At 11:08 on the morning of Friday 29 May 2009, in the East Room of the White House, Barack Obama released the review of the government's cyber defences that he had ordered on 9 February. Sixty days had been set for it, and the report ran to 76 pages. Its team had been led by Melissa Hathaway, cyber coordination executive to the Director of National Intelligence under George W. Bush and now acting senior director for cyberspace. "From now on," he said, "our digital infrastructure — the networks and computers we depend on every day — will be treated as they should be: as a strategic national asset." He was creating an office in the White House, led by a cybersecurity coordinator he would personally select. He did not say who.
Then he made it personal. "I know how it feels to have privacy violated," he said, "because it has happened to me and the people around me." Between August and October 2008, hackers had gained access to his campaign's emails and a range of files, "from policy position papers to travel plans". The fundraising website, he added, had been untouched, and the room laughed. He named no country. He spoke of intruders probing the electrical grid; of several thousand military computers infected by malware the year before, which had made troops give up their thumb drives, a story the Pentagon told in full in August 2010; and of thieves running from "the disgruntled employee on the inside" to, "increasingly, foreign intelligence services".
The review was plainer than the speech — "the status quo is no longer acceptable" — and its near-term plan listed ten actions, from appointing a cybersecurity policy official and a privacy and civil liberties official to preparing an incident response plan and starting a public awareness campaign. The reporting line had shifted. As a candidate Obama had promised a cyber adviser "who will report directly to me"; the coordinator would instead be a member of the National Security Staff and of the National Economic Council's staff, reporting, The Washington Post had written that week, to the national security adviser and the senior economic adviser, with what Obama called "regular access" to him. He set limits too: no security standards dictated to private companies, and no monitoring of private-sector networks or internet traffic.
Nobody was appointed that summer. On 3 August Hathaway said she would leave on the 21st. "I wasn't willing to continue to wait any longer," she told The Washington Post, "because I'm not empowered right now to continue to drive the change." On 22 December, nearly seven months after the speech, the post went to Howard Schmidt, once George W. Bush's special adviser for cyberspace security and then eBay's chief information security officer. In October 2010 the Government Accountability Office found only two of the review's 24 recommendations fully implemented. Schmidt, who co-signed the administration's answer to the petitions against the anti-piracy bills in January 2012, retired that May, and the post passed to Michael Daniel.
Seven Days to Pay
On Thursday 30 April 2009 the secure website of Virginia's Prescription Monitoring Program, which pharmacists used to track prescription drug abuse, was replaced by a note claiming "8,257,378 patient records and a total of 35,548,087 prescriptions". Its author claimed to have made an encrypted backup, deleted the original and found the state's backups gone, and asked $10 million for the password; after seven days, the note said, the data would go to the highest bidder. WikiLeaks published it. The Department of Health Professions shut its computer system down, the FBI and state police investigated, and the director, Sandra Whitley Ryals, said the data had been properly backed up. By press accounts the deadline passed without incident. In June the state wrote to some 530,000 people whose records might have held Social Security numbers; no arrest was ever publicly reported. Berkeley's intruders were quieter. On 8 May the University of California, Berkeley, began telling more than 160,000 people that hackers had been in its health-services databases from 9 October 2008 until 9 April, when administrators found messages they had left.
Sixty Thousand Sites
Gumblar took its name from gumblar.cn, the domain its planted script called. On 14 May 2009 the security company ScanSafe counted more than 1,500 legitimate websites carrying the script, Tennis.com, Variety.com and Coldwellbanker.com among them. A visitor's browser was passed to pages trying known flaws in Adobe Reader and Flash Player; a Windows PC that fell began rewriting its owner's Google results and collecting FTP passwords, from network traffic and from programs such as FileZilla and Dreamweaver. Stolen FTP logins, researchers reckoned, were how the script reached more sites. The gumblar.cn domain went offline on Friday 15 May and martuz.cn took over, written in the code as "mar"+"tuz.cn", possibly to slip past blacklists. By 19 May Sophos was finding Gumblar code on 42 per cent of the newly infected websites it had detected the week before. On 3 June Google's Niels Provos wrote that Google had seen about 60,000 sites compromised for gumblar, and Martuz peaking at slightly over 35,000. The method outlived both domains: that December, Japanese reports said JR East's website had spent about two weeks exposing visitors to a Gumblar variant.
Sixteen Sensitive States
In May 2009, the month India counted its votes, the government directed BSNL, the state-owned operator, not to buy equipment from Chinese vendors for deployment in sensitive regions. Fifteen months later a written reply to the Rajya Sabha from Sachin Pilot, minister of state for communications and IT, listed them: Assam, Manipur, Tripura, Sikkim, Nagaland, Arunachal Pradesh, Mizoram, Meghalaya, West Bengal, Gujarat, Rajasthan, Punjab, Jammu and Kashmir, Himachal Pradesh, Uttarakhand and Maharashtra — every one but the last on a border with China, Pakistan, Bangladesh or Myanmar. His reason was that "participation of foreign companies in strategic sector has bearing on national security", and that BSNL's network "has to be relied upon in emergency". The worry, as Voice&Data reported it, was that Chinese equipment "might have spying technologies embedded to intercept sensitive conversations and government communications".
The map decided orders. Huawei had been the lowest bidder for BSNL's west zone, Business Standard reported that November, but got no order there, because of government concerns about Chinese equipment in border areas; in the south zone, outside the map, BSNL placed an advance purchase order with it for 20 million GSM lines. According to The Tribune, the Intelligence Bureau had argued at a meeting on 9 April that for sensitive communications "distinction in terms of zones was irrelevant", and had warned of "little or no capability to test and certify" routers and switches before deployment. In August 2010 Pilot told the Rajya Sabha that guidelines drawn up with the Home Ministry let BSNL buy from Chinese vendors again. The clearance rules imposed on every operator from December 2009, and their slow turn towards testing, run through March 2010, July 2010 and May 2011.
Wolfram|Alpha answers by computing
On the evening of Friday 15 May 2009, webcasting the preparations live on Justin.tv, Stephen Wolfram's company switched on Wolfram|Alpha, which it called the first "computational knowledge engine"; the official launch followed on 18 May. Instead of listing web pages, it parsed a question typed in ordinary language and computed an answer from curated data, running nearly six million lines of Mathematica code on about 10,000 processor cores in five data centres. Reviews were mixed. The Register's reviewer found it could tell Cambridge in England from Cambridge, Massachusetts, by where a question came from, but was lost beyond the data it held, and thought the weekend's hype its greatest threat. At its Searchology event on 12 May Google had shown Google Squared, which gathered facts from across the web into a table; it opened in Google Labs on 3 June and closed on 5 September 2011. Wolfram|Alpha outlasted it, and on 23 March 2023 was among the first plugins offered for ChatGPT, supplying computation a language model could not perform reliably.
McAfee buys into whitelisting
On Friday 15 May 2009 McAfee agreed to buy Solidcore Systems, a maker of application-whitelisting software, for about $33 million in cash, with up to $14 million more if performance targets were met. Anti-virus blocked known bad code; Solidcore let only approved software run, on servers and on fixed-function devices such as cash machines, point-of-sale tills and utilities' control systems. It counted about 1,000 customers, NCR, Dell and General Motors among them, and more than 200,000 protected endpoints. McAfee meant to pair it with its own compliance tools under the ePolicy Orchestrator console; Candace Worley, a McAfee vice-president, also saw a use in "securing a virtual environment". Late in May AV-Comparatives published a retrospective test that set sixteen products, frozen with their February updates, against malware that had appeared since. Only ESET, Kaspersky and Microsoft's Live OneCare earned its top Advanced+ rating, OneCare catching 60 per cent with the fewest false alarms. McAfee completed the purchase on 1 June; the software is sold in 2026 as Trellix Application Control.
⏳ Time capsule — May 2009
- On 11 May Atlantis lifted off from the Kennedy Space Center on STS-125, the fifth and final servicing mission to the Hubble Space Telescope. In five spacewalks the crew, commanded by Scott Altman, installed Wide Field Camera 3 and the Cosmic Origins Spectrograph and repaired two other instruments; the shuttle landed at Edwards Air Force Base on 24 May.
- On 14 May an Ariane 5 rose from the Guiana Space Centre carrying two observatories at once: Herschel, whose 3.5-metre mirror was the largest yet sent into space, and Planck, built to map the faint variations in the cosmic microwave background. Both were bound for the second Lagrangian point, 1.5 million kilometres from Earth.
- On 16 May India counted the votes of its election to the fifteenth Lok Sabha, cast in five phases from 16 April; the Congress-led United Progressive Alliance won 262 seats. On 22 May Manmohan Singh was sworn in again, the first prime minister since Jawaharlal Nehru in 1962 to win re-election after a full five-year term.
- On 27 May, at the Stadio Olimpico in Rome, Barcelona beat Manchester United 2–0 in the Champions League final, Samuel Eto'o scoring in the tenth minute and Lionel Messi in the seventieth. It completed a treble of La Liga, the Copa del Rey and the Champions League, a feat no Spanish club had achieved before.
An office written into law
The coordinator's post did not last in the form Obama gave it. Rob Joyce, its last holder, left on 11 May 2018, and John Bolton, then national security adviser, eliminated it, to "streamline authority" in the words of a memo to the National Security Council's staff. Congress then wrote a version of the job into statute: the defence authorisation act for fiscal 2021 created a National Cyber Director, with an office of its own and a director confirmed by the Senate. Chris Inglis took office in July 2021; Sean Cairncross, the third to be confirmed, in August 2025. What the review asked for in May 2009, one official in the White House responsible for coordinating the nation's cybersecurity policies, is now a matter of law, beyond the reach of a memo.
The campaign disclosure acquired an attribution. In June 2013 NBC News, citing US intelligence officials, reported that the 2008 intrusions, into John McCain's campaign as well, had been traced to hacking units backed by China; Dennis Blair, Obama's first director of national intelligence, called it political cyberespionage by the Chinese government. The Chinese embassy declined to comment; Beijing's standing line was that it opposed all forms of cyberattack. Campaigns were targets again in 2016, through a forged alert that reached John Podesta's inbox in March and intrusions at the Democratic National Committee disclosed in June. The Virginia note was early too: a locked copy and a threat to sell, close kin to the pressure Maze made an industry of in December 2019; the threat alone reached Finnish therapy patients, one by one, in October 2020.