The claim came out of Hamburg in mid-September 2010. Langner Communications, a three-man firm whose engineers sometimes trained Siemens employees on Siemens's own products, said that Stuxnet, the worm found in July, was a directed attack on one specific control-system installation. On 16 September Ralph Langner wrote that it was "evident and provable that Stuxnet is a directed sabotage attack involving heavy insider knowledge". The worm, he explained, took the fingerprint of each industrial controller it reached; if the machine was not the one it had been built for, it left it alone. The following week he took the evidence to Rockville, Maryland, to a closed meeting of control-system engineers whose host, Joe Weiss, had given him 45 minutes. He spoke for an hour and a half.
His guess at the installation was Bushehr, the Russian-built reactor in south-western Iran, whose start-up, he noted, had been expected in August and had slipped. He called it a guess: "If Bushehr wasn't the target and it starts up in a few months, well, I was wrong." On 22 September Frank Rieger, a spokesman for the Chaos Computer Club, argued in the Frankfurter Allgemeine Zeitung for Natanz, which was already enriching uranium. Symantec had reported on 6 August that the worm could slip code into a Siemens controller and hide it, and it had the geography: about 60 per cent of infected computers were in Iran, and from 22 August no new Iranian infections called home — most likely, Symantec judged, because Iran had blocked the connections, not because infections had stopped.
Iran spoke at the month's end. On 25 September Mahmoud Liaee, who ran the information technology council at the Ministry of Industries and Mines, said 30,000 IP addresses had been infected — addresses, not machines — and described a worm that made industrial systems send production-line data to a designated destination: espionage, in his reading, and "an electronic war" launched against Iran, though he named no one. On 26 September Mahmoud Jafari, Bushehr's project manager, said several personal computers belonging to staff at the plant were infected, that its main systems were undamaged and that there was no problem with its fuel supply. Siemens said its software had not been installed there. The state-run Iran Daily quoted the telecommunications minister, Reza Taghipour, as saying the worm had not caused "serious damage" to government systems.
At the end of the month the researchers took what they had to the Virus Bulletin conference in Vancouver. Symantec presented, and on 30 September published its W32.Stuxnet Dossier, which counted about 100,000 infected hosts as of 29 September and read the concentration in Iran as the likeliest sign of where the worm had been seeded; Microsoft and Kaspersky Lab presented together. What the code did to the machinery on the far side of the controller was still unread. The reactor Langner had guessed at was connected to the grid on 3 September 2011, after a delay Rosatom put down to a damaged cooling pump. What the worm was hunting belongs to November; how it was tested and who built it, to January 2011 and June 2012.
The Document I Told You About
On 9 September 2010 an email headed "Here you have" filled corporate inboxes: "this is the document I told you about, you can find it here." The link looked like a PDF and fetched a screensaver file from members.multimania.co.uk. Once run, it mailed itself to the address book, copied itself to drives and network shares, tried to stop security software and installed a password stealer and a backdoor. Cisco put it at between 6 and 14 per cent of the world's spam for a few hours that Thursday. ABC News named NASA, Comcast, AIG, Disney, Procter & Gamble and Wells Fargo among the organisations "apparently affected", without confirmation from the companies themselves. McAfee named it VBMania, rated the risk low and advised blocking .scr files at the gateway. That weekend someone calling himself Iraq Resistance claimed it in a video against the invasion of Iraq: "I can smash all of those infected, but I wouldn't." SecureWorks' Joe Stewart found the name in the code and in an earlier version's email address, allowing that someone might want the group to look involved. Symantec's write-up of the family, W32.Imsolk.A@mm, was dated 20 August.
What the Error Page Said
Late on Friday 17 September 2010, at the Ekoparty conference in Buenos Aires, Juliano Rizzo and Thai Duong showed how to break the encryption ASP.NET wrapped around the state it handed to browsers. The framework encrypted view state and cookies without authenticating them, and answered tampered ciphertext with errors that told a right guess from a wrong one — the padding oracle Serge Vaudenay had described in 2002. By the pair's later count, fewer than 2,000 requests could take a site's keys, or its web.config file, which often held database passwords; with the keys an attacker could forge a ticket to sign in as any user, administrator included. Beforehand they had said it "totally destroys ASP.NET security". Microsoft's advisory followed that day; on 18 September its Scott Guthrie told developers to send every error to one identical page — a workaround that, the pair later wrote, mitigated part of their first attack and none of their second. On 28 September Microsoft shipped MS10-070 out of band, aware of "limited, targeted attacks"; Windows Update carried it from 30 September. A year later, at the same conference, the pair broke TLS 1.0.
Ten Numbers in Tembhli
On 29 September 2010 the Unique Identification Authority of India issued its first numbers in Tembhli, a tribal village in Nandurbar district of Maharashtra, where ten residents received them. The prime minister, Manmohan Singh, handed the first letter to a woman of the village, in the presence of Sonia Gandhi, chairperson of the United Progressive Alliance. Each number ran to twelve digits and was tied to a photograph, ten fingerprints and both irises; it was offered to residents, not only to citizens, and was presented as a way to cut fraud and to reach people who could not establish their claim to government services. By December, according to Shankkar Aiyar's history of the programme, it had been accepted as proof of identity for opening a bank account.
The numbers were issued without a law behind them. The Planning Commission had created the authority by notification in January 2009 and given its chairman, Nandan Nilekani, a co-founder of Infosys, the rank of a Cabinet minister; a bill to put it on a statutory footing went to the Rajya Sabha on 3 December 2010, a parliamentary committee rejected it a year later, and the Aadhaar Act passed only in March 2016. The security and privacy arguments that followed — court orders that no one should suffer for want of the number, government websites that published numbers beside bank details, the question whether Indians had a constitutional right to privacy at all — are carried in later editions of this archive, most fully in August 2017 and September 2018, and are not retold here.
A thousand categories in Heraklion
On 11 September 2010, at a European Conference on Computer Vision workshop in Heraklion, Crete, the results of the first ImageNet Large Scale Visual Recognition Challenge were presented. Organised by Alex Berg of Columbia, Jia Deng of Princeton and Fei-Fei Li of Stanford as a taster beside the PASCAL VOC contest, it asked for up to five guesses at the label of each of 150,000 test photographs across 1,000 categories, after training on more than 1.2 million. Eleven teams entered. The winner, from NEC Labs America with the University of Illinois and Rutgers, missed with all five guesses on 28.2 per cent of images, against 33.6 for Xerox's European research centre. It was no neural network: hand-designed SIFT and LBP descriptors fed a thousand support vector machines trained by stochastic gradient descent. On 20 September Apple was reported to have bought Polar Rose, a Malmö face-recognition firm that had just closed its free photo-tagging service; neither company would confirm it. A deep network won the contest in 2012; by 2014 the winning error was 6.7 per cent.
The 2011 suites lean on reputation
The paid suites arrived in the first weeks of the month. Symantec's Norton AntiVirus and Internet Security 2011 went on sale on 8 September 2010, as did Trend Micro's new Titanium range in the United States, both leaning on reputation — files and sites judged by what the vendor's network had already seen of them rather than by signatures alone. AVG 2011 followed on 29 September, promising to check links shared on Facebook and MySpace as they arrived. Microsoft, meanwhile, was widening the ground beneath them: on 22 September it said that from early October small businesses could install Security Essentials, its free anti-virus program, on up to ten PCs, a licence that until then had covered households only. Many consumers and a growing number of small businesses, said Microsoft's Eric Foster, were "unwilling or unable" to keep paying subscriptions for the suites that came on their PCs. Norton and AVG came under one owner in 2022, in the company now called Gen Digital.
⏳ Time capsule — September 2010
- On 8 September Google introduced Google Instant, which showed results while a query was still being typed; Marissa Mayer said it would save two to five seconds a search. Google withdrew it on 26 July 2017, citing the growing number of searches made on phones.
- On 13 September, a day late because of rain, Rafael Nadal beat Novak Djokovic 6–4, 5–7, 6–4, 6–2 for his first US Open title and, at 24, became the seventh man to complete a career Grand Slam.
- On 16 September Benedict XVI arrived in Edinburgh and was received by the Queen at the Palace of Holyroodhouse, opening the first papal visit to Britain made as a state visit; on 19 September he beatified John Henry Newman in Cofton Park, Birmingham.
- On 25 September, at Labour's annual conference in Manchester, Ed Miliband was elected leader of the party, beating his brother David by 50.7 per cent to 49.3 in the final round.
The month code was read for intent
September 2010 is when a worm's purpose was first set out in public from its code. Nobody had confessed and Iran admitted no serious damage; Langner and the Symantec team worked from what the program checked before it acted, and they were right about the method long before anyone could say where it had been aimed. Langner and Joe Weiss had spent years warning that industrial controllers could be attacked, and few had listened; after Stuxnet the warning needed no defence. This archive follows the idea through Duqu, built on the same frame, in October 2011; the breakers opened by remote hand in Ukraine in December 2015; and Triton, written for the safety systems of a petrochemical plant, in December 2017.
The padding oracle outlived its patch. Thai Duong returned to it with two Google colleagues in October 2014, when POODLE retired SSL 3.0, and the design the field settled on — encryption that authenticates what it carries, so that a tampered message is refused whole — is the only kind TLS 1.3 has allowed since its publication as RFC 8446 in August 2018. The twelve digits handed out in Tembhli, presented as a way to reach people who could not prove who they were, acquired a statute in 2016, a boundary drawn by the Supreme Court in 2018 and, only with the Digital Personal Data Protection Act of 2023, a general law on personal data; what that Act requires is set out on our India desk.