The post went up on the official Google blog on 12 January 2010, signed by David Drummond, the company's senior vice-president of corporate development and chief legal officer. Headed "A new approach to China", it said that in mid-December Google had detected "a highly sophisticated and targeted attack on our corporate infrastructure originating from China" which had resulted in the theft of intellectual property. At least twenty other large companies had been similarly targeted, drawn from "the Internet, finance, technology, media and chemical sectors"; American authorities had been notified. Then the part that made it more than a breach notice: Google was "no longer willing to continue censoring our results on Google.cn", and knew this "may well mean having to shut down Google.cn, and potentially our offices in China".
One of the people the post was about had been told five days earlier. Tenzin Seldon, a Stanford undergraduate, a regional coordinator of Students for a Free Tibet and the India-born daughter of Tibetan refugees, was sent to Drummond by university administrators on 7 January; he told her her Gmail account had been breached and asked to scan her laptop. On 9 January Google reported finding nothing on it: the password had been taken some other way. Google's own account was narrower than the headlines it produced. Only two activist accounts appeared to have been accessed, and that activity was "limited to account information (such as the date the account was created) and subject line". Dozens of other advocates, it said, had had their accounts "routinely accessed by third parties" — most likely by phishing or malware on their own computers, not by any breach at Google.
McAfee supplied the name on 14 January. Dmitri Alperovitch, its vice-president of threat research, had found the word "Aurora" in a file path inside two of the malware binaries; George Kurtz, its chief technology officer, wrote only that it was probably the attackers' own name for the operation. Hillary Clinton had asked Beijing for an explanation on the day of Google's post, 12 January, saying in a brief statement that "we look to the Chinese government for an explanation"; on 21 January, at the Newseum in Washington, she made internet freedom a stated priority of American diplomacy, warning that countries which restrict access to information "risk walling themselves off from the progress of the next century". Beijing answered twice. On 21 January the vice foreign minister, He Yafei, said the Google case "should not be linked with relations between the two governments and countries"; on Sunday 24 January a spokesman for the Ministry of Industry and Information Technology told Xinhua that the accusation that the government had taken part in any cyber attack "either in an explicit or inexplicit way, is groundless".
What had actually been taken from Google came out three months later. In April 2010 the New York Times reported that the intruders had reached a software repository at Mountain View and taken the source code of Gaia, the single sign-on system behind Gmail and the company's business applications, after an instant message was sent to an employee in China; individual users' passwords did not appear to have been taken, and Google would not discuss it. Nobody has been charged in connection with the campaign, then or since. Google stopped censoring google.cn by moving its Chinese search service to Hong Kong in March, and sixteen years later its search engine still cannot be reached from mainland China. Kurtz and Alperovitch left McAfee and co-founded CrowdStrike the following year.
The Browser Two Governments Warned Against
Microsoft published advisory 979352 on 14 January 2010 and revised it the next day to reflect "limited targeted attacks" — at that point seen working reliably only against Internet Explorer 6. By then the exploit was public: code uploaded to the Wepawet analysis service had escaped, and working modules existed for Metasploit and for Immunity's commercial Canvas, whose Kostya Kortchinsky called his version fairly reliable against IE6 and IE7 on Windows XP. On 15 January Germany's Federal Office for Information Security told citizens to use a different browser, noting that protected mode and disabling Active Scripting made attacks harder but could not prevent them; France's CERTA, whose alert was first published the same day, recommended an alternative browser until a patch existed. Microsoft did not accept the advice — "there is no threat to the general user, consequently we do not support this warning", said its German spokesman, Thomas Baumgaertner — and then, on 21 January, shipped MS10-002 out of band, nineteen days ahead of the next scheduled update, closing eight holes including CVE-2010-0249. Net Applications put IE6, by then more than eight years old, at about a fifth of the browser market.
Sixteen Constants in the Code
The malware Symantec catalogued as Trojan.Hydraq was a backdoor that hid inside the svchost.exe service host. What made it interesting was a detail Joe Stewart of SecureWorks published while taking it apart: its cyclic redundancy check used a table of sixteen constants rather than the usual 256, traced to a Chinese-language paper on optimising CRC algorithms for microcontrollers, and which, he wrote, "seems to be virtually unknown outside of China". Programmers reuse code documented in their own language, he reasoned — then marked the limit of it: in his opinion someone in the PRC had written the codebase, but there was no hard evidence beyond the addresses and this clue. iDefense, VeriSign's threat unit, put the number of targets at 34 and told reporters that two anonymous sources of its own, in defence contracting and intelligence consulting, had traced the source addresses and the drop server to systems associated with agents of the Chinese state, or proxies for it. The companies were mostly quiet. Adobe said on 12 January that it had become aware on 2 January of "a sophisticated, coordinated attack against corporate network systems managed by Adobe and other companies", with no evidence that sensitive data had gone; Juniper Networks, Rackspace and Akamai confirmed they had been targeted. The larger names in press reports — Yahoo, Symantec, Northrop Grumman, Dow Chemical — confirmed nothing; Morgan Stanley's name surfaced only a year later, in a leak of HBGary's email.
The Same Fifteenth of December
On Monday 18 January 2010 India's national security adviser, M. K. Narayanan, told The Times of London that his own office and other government departments had been attacked on 15 December 2009 — the same day Google gave for the attack on its network. The method was ordinary: an email with a PDF attachment carrying a trojan that could download or delete files. It was caught, and staff were told not to log on until it was cleared. On attribution he went no further than suspicion: "People seem to be fairly sure it was the Chinese. It is difficult to find the exact source but this is the main suspicion." China's foreign ministry spokesman, Ma Zhaoxu, called the accusations groundless and said his government was firmly against hacking; a separate television report that computers in the Prime Minister's Office had been penetrated was denied by an official there. Five days later Narayanan left the job: on 24 January he became Governor of West Bengal, and Shivshankar Menon took over.
The apparatus receiving such reports was new in its formal role. CERT-In had existed since 19 January 2004, but became the national nodal agency for incident response only under section 70B of the Information Technology Act, inserted by the amending Act of 2008 that came into force on 27 October 2009 — less than three months before the interview. Eleven weeks after it, a Canadian research group published what it had found inside an espionage network reaching Indian government and military systems; that report is carried in April. The reporting rule CERT-In enforces today, and the data-protection law India waited until 2023 for, are on our India desk: the six-hour rule and the DPDP Act.
Google sells a phone that takes dictation
Google's own-brand Android phone, the Nexus One, went on sale on 5 January 2010, built by HTC and sold unlocked through a web store Google ran itself. The feature it pushed hardest was voice input: a microphone button beside any text field, so a message or a search could be spoken rather than typed. Recognition did not happen on the handset — audio went up to Google's servers and text came back, which meant the models could improve without anything changing on the phone. Later the same month Google released Translate for Android, with romanisation of non-Roman scripts, spoken output, voice input and translation of incoming text messages. The phone sold poorly; the analytics firm Flurry put its first week at roughly twenty thousand, and Google closed the store on 18 July 2010, saying Android's adoption had exceeded its expectations but "the web store has not". The arrangement outlasted the hardware: speech sent to a server and text returned is still how dictation works, and the statistical translation behind the app gave way to neural networks in November 2016.
A spam botnet unplugged by its hosts
In the second week of January 2010 the Lethic botnet went quiet. Neustar's staff had established where its command-and-control servers sat and contacted the internet service providers hosting them, which decommissioned the machines; M86 Security then went to registrars in Hong Kong and China to strip the domains the stranded drones kept calling. Estimates put Lethic at two to three hundred thousand infected machines and, by one count, about a tenth of the junk mail then circulating, most of it pharmaceutical and replica goods. On 19 January Alwil Software released avast! 5 in three editions, the free one rebuilt around a behaviour shield and a new interface, with no email registration; Alwil quoted Virus Bulletin's verdict that giving the full product away was "nothing short of a miracle". On 27 January Symantec reported a third quarter roughly flat year on year, and a profit where the same quarter a year earlier had produced a loss of billions. Lethic was back on new American servers within weeks, which set the pattern: disruption by cooperation, then a rebuild at lower volume.
⏳ Time capsule — January 2010
- On 4 January the Burj Khalifa opened in Dubai at 828 metres to its architectural top, the tallest building in the world; it had been called Burj Dubai until the ceremony, and was renamed for the ruler of Abu Dhabi, Khalifa bin Zayed Al Nahyan, whose emirate had helped Dubai through its debt crisis.
- On 12 January an earthquake of magnitude 7.0 struck Haiti, its epicentre near Léogâne about 25 kilometres west of Port-au-Prince; estimates of the number of dead have ranged from about 100,000 to over 300,000.
- On 25 January Avatar passed Titanic to become the highest-grossing film worldwide; on 2 February it passed it in the United States and Canada as well.
- On 27 January, at the Yerba Buena Center for the Arts in San Francisco, Steve Jobs announced the iPad, at a starting price of $499.
The month the accusation was signed
January 2010 is when a company put its name to an accusation involving a state. Google did not say the Chinese government had done it; it said the attack had originated in China, and Beijing said the charge was groundless. But the post made the argument public, and the habit it started — a breached company publishing what it knows instead of saying nothing — outlasted every technical detail in it. The browser question took longer to settle. Microsoft opened an IE6 Countdown page on 4 March 2011 to shame the last holdouts into upgrading, support for that browser ran out with Windows XP itself on 8 April 2014, and Internet Explorer 11 was retired on 15 June 2022. The archive picks the thread up in March 2011, when a certificate authority and then RSA had to write their own versions of Google's letter.
Nobody was charged. Google's Chinese search service went to Hong Kong and never came back, and google.cn survives as a page pointing somewhere else. Later in the same year this archive records a different order of operation altogether — a worm found in July and read for its purpose in September, built for machinery rather than mail — and by December Indian government sites were being defaced in public view. For now, though, this is where the archive begins: January 2010 is its oldest edition, and 2009 and the years before it are still to be restored.