The complaint was filed on Monday 22 February 2010 at the federal courthouse in Alexandria, Virginia, and it named nobody. Microsoft Corporation v. John Does 1-27, civil action 1:10CV156, accused twenty-seven unidentified people of running a spam network called Waledac, under the federal computer-fraud statute, the CAN-SPAM Act, the Electronic Communications Privacy Act and other claims. The same day the court granted a sealed ex parte temporary restraining order — argued without the other side present, and kept off the public docket so that the other side would not read it. Its instruction went not to the defendants but to a company that was not a party to the case: VeriSign, which runs the .com registry, was to stop resolving 277 domain names.
Waledac was a spam engine, its mail advertising unlicensed pharmacies and counterfeit goods. Microsoft put it among the ten largest botnets in the United States, at hundreds of thousands of infected computers with the capacity to send more than 1.5 billion messages a day; between 3 and 21 December 2009, the company said, about 651 million spam messages attributable to Waledac were aimed at Hotmail accounts alone. The 277 domains, The Register reported, had been registered in China. Cutting them was not by itself enough, because infected machines could also take instructions from one another, and Microsoft said technical countermeasures had downgraded what remained of that traffic — work done with Shadowserver, Symantec, the University of Washington, the University of Mannheim, the Technical University of Vienna, the International Secure Systems Lab and the University of Bonn.
Microsoft said nothing publicly until the order had taken effect. On 24 February Tim Cranton, an associate general counsel, set the action out on the company's blog and gave it its internal name, Operation b49. It was the first action of what Microsoft called MARS, Microsoft Active Response for Security, and its first use of a civil court to take a botnet apart. The same machinery pointed the other way that week: on 23 February Microsoft complained of copyright infringement over a handbook it supplies to law enforcement, posted on the archive site Cryptome, whose host took the whole site offline on 24 February; the complaint was withdrawn the next day. Mark Rasch, a former Justice Department prosecutor, told Krebs on Security that the company had been "wrestling with a pig".
The takedown held. Jeff Williams of Microsoft's Malware Protection Center said in September that virtually no Waledac traffic had reappeared; the company counted 58,000 unique infected addresses as of 30 August 2010, and Cox Communications worked through several hundred of its own customers with a removal tool. None of the twenty-seven John Does came to court. On 8 September Microsoft said Magistrate Judge John F. Anderson had recommended default judgment and the permanent transfer of the domains, and on 27 October 2010 the district court ordered it: 276 names signed over to a software company. One person had come forward to claim a domain — a resident of Oregon whose own website had been taken over and pressed into the botnet's service. The machines themselves stayed infected.
The Name That Was Not New
On 18 February 2010 NetWitness, a security firm in Herndon, Virginia, published findings on a ZeuS network it called Kneber, after the account name used to register its command domains. It said the network held credentials from nearly 75,000 computers at about 2,500 organisations in 196 countries, that it had been running since late 2008 and had been found the previous month. The Washington Post carried it as one of the largest attacks yet found; the Wall Street Journal named Merck, Cardinal Health, Paramount Pictures and Juniper Networks, citing people familiar with it. Merck said one computer had been infected and isolated and no sensitive information compromised; Cardinal Health took its machine off the network; Paramount would not comment; Juniper's Barry Greene would not discuss particular incidents. Rival vendors were unimpressed: McAfee's Joris Evers said Kneber was not even a large botnet, and Symantec said it was the well-known Zeus Trojan renamed. On 19 February Brian Krebs, citing the ZeuS Tracker count, put the number of ZeuS command centres then running at close to 700. NetWitness's chief executive, Amit Yoran, argued that conventional protection was inadequate. The arrests that broke one ZeuS money-laundering network came at the turn of September and October.
The Patch That Fell Over
On 9 February 2010 Microsoft shipped MS10-015, catalogued as KB977165, closing a hole in the subsystem that ran old DOS programs on 32-bit Windows — a flaw present in every version since Windows NT 3.1 in 1993, reported to Microsoft months earlier by Tavis Ormandy of Google and published by him in January, still unfixed. Within a day Windows XP owners were describing blue screens and reboot loops that would not end. On 17 February the Microsoft Security Response Center gave its answer: the crashes came from changes the Alureon rootkit, also known as TDL3, had made to Windows kernel binaries, which left those machines in an unstable state when the update arrived. Its director, Mike Reavey, said that in every incident investigated the company had found no quality problem with MS10-015. Microsoft's own tools had removed close to two million copies of Alureon in the first half of 2009 alone. On 2 March it re-released the update — not recompiled, but wrapped in detection logic that refused to install it on a machine bearing the rootkit's marks. A security patch had learned to decline the already compromised.
Two Notices in One Week
On 25 February 2010 the Department of Telecommunications issued its Notice Inviting Applications for the auction of third-generation and broadband wireless spectrum: blocks of 5+5 MHz in the 2.1 GHz band at a reserve price of ₹3,500 crore for a pan-India licence, and two blocks of 20 MHz in the 2.3 GHz band for broadband wireless access at ₹1,750 crore, with applications closing on 19 March and bidding to open in April. The broadband auction ended on 11 June 2010 with a single company, Infotel Broadband Services, holding spectrum in all twenty-two service areas at ₹12,847.77 crore. Reliance Industries bought 95 per cent of that company the same day, subscribing ₹4,800 crore of fresh equity. The company was later renamed Jio.
The next day the finance minister, Pranab Mukherjee, presented the Union Budget for 2010–11 and gave the Unique Identification Authority of India ₹1,900 crore for what he called its operational phase, saying it was expected to issue its first numbers in the coming year; it did so on 29 September, in a village in Nandurbar district, as September records. The same speech proposed a Technology Advisory Group for Unique Projects under Nandan Nilekani, to settle the technology behind the Tax Information Network, the new pension scheme and the Goods and Services Tax; it reported the following year. Neither notice was written as a security document. Between them they laid the two pipes — a national identity number and cheap mobile data — through which most of India's later arguments about surveillance, fraud and breach reporting would run; the six-hour reporting rule CERT-In eventually imposed is set out on our India desk.
Siri began as a free download
On 4 February 2010 Siri Inc., a company spun out of SRI International and descended from the DARPA-funded CALO project, placed a free application on Apple's App Store. It needed an iPhone 3GS, took a spoken request, worked out what was being asked and handed it to an outside service — restaurant listings from Yelp and CitySearch, bookings through the taxi firm Taxi Magic — with the speech recognition licensed from Nuance. Reviewers thought the listening good and the transactions unfinished; the standalone app was withdrawn in October 2011, when the same name reappeared inside the iPhone 4S. On 11 February Google bought Aardvark, a question-routing service built by former Google engineers, for a price reported at about $50 million, and shut it the next year. On 17 February it put translation into Goggles, its camera-search application for Android, so that a photographed German menu came back in English; Franz Och, its head of translation services, said that month that speech-to-speech translation should "work reasonably well in a few years' time".
What the cloud was worth offline
AV-Comparatives froze its malware set on 3 February 2010 and the products themselves on 10 February, then ran twenty consumer anti-virus programs against about 1.2 million samples. The Austrian lab said the set was smaller than before, built from prevalence data shared across the industry so that it held malware actually circulating. G DATA detected 99.6 per cent and Kingsoft 81.8 per cent; five products, McAfee and Trend Micro among them, were marked down for false alarms, and K7 raised 193 on a clean-file set; such alarms, the lab wrote, "can sometimes cause as much troubles as a real infection". The footnotes carried a sharper figure: with no internet connection, and so no cloud lookups, Panda's detection fell from 99.2 to 73.3 per cent and Trend Micro's from 90.7 to 68.5. Symantec shipped Norton 360 version 4.0 on 17 February, the first of that suite to rate files by reputation collected from its own users. The verdict was moving off the machine, and the whole-product tests the lab had begun the previous December became the measure that lasted.
⏳ Time capsule — February 2010
- From 12 to 28 February the XXI Olympic Winter Games were held in Vancouver, with about 2,600 athletes from 82 nations in 86 events. On the opening day a Georgian luger, Nodar Kumaritashvili, died after a crash during a training run at the Whistler Sliding Centre; the athletes remembered him at the ceremony that evening. The Games closed with Canada beating the United States 3–2 in overtime at ice hockey, Sidney Crosby scoring the winner past Ryan Miller.
- On 15 February, at the Mobile World Congress in Barcelona, Steve Ballmer unveiled Windows Phone 7 Series, which brought Xbox Live games and the Zune music service onto a phone and was promised in shops by the end of the year. Microsoft left the phone business before the decade was out.
- On 24 February at the Captain Roop Singh Stadium in Gwalior, Sachin Tendulkar, then 36, made 200 not out off 147 balls against South Africa — the first double century by a man in a one-day international. India made 401 for 3 and won by 153 runs.
- On 27 February an earthquake of magnitude 8.8 struck off the Maule region of central Chile and was followed by a tsunami; the official count recorded 525 people dead and 25 missing.
The month a lawsuit became a tool
Operation b49 is the ancestor of a standard procedure: sue unknown defendants, obtain a sealed order before they can move, cut the names their software depends on, then ask for default judgment when nobody appears. Microsoft did it to Rustock in March 2011, put a reward on its operators in July, and in September 2011 named a defendant for the first time. What the method does not do is clean anything: the domains changed hands, the infected computers stayed infected until someone sat at each one, and a judgment entered against people who never appeared is not a conviction. February's other botnet case ran the older way round, through policemen rather than pleadings: Spain's Guardia Civil arrested a suspected ringleader on 3 February 2010 and two more men on 24 February, for renting out a network called Mariposa that Panda Security and the Canadian firm Defence Intelligence — working with the FBI, the Georgia Tech Information Security Center and the same Spanish force, in what they called the Mariposa Working Group — had already taken control of on 23 December 2009. The police and Panda put the network at close to 13 million machines, a figure counting unique addresses rather than confirmed computers, and the arrests were made public only at a press conference at the start of March.
The month's other two stories aged into habits. Kneber taught the trade to ask what a number is being compared with before repeating it: 75,000 machines was a large figure and an ordinary one, and the firm that produced it also sold the answer to it. The February patch taught something harder — that an update assumes a machine which has not already been rewritten underneath it, and that when the assumption fails it is the update that appears to break. Microsoft's decision on 2 March, to withhold a fix from the already compromised, is now ordinary caution. The identity number and the spectrum India notified in that one week became, between them, the subject of the data protection law it passed thirteen years later.