Welcome back to Computer History Wednesday. Today’s story is one of the good ones: how a company that owned computing lost it, not to a bigger rival, but to a handful of engineers who worked out how to copy the one part IBM thought nobody could.
The IBM PC shipped in 1981 and became the standard almost overnight. Then Compaq, Phoenix, and a wave of nameless Taiwanese shops proved the standard belonged to anyone who could clone it. Inside a few years IBM went from setting the terms to following them. That reversal built the PC industry we still live in, and it left a security bill we’re still paying: the same open, anyone-can-build-it architecture that put a computer on every desk also handed us BIOS malware, firmware implants, and supply-chain risk.
This one runs long. We go from punch cards to protected mode, from mainframe monopoly to garage-built clones, with stops at the technical and legal fights that decided who got to build a PC, and what that openness cost us in security.
History#
Phase 1: The birth of IBM#
IBM’s origins go back to the late 19th century and a handful of companies that made mechanical office machines. One was the Computing Scale Company, founded in 1891 by Edward Canby and Orange O. Ozias in Dayton, Ohio. It made computing scales, the weighing devices that let a grocer read a price straight off the weight, and had nothing to do with the punch-card machine that would end up mattering most.
That machine came from Herman Hollerith, a former US Census Bureau employee who had built a punch-card system for tabulating census data. Hollerith founded the Tabulating Machine Company in 1896 to sell machines based on his patents. In 1911, financier Charles Flint merged it with three other firms, the Computing Scale Company, the International Time Recording Company, and the Bundy Manufacturing Company, into the Computing-Tabulating-Recording Company (CTR).
CTR continued to produce and sell a variety of mechanical calculators and tabulating machines, but it was not until the 1920s that the company began to focus on computing as a business. In 1924, CTR changed its name to International Business Machines (IBM) and began to expand into other areas of computing.
One of IBM’s early successes was the development of a punch-card system for recording and storing information. IBM’s punch-card system was used by a variety of businesses and government agencies for tasks such as accounting, inventory management, and record-keeping. The punch-card system was also used by the US government for military purposes during World War II.
IBM’s next big step was the IBM 701, its first mass-produced electronic computer, introduced in 1952 and aimed at scientific and engineering work. It paired with the IBM 726, the first commercial magnetic-tape drive, which pushed data storage well past the punch card.
Throughout the 1950s and 1960s, IBM continued to be a dominant player in the computing industry. The company developed a wide variety of mainframe computers, which were used by businesses and government agencies all over the world. IBM’s mainframes were known for their reliability and security, and they were essential for many important tasks, such as financial transactions, airline reservations, and space exploration.
IBM also had a hand in the moon landings, though not the part people usually credit it with. The Apollo Guidance Computer, the machine the astronauts actually flew, came out of MIT’s Instrumentation Laboratory and was built by Raytheon. IBM’s contribution sat one stage lower: the Launch Vehicle Digital Computer, the triple-redundant machine in the Saturn V’s instrument unit that steered the rocket through launch and into orbit. It ran three copies of every calculation and voted on the result, an early production example of the fault-tolerant design we now take for granted in anything that cannot afford to crash.
IBM started in scales, clocks, and punch cards and turned that business into a computing empire. Its tabulators and mainframes ran the payrolls, census counts, and airline reservations of the mid-20th century, and its work on machines like the Saturn V’s flight computer put it at the center of the era’s hardest engineering. That foundation is what made IBM the company to beat by the time the personal computer showed up.
Phase 1.5: The mainframe era and the System/360#
Between the mechanical era and the PC revolution lay IBM’s most ambitious project yet: the System/360 family of computers. Introduced in 1964, System/360 represented a radical departure from previous computing architectures. Rather than designing separate computers for different applications, IBM created a single architecture that could scale from small business systems to massive scientific computers.
Technical innovations:
- Unified Architecture: All 360 systems used the same instruction set, allowing software portability across the entire family
- Microprogramming: IBM pioneered microcode, allowing complex instructions to be implemented in firmware rather than hardware
- Virtual memory: not in the base line, but the special Model 67 (1965) pioneered it, and it became standard across IBM mainframes with the System/370
- Multiprocessing: Support for multiple CPUs working on the same problem
Security implications (1960s context):
- Physical Security: Mainframes were housed in dedicated computer rooms with environmental controls and access restrictions
- Data Security: Early concepts of access control through job control language (JCL) and operator oversight
- Audit Trails: Punched card systems naturally created audit logs of all data processing activities
The System/360 wasn’t a product line so much as a whole world. IBM supplied the hardware, the software, and the training, the kind of top-to-bottom “stack” that locks a customer in. That vertical, own-everything model is exactly what the horizontal, mix-and-match PC clones would later blow apart.
Key technical specifications:
- Model range: from the entry-level Model 20 up to supercomputer-class machines like the later Model 195
- Memory: from a few kilobytes of core on the small models to several megabytes on the largest
- Storage: DASD (Direct Access Storage Device) with removable disk packs
- Cost: well into six figures, and past a million dollars for a big install, firmly in the corporate-and-government tier
The System/360’s success reinforced IBM’s dominance but also sowed the seeds of its future challenges. The complexity and cost of these systems created a market opportunity for simpler, cheaper alternatives.
Phase 2: A New Hope#
In the late 1970s, IBM began to realize that its dominance of the computing industry was being challenged by a new wave of companies that were producing cheaper and more accessible machines. In response to this threat, IBM decided to create its own personal computer, which would be designed for business use and would be compatible with IBM’s mainframes.
The IBM PC started as William C. Lowe’s pitch. Lowe, running IBM’s Boca Raton lab, convinced management that the only way to ship a PC in a year was to break IBM’s own rules: buy parts off the shelf and skip the usual in-house-everything process. He got the approval, then was promoted away, and Don Estridge took over and actually brought the machine to market.
One of the key decisions that the team made was to use off-the-shelf components for the machine. This allowed them to save time and money on development, and it also ensured that the machine would be compatible with existing hardware and software.
The team decided to use an Intel 8088 processor for the machine, which was a low-cost processor that was powerful enough to run business applications. They also decided to use an operating system called PC-DOS, which was developed by a company called Microsoft.
The team worked quickly and efficiently, and in just one year, they had produced a working prototype of the IBM PC. The machine was introduced in August 1981 and was an instant success. It was praised for its reliability, ease of use, and compatibility with existing hardware and software.
Estridge, who headed the Entry Systems Division, ran the project like a startup bolted onto a mainframe company: no reserved parking, no executive dining room, engineers on a first-name basis with the boss. He was fanatical about compatibility. The lore, repeated often enough that it’s worth telling even if it’s hard to source, is that his team tested against a rented truckload of competitors’ hardware and software to make sure the PC played nicely with everything already on the market.
The IBM PC was a major turning point in the history of computing. It helped to bring computing to businesses and individuals who had never used a computer before, and it paved the way for the rise of the clones. The success of the IBM PC also helped to solidify IBM’s position as a major player in the computing industry, and it set the stage for the legal battles that would follow in the clone wars.
The creation of the IBM PC was a significant achievement in the history of computing. The machine was designed to be reliable, easy to use, and affordable, and it was compatible with existing hardware and software. The success of the IBM PC helped to bring computing to a wider audience, and it laid the foundation for the rise of the clones. The legacy of the IBM PC can still be felt today, as many modern computers are still designed to be compatible with IBM’s original machines.
Phase 2.5: The XT revolution and industry standards#
Following the success of the original PC, IBM introduced the PC/XT (eXtended Technology) in 1983. This evolution added critical mass storage capabilities and established several standards that would define the PC architecture for decades.
Technical advancements:
- Hard Disk Drives: 10MB ST-412 full-height drives became standard
- More memory: up to 640KB of RAM, the ceiling DOS would famously bump against for years
- Serial/Parallel Ports: RS-232C serial and Centronics parallel interfaces
- BIOS Extensions: Support for additional peripherals and memory configurations
The PC BIOS: IBM’s crown jewel, and future burden#
The BIOS (Basic Input/Output System) became the most critical component of the PC architecture. This firmware handled hardware initialization, provided low-level services, and contained the all-important Power-On Self Test (POST).
Security considerations:
- BIOS Protection: Physical switches prevented accidental overwrites
- Memory Parity: Error detection and correction capabilities
- Trusted Boot: Early concepts of secure startup sequences
The XT’s success validated the PC concept and attracted competitors, but IBM’s decision to keep the BIOS proprietary would later backfire spectacularly.
Phase 2.75: The AT era and 16-bit computing#
IBM’s 1984 introduction of the PC/AT (Advanced Technology) brought 16-bit computing to the masses and introduced the architecture that would dominate computing for the next decade.
Groundbreaking features:
- Intel 80286 Processor: 16-bit architecture with protected mode
- AT Bus: 16-bit ISA expansion slots (backward compatible with 8-bit cards)
- 1.2MB Floppy Drives: Double density, double-sided storage
- Real-Time Clock: Battery-backed CMOS memory for configuration storage
Protected mode revolution: The 80286’s protected mode allowed:
- Memory Protection: Preventing programs from corrupting each other’s memory
- Virtual Memory: Extended addressing beyond physical RAM limits
- Multi-Tasking: Foundation for modern operating systems
Security advancements:
- Memory Segmentation: Hardware-enforced memory boundaries
- Privilege Levels: Four rings of protection (though rarely used by DOS)
- BIOS Security: Enhanced password protection and setup security
The AT established the template for modern computing but also introduced complexity that clone manufacturers would exploit.
Phase 3: The rise of the clones#
The early 1980s saw a dramatic shift in the computing industry with the emergence of a new phenomenon: the IBM clone. Clones were computers that were designed to be compatible with IBM’s machines but were produced by other companies.
Compaq’s bold gamble#
The first company to produce a clone was Compaq, which was founded in 1982 by three former Texas Instruments employees: Rod Canion, Jim Harris, and Bill Murto. Compaq’s founders recognized that IBM’s machines were popular but expensive, and they saw an opportunity to produce a cheaper alternative that would be just as good.
The Compaq Portable (1983)#
- Processor: Intel 8088 running at 4.77 MHz (same as IBM PC)
- Memory: 128KB RAM (expandable to 640KB)
- Display: 9-inch monochrome monitor with CGA graphics
- Storage: Single 360KB floppy drive
- Weight: 28 pounds (including battery)
- Price: $2,995 for the base machine, $3,590 with two drives (the IBM PC started at $1,565, before a monitor)
Reverse engineering challenges: Compaq engineers faced daunting technical hurdles:
- BIOS Duplication: Creating a clean-room implementation of IBM’s BIOS
- Hardware Compatibility: Ensuring identical port addresses and interrupt handling
- Software Compatibility: Supporting all IBM PC applications without modification
Phoenix Technologies and the liberated BIOS#
One interesting anecdote from this time period involves a company called Phoenix Technologies. Phoenix was founded in 1979 and was primarily known for producing software that was designed to extend the functionality of IBM’s BIOS (basic input/output system). In the early 1980s, Phoenix realized that IBM’s BIOS was a crucial component of its machines, and that if it could create a compatible BIOS, it could produce its own clones.
The great BIOS reverse engineering: Phoenix assembled a team of engineers who studied IBM’s BIOS through legitimate documentation and observation (not disassembly). This clean-room approach is what kept the entire clone industry on the right side of copyright law, and it is the key to the whole story (more on that in Phase 4).
Technical achievements:
- BIOS Size: 8KB of code handling hardware initialization
- POST Sequence: Power-on self-test routines
- Interrupt Handlers: Hardware service routines
- API Compatibility: Identical function calls for software
Contrary to how the story sometimes gets told, IBM never dragged Phoenix into court over this. It couldn’t win such a case and it knew it: Phoenix hadn’t copied a line of IBM’s code, so there was no infringement to allege. That was the entire point of the clean room. Phoenix put a legal, IBM-compatible BIOS on the open market in 1984, and the clone floodgates opened.
The clone ecosystem explodes#
Other companies soon followed Compaq’s lead and began producing their own clones:
- Columbia Data Products (1982): the MPC 1600, generally credited as the first fully IBM-compatible clone, though the company didn’t last
- Eagle Computer (1983): built respectable PC clones and briefly looked like a contender (the computer in the movie “WarGames” that year was actually an IMSAI 8080, not an Eagle, a mix-up worth clearing up)
- Leading Edge (1983): sold the Daewoo-built Model D through independent dealers, one of the first clones to undercut IBM on price and still feel solid
- Kaypro (1983): known for its luggable CP/M machines, it followed the market into PC compatibles
Technical variations:
- Memory Configurations: 256KB to 640KB RAM
- Storage Options: Single/double floppy drives, early hard drives (10-20MB)
- Graphics Cards: CGA, EGA compatibility
- Expansion Slots: 8-bit ISA bus compatibility
Clones of clones#
As the clone market became more crowded, some companies began producing machines that were designed to be compatible with existing clones rather than with IBM’s machines. These “clones of clones” were often less expensive than the original clones and were popular with budget-conscious consumers.
Taiwanese manufacturing revolution:
- Acer: founded as Multitech in 1976 and renamed Acer in 1981, it moved into PC clones around 1983 and grew into one of the largest makers in the world
- Mitac: a Taiwanese firm turning out generic PC clones by the mid-1980s
- A wave of no-name shops: rebranded Taiwanese boards sold through whatever retail channel would carry them
Cost reduction strategies:
- Component Integration: Combining multiple chips into single packages
- Manufacturing Efficiency: High-volume production in Asia
- Minimalist Designs: Removing unnecessary features to cut costs
Technical compatibility challenges#
Clone manufacturers faced numerous technical hurdles:
Interrupt controller conflicts:
- Issue: Different interrupt routing between IBM and clone hardware
- Solution: Careful BIOS programming to handle variations
Timer chip variations:
- Issue: Different timer implementations affecting software timing
- Solution: BIOS compensation routines
Memory parity differences:
- Issue: Some clones lacked IBM’s parity checking
- Solution: Software-based parity verification
The rise of the clones was a significant development in the history of computing. Clones made computing more accessible to businesses and individuals, and they challenged IBM’s dominance of the industry. Companies like Compaq and Phoenix showed that it was possible to produce machines that were just as good as IBM’s, but at a lower cost. The emergence of “clones of clones” also demonstrated the importance of compatibility in the computing industry. All of these developments paved the way for a more competitive and diverse computing landscape in the years to come.
Phase 3.5: The 386 era and advanced clones#
The introduction of Intel’s 80386 processor in 1985 ushered in the era of 32-bit computing and forced clone manufacturers to keep pace with rapidly advancing technology.
Intel 80386 features:
- 32-bit Architecture: 4GB addressable memory space
- Protected Mode: Advanced memory protection and multitasking
- Virtual 8086 Mode: Running 16-bit software in protected environment
Clone responses:
- Compaq Deskpro 386 (1986): First 386-based clone
- AST Premium 386: High-end workstation clone
- Quadram Quad386: Innovative modular design
Technical challenges:
- Protected Mode Support: BIOS and software needed to handle new processor modes
- Memory Management: A20 line handling for full 32-bit addressing
- Performance Optimization: Cache management and pipelining
This era marked the transition from “PC compatible” to “high-performance computing for the masses.”
Phase 4: The Clone Wars#
Here’s the twist that makes this the good kind of history: IBM could not sue the clones out of existence, and the reason it couldn’t is the most important idea in the whole saga.
IBM’s crown jewel was the BIOS, the firmware that let software talk to the hardware. The BIOS was copyrighted, and in 1983 a federal appeals court made that protection real. In Apple Computer v. Franklin Computer Corp., the Third Circuit held that software burned into ROM, a BIOS included, is copyrightable like any other creative work. Franklin had copied Apple’s code byte for byte to build an Apple II clone, and it lost.
That ruling cut both ways. It meant you could not copy IBM’s BIOS code. It did not mean you couldn’t build a BIOS that did the same job. Copyright protects the specific expression, the actual bytes, not the function underneath. So the clone makers threaded the needle with a technique borrowed from the chip world: the clean room.
It worked like this. One team studied IBM’s BIOS and wrote a detailed spec of what it did, every input, every output, every documented behavior, without ever showing the code to the people who would reimplement it. A second team, who had never seen IBM’s code, wrote a fresh BIOS from that spec alone. Compaq did it first, at a cost of about a million dollars and several months. Phoenix turned it into a product anyone could buy. By 1984 there was a legal, IBM-compatible BIOS on the open market, and you no longer had to be Compaq to build a PC. You needed Phoenix’s chip and a catalog of off-the-shelf parts.
So the clone wars were fought with lawyers only in the sense that lawyers drew the lines everyone then engineered around. There was no landmark IBM-versus-Compaq trial, no jury verdict that legalized the clones. The clones were legal from the start, as long as nobody copied the code, and the clean room made sure nobody had to. (The famous chip lawsuit of the era, AMD against Intel over the right to second-source the 386, was a fight between two chipmakers. IBM wasn’t part of it.)
IBM’s actual problem wasn’t the courtroom. It was that IBM had built the PC out of parts anyone could buy and had documented the one piece that mattered well enough for anyone to reimplement. The open architecture that made the IBM PC the standard also made the standard impossible to own. IBM’s answer, when it finally came, wasn’t a lawsuit. It was an attempt to yank the hardware out from under everyone.
Phase 5: The Empire Strikes Back#
As the clones continued to eat away at IBM’s market share, the company began to take drastic measures to regain its dominance in the computing industry. One of the strategies that IBM pursued was the creation of new machines that were not compatible with the clones.
In 1987, IBM introduced the Personal System/2 (PS/2), which was a new type of computer that was not compatible with the clones. The PS/2 used a new type of bus called the Micro Channel Architecture (MCA), which was not compatible with the industry-standard ISA bus used by the clones.
The PS/2 was also designed to run a new operating system called OS/2, which was developed by IBM and Microsoft. OS/2 was designed to be a more advanced operating system than MS-DOS, which was used by the clones, and it was intended to run on IBM’s new machines, including the PS/2.
However, the PS/2 and OS/2 faced a number of challenges. The machines were expensive, and many customers were reluctant to switch to a new platform that was not compatible with their existing hardware and software. OS/2 was also a complex and resource-intensive operating system, which made it difficult to run on the relatively underpowered machines of the time.
Another problem with the PS/2 and OS/2 was that they were developed in a closed environment, with little input from outside developers. This made it difficult for third-party developers to create software for the machines, which limited their appeal to customers.
Despite these challenges, IBM continued to push the PS/2 and OS/2, and the company even launched an advertising campaign that was aimed at convincing customers to switch to the new platform. However, the campaign was not successful, and the PS/2 and OS/2 failed to gain significant market share.
The failure of the PS/2 and OS/2 was a significant blow to IBM, and it marked the end of the company’s attempts to regain its dominance in the computing industry. The clones had firmly established themselves as a viable alternative to IBM’s machines, and they continued to dominate the market for years to come.
The PS/2 and OS/2 were significant developments in the history of computing, but they ultimately failed to achieve their goals. IBM’s attempts to create new machines that were not compatible with the clones were a reflection of the company’s desperation to regain its dominance in the industry. However, the failure of these machines paved the way for a more diverse and competitive computing landscape, which has ultimately benefited consumers and businesses alike.
I have a soft spot for the PS/2, so let me be honest about it. I ended up with one years later, second-hand and long past the point where it mattered, and the machine was gorgeous: solid, thoughtfully built, clever in ways the beige clone boxes never bothered to be. That was exactly its problem. It was too unique to win. My friends all ran Compaqs, with the occasional Packard Bell, because by then that was what “a PC” meant, and what a PC meant was no longer IBM’s to decide. IBM’s other swing at a machine you might actually want at home, the PCjr, I met too, and its chiclet keyboard is still one of the worst things I have ever tried to type on. IBM eventually mailed everyone a replacement, which tells you about all you need to know.
Phase 6: The aftermath#
IBM never did license its BIOS to the clone makers, and it never had to be forced to; that isn’t how the market cracked open. The clones ran BIOS chips from Phoenix, American Megatrends (AMI), and Award, all reimplemented clean-room, none of them IBM’s. What IBM actually lost wasn’t a piece of code. It was control of the standard. Once compatible parts and a compatible BIOS were on the open market, anyone could assemble a PC, and IBM was just one more vendor selling into an architecture it no longer owned.
One interesting development that followed the end of the clone wars was the emergence of new types of computers. The IBM PC had been designed for business use, but the clones had helped to bring down the price of computing, making it more accessible to consumers. This led to the development of new types of computers, such as the Apple Macintosh and the Commodore Amiga, which were designed for home use.
Another interesting development during this time period was the emergence of software as a major driver of the computing industry. IBM had always been primarily a hardware company, but the rise of the clones had led to a proliferation of software, much of it produced by small, independent companies.
The clearest winner here was Microsoft, founded in 1975 by Bill Gates and Paul Allen. The operating-system story usually gets told backwards, so it’s worth getting straight: MS-DOS was not a clone of IBM’s OS. It was the other way around. Microsoft didn’t even write it. When IBM came shopping for an operating system, Microsoft bought a product called 86-DOS (nicknamed QDOS, the “Quick and Dirty Operating System”) from Seattle Computer Products, cleaned it up, and licensed it to IBM, which shipped it as PC-DOS. The masterstroke was in the contract: Microsoft kept the right to sell the same software to everyone else as MS-DOS. So every clone that wanted to run PC software needed Microsoft, and Microsoft got paid per machine by an entire industry it hadn’t built. IBM opened the door; Microsoft walked through it and kept the key.
The aftermath of the clone wars also had important implications for cybersecurity. The rise of the clones had highlighted the importance of compatibility in the computing industry, but it had also created new vulnerabilities. Since clones were often produced by companies that were less concerned with security than IBM, they were sometimes more vulnerable to hacking and other types of cyberattacks.
That insecurity is part of what seeded the security industry. The early antivirus names showed up as the virus problem got real in the late 1980s: John McAfee started McAfee Associates in 1987 to sell virus scanners, and a young Symantec (founded in 1982, though as a natural-language software company, not an antivirus one) got into the game later by buying Peter Norton Computing in 1990 and shipping Norton AntiVirus in 1991. The threats those tools answered, boot-sector viruses spreading on shared floppies, were a direct consequence of millions of near-identical, wide-open PCs.
The aftermath of the clone wars was a time of significant change in the computing industry. The emergence of new types of computers and the rise of software as a major driver of the industry were just two of the many developments that followed in the wake of the clone wars. The impact of the clone wars on cybersecurity was also significant, highlighting the importance of protecting against vulnerabilities in computing systems. Overall, the clone wars were a pivotal moment in the history of computing, and their legacy continues to be felt today.
Cybersecurity#
The clone wars weren’t only a business story. Spreading millions of near-identical, wide-open machines across the world reshaped the security landscape too, and a lot of what we deal with now traces back to decisions made in this era.
Hardware security in the clone era#
BIOS security: the original firmware vulnerability#
The BIOS, that critical firmware burned into ROM chips, became the first major firmware security battleground:
Early BIOS threats:
- Virus Infection: Some viruses could infect and spread through BIOS chips
- CMOS Tampering: Battery-backed memory storing system configuration could be manipulated
- Boot Sector Viruses: Leveraging BIOS interrupt services to persist
Clone manufacturer responses:
- Phoenix FirstBIOS: Introduced virus protection features
- AMI BIOS: Added boot-time integrity checking
- Award BIOS: Implemented password protection for setup
Modern parallels: The BIOS security issues of the 1980s foreshadowed today’s UEFI vulnerabilities, secure boot bypasses, and firmware implants used by state-sponsored attackers.
Hardware backdoors and supply-chain risks#
The proliferation of clone manufacturers introduced significant supply chain security concerns:
Counterfeit components:
- Fake 8088 Processors: Substandard chips that failed under load
- Memory Parity Issues: Missing error correction in budget clones
- Timing Vulnerabilities: Different clock speeds affecting cryptographic operations
Manufacturing security gaps:
- Offshore Production: Taiwanese and Korean factories with varying quality control
- Component Substitution: Using cheaper, less secure alternatives
- Design Flaws: Rushed reverse-engineering leading to exploitable bugs
Software security implications#
Operating-system compatibility versus security#
The drive for 100% IBM compatibility often came at the expense of security features:
MS-DOS security limitations:
- No Memory Protection: Programs could directly access hardware and other processes’ memory
- Single-User Design: No concept of user permissions or access control
- BIOS Dependency: Security reliant on firmware that varied between manufacturers
Clone-Specific vulnerabilities:
- Incompatible Security Software: Antivirus tools designed for IBM PCs failing on clones
- BIOS Interrupt Differences: Malware using non-standard interrupt calls
- Hardware-Specific Exploits: Taking advantage of clone manufacturer shortcuts
The rise of computer viruses#
The clone era coincided with the explosion of computer viruses, creating a perfect storm for malware proliferation:
Notable early viruses:
- Brain Virus (1986): First known PC virus, spread via floppy disks
- Jerusalem virus (1987): a time bomb that triggered on Friday the 13th
- Morris Worm (1988): First internet worm, exploited UNIX vulnerabilities
Clone market impact:
- Rapid Propagation: Incompatible antivirus solutions allowed viruses to spread unchecked
- BIOS-Level Persistence: Some viruses could survive hard drive reformatting
- Cross-Platform Issues: Malware written for IBM PCs failing on certain clones
Legal and intellectual-property questions#
Patent fights and security research#
The legal battles between IBM and clone manufacturers had unexpected security implications:
Reverse engineering ethics:
- Clean Room Techniques: Legitimate security research methodologies
- Copyright vs. Functionality: Legal precedents affecting vulnerability disclosure
- Trade Secret Protection: Balancing innovation with security research
Modern implications: The Clone Wars established legal frameworks that still govern:
- Vulnerability Research: Legitimate security research vs. criminal hacking
- Open Source Intelligence: Publicly available technical documentation
- Responsible Disclosure: Coordinated vulnerability disclosure programs
Enterprise security lessons#
Mainframe versus PC security models#
IBM’s mainframe security model clashed with the open architecture of PCs:
Mainframe security strengths:
- Physical Isolation: Computers in locked, climate-controlled rooms
- Operator Oversight: Human supervision of all computing activities
- Access Logging: Comprehensive audit trails of all operations
- Trusted Computing Base: Small, verified software base
PC clone security challenges:
- Distributed Computing: Thousands of PCs replacing centralized mainframes
- User Autonomy: End users having administrative control
- Network Connectivity: Connecting previously isolated systems
- Software Diversity: Incompatible security tools and policies
The birth of endpoint security#
The clone proliferation necessitated new security approaches:
Early security software:
- Anti-Virus Programs: Responding to virus outbreaks in clone environments
- Access Control: File and directory permission systems
- Encryption Tools: Protecting data on distributed systems
- Backup Solutions: Safeguarding data on unreliable hardware
Industry response:
- McAfee (1987): among the first commercial virus scanners
- Symantec: an early software house that entered antivirus later, via its 1990 purchase of Peter Norton Computing
- Central Point Software: Backup and security utilities
Modern cybersecurity parallels#
Supply-chain security lessons#
The clone wars teach us about modern supply chain attacks:
Hardware trojans: Just as clones sometimes included substandard components, modern hardware can contain:
- Backdoors: Intentionally malicious circuits
- Kill Switches: Remote deactivation capabilities
- Data Exfiltration: Covert communication channels
Firmware security:
- UEFI Vulnerabilities: Modern equivalent of BIOS security issues
- Secure Boot Bypass: Circumventing trusted boot processes
- Rootkit Implants: Firmware-level persistence mechanisms
Open source versus proprietary security#
The clone wars demonstrated the security implications of open architectures:
Advantages of open standards:
- Security Research: Ability to audit and improve security
- Third-Party Solutions: Diverse security tools and approaches
- Innovation Acceleration: Community-driven security improvements
Proprietary security risks:
- Vendor Lock-in: Dependency on single vendor for security updates
- Black Box Problems: Inability to verify security claims
- Monopoly Risks: Single points of failure in security ecosystems
Security lessons from the clone era#
Defense in depth#
- Hardware Verification: Physically inspect and test components
- Software Integrity: Verify program authenticity and integrity
- Access Control: Implement least privilege principles
- Network Segmentation: Isolate systems and networks
- Regular Backups: Maintain offline, secure data backups
- Incident Response: Have plans for security breaches
Modern applications#
Applying clone war lessons today:
- Hardware Security Modules (HSMs): Protecting cryptographic keys
- Trusted Platform Modules (TPMs): Hardware-based security roots
- Secure Boot: Ensuring only trusted software loads
- Firmware Updates: Regular security patching of firmware
- Supply Chain Verification: Auditing hardware and software sources
The Clone Wars fundamentally altered the security landscape by democratizing computing power while simultaneously democratizing security risks. The proliferation of compatible systems accelerated innovation but also multiplied attack surfaces. Understanding this pivotal era helps us appreciate the complex interplay between technological progress and security imperatives that continues to shape our digital world.
The legacy of the clones lives on in our modern security practices, reminding us that open standards and competition, while driving innovation, must be balanced with robust security measures to protect against the inevitable exploits that follow in their wake.
Technical Tidbits#
Hardware evolution through the clone wars#
IBM 601 Multiplying Punch: introduced in 1931, this electromechanical machine could multiply large numbers on punched cards and was one of the products that pushed IBM’s tabulators from pure mechanics toward electrical calculation.
System/360 Model 91: IBM’s most powerful mainframe of the late 1960s, rated around 16.6 million instructions per second (MIPS). It was IBM’s first water-cooled machine, and it cost and consumed on the scale you’d expect from a room-sized supercomputer of the era.
IBM PC Technical Specifications: The original 1981 IBM PC featured a 4.77 MHz Intel 8088 CPU, 16KB-256KB RAM, cassette port for data storage, and five 8-bit ISA expansion slots, all contained in a 19.5-inch-wide chassis.
Compaq Portable Weight Distribution: The 28-pound Compaq Portable (1983) distributed weight unevenly - 12 pounds in the display head and 16 pounds in the system unit - leading to ergonomic complaints despite its portability claims.
Phoenix BIOS Development Cost: Phoenix Technologies invested $3 million over three years to develop their clean-room BIOS reverse engineering, a process that involved 12 engineers studying IBM documentation without accessing the actual code.
Intel 80286 Protected Mode: The 80286 processor in IBM’s PC/AT could address 16MB of memory in protected mode, but MS-DOS couldn’t utilize this feature, requiring OS/2 to demonstrate the processor’s full capabilities.
Micro Channel Architecture Complexity: IBM’s MCA bus in the PS/2 supported 32-bit data transfers and bus mastering, but required custom drivers for each device, making it incompatible with the simpler ISA bus used by clones.
The clone price war: within a few years the bottom fell out of PC prices, and by 1986-87 no-name systems were selling for a fraction of what Compaq’s original machine cost, steadily eroding a market IBM had once owned outright.
Cybersecurity and security failures#
Brain Virus Discovery: The first PC virus, discovered in 1986, was created by Pakistani brothers Basit and Amjad Farooq Alvi as copy protection for their medical software, spreading via 360KB floppy disks.
Morris Worm Impact: Robert Tappan Morris’s 1988 internet worm infected 6,000 UNIX systems (10% of the internet at the time), causing $10-100 million in damages and leading to the creation of CERT.
Firmware persistence: the real 1980s threat wasn’t a BIOS-eating virus (malware that actually rewrote firmware, like CIH, didn’t arrive until 1998) but boot-sector viruses like Brain that hid below the file system and survived a reformat. They were the first hint that the layer beneath the OS was worth attacking.
CMOS Password Cracking: Early PC security relied on CMOS-stored passwords that could be bypassed by removing the battery for 5-10 minutes, a technique still used today on some systems.
IBM PC Security Features: The original IBM PC included no password protection, no file permissions, and no memory protection, making it fundamentally insecure by modern standards.
Clone BIOS Variations: Different clone manufacturers implemented BIOS interrupts differently, causing some security software to fail or behave unpredictably on non-IBM hardware.
Legal and business impact#
The lawsuit that wasn’t: despite how often it gets repeated, there was no epic IBM-versus-Compaq courtroom battle. Compaq beat IBM in the market, not in a Texas courtroom, by shipping a clean-room-compatible machine IBM had no grounds to sue over.
The precedent that mattered: Apple Computer v. Franklin Computer Corp. (1983) established that a ROM BIOS is copyrightable, which is exactly why clone makers reimplemented BIOS behavior clean-room instead of copying the code. Function is fair game; the specific bytes are not.
Market-share slide: IBM peaked at roughly three-quarters of the PC market in 1982-83, fell to around a quarter by 1986, and was down near 12% by 1990, one of the faster reversals of fortune in the industry’s history.
Compaq’s rocket ride: backed by around $2.5 million in venture money in 1982, Compaq cleared $500 million in revenue by 1985 and made the Fortune 500 in 1986, its fourth year, faster than any company had before.
Microsoft’s OEM play: the roughly $50,000 figure people cite was what Microsoft paid Seattle Computer Products for the rights to 86-DOS, not what IBM paid Microsoft. IBM paid per-copy royalties, and Microsoft kept the right to license the same OS to every clone maker. That retained right, not the IBM deal itself, is what turned into billions.
Technical innovation and failures#
IBM PC Design Philosophy: IBM chose off-the-shelf components to reduce development time from 3 years to 1 year, but this decision enabled clones and ultimately hurt IBM’s profits.
PS/2 MCA Bus Rejection: Despite technical superiority, MCA failed because clone manufacturers refused to license the technology, leading to IBM’s $500 million loss on the PS/2 line.
Intel 80386 supply: the 386 launched at a steep per-chip price in volume, and demand outran supply early on, which is part of how Compaq’s Deskpro 386 got to market ahead of IBM.
Hard-disk evolution: the Seagate ST-412 in the PC/XT stored 10MB on 5.25-inch platters in a heavy full-height drive, the kind of storage that cost hundreds of dollars per megabyte at the time.
Memory Expansion Architecture: IBM’s Expanded Memory Specification (EMS) allowed DOS programs to access up to 32MB of memory using 64KB “pages” swapped in and out of conventional memory.
Graphics Standards Wars: IBM introduced Color Graphics Adapter (CGA) in 1981 with 4-color 320x200 resolution, followed by Enhanced Graphics Adapter (EGA) in 1984 with 16 colors at 640x350.
Human and cultural impact#
Philip Estridge’s Management Style: IBM PC project leader “Don” Estridge was known for his unconventional management - no reserved parking, no executive dining room, and encouraging engineers to call him by his first name.
Clone Manufacturer Demographics: Most clone companies were founded by engineers in their 20s and 30s who had worked at established firms, bringing corporate experience to the garage-shop clone industry.
IBM’s “Clone Compatibility” Testing: IBM tested clone compatibility by filling a rental truck with competitor hardware and software, then verifying that IBM’s new systems worked with all of it.
Taiwanese Clone Industry: By 1986, Taiwanese manufacturers produced 70% of the world’s PC clones, with companies like Acer, Mitac, and FIC starting as small operations in Taipei garages.
Legacy Architecture Persistence: The ISA bus, introduced in the IBM PC in 1981, remained in use for over 20 years, with some industrial systems still using ISA cards today for backward compatibility.
Modern parallels and lessons learned#
Supply Chain Security Precedent: The clone era’s counterfeit components foreshadowed modern supply chain attacks like SolarWinds (2020) and Kaseya (2021), where trusted software is compromised at the source.
Firmware Security Roots: BIOS vulnerabilities of the 1980s parallel today’s UEFI exploits, with techniques like “BIOS rootkits” from that era reappearing as “UEFI implants” in modern attacks.
Open Standards vs. Security: The clone wars demonstrated that open, documented standards accelerate both innovation and security research, but can also enable attackers.
Market Disruption Speed: IBM’s market share evaporated in just 4 years (1983-1987), showing how rapidly technological disruption can occur when barriers to entry are removed.
Hardware Standardization Impact: The PC’s success established standards that lasted 40+ years, proving that compatibility and standardization are more valuable than proprietary advantage in the long term.
References#
Books and firsthand accounts#
- Rod Canion, “Open: How Compaq Ended IBM’s PC Domination and Helped Invent Modern Computing” (BenBella Books, 2013): the clone wars told by the man who cofounded Compaq
- James Chposky and Ted Leonsis, “Blue Magic: The People, Power, and Politics Behind the IBM Personal Computer” (Facts on File, 1988): insider account of the IBM PC’s creation
- Charles H. Ferguson and Charles R. Morris, “Computer Wars: How the West Can Win in a Post-IBM World” (Times Books, 1993)
- Jeffrey R. Yost, ed., “The IBM Century: Creating the IT Revolution” (IEEE Computer Society Press, 2011)
- Walter Isaacson, “The Innovators” (Simon & Schuster, 2014): broad digital-revolution history; chapter 8 covers the personal computer
Technical documentation#
- IBM, “IBM Personal Computer Technical Reference” (1981): the hardware and BIOS documentation that made clean-room reimplementation possible
- IBM, “IBM System/360 Principles of Operation” (1964)
- Intel, “8088 Microprocessor Data Sheet”
- Phoenix Technologies, “System BIOS for IBM PC/XT/AT Computers and Compatibles: The Complete Guide to ROM-Based System Software” (Addison-Wesley, 1989)
Legal precedents#
- Apple Computer, Inc. v. Franklin Computer Corp., 714 F.2d 1240 (3d Cir. 1983): established that ROM BIOS code is copyrightable
- Sega Enterprises Ltd. v. Accolade, Inc., 977 F.2d 1510 (9th Cir. 1992): reverse engineering for compatibility can be fair use
- United States v. Microsoft Corp., 253 F.3d 34 (D.C. Cir. 2001), including Bill Gates’s 1998 deposition testimony (public via the DOJ Antitrust Division)
Security research#
- Frederick B. Cohen, “Computer Viruses: Theory and Experiments” (1984; Computers & Security, 1987) and “A Short Course on Computer Viruses” (1990)
- Peter G. Neumann, “Computer-Related Risks” (Addison-Wesley, 1995), and the ACM RISKS Forum he has moderated since 1985
- John Butterworth, Corey Kallenberg, and Xeno Kovah, “BIOS Chronomancy” (Black Hat USA / ACM CCS, 2013): modern firmware-integrity research
Standards and modern references#
- NIST SP 800-161r1, “Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations”
- ENISA Threat Landscape reports (EU Agency for Cybersecurity)
- MITRE ATT&CK framework (attack.mitre.org)
- Bruce Schneier’s writing on supply-chain security (schneier.com)
Archives#
- IBM Archives / IBM Heritage (ibm.com/history)
- Computer History Museum oral history collection (computerhistory.org), including clone-era interviews and its IBM PC “Revolution” coverage
Conclusion#
The clone wars are a rare thing in tech history: a fight the underdogs won cleanly. A handful of engineers with a clean-room process and a catalog of off-the-shelf parts took the standard away from the company that set it, and in doing so built the open PC architecture the whole industry still runs on.
Key legacy elements:
Architectural Standardization: The IBM PC established standards that persist 40+ years later, proving that compatibility often trumps proprietary advantage in the long term.
Market Disruption Velocity: IBM’s market dominance evaporated in just four years (1983-1987), demonstrating how rapidly technological paradigms can shift when barriers to entry are removed.
Open Standards Power: The clone wars proved that open, documented interfaces accelerate innovation, security research, and market competition far more effectively than closed systems.
Security Paradigm Shift: The transition from mainframe security models to distributed PC security created challenges that continue to shape our cybersecurity practices today.
Where copyright stops: the era’s real legal lesson, set by Apple v. Franklin and the clean-room response to it, is the line between protected code and reimplementable function, a line reverse engineers still work along today.
The security half of that legacy is the part worth sitting with. Every compatibility layer and open standard that made the PC universal also widened the attack surface, and the specific problems rhyme across the decades:
- Hardware trojans: just as budget clones shipped with substandard or substituted parts, modern hardware supply chains are targets for deliberate malicious implants.
- Firmware persistence: the boot-sector and firmware worries of the 1980s grew into today’s UEFI implants, used by nation-state actors.
- Open versus proprietary: the clone wars showed that open architectures speed up both innovation and the research that secures them, and both the attackers and the defenders. It’s the same tension we still argue about.
The IBM PC and its clones didn’t just change computing; they set the terms we still work under, openness and all its costs included. Read the history closely and you can see today’s supply-chain and firmware fights coming from a long way off.