Eric Butler, a software developer, announced Firesheep at ToorCon 12 in San Diego on Sunday 24 October 2010, presenting with Ian Gallagher, a security consultant with Security Innovation in Seattle, in a talk whose title told the social web to stop pretending to protect its users' privacy and start doing it. Installed in Firefox, the add-on opened a sidebar with a button marked Start Capturing. On a busy open wireless network, the kind found in a café or an airport, it waited, and whenever someone nearby visited one of the sites it knew, that person's name and photograph appeared in the list. A double-click, and the Firesheep user was inside the account. It was free, its source code was public, and it ran on Windows and Mac OS X.
Nothing in it was new. A website checked a password, often over an encrypted connection, and then handed the browser a cookie that travelled back with every later request in plain text; on an open network, Butler wrote, that cookie was as good as broadcast, and whoever caught it could present it as their own. Robert Graham of Errata Security had shown as much at Black Hat in Las Vegas in August 2007, picking conference-goers' Gmail sessions out of the air with two tools he called Ferret and Hamster. Gmail had made encryption its default in January 2010. Facebook, Twitter, Flickr, Tumblr, Yelp and Amazon, among the few dozen sites Firesheep knew, had not, and the only real fix, Butler argued, was to encrypt the whole session.
The downloads were counted by the day. Butler wrote on 26 October that the add-on had been downloaded more than 129,000 times in just over a day, and three weeks later of the hundreds of thousands of people it had drawn in — counts of downloads and attention, not of accounts taken. Mozilla, which that same week was rushing out a fix for a Firefox flaw being exploited from the Nobel Peace Prize website, declined to use its add-on blocklist: Firefox's director, Mike Beltzner, said the tool exposed a weakness in websites and exploited none in the browser. Microsoft took the other view. By the first days of November its anti-malware products were flagging the add-on, which its threat encyclopedia listed on 2 November as HackTool:JS/Firesheep; Butler replied that what people ran on their own computers was nobody else's business.
Some answered the tool. FireShepherd flooded a network with junk traffic meant to confuse Firesheep, which Butler said gave no real security; Idiocy took over Twitter sessions itself to post warnings from the victims' own accounts; Zscaler's BlackSheep, announced on 8 November, reused Firesheep's code to warn when a session appeared to be hijacked. Others answered the cause. Mozilla pointed site owners to Strict Transport Security, and on 29 October the Electronic Frontier Foundation told them to encrypt every page, citing Google's figure that encryption took under one per cent of a server's processing. By mid-November Hotmail had announced full-session encryption as an option, and GitHub and Dropbox had made changes. Facebook followed in January 2011 with a setting that encrypted a whole visit, and Twitter in March.
Aimed at the Mules
The arrests covered three countries in four days. At dawn on 28 September 2010 Scotland Yard's Police Central e-Crime Unit arrested nineteen people around London; within two days eleven of them, Ukrainian, Latvian and Georgian nationals among them, had been charged over frauds put at some £6 million taken from British bank accounts in three months. On 30 September the United States Attorney in Manhattan, Preet Bharara, charged thirty-seven people, most of them money mules who had arrived on student visas and opened accounts on false passports; the city's police came in after a suspicious $44,000 withdrawal at a Bronx bank that February. Ukraine's security service detained five the same day. On 1 October the FBI said the scheme had attempted to steal $220 million, with actual losses of $70 million, and Gordon Snow of its cyber division spoke of pursuing those who had built and controlled the malware as well as the mules. Most of those were never caught. The two men running the British end were jailed in Britain in 2011 and extradited to the United States in 2014; Vyacheslav Penchukov, whom American prosecutors call a leader, slipped away in 2010 and got nine years in July 2024; the author of Zeus was never caught — June 2014's story.
What the Cars Heard
Canada sent technicians to Mountain View to sample the disks. Street View cars had logged Wi-Fi routers for Google's location services since 2007; only in May 2010, when Hamburg's data-protection authority asked what the cars collected, did the company find they had also recorded traffic from open networks and ground them; nobody inside, it later said, had examined the data closely. On 19 October the privacy commissioner, Jennifer Stoddart, published the findings: names, telephone numbers and addresses, medical conditions listed against named people, a note of someone stopped for speeding and, surprisingly often, unencrypted cookies carrying personal information. The engineer who wrote the code had called its privacy implications superficial, and it never reached the lawyers. On 22 October Google's Alan Eustace conceded that “in some instances entire emails and URLs were captured, as well as passwords”, apologised, and named Alma Whitten director of privacy. The Federal Trade Commission closed its inquiry on 27 October on Google's assurance that the data had never been used; on 3 November Britain's Information Commissioner found a significant breach and took an undertaking, not a fine. American states settled for $7 million in 2013.
What CERT-In Counted
India's national computer emergency response team kept its own count, month by month. In the annual report for 2010 that CERT-In issued on 9 March 2011, October's line records 274,224 infected systems tracked in botnets and 11 command-and-control servers. The monthly figures ran from about 32,000 in July to more than two million in May, a spread that says as much about what the team could see as about what was infected, and they do not add up to the total the same report prints for the year. Over 2010 it handled 10,315 incidents, mostly phishing, malicious code, compromised websites and scanning. It called Zeus, the trojan behind the month's arrests abroad, the most effective botnet of the year, and noted Zitmo, a Symbian companion that forwarded victims' text messages to another number.
It also recorded where attacks were moving, onto the social sites Firesheep had embarrassed: shortened links sent as bait, and Koobface posing as a video player to reach Facebook's users. Its October entries are workshops — on mail-server security on the 8th and Windows security on the 20th, and two on secure coding with Japan's JPCERT/CC from the 26th — while the Commonwealth Games ran in Delhi from 3 to 14 October without any reported attack on their systems that this archive could find. The BlackBerry argument of August went into extra time: on 29 October, by RIM's account, the home ministry acknowledged its progress and let the messenger service continue, and the deadline moved to 31 January, January 2011's story. In 2010 CERT-In counted what it could see; since April 2022 organisations have had to tell it within six hours.
Google's self-driving cars come to light
On 9 October 2010 the New York Times disclosed that Google had been testing cars that drove themselves in California traffic. With a driver behind the wheel and a technician in the passenger seat, seven of them had covered 1,000 miles without human intervention and more than 140,000 with only occasional human control; the only accident, the engineers said, came when one was rear-ended while stopped at a traffic light. Sebastian Thrun, who led it, described the project on Google's blog that day, naming engineers from the DARPA challenges and routes from Lombard Street to Lake Tahoe, and wrote that the technology might cut road deaths “perhaps by as much as half”. The Times put even the most optimistic deployment more than eight years away; Waymo opened its first commercial service, around Phoenix, in December 2018. On 28 October the driverless electric vans that had left Parma in July reached the Shanghai Expo, after three months on the road through Moscow, Kazakhstan and western China.
SpyEye's author takes over Zeus
On 24 October 2010 Brian Krebs reported that two rival banking-trojan kits were to merge. In an 11 October post to an exclusive underground forum, the author of SpyEye, who wrote as Harderman and Gribodemon, told Zeus's customers he would now support them, having been given its source code “free of charge”, and offered them a discount on SpyEye; Slavik, Zeus's author, was said to have removed the code from his computer and stepped away. Some researchers were sceptical. By early 2011 betas of SpyEye 1.3 let buyers run their botnets from either kit's control panel, and Krebs later called Slavik's retirement staged. On 25 October Dutch police shut down 143 Bredolab servers at the hosting firm LeaseWeb and used the botnet to send victims to a warning page, a step G Data said might be illegal in several countries. Georgy Avanesov, suspected of running it, was arrested at Yerevan's airport the next day; jailed in Armenia for four years in May 2012, he admitted writing the malware but said he had passed it on.
⏳ Time capsule — October 2010
- On 1 October The Social Network, David Fincher's film of Aaron Sorkin's screenplay about the founding of Facebook, drawn from Ben Mezrich's book The Accidental Billionaires, opened in American cinemas with Jesse Eisenberg as Mark Zuckerberg, a week after its premiere at the New York Film Festival.
- From 3 to 14 October Delhi held the first Commonwealth Games in India, opened at the Jawaharlal Nehru Stadium by the Prince of Wales and President Pratibha Patil: 4,352 athletes from 71 nations and territories in 272 events, with India second in the medal table behind Australia, on 38 golds and 101 medals, its best Games.
- On 13 October the last of the 33 miners trapped for 69 days in the San José mine near Copiapó, in Chile's Atacama, was brought to the surface in the capsule Fénix 2; the first, Florencio Ávalos, had come up eleven minutes after midnight, and the last, Luis Urzúa, came up at 9.55 that evening.
- On 31 October Dilma Rousseff won the run-off for the presidency of Brazil with 56.05 per cent of the vote to José Serra's 43.95, the first woman elected to the office.
The fix Butler asked for
The fix Butler named, encrypting the whole session, is what the web did, in steps, over most of a decade. Facebook's setting of January 2011 and Twitter's of that March were later made the default; Strict Transport Security, which Mozilla urged on site owners that week, was standardised by the IETF in November 2012; the disclosures of June 2013 pushed the large services to encrypt even the links between their own data centres; and since July 2018 Chrome has marked every plain-HTTP page as not secure. The attacks moved with the traffic, onto the encryption itself: BEAST recovered a session cookie from TLS a byte at a time in September 2011, and POODLE did it by pushing browsers back to the older SSL in October 2014.
The other two stories ended less tidily. The Zeus source code leaked the following year and its descendants carried the business on, among them GameOver Zeus, pulled from under its operators by court order in 2014; the man the United States names as the original author has never been arrested. The accounts that received and forwarded the money were the weak point then and remain the place to intervene: in India the advice now turns on reporting within the first hour, while a transfer can still be frozen downstream. Google's cars had stopped listening on 7 May 2010; the Federal Communications Commission later fined the company $25,000 for impeding its inquiry. And WPA2, the protocol that locked home networks, turned out in October 2017 to accept the same handshake twice.