The letter went up on RSA's website on 17 March 2011 and was filed with the Securities and Exchange Commission the same day, as an exhibit to a Form 8-K from EMC, RSA's parent. It opened without drama: "Like any large company, EMC experiences and successfully repels multiple cyber attacks on its IT infrastructure every day." Then it said that the company's security systems had identified "an extremely sophisticated cyber attack in progress being mounted against RSA", that the investigation placed it "in the category of an Advanced Persistent Threat (APT)", that the attack "resulted in certain information being extracted from RSA's systems", and that "Some of that information is specifically related to RSA's SecurID two-factor authentication products." It was signed Art Coviello, Executive Chairman.

What it did not say was which information. SecurID worked on a shared secret: each token held a seed, the authentication server held a copy, and the six digits on the screen were the product of that seed and the clock. If seeds had gone, an attacker who also had a serial number, a username and a password could in principle produce the digits. Coviello wrote that RSA was "confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers", while allowing that it "could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack". A second exhibit, a note from RSA's support site, told customers to watch their logs and guard their serial numbers.

How they got in was not described that month. RSA's own account came on 1 April, in a post by Uri Rivner: two small groups of employees, none senior, were sent a message over two days; it went to a junk folder; one retrieved it and opened the attached spreadsheet, which carried a Flash object exploiting CVE-2011-0609, a hole Adobe had warned of on 14 March and not yet fixed. It installed a customised Poison Ivy, an off-the-shelf remote-access tool, and began collecting credentials for machines that mattered. The message surfaced only in August, when Timo Hirvonen of F-Secure sifted his firm's malware collection for embedded Flash and found an Outlook file sent on 3 March to four EMC employees, subject "2011 Recruitment plan", one line of text: "I forward this file to you for review."

The answer the letter withheld arrived at a customer. On 2 June RSA confirmed that information taken in March had been used as an element of an attempted broader attack on Lockheed Martin, which had cut its own remote access the previous month — May's story, along with the token replacement RSA went on to offer, and not retold here. The cost appeared in EMC's accounts: a $66.3 million charge in the second quarter of 2011 "related to the expansion of the customer remediation programs", with $81.3 million in reserve at 30 June. That was the price of remediation, not of lost business, and no measure of what any customer lost. In March, EMC had told the Commission it did not expect a material financial impact.

Also that month · 15–23 March

Nine Certificates, One Reseller

Between six and eight on the evening of 15 March 2011, an attacker with a username and password for one of Comodo's registration authorities — resellers permitted to approve certificate requests — made a new account there and had nine certificates issued from the UTN-UserFirst-Hardware root. The names were mail.google.com, www.google.com, login.yahoo.com three times, login.skype.com, addons.mozilla.org, login.live.com and "global trustee", which is not a domain at all. Comodo revoked them and told the browser makers. Mozilla, informed at 21:47 GMT on 16 March, shipped Firefox 4, 3.6.16 and 3.5.18 on 22 March with ten serial numbers written into a blacklist — the nine and a test certificate — because revocation checking could not be trusted to reach everyone. Comodo published its account on 23 March, the day Microsoft issued Security Advisory 2524375. It said the attack came mainly from Iran, its principal address resolving to Tehran, and that one certificate, for login.yahoo.com, had been "seen live on the internet"; it called the attack state-driven, an inference rather than a finding. Someone posting as ComodoHacker claimed it and published a private key, saying he had acted alone and for no government — which Comodo's reading did not accept and nobody could check. The same name claimed a Dutch authority that September.

Also that month · 16 March

The Morning the Spam Stopped

Shortly before eleven in the morning Eastern time on 16 March 2011, Rustock's command servers went off the air within minutes of one another and the mail stopped. Microsoft's Digital Crimes Unit had filed a civil action in the United States District Court for the Western District of Washington in February, with Pfizer as co-plaintiff — the botnet's business was counterfeit pharmaceuticals and fake Microsoft lottery mail — and had obtained an order to seize. On the day, United States marshals accompanied Microsoft's people to five hosting providers in seven cities: Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus. Evidence was taken on the premises and in some instances the servers themselves were carried away. Microsoft called the operation b107 and credited FireEye, the University of Washington, the Dutch High Tech Crime Unit and China's CN-CERT. It put the network at roughly a million infected machines capable of thirty billion messages a day; one machine it watched sent 7,500 in 45 minutes. Researchers tracking global spam volumes — the Composite Block List timed the collapse at 14:45 GMT — recorded Rustock's output falling to essentially zero and staying there. Nobody was arrested that month; what Microsoft did about that belongs to July.

India desk · March 2011

The Cables and the Question of Proof

From 15 March 2011 The Hindu began publishing stories drawn from about 5,100 United States diplomatic cables concerning India, six million words, obtained from WikiLeaks under an arrangement N. Ram described as involving no money either way and no editorial control over the stories. On 17 March it printed one dated 17 July 2008, signed by the chargé d'affaires in New Delhi, Steven White, five days before the confidence motion on the nuclear deal. In it an embassy employee reported an aide to the Congress member Satish Sharma saying ten crore rupees had gone to each of four members of another party, and showing two chests of cash. Sharma called the account baseless.

The row was about what a document is. On 17 March the finance minister, Pranab Mukherjee, told Parliament that correspondence between a sovereign government and its missions enjoys diplomatic immunity, so India could neither confirm nor deny it; the Lok Sabha was adjourned twice and the opposition walked out demanding the prime minister's resignation. Manmohan Singh told the House the next day that the government could not confirm the veracity, content or even the existence of the cables; Julian Assange called that misleading. A parliamentary committee examining the 2008 episode had found no evidence of bribery that December; the cables reopened it, and a Delhi police case brought arrests later in 2011. Two weeks earlier, on 3 March, the Supreme Court had quashed the appointment of the Central Vigilance Commissioner as void in law: the file on a pending criminal case against him never went before the committee that chose him — the month's other story about a paper nobody produced. India's duties over records held on people came later.

AI Tech desk · March 2011

Thrun shows Google's driverless car at TED

Google's self-driving car, disclosed the previous October, had its first public showing at TED in Long Beach in early March 2011, where attendees were given rides on a closed course and Sebastian Thrun, the Stanford professor leading the project, spoke for four minutes. He opened with the friend he lost to a road accident at eighteen and the aim it left him, "saving one million people every year", called the talk a progress report, and showed the car threading city traffic and the bends of Lombard Street. The cars had driven 140,000 miles, he said. TED posted the talk on 31 March. The project became Waymo in 2016 and now sells rides with nobody at the wheel; the miles reached 300,000 in 2012, the year of Nevada's first licence and California's law. On 9 March the ACM named Leslie Valiant of Harvard winner of the 2010 Turing Award, citing among other work his 1984 theory of probably approximately correct learning, still the frame for what a machine can learn.

Digital Guard desk · March 2011

Fifty-eight apps and a kill switch

On 1 March 2011 a Reddit user noticed that a publisher on the Android Market had taken popular applications, injected a root exploit and republished them; Google pulled them within minutes of being told. Lookout, which named it DroidDream, found more, and on 5 March Google's Rich Cannings put the count at 58 applications and about 260,000 downloads, on phones running versions below Android 2.2.2. Google used the remote removal it had reserved for itself and pushed a fix called Android Market Security Tool March 2011 — and on 9 March Symantec found a trojanised copy of the tool, apparently from a Chinese third-party site. On 23 March McAfee announced its first purchase as an Intel subsidiary, Sentrigo of Santa Clara, a database-security firm, on undisclosed terms. From 29 March Websense tracked a mass SQL injection it called LizaMoon, pushing a rogue product named Windows Stability Center; its count of over a million addresses, it allowed, overstated the sites hit, and Google's Niels Provos later found about 5,600. The Market is Google Play now, its guard Play Protect.

⏳ Time capsule — March 2011

  • On 9 March the Space Shuttle Discovery touched down at the Kennedy Space Center at 11.57 in the morning Eastern time, ending STS-133 and a career of 39 missions begun in 1984, with a cumulative year spent in space.
  • On 11 March a magnitude 9.0 earthquake off the Oshika Peninsula and the tsunami that followed killed close to twenty thousand people in Japan and began the accident at the Fukushima Daiichi nuclear station.
  • On 23 March Elizabeth Taylor died in Los Angeles at the age of 79, twice an Academy Award winner for best actress, for BUtterfield 8 and Who's Afraid of Virginia Woolf?
  • On 30 March India beat Pakistan by 29 runs in the Cricket World Cup semi-final at Mohali, Sachin Tendulkar named man of the match, with the prime ministers of both countries invited to watch from the ground.
Where it stands today — 2026

The month the middlemen failed

All three of March's stories were about custodians. RSA held the seeds that made other companies' tokens work; Comodo held the power to vouch for any name on the web; hosting firms in seven American cities held the machines that told a million computers what to send. In each case the compromise of a third party became its customers' problem, and in each case the customers heard late and were told less than they wanted to know. The pattern had no settled name in 2011. By December 2020, when a monitoring product's own updates carried a backdoor into United States federal networks, it was the first thing anyone looked for.

RSA's answer was to replace tokens rather than the idea behind them, and the shared secret survived another decade; what eventually displaced it was hardware that never lets its key out, in the FIDO standards and the passkeys the large platforms now offer. RSA itself passed from EMC to Dell, and then in September 2020 to a consortium led by Symphony Technology Group for $2.075 billion. Comodo's certificate business was sold to Francisco Partners in 2017 and renamed Sectigo the year after; it still issues, and no root was removed over March 2011. Microsoft's court-order takedown became a template it used many times. The gap the letter opened — a company that knew, and customers who did not — is now a legal question in India, where a breach has to be reported within six hours.