On 21 April 2009 the Wall Street Journal reported that computer spies had broken into the Pentagon's Joint Strike Fighter project — at $300 billion, "the Defense Department's costliest weapons program ever" — on the word of current and former officials it did not name. The intruders had copied and siphoned off several terabytes of data on the F-35's design and electronic systems, among it material on diagnosing maintenance problems in flight, entering through the networks of two or three contractors; the break-ins appeared to go back at least to 2007. They had encrypted the data as they took it, so investigators could not say exactly what had gone. The most sensitive material, on flight controls and sensors, was kept on computers not connected to the internet.
On origin the paper hedged. "Former U.S. officials say the attacks appear to have originated in China," it wrote, while warning that identities were easy to mask online. China's embassy said the country "opposes and forbids all forms of cyber crimes" and called such allegations "intentionally fabricated to fan up China threat sensations". The Pentagon did not confirm the account. Lockheed Martin, the lead contractor, said it believed the Journal "was incorrect in its representation of successful cyber attacks on the F-35 program", and its finance chief, Bruce Tanner, told an earnings call: "I've not heard of that, and to our knowledge there's never been any classified information breach." The Journal stood by its story.
It was the paper's second such report that month. On 8 April it had cited current and former national-security officials who said spies from China, Russia and other countries had penetrated the American electrical grid and left behind software that could be used to disrupt it, and that many intrusions had been found by intelligence agencies rather than the companies running the infrastructure. "If we go to war with them, they will try to turn them on," a senior intelligence official said. Russia's embassy said Russia had "nothing to do with the cyberattacks on the U.S. infrastructure"; China's foreign ministry said the intrusion "doesn't exist at all". No evidence was made public, and Robert Graham of Errata Security called the article "yellow journalism" whose only source was "anonymous government officials".
Parts of the fighter story came back with names attached. In January 2015 Der Spiegel published a document from the Snowden archive recording Chinese theft of "many terabytes" of F-35 data — radar, engine schematics, ways of cooling exhaust gases; China's foreign ministry called the allegations groundless. Su Bin, a Chinese aviation businessman arrested in Canada in 2014 on an American complaint naming the F-22, the F-35 and Boeing's C-17, pleaded guilty on 23 March 2016 to conspiring with two people in China to break into defence contractors' networks; he had told them which people, companies and technologies to target, and translated what they stole. On 13 July 2016 he was sentenced to 46 months. His conspiracy began in October 2008, after the earliest break-ins the Journal described, and the Justice Department did not tie the two together.
Fifty Thousand Names a Day
Conficker's newest variant — C to the industry coalition announced in February, D to Microsoft — was written to change its habits on 1 April 2009. Instead of polling 250 web addresses a day for instructions, it would generate 50,000 across 110 top-level domains and try 500, and the coalition set out to block them. F-Secure had warned that most infected machines carried the older B variant, for which the date meant nothing, and that a peer-to-peer channel let the authors push an update on any day. On 1 April the worm began polling and little else happened. A week later the channel was used: around 7-8 April machines carrying the new variant began receiving Conficker.E, which Trend Micro caught arriving on its test machines. It restored spreading through the MS08-067 flaw, fetched a spam bot Trend Micro identified as Waledac, whose domains a court order cut off in February 2010, and installed Spyware Protect 2009, a fake anti-virus that reported invented infections and charged $49.95 to remove them. It was set to delete itself on 3 May.
Reasonable Grounds for Believing
On 14 April 2009 the European Commission opened infringement proceedings against the United Kingdom with a letter of formal notice over Phorm, a system that worked, in the Commission's words, "by constantly analysing customers' web surfing" to choose the advertisements they saw. In April 2008 BT had admitted testing it in 2006 and 2007 without telling the customers involved; complaints went to the Information Commissioner's Office and the police. The Commission's quarrel was with British law: unlawful interception was an offence only if intentional, it was lawful where the interceptor had "reasonable grounds for believing" consent had been given, and no independent authority supervised it. Viviane Reding, the commissioner responsible, said the rules "must be rigorously enforced by all Member States". In July BT said it had "no immediate plans" to deploy the system. Referred to the Court of Justice in September 2010, Britain removed implied consent from its interception law and added a sanction for unlawful interception; on 26 January 2012 the Commission closed the case. The Crown Prosecution Service had declined in April 2011 to prosecute BT or Phorm, citing insufficient evidence and no public interest.
Drawn by Lot, Twice
India began voting on 16 April 2009: 716,985,101 electors, 828,804 polling stations and 1,368,430 electronic voting machines, in five phases to 13 May, counted on 16 May. The machines ran on batteries and had no network connection, so the question was who could reach them by hand. As a guard against tampering, the Election Commission's procedure randomised them twice: a computerised draw deciding which of a district's machines went to which constituency, then a second, by the returning officer, deciding which polling station. Nobody would know in advance where a given machine would stand.
The doubts came later. Some parties, the BJP among them, questioned the machines; at a demonstration session at the Commission in August 2009, by the account of S. Y. Quraishi, chief election commissioner from 2010, a critic could not show any tampering. In April 2010 Hari Prasad, J. Alex Halderman and Rop Gonggrijp published an analysis of a real machine showing two attacks that needed hands, not a network: a look-alike part that could be told silently to steal a share of the votes, and a pocket-sized device to alter stored votes between polling and counting. Prasad spent seven days in police custody that August, over the machine's anonymous source, his co-authors said. The answer was paper: a printed trail first used at a Nagaland by-election in September 2013, directed by the Supreme Court on 8 October, and beside every machine by 2019.
After chess, IBM chooses Jeopardy!
On 27 April 2009 IBM said it was building a computer to compete against human contestants on Jeopardy!, whose clues, it argued, turned on subtle meaning, irony and riddles, at which humans excelled and computers traditionally did not. Twelve years after Deep Blue beat Garry Kasparov at chess, the goal, said David Ferrucci, who led the team, was computers that could "converse in human terms". The system, named Watson after IBM's first president, would answer in a synthesised voice, without an internet connection, from text indexed beforehand; IBM hoped for a final showdown in 2010, and the match was broadcast in February 2011. On 3 April Science had carried two papers on machines doing parts of a scientist's job. Adam, built by Ross King's team at Aberystwyth with Cambridge colleagues, framed hypotheses about which genes in baker's yeast coded for orphan enzymes and tested them robotically, its findings confirmed by hand; a program by Michael Schmidt and Hod Lipson at Cornell recovered conservation laws from the motion of oscillators and pendulums, knowing no physics.
Symantec changes chiefs, Panda scans in the cloud
On 4 April 2009 Enrique Salem became Symantec's president and chief executive, succeeding John Thompson, who had run the company for a decade and stayed on as chairman. Salem had returned with Brightmail, the anti-spam firm Symantec bought in 2004; he had first arrived in 1990, when it acquired Peter Norton Computing. Symantec's annual threat report, published that month, counted more than 1.6 million new malicious-code signatures written in 2008, more than 60 per cent of all it had ever created, and at the RSA Conference in San Francisco Salem argued that signatures alone could no longer keep pace: software should also be judged by reputation, by how long a program had been around and how many people used it. On 29 April the Spanish vendor Panda Security released a free beta of Panda Cloud Antivirus, a lightweight client that sent data about files to Panda's servers for a verdict and fell back on a small local cache when offline; Panda said anonymous data from free users would sharpen its scanning. Salem held the job until July 2012.
⏳ Time capsule — April 2009
- On 2 April the leaders of the Group of Twenty met at the ExCeL centre in east London, with Gordon Brown in the chair, and agreed what they put at $1.1 trillion for international finance, trade and recovery, including $500 billion more pledged to the International Monetary Fund's New Arrangements to Borrow and $250 billion for trade finance.
- On 11 April Britain's Got Talent broadcast the audition of Susan Boyle, from Blackburn in West Lothian, singing "I Dreamed a Dream" from Les Misérables. Within a week the clip had been viewed more than 66 million times; in the final on 30 May she came second to the dance troupe Diversity.
- On 17 April the Stockholm District Court found the four men tried over The Pirate Bay guilty as accessories to crimes against copyright law, sentencing each to a year in prison and ordering them to pay 30 million kronor, about $3.5 million. In November 2010 the Svea Court of Appeal cut three of the prison terms and raised the sum to 46 million kronor.
- On 20 April Oracle agreed to buy Sun Microsystems, the maker of Java, the Solaris operating system and the MySQL database, for $9.50 a share in cash — about $7.4 billion, a 42 per cent premium — two weeks after Sun's talks with IBM had collapsed. The purchase was completed on 27 January 2010.
Several, then many
April 2009's gravest claims rested on officials who would not be named, and the matter they raised became diplomacy only years later: in September 2015 Barack Obama and Xi Jinping said neither government would conduct or knowingly support cyber-enabled theft of intellectual property for commercial advantage. Su Bin's plea gave the fighter jets a defendant, not an inventory: the Journal's "several" terabytes became the leaked document's "many", and neither was a count. The same shape — unnamed officials, flat denials, a publisher standing by its story — returned with Bloomberg's chip report in October 2018, for which no physical evidence has surfaced.
The grid claim took longer to become a finding. What officials described in 2009 — software left behind, to be turned on in a war — came nearer in December 2015, when intruders opened breakers across three Ukrainian distributors by remote hand, and reached the record in May 2023, when Microsoft assessed that a Chinese state actor it called Volt Typhoon, working against critical infrastructure in Guam and the United States, was developing capabilities that could disrupt communications "during future crises"; Beijing called it disinformation. In between, a Vermont laptop was reported as the grid in December 2016. Conficker never matched its April headlines, but it lingered: the FBI named a variant among the delivery routes of a scareware ring broken up in June 2011, and it was still spreading through weak passwords in April 2012.