STORY

Tandem Computers and the Safeguard C2 Prank

  • Tandem Computers and the Safeguard C2 Prank

  • An April Fools' Day prank at Tandem Computers in 1988 that exploited a Safeguard security leak and ultimately led to a stronger operating system.
  • The C2 Security Initiative & Lyle Settle

    • After moving from Beaverton back to Silicon Valley, my former Tektronix manager Lyle Settle brought me into Tandem Computers in Cupertino as a contractor for a year.
    • Tandem was working hard to achieve a C2 security rating under the Department of Defense's Orange Book guidelines (TCSEC).
    • My primary responsibility was authoring Tandem's first Security Administration Guide, translating the distributed Guardian OS environment's operational security for government evaluators.
    • I worked in close coordination with the Security Department, where Bill Lamb was my main technical counterpart and the subject matter expert I interviewed most extensively to translate Safeguard's internals into the documentation.
  • The April Fools' Day Black Hole

    • Safeguard was retrofitted onto Guardian OS, which was originally built for high-speed open communication rather than strict cryptographic permissions.
    • While writing the manual, I discovered that specific combinations of explicit GRANT and DENY commands could create a file descriptor state overriding standard owner privileges.
    • For April Fools' Day, I used this logic gap to initialize an un-deletable file named APRLFOOL in everyone's home directory. The permission deadlock was so absolute that not even the directory owners could delete it.
    • The stunt nearly got me fired as management panicked during the high-stakes audit. However, once resolved, the engineering team used the exploit to patch the Safeguard API leak, hardening the operating system.
  • Cupertino Culture & Watering Holes

These facts are as Randal recalls them, but much time has passed for most of this. If you find a factual error, please email realmerlyn@gmail.com.