
Show notes
Phrack is legendary. It is the oldest, and arguably the most prestigious, underground hacking magazine in the world. It started in 1985 and is still running today. In this episode we interview the Phrack staff to hear some stories about what it’s like running a hacker magazine for 40 years. phrack.org Sponsors Support for this show comes from ThreatLocker®.
Highlighted moments
So FRAC stands for freaking and hacking. It's a combination of these two words. And it used to be the manipulation of the phone lines. Effectively, the main goal was to get you free phone calls that are very hard to trace.
“Well, luckily, in the olden days, these things were rather easy. You would go to the domain registrar, and this example was a French one, Gandhi.net, and you would initiate a domain transfer, and it would ask you that you need the authorization code to transfer it. And you would right-click on the web page and save a few source code of the web page, and the authorization code would be written there in a hidden HTML tag, in a form tag.”
“And so what happened is that the FRAC staff always releases the upcoming FRAC release to the community, to some trusted friends. And then after it's released to trusted friends, then it's released to some lesser trusted friends and so on and so on. And after a few days, it ended up before the official webpage release in the hands of a PHC guy.”
“First, to solve these issues, we tried to find, like, local printers, right? And it is very, very challenging because the transportation is very costly. So, we found a Vegas printer, and I think for DEF CON, that was 10 tons or something?”
Transcript
Introduction to Phrak and its history
0:00This episode is sponsored by Datadog. The barrier to entry for attackers has never been lower. AI has collapsed the timeline of an attack from weeks to minutes. Threat actors are now moving at machine speed. But most security tools weren't built for this pace. They assume static environments and human-paced workflows. And if observability and security data is split across disconnected systems, investigations take even longer, right when speed matters most. That's where Datadog comes in.
0:30Datadog is the security and observability platform for the AI era. It unifies your telemetry into a single, real-time view, so detection and investigation can run on the same data. Datadog's BIT's AI security analyst autonomously triages and investigates security signals, cutting investigation times by up to 93% so teams can continue a threat at its source. Outpace attackers from prevention to remediation. Request your custom demo at datadog.com slash darknet.
1:03Again, that's datadog.com slash darknet. Hey, this is Jack, host of the show. So the last two episodes talked about hacking in the 80s and 90s, which was primarily phone-freaking. In those episodes, I talked about a digital magazine called Frack, which was incredibly influential to the hacking scene. It wasn't uncommon to be in a chat room and someone come in and ask, how do I get started as a hacker? And then someone else simply say, go to Frack's site, start reading it at issue one,
1:34and by the time you're all caught up, you'll be a great hacker. It's probably good to go and listen to the two episodes before this, before doing this one, just to have the context, but you don't have to if you'd rather not. But the thing is, is that in this episode, I interviewed two of the Frack staff. The magazine just celebrated their 40th anniversary, and I'm pretty sure if you run a hacker magazine for 40 years, there's got to be some interesting stories in there somewhere.
2:04These are true stories from the dark side of the internet.
2:11I'm Jack Recider. This is Darknet Diaries.
2:27This episode is sponsored by SpyCloud. Everyday stolen identity data like credentials, session cookies, PII, and more flows through criminal underground markets. Most companies don't know what's been exposed until it's too late. For the last decade, SpyCloud has existed for one reason, to disrupt cybercrime and end criminals' ability to profit from stolen data. That mission has never been more urgent. SpyCloud's latest idea has been to recapture darknet data from successful phishes,
3:00info-stealer malware, combo lists, and breachers to put it to good use. They transform it into automated identity threat protection, using advanced analytics and AI to protect workforce consumers and supplier identities from authentication bypass, session hijacking, account takeover, ransomware, and fraud. Don't wait to become the headline. Find out what criminals already know about your organization. Get your free Darknet exposure report at spycloud.com slash darknetdiaries. That's spycloud.com slash darknetdiaries.
3:34This episode is sponsored by Delete Me. This show has covered loads of crazy zero days that lead to massive cyber security attacks, but there are just as many attacks that started because someone clicked a link from someone they thought they trusted. Data brokers have so much of our info that attackers can use against us to scam or steal our identities. But Delete Me can delete it. Just go to joindeleteme.com slash dnd and let them do the hard work for you.
4:04Since my privacy is important to me, I'll take all the help I can get. A few years ago, I signed up. And ever since then, Delete Me has been busy scouring the internet for my name and giving me reports on what they found and what they deleted. Stay smart out there. Visit joindeleteme.com slash dnd to get a demo of Delete Me's business platform today. That's joindeleteme.com slash dnd. Joindeleteme.com slash dnd.
What is Phrak magazine
4:36Okay, first, let's start out with some introductions. Hi, my name is Skyper. I used to be the editor of the FRAC magazine in the year 2000 to 2005. And I've joined the FRAC staff recently again as an advisor. Hey, I'm Tim Z. I'm one of the current staff and editors of FRAC magazine. In your words, can you tell us what is FRAC magazine? So FRAC stands for freaking and hacking.
5:06It's a combination of these two words. And it used to be the manipulation of the phone lines. Effectively, the main goal was to get you free phone calls that are very hard to trace. FRAC magazine, this is all sorts of things, hacking related, to be honest. I think there is the infamous article on how to make a bomb as well in the past. Yeah, I mean, I think I saw that even in issue one. There was a balloon that had acetylene in it that we put like snap caps or pop caps on it
5:37and throw some rocks together. And you throw the balloon off like a roof. And when it hits the ground, the snap pops, the little popper snap, and then it creates a little explosion. I think that was issue one. And so it's interesting how anarchy kind of shows up in FRAC. Like bombs, what is this doing in a hacker magazine? I think we have to put this into a different context of where we were 40 years ago. Terrorism didn't really happen, at least not in most countries.
6:11And so building bombs was not seen as necessarily something evil or criminal, but it was just young kids exploring things. What can they do? They didn't mean to do any harm with them. They were just experimenting.
6:29In my opinion, FRAC seems to capture some kind of counterculture. It's notes from the underground type stuff. Because back in the 90s, cybersecurity wasn't quite a mainstream profession yet. Like schools didn't teach you how to secure networks or how to hack. But nowadays, almost every major university has a major in cybersecurity. So back in the 90s, there was just this underground group of people breaking computers, basically, and talking about it in chat rooms and on forums. You had freakers, hackers, rippers, crackers, seeders,
7:00which welcomed in artists and musicians who were making things on their computers. And this was collectively known as the scene back then. And I think it was this underground scene that FRAC was born out of and has its roots in. So the scene was made by, like, largely people trying things out with their new hardware that they found or, like, trying to, like, make something do something that was not supposed to be doing or that was not engineered to do. So that's what the original hacker was all about. I think if you summarize it, then FRAC contains condensed, hardcore technical articles without any bullshit.
7:37The stuff works and is practical. I'm fascinated by these two cultures, the cybersecurity professional and the scene hacker. One does it for money, and it's their career. And one does it for fun. It's their hobby. But they are both passionate about it. One tries to do it in the light. One wants to do it in the shadows. But they both like sharing what they know. What's the difference, honestly? Attitude? Style? But as computers grew more mainstream, becoming more common in every house, more interest grew in hacking.
8:12I mean, I'm sure you've gotten some kind of new electronic at some point in your life, and you sat down and you said to yourself, what are all the cool things that this thing can do? So imagine getting a computer and learning that it can print stuff and play games and make sounds, but then also hearing about some of the secret stuff it can do, like hack other people's computers. Some more people got fascinated with hacking and were contributing to things like FRAC, submitting articles on how to do cool secret stuff on your computer. But also, along with the rise of computers, the cybersecurity profession became popular,
8:46which sort of brought in a whole new culture of hackers. These weren't the rollerblading, cargo pants-wearing mohawk kids. The cybersecurity professional wears a collared shirt and sometimes a tie. You can see the stark contrast of these two cultures when you go to conferences like Black Hat and DEF CON. At Black Hat, you see people wearing suits and ties. They say they're geeks and nerds, but they don't look it. At DEF CON, there's a lot of people wearing cargo shorts, black shirts, hoodies, having mohawks.
9:20At Black Hat, I feel like those people have to be there for work. But at DEF CON, I feel like those people want to be there for the fun. And because I grew up in the scene, my heart is still there. We were the kids who tried stuff with no manual or tutorial. We built things that weren't possible. We did it without permission or rules. We pushed the boundaries and explored a new frontier. Which also, like a lot of those things, they actually paved the ground for like a lot of the security industry exists now.
9:51So a lot of people's job, they exist because of some of the articles that were written there, which is very interesting.
Historical significance and famous articles
9:56At this point, we're 40 years into FRAC. And some of the articles have historical significance. Historical significance has the article of the E911 documentation that was released in 1989, I believe. I think it was issue 24. And it was the documentation that detailed how the emergency 911 system works in America. And it was the first time that FRAC got into some legal problems with the authorities.
10:26I think that has some significance because it happened right after Operation Sun Devil with the Secret Service hunting hackers. And it also sparked the creation of the Electronic Frontier Foundation because the FRAC person who released that article was so unfairly treated by the government and by the corporates. Yeah, I think that article solidified FRAC as the coolest hacker magazine ever because the founder, Night Lightning, or one of the early founders, got arrested for publishing that article and then fought the law and won.
11:06And so it's like, well, I got arrested for hacking and I beat it and I got off scot-free. And that was just such a middle finger to the establishment of like, no, we're hackers and we can beat you. And we did beat you in your court, in your arena, in your court of law. We still won. We didn't do anything wrong. Screw off and leave us alone. And that must have been just like the most amazing epic moment for the time to beat the law.
11:36And I know there were some other FRAC contributors who didn't, weren't so successful with that E911 article. They pled guilty before they could fight it, but the fact that that happened and one of the only times anyone ever has been arrested for a CFAA violation and got off. It's only like I can count on one hand, I think, how many times that's happened. And FRAC was one of them. So, yeah, that was definitely quite an article. Yeah, Night Lightning faces 60 years in prison and $122,000 in fine.
12:08That's a lot more money nowadays, I think. Another article which made big waves was titled, Smashing the Stack for Fun and Profit. So, Smashing the Stack for Fun and Profit, issue 49, was the first article that told to the wider audience how buffer overflows work. So, in the olden days, buffer overflows were used to trick a computer, a target, to execute a program that is not intended to execute, to break into a computer system, so to say.
12:39And this article detailed it, how to do it yourself, how you can do it. It was not the first time it was used on the internet. The first time was probably by Robert T. Morris, who wrote the very first Internet worm. And there were other articles around how to manipulate the stack. But it was never that detailed, in that clarity, and reaching such a wide audience. When this article came out, buffer overflows became the new favorite way hackers would break a system.
13:10And it was a favorite because of how successful it was to do. Programs just weren't designed to stop this from happening. And so many things were vulnerable. I think the race just started with source code reviews and finding vulnerabilities, disclosing them, irresponsibly disclosing them in the olden days. And then slowly getting an idea of what responsible disclosure is, that not every corporate is your enemy. And trying to work together with them, trying to find common ground, how we can make the internet a better place for everybody.
13:41And this is one of those cases that this was like a very elite and underground technique, known probably just by governments or things like this, that when it hit the, when the article was written, it just like clicked in so many people's minds. So there was like this myriad of software that's like abundantly available and like most likely vulnerable. Like it just flew around with it, like everywhere. So, yeah. So just to put this into perspective, when I started out with computer security and hacking, when I wanted to learn how to break a computer system, I've been told what you have to do is you have to go to the library.
14:23You have to find the book about Robert T. Morris. You have to find and read the articles, the news articles to piece together information, how he did it. And then when FRAC came out with Smashing Stack and Fun and Profit, it was all clear immediately. Back then, hackers weren't very respected. Companies would try to ignore the vulnerabilities that they were told about, almost with the audacity of being upset that somebody would buy their software and then try to break it, as if hackers were the problems. Like they were just some punk kids trying to jab their fingers in somebody's eye.
14:57I think that has flipped and I always like to compare it against the early companies who did safety assessment for cars. The car industry tried to sue them and outlaw them and says, what are you doing? You can't show the people how dangerous it is to drive without a seatbelt. But they did. And now everybody has learned that it is right to have a seatbelt. It's good to have a seatbelt. And the same thing happened with this article and with the exploit development.
15:29In the beginning, they were hesitant. They were blaming the hackers for releasing such destructive technology. But if the hackers hadn't released it, then other governments surely would have exploited these holes anyway. True. Now they don't do this only for the front. They do this mainly for the profit. And it 100% became a business and a career. People are hired now to hack companies to assess their security. Like you see this every day. There's a lot of episodes that you covered already about like this, like, you know, companies that they hired people to do like penetration testing and their physical security and all those things.
16:05This was unthinkable back then, I think. There are so many good articles on FRAC. I think the, you know, the NMAP one, the port scanning, the art of port scanning from issue 51 by Fjodor, which followed the release of the NMAP tool. NMAP was the grandfather of all port scanners out there. Oh, wow. Yeah. NMAP is the de facto tool, almost a standard for how we do port scanning today. It's a super simple command line tool. And the person who made NMAP published how to effectively port scan using the tool on FRAC.
16:39And that taught millions of people how to port scan. Even today, NMAP is still highly used by just about everyone in cybersecurity. And there's another article on FRAC, which goes into detail of how to do GPS jamming. I like that this article is in there because it shows that GPS jamming is not really cybersecurity. But it is GPS in itself is a technology that everybody uses and that nobody ever really thought about how vulnerable it is.
17:09And because it is already a weak, a very weak signal coming from the satellites, of course, you can jam it. But it was not apparent to everybody until we released the article. And then you could buy jammers, you know, two years later, you could jammers all over the place from China and whatnot for very low money. But it was FRAC first who released that article and got this idea out there that, hey, GPS is actually very easy to jam. No one ever thought about that. That's a good point. I don't always know where the line is on whether something is a cybersecurity problem or not.
17:42I published an episode recently about a credit card skimmer. And a lot of you complained and said that episode had nothing to do with cybersecurity. And it made me wonder, okay, well, if it's not a cybersecurity problem, whose problem is it? I mean, if you've got articles on FRAC, a hacker magazine that shows you how to exploit a technology and compromise the integrity of it, then maybe that is a cybersecurity problem. And, of course, we had the Hackers' Manifesto article as far from 1986. For me, this is the most significant article in all of FRAC, just because it sets out the baseline and the conduct, how hackers should behave and what hackers should do and should not do and how we think.
18:25Oh, yeah. I told you about the Hacker Manifesto in one of the previous episodes. One of the Legion of Doom members wrote it and published it first on FRAC. And I'll give you a short excerpt from it. I'm reading from FRAC here. This is our world now. The world of the electron and the switch. The beauty of the bod. We explore and you call us criminals. We seek after knowledge and you call us criminals. We exist without skin color, without nationality, without religious bias. And you call us criminals? You build atomic bombs. You wage wars. You murder.
18:55You cheat and lie to us and try to make us believe it's for our own good. Yet we're the criminals? Yes, I am a criminal. My crime is that of curiosity. My crime is that of judging people by what they say and think, not what they look like. I am a hacker. And this is my manifesto. You may stop this individual, but you cannot stop us all. After all, we're all alike. Yeah, these things are still valid today. Maybe perhaps even more valid today than they were back then. That we are all equal.
19:27That we don't care about skin color, religion, our nationality. And, you know, a lot of criminals forget this. And that's why they are criminals. They are not hackers. If you hack for a nation, you're not a hacker. You're actually more concerned about your nationality than about the hacker manifesto, where we don't care about that. We only care about skills. Correct. Yeah, I wrote a little bit about it in the last FRAC, FRAC72. We're going to take a quick ad break here, but stay with us. Because when we get back, we're going to get into my favorite FRAC stories.
19:59This episode is sponsored by Arctic Wolf. Everyone is slapping AI-powered on their security tools. But Arctic Wolf took a different approach. Instead of duct-taping AI onto the SOC, they rebuilt the SOC around AI and called it the Aurora Super Intelligence Platform. If you ever tried to build your own AI pipeline, you know the pain. Data engineering, model tuning, governance, validation. Aurora removes all of it. You deploy it and instantly inherit the intelligence, guardrails, and operational maturity of one
20:31of the world's largest agentic SOC. Under the hood, Aurora is running a fully agentic architecture they call the Swarm of Experts. These agents are battle-tested inside the world's largest commercial SOC and only ship when they can outperform human-only workflows. And its integration is seamless as Aurora works within Arctic Wolf's concierge experience, allowing your security team to focus on higher value strategy and proactive risk reduction. If you want to see what a real trustworthy agent-led SOC looks like, not the marketing slide version, go to arcticwolf.com slash darknet.
21:05That's arcticwolf.com slash darknet.
Reviving Phrak in the year 2000
21:09The first issue of FRAC was published in 1985, before websites were popular. So it was just hosted on a BBS, and you had to, like, use your home phone and dial into it and read it that way. And they wanted the articles to spread, so they encouraged people to mirror it on other people's BBSs in other towns. But eventually, when websites became popular, FRAC moved to FRAC.com. And that became its new home. But it didn't stay that way.
21:39I think FRAC.com got hacked at least once. The web server was often down, not reachable. Somewhere around 1998, FRAC.com went offline. It stopped publishing articles for two years and was down most of the time. I should also mention that FRAC changed owners quite a bit. The original founders went off and did something else. New people came in, and they were doing stuff, but it's a free magazine, and they never tried to make money. So it relied on volunteers to keep it going, and they could only spend so many years of
22:11their lives before going off and doing something else. By 2000, the site looked dead. The website had been mostly offline for the past few years, and no new articles for two years. And at that point, it was ran by Mike Schiffman, aka Rout. But Skyper wasn't involved at all, and Mike didn't even know who Skyper was. But Skyper had a plan. He wanted to revive FRAC and needed to do something epic to prove his worthiness. And so I decided to steal a domain, which was frac.org, which back then was not owned
22:47by the FRAC staff. It was owned by somebody who probably didn't even know about FRAC. How did you steal a domain? Well, luckily, in the olden days, these things were rather easy. You would go to the domain registrar, and this example was a French one, Gandhi.net, and you would initiate a domain transfer, and it would ask you that you need the authorization code to transfer it. And you would right-click on the web page and save a few source code of the web page, and
23:17the authorization code would be written there in a hidden HTML tag, in a form tag. And that was all you needed back then to do hacking. Wow. So just by looking at the view source of a website, it would show you the authorization code that it was expecting in order to prove that you're the owner of the site. I mean, it has to compare the authorization code you type in with something, right? So there's some logic on the back end somewhere. It just happened to be right there in the source code of the site. It was as simple as just doing view source. And then you could take over anyone's domain.
23:49But you also have to put this into perspective. Back then, not many browsers had a feature to actually view the source code. So Skyper had frack.org and wanted to use it to revive frack.com. But he wasn't doing this alone. He actually was involved with a few hacking groups, specifically HERT and Tesso. So HERT stands for the Hackers Emergency Response Team. And HERT was founded around the same time when the CERTs were founded, the Computer Emergency Response Team. And it was meant to be a counterweight to the CERT because the community felt that often the
24:26CERT, the Computer Emergency Response Team, didn't really know what they were doing. And the publications were often not technically correct. And so the community created the Hackers Emergency Response Team, where the hackers published their version of the vulnerability and their exploits and their assessment of the risk. And yeah, that was what HERT was. And Tesso was a German slash Austrian hacker group who later became more internationally and
24:59went by the name of Team Tesso. So with frack.org in hand and with Tesso and HERT behind him, Skyper got busy recreating the site to show he can manage a website like that. And then I spent many days and many nights to recreate all the articles. I put them in an SQL database so it was searchable and copied all the data. I created the webpage and then put it online and then called Mike Schiffman, who was the editor-in-chief back then. I caught him doing breakfast.
25:30He was literally saying, I'm just having breakfast, but what you're saying sounds great, so let's do it. There was no hesitation. And it was a combination of people from Tesso and HERT who took over the FRAC magazine in 2000 or revived the FRAC magazine in the year 2000. So Skyper was now in control of FRAC and it officially moved from FRAC.com to FRAC.org, which is where it remains today. And it was a whole new fresh team. Nobody from the old FRAC staff was around to write any articles or to help.
26:02So this new team got busy with a fresh new issue, issue 57. Yeah, well, the first one already was the first hardcover release ever. So we decided we want to land with a big bang and decided for our very first release, not just are we going to write all the articles ourselves, we also create the first hardcover release, which we released at a hack conference, a physical copy. So in 2001 was the first time FRAC had a hard copy created, elevating it to the next level. It was fantastic. It was a fantastic success. I think we printed 800 hard copies or so.
26:35We all picked them up with a car, with a rented car. And these hard copies are heavy. We picked them up in the printer in Netherlands and the car almost crashed with all the load in the trunk on the back seats. We drove to the conference and went to the main tent and announced that I'm going to distribute FRAC in half an hour. And we had a great party and handed out the magazines and lots of alcohol and celebrating and talking about it.
27:07It was a fantastic time.
The anti-security movement and internal conflict
27:09So hackers trying to hack a hacker website is always going to be a thing. And FRAC.org had its fair share of attacks. And there was a group that particularly was trying to take down FRAC. And they called themselves the FRAC High Council or PHC. Yeah, around that time there was a movement called the anti-security movement.
27:31And it was around the time when hacking really got commercialized. And many, many, many companies entered the community and started to sell cybersecurity technology. And hackers would start working for these companies and they would sell the secrets that they did not research and did not discover, but that were given to them by the community. And they were making lots of money from it. And the community was not very happy about that because effectively these people stole from the community.
28:06And so a movement emerged called the anti-security movement, which basically said, well, that's not okay. We can't do that. And out of that, the PHC materialized and they were probably, let's call them the radical form of anti-security movement. They would do a witch hunt and they would try to hunt down every hacker who would work for corporate. I call it hacker cannibalism, where hackers ate other hackers and destroyed other hackers, often unfairly and unjustified.
28:42It was really a witch hunt. And that went on for some time and PHC then tried to take over FRAC because they were not happy with the editorial staff who was running FRAC. Of course, they tried to hack into the servers and things that you would do, but they also tried to steal articles or send out call for papers and pretending that they were FRAC. But they never owned the domain. Oh, how interesting. They tried to pretend to be FRAC by publishing lookalike articles that pretended to expose secrets, but they weren't actually secrets.
29:15A little war was breaking out between the corporate cybersecurity culture and the underground hacker culture. The FRAC High Council thought if FRAC publishes articles on how to hack, that'll be used by corporations to make money. So therefore, don't publish any articles at all or publish articles that would be detrimental to the cybersecurity professionals out there who are trying to profit from it. Yeah, they wanted to keep all the secrets among themselves and so that only they can use them. It's very selfish. And it's also counterproductive.
29:47In an intellectual society, you need to share your ideas to inspire other people. And for other people also to verify your ideas and to take your ideas further to the next step. Otherwise, it's a stagnation and you won't go anywhere. Okay, so they tried to publish an article as FRAC, just posing as them. What else? They actually stole some of the pre-release of FRAC. And so what happened is that the FRAC staff always releases the upcoming FRAC release to the community, to some trusted friends.
30:22And then after it's released to trusted friends, then it's released to some lesser trusted friends and so on and so on. And after a few days, it ended up before the official webpage release in the hands of a PHC guy. So this PHC guy knows that we haven't released it publicly yet, but it's still a community release only. And he modifies the FRAC articles, puts some backdoors in there, and then publishes on his webpage, the PHC webpage, as a new FRAC release.
30:53And these backdoors, they were not even clever backdoors. They were just very destructive backdoors. They would delete your entire computer. Wow. So have you ever looked up a tutorial online and it had some script or code or something, and that's what you needed to do? That's the command you were looking for? And so you just copy and paste it into your computer, but you don't actually know what it does? Yeah, well, if you would have tried to copy and paste this script, it had the command RM-RF, which would delete your whole hard drive. How funny is that?
31:23Obviously, FRAC staff didn't put that destructive command in their magazine, but that version of the article still existed out there somewhere. Skyper and his team had brought FRAC back. They were publishing yearly issues of FRAC. But then Skyper moved on to do other things, but there was enough momentum and there was enough people involved with FRAC at that point for it to keep going on its own. But it was slow going. Yearly issues turned into every other year issues, and then sometimes there'd be four years between issues. And in 2016, it seemed like that was the last issue of FRAC.
31:58FRAC staff just wasn't there anymore, and there were no issues coming out. But five years after that, in 2021, to all our surprise, a new issue of FRAC was released. We thought it was dead, but we were super happy to see a new issue. And I remember hearing people at DEF CON tell me that year that they used an exploit that they saw in that new issue of FRAC to make a bunch of money on bug bounties that year. So it still had teeth and grit and was hard-hitting, well, at least until things got patched.
Passing the torch to Tempout
32:26But that seemed to be the last hurrah for FRAC. The internal FRAC staff just sort of fizzled out. There wasn't support much for it. The people were just very loosely involved at that point. And they decided to get together in 2023 to discuss the future of FRAC. And we actually met in Spain to discuss a bit the future about FRAC. And we decided that's not just for two or three people to decide that we should really ask Mike Schiffman again and some of the old staffers and previous staffers what their opinion is.
32:59And then eventually we had a big phone call with maybe six or eight people of the old staff and new staff on there. And we discussed what we should do. And there were various options. Some people said, hey, let's do one more FRAC and let's just call it. That's it, you know, the last FRAC. And then other people said, no, we can't even do that. The community is dead. And most importantly, there were the very few of us who said, no, no, the community is always there.
33:30There is still a community that deserves a magazine like this. There's always curiosity out there and always the need for people to publish articles. And we have to provide a platform for them so they can do it. And FRAC is the perfect platform for these articles. So we were brainstorming about who we could contact out there, who has experience with running a magazine, who would enjoy running a magazine, and who is also technically skilled. Because, you know, FRAC in the end is a very technical magazine.
34:02So the group that came to our minds were the people who were running already Temp Out magazine. Temp Out is very similar to FRAC. It's an e-zine which posts articles on hacking. It has its own edginess to it. Like, there's a bunch of ASCII art and hard-hitting articles. And it was TMZ here who co-founded Temp Out. So Temp Out is a group that is a research group that we formed maybe five years ago now. We started in RSTs with three people. We just wanted to, like, research ELF, infection techniques, so Linux viruses and things like this.
34:38We thought it was, like, a very niche area that we had, like, people in common that wanted to do that. And so we kind of, you know, brainstormed a little bit. And then more people were joining, and then eventually we had, like, a Discord channel. There's, like, 1,500 people there now. And suddenly, you know, the community was like, okay, what if we make, like, a zine, you know? Like, in the old days, people were like, oh, yeah, I want to write the script or whatever. So we just gave it a go, like, and we made four volumes already of it so far.
35:11And it's been, like, really, really nice. And we contacted them, and we had a phone call together, and the rest is history. I was honestly, like, speechless when that happened. Like, I was very, very anxious. I remember that I was on vacation, and I just ran to the – I was actually about to catch a flight. So I just, like, found, like, the quietest corner of the airport lounge that I could find and had the call with them.
35:41And took notes of everything. Essentially, like, the idea was, like, okay, if you wanted to give it a go, you know, trust you with that. The former staff also was saying, like, okay, we maybe should, you know, do something different this time. Like, make FRAC, like, well-known again.
36:00The Tempout team had already established themselves as a group who was technical, smart, and could ship articles. And immediately got busy reviving FRAC. Once again, I had no idea that the teams behind FRAC have shifted so much throughout the 40 years. But when it's volunteer-driven, I suppose that's what happens. So the Tempout team was excited to be taking over FRAC and wanted to make their first issue a big one. It was 2023. And in the seven years before that, there had only been one FRAC issue released. So a lot of people just thought it was dead.
36:30But to show them that it wasn't dead, they wanted to make a physical copy and release it at DEF CON. Yeah, we just thought, actually, about doing only an online release. We didn't really thought about actually doing a physical release last year until kind of late in the process. And then we were just like, okay, what if we do it? You know, can we do it? Do we have, like, some budget? Can we, like, talk to some people? So we were able to raise some funds and we were able to get, like, 500 copies down to Vegas.
37:03Yeah, it was a very interesting first experience on logistics because, you know, releasing a physical copy of things, it's not as easy as it sounds. Like, not only, like, you have to actually make the material, but, you know, the distribution, especially at DEF CON. Wow. Okay, so last year, you actually reached out to me to, you were looking for a place to spread them or give them out. Yeah, yeah, yeah, yeah. So we had a few of them downstairs, right? And then we were just like, yeah, sure.
37:34But we kind of wanted, like, a place more centralized for that. And that was very nice to get some of the copies there at the party, at the Dark Nerd artist party. People really liked it. And I remember, like, a lot of people were so happy. And I think that's what made me feel, like, very realized. That's why I was, like, a lot of people, they looked at it and they looked at it as the most precious thing that I ever touched. Like, you know, they say, yeah, I'm here and I like what I do now because of FRAC, like, 25 years ago, 30 years ago. So, you know, that's really, like, very, very nice to hear.
38:08It was a special moment for me. I mean, the fact that the FRAC staff came in and started handing out FRAC magazines at my party was, I felt like, man, this is special. This is cool. I did, I feel honored to have been one of the places to spread it because I think you only even pick, like, three or four places to spread out the magazines there. Yeah, correct. And thank you for having us. It was really good. I cherish my copy that I got from you. I wish I got it signed. And as soon as I left that night, I was like, oh, no, how did I not get it signed by you?
38:41But, yeah, that feels like a very special book to own. It's more of a book. It's in my hand here. And, my gosh, this thing is heavy. So, FRAC 71, I'm just looking through it. It's very text. There's hardly any pictures at all. And I guess that's because you were saying, you know, we weren't even thinking about printing it. And then when you finally got around to printing it, it's like, okay, well, we'll just print the articles.
39:05Yeah. So, editing this is already hard, you know, for somebody that doesn't have, like, you know, that doesn't work with it, I guess.
39:12But we also, like, okay, we keep the style, right? Like, that's what the first thought, like, also. So, it's easier because it's, you know, less editing. But also, like, which is already pretty hard. But, you know, we keep the plain text style, which a lot of people relate to and really, really like. So, Tempout proved themselves to be able to ship an issue of FRAC. Great.
Celebrating the 40th anniversary edition
39:35But FRAC started in 1985. So, with 2025 coming, it would mark the 40th anniversary of FRAC, which got a lot of people excited to pitch in and help make a great new issue. At FRAC 72, because it's marked our 40th anniversary, we all wanted to make something very special. So, we, the initial idea was to go back to the Netherlands to release the magazine there again as a hard copy, where we released the first hard copy 24 years before. But we got enough funding and we got enough community support to then be able to coordinate a release at three different conferences at the same time, which was in Netherlands and at DEF CON in Las Vegas and at HOPE in New York City.
40:24And then very smaller conferences all around the world. So, that was beautiful how the community came together and everybody chipped in some dollars and helped us. The one that I have actually has a DEF CON special edition written on the cover. So, were there multiple covers? Yes, we have three different covers. Actually, four. One of them is going to be released later this year. I'd like to add something there. When TMZ says there are four covers, three that are already released, and one of them that will be released at the end of the year, it's because we're going to release the PDF online for everybody to print it at home or print it on a professional print shop and get it shipped to their home address.
41:08So, FRAC issue 72 was released at DEF CON in 2025, and I was there to get a copy of it. Yeah, this year we turned it up a notch. This year we didn't show up with 500 copies. We turned up with close to 8,000 copies at DEF CON. Most, if not all, articles of FRAC are simply text files. There are no visuals or graphics at all. Well, I should say you can see some ASCII art there, but that's just still text in the shape of a picture. But this 40th anniversary edition, man, does it pop. Every page has a graphic on it, and it's really cool.
41:40It feels like a high-quality magazine at this point, and it's bulky and has a ton of articles in it. Yeah, so we got the opportunity to have the wonderful people from Paged Out, which is another magazine as well, to do the graphics for us. I mean, as you know, because you saw it already, it's mind-blowing. The quality is so, so good. And I remember when I got the confirmation that they would do it, I was so relieved that I didn't have to do it myself.
42:12Because one, I mean, I know that it's hard for me because I'm not an expert on this. And second, I would never be able to match this quality or nobody, at least that it's in the current staff. And they just, like, it's just incredible. And I think, like, FRAC never looked that good. Yeah. It looks great. Yeah. It feels like you're coming of age, but even 40 years later, and it's, like, looking great. I like that. That makes me excited about the future.
42:43Getting it, you said 8,000 copies to DEF CON? Yeah. We had, I think, around 15,000 copies spread amongst those three conferences. Yeah. I mean, gosh, how much does that even weigh? How do you even get that to DEF CON?
43:02It's part of the problem as well. First, to solve these issues, we tried to find, like, local printers, right? And it is very, very challenging because the transportation is very costly. So, we found a Vegas printer, and I think for DEF CON, that was 10 tons or something? 10 tons. Of paper? Wow. Yeah. Yeah. So, the logistical issue is that you don't only have to deliver it by truck to DEF CON. You also need manpower on the ground to hand-carry 10 tons from the loading bay to the registration desk.
43:40So, all these little details we had to learn and figure out. It was great to see FRAC all over the place at DEF CON this year. People were showing me how excited they were when they got their copy. Some got it signed by the FRAC staff. Some had me sign it for some reason. It was a wonderful time. But what surprised me is that this is such a high-quality magazine, but then thousands of them were given out to everyone just for free? FRAC is for the community always. It's always free. So, if somebody tries to sell you a FRAC, you know that it's not from us.
44:15So, you're never going to charge for these things? We're never going to charge. No, no. It's so cool having… People are welcome to help us in any way, right? The community is there for this. People can help us with article reviews, with art as well. And the people did, which is very, very nice to see. Like, these years, there's a lot of people involved. You know, the artists that design the covers, for example, as well. So, there's several ways that people can help us make this happen. And we do it for them, and they do it for the community as well.
44:48So, it's impressive that you're able to make it happen and have such a high-quality print magazine here. I mean, this thing is like 100 pages long. It needs to be said that, of course, this thing costs money to print. The printer still wants to be paid. He doesn't do a favor for FRAC. And so, the Defcon print in its own was about $55,000. So, this is still money that we had to raise from the community.
45:19But good thing is that many of our friends who were doing FRAC with us in the year 2000 and 2001 and who were reading FRAC with us and who were writing articles for us, now, 24 years later, they have all made their fortunes. They're running big companies. Some of them are traded on the stock exchange. So, these people came back to us, and they were happy to support us financially and help us with this immense cost. The magazine that launched 10,000 cybersecurity careers, huh?
45:53Exactly.
The future of the magazine
45:55Well, so that's where we're at today, 40th anniversary. Well, congrats on 40 years of running a thing or keeping it going. And it's so fascinating that it's community-driven, almost like Dread Pirate Roberts, right? His name lives on, but it's not always the same person that lives on, right? And so, FRAC continues to live on because the community keeps it going. And the community is as strong as ever now. And I think it's going to grow even further. Yeah. Tell us about the future. Yeah. So, I think we really want to keep the community growing.
46:28We want to get a little bit better. So, every time we do a release, we learn a lot about everything, right? Logistics and article reviewings and, you know, project management and all those things. So, we're not experts on this. We also, like, have, you know, our day jobs and all those things.
46:46So, we're learning as we go as well. And the community, I think, we want to grow and have, like, more people involved to help us. We have a lot of people that sometimes they say, yeah, I don't have time to write an article this year or something like this. But, you know, they do have spare time to, like, help with article reviews. So, for example, this is already, like, a very, very good help. I think in the future, we want to get more people involved. Like, if you want to say, like, in a very brief way, we want, like, to be accessible.
47:18Okay. So, I got a physical copy, but that's just because I happen to be at the right time and right place. Is there a way to get a physical copy by ordering it? Yes. Like, last year, we made it available for self-print at cost, obviously, so we don't profit. And, of course, you can print anywhere you want. We have, like, just a recommended printer, whatever. It doesn't really matter because we released the full high-quality PDF as well. So, you can print and edit if you want at your own local print shop. And this year is going to be the same. FRAC is currently looking for new articles for their upcoming issue.
47:49If you've got a new hacking technique or are thinking of researching a specific technology or protocol, reach out to the FRAC staff with your draft or even just an idea. They are very helpful at giving you feedback to help you draft a great article. Even if your English is not very good, they can help co-author the article with you. And, of course, you can still read every issue of FRAC free of charge at frac.org. Here's to another 40 years of an awesome hacker magazine. A big thank you to Skyper and TMZ for coming on the show and sharing the history and stories of FRAC.
48:32It really is looking better than ever, and I can't wait to see what they make next. In the show notes, you'll find links to where you can order a physical copy of Issue 72 or just download the PDF and print it at home. This show is made by me, the Packet Tickler, Jack Recider. Editing by the Control-Alt Delight, Tristan Ledger. Mixing by Proximity Sound and our theme music is by the Mysterious Breakmaster Cylinder. I named my dog, Regex. Because nobody understands him. Not even me. This is Darknet Diaries. This is Darknet Diaries.