On 23 October 2008, with attacks already circulating, Microsoft broke its monthly routine to publish MS08-067, a fix for the Server service, the part of Windows that shares files and printers. A crafted request could run code on an unpatched machine, on Windows 2000, XP and Server 2003 without any password, and the bulletin warned that the flaw could be used in "a wormable exploit". The worm came on about 21 November: Microsoft called it Conficker, F-Secure and Symantec Downadup. A second version, which Microsoft catalogued on 29 December, added two routes that needed no flaw at all. It tried network shares against a list of more than 240 common passwords, and it copied itself onto USB sticks with an AutoPlay entry reading "Open folder to view files".
No one could count the infected machines directly, but each called home. Every day the worm computed 250 domain names and checked them for new code, and F-Secure, in Finland, had registered some. On Tuesday 13 January it estimated 2.4 million infections, the next day 3.5 million, and on Friday 16 January nearly nine million: each call carried a number the worm raised whenever it infected another machine, and F-Secure had added the numbers up. Other researchers doubted the arithmetic, suspecting that some machines were counted more than once. SRI International's later census put active infections at about a million for the first version and under three million for the second, and warned that reinfections could inflate F-Secure's counter.
By most accounts it had reached warships. The Ministry of Defence said on 15 January that a virus it would not name had affected its systems since 6 January; NavyStar desktops on Royal Navy ships, the carrier Ark Royal among them, had lost the email sailors used to write home. Reports put three-quarters of the fleet's ship networks among the infected; the ministry neither confirmed nor denied, and said no operational system was hit. In mid-January the worm reached the French Navy's Intramar network, which was cut off while the navy fell back on telephone, fax and post. Libération reported in February that naval Rafale fighters had been grounded on 15 and 16 January for want of flight plans. The Defence Ministry denied it.
Sheffield's hospitals had lowered their own guard. In Christmas week, after computers in an operating theatre rebooted in the middle of surgery, Sheffield Teaching Hospitals' IT change advisory board switched off automatic updates on all 8,000 of its PCs, The Register reported; the trust spoke of "problems with a number of PCs in theatres". More than 800 were infected, and non-urgent imaging appointments were cancelled while machines were cleaned. Within a month Microsoft would put up a reward and a coalition would be registering the worm's domains before it could call them, as February records, and a later version was set to change its habits on 1 April. No one has been publicly charged with writing it. Its first version shut itself down on machines set to a Ukrainian keyboard layout; three years on it was still spreading through guessed passwords, as April 2012 records.
A Word from the Dictionary
On the night of 4 January 2009 an intruder set an automated password guesser against a Twitter administrator's account and left it running. Staff signed in to the administrative controls on the same page as every user, and nothing stopped thousands of wrong guesses; the password, he told Wired, was "happiness". Almost every employee held those controls, which could reset any user's password. He reset some and posted them on a website for others to use, and on Monday 5 January the accounts of Barack Obama, then president-elect, Britney Spears, Fox News and CNN's Rick Sanchez posted false and crude messages; Obama's offered his more than 150,000 followers a chance at $500 of free petrol for filling in a survey. Twitter suspended the accounts, took its support tools offline, confirmed a dictionary attack and counted 33 compromised. The Federal Trade Commission, whose settlement announced in June 2010 also covered an intrusion that April through an employee's personal email, counted unauthorised tweets from nine; its order, final in March 2011, required a security programme audited every other year for ten years. In July 2020 intruders reached Twitter's internal console by telephone.
A Small Republic Offline
From 18 January 2009 the two companies carrying most of Kyrgyzstan's internet traffic, about 80 per cent by one estimate, were flooded with junk requests. Don Jackson of SecureWorks said on 28 January that most traffic in and out of the country had been blocked for a week, and email to and from the American air base at Manas disrupted. Most of the attacking machines were in Russia, he said, and the flood bore the signature of the pro-Russian nationalists believed to have attacked Georgia in August 2008; the culprits were most likely Russian citizens recruited by officials. That was his reading, not a finding. His team offered two motives, silencing an opposition coalition or pressing President Kurmanbek Bakiyev over the base. Arbor Networks, which saw no attack traffic, put that down to not watching the right botnets. The providers limited the damage by moving big customers to new addresses; some opposition and media sites stayed dark. On 3 February, after Russia agreed $2 billion in loans and $150 million in aid, Bakiyev said the base would close; renamed a transit centre, it stayed until June 2014.
The Super User
On 7 January 2009 B. Ramalinga Raju, chairman of Satyam Computer Services, wrote to his board that ₹5,040 crore of the ₹5,361 crore in cash and bank balances on its books on 30 September did not exist. With interest that had never accrued, a liability kept off the books and inflated receivables, the hole came to ₹7,136 crore. "It was like riding a tiger," he wrote, "not knowing how to get off without being eaten." Satyam ran computer systems and back offices for more than a third of the Fortune 500. Its shares lost more than 70 per cent that day; Raju was arrested on 9 January and the government replaced the board. By 19 January State Farm had ended its contract; about 400 Satyam staff had worked on its technology projects. "These people didn't do anything wrong," said a State Farm spokesman.
Investigators described the fraud in the language of systems. The CBI said an emergency facility for loading invoices from spreadsheets into Satyam's Invoice Management System had been used to raise 7,561 false ones, worth about ₹5,100 crore, and that a "Super User" ID hid them from every division but finance, which booked them as receivables. In 2007 the head of internal audit found invoices for Agilent, Citigroup and Bear Stearns that did not match the Oracle ledger the system fed; his team lost access, and in July 2008 he closed the findings on the managing director's instructions, SEBI found. Tech Mahindra won control on 13 April 2009. On 9 April 2015 a special court sentenced Raju and nine others to seven years; on 11 May a sessions court suspended the sentences pending appeal.
Microsoft's Songsmith picks the chords
On 8 January 2009, at the Consumer Electronics Show in Las Vegas, Microsoft Research released Songsmith, a $29.95 Windows program that generated accompaniment, in any of 30 styles, for whatever a person sang. It grew out of MySong, built by Dan Morris and Sumit Basu with Ian Simon of the University of Washington: a hidden Markov model trained on 298 lead sheets, each a melody with its chords, learned which notes went with which chords and which chords followed which, and a slider its designers called the "happy factor" made the result happier or sadder. The promotional video became a target of derision, watched hundreds of thousands of times within weeks, and a genre of parody grew up on YouTube, feeding famous rock vocals through the program. On 20 January Google's computer-vision team described how YouTube had stopped taking thumbnails at fixed points in each video and let an algorithm pick representative frames; a deep neural network took over the job in October 2015. Songsmith is still offered in 2026, free to teachers for classroom use.
Symantec takes a $7 billion write-down
On 28 January 2009 Symantec reported a net loss of $6.81 billion for the quarter to 2 January, against a profit of $132 million a year earlier. Its operating profit had beaten forecasts. The loss came from a charge of about $7 billion against goodwill, the premium paid in past acquisitions, and the company put the charge down to the economy and a fall in its market value. Sales were flat at $1.51 billion, and the consumer business grew 2 per cent. On 13 January AVG Technologies, best known for its free anti-virus program, had bought Sana Security of Redwood City, California, for an undisclosed sum. Sana's software learned how applications normally behaved and stepped in when malware forced them off that path, rather than matching signatures; behaviour-based protection, The Register noted, was "moving into vogue". Symantec's Norton AntiBot, launched in 2007, had been built on Sana's engine. AVG and Norton ended up under one roof: Avast bought AVG in 2016, and in 2022 Symantec's consumer business, by then NortonLifeLock, bought Avast and became Gen Digital.
⏳ Time capsule — January 2009
- On 3 January Satoshi Nakamoto, a pseudonym, mined the first block of Bitcoin, a currency kept by its users' computers rather than a bank, and wrote into it a headline from that day's Times: "Chancellor on brink of second bailout for banks". The software was released on 9 January, and on 12 January Nakamoto sent ten bitcoins to Hal Finney in the first transaction.
- On 15 January US Airways Flight 1549, an Airbus A320 climbing out of LaGuardia for Charlotte, flew into a flock of Canada geese and lost thrust in both engines. Less than four minutes later Captain Chesley Sullenberger and First Officer Jeffrey Skiles brought it down on the Hudson off Midtown Manhattan, and all 155 people aboard survived.
- On 20 January, on the West Front of the Capitol, Barack Obama took the oath as the 44th president from Chief Justice John Roberts, on the Bible Abraham Lincoln had used in 1861. Roberts misplaced the word "faithfully", and the oath was given again the next evening in the White House Map Room, without a Bible.
- On 23 January an H-IIA rocket lifted off from Tanegashima carrying Ibuki, the Greenhouse Gases Observing Satellite built by JAXA with Japan's environment ministry and National Institute for Environmental Studies: the first satellite dedicated to measuring carbon dioxide and methane from orbit.
What no patch could fix
January 2009 showed that a patch is not a cure. Conficker spread first through machines the October fix had not reached, then through what no fix could reach: a guessable password, a USB stick, a hospital that had turned updates off after its theatre computers restarted. From February 2011 Windows Update stopped older versions of Windows offering to run programs from a USB stick, and in June 2011 a scareware ring the FBI said had used the worm as one delivery route was broken up; there is still no update for a guessable password. In May 2017 a worm built on another Windows file-sharing flaw, patched two months before, disrupted a third of England's hospital trusts before a newly registered domain halted its spread, as Three Days in May records.
The month's other stories have their sequels here too. Twitter's staff had signed in to its administrative controls on the public login page; in July 2020 intruders talked employees out of credentials for its internal console and tweeted from Barack Obama's account again. The accusation against Russia over Kyrgyzstan rested on a researcher's reading of the traffic; when floods hit Ukraine's banks in February 2022, the American and British governments named Russia's military intelligence within three days. Satyam's kind of gap, between one system's records and another's, reopened at Punjab National Bank in February 2018. The month's largest breach, disclosed by Heartland on inauguration day, is told in August. For now this is where the archive begins, and 2008 and the years before it are still to be restored.