Google's announcement went up on its corporate blog on 22 March 2010, signed by David Drummond, its chief legal officer. Searches typed into google.cn would from that moment be answered from google.com.hk — in simplified Chinese, unfiltered, from servers in Hong Kong. Drummond called it "a sensible solution to the challenges we've faced", "entirely legal" and a way to "meaningfully increase access to information for people in China". Google kept the google.cn domain, warned that its services might be slow and might be blocked, and put up a page showing what was still reachable from the mainland. The decision, it said, had been taken at headquarters in the United States, and no employee in China bore responsibility for it. The attack that began the argument was disclosed in January.

The answer came the next day. An unnamed official of the State Council Information Office told Xinhua, the state news agency, that Google was "totally wrong" to stop filtering, that it had broken a written promise made when it entered the market, and expressed "dissatisfaction and anger" at its "unreasonable accusations and practices". Qin Gang, a Foreign Ministry spokesman, warned that politicising the affair would damage relations with the United States. The redirect was never clean. The filtering apparatus between Hong Kong and the mainland went on discarding results, and on 30 March searches through Google's sites failed across the mainland for a day. Google's first guess blamed itself: a parameter it had lately added to search URLs, gs_rfai, happened to contain the letters rfa, the initials of a broadcaster long unreachable in China. Within hours it withdrew that explanation, saying the parameter was a week old and that whatever had blocked the Hong Kong site must have been a change in the filtering apparatus itself. Access returned the next day without Google altering anything.

The commercial reply was faster than the diplomatic one. Tom Online, Li Ka-shing's portal, let its agreement with Google lapse and moved to Baidu; its executive vice-president, Elaine Feng, said the company's practice was to work with firms that complied with regulations. China Unicom, the second-largest carrier, took Google's search off Android handsets it had built with Google; its president, Lu Yimin, said Unicom would work with any company that abided by Chinese law and that it had no cooperation with Google at present. Google had itself held back two of those handsets in late January, calling a launch irresponsible while it weighed its position, and on 25 March confirmed it had postponed its mobile applications on Android devices from operators in China until further notice. Analysys International afterwards put Google's share of mainland search at 30.9 per cent in the first quarter of 2010 and 24.2 per cent in the second, as Baidu rose from 64 to 70 per cent.

The redirect lasted three months. On 28 June, with its internet content provider licence up for renewal and in doubt, Google said it was replacing the automatic redirect with a landing page at google.cn carrying a link to the Hong Kong site alongside its remaining local products, and the redirect was gone by the end of the month; on 9 July it said the licence had been renewed and that it looked forward to continuing to provide web search and local products to its users in China. The share kept falling. Access was cut off almost entirely around the anniversary of the Tiananmen Square crackdown in June 2014, and Google search has not been generally available on the mainland since. What the redirect bought was not a market but a position: the company had stopped filtering, and it had not been thrown out.

Also that month · 24–26 March

Everything Fell but Chrome

CanSecWest opened in Vancouver on 24 March 2010, and with it the fourth Pwn2Own, run by TippingPoint's Zero Day Initiative with a $100,000 pool — ten thousand dollars a browser, fifteen thousand a phone. Peter Vreugdenhil took Internet Explorer 8 on 64-bit Windows 7 by chaining two flaws, one to defeat address space layout randomisation and one to get past data execution prevention. Nils, head of research at MWR InfoSecurity, did the same to Firefox on the same machine and kept it. Charlie Miller took Safari on a MacBook running Snow Leopard, his third year running. Ralf-Philipp Weinmann of the University of Luxembourg and Vincenzo Iozzo of Zynamics took an unjailbroken iPhone 3GS running iPhone OS 3.1.3: a web page was enough, and the phone's text-message database, deleted messages included, was on their server in about twenty seconds. They never broke Apple's code signing — they strung together fragments of code already on the device, in what Iozzo called the first public demonstration of chained return-into-libc on ARM. Chrome alone went unbroken; the BlackBerry Bold, the Symbian Nokia and the Android Nexus One went untouched. Every flaw went to its vendor.

Also that month · 24–28 March

What Chile Was Told

On Wednesday 24 March 2010 Mauricio Ereche, a DNS administrator at NIC Chile, found that Chilean internet providers were being handed wrong addresses for facebook.com, twitter.com and youtube.com — the answers China's filtering apparatus returns to users on the mainland. VTR, Telmex and others reaching the wider internet through Global Crossing had taken them, and so had a NIC Chile server in California. The queries had reached a copy of the I root server that Netnod, a Swedish operator, ran in Beijing, and the replies had been altered in transit. Netnod said the machine itself held no bad data; CNNIC, the Chinese registry that hosted the node, denied any part in it; and researchers agreed the rewriting was being done on the Chinese network around it. NIC Chile, making the trouble public on the Friday, said everything pointed to China's content filtering but that it could not be certain. Netnod withdrew the route announcements that sent queries to the Beijing node, effectively taking it off the network; its chief executive, Kurt Erik Lindqvist, could not say exactly when that was done. "All of a sudden, the consequences are that people outside China may be subverted or redirected to servers inside China," said Rodney Joffe of Neustar. Danny McPherson of Arbor Networks thought it accidental, and an illustration of how easily such information is corrupted.

India desk · March 2010

Clearance Before Purchase

India spent 2010 deciding what its mobile networks were allowed to be made of. From December 2009 the government had been examining Chinese-made equipment installed in border districts and areas troubled by insurgency, and operators had been told that core network equipment needed Home Ministry clearance before an order could be placed. Agence France-Presse reported on 30 April that the telecommunications ministry had revised its sourcing rules in March, requiring that dependence on foreign engineers be "minimal or almost nil" within two years of purchase. An executive at one of the larger operators, speaking anonymously, said his company had been told it could not buy from UTStarcom, an American firm manufacturing in China, and thought most had had the same letter. The telecom ministry's spokesman, Satyendra Prakash, said there was no blanket ban on procurement from any company or any country — only that operators had to get their equipment cleared by the Home Ministry before placing an order.

The rules hardened. In July the Department of Telecommunications amended operators' licences: vendors were to deposit source code in escrow, operation and maintenance was to pass to Indian engineers within two years, core equipment needed third-party audits, and a vendor found to have shipped spyware or malware could be fined the full value of its contract. The list of core equipment grew that month to take in billing systems, servers and workstations. All of it concerned equipment nobody had caught doing anything; what did reach Indian government and military systems that year was reported in April. India's answer became a list: a National Security Directive in December 2020 and, from 15 June 2021, a rule that operators buy only from trusted sources, the Chinese vendors outside it. What those networks must now disclose is set out on our India desk.

AI Tech desk · March 2010

The second prize Netflix never ran

On 12 March 2010 Netflix abandoned the second Netflix Prize it had announced the previous August, settling a class action filed in December 2009 under the Video Privacy Protection Act and closing a Federal Trade Commission inquiry into whether the ratings it had published could be traced back to subscribers. They could: Arvind Narayanan and Vitaly Shmatikov of the University of Texas had matched the first contest's anonymised ratings against public reviews on the Internet Movie Database and named individual renters. Neil Hunt, the chief product officer, said the company still hoped to work with researchers. The contest that produced BellKor's Pragmatic Chaos and a ten per cent gain on Cinematch got no sequel, and the winning ensemble was never deployed. Eight days earlier YouTube had opened automatic captioning to every user, English only, the captions translatable into fifty languages, its product manager Hiroto Tokusei conceding that they "aren't perfect". Machine learning worked at scale that month, and the data it ran on had become a liability; releases like Netflix's largely stopped there.

Digital Guard desk · March 2010

Madrid, Vodafone and a battery charger

In the first days of March 2010 the Guardia Civil filled a room in Madrid to describe a botnet called Mariposa, and half the names it gave were vendors': Panda Security, Defence Intelligence and the Georgia Tech Information Security Center, whose working group had seized the command channel on 23 December 2009, only for an operator to take it back and turn it on them. Three Spaniards had been arrested; the police count ran to millions, of internet addresses rather than machines. Captain César Lorenzana said it was "almost impossible to be sent to prison for these kinds of crimes in Spain". A Panda employee then opened a new HTC Magic from Vodafone Spain and found the Mariposa client on its memory card; on 18 March the operator accepted it was replacing three thousand cards, calling the matter isolated. On 8 March US-CERT warned that the Windows software for Energizer's DUO battery charger installed a backdoor, which Symantec had pulled apart. The shape became routine: vendors sinkholing, police arriving later, the kit's Slovenian author convicted in 2013.

⏳ Time capsule — March 2010

  • On 7 March, at the Kodak Theatre in Hollywood, Kathryn Bigelow became the first woman to win the Academy Award for best director; her film The Hurt Locker took six awards to Avatar's three, having earned about twelve million dollars before the nominations.
  • On 9 March the Rajya Sabha passed the constitutional amendment reserving a third of seats in Parliament and the state assemblies for women, by 186 votes to one. The Lok Sabha never took it up and it lapsed in 2014; the amendment that finally carried the reservation was passed in September 2023, and it still waits on a fresh delimitation.
  • On 12 March the third season of the Indian Premier League opened at the DY Patil Stadium in Navi Mumbai, Kolkata Knight Riders against Deccan Chargers. It was the first cricket tournament carried live on YouTube.
  • On 21 March the United States House of Representatives passed the Senate's health insurance bill by 219 votes to 212, and on 23 March President Obama signed the Patient Protection and Affordable Care Act into law.
Where it stands today — 2026

What a redirect could not move

March 2010 is the month a company tested how much a border could be made to matter. Google's answer to a censorship requirement was geographic: move the servers off the mainland, keep the domain, and let the state decide what to do about it. The state decided. Partners left within days, the filtering apparatus went on working, the licence came back only after the redirect had been softened into a link, and the market share went down and stayed down. By 2026 Google search is not generally available on the mainland, and the share Google gave up went to Baidu, which has spent the years since losing ground to newer Chinese rivals rather than to Google. What the month settled is that a company can refuse to censor and still lose the users it had censored for — and that losing them is not the same as being expelled.

The other lesson was in the plumbing. A copy of the domain name system's root, sitting in Beijing, told machines in Chile and California where Facebook was, and they believed it, because nothing in the protocol asked for proof. The root zone was signed with DNSSEC on 15 July 2010, giving resolvers a way to check an answer against a key. Signing the root did not settle the wider question of whose assurances the internet runs on: the certificate authorities came apart in March 2011, and a trusted intermediary has been the cheapest way in ever since. Pwn2Own became an institution with prize pools past a million dollars, and the browsers it broke in a weekend were hardened by the kind of sandbox that kept Chrome standing in 2010.