Summary

  • RFC 1135 recorded disagreement about intent and post-incident ethics; it was an informational memo, not a standard or a single adopted code.
  • The MIT team distinguished explaining a vulnerability and its algorithms from publicly releasing decompiled source. CPSR’s call to publish flaw descriptions did not settle the separate source-code decision.
  • The records support a history of competing choices, not a universal disclosure policy, complete media account, or proof that any one position was adopted across the Internet.

Two decisions hid inside one word

On Saturday afternoon, 5 November 1988, researchers at MIT discussed whether to release the decompiled source of the worm. Their chronology says the team agreed not to publish that source during the crisis. It also says the team did not want the program’s inner workings hidden: it intended to describe the algorithms so others could understand what had happened. The team’s stated concern was practical. Adding a destructive change and recompiling a working program required less effort than recreating the program from an explanation.

That was not a simple choice between secrecy and openness. A technical description, a source listing, a defensive patch, and a private copy sent to another researcher were different objects with different audiences and risks. The MIT account says the team considered possible later distribution after sites had time to install fixes. This was the team’s recorded decision, not a policy order from MIT’s administration or a rule for every Internet operator. The MIT chronology describes the choice directly.

A second contemporary record made the difference visible. In December 1989, Jon Reynolds’s RFC 1135 reviewed the worm’s aftermath and set out statements by the Internet Activities Board, the National Science Foundation, MIT, and Computer Professionals for Social Responsibility. It calls itself a report of an Internet event and says it specifies no standard. The document is valuable because it records disagreement; that same status limits what its publication can prove. RFC 1135 is an archive of positions, not a vote showing that the community adopted one of them.

Four statements did not make one code

The IAB’s January 1989 RFC 1087 described the Internet as a shared research facility and framed professional responsibility around its continued availability. It named purposeful unauthorized access, disruption, waste, damage to information integrity, and compromise of privacy as unacceptable. It also warned that network-wide experiments could affect people beyond the researcher, and that protective measures could become counterproductive if they obstructed the free flow of information. The statement joined restraint to openness; it did not describe a central body that could decide every local disciplinary case. RFC 1087 is explicitly an IAB policy statement.

RFC 1135 reports a different emphasis in the NSF division advisory panel’s November 1988 statement. As Reynolds summarized it, the panel included negligence as well as purposeful disruption and encouraged organizations that managed networks to publish their own ethical policies and disciplinary procedures. The recommendation pointed toward action by institutions responsible for particular systems. It did not, in the text preserved by RFC 1135, establish a universal enforcement office.

MIT’s statement of responsible computer use predated the worm. RFC 1135 describes it as campus guidance about intended use, privacy, security, system integrity, and intellectual property. That matters because a university’s conduct rules govern its members and systems; their presence does not make them Internet-wide law.

CPSR, by contrast, argued that effective correction required publishing descriptions of security flaws. Its statement defended open exchange and warned against policies that would restrict researchers’ ability to share ideas. But the proposition “publish descriptions of flaws” is not the same as “release a working copy of the exploit.” The MIT team’s account makes that distinction explicit. Reading the two records together reveals a disclosure spectrum where a slogan about openness can conceal several separate decisions.

RFC 1135 quotes the CPSR position; that is evidence of what the 1989 memo reported, not a complete independent history of every CPSR action.

Explanation and execution carried different costs

The MIT researchers said that detailed knowledge of the program should not be hidden. They nevertheless considered a public source release different because a recipient could more easily add a destructive change and rebuild it. Their account describes withholding their decompiled source publicly during the immediate response while discussing algorithms and working with other researchers. It also records an argument, associated with Jerry Saltzer, for possible release after affected sites had time to patch.

This distinction did not resolve every risk. Keeping source private could make independent checking harder; publishing it could reduce the work required to reuse the program. Publishing an explanation could help defenders and still provide information to someone capable of rebuilding the method. Patches could give operators a concrete repair without settling what level of technical detail should enter the public archive. The sources record a team’s decision and arguments around it, not measured evidence of how much any one choice changed the outcome. The MIT team’s conclusion lists both source availability and openness among the issues the incident exposed.

The difference also explains why “the Internet chose disclosure” would be too broad. RFC 1135 places several statements side by side but gives no adoption tally, vote, distribution record, or later compliance audit. Its own description of the debate over whether the worm escaped accidentally or was deliberately released is also not a finding of intent. It shows that a contemporary author recorded competing accounts and rejected infestation as an acceptable way to expose flaws. It cannot settle the actor’s motive by itself.

The press was another boundary, not a single actor

RFC 1135 criticizes sensational coverage and reports that some Berkeley researchers found the press disruptive. The MIT chronology gives a more local account: the team says its News Office batched requests into a press conference and kept reporters away from much of the analysis work. The researchers also say that many reporters asked genuine questions, even as they recount mistaken claims and expectations for a dramatic visual demonstration.

These accounts are not mutually exclusive. They describe different experiences and show why “the media” should not be treated as one uniform institution. News staff could protect researchers’ time while providing a public channel; a headline or rumor could still distort what readers thought had happened. RFC 1135 records the author’s 1989 assessment, and the MIT chronology records one team’s view. Neither is a census of all reporting or a quantified measure of delay.

That boundary matters because public interpretation carried practical effects. Claims that an attacker was a hero could recast an unauthorized act as a security service; claims that a new outbreak was underway could consume attention even when the report was false. The evidence supports those as documented communication problems, not a claim that press coverage caused the incident or controlled the technical response.

What the RFC could preserve

RFC 1135 is not an Internet-wide ethics standard. Its pages preserve a moment in which organizations described responsibilities at different scales: an IAB policy for shared infrastructure, an NSF recommendation to network operators and institutions, existing campus conduct rules, and a civil-society argument for open research. The MIT account adds a specific distinction between publishing methods and distributing executable source. The archive does not show that these views were reconciled or universally adopted.

Heng Lu’s later Note 64 offers a useful interpretive lens: publication is not the same thing as implementation or adoption by participants running systems. That 2026 design doctrine is not evidence about 1988, and it should not be attributed to the IAB or to Reynolds. Applied carefully, it helps ask a historical question: did a published statement describe a principle, or do the records show that an organization implemented it? For RFC 1135, the answer is often the former.

The enduring record is therefore not one settled disclosure rule. It is a set of separable choices: describe a flaw, explain an algorithm, send a patch, share a source copy with a limited group, or publish the working code. Each choice changes who can inspect, repair, reproduce, or reuse the material. The 1989 memo makes that disagreement legible. It does not authorize a single institution to decide the answer for every network.

Sources