The Washington Post had the story on 24 August 2010, from an advance copy of an essay written for the September/October issue of Foreign Affairs, which the magazine posted the next day. The news was in the first paragraph. "In 2008," wrote William J. Lynn III, the deputy secretary of defense, "the U.S. Department of Defense suffered a significant compromise of its classified military computer networks." An infected flash drive had been inserted into a military laptop at a base in the Middle East, and its code, "placed there by a foreign intelligence agency," had uploaded itself onto a network run by Central Command and spread undetected on classified and unclassified systems, "establishing what amounted to a digital beachhead." He called it "the most significant breach of U.S. military computers ever".
What it left out mattered as much. It named no agency and no country and did not name the worm; it said data could be transferred, not that any had been; and it did not say how the drive came to carry the code — the car park that later retellings supplied is not in it. The worm had a name already. Wired's Danger Room had reported "a virus called Agent.btz" in November 2008, when Strategic Command suspended the use of removable storage, and the Los Angeles Times had written that defence leaders had taken "the exceptional step of briefing President Bush" on an attack that "may have originated in Russia". The code was a variant of SillyFDC, which Symantec had rated "Risk Level 1: Very Low" in 2007.
Some of the troops who had cleaned it up doubted the spy story. "The code was used by Russian hackers before. But who knows?" one officer told Danger Room on 25 August, and an officer who took part said how much was grabbed, whether it got out and who got it was "all unclear". Lynn, by telephone, said only: "It was tied to a foreign intelligence service." Asked why a spy service would mount something so feeble, he allowed that "It isn't the most capable threat," and added: "But that kind of makes the point." The clean-up, Operation Buckshot Yankee, took nearly fourteen months of stop-and-go work; Strategic Command's General Kevin Chilton had asked how many computers were on the network and "couldn't get an answer in over a month".
The fuller account came in December 2011, when the Washington Post reported that National Security Agency analysts had found the program in October 2008 because it was beaconing — trying to reach its makers from inside the classified networks — and had written a response that put it to sleep. The ban on thumb drives, the operation's most controversial order, drew a backlash from officers who used them for combat imagery and after-action reports, and lasted until February 2010. Buckshot Yankee did not create Cyber Command: Robert Gates ordered the command in June 2009, and the brass had been weighing such a consolidation before November 2008. By Danger Room's account the operation "turbo-charged" it. Lynn returned in July 2011 with the department's first cyber strategy.
Messages Kept Offshore
On 1 August 2010 the United Arab Emirates' Telecommunications Regulatory Authority said BlackBerry Messenger, email and web browsing would be suspended from 11 October, because certain services "allow users to act without any legal accountability, causing judicial, social and national security concerns," and because data was "immediately exported off-shore, where it is managed by a foreign, commercial organization." The Emirates had history with the device: in July 2009 the operator Etisalat pushed subscribers a "performance enhancement" patch that independent programmers found was built to intercept their communications and send email to its servers, and Research In Motion published a guide to removing it. On 3 August Saudi Arabia's regulator ordered Messenger halted from 6 August. Beyond a reported four-hour outage, the order did not take hold; a Saudi official said RIM and the operators were testing three servers through which the kingdom's traffic would pass, and on 10 August the regulator said it had "decided to allow the continuation" of the service. RIM told customers that for corporate mail it had no "master key" and that no "back door" existed. On 8 October the Emirates pronounced BlackBerry "now compliant", without saying what RIM had agreed.
The Library Next Door
Microsoft closed July's shortcut flaw with an out-of-band patch on 2 August; the next problem was older and wider. On 18 August ACROS Security of Slovenia published an advisory on iTunes for Windows, already fixed by Apple, describing remote "binary planting": open a media file from a network share and a library planted beside it would be silently loaded and run. Hours later HD Moore of Rapid7, who said he had found the class while researching the shortcut flaw, said: "The cat is out of the bag, this issue affects about 40 different apps, including the Windows shell." ACROS said about 90 per cent of some 220 applications it tested were vulnerable; a UC Davis paper that July had counted more than 1,700 unsafe library loadings in popular Windows software, 28 of them serious routes to remote code execution. Microsoft's Security Advisory 2269637, on 23 August, put the fault in applications "passing an insufficiently qualified path when loading an external library" and offered a tool to block loading from WebDAV and remote shares, not a patch, saying the fixes would have to come from the applications' makers. By 25 August Offensive Security was listing forty exploits, from Photoshop to Wireshark.
Sixty more days
On 12 August 2010 the Home Ministry said that if a technical solution was not provided by 31 August, the government would "review the position and take steps to block" BlackBerry's corporate email and Messenger, which had about a million users in India. The 2008 Mumbai attacks had helped prompt a review of telecommunications security before October's Commonwealth Games in Delhi. RIM answered late that night that its enterprise architecture was the same around the world, that it "truly has no ability to provide its customers' encryption keys," and that it made no special deals for specific countries. The ministry's spokesman said the next day: "We are talking only to BlackBerry. Not to Google or others." Minutes of an official meeting, reported by the Associated Press, put Skype and Google next in line.
RIM's offers shifted through the month. Reuters reported that it had offered the network address of every enterprise server in India and the identifiers of every handset, and it proposed an industry forum, arguing that banning "one solution, such as the BlackBerry solution," would be "ineffective and counter-productive." On 30 August the ministry said RIM had made "certain proposals for lawful access by law enforcement agencies" that would be "operationalised immediately", to be reviewed within sixty days while the telecom department studied running such services through a server located only in India. The home secretary, G. K. Pillai, said notices would go to Google and Skype; on 31 August Google said it had yet to receive one, and Skype did not comment. By 1 October he was describing "manual access to the Messenger service", printouts within four to five hours of a request. RIM's next offer belongs to January 2011, the settlement to February 2012.
Android learns to take orders by voice
On 12 August 2010, in San Francisco, Google's Hugo Barra introduced Voice Actions for Android: spoken commands to send a text or an email, call a contact or a business by name, play music, open a website, get directions or start navigation, or send oneself a reminder by email. It needed Android 2.2, came pre-installed on Motorola's Droid 2 for Verizon, reached the Nexus One, HTC's Evo and the original Droid through updates from Android Market, and understood only US English. On 20 August Like.com, whose shopping search matched clothes and accessories by colour, shape and pattern, announced that Google had acquired it, on undisclosed terms. On 30 August Google announced Priority Inbox for Gmail, which ranked mail by how likely each user was to act on it; its engineers later called it "one of the largest and most user facing applications of ML at Google". The spoken commands were folded into Google Now with Android 4.1 in 2012, the line that led to Google Assistant in May 2016.
Intel agrees to buy McAfee for $7.68 billion
On 19 August 2010 Intel agreed to buy McAfee for $48 a share in cash, about $7.68 billion and some 60 per cent above McAfee's close of $29.93 the day before; both boards had approved it unanimously. Intel said security was now a fundamental component of online computing, and that protecting billions of new internet-ready devices — phones, televisions, cars, medical devices, cash machines — needed an approach combining software, hardware and services; McAfee's chief executive, Dave DeWalt, pointed to millions of new threats appearing every month. McAfee's shares jumped about 58 per cent that morning and Intel's slipped about 3 per cent. On the conference call UBS's Uche Orji asked whether owning McAfee would give Intel anything a collaboration could not; Sterne Agee's Vijay Rakesh, surprised by the premium, called it even by Intel's standards "a pretty big acquisition for them". Ten days earlier, on 9 August, Symantec had completed its purchase of VeriSign's identity and authentication business, SSL certificates included, for about $1.28 billion in cash. Intel's own deal closed the following February.
⏳ Time capsule — August 2010
- On 5 August a collapse at the San José copper and gold mine near Copiapó in northern Chile trapped 33 miners about 700 metres underground; seventeen days later a drill bit came up with a note attached — "Estamos bien en el refugio los 33" — and all 33 were brought up in October.
- On 12 August Oracle sued Google in the federal court for the Northern District of California, claiming that Android infringed seven of its Java patents and its Java copyrights; on 5 April 2021 the Supreme Court held, 6–2, that Google's use of the Java interfaces was fair use.
- From 14 to 26 August Singapore held the first Youth Olympic Games, with about 3,600 athletes from 204 nations in 26 sports, opened by President S. R. Nathan at the Float@Marina Bay.
- On 25 August the Lok Sabha passed the Civil Liability for Nuclear Damage Bill, and the Rajya Sabha followed on 30 August; it capped an operator's liability for an accident at ₹1,500 crore, three times the figure first proposed.
The ways in
Lynn's essay argued for an institution, and the institution came: Cyber Command reached full operating capability that October and became a unified combatant command on 4 May 2018. The question he declined to answer took longer. In March 2014 Kaspersky found that the Turla espionage tools shared agent.btz's encryption key and file names, and said the facts could not prove common authorship; the GRIZZLY STEPPE report DHS and the FBI published in December 2016 listed agent.btz among names reported for Russia's intelligence services — one line in a table, not a forensic account. On 3 December 2010 an Air Force order barred removable media from SIPRNet machines again, this time because unauthorised transfers on them were "a method the insider threat uses to exploit classified information" (November).
The argument over keys outlived the device at its centre. The Emirates' "now compliant" of 8 October came with no account of what had been agreed; BlackBerry's consumer Messenger closed on 31 May 2019; and in India any request for a way in has since had to reckon with the Supreme Court's unanimous holding of 24 August 2017 that privacy is a fundamental right (August 2017). Binary planting never received a single fix. Microsoft's advisory went through nineteen versions, the last in May 2014, as the company added twenty-nine bulletins for its own products — Office, Movie Maker, the Remote Desktop client and Lync among them; a July 2011 update gave developers safer ways to load libraries; and MITRE's ATT&CK catalogue still files search-order hijacking under T1574.001, beside side-loading.