On 27 August 2011 a user of the Gmail Help Forum, posting as alibo, wrote that he could not reach his account from Iran and that it vanished through a virtual private network. He attached a screenshot of Chrome refusing a certificate for google.com. "I think my ISP or my government did this attack (because I live in Iran and you may hear something about the story of Comodo hacker!)" he wrote. Researchers found nothing forged in the file. It was a valid wildcard certificate for Google's domains, issued on 10 July 2011 by DigiNotar, a small Dutch certificate authority, and it would have satisfied almost any browser on earth. Chrome objected only because Google had pinned its own domains to a short list of issuers that did not include DigiNotar.
Google and Mozilla went public on 29 August, and the certificate was revoked that evening. DigiNotar brought in the Dutch firm Fox-IT on 30 August; it called the inquiry Operation Black Tulip, and by then the company's own parent had conceded that DigiNotar detected an intrusion into its certificate authority infrastructure on 19 July 2011 and told nobody outside. Mozilla, announcing on 2 September that it was removing the roots altogether, wrote that more than 200 certificates had been issued against more than 20 domains, addons.mozilla.org among them, that DigiNotar had quietly revoked some of them six weeks earlier without saying so, and that "it is therefore impossible for us to know how many fraudulent certificates exist, or which sites are targeted." On 4 September the Mozilla developer Gervase Markham put the confirmed count at 531, in names including the CIA, MI6 and Mossad; Fox-IT's final report identified the same number and called even that list non-exhaustive.
The measure of the harm came out of a revocation log. Every browser that met the counterfeit certificate had asked DigiNotar's service whether it was still valid, and the queries were recorded: close to 300,000 unique addresses, of which Fox-IT put 95 per cent in Iran, most of the remainder resolving to proxies, Tor exit nodes and VPNs. That is a count of machines that checked, not of accounts read; the report did not claim otherwise. Fox-IT said several traces independently pointed to a perpetrator in Iran, and that the intruder appeared to have intended to abuse a trusted party's certificates to spy on a large number of Iranian users. On 5 September a man calling himself Comodohacker claimed the intrusion on Pastebin, said he was a 21-year-old Iranian and claimed access to four more authorities. That was a claim, and stayed one.
DigiNotar also signed for the Dutch state under its PKIoverheid programme, which is how a private failure became a government one. On 3 September the state said it would take over operational management of DigiNotar's systems, and the Fox-IT inquiry with them. Apple shipped Security Update 2011-005 on 9 September; iPhones waited for iOS 5 on 12 October. GlobalSign, named in that post, suspended new certificates and resumed a week later; its December report found its web server breached and that server's certificate stolen, the issuing machine air-gapped and untouched. DigiNotar, which VASCO Data Security had bought in January 2011, filed a voluntary bankruptcy petition in Haarlem on 19 September; the court declared it bankrupt the next day. Later that month the Ministry of the Interior revoked both PKIoverheid roots, effective 28 September.
Eighty-three machines in Kobe and Nagoya
On 19 September 2011 Mitsubishi Heavy Industries confirmed that 45 servers and 38 personal computers at its plants and offices were carrying at least eight kinds of malicious software. The sites named were the Kobe Shipyard and Machinery Works, which builds submarines and components for nuclear power stations, the Nagasaki Shipyard and Machinery Works, and the Nagoya Guidance and Propulsion Systems Works, which makes missiles and rocket parts. The company said it had found the infections in August. It had not told the defence ministry, which learned of them from press reports and demanded a full investigation, saying a report should have been made; contractors were obliged to notify ministers promptly of breaches touching sensitive information. The defence minister said he had received no report of classified information having been taken. A spokesman said the company had no clues as to who was behind it, that crucial data about its products and technologies had so far been kept safe, and that network details such as addresses might have leaked. No public attribution was made that month. Japan's parliament and more of its defence industry followed in October.
What broke underneath
Two of the month's failures were in the floor, not the walls. On 23 September, at the Ekoparty conference in Buenos Aires, Thai Duong and Juliano Rizzo demonstrated BEAST against a live PayPal session. The weakness was old and documented: in SSL 3.0 and TLS 1.0 each record takes its initialisation vector from the previous record's last ciphertext block, so an attacker who can make a browser send chosen text from JavaScript over the same connection and watch the result recovers a session cookie a byte at a time. OpenSSL had shipped a countermeasure in 2002, left switched off because it broke other implementations; Mozilla's bug had been open since June. The number it was given, CVE-2011-3389, outlived the month by a decade. Separately, a notice sent on 31 August told kernel.org's users that intruders had taken root on a server called Hera, that 448 credentials were exposed, and that an off-the-shelf rootkit, Phalanx, had been installed — noticed because a machine reported an Xnest error with no Xnest on it. The administrators believed the git repositories unaffected and set about proving it; the site stayed down over a month.
The pictures shown off the record
The pictures were shown off the record. On 5 September 2011 Kapil Sibal, the minister for communications and information technology, met officials of Facebook, Twitter and Orkut and put in front of them images that, by the account the Tribune published that December, depicted the Congress president, Sonia Gandhi, and the prime minister, Manmohan Singh, in a bad light, together with others insulting to various religions. He did not ask for a law. He asked the companies to build their own screening and take the material down; their refusal came later, at the meeting of 5 December with Facebook, Twitter, YouTube and Microsoft, where the executives declined to remove the material. Facebook said it wanted its site to be a place where people could discuss freely while respecting the rights and feelings of others, that it already had policies and on-site features in place, and that it would remove anything violating its terms.
The minister had leverage without a statute. The Information Technology (Intermediaries Guidelines) Rules, notified in April 2011, already obliged an intermediary to remove material a complainant called objectionable, disparaging or harmful, with no judge and no clock. By December the Department of Information Technology had held six such meetings, the Committee to Protect Journalists reported; the argument became public on 5 December and then a criminal summons in Delhi, which is January 2012's story. What nobody was obliged to report was the breaking-in. In a written reply to the Lok Sabha that August, the minister of state, Sachin Pilot, had said 117 government websites were defaced between January and June 2011, and had listed the remedy: audits before hosting, the National Informatics Centre barred from hosting unaudited sites, CERT-In advisories, a crisis plan. A defacement now has to be reported within six hours.
Watson's first customer was a health insurer
On 12 September 2011 IBM and WellPoint, a Blue Cross Blue Shield operator with 34 million members, announced an agreement to build the first commercial applications of Watson, seven months after its Jeopardy! win. The design set it against three bodies of material at once — a patient's chart and electronic records, the insurer's own history of medicines and treatments, and a library of textbooks and journals — and return options ranked by confidence, for treating physicians and for the staff weighing requests for treatment. Neither side disclosed the money. IBM's Manoj Saxena said the work fitted "the sweet spot" of what had been imagined for Watson; pilots were promised for early 2012 at cancer centres and oncology practices. On 3 September an audience at IIT Guwahati's Techniche festival had rated the chat program Cleverbot 59.3 per cent human, against 63.3 for the people it was hidden among, and on 30 September Nuance completed its €53 million purchase of Loquendo, the speech house spun out of Telecom Italia. IBM sold the health business built on that first contract in 2022.
A botnet defendant named, a browser removed
On 22 September 2011 Microsoft's Digital Crimes Unit filed in the Eastern District of Virginia against Dominique Alexander Piatti, his company dotFREE Group SRO and twenty-two unnamed defendants, announcing the case five days later; it was the first time Microsoft had named a defendant in one of its civil botnet suits. An ex parte restraining order cut the subdomains through which Kelihos took its instructions, more than 3,700 of them registered under cz.cc, a free subdomain service. Microsoft counted about 41,000 machines and as many as 3.8 billion spam messages a day, and Richard Boscovich said the company meant to "keep it down". Piatti wanted a lawyer before commenting; on 26 October Microsoft accepted neither he nor his firm had controlled the subdomains and dropped them. A successor was taken down in March 2012, and the network outlived both, its operator arrested in Barcelona in 2017. On 30 September a Security Essentials signature read Google Chrome as the Zbot trojan and deleted it from some machines; Microsoft corrected the file that morning and said about 3,000 customers were affected.
⏳ Time capsule — September 2011
- On 11 September the National September 11 Memorial was dedicated at the World Trade Center site on the tenth anniversary of the attacks, with 2,983 names inscribed on 152 bronze parapets around the two pools; it opened to the public the following day.
- On 20 September the repeal of the United States military's "Don't Ask, Don't Tell" policy took effect, sixty days after the certification sent to Congress on 22 July.
- On 23 September the OPERA collaboration reported neutrinos arriving from CERN about 60.7 nanoseconds earlier than light would have; in February 2012 the team traced the result to a loose fibre-optic cable between a GPS receiver and its master clock, and a corrected measurement in July 2012 matched the speed of light.
- On 28 September Amazon announced the Kindle Fire at $199, a colour tablet undercutting the iPad by more than half; it reached buyers on 15 November.
The month trust got a ledger
DigiNotar's failure was not a bug but the shape of the system: several hundred authorities could each sign for any name on the internet, and nothing made a signature visible to the party it was aimed at. The answer was a log. Certificate Transparency, proposed in 2012 by the Google engineers Ben Laurie, Adam Langley and Emilia Kasper and published as RFC 6962 in June 2013, turned misissuance into something a domain owner could look up; from April 2018 Chrome required it of every newly issued certificate. The lever proved usable on large authorities too: in March 2017 a Google engineer set out a plan to distrust Symantec's certificates over misissuance the company had not disclosed.
Pinning, which caught the certificate, did not generalise; the header version, RFC 7469 of April 2015, was deprecated by browsers in 2017 because a site could lock itself out of its own name. TLS 1.0, which BEAST broke that September, was formally retired only by RFC 8996 in March 2021, two and a half years after Apple, Google, Microsoft and Mozilla said together they would drop it. No court ever weighed the interception: Fox-IT's traces pointed to Iran, and a man calling himself Comodohacker claimed the work. The kernel.org case was charged — a federal grand jury indicted Donald Ryan Austin on 23 June 2016, accused of installing rootkit and trojan software with credentials belonging to someone associated with the Linux Kernel Organization — how he got them the indictment did not say. India's first reporting clock arrived in 2022, its privacy statute with the DPDP Act in 2023.