STEVE GIBSON▊
- OPERATION
- Gibson Research Corporation (GRC), founded 1985 · SpinRite (1988) · ShieldsUP FACT
- HABITAT
- Security Now podcast with Leo Laporte, weekly since 2005; passed 1,000 episodes in November 2024 FACT
- RECORD
- No conviction. No adjudication. No fraud allegation from any named critic. Every charge below is a technical dispute. FACT
- STATUS
- STILL BROADCASTING — the products ship, the podcast airs, the attrition file stays open
- DISPOSITION
- Filed on attrition.org's Charlatan List — attrition's characterization, contested by a large and loyal audience ATTRIBUTED
…maliciously potent Windows XP machines are mated to high-bandwidth Internet connections, we are going to experience an escalation of Internet terrorism the likes of which has never been seen before.
Steve Gibson in 2001, predicting that Windows XP’s “raw sockets” would unleash unstoppable denial-of-service attacks and destabilize the whole internet — a catastrophe that did not arrive. Microsoft shipped the feature; the net kept working. The Register, 2001.
The specimen, observed since 1985 in the coastal scrubland of Southern California, builds two things in roughly equal volume: working software and alarming predictions. The field disputes only one of them.
A word of caution before we approach. This is not the same animal as the others in this drawer. There is no forged credential here, no guilty plea, no vanished client. The tools are real. The following is real and has renewed itself weekly for twenty years. What the field contests is narrower, and stranger: the predictions — loud, confident, apocalyptic — and the pattern of the community assembling, each time, to take them apart.
A divided field is the hardest thing to film. That is why the archive exists. Every event below carries its receipt. Both sides get the microphone.
the drama timeline
ACT I — THE BUILD (1981–2000)
Unusually for this drawer, the display structure is made of actual work. Watch closely: the tools constructed in this act are the same ones the defense will carry into every dispute that follows.
-
1981–1988
Light pens, then a disk utility that would not die
Gibson Laboratories ships a light pen for the Apple II and Atari; Gibson Research Corporation follows in 1985; SpinRite, a hard disk scanning and data recovery utility, ships in 1988 — and is still sold today. From 1986 to 1993 he writes InfoWorld's "Tech Talk" column.
-
1999
OptOut and ShieldsUP
Creates OptOut, one of the first adware-removal programs, and runs ShieldsUP, a free browser-based firewall test that becomes one of the oldest services of its kind. Millions of users check their ports against it.
Note this act carefully. In every other file in this drawer, Act I is the fabrication. Here it is the genuine article — which is precisely what makes the specimen divisive rather than simple.
ACT II — THE PREDICTION SEASON (2001)
The year everything happens at once: the specimen is genuinely attacked, genuinely fights back, and genuinely predicts the end of the internet. The field arrives to sort out which was which.
-
2001
grc.com is DDoSed — for real
His company's website is brought down by denial-of-service attacks that continue for two weeks. Gibson blogs the whole campaign and his ultimately successful hunt for the attacker. The victimhood is real; nobody disputes this part.
-
JUN 2001
The raw-sockets prophecy, and the rebuttal
Gibson warns that Windows XP's raw-socket support will let spoofed-packet floods destabilize the internet. The Register answers with a headline — "Steve Gibson really is off his rocker" — and a technical rebuttal: "Raw sockets in XP only marginally improve the situation for a malicious party."
-
AUG 2001
Code Red and the trumpets of Revelation
Gibson forecasts catastrophe from Code Red's scheduled return. The Register opens its response with Revelation 8:7 and files him under "techno-hypemeister and headline glutton." It also disinters an older prediction, per Rosenberger: that the Dark Avenger Mutation Engine would render anti-virus software permanently ineffective. The internet, follow-up coverage notes, survived.
Observe the ecosystem at work. The specimen predicts fire; the field measures the temperature; the readership is entertained either way. Every party in this exchange is, in its own economy, profiting.
-
NOV 2001
ShieldsUP, pointed the wrong way
Researcher "Thor" of HammerOfGod shows at a Blackhat session that ShieldsUP's client-side IP handling lets anyone aim the scanner at an arbitrary address — an anonymous port-scan proxy, and scripted, a DoS vector. The Register's headline: "Steve Gibson accidentally creates DoS tool."
-
2004
The asterisk on the prophecy
Microsoft limits raw-socket support in Windows XP Service Pack 2 — three years after Gibson's warning. His critics say the internet never burned; his defenders note the vendor quietly removed the thing he warned about. Both readings fit the record; the record itself is not in dispute.
ACT III — THE BACKDOOR THAT WASN'T (2006)
The most instructive episode in the file, because it contains something rare in this genre: the specimen publishing its own rebuttal.
-
JAN 2006
The WMF speculation
Examining the Windows Metafile vulnerability, Gibson suggests on a podcast and on grc.com that the flaw looks like an intentional Microsoft backdoor. Slashdot amplifies it into a full internet rumor. The Register's account: a "popinjay expert" who, "due to his lack of security experience, observed behavior that he could not explain by means other than a Microsoft conspiracy."
-
JAN 2006
Russinovich answers — and Gibson prints it
Mark Russinovich examines the code and sends his results to Microsoft and to Gibson: "The bottom line is that I'm convinced that this behavior, while intentional, is not a backdoor." Microsoft's response attributes the bug to a coding error and misleading documentation. Gibson publishes the correspondence on his own site and concedes the malice reading outright: "no one believes (myself included) that Microsoft would act in a deliberately malicious manner" — and, of the mistake theory, "Of course, sure, absolutely, probably was."
Mark the behavior, because it separates this specimen from every convicted animal in the drawer: challenged with evidence, it printed the challenge, named the challenger, and gave ground. Charlatans, as a species, do not do this.
-
EPILOGUE
Still broadcasting
Security Now, launched with Leo Laporte in 2005, passes 1,000 weekly episodes in November 2024. SpinRite and ShieldsUP still ship from grc.com. The attrition.org file remains open. The archive keeps the tape running.
both sides, on the record
The critics' pattern claim (theirs, not ours): recurring public alarms — raw sockets ending the internet, Code Red as tribulation, WMF as a deliberate backdoor — each dismantled in print by the technical press, at length, in real time [3] [4] [6].
The tool finding: his own free scanner was shown usable as an anonymous port-scan proxy and DoS vector, per a named researcher at Blackhat [5].
The listing: attrition.org keeps a Gibson file on the same Charlatan List that holds the convicted and the fabricated — attrition's editorial judgment, sustained for two decades [1].
The products are real and widely used. SpinRite has shipped continuously since 1988; ShieldsUP is one of the oldest free firewall-testing services on the web; OptOut was one of the first adware-removal programs ever written [7] [8] [9].
The following is real. Security Now has run weekly since 2005 and passed 1,000 episodes — twenty years of listeners who find the analysis worth their hour [10]. And the raw-sockets record carries his asterisk: Microsoft did limit raw sockets in XP SP2, three years after his warning [7].
Scope of the record: every charge on this sheet is a technical disagreement. No court, no regulator, and no named critic has alleged fraud, fabricated credentials, or a crime. On WMF he published his challenger's rebuttal on his own site and conceded the malice reading [2]. The harshest documented charge is being loudly, publicly, confidently wrong — which the industry has never once made disqualifying.
YOU DECIDE
Scoped to the claims, never the man. Two specific predictions — "XP raw sockets will destabilize the internet" and "WMF was an intentional backdoor" — lost their arguments on the public record, the second by his own published concession; the first keeps an asterisk named Service Pack 2. Nothing here is adjudicated. Nothing here is fraud. The record shows a divisive expert whose products have outlived every one of his predictions.
Weigh the costly signals: he printed Russinovich's rebuttal on his own site, named the challenger, and gave ground. The Register spent five years of column inches on him and never once alleged a fraud.
The archive does not judge. The archive merely keeps the tape running.
evidence locker
PRIMARY RECORD
GRC — "M.I.C.E. — Metafile Image Code Execution" SELF-PUBLISHED — Gibson's own WMF page: his claim, the Russinovich correspondence, and his concessions, in his own words.
grc.com/wmf/wmf.htm
PRESS & CRITICS
SUBJECT'S OWN CHANNELS — THE SPECIMEN, UNEDITED
GRC — ShieldsUP SELF-PUBLISHED — the free port scanner, still running.
grc.com/shieldsup
The standard. Everything above is sourced to named press reporting, the attrition.org archive, a sourced encyclopedia biography, and the subject's own published pages. Facts are stated as facts; characterizations are stated as characterizations and wear their author — "popinjay" belongs to The Register, not to us. Every charge on this page is a technical dispute; none is a fraud finding, and the page says so. The defense is presented at full strength, including what the record does not show. No motive is asserted, no private character diagnosed. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.