Skip to main content
← Back to Archives More from 2026

Cliff Stoll at DEF CON 34: The Best Talk I’ve Ever Seen

This is easily the best talk I have ever seen.

On August 8, 2026, forty years to the day after discovering a 75-cent accounting discrepancy that led to one of the foundational investigations in computer security, Cliff Stoll took the stage at DEF CON 34.

He did not bring a polished slide deck. He brought an overhead projector and the original physical transparencies from a presentation he gave to the NSA in 1987. Sitting nearby was a thermos of minestrone soup.

Then he spent an hour retelling the story that became The Cuckoo’s Egg—one of the great stories of computer security.

The 75-Cent Discrepancy

In 1986, while working at Lawrence Berkeley Laboratory, Stoll was asked to figure out why the lab’s computer accounting records were off by 75 cents. He traced the discrepancy to a few seconds of unauthorized computer use.

From there came soldering irons, serial lines, telephone traces, bureaucratic dead ends, improvised traps, and a lot of determination.

He kept pulling the thread. Eventually, Stoll was following an intruder across networks and modem banks and into military and research systems, painstakingly recording what the hacker did and trying to trace the connection back to its source. The investigation ultimately exposed German hackers selling information to the Soviet KGB.

Today we'd have names, teams, and mature tooling for much of this: incident response, intrusion detection, threat intelligence, network telemetry, digital forensics.

Stoll had basically none of that. So he built what he needed.

He wired serial connections together with clip leads. He wrote little programs to watch the intruder. He slept at the lab so he could be there when the hacker appeared. He built what we would now recognize as a honeypot, creating fake material interesting enough to keep the intruder connected while telephone companies tried to trace the call.

Swapping Saturn for Call Data

And then there is my favorite part. At one point, Stoll needed long-distance telephone trace information. The phone company wanted a search warrant before handing it over. Stoll thought the trace was lawful, but the carrier still wasn't going to do it without the legal process its policy required.

Stoll explained that he didn't have a warrant. He was a planetary astronomer. So, as he tells it in the talk, he mailed the operator high-resolution telescope photographs of Saturn and the Moon instead. A week later he had the call data.

He had basically exchanged astronomical photographs for the kind of telephone trace data we'd now associate with pen-register/trap-and-trace procedures. It is a completely wild piece of legal and bureaucratic hacking.

There is another reason I love this story: I somehow never knew Stoll was a planetary astronomer. I was one too, years later. Of course Cliff Stoll's solution to a telephone-tracing problem involved telescope photographs of Saturn.

Security Is About People

But the part of the talk that has stuck with me most isn't any of the technical—or legal—improvisation. It is one of those original NSA transparencies.

The NSA had sent Stoll questions in advance: How was the penetrator tracked? What auditing features existed? How were passwords obtained?

Stoll hated the questions. Not because they were technically wrong, but because of how they were written. They were detached, passive constructions. Passwords “were obtained.” The person doing the thing had vanished from the sentence.

So Stoll rewrote them in the active voice, with rather less clinical names for the maldoer:

“How does this bastard break into computers?”

“How does this scoundrel become superuser?”

It's funny, but this isn't just Cliff being Cliff. His point is that the passive voice and clinical language can make the person doing the thing disappear.

Forty years later, we have much better tools and much more specialized language. A lot of that language is useful. But it can still make the humans disappear: “threat actors” exploit vulnerabilities, credentials are compromised, data is exfiltrated, incidents occur.

Stoll's rewrite is a useful corrective. Someone did something. Someone else has to notice, care, and figure out what happened.

Maybe that's what I love most about the talk. Almost all of the technology is ancient. The instinct to keep pulling at something that doesn't quite make sense isn't.

Cliff Stoll is a treasure. If you watch one talk this week, make it this one.