The disorder began in Tottenham on the evening of 6 August 2011, two days after police shot Mark Duggan there, and ran until 11 August through Croydon, Hackney, Birmingham, Manchester, Salford, Liverpool and Nottingham. Five people died. More than three thousand arrests had been made by 10 August, and the damage was later put at around £200 million. Within a day the argument about how it had spread had narrowed to a single application. BlackBerry Messenger was free where a text message cost money, it carried to closed groups rather than to the open web, and it was common on younger handsets; police and politicians concluded that this was where the meeting points had been set. Twitter and Facebook, being public, were read as much as blamed.
As the disorder spread, Research In Motion said it felt for those affected by the weekend's riots in London, that it had engaged with the authorities to assist in any way it could, and that, as in every market where BlackBerry was sold, it co-operated with local operators, law enforcement and regulators. In Britain that co-operation ran through the Regulation of Investigatory Powers Act. On 9 August the company's Inside BlackBerry blog was defaced. A crew calling itself TeaMp0isoN told the company it would not assist the UK police, since people who merely owned a BlackBerry in the wrong place would be charged for nothing, and threatened to publish the names, addresses and telephone numbers of the company's own staff, and to pass them to rioters, if chat logs or locations were handed over. By then the question had moved from the company to Parliament.
The Commons was recalled on 11 August. "Everyone watching these horrific actions will be struck by how they were organised via social media," David Cameron told the House. "Free flow of information can be used for good, but it can also be used for ill, so we are working with the police, the intelligence services and industry to look at whether it would be right to stop people communicating via these websites and services when we know they are plotting violence, disorder and criminality." The objection was immediate and comparative. Critics noted that Britain had publicly welcomed the use of the same tools by protesters in Egypt and Iran, and that a power to stop people communicating was the power those governments had reached for. What went unanswered was who would decide, and on what evidence.
The courts moved faster than the policy. On 16 August two men in their early twenties were each sentenced at Chester Crown Court to four years for setting up Facebook pages inviting disorder in two Cheshire towns; no disorder followed, residents having reported the pages, and the Court of Appeal upheld the sentences that October. On 24 August the Home Office said the questions for the next day's meeting included "whether and how we should be able to stop people communicating via these websites and services when we know they are plotting violence, disorder and criminality". On 25 August the Home Secretary, Theresa May, met police chiefs and executives from Facebook, Twitter and BlackBerry Messenger. The government sought no additional power to close or restrict the networks. The meeting was about helping the police use them better.
Taken offline
On 11 August 2011 the Bay Area Rapid Transit authority switched off mobile phone service for about three hours during the evening commute at four stations in downtown San Francisco. A protest had been called on the Civic Center platform over the fatal shooting of a man there by a BART officer on 3 July. BART said organisers were using mobile devices to coordinate disruption, that the interruption was lawful and meant to keep passengers safe. Anonymous answered under the banner #OpBART: on 14 August it broke into the marketing site mybart.org and published the names, addresses and passwords of about 2,400 people who had registered there, and on 15 August a protest at Civic Center forced BART to close four downtown stations during the evening commute. Hong Kong lost a different piece of plumbing. On 10 August the exchange's news site, HKExnews, went down and trading was suspended in seven stocks due to publish price-sensitive results there, HSBC and Cathay Pacific among them; the chief executive, Charles Li, called it a malicious attack from outside, and said the trading systems were untouched. A Hong Kong businessman, Tse Man-lai, was jailed for nine months in 2012 — not for that outage but for attacks on the same site on 12 and 13 August, mounted to advertise his own defence against them.
Seventy-one, and the arguing
McAfee published its account of what it called Operation Shady RAT on 2 August 2011, with an exclusive in Vanity Fair. Dmitri Alperovitch, the company's vice-president of threat research, had read one command-and-control server's access logs and counted seventy-one compromised parties — much of the press reporting rounded the figure to seventy-two — most of them American, among them thirteen defence contractors, the United Nations, the ASEAN secretariat and five sporting bodies, the International Olympic Committee and the World Anti-Doping Agency among them; the oldest intrusions in his list began in mid-2006. McAfee said the pattern of victims suggested a state actor, and named none. Symantec's Hon Lau replied that same week, in a post titled "The Truth Behind the Shady RAT", that this was one of many such attacks taking place daily and, given the errors in the server's configuration and the unremarkable malware, not a truly advanced persistent threat. Kaspersky Lab published its own analysis on 18 August: there was no evidence of what, if anything, had been taken from the infected machines, and defects in the code argued against a well-funded state operation. Its chief security expert, Alex Gostev, added that the campaign had been known to researchers for months, and Eugene Kaspersky, writing the same day, called the malware primitive and the report alarmist. McAfee said a law-enforcement investigation kept it from saying more. In the last days of the month certificate errors began appearing on Iranian internet providers — a quieter discovery, and September's story.
The fast that ran on missed calls
Delhi Police detained Anna Hazare early on 16 August 2011, before he could begin his fast, with more than a thousand of his supporters; he was remanded to Tihar Jail after refusing to sign a personal bail bond, and by that evening, the detention having plainly made matters worse, an order for his release had been issued — he declined to leave until he had somewhere to fast. He walked out on 19 August to Ramlila Maidan with police permission to fast for fifteen days. Both Houses passed a resolution on 27 August accepting three of his conditions, and he ended the fast on 28 August. The mobilisation ran on telephones. The campaign's missed-call number, run by the Mumbai messaging firm Netcore, was reported to have taken more than a crore missed calls in the months before the August fast; bulk SMS, email, Facebook pages and Twitter hashtags did the rest.
Nothing was switched off. In the fortnight Britain spent debating whether to stop people communicating, the Indian state detained the organiser and left the network alone. It did not stay that way. On 17 August 2012, after rumours of reprisals against people from the north-east spread by text message following violence in Assam, the government capped bulk SMS at five messages per SIM a day for fifteen days, raising the limit to twenty on 23 August; district internet shutdowns became ordinary within a few years. The demand itself was met slowly: the Lokpal and Lokayuktas Act received assent on 1 January 2014, and the first Lokpal took office in March 2019. A written reply in Parliament, reported that August, put the number of hacked government websites at 117 for the first half of 2011; none had to be reported to anyone on a clock. Since April 2022 CERT-In requires six hours.
The free class that outgrew Stanford
Sebastian Thrun and Peter Norvig had opened Stanford's introduction to artificial intelligence to anyone who wanted it, free and online, and the sign-ups became the story. The New York Times put registrations at more than 58,000 on 15 August 2011, from over 175 countries, and the count ran on past a hundred thousand before the month ended. None of those students would receive Stanford credit; those who finished were promised a statement of accomplishment. Two sibling courses opened on the same terms, Andrew Ng's introduction to machine learning and a class on databases. What Thrun built out of that audience came five months later, in January 2012. On 18 August IBM announced two experimental chips it called cognitive computing, built under DARPA's SyNAPSE programme with phase funding the company put at about $21 million: each core carried 256 digital neurons, one holding 262,144 programmable synapses and the other 65,536 that could learn. Dharmendra Modha, who led the work, framed it as moving "beyond the von Neumann paradigm". The line ran on to the million-neuron TrueNorth chip of 2014 and NorthPole in 2023, research silicon throughout.
Paying for the defence, not the bug
Microsoft announced the BlueHat Prize at Black Hat in Las Vegas on 3 August 2011: $200,000 for the best defensive technology, $50,000 for the runner-up, an MSDN subscription valued at $10,000 for third, and a pool the company put at more than $250,000. Entries closed on 1 April 2012. The terms asked not for vulnerabilities but for mitigations that would shut off whole classes of memory-safety exploitation — Matt Thomlinson of Trustworthy Computing put the interest as "developing innovative solutions rather than discovering individual issues". Twenty arrived, and all three finalists had attacked return-oriented programming. Vasilis Pappas of Columbia University took the $200,000 in July 2012 for kBouncer; Ivan Fratric of Zagreb took $50,000 for ROPGuard, whose checks Microsoft had drawn on for four defences shipped days earlier in the EMET 3.5 preview. The contest ran once, and in June 2013 gave way to standing bounties of $100,000 for a mitigation bypass. On 28 August F-Secure described Morto, a worm that spread over Remote Desktop by guessing about thirty common administrator passwords, and exploited nothing at all.
⏳ Time capsule — August 2011
- On 5 August Standard & Poor's cut the credit rating of the United States from AAA to AA+ with a negative outlook, the first downgrade in the rating's history.
- Also on 5 August, at 16:25 UTC, NASA launched Juno on an Atlas V from Cape Canaveral; the spacecraft took nearly five years to reach Jupiter, entering orbit on 5 July 2016.
- On 23 August, at 1.51 in the afternoon Eastern time, a magnitude 5.8 earthquake centred in Louisa County, Virginia, was felt across more than a dozen states; it cracked the stone near the top of the Washington Monument, which stayed shut to visitors until May 2014.
- On 24 August Steve Jobs resigned as chief executive of Apple and the board named Tim Cook in his place.
The power nobody took
Britain never built a kill switch. The route it took instead was interception law: the Investigatory Powers Act, which received royal assent on 29 November 2016, putting the compelled removal of electronic protection on a statutory footing. The application at the centre of the argument removed itself: BlackBerry's consumer messenger closed on 31 May 2019. In the United States the question was left open. BART wrote its own policy in December 2011, permitting interruption only on strong evidence of imminent unlawful activity, narrowly tailored; California's legislature passed a bill requiring a court order, which the governor vetoed on 29 September 2012; the Federal Communications Commission, asked to rule the shutdown unlawful, opened a proceeding on 1 March 2012, took comment and issued no rules. Fifteen years on, a transit agency's authority to switch off a phone network rests on the agency's own policy.
Shady RAT's number did not last; the arguing about it did. Three security companies contradicting each other in public over scale, sophistication and what a log proves pushed the field towards reports that name the actor, publish the indicators and state the confidence. Mandiant did exactly that in February 2013, naming a unit of the Chinese army and the Shanghai building it worked from; on 19 May 2014 a grand jury in Pittsburgh indicted five of that unit's officers, the first criminal charges brought against named state hackers. Nobody was ever charged over Shady RAT, and the seventy-one were never named. Alperovitch left for a company of his own. What he was criticised for in 2011 — publishing a count and a suspicion, and asking the reader to take both on trust — is now what such reports are written to avoid.