The worm whose surge January recorded took its orders from no fixed server. Each day every infected PC computed 250 domain names — across five top-level domains in variant A, eight in variant B, which added .cn, .ws and .cc — and tried them for new code. The worm's authors needed only one of the day's names to answer; defenders had to hold every one. Yet anyone with the code could compute the lists: at SRI International, Phillip Porras's team found that winding forward the clocks of infected laboratory machines showed the names for days not yet come. Since November some researchers had been registering them in advance, by hand and at their own expense.
The precedent was Srizbi: in November 2008 FireEye had registered that botnet's fallback domains until the cost stopped it, and soon after it quit, someone else took them and the botnet came back. In late January the Shadowserver Foundation opened a mailing list for the effort. Neustar, which runs .biz, asked ICANN to waive its fees, the first such request ICANN had received, and it agreed. The core group met at a DNS security symposium in Atlanta on 3–4 February; China's .cn administrators signed on once a holiday was over. On 12 February Microsoft named the coalition — ICANN, VeriSign, Neustar, Afilias, CNNIC, Symantec and F-Secure among them — and offered $250,000 for information leading to the arrest and conviction of those who launched the worm. Members called themselves the Cabal; the lasting name was the Conficker Working Group.
The aim was that every name the worm tried should already be spoken for. Keeping it so was daily work, often on volunteers' nights and weekends: each day's list generated, registered and checked, every clash with a name someone already owned researched. The worm kept arriving elsewhere. On 13 February German reports said several hundred Bundeswehr computers were infected, and by 16 February a Defence Ministry spokesman had confirmed it, adding that some offices had been cut off from the forces' network to stop the spread. At Manchester City Council that month staff lost email and printing, and 1,609 bus-lane fines missed their legal deadline. The council blamed a memory stick; the bill, reported that summer, was about £1.5 million, mostly clean-up, consultants and new terminals.
Within days of the announcement came what looked like an answer. A variant SRI dated to 16 February and Microsoft to the 20th — B++ to SRI, Conficker.C to Microsoft — could take new code by two routes that needed no domain at all, developed, SRI suggested, perhaps in answer to the coalition's work; a rewrite would, from 1 April, pick 500 names a day from 50,000. Rick Wesson of Support Intelligence had been registering names since November, paying for them himself by the writer Mark Bowden's later account; the reward was meant to end with the authors in court and the money paid. Seventeen years on, the record shows neither: no one has been publicly identified as Conficker's author, and nothing shows the $250,000 paid.
The Picture in the PDF
On 19 February 2009 Adobe warned of a critical flaw in Reader and Acrobat 9 and earlier, with reports that it was being exploited. The Shadowserver Foundation had found booby-trapped PDF files in what it believed was a small set of targeted attacks, one variant installing a remote-access trojan called Gh0st RAT. Symantec said it had known of the flaw since 12 February and had seen it used only in a few attacks on victims chosen in advance. The flaw lay in the handling of JBIG2 image streams, a compression format for black-and-white scanned pages. Adobe promised a fix for version 9 by 11 March. The interim advice was to switch off JavaScript, which the exploits used to arrange memory, until Secunia built a working exploit without it. Sourcefire's researchers did not wait: within days they published an unofficial patch for Reader 9 that replaced the vulnerable library file, and the SANS Internet Storm Center urged anyone tempted to test it first. Adobe's own, version 9.1, came on 10 March, a day early; versions 8 and 7 followed on 18 March, Reader for Unix on 24 March.
Forever, for a Fortnight
On 4 February 2009 Facebook revised its terms of use. The old text said that when members removed what they had posted, the licence Facebook held over it expired; the new one dropped that and let the licence outlive the account. Few noticed until Sunday 15 February, when Chris Walters of the Consumerist read it as Facebook claiming the right to use anything members uploaded, in any way, for ever. A protest group passed 80,000 members, and the Electronic Privacy Information Center prepared a complaint to the Federal Trade Commission. Mark Zuckerberg first wrote that Facebook would not share information in ways people did not want; on 18 February it went back to its old terms, saying it had never meant to claim ownership of anyone's content. On 26 February it published draft principles and a statement of rights and responsibilities, promising that a vote would bind it if 30 per cent of active users took part. In April about 600,000 voted, some 74 per cent in favour, and Facebook, treating the result as advisory, adopted them. In December 2012, with 589,141 of 668,872 voters against, it abolished the votes.
Other People's Posts
On 24 February 2009 the Times of India reported that the Supreme Court had refused to shield a nineteen-year-old computer science student from Kerala from a criminal case over an Orkut community he had started against the Shiv Sena. The posts at issue were mostly anonymous members', accusing the party of dividing the country by region and caste. In 2008 a Sena office-bearer complained to the police in Thane, and a case was registered under sections 506 and 295A of the Penal Code, for criminal intimidation and outraging religious feelings. Police, reports said, traced him through his Orkut and Gmail accounts to his home in Kerala; he was not there, and they took his hard disk. With anticipatory bail from the Kerala High Court, he asked the Supreme Court to quash the complaint.
His counsel argued that the posts had stayed within the community and that he would be in danger in a Maharashtra court. Chief Justice K.G. Balakrishnan and Justice P. Sathasivam would not quash the proceedings: he was a computer student and knew how many people read such sites, and if someone filed a criminal case over the content he would "have to face the case". The paper read it as a warning to anyone who opened a blog to others' comments behind a disclaimer; Indian bloggers took it up at once. Reports this archive could find do not say how the case ended. The amended IT Act, signed that month, brought Section 66A into force in October; Thane district and section 295A met again in November 2012, over a Facebook post in Palghar, and the Supreme Court struck 66A down in March 2015.
A singularity school at NASA Ames
On 3 February 2009, at the TED conference in Long Beach, Ray Kurzweil and Peter Diamandis of the X Prize Foundation unveiled Singularity University, housed under a lease at NASA's Ames Research Center in Silicon Valley, with Google among its founding sponsors. The Financial Times called it a school to prepare scientists for "an era when machines become cleverer than people"; the researchers who met at Asilomar at the end of the month, in the panel July recounts, were, their chairs later reported, broadly sceptical of any coming singularity. Modelled on the International Space University, which Diamandis had helped to found, the school would not be accredited. Its core was a nine-week summer programme for graduate students at $25,000, covering ten fields, artificial intelligence and robotics among them, with shorter courses for executives. Classes began on 29 June with forty students from thirteen countries, twenty-five of them on full or partial scholarships. In 2013 the school became a for-profit company, and in 2019 it left NASA's campus for Santa Clara.
Security firms' own websites fall to SQL injection
On 7 February 2009 a Romanian who wrote as unu showed that the new version of Kaspersky Lab's US support site, rolled out in late January, was open to SQL injection; its database held about 2,500 customers' email addresses and some 25,000 activation codes. Kaspersky took the server down, and the audit it commissioned from David Litchfield of NGS Software found attempts on customer data had failed: "At no point was customer data accessed." A BitDefender partner's site in Portugal followed on 9 February, giving up customers' personal details and email addresses, though BitDefender said the site held no card data; then came an F-Secure server holding only statistics already public, which the attackers could read but not change. On 19 February Symantec pulled its partners' download centre after a similar claim, then said there was no vulnerability: the report had rested on an error message. Later intruders wanted more: a SQL injection began the break-in that took Bit9's code-signing certificate, disclosed in February 2013, and Kaspersky reported Duqu 2.0 inside its own network in June 2015.
⏳ Time capsule — February 2009
- On 1 February, in Melbourne, Rafael Nadal beat Roger Federer 7–5, 3–6, 7–6, 3–6, 6–2 in four hours and 23 minutes, after a semi-final against Fernando Verdasco that had lasted five hours and 14 minutes. It was his first Australian Open, his first major on a hard court and his sixth in all; no Spaniard had won the title before.
- On 10 February, 789 kilometres above Siberia's Taymyr Peninsula, Iridium 33, a working American communications satellite, and Kosmos 2251, a Russian military satellite switched off in 1995, collided at about 11.7 kilometres a second — the first such collision between two satellites. By July 2011 more than 2,000 large fragments had been catalogued.
- At 23:31:30 UTC on Friday 13 February, Unix time — the count of seconds since the start of 1970 by which Unix-like systems keep the date — reached 1234567890. Programmers held parties around the world to watch the counter pass, and Google marked the moment with a doodle.
- On 22 February, at the 81st Academy Awards in Los Angeles, Slumdog Millionaire won eight Oscars from ten nominations, among them best picture and best director for Danny Boyle. A. R. Rahman won two, for the score and, with the lyricist Gulzar, for the song "Jai Ho"; Resul Pookutty shared sound mixing with Ian Tapp and Richard Pryke.
Every door, every day
The Working Group's own review — written by the Rendon Group with Department of Homeland Security funding, dated June 2010 and published in January 2011 — called keeping the botnet from its author the group's biggest success and cleaning infected machines its biggest failure: millions of A and B infections remained. Both verdicts held. ICANN turned its fee waiver into a standing process for registries facing attacks on the domain system, and the method moved into court, where a sealed order cut Waledac from 277 domains in February 2010 and court orders pulled GameOver Zeus's traffic onto a server the FBI controlled in June 2014. Registering a malware family's future names stayed a way of counting it, too, as Doctor Web showed with Flashback's Macs in April 2012.
The month's other stories ended in design rather than arrests. F-Secure counted a malicious PDF in almost half the targeted attacks it saw in the first four months of 2009. Adobe put Reader inside a sandbox in November 2010; in December 2011 it patched a flaw already used in targeted attacks in the older versions first and left the sandboxed one until January, and in February 2013 MiniDuke arrived through a way out of it. Facebook's fortnight set a pattern of change, outcry and partial retreat that Instagram repeated in December 2012, and the question of what members had actually agreed to share came back, with Cambridge Analytica, in March 2018.