To save a slideshow on RockYou, a user had to type in an email address and the password to that email account. The company, founded in San Francisco in late 2005 by Lance Tokuda and Jia Shen, made widgets for MySpace and Facebook — slideshows first, games later — and by the end of 2007 had more installations on Facebook than any other widget maker. On the evening of Monday 14 December 2009 TechCrunch reported that a hacker had reached its user database through SQL injection, a technique documented for more than a decade, and had counted 32,603,388 accounts, the passwords stored exactly as typed. The hacker, who wrote as igigi, had posted a sample with the passwords masked, and a warning: "Don't lie to your customers, or i will publish everything."

The dates did not agree. RockYou said its IT team had been alerted on 4 December that the database had been compromised, "potentially revealing some personal identification data for approximately 30M registered users", and had taken the site down and patched it. Imperva, a database-security firm, said it had learned of the flaw and its exploitation from underground forums and warned RockYou over the weekend of 12–13 December; Computerworld reported that the hole stayed open for at least a day afterwards. RockYou began telling users only once the story was out, ten days after its own date. Its notice conceded that the database held "the usernames and passwords for about 32 million users in an unencrypted format", with their email addresses, and told anyone who reused them to change their email passwords.

Then the hacker posted all 32 million passwords, stripped of names and addresses, and Imperva's Application Defense Center studied them, observing that there had never before been such a volume of real passwords to examine. Its report, Consumer Password Worst Practices, published in January 2010, found 290,731 accounts using 123456, followed by 12345, 123456789, Password and iloveyou; "rockyou" itself came seventh. About 30 per cent of the passwords were six characters or fewer, the site's minimum being five; about 40 per cent used only lower-case letters, fewer than 4 per cent any special character, and 0.2 per cent passed two of NASA's basic tests of strength. Imperva calculated that guessing 123456 alone would open one account in every 111 tried, and that the 5,000 commonest passwords covered a fifth of all users.

The endings were civil, and small. A user of RockYou's photo application sued on 28 December; in April 2011 a federal judge let his claims of breach of contract and negligence proceed, and the settlement filed that November proposed $2,000 for him, $290,000 for his lawyers, nothing for the class, and two security audits in three years by an auditor RockYou chose, the company saying it could not afford damages. On 27 March 2012 the Federal Trade Commission announced that RockYou had agreed to settle charges that it failed to protect 32 million users and collected data from about 179,000 children without parental consent: a $250,000 civil penalty on the children's-privacy charges, and independent audits every other year for twenty years. RockYou filed for Chapter 7 bankruptcy on 13 February 2019.

Also that month · 17–18 December

An Hour at Another Address

From 9.46 p.m. Pacific time on Thursday 17 December 2009 until about eleven — early on Friday in Europe — about 80 per cent of twitter.com's traffic went elsewhere: a black page with a green flag, the words "This site has been hacked by Iranian Cyber Army", an English taunt about American control of the internet, Persian verses pledging obedience to Iran's Supreme Leader, and an email address. Twitter's servers were never touched. Someone had signed in to its account at Dyn, which ran its DNS, with what Dyn's chief technology officer, Tom Daly, called "a set of valid Twitter credentials", and pointed the name elsewhere; the API went on working. Twitter said the motive "appears to have been focused on defacing our site, not aimed at users". The same banner appeared on mowjcamp.org, a pro-opposition Iranian site. The name was the attackers' own: some reports tied the group to the Iranian state, and some doubted Iranians were involved at all. On 12 January the name reached Baidu, which blamed its registrar and sued. State control of the group has never been publicly shown.

Also that month · 17 December

Twenty-Six Dollars of Software

On 17 December 2009 the Wall Street Journal reported that Shiite militias in Iraq had been capturing the live video American Predator drones relayed by satellite, using SkyGrabber, a $25.95 program sold by a Russian firm, SkySoftware, for pulling films, music and pictures out of satellite data. The feeds were not encrypted. In the Journal's account the military had found intercepted video on a captured militant's laptop late in 2008 and on others in July 2009, believed the groups were funded and trained by Iran, and had known of the weakness since the 1990s Bosnia campaign but assumed no adversary could exploit it. Officials said Robert Gates had had James Clapper, his under-secretary for intelligence, review the problem and that the feeds were being encrypted, though upgrading every aircraft and ground receiver would take years; they said there was no evidence the militants could jam the aircraft or take control of them. Nothing had been hacked, as several former officials pointed out: a signal sent in the clear had simply been received.

India desk · December 2009

Twenty-One Databases

On 23 December 2009 the Union home minister, P. Chidambaram, gave the Intelligence Bureau's centenary endowment lecture in New Delhi and called it "A New Architecture for India's Security". A year after taking the ministry in the wake of the Mumbai attacks, he described police stations as "virtually unconnected islands" and national databases that did not talk to one another. His remedy was NATGRID, under which "21 sets of databases will be networked" for intelligence and enforcement agencies within 18 to 24 months, and above it a National Counter Terrorism Centre, running by the end of 2010, with intelligence, investigation and operations under one head. He spoke eight days after an emailed trojan was aimed at the national security adviser's own office, an attack disclosed in January.

The centre never opened: when the government moved to create it in February 2012, chief ministers across party lines objected to its powers of search and arrest, and it was shelved. NATGRID came more slowly and without a statute. The Cabinet Committee on Security approved its project report in principle on 6 June 2011, a notification three days later put it outside the Right to Information Act, and no law has been passed to govern it. It was due to go live on 31 December 2020; by December 2025 it was fielding about 45,000 requests a month, had been opened to police superintendents and linked to the population register's details of 119 crore residents. The 2023 data-protection law lets the government exempt any agency it notifies on security grounds; what that law asks of everyone else is on our India desk.

AI Tech desk · December 2009

Google Goggles searches by sight

On 7 December 2009 Google released Goggles, a Labs application for Android 1.6 and later that sent a photograph to Google's data centres, matched it against known objects and returned search results. Vic Gundotra, vice-president of engineering, wrote that it identified landmarks, works of art and products, and that visual search would one day be "like a mouse for the real world". Reviewers found it good with book and DVD covers, logos, paintings and business cards and poor with food, cars, plants and animals; faces were left out, Google saying it first had to understand the privacy implications. On 12 December, at the NIPS workshops in Whistler, Li Deng and Dong Yu of Microsoft Research and Geoffrey Hinton of Toronto held a day on deep learning for speech recognition, where Hinton's students reported deep belief networks outperforming other techniques at recognising phones in the standard TIMIT corpus. Goggles learned to translate in February. Deng later reckoned deep networks were running in large-scale recognisers within eighteen months; Microsoft's own underpinned the English-to-Mandarin speech translation it showed in October 2012.

Digital Guard desk · December 2009

Fifteen products against a hundred websites

On 17 December 2009 AV-Comparatives released what it called its first public whole product dynamic test. Instead of scanning files, four people spent nearly twelve hours a day, from 16 to 26 November, pointing sixteen identical PCs at freshly crawled sites carrying exploits and malware, about thirty of them on Chinese domains, and recording what each product stopped; the machines ran Windows XP and Internet Explorer 7, which the lab judged typical of home users. Of 100 valid cases Symantec and Kaspersky blocked 99, Norman 74 and Kingsoft 60; Sophos, whose product was built for businesses, declined to take part. The Austrian lab's summary of the year named Norton the best product of 2009, ahead of Kaspersky and ESET, remarking that a program once "known to be a resource hog" now had a very low system impact. Virus Bulletin had opened the month with a record 43 products in its VB100 test on Windows 7, released in October. The lab promised a larger, automated version for 2010; the test it grew into, now the Real-World Protection Test, still runs.

⏳ Time capsule — December 2009

  • On 1 December the Treaty of Lisbon, signed on 13 December 2007, came into force, giving the European Union legal personality, making its Charter of Fundamental Rights binding and creating a full-time President of the European Council; the leaders had chosen Belgium's prime minister, Herman Van Rompuy, for the post on 19 November.
  • On 9 December, the eleventh day of a fast by K. Chandrashekar Rao, the Union government announced that it would start the process of forming a separate state of Telangana; on 23 December it said nothing would be done until there was consensus. Telangana was created on 2 June 2014, with Rao as its first chief minister.
  • From 7 to 18 December the United Nations climate conference met at the Bella Center in Copenhagen. The accord drafted on its last day by the United States, China, India, Brazil and South Africa aimed to hold warming below 2 °C and pledged $30 billion to developing countries over three years, rising to $100 billion a year by 2020; on 19 December the conference agreed only to take note of it.
  • On 25 December 3 Idiots opened in India: Rajkumar Hirani's film, loosely adapted from Chetan Bhagat's novel Five Point Someone, with Aamir Khan, R. Madhavan and Sharman Joshi in the title roles. It was the highest-grossing Indian film until Dhoom 3 passed it in 2013.
Where it stands today — 2026

The list that outlived the company

December 2009 handed the security industry its first large look at how people actually choose passwords, and it did so because a company had kept them as typed. Nothing in the failure was new — TechCrunch called the injection technique more than a decade old — and it kept recurring: Yahoo Voices in July 2012, plain text behind an injection flaw again; Adobe in October 2013, passwords encrypted where they should have been hashed. RockYou is gone; its file is not. Kali Linux still ships rockyou.txt, some 14.3 million lines, in its wordlists package; the name was borrowed for compilations of 8.4 billion entries in 2021 and a claimed 9.9 billion in 2024, and the compiling reached sixteen billion credentials in June 2025.

The month's other lessons lay around systems rather than inside them. Twitter's servers were never touched; the account that told the internet where to find them was enough, and when Dyn itself was flooded in October 2016 Twitter went dark again. The drone video had gone out in the clear since the Bosnia campaign because encryption cost money and complicated sharing with allies, and nobody expected an adversary to tune in. Albert Gonzalez pleaded guilty in Boston on 29 December over Heartland, whose network his indictment said had been entered by SQL injection; his sentence is in July 2013. And in the last weeks of the year Google was detecting the intrusion it would disclose on 12 January, the story that opens January 2010.