The flow was built for convenience. When someone set up 3G service on a new iPad, AT&T recorded the serial number of the SIM — the ICC-ID — against the email address they had given, and its sign-up page used the ICC-ID to fill that address in for them at the next log-in. The numbers were regular enough to guess at. On 5 June 2010 Daniel Spitler began discussing the behaviour in an internet relay chat channel, and the group he belonged to, which called itself Goatse Security, wrote a script in PHP that it named the iPad 3G Account Slurper. It sent the page one candidate ICC-ID after another, wearing an iPad's browser identification, and wrote down every address the page handed back: 114,067 of them, by the group's own count, the figure Gawker carried as "114,000". AT&T's own letter to customers put it at more than 114,000; the prosecutors who brought charges in 2011 alleged about 120,000.

On Wednesday 9 June Gawker published the story, with screenshots of the list and the addresses blacked out. The names were the point. Ryan Tate's account put the White House chief of staff, Rahm Emanuel, on the list, along with the mayor of New York, Michael Bloomberg, Diane Sawyer of ABC News, the chief executive of the New York Times Company, Janet Robinson, and the film producer Harvey Weinstein; the Register added the commander of an American strategic bomber group and counted Dow Jones, Condé Nast, Viacom, Google, Amazon, Microsoft and AOL among the employers represented. Nothing else had been exposed — no passwords, no card numbers, nothing off the devices — but an address is an address, and some of these belonged to people whose correspondents were worth guessing at.

AT&T said it had learned of the collection on 7 June and had switched off the pre-population within hours; iPad owners then typed both address and password. On 13 June it wrote to the customers concerned over the signature of its chief privacy officer, Dorothy Attwood: the addresses and ICC-IDs had been taken by people who "maliciously exploited" a convenience feature, no other account or device data was affected, the likely consequence was spam and targeted phishing, and "We apologize for the incident and any inconvenience it may have caused." The company said no one from the group had ever contacted it and that it had heard of the problem from a business customer. Goatse Security said it had tried to reach AT&T, got no reply, and waited until the hole was shut before saying anything; Gawker said its own reporters had told AT&T before publication. The next day TechCrunch gave the group an award for public service.

Federal agents searched Andrew Auernheimer's house in Arkansas on 15 June, and county officers charged him with drug possession over what was found there; the police would not say what the warrant was for, and the state dropped those charges once the federal case began. The computer charges came on 18 January 2011: conspiracy to access a computer without authorisation, and fraud in connection with personal information. Spitler pleaded guilty that June, and in January 2014 was given three years' probation and $73,167 in restitution. Auernheimer went to trial, was convicted on 20 November 2012 and was sentenced on 18 March 2013 to 41 months in prison. On 11 April 2014 the Third Circuit vacated that conviction: the case had been tried in the wrong district, neither the defendants nor AT&T's servers having been in New Jersey. He was released the same day. The court said nothing about whether reading a public page without a password is unauthorised access.

Also that month · 3–10 June

No Situational Awareness

On 3 June 2010 General Keith Alexander made his first public appearance since taking charge of United States Cyber Command, at the Center for Strategic and International Studies in Washington. The command had reached initial operational capability at Fort Meade on 21 May, dual-hatted with the National Security Agency, which Alexander already ran. His account of the problem was blunt: "The potential for sabotage and destruction is now possible and something we must treat very seriously." Of the military's own networks he said, "We have no situational awareness," and added that they were "not neatly bounded by those ending in the .mil". A week later, on 10 June, Senators Joe Lieberman, Susan Collins and Tom Carper introduced S. 3480, which would have let the president declare a national cyber emergency and order measures to preserve critical infrastructure by "the least disruptive means feasible". The press read it as a kill switch. Lieberman called that "total misinformation" and said the government should never take over the internet; the sponsors argued the bill narrowed the authority the president already had. It died without a vote when the Congress ended.

Also that month · 5–15 June

Five Days for a Help Page

On Saturday 5 June 2010 Tavis Ormandy, a security researcher at Google, told Microsoft about a flaw in the Windows Help and Support Center: helpctr.exe mishandled escape sequences in the hcp:// links it was registered to open, so a crafted link could step outside the set of help documents it was allowed to load and run commands instead. Microsoft acknowledged the report that day. Five days later he published it to the Full Disclosure mailing list with working code and a hotfix of his own, writing that there was "a significant possibility that attackers have studied this component, and releasing this information rapidly is in the best interest of security". Microsoft issued Advisory 2219475 on 10 June, said his hotfix could be bypassed easily, offered a registry change instead and warned that broad attacks were likely. On 15 June researchers at Sophos said the flaw was being exploited in the wild. The patch, MS10-042, shipped on 13 July. On 22 July Microsoft dropped the phrase "responsible disclosure" in favour of "coordinated vulnerability disclosure", saying the old term had become too emotionally charged.

India desk · June 2010

Twenty-Two Circles in an Afternoon

On 11 June 2010 India's auction of broadband wireless spectrum closed. The only bidder to take 20 MHz in all twenty-two service areas was Infotel Broadband Services, an unlisted internet service provider, at ₹12,847.77 crore for the pan-India holding; Qualcomm took four circles, Delhi and Mumbai among them; Bharti Airtel four, Aircel eight, Tikona five. Counting the sums charged to the state-owned BSNL and MTNL, the broadband auction raised ₹38,543 crore for the exchequer. Within hours of the result Reliance Industries announced that it would put ₹4,800 crore of fresh equity into Infotel for 95 per cent of a company whose principal asset was a licence a few hours old. Infotel was renamed Reliance Jio Infocomm in January 2013 and began selling service on 5 September 2016.

What the auction sold was capacity, not safety. The state's interest in the traffic that would run over it was legibility: through the same summer the home ministry was pressing the providers of encrypted services for access its agencies could use, with a deadline at the end of August that this archive takes up in August. The instrument was the 2008 amendment to the Information Technology Act, signed on 5 February 2009, whose section 69 allowed the government to order interception, monitoring and decryption. What India did not have in June 2010 was any general law on personal data, or any duty on a company to tell a customer that their details had been handed to a stranger; AT&T's letter of 13 June had no Indian equivalent, and nothing required one. Both came later — reporting duties through CERT-In's six-hour rule, and a general law through the Digital Personal Data Protection Act of 2023.

AI Tech desk · June 2010

Kinect named, and Watson explained

On the evening of Sunday 13 June 2010, at a premiere in Los Angeles choreographed by Cirque du Soleil, Microsoft gave Project Natal its retail name — Kinect, from kinetic and connection — and put it on stage: a kart racer, hurdles and beach volleyball, and console menus driven by hand and voice. The following day's E3 press briefing set the North American release for 4 November. The parts mattered more than the games: an infrared projector and camera built on range-sensing silicon from PrimeSense, an Israeli firm, a depth value for every pixel, and a skeleton inferred from that depth in software. Three days later the New York Times Magazine published Clive Thompson's "What Is I.B.M.'s Watson?", the first long public account of the question-answering system David Ferrucci's group was building to play Jeopardy!: no internet connection, evidence weighed into a confidence score, and scores of sparring matches against former contestants, most of them won. From 2026 the pairing reads as two halves of the decade that followed: perception made cheap, language made answerable.

Digital Guard desk · June 2010

McAfee and Norton turn to phones

The month's industry news was the two largest endpoint vendors turning to handsets: McAfee's purchase of the mobile management firm Trust Digital, agreed in May, was due to close before June was out. Symantec, days after setting out its Norton Everywhere plan, put a free beta of Norton Smartphone Security for Android into the Android Market that month, with remote lock and wipe, malware scanning and call blocking. On the desktop the month went badly: on 4 June Adobe warned that a flaw in Flash Player, Reader and Acrobat, CVE-2010-1297, was being exploited in the wild, patched Flash on 10 June, and on 29 June shipped Reader and Acrobat 9.3.3 with seventeen fixes, brought forward from the next quarterly release. Securing the phone turned out to be a separate trade, not a tab in the anti-virus console.

⏳ Time capsule — June 2010

  • On 4 June the Falcon 9 rocket built by SpaceX made its maiden flight from Cape Canaveral and reached orbit at the first attempt.
  • On 7 June a court in Bhopal convicted seven former officials of Union Carbide India Limited of causing death by negligence over the gas leak of December 1984, sentencing each to two years' imprisonment and a fine of ₹1 lakh; an eighth accused had died before judgment.
  • On 11 June the World Cup opened at Soccer City in Johannesburg, where South Africa drew 1–1 with Mexico in front of 84,490 people, Siphiwe Tshabalala scoring in the 55th minute and Rafael Márquez equalising in the 79th.
  • From 22 to 24 June, on Court 18 at Wimbledon, John Isner beat Nicolas Mahut 70–68 in the fifth set of a match that ran 11 hours and 5 minutes across three days and 183 games; the scoreboard stopped at 47–47, which was as far as it had been programmed to count.
Where it stands today — 2026

What counted as asking

There was no cleverness in the flaw, and that is why it lasted. A predictable identifier in a request, and a server that answers it without asking who is enquiring: the field settled on calling it an insecure direct object reference, and it never went out of production. A year later Citigroup's card site was found doing the same with account numbers edited into the address bar, covered in June 2011, and the remedy in 2026 is the one that was available in 2010 — decide, on every request, whether this caller may have this record. What changed faster was the telling: AT&T's letter of 13 June, written because a story had already run, set the shape of a genre — addresses only, expect phishing, nothing else touched.

The question the Third Circuit stepped around in 2014 stayed open another seven years. It ran through the prosecution of Aaron Swartz and the reform bill it produced, carried in January 2013, to 3 June 2021, when the Supreme Court held in Van Buren v. United States, six to three, that using authorised access for an improper purpose does not exceed it, and to 19 May 2022, when the Justice Department made it policy not to charge good-faith security research under the Computer Fraud and Abuse Act. None of it says in so many words that a public page which answers a question has consented to being asked. The other June thread ended quietly: no American statute ever gave a president a switch for the internet, and Cyber Command became the tenth unified combatant command on 4 May 2018, still sharing a commander with the National Security Agency.