1. Editor's Report - By Aaron Schiff

This third issue has come out much quicker than I thought it would. This is mainly due to a large article by Frenchman Jean-Bernard Condat. Also, would readers please read the article 'Changes to CDUGD' and comment on whether or not they think the changes are a good idea.

LAW SPECIAL: Issue #1.05 is to be a 'Law Special'. In this issue I wish to
focus on the New Zealand and Australian laws regarding computer crime (eg Hacking, Fraud etc..) For this I need:

The deadline for submissions to this special issue is March 25th although submissions I receive soon after this date will not be rejected.

NORWAY: People in Norway can download CDUGD from Digital Express BBS - the
phone number is at the top of this issue.

Enjoy the 3rd issue!

2. Changes to CDUGD - By Aaron Schiff

A few changes are to be made to CDUGD. None of them are major, but I hope that they will improve the overall success of CDUGD. The changes are:

1) Coverage: CDUGD will still be mostly New Zealand oriented, however, I
have decided that articles about non - New Zealand computing issues will be accepted. I hope that this will broaden the target audience of CDUGD as well as raise the number of contributions.

2) Australia: This is not yet a definite change, I am thinking of
including Australian articles as a normal part of the digest. The decision as to whether or not to do this has not yet been made. I would like readers to comment (in public or privately) on whether or not this should be done. If you are reading this in Australia, please contact me if you are able to help out with the Australian side of things in any way (eg distribution, writing articles etc...)

3) CDUGD News: This will be a regular column (similar to 'PHRACK World
News' and is just short descriptions of events happening in the computing world. I need someone to write this column on a regular basis. Any volunteers?

3. Response to 'Hacking in NZ' - By Mark Neely

This article is in response to the article 'Hacking in NZ' by The Death Pirate and published in CDUGD #1.02

>6 Hacking In NZ - By The Death Pirate
>Hacking is basically to break or force your way into a system illegally.
>Basically connecting to another modem without permission. But if this is
>so, then isn't connecting to a BBS system without permission illegal??

"Hacking" (see arguments re: cracking/hacking...sheesh, everyone bags people for confusing the two) essentially means unauthorised access to a computer. The more "deviant" the intention behind the intent, then (as a general rule - see the decision on appeal in the R T Morris appeal, which was as a result of the particular drafting of the legislation) the greater the penalty involved.

>This is one point which was heard in the recent trial of a 19 year old
>hacker in the USA, (refer to your PC World).

Robert Tappan Morris Jnr. (son of Robert Morris, NSA scientist). He was given a suspended sentence, good behaviour bond and a fair amount of community services.

>However, really what it should mean is to force, hack into a system
>without an account or permission.

Not necessarily... the way most legislation is drafted would catch an authorised user (i.e. with legitimate account + password) trying to execute an unauthorised process/command!

>The Author Deliberately left out details which he thought could have
>enabled any illegal action.

Which "he thought could have enabled any illegal action"...this is hardly conclusive!

As a side note, as NZ and Australia appear to be strengthening economic ties etc, it is likely that we may see the sharing of services (airlines today, maybe telecommunications tomorrow!).

Under recent amendments to the Commonwealth Crimes Act (Pt IVA), persons who gain unauthorised access to Cth. computers (or computers which the Cth government have an interest [defined in the legislation]) can be prosecuted under the Act.

Of particular note is the section which would appear to provide that persons who use a service provided by a Cth authority or body (which one would assume would include Telecom??) is also liable for prosecution!!

Thus, practically anyone who uses a modem to "hack" into a computer could find themselves liable to prosecution under the Cth Act!

Should there be sufficient interest, I could look into this matter further.

Mark N.

          ------------- Verbose Disclaimer Follows -------------
Mark Neely
Articled Clerk (Slave)              |         Tutor
Messrs Cridlands,                   |         Law School
Barristers and Solicitors.          |         Northern Territory
Darwin, NT Australia


The views expressed herein are neither a reflection of the views held by my employer nor those of the NTU. They are not to be taken (unless otherwise indicated) as a formal legal opinion or advice given in my professional capacity.

Whistleblowers BBS Extremely Successful - By Jean-Bernard Condat

Whistle-blowers may now anonymously report government fraud, waste, and abuse via computer to the House Government Operations sub-committee on Government Information, Justice, and Agriculture. The number for the computer system, which will accept files and messages, is (202) 225-5527. Aliases are permitted.

The Truelson' PhD published in 1986, draws upon the theorical framework of systemic corruption--an organized conspiracy to suppress revelation of corrupt practices--to propose a retaliation model to account for organiza- tional retaliation against whistleblowers with legitimate protests. This study is one basis of this incredible bulletin board.

House Government Information Subcommittee's whistleblower computer BBS has been "tremendously successful" and has generated about "50 substantive leads" in its two months of operation, Subcommittee Chief Counsel Robert Gellman said. Board has received 700-800 calls, many from curious browsers who want to see what's available and others who want to discuss policy matters.

But Gellman said board was designed solely to allow whistle-blowers to post private notes to alert Subcommittee to instances of waste, fraud and abuse, so there isn't much for anyone else to see. There are no files available to download or bulletin to read, as there are on most bulletin boards. Gellman said message senders often don't use their real names, and Subcommittee staff has used electronic mail feature to send message back asking for more information.


1. Food Chemical News, December 16, 1991, ISSN 0015-6337;

2. Judith Anne Truelson, "Blowing the Whistle on systemic Corruption,"

University of Southern California (Los Angeles, CA), 1986;

3. Communications Daily, February 13, 1992, ISSN 0277-0679.


Welcome to


This bulletin board exists to help the United States Congress identify waste, fraud, and abuse in the federal government. You are invited to leave messages or upload files that relate to this purpose. There are no public files or public messages on this board.

Your SYSOP is Congressman Bob Wise from West Virginia.

The CONTENTS of all communications are confidential and not accessible to other users. However, the name you use to sign on may be visible to other users. If this is a concern, please use a pseudonym to protect your identity.

What is your FIRST name (pseudonyms okay)? CONDAT JEAN-BERNARD

Checking Users...
User not found
What is your STATE (any entry acceptable)? LYON IN FRANCE Welcome to the FEDERAL WHISTLEBLOWER BULLETIN BOARD.

This Board is operated by an investigative subcommittee in the U.S. House of Representatives.

Your SYSOP is Congressman Bob Wise from West Virginia.


1. There are NO public files and NO public messages on this board. If you are looking for downloads, games, etc., you won't find them here.

2. If you have a concern about protecting your identity, please use a pseudonym. Because of software limitations, the name you use to sign on with may become known to others. You may leave your real name in the contents of a message, but this is not required. THE CONTENTS OF MESSAGES CAN ONLY BE READ BY THE SYSOP. Messages cannot be read by any other user. Use the Comment command to leave messages to the Sysop.

C)hange FIRST name (pseudonyms okay)/LAST name (pseudonyms okay)/STATE (any
ry acceptable), D)isconnect, [R]egister? R
Enter PASSWORD you'll use to logon again (dots echo)? .... Re-Enter password for Verification (dots echo)? ....
Please REMEMBER your password
Welcome to RBBS-PC, Condat. You have 60 mins for this session. Logging CONDAT JEAN-BERNARD
RBBS-PC 17.3C Node 1, operating at 1200 BAUD,N,8,1

      |     Welcome to the FEDERAL WHISTLEBLOWER BBS     |
               Your SYSOP is Congressman Bob Wise
BBS Phone: (202) 225-5527


1) Remember your password. If you forget it, you can't read your mail and we can't contact you.

2) Use mixed case in messages. ALL UPPER CASE IS HARD TO READ.

3) If you upload a file, please leave a message so we know who provided it. If you don't, the upload will not be acknowledged. This is NOT a requirement. Anonymous uploads are acceptable.

4) Callers may be deleted after 30 days. If this happens to you, just register again. It only takes a second.

Checking messages in MAIN..
Sorry, CONDAT, No NEW mail for you

RBBS-PC 17.3C Node 1

Caller #  1279  # active msgs: 74  Next msg # 539
             ------*>>>   RBBS-PC  MAIN MENU   <<<*------
----- MAIL ---------- SYSTEM ---------- UTILITIES ------ ELSEWHERE ---
 [R]ead Mail to Me   [B]ulletins        [H]elp (or ?)       [F]iles
 [C]omment to SYSOP  [I]nitial Welcome  [X]pert on/off      [G]oodbye

Current time: 09:38 AM Minutes remaining: 58 Security: 5

MAIN: 58 min left
MAIN command <?,B,C,F,G,H,I,K,Q,R,U,X>? B

Ctrl-K(^K) / ^X aborts. ^S suspends ^Q resumes 
 ======[ WHISTLEBLOWER BBS Bulletin Menu ]=======
 Bulletin  Description
 -------   -------------------------------------
   1       Description and Purpose of this Board
   2       Upload and Download Policies (NO DOWNLOADS!)
   3       Operating Policies
   4       How to Blow the Whistle
Read what bulletin(s), L)ist, S)ince, N)ews ([ENTER] = none)? 3 Ctrl-K(^K) / ^X aborts. ^S suspends ^Q resumes

1. The highest priority on this bulletin board is protecting the confidentiality of callers. A caller concerned about confidentiality should use a pseudonym.

2. There is no Caller-ID service on the bulletin board's incoming line. Incoming calls are not traced. Each caller must consider the possibility that a call to this board is being recorded or traced at the source of the call.

3. The Whistleblower BBS is operated by an investigative subcommittee in the United States House of Representatives. The purpose of the board is to assist the Congress in identifying waste, fraud, and abuse in federal agencies, programs, contracts, and grants. No action will be taken on any information that does not further this purpose.

4. A higher priority will be assigned to matters that involve large amounts of federal funds or that affect health or safety. Other matters may be pursued to the extent permitted by available resources.

5. We cannot provide any type of general assistance to callers. The board should not be used for any political purpose or to lobby Congress on legislative or policy matters.

6. Messages that relate to the purpose of the board will be acknowledged. A caller who provides an investigative lead is encouraged to call back in the event more information is required. Messages that do not relate to the purpose of the board may not be acknowledged. Most messages will be erased after they are read.

7. General information about investigations that result from activities on the Whistleblower BBS may be made public, although no information specifically identifying an individual caller will be released. Publicity for the board will help to accomplish its purpose. However, a caller will not necessarily be informed about the details of any investigation that results from his or her message.

8. Information obtained on the Whistleblower BBS may be shared with other congressional investigators, agency Inspectors General, and the General Accounting Office (the audit arm of Congress). INFORMATION THAT SPECIFICALLY IDENTIFIES CALLERS WILL NOT BE SHARED. Callers should identify any special confidentiality concerns or expressly state if they need to place any specific restrictions on the use of the information that they provide. Information will not be shared if a caller specifically requests.

9. Casual visitors to the board may be deleted from the user base at any time. If you call a second time and find that you are not recognized, just re-register. It only takes a few seconds. Users not engaged in current discussions may also be deleted as a security precaution.

10. Text files may be uploaded, preferably in ASCII format. Word Perfect format is a second choice. Files may be compressed using standard compression programs. Files other than text files will be immediately deleted.

11. If you attempt to use a common pseudonym (e.g., John Doe), you may find that it is already in use. When you first enter a name not in use, you will receive a message about the board. If you enter a name that is known to the board, you will be asked for a password. If this happens, you must hang up, call again, and use a different name. Anyone reading this has already solved the problem. This paragraph is included as an explanation.

Ctrl-K(^K) / ^X aborts. ^S suspends ^Q resumes 
 ======[ WHISTLEBLOWER BBS Bulletin Menu ]=======
 Bulletin  Description
 -------   -------------------------------------
   1       Description and Purpose of this Board
   2       Upload and Download Policies (NO DOWNLOADS!)
   3       Operating Policies
   4       How to Blow the Whistle

Read what bulletin(s), L)ist, S)ince, N)ews ([ENTER] = none)? 4

Ctrl-K(^K) / ^X aborts. ^S suspends ^Q resumes


How to Blow the Whistle on Fraud, Waste, and Abuse

1. You do NOT have to give your name or identify yourself in any way. But you should call again after you have left a message. Use the same name you used the first time and see if there is an answer for you. Use the READ MAIL TO ME command. This permits continuing communications so that we can ask you for more information or clarification. Allow a few days for your message to be read.

2. Remember that we are more interested in conduct involving SIGNIFICANT amounts of federal funds or MAJOR instances of wrongdoing. We have limited resources, and we are less likely to investigate minor matters. When in doubt, we encourage you to report the matter and let us decide.

3. Provide enough information so we can find and investigate the objectionable activity. Whenever possible, tell us WHO, WHAT, WHERE, WHEN, WHY, and HOW. Be as specific as possible.

4. WHO: Identify the agency, office, program, contract, or grant:

          Vague:         ABC Department
          Okay:          ABC Department, Z Bureau
          Good:          ABC Department, Z Bureau, Denver Office
          Better:        ABC Department, Z Bureau, Denver Office, Contract
                         Number 123-456 dated 2/1/89

5. WHAT: Describe the conduct:

          Vague:         Wasted Money
          Okay:          Bought unnecessary computers
          Good:          Bought 200 Personal Computers to use funds at the
                         end of the fiscal year
          Better:        John Smith authorized the purchase of 200
                         unneeded PCs under contract 123-456 on 9/30/91 to
                         avoid returning excess funds to the Treasury

6. WHERE: State where the activity occurred:

          Vague:         Unnecessary travel
          Okay:          Trips to Los Angeles
          Good:          Trips from Headquarters to Los Angeles
          Better:        John Smith authorized travel for himself from
                         Chicago to Los Angeles every Friday before the
                         UCLA football team played a game at home so he
                         could watch the game

7. WHEN: Provide all relevant dates:

          Vague:         Last year
          Okay:          1990
          Good:          Starting in May 1990
          Better:        Began on May 5, 1990, continued every other week
                         until December 14, 1991

8. WHY and HOW: Explain the conduct involved:

          Vague:         Broke the law
          Okay:          Did not follow procurement rules
          Good:          Failed to obtain sole-source contracting
          Better:        Procured 1000 buses from ABC Corp. under contract
                         number 123-456, on 5/1/90, under a sole source
                         contract that was not approved by the contracting
Ctrl-K(^K) / ^X aborts. ^S suspends ^Q resumes 
 ======[ WHISTLEBLOWER BBS Bulletin Menu ]=======
 Bulletin  Description
 -------   -------------------------------------
   1       Description and Purpose of this Board
   2       Upload and Download Policies (NO DOWNLOADS!)
   3       Operating Policies
   4       How to Blow the Whistle
Read what bulletin(s), L)ist, S)ince, N)ews ([ENTER] = none)?
             ------*>>>   RBBS-PC  MAIN MENU   <<<*------
----- MAIL ---------- SYSTEM ---------- UTILITIES ------ ELSEWHERE ---
 [R]ead Mail to Me   [B]ulletins        [H]elp (or ?)       [F]iles
 [C]omment to SYSOP  [I]nitial Welcome  [X]pert on/off      [G]oodbye

Current time: 09:41 AM Minutes remaining: 55 Security: 5

MAIN: 55 min left
MAIN command <?,B,C,F,G,H,I,K,Q,R,U,X>? C

Type comment 60 lines max (Press [ENTER] to quit)

 1: Hallo!
 2: I am a French journalist and will be very please to receive a press
3: information on this curious BBS.
4: My e-mail address is MCI Mail #501-3469 or DialMail #24064 5: Don't hesitate to contact me.
6: Jean-Bernard Condat
7: CCCF, B.P. 8005, 69351 Lyon Cedex 08, France (Fax.: +33 1 47877070) 8:

A)bort, C)ontinue adding, D)elete lines, E)dit a line
I)nsert lines, L)ist, M)argin change, R)evise subj, S)ave msg, ?)help Edit Sub-function <A,C,D,E,I,L,M,R,S,?>? s
Adding new msg # 539.
Receiver will be notified of new mail

             ------*>>>   RBBS-PC  MAIN MENU   <<<*------
----- MAIL ---------- SYSTEM ---------- UTILITIES ------ ELSEWHERE ---
 [R]ead Mail to Me   [B]ulletins        [H]elp (or ?)       [F]iles
 [C]omment to SYSOP  [I]nitial Welcome  [X]pert on/off      [G]oodbye

Current time: 09:43 AM Minutes remaining: 53 Security: 5

MAIN: 53 min left
MAIN command <?,B,C,F,G,H,I,K,Q,R,U,X>? g Log off (Y,[N])? y

Now: 03-06-1992 at 09:43:54
On for 7 mins, 5 secs 60 min left for next call today

CONDAT, Thanks and please call again!

End of CDUGD Volume 1, Number 2