In the predawn hours of an August Monday, a Hotmail mailbox could be reached through a web page that looked almost too plain to be dangerous. Enter an address, pass along the little string “eh,” and the account could open in a browser, with private mail sitting there as if the lock had never existed.[1][2]
In 1999, hackers publicized a Hotmail flaw that exposed millions of accounts through a simple browser exploit involving “eh.” Microsoft denied that it was a deliberate backdoor, then rushed out fixes after the breach became public.
Hotmail had become a prize worth attacking. Microsoft had bought the webmail service in December 1997 for $450 million, folded it into MSN, and by the summer of 1999 was serving tens of millions of users who could check email from almost any connected computer.[1] CNN put the subscriber count at more than 40 million; other accounts placed it as high as 50 million.[4][5]
The exposed mailboxes were not theoretical. CNN reported that several web addresses prompted only for a Hotmail username. Once a name was entered, the account appeared, and visitors could in some cases read, forward, or send messages under that person’s identity.[4] Wired described the exploit as a few lines of simple HTML code using a Hotmail login script called “start,” along with the password “eh.”[2]
The Tiny Code That Opened a Giant Service
The breach surfaced publicly through the Swedish newspaper Expressen after rumors had circulated for days.[5] Wired reported that a group calling itself Hackers Unite claimed responsibility for publicizing the hole, though Wired could not confirm the identities behind the claim.[2]
Lasse Ljung of Göteborg, who used the online nickname DarkWing, spoke for the group on Internet Relay Chat. He said Hackers Unite included one Swedish citizen and seven Americans, and framed the breach as a protest against Microsoft’s security. “We did not do this hack to destroy,” he told Wired, “we want to show the world how bad the security on Microsoft really is.”[2]
The public tools were startlingly small. The Guardian described websites in Britain and Sweden carrying nine lines of code that let browsers bypass Microsoft’s security system.[5] SmarterMSP later summarized the trick in its most memorable form: visit a page exploiting the login script, type a Hotmail address and the password “eh,” and the mailbox could be reached.[1]
Microsoft rejected the idea that engineers had left a deliberate backdoor. Rob Bennett, MSN’s marketing director, told Wired there was “nothing to these allegations,” and described the flaw instead as “an unknown security issue.”[2] Richard Smith, a computer security specialist and president of Phar Lap Software, gave CNN a blunter diagnosis: “It’s simply a bug at Hotmail servers.”[3]
Other explanations followed the same thin trail of URLs and scripts. Jon Thompson, administrator of one site that hosted the exploit, told MSNBC.com that associates had known about the weakness for about eight weeks and believed Microsoft’s new Passport sign-in service was involved. Microsoft project manager Deanna Sanford said the flaw was not related to Passport, though she did not know how long it had existed.[2]
Another lead pointed to Michael Nobilio, a New Jersey programmer who had written a harmless JavaScript shortcut to save his Hotmail username as a cookie. Nobilio said his tool still required a password. Smith believed someone may have noticed that a related URL could be abused to reach accounts without one.[3]
Once the breach was public, Microsoft moved fast. CNN reported that Hotmail was taken down for about an hour while the company responded and added code to block future attacks.[4] Wired reported that Microsoft began work at 2 a.m. Pacific time, had an initial fix in place by 10 a.m., and fixed a related variant around noon as changes spread across Hotmail servers.[2] SmarterMSP summarizes the repair as arriving within two hours once the issue was known.[1]
The strange part was how little drama the key itself carried. At the edge of the webmail boom, one of the internet’s largest private spaces could be made to open with two lowercase letters, sitting in a browser field: eh.




