news2mail.com

HomeNl › Comp

nl.comp.hacken

Dutch-language group on hacking and computer security.

nl.comp.hacken covered security in the Dutch scene of the 1990s and 2000s — vulnerability talk, phreaking history, and the hacker-culture current that produced XS4ALL and the Dutch hacker camps.

Posts ran in Dutch; the group is cited by histories of the Netherlands’ unusually influential hacker community.

Long-form reference · 7,874 words · about a 34-minute read

The group's own paperwork

Almost nothing survives of what was said in nl.comp.hacken. A great deal survives of how it came to exist, because the nl.* hierarchy conducts its administration by signed control message and those messages are archived. The file for this group at the Internet Systems Consortium contains ten articles, all of them sent from the hierarchy's administrative address and all of them PGP-signed: five identical newgroup messages dated 13, 16, 20 and 27 January and 10 February 2004, and five identical rmgroup messages dated 26 and 29 September and 3, 10 and 24 October 2011. Between those two dates lies the whole documented life of the group — seven years and eight months, from a Tuesday in January to a Monday in September.

The newgroup message is not a bare instruction. It opens by stating that nl.comp.hacken is an unmoderated newsgroup, then says that the administration wishes to advise creating it, and then supplies the line that news administrators were to paste into their own newsgroups file. That line, which is the group's official one-sentence description and the only text about it that ever appeared in the hierarchy's canonical list, reads in full:

nl.comp.hacken Discussies over hacken.

Discussions about hacking. Three words of Dutch, one of them a naturalised English verb, well inside the fifty-five characters the hierarchy allowed itself for a description. The group's name is that same verb: hacken, to hack, conjugated and spelled as ordinary Dutch, in a hierarchy whose other computing groups are called things like nl.comp.netwerken and nl.comp.programmeren.

The message then prints the group's provenance, which is the interesting part. A Request For Discussion was opened on 7 September 2003. A Call For Votes followed on 7 December 2003 — and, on the same day, a second Call For Votes was opened by mistake for a group called nl.comp.hack, an error the administration recorded rather than quietly corrected, using the adverb abusievelijk. The result was posted on 4 January 2004. The tally, reproduced in every one of the five newgroup articles, was 84 votes in favour, 9 against, 1 abstention and 5 invalid; a net majority of 75; ninety per cent in favour. The message closes that section with a sentence of institutional deadpan: De nieuwsgroep voldoet aan de eisen — the newsgroup meets the requirements — followed by its own English gloss, It has come up to the requirements.

It is worth doing the arithmetic against the rule, because this is one of the few Usenet groups whose paperwork lets a reader check the sum. The Dutch guidelines of the period required a net majority of at least fifty votes and at least twice as many in favour as against. Eighty-four minus nine is seventy-five, comfortably over the first threshold; and eighty-four in favour to nine against is a ratio of more than nine to one, where two to one was what the rule asked. The proposal was not close, and the administration's own summary says so in the flattest available language. Readers who want the hierarchy's procedure in full — the mentors, the thirty days, the two independent voting bureaux, the five-day objection window — will find it set out on the nl.* hub page, which owns that story; what matters here is that this group went through all of it and passed.

The removal messages of 2011 are shorter and more bureaucratic still. Each states a reason for removal in Dutch and English — Volgens de gebruikelijke afspraken wordt de volgende nieuwsgroep nu opgeheven, it is common practice to remove the following newsgroup now — names the group in square brackets, records that it was created on 13-01-2004, and concludes that nl.comp.hacken no longer belongs to the nl hierarchy. No further ground is given, and the closing note gives the administrator's distribution address as [email protected], where the newgroup messages of 2004 had given [email protected]. The group went out in a batch: the hierarchy's control log shows twenty-nine nl.* groups removed on the same day, among them groups for architecture, volleyball, darts, running and cryptography. Nothing in the message distinguishes this group from the other twenty-eight.

The consequence is visible in the current administrative files. The Internet Systems Consortium's active file lists twenty-one groups under nl.comp — nl.comp.hardware, nl.comp.netwerken, nl.comp.os.unix, nl.comp.virus and the rest — each carrying the status flag y, meaning unmoderated and open to posting. There is no line for nl.comp.hacken, and the hierarchy's periodic checkgroups message no longer names it. The address this page preserves is, in the strictest administrative sense, no longer an address.

The charter, and what it ruled out

The newgroup message carries the charter in full, between two rules of equals signs. It is short, and it divides cleanly into what the group was for and what it refused. The first half:

Deze groep dient voor discussies over hacken. Dit kan bijvoorbeeld gaan over ethiek, techniek, meetings of hackerscultuur. Ook discussies over aanverwante onderwerpen als computerbeveiliging, virusschrijven, coden, lockpicking en phreaken zijn on-topic, evenals de ethiek daaromtrent.

This group is for discussions about hacking; that can cover, for instance, ethics, technique, meetings or hacker culture; discussion of related subjects such as computer security, virus writing, coding, lockpicking and phreaking is also on topic, as is the ethics of those. Two things are worth noticing before the content. The first is the order: ethics leads, technique is second, and meetings — the camps and gatherings — comes before culture. The second is the language. A charter of forty-odd Dutch words contains on-topic, lockpicking, meetings and phreaken, the last of these an English noun given a Dutch infinitive ending. Any assumption that traffic in this group ran in Dutch thickly seasoned with English jargon does not need to be assumed; the group's own founding document does it.

The second half is a list of exclusions, and it is unusually specific for a Usenet charter:

Off-topic en zeer ongewenst zijn verzoeken om bepaalde sites aan te vallen en discussies over het cracken van accounts van vrienden of vriendinnen en meer van dat soort illegale praktijken. Ook vragen over cracken van software, serials, trojans en posten van IP-adressen met logingegevens zijn ongewenst en off-topic.

Off topic and highly unwelcome: requests to attack particular sites; discussion of cracking the accounts of friends or girlfriends and more of that sort of illegal practice; questions about cracking software, serial numbers and trojans; and the posting of IP addresses together with login credentials. The phrase zeer ongewenst, very undesirable, is doing work that off-topic alone would not: the charter is not merely allocating subjects between groups, it is declining a category of request.

That the exclusions had to be written down at all is itself a piece of evidence about what the proponents expected to receive, and it places the group precisely. Software cracking, serial numbers and the trade in them belonged to an entirely different quarter of Usenet — this directory's page on alt.new.cracks covers that subject and its legal history — and the nl.comp.hacken charter pushed it out of the door in a single clause. A charter, it should be said, is a statement of intent and not a description of behaviour; no charter on Usenet was ever self-enforcing, and an unmoderated group had no mechanism to enforce one beyond the social. What a charter does establish, reliably, is what the people who proposed a group told the hierarchy it was for, at a moment when ninety per cent of the voters agreed with them.

A group founded eleven years after the watershed

The dating deserves stating plainly, because the group's subject and the group's calendar do not coincide, and the discrepancy is easy to get wrong. The Dutch hacker scene that gives this address its interest was formed in the late 1980s and early 1990s: a magazine from 1989, a conference from 1989, a legal vacuum that closed in 1993, an internet provider from 1993, a public digital city from 1994. nl.comp.hacken existed from January 2004 to September 2011. It did not carry any of that as news. It carried it as history — recent history, argued over by people who had been present for a good deal of it, but history nonetheless.

By the time the first article could be posted here, the Wet computercriminaliteit was eleven years old, the intrusion offence it created was settled law, and the second round of Dutch computer-crime legislation was already before parliament. The Convention on Cybercrime had been open for signature for over two years. The quadrennial camp series was on its fourth edition. XS4ALL had been a subsidiary of the national telephone incumbent for five years. Whatever else nl.comp.hacken was, it was not a group that watched the law being written. Its readers could remember that period; the group could not have reported it.

This matters for how the page should be read. Where the sections below describe the 1980s and 1990s, they are describing the world the group's subject came from, verifiably and with dates, not events the group covered as they happened. Where they describe the 2000s, they are describing the group's own decade — a decade in which Dutch hacking was a settled legal category, an established set of institutions and a four-yearly festival, rather than an open question.

There is a second and smaller correction to record. The nl.* hierarchy is sometimes described as having moved away from formal ballots in favour of administrators consulting the community and deciding, and there is something to that as a general trend. It is not what happened here. This group was created by a full Request For Discussion, a Call For Votes, an independently counted ballot and a published tally, in the winter of 2003. The paperwork is unambiguous, and it is more recent than the trend it is supposed to illustrate.

Hacker, kraker, cracker

The argument over what to call people who enter computers without permission is the oldest recurring subject in every group of this kind, and it arrived in Dutch with an extra layer, because Dutch already had its own word. To break something open is kraken. The person who does it to a computer is a kraker or, unambiguously, a computerkraker; the Dutch encyclopaedic definition of that term glosses it directly as the jargon cracker, and treats it as a borrowing from the hacker community's own vocabulary rather than from journalism. In the Netherlands and Belgium the act it names is a form of computer crime, punishable as computervredebreuk.

That third word is the most revealing of the set, and it is a legal coinage rather than a subcultural one. Computervredebreuk is formed by analogy with huisvredebreuk, the older offence of breaking the peace of a dwelling by entering it unbidden. The Dutch legislature, asked to name a new offence in 1993, reached for the vocabulary of trespass rather than the vocabulary of theft, and German law reached the same way: commentary on the German provision against the spying-out of data describes it as the general penal provision against an electronic Hausfriedensbruch. Whatever the scene thought a computer was, the statute decided it was a kind of room.

The international dispute, which nl.comp.hacken inherited along with the vocabulary, was already old by 2004 and had published positions on both sides. The Jargon File, the hacker subculture's own compiled dictionary, dates the term cracker to about 1985 and describes it as coined by hackers in defence against journalistic misuse of hacker. The clearest dated statement of the distinction, though, is not a subcultural document at all: it is RFC 1392, the Internet Users' Glossary, published in January 1993, two months before the Dutch statute came into force. Its entry for hacker reads:

A person who delights in having an intimate understanding of the internal workings of a system, computers and computer networks in particular. The term is often misused in a pejorative context, where "cracker" would be the correct term.

And its entry for cracker:

A cracker is an individual who attempts to access computer systems without authorization. These individuals are often malicious, as opposed to hackers, and have many means at their disposal for breaking into a system.

That is the scene's position, restated in the most institutional venue available to it. Later the argument fragmented rather than resolving: the computer underground largely declined to accept the hacker-versus-cracker dichotomy at all and substituted a spectrum — white hat, grey hat, black hat, script kiddie — reserving cracker for the more damaging end of it, and the compilers of the dictionary rejected that reframing in turn. An account of the word's history published in 2014 recorded that the black-hat meaning still prevailed among the general public.

General Dutch usage certainly never followed. The standard dictionary of the language, Van Dale, defines a hacker as someone who breaks into a computer to obtain or alter data, usually with the aim of demonstrating its weak points. That definition flattens exactly the distinction the scene insisted on — a hacker, here, is by definition an intruder — while retaining the demonstrative motive the scene claimed for itself, which is a curious halfway house and probably an accurate reflection of how the Dutch press had been writing about the subject since the 1980s. The comparison the Dutch encyclopaedia draws is with the American dictionary treatment, which retains the intrusion and drops the motive altogether.

Underneath the terminology sat a claim about what the scene was, and the claim was not merely defensive. Its members could point to what the same milieu had built — a magazine, an internet provider, a free public digital city, a four-yearly festival — while the criminal code had begun, from 1993, to describe a set of acts in which some of the same people had been involved. The dispute was never settled in this group, and is not settled now. What a page like this can record is that it was conducted in Dutch, in a group whose charter listed ethics before technique, by people with a considerable stake in the answer.

The other kraker: a housing movement with the same verb

The coincidence is worth documenting because it is a genuine fact about the Dutch language and not a metaphor invented for this page. The Dutch disambiguation for kraken lists, under the sense of breaking or forcing open, two entries side by side: the computerkraker, someone who breaks into a computer, and kraken in the property sense — taking unused premises, buildings, sites or houseboats into use without the permission of those entitled to them. In ordinary Dutch of the period, a kraker was overwhelmingly the second thing: in Amsterdam in the 1980s the everyday referent of the word was the housing movement rather than the computer.

That movement is well documented. Squatting in the Netherlands in the modern sense began in the 1960s and had become, by the 1980s, a powerful anarchist social movement in regular conflict with the state, most visibly in Amsterdam in the Vondelstraat confrontations and the coronation riots of 1980. Its legal footing came from two Supreme Court decisions that a reader of the previous section will recognise. The first, from 1914, held that showing residential use of a property required no more than a chair, a table and a bed. The second, from 1971, held that the concept of huisvrede — domestic peace — required the permission of the current occupant before anyone else might enter, with the consequence that owners had to evict through the courts rather than by forcing the door.

Black-and-white night photograph of a crowded Amsterdam street with tram rails, torn-up paving stones piled in the road and a mechanical excavator standing among the crowd.
The street outside a squatted building in the Vondelstraat, Amsterdam, photographed from the Constantijn Huygensstraat by the Anefo press agency and dated 1 March 1980 by the Nationaal Archief. In ordinary Dutch of this period a kraker was a squatter; the same verb, kraken, supplied the word for someone who broke into a computer, and the offence created in 1993 was named by analogy with the older offence of breaking the peace of a dwelling. Rob Bogaerts for Anefo · public domain · via Wikimedia Commons.

So the same noun, vrede, and the same statutory instinct about entering a space someone else is in, sat at the foundation of both careers of the word. The 1971 ruling gave Dutch squatters a defence built on domestic peace; the 1993 statute gave Dutch computer users an offence built on its analogy. This is a fact about legal vocabulary, and it should not be inflated into a claim about people: the sources consulted for this page establish no organisational continuity between the housing movement and the computer scene, and this article asserts none.

The subsequent legal history of the housing sense runs in parallel and, on the whole, later. An amendment in 1987 allowed owners to take anonymous squatters to court without knowing their names. A law of 1994 made it unlawful to squat a building that had stood empty for less than a year, after which it became conventional practice for squatters to telephone the police themselves on taking a building, so that the year and the chair, table and bed could be established on the record. Squatting became a criminal offence on 1 October 2010 — seventeen years after computer intrusion did. A government report published in 2016 recorded that between October 2010 and November 2014, 529 people were arrested under the new offence in 213 separate incidents, of whom 210 were convicted and 42 acquitted.

One small artefact ties the two senses together neatly enough to be worth recording. When De Digitale Stad, Amsterdam's free public network, reached its third version and adopted a graphical interface laid out as a city of squares, shops and houses, empty houses in it could be gekraakt — squatted — by users who wanted them. The metaphor was chosen by people who knew precisely which sense of the verb their neighbours would hear first.

The law and what it changed

The single most important fact about Dutch computer law in the years this group's subject was formed is a negative one: for most of that period, entering a computer system without permission was not an offence under Dutch criminal law. There was no provision to charge. Conduct that also amounted to something else — theft, forgery, damage to property, unauthorised use of telephone service — could be prosecuted as that other thing, but intrusion as such was not a crime, because no article of the criminal code described it. That is the pre-1993 position: not tolerance, not a policy of leniency, and not a loophole in the ordinary sense, but the absence of an offence.

The Wet computercriminaliteit came into force on 1 March 1993 and closed the gap in both directions at once. It added specific offences, computervredebreuk among them, to the Wetboek van Strafrecht, the criminal code; and it added powers relating to the investigation of automated systems to the Wetboek van Strafvordering, the code of criminal procedure. The second half is as consequential as the first and is more often forgotten: the statute did not only make something punishable, it equipped the police to look for it.

The offence now stands as article 138ab of the criminal code, and it is worth reading closely because its structure explains a good deal about what could and could not be said in public afterwards. It defines the conduct as intentionally and unlawfully entering an automated work, or part of one, and then specifies four ways in which entry is in any event made out: by breaking through a security measure, by a technical intervention, by means of false signals or a false key, or by assuming a false identity. The basic maximum penalty is one year's imprisonment or a fine of the fourth category. It rises to four years where the intruder records data from the system, whether for himself or for others; where he applies the machine's processing capacity to his own ends; or where he uses the system he has entered as the starting point for a further intrusion into another.

Nineteenth-century lithographed print of a robed allegorical figure of Justice holding a book lettered Wetboek van Strafrecht 1 September 1886, with a sword and a pair of scales.
"Invoering van het nieuwe strafwetboek": a print issued with the weekly De Nederlandsche Spectator in 1886 to mark the entry into force of the Dutch criminal code on 1 September of that year. That code is the one into which computervredebreuk was inserted in 1993, drafted by analogy with huisvredebreuk, an offence it had carried from the start. Rijksmuseum · public domain · via Wikimedia Commons.

What changed for public discussion was therefore the framing rather than the vocabulary. Before March 1993 a Dutch hacker could describe an intrusion as a demonstration and be describing, in law, nothing punishable. Afterwards the same description was an account of an offence, and everything said about it in public — in a magazine, from a podium, in a newsgroup — stood in a different relation to the police. When the charter written in 2003 rules requests to attack particular sites off topic and very undesirable, it is not being squeamish; it is being drafted a decade into a statutory regime.

The Netherlands was late to this by comparison with its neighbours, and the comparison is checkable. The United States had amended its computer fraud statute in 1986. The United Kingdom's Computer Misuse Act 1990 received royal assent on 29 June 1990 and commenced on 29 August 1990. The Dutch offence arrived on 1 March 1993, roughly two and a half years after the British one and seven after the American. A full European timetable is not something this page has verified, and none is offered here; the two dated comparators are enough to establish that the Dutch vacuum lasted longer than those of two comparable jurisdictions, which is the point the Dutch scene's own accounts make about it.

The later legislative history is well recorded and runs on a slow clock. Proposals to amend the 1993 act date from 1998, and a bill styled Computercriminaliteit II was laid before the lower house in 1999. Its passage was then suspended while the Council of Europe developed its Convention on Cybercrime, which was opened for signature in Budapest on 23 November 2001 and entered into force on 1 July 2004. The Netherlands signed on the opening day, 23 November 2001, ratified on 16 November 2006, and the convention entered into force for the Netherlands on 1 March 2007. A separate implementing bill was introduced on 22 March 2005 as an amendment to the pending Computercriminaliteit II, which the upper house passed on 30 May 2006 and which came into force, with one sub-article excepted, on 1 September 2006. A third instrument, the act of 27 June 2018 amending both codes in connection with the detection and prosecution of computer crime and known as Computercriminaliteit III, entered into force on 1 March 2019, and included the power for the police to enter computer systems themselves — a provision that attracted criticism on privacy grounds, and which arrived seven and a half years after this group was removed.

One episode of the transition was put on a conference programme while it was happening, and it is documented. At the open-air camp near Lelystad in August 1993 — five months after the statute came into force — a session on the juridification of hacking brought together the first person arrested under the new law, identified in the Dutch record only by a first name and an initial; a system administrator at the Vrije Universiteit in Amsterdam who had been involved in that arrest; computer-security specialists; and representatives of hacker groups. An officer of the national criminal intelligence service had announced that he would attend, and was stopped from doing so by his employer. At later editions of the camp the police simply came: the programme of the 2005 camp included a police village staffed with specialists from the force's information-technology department.

Two things are worth saying about how this page treats all of that. Prosecutions appear here as legal record — instruments, dates, provisions and reported outcomes — and not as narrative. No defendant is named: the Dutch record identifies the first person arrested under the 1993 act by a first name and an initial only, and this page does not go further. And nothing in this section is advice about the current state of Dutch law, which has been amended twice since the group closed.

Why the Netherlands: the structural answer

The Dutch hacker scene is disproportionately prominent in the international record for a country of its size, and the reasons offered for that are usually cultural. The checkable ones are structural, and there are four of them.

Early and dense connectivity. The Netherlands was on the international network before almost anywhere else in Europe, through the CWI in Amsterdam, whose machine mcvax had been a junction of European UUCP traffic since the early 1980s and whose administrator Piet Beertema opened its link to the American science network NSFNET on 17 November 1988, making the Netherlands one of the first two countries connected, shortly after France's INRIA. The full account of that — the machine, the domain, the several competing superlatives and what each of them actually claims — belongs to the nl.* hub page and is not retold here. The relevant consequence is narrow: by the time there was a Dutch hacker scene, the plumbing and the people who ran it were already in place, and they were not customers at the far end of somebody else's feed.

A documented university network. SURFnet, the Dutch research and education network, was established in the second half of the 1980s — 1987 by the organisation's own account, with incorporation following in January 1989 — and is run by a cooperative of Dutch educational and research institutions. Its significance for this page is administrative as well as technical: the contact address for the entire nl.* hierarchy was, and in the distributed news-server configuration files still is, an address at nic.surfnet.nl. The country's universities were on the network first, and the one documented Dutch intrusion case of 1993 — the first arrest under the new statute — involved a university system administrator.

An unusually large closed community. Selling internet access to the general public in the Netherlands was not initially permitted; access had to run through a closed user community of which one was a member. The Netherlands happened to possess an exceptionally large one. The Hobby Computer Club, founded in 1977, had tens of thousands of members, and in 1991 the subscribers of its hobbynet became the first private individuals in the country with internet access. Providers selling to private customers followed, the magazine's own access service among the earliest of them in 1993. The scale of what came next can be measured at the other end: when De Digitale Stad opened in January 1994, roughly three hundred private individuals in the whole of the Netherlands had internet access at home. When the Hack-Tic circle began selling access in 1993, it projected five hundred customers in the first year and reached that number on the first day.

A legal vacuum that lasted longer than elsewhere. This is the fourth structural factor and the one the previous section documents: no intrusion offence at all until 1 March 1993, two and a half years after the United Kingdom and seven after the United States. A scene that is not committing a crime can hold a conference in a public music venue, publish a magazine with a subscriber list, and give interviews. Dutch hacking spent its formative period doing exactly that, which is why so much of it is documented at all — and why the archive that exists is made of magazines, conference programmes and newspaper reports rather than of court files.

One item frequently offered as a fifth factor should be handled carefully. It is often said that Dutch telephony was cheap by the standards of neighbouring countries, and this page has not been able to verify it. What the record does show points the other way: Dutch telephone charging in the 1980s was metered in pulses, or tikken, generated in band on the line, with the pulse both incrementing the subscriber's counter at the exchange and driving the meter in a payphone. That is a regime in which calls cost money by the minute, and it is precisely the regime that gives phreaking — the manipulation of telephone charging, one of the named on-topic subjects of this group's charter — a readership. The confident version of the cheap-telephony claim is therefore not repeated here; what the record does support is that the charging system itself was a documented preoccupation of the Dutch hacker press.

The scene as documented history: a magazine

The printed voice of the Dutch scene was Hack-Tic, a magazine for technically minded computer users, edited and published by Rop Gonggrijp, which first appeared in 1989 and ran to 1994. Its complete run of those years remains readable online at the publication's own site. Described in the English record as having had a cult following and as having upset authorities beyond the Dutch borders, it is among the most-cited primary sources for anything about this subculture.

Its index shows the range better than any characterisation. Alongside the recurring telephone material there are articles on computer security, or more often its absence; on the internet; on bulletin board systems; on operating systems of the period — Unix, VMS, Novell NetWare, in an era before Windows was an operating system to write about; on car telephony and international networks; and on subjects that have simply stayed current, including computer crime, social engineering, and PGP, which the magazine was explaining to Dutch readers in 1991. The magazine had twenty dial-in lines of its own in 1990 and was itself part of NEABBS, the Nederlands Eerste Algemene Bulletin Board System, based in Amsterdam.

Its relationship with the state telephone company was adversarial and is documented in its own pages. The magazine's early coverage of the metered-pulse charging system, and of the devices that could be bought to generate dialling tones, produced a response from the PTT to the effect that such criminal devices were forbidden — until, in the magazine's account, the company realised it was selling one of them from its own catalogue. That anecdote is offered here as an illustration of the register in which the argument was conducted, and no technique of any kind is described on this page.

The magazine's run is indexed as 1989 to 1994, the English account placing the last issue in 1993; in 1994 the access business it had started was moved into its own foundation and given a new name, expressly chosen to shed the association with the hacker world. That is the transition the next section describes.

The camps, from 1989 onward

The other documentary spine of the scene is a conference series, and it has kept unusually good records because each edition has its own name, place and dates. The quadrennial Dutch hacker convention has recurred every four years since 1989, in different places, organised at first by the Hack-Tic circle and latterly by a foundation established for the purpose. In the years it does not fall, comparable events run in Germany and the United Kingdom.

The first was the Galactic Hacker Party, held at the Paradiso in Amsterdam from 2 to 4 August 1989, with an accompanying conference under the name ICATA, the Intercontinental Conference on Alternative Use of Technology Amsterdam; organisers and visitors treated the two as one event, and the combination is the format every subsequent edition has used. It was organised by people around the magazine — its editor Rop Gonggrijp and Patrice Riemens, with Caroline Nevejan on behalf of the Paradiso — and a department of the University of Amsterdam supported it by supplying a permanent connection to the internet, which was a novelty. Its attendance drew Hack-Tic readers and contributors, people from the German Chaos Computer Club, people from the New York quarterly, and participants from a range of other countries; the lectures included feminism and computers, models for artificial intelligence, and human-computer interaction. The conference issued a joint declaration whose opening proposition was that the free and unimpeded flow of information is an essential part of fundamental liberties and is to be upheld in all circumstances. The best-known transcription of that sentence contains an obvious typographical corruption, so it is paraphrased here rather than quoted.

The second edition, Hacking at the End of the Universe, took place near Lelystad in the Flevopolder on 4, 5 and 6 August 1993 with five hundred participants, organised by the magazine. The PTT supplied eight telephone lines for the occasion, which was how the field kept in electronic contact with the rest of the world. The workshop programme covered virtual reality, encryption, mobile and cordless telephony and wireless networking; the legal session described earlier in this article was on the same programme. Two institutions were conceived in that field: the groundwork for the provider was laid there, and the idea for the digital city was born there.

The series then runs: Hacking in Progress at the Kotterbos campsite near Almere from 8 to 10 August 1997, with attendance variously reported between fifteen hundred and twenty-five hundred; HAL 2001, or Hackers at Large, at the University of Twente in Enschede from 10 to 12 August 2001, whose site's network operations centre gave the event what was then the largest internet uplink any conference had had, a fibre connection in excess of a gigabit per second of which it never used more than about two hundred megabits; What The Hack at Liempde from 28 to 31 July 2005; Hacking at Random at the Paasheuvel campsite near Vierhouten from 13 to 16 August 2009, with an attendance of 2,300; Observe. Hack. Make. from 31 July to 4 August 2013; Still Hacking Anyway in 2017; May Contain Hackers in 2022; and What Hackers Yearn in 2025.

A tall black rectangular slab standing on a grass field among dome and ridge tents, with a skull-and-crossbones flag flying beside it and woodland behind.
The monolith erected by the German Chaos Computer Club on the camp site at HAL 2001, the fourth edition of the quadrennial Dutch hacker convention, held at the University of Twente in Enschede from 10 to 12 August 2001. The name was derived from the computer in 2001: A Space Odyssey and then back-formed into Hackers At Large. CEphoto, Uwe Aranas · CC BY-SA 3.0 · via Wikimedia Commons.

The political content is on the record too, and it changed with the law. The stated main political topic of the 2001 edition was opposition to the American Digital Millennium Copyright Act and to comparable anti-hacking legislation then in preparation in Europe; Phil Zimmermann, the author of PGP, lectured at that edition. Cryptography and privacy policy were recurring subjects across the whole series, as they had been in the magazine from 1991 — the general argument about encryption policy, and the statute-versus-mathematics framing it eventually acquired, belongs to this directory's pages on comp.society.privacy and alt.privacy and is not rehearsed here. Two things about the camps bear directly on the newsgroup, though. The first is that the charter of nl.comp.hacken names meetings as an on-topic subject in its second sentence. The second is arithmetic: the camps came every four years and the magazine had stopped in 1994, so for most of the intervening time there was nowhere obvious for the conversation to run. A newsgroup was the cheap, always-on layer of that world.

Two wooden clothes pegs, each hand-written with a pair of numbers, lying above a red printed card headed WhatTheConfig listing DNS, WINS, netmask and gateway addresses.
Address allocation by clothes peg at What The Hack, the 2005 edition of the convention, held at Liempde from 28 to 31 July: two pegs hand-numbered with the last two octets of an IP address, issued with a printed card giving the camp network’s DNS, netmask and gateways. The method is the one set out, half in earnest, in RFC 2322, written at the 1997 edition. en:User:Ministry of Truth · CC BY-SA 3.0 · via Wikimedia Commons.

Institutions: a provider and a digital city

The same milieu built two institutions that outlived it, and both are documented well enough to be described without recourse to anecdote.

XS4ALL began in 1993 as an experiment in selling access, run out of the magazine's orbit; the name is a rendering of the English phrase access for all. The English-language record calls it the sixth provider in the Netherlands, after NLnet, SURFnet, the hobby computer club's service, Knoware and the Internet Access Foundation, and the second company to sell access to private individuals; the Dutch record agrees on that second place, naming the hobby computer club's hobbynet as the first. Its founders were Felipe Rodriquez, Rop Gonggrijp, Paul Jongsma and Cor Bosman, and the ground for it had been prepared in 1991 in Hacktic Netwerk, the organisation set up out of the magazine. In 1994 the access business was placed in its own foundation and renamed, deliberately, to shed the association with the hacker world; a limited company followed in March 1996; the firm was sold to the national telephone incumbent in December 1998, for a reported 120 million guilders, and continued as a subsidiary. The parent announced in January 2019 that it would retire the brand, and stopped offering service under the name on 24 December 2021. A self-declared ideological successor, Freedom Internet, was launched in November 2019 on the back of a crowdfunding campaign that raised two and a half million euro.

De Digitale Stad opened in Amsterdam on 15 January 1994, a joint initiative of the cultural centre De Balie and the magazine, with Marleen Stikker among its founders, modelled on the WELL and on North American freenets but without their regional restriction. Anyone with a modem could have a free account with electronic mail, internet access and space for a home page, and public terminals were placed around the city. It was conceived as a ten-week experiment tied to the municipal elections of March 1994 and intended, among other things, to narrow the distance between citizens and politicians; that particular aim failed, because the politicians stayed away. It was funded by the city only in its opening period, formalised as a foundation in 1995, split into a commercial arm and a public one in 1995 and 1996, taken private in a management buy-out in 1999 and partly sold to a British company in 2000.

Its documented significance is not in dispute, and it has an unusually concrete measure. On 18 May 2023 the executive board of UNESCO approved the inscription of De Digitale Stad, with sixty-four other collections, on the Memory of the World International Register — the same register that carries archives of national and world importance.

Printed cover of a Dutch tabloid newspaper: a grid of red and black squares carrying single letters and punctuation marks, captioned with words such as KIOSK, PLEIN, STEEG and POSTKANTOOR.
The newspaper issued by Stichting De Digitale Stad, Amsterdam’s free public network, held by the Amsterdam Museum and dated by it to between 1993 and 1995. Its cover sets out the service as a city of squares, alleys and a post office. The service opened on 15 January 1994 as a ten-week experiment and was inscribed on UNESCO’s Memory of the World International Register in May 2023. Stichting De Digitale Stad (uitgever) · public domain · via Wikimedia Commons.

Both institutions matter to this page because they are the answer the scene gave when asked what it was. The terminology argument recorded earlier — whether the word for these people was hacker or kraker — was never purely lexical, because one side of it could point at a magazine, a provider and a digital city, and the other could point at articles 138ab and following. Both sets of exhibits are real.

What the group carried

No message archive of nl.comp.hacken is held on this site, and archive coverage of the nl.* hierarchy generally is uneven. What can be established about the traffic must therefore be established from the charter, from the group's position in the namespace, and from what is true of every group of this kind — and it should be given as classes of discussion, not as incidents. Four classes are supportable.

  • Security discussion. The charter names computer security, virus writing, coding, lockpicking and phreaking as on-topic subjects, and technique second among the group's purposes. This is the ordinary content of such a group: operating-system and network security, in a decade when that increasingly meant Windows as well as Unix, discussed by people some of whom did it professionally. Nothing about method is described on this page.
  • The legal argument. The charter names ethics first, and the group ran from 2004 to 2011, a period in which Dutch computer-crime law was amended once and a treaty entered into force for the Netherlands. Where the earlier scene had argued about whether the law should exist, a group of this vintage was arguing inside a settled one.
  • The scene's own news. Meetings is in the charter's second sentence. Between 2004 and 2011 the camps of 2005 and 2009 both fell inside the group's life, as did the sale, growth and consolidation of Dutch providers.
  • The terminology dispute. No group of this name anywhere avoided it. In Dutch it had an extra term to argue over and a dictionary definition to argue with.

Two further things are safe to say about the shape of the traffic, because they follow from the paperwork rather than from imagination. The first is that the group received requests of the kind its charter refuses — the charter would not have listed them, in that detail, otherwise. The second is that the language mixed: a Dutch-language group whose own founding document reaches for on-topic, lockpicking and phreaken was not going to conduct its technical discussion in pure Dutch, because the technical vocabulary of the subject never really translated.

Beyond that, nothing specific can be stated. Anyone chasing a particular remembered thread is better served by a news archive than by any summary, this one included.

Carrying the group, and how it ended

For a Dutch news administrator, carrying nl.comp.hacken was a routine decision with an unusually loaded name attached to it. A site took the hierarchy as a feed and chose locally which groups to keep; a text-only discussion group cost almost nothing in spool space, so the usual grounds for dropping something — volume, binaries, disk — did not arise. The hierarchy's own rules made no special provision for the subject either: nl.* groups were created by proposal and ballot, not by subject-matter licence, and once a group existed the decision to carry it belonged to each site, as the hierarchy's own administrators repeatedly said. How often that decision was actually argued over at Dutch universities and providers is not something the surviving record settles, and this page does not guess.

The ending is better documented than the middle, and it was unremarkable. The rmgroup messages of September and October 2011 give no reason beyond common practice, and the group went in a sweep of twenty-nine. The nl.* hierarchy's contraction through those years is legible in its own control log, and the honest account of where the traffic went is that nobody knows how it divided: Dutch web forums absorbed an enormous quantity of it through the 2000s, but so did mailing lists, chat and later social platforms, and the surviving record does not apportion them. The hub page for the hierarchy sets out what the sweeps of 2009 and 2011 removed and what still runs.

The scene, unlike its newsgroup, did not end. The camps continued through 2013, 2017, 2022 and 2025; the digital city became documentary heritage in 2023; the provider's name was retired in 2021 and a successor launched in its declared spirit in 2019. Dutch-language traffic on these subjects also existed outside the hierarchy altogether, in the international alt.* branch that answers to nobody — alt.nl.support is this directory's example of that side of the split. What remains of nl.comp.hacken itself is ten control messages, a charter, a tally and an address.

What the record does not show

The paperwork for this group is unusually complete and the traffic is unusually absent, and it is worth being explicit about which is which.

  • No message archive is held here. This page quotes no posting, names no poster, cites no thread title and gives no message count, because it has verified none. Where a number appears in this article it comes from a control message, a statute, a treaty record or an encyclopaedia article, and the source is named in the sentence.
  • No technique of any kind is described. Not in the summary of the charter, not in the account of the magazine, not in the discussion of the law. The subjects the charter lists are named as subjects and left there.
  • No participant in the group is named. The people named on this page are named in the published record for what they founded, edited or said in public — a magazine, a provider, a digital city, a lecture at a camp. Nobody is named as a poster to nl.comp.hacken, because no archive of the group has been consulted, and no defendant is named in the legal material.
  • Nothing here is instruction. The legal material is a record of instruments and dates. It is not advice about the law of the Netherlands, which has been amended twice since the group was removed, and it is not a description of what any conduct would attract today.
  • The reasons are missing. The control messages record that the group was created and that it was removed. They record no argument for either beyond the tally and the phrase about common practice. Why ninety per cent of ninety-four voters wanted this group in 2003, and what had changed by 2011, are questions the archive does not answer.

Scope and limits of this page

This directory preserves exactly one group from the Dutch hierarchy, and that is an artefact of how the site was reconstructed rather than a judgement about the hierarchy's contents. These pages were rebuilt from the subscription roster of a mail-to-news gateway, and in the Dutch case the roster records nl.comp.hacken and nothing else. A reader arriving from a citation of some other Dutch newsgroup has not found a gap in the record; they have found the edge of one small window onto it. The nl.* hierarchy itself, its administrators, its creation procedure and its 177 surviving groups are the subject of the hub page.

Within that window, the division of subjects is deliberate. Dutch computer-crime law, the Dutch vocabulary of hacking and the documented Dutch scene are this page's own material. The general argument about privacy, encryption policy and the limits of legislating against mathematics belongs to comp.society.privacy and alt.privacy; software cracking, serial numbers and the trade in them, which this group's charter explicitly refused, belong to alt.new.cracks.

Finally, a note on register. This is a page about a newsgroup, a legal history and a documented subculture, and it reports what was argued rather than joining the argument. The dispute over hacker and kraker is recorded here with its published positions and their dates, and no verdict is offered on it. The statutes are recorded with their instruments, dates and provisions, and no view is offered on whether they were wise.

Reading nl.comp.hacken today

  • Historical archive: Google Groups — nl.comp.hacken (coverage varies by group and era).
  • Open in a newsreader: news:nl.comp.hacken — the original site offered exactly this link, and it still works if your system has a newsreader registered for the news: scheme.
  • Live access: point an NNTP newsreader at a modern server — see accessing Usenet today.
  • The original news2mail e-mail subscription service ended in the mid-2000s and no longer operates.