In May 2011 five engineers — Steve Crocker, David Dagon, Dan Kaminsky, Danny McPherson and Paul Vixie — took the PROTECT IP Act's requirement that American internet providers filter and redirect lookups for sites a court had found dedicated to infringement, and set out what it would break. Vixie had been principal author of successive versions of BIND, the leading DNS server software; Kaminsky was one of the seven recovery key shareholders able to restore the keys of the DNS root. DNSSEC, which lets a computer check that an answer about a name comes from its owner, would treat a court-ordered redirect as the tampering it was built to catch. A failure from a nameserver obeying a court and one from a hacked nameserver, they wrote, would be indistinguishable.

Their second argument was about people. A filter in the resolver removes nothing; it stops one server answering, and a computer can be pointed at another by changing a single setting, as malware already did routinely. The paper imagined a teenage music sharer redirecting the family computer's DNS settings, and a parent later banking online along the same path. The sponsors gave way in the week before the protest. On 12 January 2012 Senator Patrick Leahy, who had introduced the Senate bill, called the provision a highly technical issue that deserved more study before it was implemented; on 13 January Lamar Smith, sponsor of the House's Stop Online Piracy Act, said DNS blocking would come out of it.

On Saturday 14 January the White House answered petitions on its We the People site. The reply, signed by the intellectual-property enforcement coordinator, the chief technology officer and the President's cybersecurity coordinator, Howard Schmidt, said the administration would not support legislation that "increases cybersecurity risk", and warned against tampering with the domain name system, which it called a foundation of internet security. The protest went ahead. At 05:00 UTC on Wednesday 18 January English Wikipedia went black for twenty-four hours; Reddit went dark for twelve from eight in the morning, Eastern time, and Google blacked out its logo. By the Wikimedia Foundation's count there were more than 162 million visits to the darkened pages, and more than eight million American readers used them to find their representatives in Congress.

Senators began taking their names off the Senate bill that Wednesday, Marco Rubio among them. On Thursday the Justice Department unsealed its case against Megaupload and seized the site's domains under laws already in force. On Friday 20 January the Senate majority leader, Harry Reid, postponed the vote set for the following Tuesday "in light of recent events", and Smith put the House bill aside until there was wider agreement on a solution. Neither bill came back. The provision the engineers had warned about went first, conceded as a technical question that needed study, and a day of darkened websites finished the rest.

Also that month · 19–20 January

A safe room in Coatesville

The indictment unsealed in Virginia on 19 January 2012 charged two companies, Megaupload among them, and seven people with racketeering, copyright and money-laundering conspiracies; prosecutors put the harm to copyright holders at more than half a billion dollars and the proceeds at $175 million, and eighteen domains were seized. Four of the seven were at a mansion at Coatesville, outside Auckland, when police arrived in two helicopters on 20 January, New Zealand time — the eve of Kim Dotcom's thirty-eighth birthday. Police said he retreated into the house and set electronic locks, and that officers had to force their way into a safe room, where they found him near a firearm that looked like a shortened shotgun. In Washington that Thursday the Justice Department's website slowed under what the department called "a significant increase in activity". Anonymous claimed that, and attacks on the FBI, the RIAA, the MPAA and Universal Music, as its largest yet; accounts linked to it put the participants at 5,635, some drafted by links that fired the attack when clicked.

Also that month · 3–16 January

The claim and the count

On 3 January 2012 a self-described Saudi hacker, 0xOmar, claimed on an Israeli sports website to have published the details of 400,000 Israeli credit cards. The chief executive of Israel Credit Cards-Cal said about 14,000 valid cards had been identified; Isracard's said the data came from break-ins at websites, not at the card companies. A second batch on 6 January was claimed at 11,000; the card companies again found far fewer that worked. An Israeli replied with 217 Saudi cards by 11 January, and on 16 January the websites of the Tel Aviv Stock Exchange and El Al failed under a flood 0xOmar claimed; the exchange said its trading systems were untouched. Zappos's number was its own. On 15 January it told the holders of more than 24 million accounts that an attacker, entering through a server in Kentucky, had reached one or more of their names, addresses, phone numbers, last four card digits and scrambled passwords — not the payment database — without saying when. It reset every password and turned off its phones: if one customer in twenty called, its chief executive, Tony Hsieh, reckoned, that would be more than a million calls.

India desk · January 2012

The landlord and the tenants

The case began as a private complaint. On 23 December 2011 a Delhi magistrate, Sudesh Kumar, acting on a journalist's petition about images he said offended several faiths, summoned twenty-one defendants — Facebook, Google, Yahoo, Microsoft, their Indian arms and a few smaller sites — for obscenity and conspiracy; graver charges needed the government's sanction, and a court document showed on 13 January 2012 that it had been granted. The day before, refusing Facebook and Google a stay, Justice Suresh Kait of the Delhi High Court said: "Like China, we can block all such websites," adding that he hoped it would not come to that. On 16 January he likened the companies to landlords profiting from their tenants and let the prosecution go on; Google's counsel answered that the material belonged to the websites' owners and that keyword filters would catch unrelated pages.

Facebook and Google said in February that they had removed the material. In August 2013 a magistrate put the proceedings against the American companies on hold for want of help from the United States, and this archive has found no verdict since; the law moved instead, when the Supreme Court read section 79 down so that a platform need act only on a court order or a government notice (March 2015). The fortnight's other document was a memo posted by a group calling itself the Lords of Dharmaraja, presented as Indian military intelligence and claiming that RIM, Nokia and Apple had traded back doors for market access. A military spokesman called it forged and Apple denied giving any government such access; the same group also claimed Symantec source code.

AI Tech desk · January 2012

From a class of 160,000 to Udacity

On 23 January 2012, at the DLD conference in Munich, Sebastian Thrun announced Udacity, an online school that would teach computer science free. The autumn before, he and Peter Norvig, Google's research director, had opened Stanford's introductory artificial-intelligence course to anyone; Thrun said he had hoped for 500 students and got 160,000, of whom about 23,000 finished. "I can't teach at Stanford again," he told the audience, though he had given up his tenure the previous spring, and the chair of his department later said he would remain a research professor, a post that did not require him to teach. Udacity's first two courses were to begin on 20 February. On the day of Thrun's talk True Knowledge, of Cambridge in England, released Evi, a question-answering app pitched against Apple's Siri; Amazon later bought the company (April 2013). Udacity turned to vocational nanodegrees and was bought by Accenture in 2024.

Digital Guard desk · January 2012

Symantec's own breach, six years on

On 5 January 2012 Symantec said the code the Lords of Dharmaraja had exposed came from two older enterprise products, Symantec Endpoint Protection 11.0 and Symantec AntiVirus 10.2, not the Norton range, and had been taken from a third party's network, not its own. On 17 January its spokesman, Cris Paden, revised that: Symantec now believed the code had been stolen from it in 2006, and named the 2006 versions of Norton AntiVirus Corporate Edition, Norton Internet Security, Norton Utilities, Norton GoBack and pcAnywhere. It was still investigating how. Because of the code's age, the company said, customers, Norton users included, were in no added danger, except those using pcAnywhere, its remote-control software, who might face "a slightly increased security risk". It patched pcAnywhere 12.5 on 23 January and that week, unusually, advised customers to disable the product until a final set of updates was out. The group's attempt to extort $50,000, which Symantec reported to law enforcement, ended in February with the pcAnywhere code online. Symantec discontinued pcAnywhere in 2014.

⏳ Time capsule — January 2012

  • On 13 January India completed a year without a recorded case of wild polio, pending laboratory results; the last had been a two-year-old girl in West Bengal, and the country was declared polio-free on 27 March 2014.
  • On the night of 13 January the cruise ship Costa Concordia struck a rock off the Tuscan island of Giglio and partly sank; thirty-two people died.
  • On 19 January Eastman Kodak filed for Chapter 11 bankruptcy protection in New York, with a $950 million credit facility from Citigroup to keep it operating; it emerged in September 2013 as a company focused on imaging for business.
  • On 29 January, in Melbourne, Novak Djokovic beat Rafael Nadal 5–7, 6–4, 6–2, 6–7, 7–5 after five hours and fifty-three minutes, the longest Grand Slam final of the Open Era; it ended at 1.37 the next morning.
Where it stands today — 2026

The block that kept coming back

SOPA and PIPA lapsed with the Congress that wrote them. Site blocking came back in 2025: in January Zoe Lofgren, who in 2011 and 2012 had been among the loudest House opponents of the two bills, introduced a House bill for court-ordered blocking of foreign piracy sites; a Senate bill followed in July whose definition of a service provider, TorrentFreak reported, would take in DNS resolvers; a third came in September 2026. None has passed either house. The engineers' larger point, that the naming system is security infrastructure, has held regardless: DNSChanger pointed four million computers at criminals' resolvers (July 2012), and a flood against one DNS provider took much of the American web down in October 2016.

Megaupload's case has outlasted the site by fourteen years. Andrus Nõmm, a programmer, pleaded guilty in Virginia in 2015; Finn Batato died of cancer in 2022; Mathias Ortmann and Bram van der Kolk pleaded guilty in New Zealand and were jailed in June 2023 for about two and a half years each. Kim Dotcom's surrender was ordered in August 2024, three months before he had a stroke; the High Court rejected his challenge in September 2025 and the Court of Appeal on 1 July 2026, and his lawyer said he would seek a Supreme Court hearing. He remains in New Zealand. In 2019 Zappos agreed a settlement with its customers, denying wrongdoing: ten per cent off one order. And for now this is where the archive begins; 2011 is still to be restored.