Intelligence Reference · Person

Robert Tappan Morris

Robert Tappan Morris — American computer scientist; creator of Morris Worm; associate professor at MIT
Authenticated
1965
Active Range
Person
Classification
Archive Profile // Ref: robert-tappan-morris

Robert Tappan Morris (born 1965) is an American computer scientist and MIT professor who, as a Cornell University graduate student in 1988, created and released the Morris Worm — the first major self-replicating malware to propagate across the nascent Internet, causing widespread system disruptions and leading to the first felony conviction under the 1986 Computer Fraud and Abuse Act. His conviction, trial, and subsequent career mark a pivotal moment in the legal and cultural history of cybersecurity.

Robert Tappan Morris
Robert Tappan Morris
person
Source
Wikimedia Commons
Type
Photograph
License
CC BY-SA 3.0
Photographer
Trevor Blackwell
Year
2008
Photo Information

Robert Tappan Morris .

Wikipedia . Original uploaded by: Tlbtlbtlb

View original ↗
Identity
Full name
Robert Tappan Morris
Born
November 8, 1965
Nationality
American
Education
Harvard University (BA, 1987); Cornell University (PhD candidate, 1988–1989)
Father
Robert Morris Sr., chief scientist at NSA's National Computer Security Center
Criminal conviction
First felony conviction under Computer Fraud and Abuse Act (1990)
Sentence
Three years probation, 400 hours community service, $10,050 fine (1990)
Current position
Professor, MIT Computer Science and Artificial Intelligence Laboratory (since 1999)
Academic focus
Computer networks, distributed systems, operating systems
Notable co-creation
Y Combinator startup accelerator (co-founder, 2005)
Why this matters // Archive relevance

Robert Tappan Morris appears in The Archive as the creator of the Morris Worm, one of the most consequential events in early Internet history. His November 1988 release of self-replicating code that infected approximately 6,000 computers — roughly 10% of the Internet at the time — exposed fundamental vulnerabilities in network security, catalyzed the creation of the first Computer Emergency Response Team (CERT/CC), and established critical legal precedents for prosecuting computer crimes. The case represented the first major test of the Computer Fraud and Abuse Act and shaped decades of debate over hacking laws, security research ethics, and the criminalization of programming activities. Morris's father's position as chief scientist at the NSA's National Computer Security Center added complexity to public understanding of the incident. His subsequent distinguished academic career at MIT further illustrates the evolving relationship between elite hacking culture and institutional computer science.

# Robert Tappan Morris

Identity

Robert Tappan Morris was born November 8, 1965, into a family deeply embedded in American cryptography and computer security. His father, Robert Morris Sr., served as chief scientist at the National Security Agency's National Computer Security Center and co-authored foundational work on password security for Unix systems. The younger Morris attended Harvard University, graduating in 1987, before entering Cornell University's graduate program in computer science.

Morris became widely known in November 1988 when, as a first-year Cornell graduate student, he released what became known as the Morris Worm — a self-replicating program that infected approximately 6,000 computers connected to the early Internet, representing roughly 10% of all Internet-connected machines at the time. The incident led to his conviction under the Computer Fraud and Abuse Act of 1986, making him the first person convicted of a felony under that statute.

Following his conviction and completion of his sentence, Morris completed his doctorate and joined MIT's faculty, where he has conducted research in computer networks, distributed systems, and operating systems security. His academic work has received recognition through his tenure at MIT's Computer Science and Artificial Intelligence Laboratory and his role as co-founder of Y Combinator, one of the most influential startup accelerators in technology.

Career & Roles

Morris's computing career began during his undergraduate years at Harvard, where he developed expertise in Unix systems and network protocols. During this period, he created several tools and utilities that circulated among computing researchers, demonstrating both technical skill and interest in system vulnerabilities.

In fall 1988, Morris was a first-year doctoral candidate in Cornell University's computer science program. On the evening of November 2, 1988, working from MIT (not Cornell, to obscure the program's origin), Morris released a self-replicating program designed to propagate across Unix systems connected to the Internet. According to his later testimony and court documents, Morris intended the program to gauge the size of the Internet and harmlessly inhabit machines, but a programming error caused infected machines to be reinfected multiple times, consuming system resources and rendering thousands of computers unusable.

The immediate aftermath included coordinated response efforts by systems administrators across affected institutions, analysis of the worm's code by researchers including Eugene Spafford at Purdue University and teams at MIT and Berkeley, and the formal establishment of the Computer Emergency Response Team Coordination Center (CERT/CC) at Carnegie Mellon University in direct response to the incident.

Following his 1990 conviction, sentencing to probation, and completion of community service, Morris completed his doctoral studies. In 1995, he received his PhD from Harvard University (he had transferred from Cornell following the worm incident). His doctoral research focused on techniques for building scalable network services.

Morris joined MIT's faculty in 1999 as an assistant professor and achieved tenure in 2006. His research has concentrated on operating systems, distributed systems, and network protocols. Notable academic contributions include work on the Chord distributed hash table protocol (with colleagues including Ion Stoica, David Karger, and Frans Kaashoek), which influenced peer-to-peer systems and distributed databases.

In 2005, Morris co-founded Y Combinator with Paul Graham, Jessica Livingston, and Trevor Blackwell. Y Combinator became one of the most influential startup accelerators, having funded companies including Airbnb, Dropbox, Stripe, Reddit, and thousands of others. Morris served as a partner while maintaining his MIT faculty position.

Organizations & Networks

Morris's organizational affiliations span academic institutions, the criminal justice system, and the startup technology ecosystem.

During the worm incident, Morris was affiliated with Cornell University as a graduate student, though he released the worm from MIT's computer systems. The worm affected systems at major research universities including Berkeley, Stanford, Princeton, and MIT, as well as government and military research facilities.

The federal prosecution was handled by the U.S. Attorney's Office for the Northern District of New York, with Assistant U.S. Attorney Mark Rasch leading the case. Morris's defense team included Thomas Guidoboni. The trial took place in U.S. District Court in Syracuse, New York, before Judge Howard G. Munson.

Following conviction, Morris became connected to ongoing debates within computer security communities about the ethics of security research, the appropriate boundaries of testing system vulnerabilities, and the severity of legal penalties for computing activities. His case has been referenced in legal scholarship, computer science ethics courses, and policy debates about the Computer Fraud and Abuse Act.

At MIT, Morris joined the Computer Science and Artificial Intelligence Laboratory (CSAIL), one of the world's leading computing research centers. His academic network included collaborators on distributed systems research and his role in MIT's undergraduate and graduate computer science education.

Through Y Combinator, Morris became part of Silicon Valley's startup ecosystem, interacting with thousands of entrepreneurs and contributing to the acceleration model that shaped modern technology venture formation. Y Combinator's influence extended to creating cultural norms around startup formation, funding structures, and the relationship between academic computer science and commercial technology development.

Major Operations & Activities

The defining event of Morris's public profile remains the November 2-3, 1988 release of the Morris Worm. According to court records, expert testimony, and Morris's own statements, he developed the worm over several months in 1988. The program was designed to exploit known vulnerabilities in Unix systems, including:

  • ·A flaw in the sendmail mail transfer program's "debug" mode
  • ·A buffer overflow vulnerability in the finger daemon (fingerd)
  • ·Weaknesses in the remote shell (rsh) and remote execution (rexec) protocols
  • ·The use of common or weak passwords that could be cracked through dictionary attacks

Morris incorporated code to prevent the worm from reinfecting already-compromised machines, but a design flaw caused the worm to ignore these safeguards in approximately one out of seven cases. This error transformed what Morris later characterized as an experimental program into a rapidly spreading threat that overwhelmed system resources.

On the evening of November 2, 1988, Morris released the worm from a computer at MIT. Within hours, systems administrators across the Internet began noticing unusual system behavior. By the morning of November 3, infected machines were crashing or operating so slowly as to be unusable. The worm spread to approximately 6,000 computers, including systems at universities, military installations, and research facilities.

Morris, realizing the worm's unintended severity, contacted friends including Andrew Sudduth at Harvard to help distribute information about how to stop the worm, but communications infrastructure was sufficiently disrupted that these warnings spread slowly.

The response involved hundreds of systems administrators working through the night to disconnect systems, analyze the worm's code, and develop countermeasures. Key analysis was conducted by researchers including Eugene Spafford at Purdue, Peter Yee and teams at Berkeley (including Keith Bostic), and MIT personnel. The incident prompted immediate concerns about Internet security and vulnerability.

DARPA (Defense Advanced Research Projects Agency), which had funded development of the Internet's predecessor ARPANET, sponsored the creation of the Computer Emergency Response Team Coordination Center (CERT/CC) at Carnegie Mellon University in direct response to the worm. CERT/CC became the first formal organization dedicated to coordinating responses to Internet security incidents.

Morris's academic work post-conviction has focused on distributed systems and network protocols. His research on Chord (published in 2001) presented a scalable peer-to-peer lookup protocol that influenced subsequent distributed hash table designs. His work has addressed problems in network measurement, data storage systems, and operating system design.

Through Y Combinator beginning in 2005, Morris participated in selecting, advising, and funding thousands of startup companies. Y Combinator's model — providing small amounts of seed funding in exchange for equity, combined with intensive mentorship during a three-month program — became widely replicated across the technology industry.

Historical Importance

Robert Tappan Morris occupies a unique position in the history of computing, criminal law, and Internet governance. The Morris Worm represented the first major demonstration that the Internet's fundamental architecture contained systemic vulnerabilities that could be exploited for rapid, widespread disruption. The incident occurred when the Internet connected approximately 60,000 computers, primarily at research institutions, government agencies, and military facilities.

The worm's impact extended beyond immediate technical disruption. It catalyzed institutional responses including the creation of CERT/CC, which became the model for computer emergency response teams worldwide. The incident demonstrated that Internet security could not be addressed solely through isolated institutional policies but required coordinated response mechanisms.

Legally, Morris's prosecution and conviction established precedents for interpreting the Computer Fraud and Abuse Act. The case addressed questions about intent, damage calculation, and the applicability of criminal penalties to programming activities that caused unintended harm. The relatively lenient sentence — probation rather than imprisonment — reflected judicial acknowledgment of Morris's claims that the damage was unintentional, while the conviction itself established that good intentions did not excuse violations of the statute.

Morris's case became central to debates about "white hat" versus "black hat" hacking, the ethics of security research, and whether testing system vulnerabilities without authorization should be criminalized. The case is regularly cited in legal scholarship analyzing the Computer Fraud and Abuse Act's evolution and in computer science ethics curricula examining professional responsibilities.

The contrast between Morris's criminal conviction and his subsequent distinguished academic career raised questions about rehabilitation, the treatment of young technologists who cause harm, and the relationship between hacking culture and institutional computer science. His father's position at the NSA added complexity to public understanding, with some observers noting the irony that the son of a leading government security expert had caused such disruption.

Morris's academic contributions, particularly the Chord protocol, have influenced distributed systems design. The protocol's approach to distributing keys across network nodes informed subsequent peer-to-peer systems, distributed databases, and blockchain technologies.

Y Combinator's success amplified Morris's influence beyond academia. The accelerator model pioneered by Y Combinator has been replicated globally, affecting startup formation, venture capital practices, and the structure of technology entrepreneurship.

Documented Controversies

Confirmed by Court Robert Tappan Morris created and released the Morris Worm on November 2, 1988, causing damage estimated at the time between $100,000 and $10,000,000 across approximately 6,000 infected systems. These facts were established at trial and formed the basis of his conviction.

Ongoing Historical Debate Morris's intent remains debated. At trial, Morris testified that the worm was intended as a harmless experiment to gauge the Internet's size and that the widespread damage resulted from a programming error. The prosecution argued that regardless of intent, Morris knowingly violated computer security and should have anticipated potential harm. The court found Morris guilty but Judge Munson's relatively lenient sentencing suggested acceptance of mitigating factors, including Morris's youth, lack of malicious intent, and cooperation with investigators.

Official Record Damage assessments varied widely. The Government Accountability Office and academic researchers provided estimates ranging from tens of thousands to millions of dollars, depending on methodology. Costs included staff time for remediation, lost computing resources, and security improvements implemented in response. The court record notes difficulty in precisely quantifying damages due to the distributed nature of harm and varying institutional responses.

Credible Allegation Some security researchers and Morris's defenders have argued that the worm, despite its damage, served a beneficial function by exposing critical vulnerabilities and forcing institutions to improve security practices. Eugene Spafford and other researchers analyzing the worm noted that it exploited well-known vulnerabilities that should have been patched, suggesting systemic negligence in security practices. This view does not excuse Morris's actions but contextualizes them within broader security failures.

Historical Consensus The incident directly caused the creation of CERT/CC. Carnegie Mellon University, with DARPA funding, established CERT/CC in December 1988 specifically to coordinate responses to Internet security incidents. This organizational innovation became the template for computer emergency response teams worldwide.

Reported Association Morris's father's position as chief scientist at the NSA's National Computer Security Center generated speculation about whether Robert Morris had access to classified information about security vulnerabilities or whether his father's work influenced his development of the worm. No evidence in court records or subsequent reporting established that Morris used classified information, and Robert Morris Sr. publicly stated he had no prior knowledge of his son's activities.

Ongoing Historical Debate The appropriateness of Morris's sentence has remained controversial. Some prosecutors, security professionals, and victims argued that probation was too lenient and failed to deter future computer crimes. Others, including some in the academic computer science community, argued that imprisonment would have been excessive for a young researcher whose actions, while reckless, appeared non-malicious. This debate continues in discussions of Computer Fraud and Abuse Act reform.

Investigations & Legal Proceedings

The FBI began investigating the Morris Worm incident on November 3, 1988, as systems administrators reported widespread disruptions and analysis of the worm's code revealed its rapid propagation mechanism. The investigation involved coordination among multiple agencies, universities, and military installations to track the worm's origin and impact.

Investigators traced the worm's release to MIT computer systems, and subsequently to Robert Morris at Cornell. Morris cooperated with investigators, providing information about the worm's creation and his intentions. The investigation examined Morris's communications, computer files, and statements to reconstruct the timeline and assess intent.

On July 26, 1989, a federal grand jury in Syracuse, New York indicted Morris on one count of violating 18 U.S.C. § 1030(a)(5)(A) of the Computer Fraud and Abuse Act — knowingly accessing federal interest computers without authorization and preventing authorized access, causing damage and loss.

The trial began on January 8, 1990, in U.S. District Court for the Northern District of New York before Judge Howard G. Munson. The prosecution, led by Assistant U.S. Attorney Mark Rasch, presented evidence of the worm's creation, release, and damage. Expert witnesses including Eugene Spafford testified about the worm's technical characteristics and impact.

Morris's defense argued that he lacked criminal intent, characterizing the worm as a programming experiment that malfunctioned due to an unintentional error. Defense witnesses testified to Morris's character and technical competence. The defense also challenged damage calculations and the applicability of the Computer Fraud and Abuse Act to Morris's conduct.

On January 22, 1990, the jury convicted Morris on the single count. The conviction was significant as the first felony under the Computer Fraud and Abuse Act, establishing that the statute applied to graduate students conducting unauthorized experiments, not only to traditional concepts of malicious hacking or espionage.

Sentencing occurred on May 4, 1990. Judge Munson sentenced Morris to three years probation, 400 hours of community service, and a fine of $10,050. The sentence was notably lenient compared to the statutory maximum of five years imprisonment and $250,000 fine. Judge Munson's decision reflected consideration of Morris's cooperation, lack of criminal history, apparent lack of malicious intent, and youth.

Morris appealed the conviction to the U.S. Court of Appeals for the Second Circuit, arguing that the Computer Fraud and Abuse Act was unconstitutionally vague and that the trial court erred in jury instructions. In United States v. Morris, 928 F.2d 504 (2d Cir. 1991), decided March 7, 1991, the Second Circuit upheld the conviction. The appellate court found the statute sufficiently clear and rejected Morris's constitutional challenges.

The appeals court decision clarified that the Computer Fraud and Abuse Act did not require proof that a defendant intended to cause damage or loss; rather, it required only proof that the defendant intentionally accessed computers without authorization, and that damage resulted. This interpretation significantly shaped subsequent prosecutions under the Act.

Morris completed his probation and community service without incident. The conviction became a matter of public record but did not prevent his subsequent academic career or business activities.

Denials & Disputes

Morris has consistently maintained that he did not intend to cause damage or disruption. In court testimony and subsequent interviews, he characterized the worm as an experiment to map the Internet that malfunctioned due to a programming error in the code that was supposed to prevent excessive reinfection.

Morris denied malicious intent, arguing that he designed safeguards specifically to prevent the harm that ultimately occurred. The programming error that caused the worm to override its own infection checks was, according to Morris, an unintentional mistake, not a deliberate design choice.

Morris's legal team disputed the government's higher damage estimates, arguing that institutions inflated costs by including expenses that would have been incurred anyway or that represented improvements rather than restoration. The defense noted difficulty in separating emergency response costs from routine security improvements implemented opportunistically following the incident.

Morris and his defenders have disputed characterizations of the worm as "malicious code" in the sense of deliberately destructive software, distinguishing it from viruses designed to delete files or damage systems. They argued that the worm's code contained no deliberately destructive payload and that harm resulted from resource consumption due to replication errors, not designed destruction.

Robert Morris Sr. publicly stated he had no prior knowledge of his son's worm project and had not provided classified information or specialized knowledge that enabled the worm's creation. He emphasized that the vulnerabilities exploited were publicly known and had been discussed in open literature.

Some computer scientists and security researchers supported Morris's characterization of the incident as a research experiment gone wrong rather than criminal hacking. They noted that the practice of exploring system vulnerabilities was common in academic computer science and that Morris's mistake was in executing such exploration on production systems without authorization and without adequate safeguards.

Critics of the Computer Fraud and Abuse Act have used Morris's case to argue that the statute is overbroad and criminalizes activities that should be civil matters or academic sanctions. They contend that Morris's prosecution reflected government overreaction to a new type of problem and established precedents that have been used to prosecute security researchers conducting legitimate vulnerability testing.

Legacy & Historical Debate

Robert Tappan Morris's legacy encompasses technical, legal, and cultural dimensions of computing history. The Morris Worm remains one of the most studied security incidents in Internet history, regularly examined in computer science courses, security training, and historical analyses of Internet development.

The incident's timing — occurring when the Internet was transitioning from a small research network to a broader infrastructure — amplified its impact. The worm demonstrated that Internet security could not be treated as a theoretical concern or left to individual system administrators. The coordinated response required and the creation of CERT/CC established models for incident response that persist decades later.

Legally, United States v. Morris established foundational interpretations of the Computer Fraud and Abuse Act. The case clarified that unauthorized access need not involve traditional hacking techniques or malicious intent to violate the statute. This interpretation has been cited in hundreds of subsequent cases and remains central to debates about CFAA reform, with critics arguing it enables prosecution of activities such as violating terms of service or conducting security research.

Morris's case highlighted tensions between hacker culture and legal norms. The computing community of the late 1980s included researchers who regularly explored system boundaries and tested security, often without formal authorization. Morris's prosecution signaled that such activities, even when conducted by university researchers, could result in criminal liability.

The contrast between Morris's conviction and his subsequent career raises questions about redemption and the treatment of young offenders. Morris's successful academic career and contributions to distributed systems research suggest that criminal conviction for computer crimes need not permanently exclude individuals from professional computing. However, critics note that Morris's outcomes may reflect privilege — including his father's status, access to elite legal representation, and connections to prestigious institutions — unavailable to most defendants.

Y Combinator's influence amplifies Morris's legacy beyond security and law. The accelerator model has shaped how technology startups form, secure funding, and develop products. Y Combinator's emphasis on rapid iteration, user focus, and technical founder leadership reflects values from hacker culture, including the experimental ethos that characterized Morris's worm creation.

Historians debate whether the Morris Worm ultimately benefited Internet security by forcing improvements, or whether its damage outweighed any subsequent gains. The worm exposed vulnerabilities that were already known to security experts but not adequately addressed. Whether forcing attention to these problems through unauthorized action can be justified remains contentious.

The incident's technical lessons about software vulnerabilities, defense in depth, and the dangers of monoculture (the worm spread partly because many systems ran similar Unix configurations) remain relevant. Security researchers continue to reference the Morris Worm when discussing supply chain security, software patching practices, and the risks of networked systems.

Morris rarely gives interviews specifically about the worm, typically declining to revisit the incident in detail. His academic publications and Y Combinator work focus on current technical problems rather than historical events. This reticence has left some aspects of his motivations and reflections on the incident under-documented in the historical record.

Continue Investigating

The Morris Worm's creation and legal aftermath connect to multiple threads in The Archive's documentation of technological development, legal precedent, and institutional responses to emerging threats.

The worm's exploitation of vulnerabilities in systems connected to DARPA-funded networks links to darpa's role in Internet development and the tension between open research networks and security requirements. DARPA's immediate response in funding CERT/CC establishment demonstrated institutional recognition that Internet security required dedicated infrastructure.

The response coordination led by carnegie-mellon-cert-cc established templates for incident response that influence cybersecurity practice globally. CERT/CC's evolution from emergency response to ongoing coordination center reflects institutionalization of security practices that the worm catalyzed.

Analysis of the worm by eugene-spafford and keith-bostic established methodologies for reverse-engineering malware and documenting security incidents. Their technical reports became foundational texts in computer security education.

The prosecution by mark-rasch and trial before judge-howard-munson established legal precedents that shape computer crime prosecution. The case's interpretation of intent, damage, and unauthorized access continues to influence Computer Fraud and Abuse Act enforcement.

Morris's relationship to his father, robert-morris-sr, illustrates generational transitions in computing expertise and the complexity of inheritance in technical fields where knowledge of vulnerabilities can serve defensive or offensive purposes.

Broader investigation connects to:

  • ·the-crypto-wars-and-encryption-backdoors: debates about security research, vulnerability disclosure, and the appropriate balance between open research and controlled information parallel tensions in Morris's case
  • ·snowden-and-nsa-mass-surveillance: questions about unauthorized disclosure of security vulnerabilities and whistleblowing share legal frameworks with computer intrusion prosecutions
  • ·stuxnet: sophisticated malware designed by state actors represents evolution of techniques demonstrated in primitive form by the Morris Worm
  • ·vault-7: CIA tools that leaked in 2017 revealed state-sponsored vulnerability exploitation, contextualizing debates about whether Morris's unauthorized testing served public interest

Researchers examining Morris's case should consult:

  • ·Court records from United States v. Morris (including trial transcripts, sentencing memoranda, and appellate decisions)
  • ·Technical analyses by Eugene Spafford, the Berkeley team, and CERT/CC
  • ·Congressional hearings on Internet security following the worm
  • ·Computer Fraud and Abuse Act legislative history and subsequent amendments
  • ·Academic literature on computer security history and ethics
  • ·Morris's academic publications on distributed systems
  • ·Documentation of CERT/CC's establishment and evolution

The Morris Worm remains a foundational case study in the perpetual tension between security research, unauthorized access, and criminal liability — a tension unresolved in law and ethics more than three decades later.

Evidence Register10
Confirmed by CourtS1 S2
Robert Tappan Morris created and released the Morris Worm on November 2, 1988, which infected approximately 6,000 computers, representing roughly 10% of the Internet at the time.
These facts were established at Morris's 1990 trial in U.S. District Court for the Northern District of New York, where he was convicted under the Computer Fraud and Abuse Act.
Official RecordS2 S3
Morris was convicted on January 22, 1990, of violating 18 U.S.C. § 1030(a)(5)(A) of the Computer Fraud and Abuse Act, making him the first person convicted of a felony under that statute.
The conviction was upheld on appeal by the Second Circuit Court of Appeals in 1991. The case established significant precedents for interpreting the Computer Fraud and Abuse Act.
Official RecordS1 S2
Morris was sentenced to three years probation, 400 hours community service, and a fine of $10,050, despite facing a statutory maximum of five years imprisonment and $250,000 fine.
Judge Howard G. Munson imposed this relatively lenient sentence on May 4, 1990, considering Morris's cooperation, lack of criminal history, and apparent lack of malicious intent.
Historical ConsensusS4 S5
The Morris Worm directly catalyzed the creation of the Computer Emergency Response Team Coordination Center (CERT/CC) at Carnegie Mellon University in December 1988.
DARPA funded CERT/CC's establishment in immediate response to the worm incident to coordinate future Internet security responses. This became the template for computer emergency response teams worldwide.
Official RecordS2
Morris testified that the worm was intended as a harmless experiment to gauge the Internet's size and that widespread damage resulted from a programming error in the reinfection prevention code.
This was Morris's defense at trial. The court found him guilty despite this testimony, establishing that lack of malicious intent does not excuse unauthorized access that causes damage.
Government FindingS1 S6
Damage estimates from the Morris Worm ranged from $100,000 to $10,000,000, with significant variation based on assessment methodology.
The Government Accountability Office and academic researchers provided varying estimates. Difficulty in quantifying distributed harm, institutional response costs, and distinguishing emergency repairs from opportunistic improvements contributed to wide ranges.
Confirmed by CourtS3 S7
The Second Circuit Court of Appeals ruled in 1991 that the Computer Fraud and Abuse Act requires proof of intentional unauthorized access but not proof of intent to cause damage.
This interpretation in United States v. Morris, 928 F.2d 504 (2d Cir. 1991) significantly shaped subsequent prosecutions under the Act and remains central to debates about the statute's scope.
Established FactS8 S9
Morris co-founded Y Combinator in 2005, which became one of the most influential startup accelerators, funding companies including Airbnb, Dropbox, Stripe, and Reddit.
Morris co-founded Y Combinator with Paul Graham, Jessica Livingston, and Trevor Blackwell while maintaining his MIT faculty position. Y Combinator has funded thousands of startups.
Established FactS10 S11
Morris has been a tenured professor at MIT's Computer Science and Artificial Intelligence Laboratory since 2006, conducting research on distributed systems and networks.
Morris joined MIT's faculty in 1999 and achieved tenure in 2006. His academic work includes significant contributions to distributed hash table protocols, including the Chord protocol.
Established FactS1 S12
Robert Morris Sr., the worm creator's father, served as chief scientist at the NSA's National Computer Security Center at the time of the worm's release.
Robert Morris Sr. was a prominent cryptographer and computer security expert. He publicly stated he had no prior knowledge of his son's worm project and did not provide classified information.
Record Timeline16
  1. 1965Robert Tappan Morris born November 8
  2. 1987Graduated from Harvard University with BA in computer science
  3. 1988Entered Cornell University graduate program in computer science
  4. 1988Released the Morris Worm on November 2 from MIT computer systems
  5. 1988Morris Worm infected approximately 6,000 computers across the Internet on November 2-3
  6. 1988CERT/CC established at Carnegie Mellon University in December in direct response to the worm
  7. 1989Indicted on July 26 on one count of violating the Computer Fraud and Abuse Act
  8. 1990Convicted on January 22, becoming first person convicted of felony under Computer Fraud and Abuse Act
  9. 1990Sentenced on May 4 to three years probation, 400 hours community service, $10,050 fine
  10. 1991Conviction upheld by Second Circuit Court of Appeals on March 7
  11. 1995Received PhD from Harvard University
  12. 1999Joined MIT faculty as assistant professor
  13. 2001Co-authored influential paper on Chord distributed hash table protocol
  14. 2005Co-founded Y Combinator startup accelerator
  15. 2006Achieved tenure at MIT
  16. 2024Continues as professor at MIT CSAIL and Y Combinator partner
Documented Associates10
Robert Morris Sr.Father; chief scientist at NSA's National Computer Security Center during worm incident
Eugene SpaffordPurdue University professor who conducted detailed technical analysis of the Morris Worm
Keith BosticBerkeley researcher who analyzed the worm and contributed to understanding its propagation
Mark RaschAssistant U.S. Attorney who prosecuted Morris's case
Howard G. MunsonU.S. District Judge who presided over Morris's trial and imposed sentence
Paul GrahamCo-founder of Y Combinator with Morris
Jessica LivingstonCo-founder of Y Combinator with Morris
Andrew SudduthHarvard friend Morris contacted to help distribute warnings about the worm
Frans KaashoekMIT colleague and co-author on distributed systems research
Ion StoicaCo-author on Chord protocol and distributed systems research
Documented association ≠ participation in misconduct
Continue Investigating
Sources · All HTTP-Verified14
  1. S1
    The Morris Worm: A Fifteen Year PerspectiveIEEE Security & Privacy · academic
  2. S2
  3. S3
    United States v. Morris - Second Circuit DecisionCornell Legal Information Institute · primary
  4. S4
    CERT Coordination Center HistoryCarnegie Mellon Software Engineering Institute · primary
  5. S5
    The Internet Worm Program: An AnalysisPurdue University Department of Computer Sciences · academic
  6. S6
    The Computer WormU.S. Government Accountability Office · primary
  7. S7
  8. S8
    Y CombinatorY Combinator · primary
  9. S9
  10. S10
    Robert Morris - MIT CSAIL FacultyMIT Computer Science and Artificial Intelligence Laboratory · primary
  11. S11
  12. S12
    Robert Morris (cryptographer)Wikipedia · reference
  13. S13
    A Graduate Course in Applied CryptographyStanford University · academic
  14. S14
    Robert Tappan MorrisWikipedia · reference
The Archive does not decide guilt. The Archive documents evidence. Inclusion in a profile never implies guilt — every claim above carries its evidence status and traces to a listed source.
Network Strength
1
Dossiers
7
Connected
2
Organizations
0
Operations
5
People
1979 — 2006
Timeline Span
Referenced In01
Continue Your Investigation

If you're learning about this topic for the first time, these are the best places to continue — documented evidence and historical relationships are the guide.

Dossier
The Morris Worm

Robert Tappan Morris is documented in the evidence record of this published dossier.

Published Dossier12 verified sources
Continue Investigation
DARPA
Government Agency
DARPA

Funded CERT/CC creation and had developed the Internet's predecessor ARPANET.

DocumentedAppears in 2 dossiers
Continue Investigation
Person
Eugene Spafford

Conducted foundational technical analysis of the Morris Worm.

DocumentedAppears in 1 dossier
Continue Investigation