never see his blips again because he violated a major precept of data security. He stored his original disks and his copies in the same room—the one with the fire.

“The remark at all times in cases like this is ‘Why didn’t the dealer tell me?‘” says Harold Joseph Highland, a top computer crime consultant and author of _Protect Your Microcomputer System_ (John Wiley & Sons, 1984).

A store can only sell you a computer, not common sense. Nor can this chapter impart it to you. It can, however, pound away at the elements of data security—people, policies, hardware, and software. They go together, these four. And so do the criminal and noncriminal parts of data security. If you’ve lost control of your computer files and don’t know what’s normal, you’ll hardly notice the abnormal. You’ll never thwart a computerized embezzler, for instance, with a gun. You will with good software. Buy it and errors in your electronic files may leap out at you. May. Remember Canyes’s Law of Computing: “Sooner or later you’ll feel like killing yourself.”

In other places I’ve written about good software and other mundane ways to make yourself less suicidal. And here, too, you’ll read of everyday calamities like coffee spilled on floppy disks. But this is also the fun chapter, the one with the stories about errant whiz kids and a computer crook who supposedly stole $8 million and got away with it.

Each of their sins met Harold Joseph Highland’s definition of a computer-related crime. They were “committed using a computer as a tool.”

“In other words,” explains Highland, who has taught computer science at the State University of New York, “you use the computer to get to financial records. Or to get to software if you’re illegally copying software.”

Estimates of the size of the threat have ranged from the double-digit millions up to over $5 billion a year. This uncertainty has sparked a feud between the icebergers and some computer makers.

Highland is an iceberger. He says that reported computer-related crimes are “just the tip of the iceberg,” that the annual loot is at least $750 million and more likely reaches the billions. Another expert wrote a crime article livened up with a drawing of the _Titanic_. Meanwhile, the Computer and Business Equipment Manufacturers Association pooh-poohs all but the more conservative estimates. “Computer crime is not now, never has been, and never will be out of control,” an association official once said, “unless security is completely ignored. And that is not going to happen.”

“If that’s your opinion, sir,” counters Captain Zap, the computer felon now working as a security consultant, “why are fourteen-year-olds getting on defense networks? And what about adult criminals doing their thing on banks?”

Also, how about computer crimes against small business?

“No one’s going to find out why Joe Blow goes out of business,” says Ken Churbuck, a New Hampshire lawyer and former computer engineer, who believes that electronic crime may be the downfall of many more small businessmen than supposed. “You think Joe Blow can afford an investigation? You think anyone else wants to autopsy the corpse?”

Large business or small, however, don’t swear off computers and buy quill pens for your accountants. You may or may not get robbed electronically, but you’ll very possibly lose money if you cheat yourself of the benefits of computerization.

Although computer crooks may be difficult quarry at times, at least you can console yourself that they’re normally _not_ geniuses.

Consider a story from Highland. The law caught up with one crook—presumably more knowledgeable about computers than banks—after he asked a teller to cash seven identically dated checks made out to him. The embezzler had simply learned how to take advantage of a feature in the check-printing program. It allowed checks to be reprinted in the event of mistakes; only his stupidity offset this programming error.

“You don’t have to be knowledgeable,” Highland says. “You can be an absolute idiot and try a computer-related crime.”

Some of the victims, alas, show their own streaks of naïveté. One small business lost thousands of dollars to a bookkeeper who funneled it to relatives’ firms via phony invoices. Such crimes happen with or without computers. But the company begged for trouble here by retaining an accountant old-fashioned enough to have felt at home alongside Scrooge and Cratchitt. Computers baffled him but not the embezzler, who knew of this vulnerability.

Executives at big corporations needn’t be smug about such grass-roots examples.

Many large companies, for instance, have reduced _the crooks’_ risks in computerized crime by auditing samples instead of everything—pulling one hundred checks, perhaps, out of a batch of four thousand. The young man trying to cash his seven duplicates worked for a large West Coast firm given to quick and dirty sampling; just tote up the odds of catching him through an audit if he’d been smart enough to go to different banks. Ideally, at least, your system should flag quirks like the seven checks.

You can also complicate life for computer crooks by studying classic cases of the past.

Mostly the criminals sinned with or against large computers. And yet eternal truths linger on even in the micro-mini age. In fact, some mainframe cases may mean even more to the desktop crowd today, with so many small computers hooked up as terminals on large systems. You might also say giant machines are acquiring plenty of pygmy siblings—joined Siamese style with them at the brains. And the big and small machines aren’t just wired together by phone or otherwise. Increasingly, mainframes are sending electronic copies to micros outside data-processing departments. What’s more, in power and capabilities, the pygmies are matching some big IBMs and Univacs of yore.

So whether you’re using a $1,000 Apple or a $100,000 mini, you’ll come out ahead knowing about the Golden Oldies of computer crime.

Computer consultants, especially Donn Parker, a prominent expert with the SRI think tank in Menlo Park, California, have labeled various offenses.[50]

Footnote 50:

The categories of computer-crime offenses, together with many examples, come from Donn Parker’s _Computer Security Management_, published in 1981 by Reston Publishing Company, Reston, Virginia. Another book for more information is Parker’s _Fighting Computer Crime_, published in 1983 by Charles Scribner’s Sons, New York, N.Y.

Data Diddling

When a time-keeping clerk hoodwinked a railroad, he committed the most tried-and-tested computer crime: =data diddling=.

That’s just jargon for fiddling with data before or during entry into the machine.

The culprit’s duties included filling out time forms for three hundred employees, and he learned that someone had shown a fit of absentmindedness in setting up a computer system storing pay and hour records. The railroad put workers’ names as well as their identification numbers into the computer. But the machine used only the numbers to track down names and addresses to print on checks. Manually processing the forms, however, humans normally ignored the computer numbers. They actually had the gall to think of the workers just by their names.

Wheels turned in the clerk’s head. Why not sneak in overtime pay by using other people’s names on the paper forms but _his_ own number for the myopic computer? And so his income increased by several thousand dollars each year.[51]

Footnote 51:

The example of the railroad clerk is from a report Parker coauthored for the Justice Department, “Computer Crime: Criminal Justice Resource Manual.”

The clerk’s end came only when an auditor by chance looked over W-2 forms and asked why the railroad had been so generous toward the man. Confronted, the clerk confessed. There’s a moral here: if you have a timekeeping and payroll system, don’t rely on ID numbers alone. Attach to them the first few letters of workers’ names. Also, include a cross-comparison of names and numbers in your auditing procedure.

Today scattered terminals—or micros or minis used as them—make data diddling as tempting as ever. A police officer in an eastern city told me criminals had walked into the offices of used-car lots, sneaked in a few minutes on terminals there, and altered financial records in a credit bureau’s computer.

Forget about the mystique of computer crime. People have been diddling credit bureau files for years by changing or deleting paper records. Machines and lack of paper records in some cases just make their work easier and faster.

The Trojan Horse

A comely woman at a New England firm was the victim of what might loosely be called a computerized sex crime.

“She would be doing her electronic paperwork,” Tracy Kidder said in _Soul of a New Machine_, “when suddenly everything would go haywire, all her labor would be spoiled, and on the screen of her cathode-ray tube would appear cold, lascivious suggestions.” Someone had electronically wheeled in a =Trojan horse=—hidden unauthorized instructions in the computer’s program.

The “sex crime” kept up daily for several weeks, leading an executive to observe that the villain must have “the mentality of an assassin.” It was unfair. Young computer whizzes at the company played horse pranks on each other all the time. But this victim couldn’t strike back. Gallantly, the woman’s bosses set electronic traps to learn from which terminal the masher was mashing. The villain, though, was too nimble. “At one time,” said Kidder, “he made his escape by bringing to an abrupt halt the entire system on which most of the engineer departments relied.” Finally, one of the woman’s protectors chatted casually with a suspect about the computer’s wondrous vulnerabilities to pranks. The obscenities and glitches stopped.

This Trojan horse was just a prankster’s, but the company may have squandered thousands of dollars in human and computer time to kill it off.

Consider, too, the company—Data General, the mini maker that Kidder admired.

Imagine a serious saboteur wheeling his horse into the computer of a company without the same knowhow.

It happens. Donn Parker says Trojan horse tricks are “the most common method in computer-based frauds and sabotage.” A horse, in fact, may have shown up in the first federally prosecuted computer crime in Minneapolis in the 1960s. A programmer told an IBM 1404 to drop an unflattering series of bytes about his personal checking account—overdrawn.

Trojan horses are more of a mainframe and mini problem than a micro one. Normally, professional programmers don’t run desktop computers.

But as computer literacy spreads, this might not matter so much, and besides, unsecured micros make such easy nuts to crack. “They’re peanuts,” Highland says, “not butternuts.” Most micro systems today lack electronic console logs—requiring operator ID numbers—that some bigger computers have to tell who did what on the machines. In other words, there’s no =audit trail=. John Lewis, an FBI agent teaching a course on computer crime, told me, “I can write a perfectly error-free payroll program on a micro, load it in from a disk, and run it. But I modify one or two lines in there, saying, ‘When you find John Lewis’s name, add $1,000 to net pay.’” You can even have the program zap the evidence immediately after the crime. Significantly, too, you can reprogram a micro in a fraction of the time you’d need on a mainframe.

And in the future the micros, while retaining their ease of programming, will develop more electronic nooks and crannies in which to hide horses. And what about the micros already hooked in at times with the big computers or using down-loaded data from them? If a saboteur or con man is giving fits to the giant machines, then the pygmy machines may suffer along.

The Salami Trick

You just can’t make sense of your savings account statement. No matter what you do, it’s a nickel off. You don’t, however, pursue the matter—not over five cents.

All over your city your fellow depositors are thinking similarly.

A computer crook, meanwhile, is growing rich.

The nickels, dimes, whatever, add up. He works at the bank and has programmed its computer to round interest downward, for instance, rather than upward. The sliced-off money goes into a dummy account. From hundreds of cheated customers, maybe thousands, he’s amassing enough over the years for a new Buick. He may even have told the computer to steal prudently and not clip anyone more than twice a year.

It’s the old salami trick, an MO of countless embezzlers inside and outside the computer world—ranging from pudgy, fat-bottomed drones to glamour figures in Hollywood and on Wall Street.

An amusing salami tale comes from Thomas Whiteside’s brilliant _New Yorker_ series on computerized crime. The name “Zwanda” did the crook in.

Programming for a mail-order sales company, he rounded down sales-commission accounts and diverted the loot to a dummy account for a “Zwanda.” The “Z” name made sense. The computer worked alphabetically, and he could more easily guide the money to the end account.

“The system,” Whiteside says, “worked perfectly for three years, and then it failed—not because of a logical error on the culprit’s part but because the company, as a public-relations exercise, decided to single out the holders of the first and last sales-commission accounts on its alphabetical list for ceremonial treatment.

“Thus, Zwanda was unmasked, and his creator fired.”

Could Zwandas show up in your company’s microcomputer—not just mainframes? Perhaps. It’s no less likely than the micro case mentioned earlier in which the bookkeeper was paying bogus bills from his relatives’ firms.

Of course, in the case of a micro, the trouble probably will be not in the way the program is written but in how it’s set. Most micros, after all, use off-the-shelf software.

Superzapping

It’s named after the “superzap” program used on some large IBM computers.

“Superzap” is known among the pros as a break-glass program, the kind you use in emergencies to change or divulge the computer’s contents. It can bypass all security controls. You can also think of =superzapping= another way. The computer is a high-rise building, and this program is a master key to all the apartments or offices inside. Pity the building manager if a thief can counterfeit the key.

Donn Parker, the source of those comparisons, says a New Jersey bank lost $128,000 to superzaps.

The crook was none other than the bank’s manager of computer operations. He first superzapped legitimately to change errors in accounts as his superiors asked. The main program wasn’t working—hence, the superzapping. The bank was upgrading its computer system, the glitches kept piling up, and the operations manager zapped again and again, discovering the joys of ignoring the normal controls. The usual electronic logs and journals just didn’t show his actions.

So, he decided, why not zap away the barriers to shifting the money to the accounts of three friends?

The bank learned of the crime only after a customer saw that his own money wasn’t adding up right.

Superzaps like this, of course, are simply special breeds of Trojan horses, just as the salami tricks _can_ be. Like the horses, the zaps aren’t so much a micro crime now. They’re more of a mini and mainframe one, but watch out for the future when garden-variety crooks are more learned and micros are more like the bigger computers.

The Trap-Door Trick

A =trap door=—or =back door=—normally is just a shortcut into the program, bypassing the normal security systems, meant as a debugging aid. Once the writers have a program up and running, they should get rid of the door. Large programs are so complicated that programmers sometimes leave the doors in as an emergency way for them to get back in if the main passwords are lost or the computer “hangs up.” David Lightman, the teenage hacker in the movie _WarGames_, used the trap-door ploy to penetrate a Defense Department computer and almost caused a nuclear Armageddon.

In a real-life example mentioned by Parker, some automobile engineers in Detroit called up a computer service bureau in Florida, found a trap door, and could “search uninhibitedly” for privileged passwords.

“They discovered the password of the president of the time-sharing company and were able to obtain copies of trade-secret computer programs that they proceeded to use free of charge.”

The electronic thievery didn’t stop until the company found out accidentally. And it never learned how many other crooks were rummaging around inside the computer.

Once again, this form of crime isn’t so much a worry for the desktop set as for those using bigger machines. At least for now.

The Logic Bomb

Heard the old joke about the Washington speech writer at odds with his boss? It’s a favorite story among journalists and other wordsmiths.

The aide was tired of drudge work for a dumb, lazy but electable congressman who didn’t even read the immortal prose ahead of time.

One day the politician, a square-jawed, movie-actorish man, was mellifluously speaking on the House floor. As usual, he was fresh to the material. But his rendition overwhelmed everyone, from the pols to the pages, to the tourists in the galleries. He _knew_ he was on his way to the White House.

With actorlike polish he intonated through the third page, including the last sentence:

“And now, let the words ring out, loud and clear, to all corners of the earth—to our friends, to our foes, across every ocean, every mountain. You purblind piece of excrement, I quit, and you’re on your own.”

The fourth page, of course, was blank.

Malicious programmers must nod and wink when they hear the story.

For the speech writer had just the right kind of temperament to hide a =logic bomb=—a computer glitch that explodes, so to speak, only under certain conditions.

The conditions in the Washington joke were clear. The congressman mustn’t read the speech to himself beforehand—something inevitable. He was dependably lazy. Nor must he understand the speech; no problem, certainly, for he was dumb about everything all the time. Above all, however, if this bomb were to “kill,” he must be embarrassable. And that’s why the bomb in a sense just maimed him—because, like most politicians, he never blushed.

In a real-life story told by Parker, a payroll programmer hid a bomb to erase the entire personnel file if he ever got fired—that is, if his own name ever vanished from it.

Simulation and Modeling

A crooked accountant embezzled a million dollars using =simulation=.

On his own computer he set up a mock version of the victim company’s accounting and general ledger. Then he could figure out how his thefts would show up on the company’s electronic books—and how to cover up the crime.

Scavenging

A Texan ripped off oil companies through computerized =scavenging=.

He used a computer time-sharing service bureau, the same one as the oil companies. This thief read scratch tapes—temporary storage tapes without the safeguards protecting the main ones—by phone off the service’s computer. He was stealing secret seismic information to sell to the oilmen’s competitors.

Finally, however, the service bureau caught on.

A worker there had grown curious. Why did a red “read” light glow at bizarre times? How come the customer was prowling through the tapes before entering his own data? Parker says a “simple investigation” ended the electronic scam.

Scavenging can be physical, too—nothing more complicated than rummaging through old trash barrels for printouts.

Data Leakage

“Hidden in the central processors of many computers used in the Vietnam War,” Parker says, “were miniature radio transmitters capable of broadcasting the contents of the computers to a remote receiver.

“They were discovered when the computers were returned to the United States from Vietnam.”

It was a =data-leakage= problem—defined by Parker and other pros as the removal of data or copies of it from a computer or a computer center. Culprits can even smuggle out secrets by hiding them in apparently routine reports. “Data leakage,” he says, “might be conducted through use of Trojan horse, logic bomb, and scavenging methods.”

You don’t have to be in the Vietcong or KGB, of course, to spy on a computer by radio. Today a smart snoop can walk casually into your computer area and leave behind a miniature transmitter—perhaps hooked up to the maze of wires that snake under the floor of many modern offices. “I could then find out everything that you were sending for a year,” says Harold Joseph Highland, “which is the life of the unit I could transmit with. I could buy it for

9.50 from any of the large supply houses. There’s one more expensive that will transmit up to five miles away. With the forty-buck one I can park across from the building and keep a tape recorder going.”

Wiretapping

Some say it’s rare in the computer world. The thinking goes, There are easier ways to steal. Why tap when so often you can just call up your victim’s computer and be greeted with a friendly electronic whine?

But don’t count on wiretapping not existing.

Your local radio store carries cheap equipment usable for tappers.

And electronic banking and new computer services will grow, making wiretapping more tempting. A security consultant, J. Michael Nye, opened an unlocked closet of the second floor of an office building in Hagerstown, Maryland, and pointed to the telephone wires inside. “See these?” he asked me. “They’re hooked up to a bank’s computer. If you wanted to change the amount of money in a deposit, you could attach a portable computer and no one might be the wiser.”

The wiretapping threat may increase because of the break-up of the Bell system—as more and more repair people parade in and out of wire closets.

You might be able to get around the threat, or at least reduce it, by electronically scrambling the messages you transmit over the phone wires.

For the moment, don’t let fear of wiretapping obsess you unless, say, you’re routinely transferring millions of dollars via computer.

Piggybacking and Impersonation

It’s bone cold outside, the stranger looks harmless, and you let him in as you unlock the doors of your apartment building one night. The next day all the old ladies in the lobby are talking about a burglary.

You fret. Rightly. You may have let a criminal succeed in =piggybacking= his way behind you into the building.

It’s happening, too, in computer rooms, which crooks use similar tricks to enter.

That’s physical piggybacking. The electronic kind, rare, can happen this way. You punch in a password or key on your terminal and hook up with the computer, unaware that the piggybacker has a hidden terminal connected to the same phone line. Perhaps you haven’t signed off properly. The computer keeps the connection going, and the piggybacker “rides” on.

=Impersonation= is what it sounds like, and it can be physical or electronic.

Leslie D. Ball, a Massachusetts consultant and college professor, once illustrated computers’ vulnerabilities to such tricks. “Why is it more difficult to rob a bank of $2,500 than to steal millions from its computer?” he asked, and quickly answered the question.[52]

Footnote 52:

All the Ball quotes and paraphrases in this chapter are from _Technology Review_.

“During a security consulting project at an Atlantic City hotel,” Ball said, “I spent the evening with an associate in the casino. At about eleven p.m. we headed for our rooms, but the elevator stopped where the computer center was located, and we decided to look around. The door marked ‘Computer Center—No Admittance’ was locked but had a bell beside it. A computer operator opened the door when we rang, letting us in without a word. For the next ten minutes we wandered through the center without speaking to the operators on duty.” In effect, by acting as if they belonged in the room, Ball and the associate were impersonating authorized people. “Finally,” he recalled, “we said, ‘Thank you’ and left. They were lucky we were not disgruntled heavy losers!”

A real impersonator, an ex-college professor named Stanley Mark Rifkin, passed himself off as a bank branch manager to steal $10.2 million. He bought diamonds in Switzerland. The law caught up with him only because, like many bright, cocky computer crooks, he bragged. That wasn’t all. “While awaiting trial,” Ball says, “he attempted a fifty-million-dollar transaction from another bank. When apprehended, Rifkin told a reporter that he thought he finally had all the bugs worked out.”

Rifkin was just another example of an ordinary man using legally acquired skills to commit an illegal act.

However smart, and despite his background as a computer science professor-consultant, he was hardly a _genius_. “Master criminal?” asked H. Michael Snell, a publisher who’d dealt with him.[53] “I could sooner imagine a smoking gun in the hands of Winnie the Pooh. In fact, Stan resembled Pooh Bear: short, stocky, paunchy from too much good food and wine, a deeply receding hairline above an intelligent, sloping forehead. Quiet, unassuming, not the kind of guy who’d stand out at a cocktail party.” Rifkin was good at puzzles, at problem solving, but as Snell and others agree, that’s true of all talented programmers. You could say the same, too, of first-rate accountants and engineers. Rifkin’s case made me think of Hannah Arendt’s phrase about Adolph Eichmann, applied not to the Nazis but to garden-variety crooks within the computer field: “the banality of evil.”

Footnote 53:

The H. Michael Snell quotes are from an article he published in _Computerworld_.

Rifkin’s take happened to be larger than most. But his mind-set was the same.

Snell said, “He shared the dreams of many academics who feel blocked from great success and wealth, and he loved ‘get-rich-quick’ stories, such as a friend who struck gold in California real estate or the Silicon Valley’s overnight millionaires.”

Greed, however, isn’t the only motive. “People who like computers are games people,” John Lewis, the FBI agent, told me, “and they like challenges. It’s ‘me against the machine.’ You give them a computer and say you can do anything but that, and that’s the first thing they’re going to do. You go back to the Book of Genesis in the Bible where God said, ‘You can do anything in the Garden of Eden but eat from that tree,’ and what’s the first thing people did?” We were in a windowless, fluorescent-lit room at the FBI Academy in Quantico, Virginia, where Lewis lectured on computer crime. He looked at a fellow instructor, a tall, alert man who started out in the bureau not as an agent but as a programmer. “I’ve seen Ken get ahold of material. Like this one program that said it couldn’t be copied. Now he didn’t care what the program did. The first thing he did was copy it. Because they said he couldn’t do it. And he did it.”

I thought of John and Ken three weeks later when I picked up a copy of _Technology Illustrated_ magazine.

A stranger in Quantico, Virginia, it seemed, was dialing up the electronic bulletin boards on which computer pranksters sometimes left messages. The bulletin boards were a form of electronic mail. Callers could write out their thoughts for friends or anyone checking up on the highest-numbered entries. The mysterious computer dialer from Quantico, however, would just read, never send. Aware of the FBI Academy’s location, one of the pranksters posted a friendly suggestion on a board.

He invited the Quantico caller to subscribe to the TAP newsletter—said to be “to phone phreaks what the _Wall Street Journal_ is to stockbrokers.”

TAP stands for a group named the Technology Assistance Program, a successor to Youth International Party Line (YIPL), whose own radical pedigree goes back to Abbie Hoffman’s Yippies. “Al Bell” and Hoffman started YIPL. It was a high-tech display of Hoffman’s _Steal This Book_ philosophy, there being, however, a serious problem, one shared by society at large. The technocrats usurped the politicians.

They were, reportedly, “more interested in blue boxing Ma Bell than in pushing politics.” Cheshire Catalyst, who was editing the TAP newsletter when I talked to him, said, “You don’t have to be a phone phreak to read us—but it helps.”

Lindsay L. Baird, Jr., a tough, no-nonsense consultant with famous corporate clients, told me TAP was a serious threat. “They’re now using micro systems to test the 800 numbers methodically to see which ones have computers on them,” he said of some TAP people. The corporate computers whine their strange mating call no matter who dials up, saying electronically, “I am here, I am a computer, I am ready.” You might say they’re like an unlocked, unattended BMW left with the motor running in New York City. And Baird claimed, rightly or not, that TAP has some political zealots mixed in with the technocrats and that they could indulge in large-scale computer zapping over the next few years.

The TAPpers’ side was this: they illegally logged on to networks like Telenet and the feds’ because they couldn’t stand seeing expensive computer time go unused. “Nobody wants to pool it as a computer utility and make it available to everyone because it would probably not make a profit,” groused “A. Ben Dump” in the newsletter. Cheshire portrayed TAP to _High Technology_ as basically just pranksters, at least in his case. “Good grief!” Cheshire once ghost-wired to a Telex machine; “I seem to have reached Adelaide, Australia. This is just a computer hacker in the United States out for a good time.” The TAPpers said they were against the Bell bureaucracy, not America at large, and, in fact, censored an article submitted to their newsletter telling how to build an H-bomb. “Among other things,” Cheshire worried, “anyone using that technology is going to take out the phone network.” I still wondered. Would TAP have printed the article if a way existed to H-bomb the countryside without toppling any microwave towers?

■ ■ ■

Hacking: An Addiction to Be “Squelched”?

With _WarGames_-style break-ins in mind, someone once called hacking an addiction to be squelched.

That’s wrong. Hacking is more an addiction to be tamed.

The term “hacking,” perhaps born at M.I.T., just means someone who hacks away at computer problems until he solves them. Many hackers for some reason or another love Chinese food. Sooner or later a computer-crime expert will link computer addiction to ODing on monosodium glutamate.

Cheshire Catalyst is a prototypical hacker in many ways. He’s a thin, bearded man in his twenties, extrapolite, who, when I saw him, was in Washington for an aeronautics and space gathering and wore a Space Shuttle tie and an Apple pin. His nickname indeed came from the grinning, vanishing cat in _Alice’s Adventures in Wonderland_. Proudly he told me how his clock ran counterclockwise. Cheshire said he hoped someday to meet another backward-clock buff, Grace Hopper, a distinguished military officer who helped give the world the COBOL computer language.

Cheshire might find even more of a soulmate in Steve Wozniak, the Apple cofounder, who is perhaps one of the world’s leading hackers—in addition to having been a phone phreak in his time. “Woz” and a friend snooped on computers across America. The friend was John Drapper, a bearded, somewhat maniacal-looking man who earned the nickname Cap’n Crunch because he used prize whistles from cereal boxes to steal free long-distance calls by way of a tone at exactly the right frequency. Later, Crunch wrote the EasyWriter word-processing program used on the Apple and later the IBM PC.

On balance Cheshire thinks that hackers do more good than harm. “Let’s say you have money in a bank,” he says. “Wouldn’t you rather that a hacker get into its computer than a criminal did? He could warn the bank. If I had money at a bank, I’d feel safer with hackers checking out security.”

Well, it depends. Some hackers are nothing more than electronic vandals. Some are a privacy threat; they’re doing the equivalent of spying on mail and tapping phones.

Still, talented hackers may become real assets to corporations. They’ll care infinitely more about your computer system—and all its quirks—than will programmers working nine to five for the money alone. Just a little oversimplistically it’s been said that you can befriend a hacker merely by supplying a computer with enough RAM, encouragement, a long leash, and lots of chow mein.

■ ■ ■

The TAPpers, depending on your viewpoint, came across in _Technology_ as reassuringly or distressingly middle class. Cheshire at the time of the article was teaching computer skills at a large corporation. “VAX-man”[54] worked as a computer programmer, “The Librarian” as a systems analyst, and another was, of all things, a middle manager for a defense contractor; indeed, every member reportedly boasted a technical background. Most, I suspect, perhaps nearly all, didn’t see themselves as criminals.

Footnote 54:

Presumably VAX-man chose his name with both the VAX minicomputer series and the Pac-Man game in mind.

“We’re just an information service for the people,” said one.

Well, okay. Maybe it’s good that if G-men want to bone up on the latest electronic tricks, they need only log on to hackers’ bulletin boards and read the TAP newsletter. Still, how many crooks have the same idea?

TAP’s another indication that for the criminally greedy the “data cookie jar,” as it’s been called, is out there.

Lindsay Baird scoffs at computer trade associations’ efforts to play down the problem. And he fires back with statistics of his own. “I’ve worked on thirty-five or forty cases,” he says, “and only one was reported to authorities.” The loot ranged from $40,000 to $29 million. And Baird, dismayed that some computer criminals’ sentences are more shoplifterlike than adequate, jokes, “My wife tells me I ought to commit a crime.”

“The security problems with computing systems in the 1960s was like a balloon deflated,” he says, “and you could hold it in your hand. But now it’s like a huge balloon inflated. Or a big bowl of Jell-O.

“You just can’t handle it now, and the manufacturers have got to be concerned.”

Of course you should remember that most corporate data are far from sensitive, that only the most self-important executive would view everything as a national-security secret. Also, Baird is hardly hurting his bank account in sounding the computer-crime alarm. Still, he’s basically right in saying that computer buyers _with sexy data of interest to thieves_ now may have three choices:

1. Burden programmers and others with electronic versions of heavy padlocks.

2. Keep their computer systems easy to use—and vulnerable. (“Then you’re going to get raped.”)

3. Compromise. (“You get half raped.”)

Baird doesn’t blame just the manufacturers for some computers’ sievelike leaks. “Business isn’t willing to pay the price to secure systems,” he says—a complaint echoed in effect by the Computer and Business Equipment Manufacturers Association (CBEMA). It acknowledges the present clash between security and ease of use of computer systems. “If a computer could be designed with various levels of security as options, computer security might well be a marketable commodity,” said a statement from CBEMA to a trade magazine. In recent years there has been much more research in this area, and when 32-bit micros become the norm, it will be much easier to beef up security.

When crimes do happen on existing systems, they’re often covered up by top executives panicky over going to court or jail.

How’d you like to be the chairman of a corporation faced with an ugly data-security scandal—and the possibility of a stockholders suit? You needn’t be in the scandal personally. Your stockholders could charge you with malfeasance, if not misfeasance, for _letting_ it happen. So could the Securities and Exchange Commission and other feds. When companies hush up computer crimes, it’s not necessarily for high-minded reasons such as protecting assets by playing down vulnerability to electronic crime. Consider Baird’s experiences.

Called to a New England firm to do routine theft prevention, Baird merrily put himself on the payroll—not to steal but to demonstrate system weaknesses.

“I also,” he says, “nicked the vice-president for participating in a $400,000-a-year kickback.”

At another company, an accounting firm did the books at year’s end and had to make an adjustment of $1.2 million. “Then,” said Baird, “we went in some more and really did a number on that company. And we came up with $4.5 million in proven losses. And it all had to do with their computer system.”

But, you’re wondering, how about that crook who stole $8 million and got away with it?

The story—perhaps apocryphal but told in the sedate _Smithsonian_ magazine—is that bank officials confronted the thief in a restaurant over breakfast.

He coolly confessed. If they tried to jail him, why he’d blow the whistle on the bank’s vulnerable computer system. And it would cost more than $8 million to fix.

So the bank officials just asked him to step down quietly.

Leaving the table, the crook smiled.

“I’ll keep the eight million,” he said, “but I’ll pick up the tab for breakfast.”

Definitely, then, Donn Parker was on target when he once called computer security “first and last a people problem.”

People and Policies: Working with the Right Ones

Honest, loyal employees are more important than the latest security gizmos. Use common sense. Beware of the $26,000-a-year programmer who suddenly acquires a posh home and a sports-car collection. Don’t pry. But don’t shut your eyes, either.

Start with a sensible hiring policy. Decide on the questions you want to ask applicants and their references—about the prospective employees’ backgrounds and characters. Then bounce them off your legal department. The rule of thumb is that you won’t get in trouble if the questions are related to the job. IBM has said it doesn’t even ask applicants about their ages or marital statuses. If there aren’t legal obstacles, you might invest $25 in a credit-bureau check of a keypunch clerk but perhaps several hundred dollars for a top programmer. Keep in mind the notorious lack of reliability of many reporting services. Check for criminal records when hiring for responsible positions. A Maryland hospital didn’t. It hired a convicted embezzler, a computer operator who later diddled $40,000 out of the system.

Granted, there are occasions when you might knowingly hire an ex-con to give him a chance. But ask the normal questions. What’s he done to justify your trust since his sentencing? What are your risks? How much could he steal, and how?

Whomever you hire—ex-cons, Harvard grads, or combinations of the two—know how to respond to the common criminal motives.

Jay BloomBecker, a top computer crime expert, sums up one of the main motives by quoting the title of a collection of Doonesbury comic strips: _But the Trust Fund Was Just Sitting There_.

Reduce the temptation. Let your people know there’ll be surprise audits—and mandatory vacations. A thief busy slicing salami might be loath to take too much time off, lest his or her replacement catch on to what’s happening. Likewise, consider rotating duties every few months and also divvying them. People who write checks with computers, for example, ideally won’t be the ones approving them; in a small business, of course, this might not be possible.

The old need-to-know policy, of which the military is so fond, may also increase the criminals’ risks—by increasing the need for collusion. This, too, isn’t always possible, and it could boomerang. If employees aren’t supposed to know what their colleagues are doing, maybe a thief would actually have less chance of being noticed.

Also, tell people that stealing—even small amounts from a large company—_will_ hurt. If you can’t prove how it will hurt the corporation noticeably, then you’d better make a good case that it will hurt them. Pretend you’re a department store warning the nimble fingered: “All will be prosecuted.” Well, within bounds. You needn’t fire and prosecute a thirty-year man because he once used a company micro to calculate his average golf score.

But do remind your employees of the applicable theft-of-service laws, larceny ones, and others.

Not that electronic theft is your only problem. Whiteside tells of a computer-ridden North Carolinian, working for an insurance firm, who reportedly shot a handgun several times at the hated machine. And Harold Joseph Highland offers another cautionary tale. Executives at an East Coast firm fired a crabby woman, then returned the next Monday to find its floppies sliced apart with a paper cutter. They never proved her guilt. Regardless, _someone_ moved the blade up and down, costing the company several hundred thousand dollars in time reentering the paper versions of the records into the computer. And that doesn’t even include the orders canceled by customers angry over the delay. In yet another story, a disgruntled worker short-circuited a terminal by urinating on it.

“Hire well,” says Jack Bologna, an expert on the “people” side of computer security, summing up ways to avoid such traumas. “Pay fairly, praise people for good work, give them opportunities for advancement, and make them feel comfortable talking over their problems.”

Remember that the line can fuzz between outright sabotage and simple sloppiness induced by poor morale.

If there’s a disaster and you’re not sure if it’s accidental or deliberate, however, don’t be too quick to point your finger. You may find it chopped off with a lawsuit filed by your suspect, perhaps for less than $1,000, while your firm must spend several times that to defend itself. Unjustified accusations, also, hurt morale and may even add to security problems.

And if you do prove theft or sabotage?

Act. Don’t cover up. Rather, cover yourself—legally. Tell your boss what happened. If you’re mum and someone else reports the crime, your superior may consider you among the guilty. Also, don’t discount the possibility that your boss may himself be either guilty or a part of a cover-up because he fears a stockholders’ suit. You may have no choice but to report him to _his_ boss. Press for an independent audit committee if you’re powerful enough and if the size of the crime justifies one.

Should you fire someone for a computer-related offense, do it artfully.

“If they’re in a critical job position, help them clean out their desk, collect their ID card and any office keys, and walk them to the door or to the personnel department,” says Timothy A. Schabeck, who edits _Corporate and Computer Fraud Digest_ with Jack Bologna. The FBI’s Lewis says as much.

If you do prefer instant firing, follow Schabeck’s advice to provide counseling and severance pay. And soften the blow, too, by warning everyone, when hired, that your axes are quick and sharp.

Mightn’t instant firing, however, be brutal, anyway? Well, it depends on the amount of damage that a discharged employee could inflict and on how vindictive you perceive him to be. Ideally, you could minimize the damage by having backup disks or tapes out of the your victim’s reach. Also consider how successfully you can keep the fired employee from returning to your computer—by ruse or otherwise? Is your office absolutely physically secured? Can you trust guards or janitors working weekends not to admit a familiar face?

It’s all a part of bridging the gap between policy and practices.

Don’t just wait until a crime to make your staff security conscious.

Too often, warns James A. Schweitzer, a Xerox security expert, people protect information only if it’s on paper. He says, “There have been a number of cases where tapes and disks have mysteriously disappeared from places like desktops.” If need be, designate an employee to make sure others have locked up right by the end of the day. In less than a minute, using a floppy disk, a thief may duplicate hundreds of times as much material as he could on a paper copier.

Worry, too, about your people’s use of _modems_—the gizmos that transform your computers digital output into a whiny sound for the phone lines.

Don’t let them routinely keep sensitive material on disks that will play back to savvy criminals who happen to dial in.

This especially applies to Winchesters. They’re the oxide-coated aluminum disks that remain in the machine housing them, and they stash away many times the amount of information on most plastic floppies. Now imagine the delights awaiting a thief or snoop. Via your auto-answer modem he could rifle thousands of pages of Winchestered documents. Such electronic robberies needn’t happen, but until businesses get burned this way, they will. So if you’re sharing an electronic spreadsheet or mailing list with your branch office, do so if possible at a prearranged time during business hours when you know who’s calling. Tell your people to do the same.

You’ll also need a privacy policy—internal and external. Do you, for instance, want salary information on a Winchester disk that any of your company’s computer-users could read? And how about employees’ health records? Good data security should protect your people as well as your company. So limit your computerized records to the essential and tell your executives not to use their home computers to bypass privacy laws.

Worry, too, about an external-privacy policy. Are you respecting the rights of your customers, including those, who, by computer, may be transmitting to your company _their_ electronic jewels?

It isn’t just decency you want; it’s also good protection against suits, whether from people or client companies.

Here again, set a firm policy against your people misusing their personal micros. Alan F. Westin, a Columbia University professor of public law and government, correctly warned in _Popular Computing_, “A financial officer of a bank might store information about the life-style, habits, sexual preferences and other personal behavior of large individual borrowers or key corporate executives.” The banker might do this behind customers’ backs to help decide who was “stable” enough for loans.

You’ll also need a policy covering employees who use your computers for, say, maintaining their church’s bingo books. Why not let them? It isn’t the worst public relations. Some companies even allow their employees to play games after hours, tapping into company systems from home, and you, too, might experiment with this, provided it won’t add to your data-security problems. Better a fringe benefit than a crime.

On the other hand, you’ve got to draw the line somewhere. Can you estimate how much this extracurricular use of your machines costs in wear and tear—in, eventually, replacement costs? Feel your employees out on this one if you’re running a small business or hold sway over a large one. Would they rather enjoy computer privileges or better health insurance? You might offer cafeteria-style fringe benefits, with computer use as one of the options. Employees not selecting this choice might have to agree to it, anyway, if you discovered them using a company computer for personal purposes. This problem, of course, may lessen as the prices of small computers plummet and their capabilities grow.

Whatever the form of potential crime—theft or otherwise—keep remembering one of the basics of data security: It should cost neither more money nor morale than justified.

Hardware and Software

Now for advice on finding the _most_ crookproof computers and programs.

Buy a micro with 16- or 32-bit word lengths and RAMs of 256K or more. Those specifications will let you use more elaborate codes to protect information. What’s more, they might be less cumbersome than codes on an 8-bit machine. Look, too, for electronic design that lets your computer establish privilege levels—reachable through passwords. That way, Sally, the new secretary, can start out getting into the computer only for word processing. Helen, the payroll clerk, can have access to confidential salary information but not a top-secret budget that doesn’t give her the raise she’s been pestering you about. Questions exist about the effectiveness of passwords and codes, at least when the thieves or snoops may be sophisticated, but that’s another story. Most experts will tell you that anything that can be coded can be cracked. The trick is to make it not worth the criminals’ time and resources. Of course, the best safeguard is still the simplest: locking up the disks and computer after you or your people are through.

New minis, by the time you’re reading this, may all be 64 bit or higher. They adapt to codes—and fancy electronic logs showing the kind of work done on them—more easily than do micros. And they might justify other costly security measures. Suppose, for instance, you want to follow the many government agencies’ examples and pen in the tiny radio waves that computers emit so that eavesdroppers can’t pick them up with sensitive receivers. A micro fortified this way might cost perhaps $10,000. “What’s the sense of doing that for what’s essentially a throwaway computer?” asks Harold Joseph Highland. The “throwaway,” be assured, is an exaggeration, but his point comes through.

Of course, don’t forget the disadvantages of minis.

Most machines at the mini level or above need professional programmers, and that’s bad news if you’re trying to stay in complete charge of your business.

Also, minis, because of their expense, normally won’t pay for themselves unless they have at least several terminals.

And the more terminals you have, the more “doors” through which crooks can “walk.”

Still, you normally shouldn’t let security alone determine if you end up with a micro or with a mini. Remember the warning earlier in this chapter that security costs shouldn’t overwhelm you. How often, for instance, is your information so sensitive that you’re worried about criminals lurking in the bushes with the elaborate equipment needed to make sense of the tiny waves your computer emits? Your data might not even justify use of codes.

I myself haven’t the slightest need for codes, user-privilege levels, anything other than locking up my disks, since I’m essentially a small businessman who is the sole operator of a micro.

Even the FBI doesn’t really worry about security on some computers. At the time I visited the agency’s academy in Virginia, several little Radio Shack models were purring away there—the same kind you’d buy off the shelf. The micros’ software had passwords, but some agents could bypass them, anyway, which wouldn’t be necessary, of course, since, in this case, the FBI _wants_ the machines to be used.

Before saddling yourself with fancy electronic precautions, do see if a security service, a good, heavy safe, a locked room, or a burglar alarm would work instead. And what about simply carrying home some duplicates of your most important floppies? That possibility will become increasingly attractive as the disks’ storage capacity increases. This isn’t to say, however, that you should store Exxon’s major corporate secrets in a dirty unlocked drawer next to old underwear. But a small businessman might consider taking his backup disks home.

If you buy a safe for your office’s disks or tapes, think about fire protection. Check with your fire department. What makes of safes could be in the middle of the flames without the disks suffering temperatures of more than 115 degrees Fahrenheit?

Investigating locks and burglar alarms, you’ll learn that your computer may be able to protect itself. How? Some gadgets can let only card-carrying employees—your people with magnetic cards—enter a room. And they can tie into the computer to save you money. The same applies to burglar alarms. Of course, you might want nothing fancier than a strong lock bolting your computer to a heavy table. Don’t spend more than the data are worth to replace.

You might also consider a guard service. The problem is that salaries add up even for quick nighttime checks.

After a few months or a year, you may be well on your way to having shelled out the cost of an elaborate electronic security system. Guards normally would be more appropriate for users of large minis and mainframes than for desktop types.

One advantage of physical security—most any kind—is that it can protect the computer equipment itself, not just your electronic files.

You’ve undoubtedly read of theft of computer chips from Silicon Valley firms. Now be prepared for reports of widespread computer theft, eventually, as the market grows for both legally bought and fenced merchandise. With computers shrinking in size, they may well be an even hotter item for fences than stolen Selectrics. Even Apples several years ago were too intimidating to a burglar, like the one who stole the silverware of an acquaintance of mine but passed over his computer. Be assured, though, that crooks are increasingly computer literate. There’s even talk of the mob moving into computer crime, raiding government files, and, presumably, engaging in less challenging illegalities, like setting up computer-fencing rings.

With computer crooks in the future being smarter and more organized, you should think hard before depending on simply passwords or codes to protect you.

First, assume that at least some people may try to unravel your puzzles. A whole generation of prodigies right now is practicing by copying the supposedly uncopyable computer games on disks. In effect, notes Churbuck, the New Hampshire lawyer, each disk provides two puzzles. One is the original game. The other is the puzzle of figuring out how to make illicit copies. And at the University of Western Ontario, Prof. John Carroll surveyed students in two advanced computer courses and found that one-third had sought free, illegal computer time. It’s been pointed out that the very best, the very brightest, students have too many legitimate opportunities—on large systems—to worry about pillaging small computers. And that may be true. But by the late 1980s or early 1990s, some journeyman criminals may develop among the second-raters.

Second, don’t shrug off a warning from R. E. (Bob) Kukrall, author of the handbook _Computer Auditing, Security and Controls_: “Cracking a computer system’s defenses may be about as difficult as doing a hard Sunday crossword puzzle.” He says that thieves managed in minutes to call up computer files that were protected by a five-digit code number. They just programmed the computer itself to try each of 100,000 combinations.

“In effect the speed and capabilities of the computer were used to violate its own security,” Kukrall said in _TeleSystems Journal_.

■ ■ ■

How the _National Enquirer_ Gets Some Security along with Bargain Communications

Some _National Enquirer_ reporters send in stories via computers, but there’s little danger of rival tabloids spying on the computer collecting the articles.

The reason? There’s no receiving computer, actually—just an auto-answer modem rigged up to a dot-matrix that spews out paper copies at several hundred words a minute.

The modem and printer can’t send messages or relay stories elsewhere. But who needs that—not when some computer-smart _National Star_ reporter might give his eye teeth to find out what the competition is up to?

To be sure, the scheme has some problems:

● The _Enquirer_ can’t transfer the reporters’ stories to a computer there for editing, since they are on plain old paper but not in an electronic format. Editors, however, heavily rewrite the original stories. Capturing reporters’ key-strokes for the typesetter wouldn’t help as much as at an ordinary newspaper.

● Theoretically someone could still steal the hard copy (just as he or she could sneak off with a floppy disk).

● The system isn’t secure against telephone tappers who could translate the modem whines.

Still, the system is dirt-cheap. If knowledgeable, you could probably replicate it for less than $500 for the printer and modem. And you could send to it with just a $400 lap-sized portable.

Beyond that, the _Enquirer_’s arrangement may be safer than leaving an unprotected computer on the phone to collect unencrypted files.

■ ■ ■

Then there’s the Dalton school case in New York City in which the four culprits, age thirteen, violated silicon sanctity hundreds of miles away. The feds caught up with them before they could steal Pepsi Cola, by coaxing an order out of a warehouse. But another computer didn’t fare so well. The thirteen-year-olds destroyed more than one-fifth of the 50 million bits in the machine’s memory, inspiring a magazine writer to call them “electronic Huns.”

More recently, the 414 Gang out of Milwaukee—named after their telephone area code—broke into computers across the country. These half-dozen or so high school students, tapping on home micros, broke into more than sixty computers and among other things they:

▪ Hooked up with a VAX 11/780 at Sloan-Kettering Cancer Center in New York. Eighty hospitals across the U.S. were using the computer to help treat hundreds of radiotherapy patients.[55]

▪ Broke into an unclassified computer at the Los Alamos nuclear laboratory.

▪ Penetrated a Security Pacific Bank computer in Los Angeles. That may not have been so much a challenge. The account name and password both were “SYSTEM”—a word that many computer manufacturers routinely put in new machines and that their customers often forget to take out. “TEST,” “DEMO,” and “MAINTENANCE” are other old standbys.

Footnote 55:

The 414 invaders fortunately didn’t alter radiotherapy information. But they reportedly did zap a file used to bill customers a total of $1,500 for computer use.

If teenagers can wreak Attilan havoc and snoop on a bank computer, then think of adults.

So use passwords and codes, knowing their vulnerabilities. Try, anyway, to give computer crackers a good challenge by avoiding use of obvious passwords like street names or those of wives or children. Consider a two-level password; also, maybe one with two words of pure gibberish; that’s what CompuServe does. And, obviously, purge the computer of standard passwords in the “SYSTEM” vein.

If your system permits dialing in through a modem, see if it can limit the number of tries that people can make before the modem hangs up the phone. Your dial-up computer should send its name until the caller has given the right ID. Be careful of overly helpful =prompts= that lead callers on to the next step. “A prompt saying, ‘Hi! This is the Last National Bank Disbursement Department,’ sort of gives the game away, doesn’t it?” says a _Creative Computing_ article laying out precautions. Also, change passwords regularly. And if an employee’s leaving? Change the access codes.

Here’s what I’d ponder if shopping for a password or encryption system:

1. How hard, exactly, would it be to puzzle out? Just how many combinations would a computer cracker have to try? Could he easily do this through his own machine—or yours? You might want to consult a cryptography expert to learn how much of a challenge _this_ particular program would be. You’d be surprised. You may see the manufacturer’s claims instantly deflated.

2. How compatible is the program with your computer? If security is so important, choose the protective software first, then the hardware—assuming, of course, that it will run your applications programs.

3. Is the security program easy to use? If it’s too hard, it’ll be self-defeating. “Ease of use” would include how much time the security software adds to your normal tasks.

4. Are you certain the program won’t jeopardize the accuracy and completeness of your files by making you more accident-prone?

5. Should you expand your system, will the security software be able to grow along?

6. Do you want a =public key= encryption system? It works this way. You pass out a code that people can use in sending messages to you. Only you have the means to unscramble them, though.

7. Will your code be based on the =Data Encryption Standard= (=DES=), published by the U.S. government and repeatedly tested by the National Security Agency (NSA) and the National Bureau of Standards? To this day the rumors persist that NSA has built in a trap door to snoop on DES-style codes. True? I don’t know. Captain Zap says, “I don’t trust it. I don’t think NSA would have approved it if they couldn’t crack it.” NSA-approved codes are overkill in all but the most sensitive systems.

Telenet has a special interest in encryption software. It is the network into which thousands of computer users dial to reach other machines and services like The Source.

In 1984 Telenet claimed to be the first public network offering encryption software—a package for the IBM and clones that uses the public-key method and sells for somewhere under $600.

“You have a directory that has all the public keys in it,” said Claudia Houston, Telenet public affairs manager, explaining the Phasor software’s operation. “You look up the guy’s key that you want to send a message to. You punch that key and your message gets encrypted.”

For a two-page message, a Telenet man says that might take thirty seconds. Then you’re ready to send over the phone lines. Even if someone wiretaps you, theoretically, he won’t be able to puzzle out your secrets.

MCI Mail also offers encryption—through a customized version of a popular communication program—and other electronic networks will undoubtedly follow suit.

“Black boxes,” or hardware that scrambles messages, might likewise help; the topic is too complex for me to cover here in the detail it deserves. This equipment usually costs well into the thousands. One security expert, J. Michael Nye, even puts out a consumer’s guide to black boxes.[56] A good black box could be just a special modem with scrambling circuits built in. “If no one else produces a good, low-cost modem with encryption,” says Nye, “I might start doing it myself.”

Footnote 56:

After writing a draft of this chapter, I helped Nye prepare a section of his black box guide.

I find it to be useful, but overly technical for some lay people.

Nye may be reached at Marketing Consultants International, Suite #214, 100 West Washington St., Hagerstown, Md. 21740. Call 301/791-0290 for the latest information about the guide’s price and other details.

■ ■ ■

Captain Zap’s Wisdom on Protecting Your Dial-up Computer

The Captain and friends stole—via computer connections—over $100,000 in goods and $212,000 in services, including a $13,000 Hewlett-Packard minicomputer. He received a $1,000 fine and two and one-half years’ probation, with fifteen hours a week community service.

Far from being 100-percent antiestablishment, however, Zap is a Philadelphia Republican fond of wing tips. (“They show good breeding.”) And a computer security consultant, a client, praises him as “a damn good technician.” A computer-crime expert named Jay BloomBecker isn’t so keen on the use of e×-criminals in security: “There are a lot of people just as bright who have stayed within the law.” Regardless, Zap has some good tips for security-minded computer users, especially those with dial-up machines. Among them:

▪ _Don’t think of computers as gods._ “Remember, there’s just another human at the other end.”

▪ _Spread out your computer numbers; you might even use different telephone exchanges._ Don’t have numbers adjacent to each other—like 555-1212 next to 555-1213. If you do, your computers will be easier targets for hackers with _WarGames_-style dialing programs that scan local exchanges for computer numbers.

That’s good advice from Zap. In the same vein, even if you have just one micro, you might consider trying to get a phone number in an exchange miles from your actual location. You might even want to use a tie line to another city. It all depends on whether you think the costs would justify the added protection; for many businesses they wouldn’t.

Also, you might keep your modem number secret from people who don’t need to know. A Hollywood director, fearful that computer-smart science-fiction fans might tap into his dial-up machine, used such a precaution. Only he and his regular callers knew the number. His super-secretive approach obviously wouldn’t have worked in a typical business, especially one with many phone lines coming in. Also, nothing’s foolproof; suppose an electronic snoop unlocks your building’s wire closet.

▪ _If possible, use modems faster than 1,200 baud._ Then, says Zap, “most hackers’ modems can’t keep up.” Most small computers’ modems transmit at 300 baud, about 300 letters or numbers a second.

▪ _Remember that hackers can be ingenious._ “Don’t be smug just because you have a dial-back modem. That’s a device that makes callers tap out a special code, and then it rings them back at their authorized location. You can get around it by tying into the central office and setting up a three-way call—without anyone hearing you. I know hackers can set up three-way calls. I’ve done it myself.”

▪ _Protective devices, however, are better than nothing at all._ “Despite their limitations, I’d still install a call-back arrangement or a device that asked you for a code—or maybe a combination of the two. A combination usually would be much better.”

▪ _Don’t get hung up on protecting your dial-up computer with just hardware or just software—use both._ “Black boxes can help keep the wrong people from breaking in. But you also need good security software to control _how_ deeply even authorized people can get into your computer. You want some people—like customers—to have only _partial_ access to the goodies inside your system.”

▪ _Watch what you throw away._ “Some hackers can log onto your dial-up computer after first poking through your trash—for printouts with passwords and similar material.” Another hacker jokingly refers to “The Dempster Dumpster Library.”

■ ■ ■

Don’t lose track of security threats around your office itself while worrying about modems and encryption. Would you believe that you can’t absolutely erase an electronic file—say, a letter or report on your disk—just by following the directions in your software? A snoop might recover the information with a special program like Disk Doctor. Luckily, however, you can zap a sensitive file by magnetically “writing” over its part of the disk. Say you want to wipe out a letter 500 words long, File A. Well, do the following:

1. See if your disk has a file at least 500 or 600 words long. If so, make a copy. If not, type out a file that long. I’ll call this new file “B.”

2. “Write” File B’s contents under A’s name. “Overwrite” in other words.

3. Erase A.

To _really_ erase an entire disk? Well, don’t depend on your computer’s “copy” program or “format” program. Instead, just sweep a magnet over it—within a quarter inch or so.[57]

Footnote 57:

My thanks to J. Michael Nye, for calling my attention to the problems of incomplete erasures. Ed Bigelow, of Adevco, a Pennsylvania company selling networks to link computers in the same office, also was helpful.

So much for the James Bond kind of data security. Now on to coffee spilled on floppy disks.

Whether it’s coffee or Coke, unless you’re careful, you’re possibly going to be your own biggest data-security threat. Just ask people like Betty Cappucci, a quality-control manager with the Dennison Kybe Corporation in Kopkinton, Massachusetts. “Most of the time,” she says of returned disks, “it isn’t the disk—it’s spit or fingerprints. All you have to do is look at offices with people eating their lunch near their computers.”

“We see disks coming back with cigarette ashes and coffee stains,” said Jack Fitzgerald, who at the time was a field engineer with another disk maker.

And it isn’t just the very smallest computer users who abuse their disks. “The big problem in computer facilities,” he says, “often is cleanliness. I’ve been to a large investment firm in New York City and seen apple cores on the floor, Big Mac containers near the disks. And yet they were complaining of data-loss problems.

“This was a major investment firm with all sorts of ads on news programs and football games about how carefully they protected your money,” says Fitzgerald. “No investor lost money in this case because the firm at least had backup disks. But the company itself lost thousands of dollars of processing time—money they could have spent helping their investors earn more.”

A programmer with a Florida accounting firm, however, didn’t even have a backup when his disk crashed on a large computer.

“He was actually crying on the phone,” Fitzgerald recalls. “He had lost two disks. And he was willing to pay $20,000 to get data off them. His job was on the line.

“I’ve had disk crashes myself,” Fitzgerald says, discussing his off-hours work on his micro. “I was developing a small game similar to Space Invaders. I lost power on my computer and about three hours of work. I ignored one of my basic rules, which is to back up about every 20 lines—make a copy on a second disk.” Captain Zap’s rule is, “Every fifteen minutes, save on both disks.” That’s extreme. Like all forms of security, apply this in relation to the trouble it would take to recover a loss.

Even Paul Lutus, famous in the industry for his work developing Apple software, has a scary crash story.[58]

Footnote 58:

The Lutus story is from _Popular Computing_.

He’d toiled to develop a new program, of which he took two copies to the company. An electronic glitch cost him one of the copies. The sun melted the other. It seems that Steve Jobs, an Apple cofounder, had put the disk under the windshield of his car. “I ended up very carefully prying apart the case of Jobs’s copy and switching the floppy disk inside to another case so we could recover the programs,” Lutus says. “I haven’t always been so lucky.... For me the biggest drawback to personal computing is the quality of the mass storage. I dislike floppy disks intensely.”

Here’s how you can help your floppies and data survive threats more immediate—sloppiness and stupidity:

1. Zealously enforce a no-drinking, no-eating policy around disks, at least if trouble develops.

2. Remember the Rothman Dirt Domino Theory. Dirt, dust, and grease often can sneak up on your floppies indirectly, in stages. You start with clean hands. Then, however, they fall domino style when you touch a dirty table or one with your office mate’s submarine-sandwich drippings. You return to your own desk briefly before you yourself leave for lunch. You don’t work with floppies then, and you wash your hands after eating, but during your brief stop at your desk before lunch, you’ve already left a trace of grease behind, anyway. Your disk box picks it up when you set it on the wrong spot on the desk. Then, working with the floppies, you lay one atop the box. Now the disk itself fails. Alas, most disk failures aren’t gradual like a recording that gets progressively noisier until you can’t stand to listen to it anymore—they tend to be sudden and total.

3. Realize that floppies don’t always mix well with office materials that correct errors the old-fashioned way—erasers, for instance, white-out fluid, or that unavoidably flaky correction tape.

4. Know about other natural enemies of floppies or at least of the data on them. Beware of airport metal detectors. A disk maker says this isn’t a problem; but don’t gamble, since a magnetic detector, misadjusted, might still mush your data. Beware, too, of telephones atop disks: the magnets in them are powerful.

5. Don’t even let your floppies rest against your computer’s screen, which, like a television’s, can be full of static electricity, attracting dust.

6. Remember that the more information you can pack on a floppy, the more vulnerable it may be to damage from dirt, fingerprints, magnetic fields, and other causes.

7. Clean your disk heads. Don’t use rubbing alcohol. “Try something like a Freon-based material with 91 percent pure alcohol,” Fitzgerald says. “You can get it at some computer stores.” Or, after every twenty hours of operation, use a cleaning diskette, three of which typically come in a $15 package. Each disk, says Fitzgerald, will last about thirty cleanings.

8. Have head alignment checked, to reduce disk errors. With heads out of whack, your machine may be the only one that can read your disks—not even identical machines. A crude way of assuring proper alignments, in fact, might be to see if other machines can read disks written on your micro.

9. Buy quality disks. Of course, the more you spend on disks, the more expensive your backups become—discouraging you from making them. Find a balance between cost and convenience that suits your security needs.

Timing—that’s the secret to saving your electronic diamonds or rhinestones on your floppies, whatever the quality.

In the past, working just with paper, timing meant to me nothing more than the Rothman Chronological Method. The newer the document on my desk, the closer it would be to the top of the file. It wasn’t the most efficient way. But I rarely lost material, just temporarily misplaced it. Computerizing, however, I worried.

“Floppies are treacherous,” my friend Michael Canyes said like a John Bircher discussing commies. “They always trick you when you least expect it.”

“Thanks,” I said. “The way you’re encouraging me to computerize, I’m beginning to think you actually want to sabotage me. Help me lose my manuscripts and all that.”

“Just back up your copy page or so,” Michael said.

“Isn’t that a lot of trouble?”

“Maybe twenty seconds. Then you’re protected if the power fails. Or maybe your computer. You can’t afford to have your material stored just in on your chip. It’s just temporary. You cut off the current a fraction of a second, it’ll forget everything. You’ve got to get your stuff on the disk ASAP.”

All right, I supposed my creative juices wouldn’t dry up during the half minute the disk drive was whirring.

“The ‘Save’ command on WordStar is =KS=,” Michael said. “Just hold down the ‘Control’ button on your computer while you’re doing that. Then you’ll hear a whir and the disk drive clicking away.” Somehow my Kaypro was coming across as an animal to be fed during training; the clicking could be the sound of a dog chomping up candied biscuits after a successful lesson.

“You’re also going to make backup disks,” Michael said. “Sort of like electronic carbon paper.”

“I don’t have time,” I said.

“You’ll find time. You can do it in just a minute or so. You can even use a scratch disk to be safe.”

“What’s a scratch disk?”

“Suppose the power failed or something went wrong with your machine while you were making your copy,” Michael said. “Then you could be up the creek without a paddle. You might lose both the original and the copy.”

“So?”

“That’s why you have a scratch disk. You copy on it first. If something goes haywire, then you’re still safe. Because, during your last work session, you made a backup.”

“Theoretically,” I said.

“And if something goes wrong while you’re recording on your permanent backup disk, then you can just work from the scratch disk. It’s just what it sounds, sort of a scratch pad.”

“Oh, I’ll use paper, thank you,” I persisted. “The best backup yet. It’ll be years before it falls apart. And who knows? Maybe by then the Library of Congress will be preserving my manuscripts.”

Michael withheld a guffaw.

“Well, I can type a mean streak on my Selectric,” I said. “I can get my stuff back into the computer in no time.”

Always the patient teacher, Michael didn’t argue.

Presumably, however, another writer nowadays would have agreed with Michael immediately. His editors had been looking forward to having the printer set type from the disk he’d submit with the paper version of his manuscript—a crowded floppy storing every single byte from his toil. Then the editors could bring the book out six or eight weeks faster, with the disk in the printer’s hands. But in this unlucky man’s case the disk never reached the printer’s hungry computer—he hadn’t, alas, made an electronic copy. A case of hubris if ever there was one.

You might avoid such traumas by following the Rothman Chronological Method II (RCM II), a lazy man’s form of data security for those with fast printers:

1. Every five minutes or so, type out the “KS” or an equivalent and dump your work of the moment into the disk—for, ideally, permanent preservation.

2. Every half an hour make a printout of your recent work. With a fast printer, that’ll still be faster than messing around with an electronic copy at this point. Remember, you still have the backup disk from your last work session. So even if the original fails, you’ll need to reenter just the newest material.

3. Every day make your backup floppy. You might forget about the scratch disk and make two copies.

What about working with hard disks? Well, Winchesters are more dependable than floppies. On the other hand, they commonly store many times more material than do the soft disks—meaning perhaps a fiftyfold increase in your agony if one fails.

“Always try to use an uninterruptible power supply with your Winchester,” warns Fitzgerald, whose former company produces hard disks as well as floppies. Some manufacturers say their hard disks don’t need this protection. But, in general, it’s a good idea; here’s why.

Normally, the head picking up the magnetic patterns is only ten or twenty thousandths of an inch from the oxide-coated disk. The disk is aluminum—and shear-prone in the event of a crash. Instead of the typical soft whirl, you’ll hear an ear-piercing squeal like a car brake out of adjustment, except that the aftermath will be more costly. Repairs may run into the hundreds of dollars, not to mention the loss of data.

Not every power failure will produce a disk crash. But why gamble with your Winchester and its data?

An uninterruptible power supply will protect them by pumping out juice long enough for you to know something is amiss and shut the disk down. It sells for several hundred dollars, commonly, and is normally worth it.

“Also,” says Fitzgerald, “be sure the drive is grounded and shielded as the manufacturer recommends. If not, power surges could cause it to lose track of its data.”

He suggests one more precaution. Since the disk and the head are so close, why not warn furniture bangers? This could change. Hard disks are shock mounted in some portables nowadays, so that the equipment isn’t quite _that_ delicate. But I’d still try not to be too klutzy around it—and to be careful in other respects.

You can back up a Winchester in one of several ways:

1. Dumping to floppies. It’s cheap but slow. Then again, you can speed up the process by updating only the files you’ve been working on. You just “write” over them.

2. Transferring the Winchester’s contents to a special tape drive large enough to hold them. This method is fast but may cost you a good $1,500.

3. Dumping to an ordinary videocassette recorder. Although slow, it’s okay up to around 100 megabytes or so, and you can set the VCR timer to “watch television” off the Winchester at night when you’re not using it.

“Interesting,” you say, “but how about the lap-sized portable I’m considering? How do I protect the information inside that?” The best way, of course, is not to lose the memory and the rest of the portable; as a well-practiced raincoat forgetter, I’ll never be the ideal owner of a lap-sized portable.

Common sense, too, suggests that you not store a lap-size portable inside a car with the sun blazing down—bad news for heat-sensitive chips and other parts.

If your portable uses a =bubble memory=, your data-security problems are milder in some respects than with other kinds. The bubbles are tiny magnetized areas inside a small metal container. Magnetized “north,” a bubble might mean a bit specifying “one.” Magnetized “south,” it could mean zero. (You’ll recall that bits form a byte standing for a letter or number.) Magnetic bubble memories aren’t that much faster than disks, but they _keep_ remembering forever—unlike the CMOS (Complementary Metal Oxide Semiconductor) RAMs used in many portables.

An RAM will develop amnesia if your power fails, and a CMOS RAM is no different. It’s just that the CMOS keeps the power requirements extralow so small batteries can dribble out the needed juice after you’ve “officially” switched your machine off. This “hibernation” may last weeks or months. (Check your instruction manual.) You’re in great shape, however, only as long as your batteries are; the Eveready commercials may talk of nine lives, but your data may have only one. Someday your care may count more than ever. Low-cost CMOS RAMs may eventually store thousands of pages on one chip; and power failure might not be the only risk.

Imagine. You can tap out a chapter of your 1,000-page great American novel some bitter winter night, lazing on the rug by your fireplace. Your lover is stroking your back and—ZAP! Since CMOS RAMs are such low-voltages devices, think what thousands of volts from static can do.

Here’s one solution to the portables’ static problems. Before computing, you might discharge yourself on a nearby vent or anything else that’s grounded. You can also spray your home and office rugs with Static Guard or its equivalent. And you also can use a static mat—cheap at your local computer store—if the zaps persist.

What about a plane thirty thousand feet up? Then you might try discharging yourself against a metal ashtray before using your portable. If it’s all plastic, with no metal parts, by the way, your risks are much less than otherwise. But they’re still there.

Whatever style portable you’re using, remember the importance of backups—however inconvenient or costly. Through a cable called a =null modem=, you can pipe valuable reports from your portable to a larger computer a few feet away. You may want to do this, anyhow. Your lap-sized computer simply may run out of storage room much more quickly than a bigger machine and may lack floppy disks to spread those bits and bytes around. So make sure your portable software lets you zip material back and forth between machines.

“And in the field? What backup technique, then?”

Well, you’re often stuck with slow, tape-style storage. And mini-disk drives may be expensive and take up room if they’re not already in your portable.

But why not see if your company will let you send valuable reports over the phone for temporary storage in its big computer? You can also stash them away inside a desktop computer hooked up to the portable the same way. And there’s yet another answer. Rent electronic storage space on a commercial computer network like The Source of CompuServe.

In the future, maybe computer memories—on little portables and desktops alike—won’t be so temperamental. Perhaps there will be superreliable CMOS RAMs. Or how about practical, low-cost disks that you use lasers to “read” and “write” on? Dreams, dreams!

Meanwhile, most of us struggle along with floppies and must keep thinking, Backup! Handle carefully! Clean! Maintain! and How often? In summary, keep asking yourself:

1. How much time or money does it take to enter your data or set up your computer equipment?

2. How easily could you duplicate or replace it?

3. How much time or money do you have for copying, cleaning, maintenance, whatever precaution you’re taking?

Do keep data security in perspective. Remember, even if you must be a zealot at times, it’s just part of surviving with your computer. Harold Joseph Highland, a data-security stalwart in his work—a believer in two backup disks of book manuscripts—tells of people who make out very well with far less copying. They are students at the University of Minnesota, computer-science majors, and they trudge through snow and ice carrying unbacked-up floppies in their books. Their professors are tolerant. If a disk fails and a student’s assignment is late, they understand. The students can’t afford too many floppies, and some just don’t have the time for backups. It’s the same, perhaps, at countless other colleges, and maybe that’s only right for twenty-year-olds who’ll learn soon enough about disappointments beyond the campus.

But you’re in business, perhaps, without a friendly professor ready with a sympathetic nod. Your making regular backups is just plain good sense, and if you don’t, you deserve what’s coming to you.

Isn’t that what data security should be about?

It needn’t be Orwellian at all. If anything, in fact, Winston Smith had more of a data-security problem than Big Brother. Privacy, certainly, is an important data-security element, as is what the jargonists call =integrity=—accuracy and completeness of files. Think of Winston Smith and his appreciation of history and Big Brother’s propensity for tampering with the contents of back issues of the _London Times_! Even if “1984” has already become a year, the number, to true believers in data security, remains a warning.

This will be especially true as more and more machines swap secrets over the wires between home and office.

11 ❑ Wired to Work

John Fuller’s daughter is grown now, and he’s taken over her room, cluttering it with computer and boating magazines and his Heathkit micro. At first glance it looks like the computer room of any of thousands of hobbyists. You may, in fact, catch whiffs of smoke from Fuller’s soldering gun.

It’s an unlikely setting for a working office of the U.S. Navy.

And yet that’s exactly what it was when Lieutenant Commander Fuller responded to my notice on an electronic bulletin board asking if anyone at home was hooked up to his boss via computers.

“I’ve been getting away with it for six months,” Fuller drawled proudly.

On the verge of retirement from the navy, he was determined to telecommute in civilian life, too, perhaps as a management consultant, his military job. “It seems foolish for me to get in a car to go to an office,” he said, “if I can go to that office by phone. I’m much happier not having to get into traffic for forty-five minutes each morning. I can have coffee and read the _Washington Post_, and I’m not tense. I work fewer hours. But I don’t have five or six guys to talk to about ball scores, either. The government’s getting a better deal from me working at home.”

In fact, Electronic Services Unlimited (ESU), a research firm in New York City, found typical productivity increases between 15 and 20 percent.

So it isn’t surprising that at least 250 firms, including some big names like American Express and McDonald’s, were allowing work at home as of 1984. Many more companies might be. They might have kept quiet, however, fearing either (1) union resistance or (2) pressure from employees who wanted to telecommute before management was ready for them to do so.

“I look outside my Manhattan window and think some cities are going to be transformed—streets will be empty,” _InfoWorld_ quoted an ESU official.

That might have been stretching it. In 1984 only several thousand people were full-time telecommuters on a payroll. But Jack M. Nilles, coiner of the word “telecommuting,” said the number may have reached twenty thousand if you included other people.[59] Lone individuals, stockbrokers, even a software house organiz