IRC LOL All articles
Investigation

Someone Else's T1: The Bootleg Bandwidth Economy That Built the Early Internet

IRC LOL
Someone Else's T1: The Bootleg Bandwidth Economy That Built the Early Internet

Photo by Photo by Albert Stoynov on Unsplash on Unsplash

In 1999, a mid-sized insurance company in Hartford, Connecticut was paying roughly $3,000 a month for a T1 line — 1.544 megabits per second of dedicated internet connectivity, which was serious money and serious bandwidth for the era. Their IT department used maybe forty percent of it during business hours. The rest sat idle overnight, pushing nothing but keepalive packets into the void.

A network administrator at that company — young, underpaid, extraordinarily bored — had a friend who ran a warez FTP site. The FTP site needed upstream bandwidth. The insurance company had upstream bandwidth. The network administrator had access to the router. The math was not complicated.

This arrangement lasted eleven months before anyone noticed the anomalous traffic patterns. By then, the FTP site had distributed approximately 800 gigabytes of software, games, and MP3s across the scene. The network administrator was fired. No charges were filed, because the insurance company's legal team looked at the situation and decided that explaining to a jury what an FTP server was would be more embarrassing than the loss itself. The FTP site moved to a different corporate host within a week.

The Infrastructure Problem Nobody Wanted to Solve Honestly

The early internet underground had a fundamental infrastructure problem: the things they wanted to do required bandwidth they couldn't afford and couldn't obtain legitimately. A private FTP site serving a warez distribution network needed serious upstream capacity. An underground IRC server needed a stable, high-bandwidth connection that could handle hundreds of simultaneous users. A SHOUTcast station streaming MP3s to listeners across the country needed continuous throughput that a residential DSL line simply couldn't provide.

Legitimate hosting existed, but it was expensive and it asked inconvenient questions. Colocation facilities in 1999 wanted business registration paperwork and credit cards and contracts. They wanted to know what you were hosting. The underground didn't want to answer those questions, which meant the underground needed a different approach.

The approach it found was, in retrospect, obvious: find the bandwidth where it already existed and wasn't being fully used, and redirect it. Corporate America was swimming in underutilized T1s and T3s, connected to the internet for email and web browsing, monitored sporadically if at all, and administered by people who ranged from vigilant to completely indifferent. The underground found the indifferent ones.

The Taxonomy of Stolen Bandwidth

Not all bootleg bandwidth was obtained the same way, and the methods said a lot about both the sophistication of the operation and the moral flexibility of the people involved.

The most common arrangement was the inside job: a sympathetic employee at a company with fat pipes who either actively helped or simply looked the other way while someone plugged a server into the DMZ. Universities were particularly popular targets for this, because university networks had enormous bandwidth, a culture of openness that predated the commercial internet, and IT departments that were perpetually understaffed and occasionally staffed by graduate students who were themselves scene-adjacent. A surprising number of early warez sites and IRC servers lived on university iron, blessed by a grad student with root access and a philosophical objection to intellectual property law.

Step up from the inside job and you found the compromised server: a machine at a legitimate company that had been popped through a vulnerability — an unpatched IIS server, a default-password router, a misconfigured FTP daemon — and was now running additional services that the company didn't know about. The attacker wasn't stealing the company's data. They were stealing its electricity and its bandwidth. The company's machine was doing its regular job and also, quietly, serving gigabytes of pirated software to enthusiastic teenagers in the Pacific Northwest.

At the top of the sophistication ladder sat operations that had compromised entire network segments — sometimes through BGP manipulation, sometimes through more straightforward means — and were essentially squatting on address space that belonged to someone else. These were rare and required genuine technical skill, but they existed, and the people running them understood routing protocols better than most of the legitimate engineers whose infrastructure they were occupying.

What the Bills Eventually Revealed

The detection problem for corporate victims was genuinely difficult. Bandwidth monitoring in the late 1990s was not the granular, real-time discipline it would later become. Many companies looked at their internet bills monthly, noticed that usage was higher than expected, assumed it was legitimate business growth, and paid without investigating. The T1 was a fixed monthly cost regardless of utilization, which meant there was no variable bill to trigger an alert. Suspicious traffic could live in a corporate network for months before anyone looked hard enough to see it.

When detection did happen, it usually came from one of three directions: a routine audit that caught anomalous outbound connections, a complaint from another party (an IP abuse report from a rights holder, for instance), or a pure accident — someone rebooting the wrong server and discovering it was running processes that weren't in any documentation.

The aftermath was usually quiet. Companies that discovered they'd been hosting warez sites or running IRC servers for the underground had strong incentives to keep it out of the press. Admitting that your network had been compromised for eleven months without detection was not a great look for an insurance company, a bank, or a government contractor. The FBI was occasionally involved, but prosecutions were rare. The underground had correctly intuited that its victims were often too embarrassed to pursue the matter.

The Legitimate Inheritance

Here is the uncomfortable part: the infrastructure experiments that the bootleg bandwidth economy enabled were genuinely influential. The people running underground FTP sites on hijacked corporate connections in 1999 were solving real distributed systems problems — load balancing across multiple sites, geographic redundancy, automated failover when a host went dark — years before those problems had legitimate commercial solutions.

The SHOUTcast operators who piggybacked on university T3s to stream audio to thousands of simultaneous listeners were doing content delivery network work before Akamai was a household name in tech circles. The IRC server operators who built networks spanning dozens of servers across multiple continents, connected through whatever bandwidth they could scrounge, were running distributed infrastructure that was, in its own chaotic way, more resilient than most commercial systems of the era.

Some of the people who built those systems went on to build legitimate ones. The skills transferred. The concepts transferred. The specific knowledge of how to keep a server running when your hosting situation was precarious and could disappear at any moment was directly applicable to the early cloud computing era, when the infrastructure was legitimate but the reliability guarantees were similarly uncertain.

The insurance company in Hartford got a new network administrator who installed a proper monitoring system. The FTP site moved to a compromised university server in the Midwest and kept running for another two years. The grad student who blessed it with access graduated, got a job at a startup, and spent the next decade building content delivery infrastructure at scale.

He did not put the FTP site on his LinkedIn. The skills, though — the skills he put on his LinkedIn. They were real, and they were earned, and the Fortune 500 paid for the education without ever knowing they'd enrolled.

All Articles

Related Articles

PC방 Prophets: How Korean StarCraft Fans Engineered Twitch's Brain Six Years Before Broadband Got Good

PC방 Prophets: How Korean StarCraft Fans Engineered Twitch's Brain Six Years Before Broadband Got Good

Digital Gravediggers: When Archive Team Volunteers Became the Internet's Emergency Room Surgeons

Digital Gravediggers: When Archive Team Volunteers Became the Internet's Emergency Room Surgeons

The Lost Library of Digital Babel: Inside IRC's Great Logging Disaster

The Lost Library of Digital Babel: Inside IRC's Great Logging Disaster