The venue was a warship. On 11 October 2012 Leon Panetta, the United States secretary of defence, spoke to Business Executives for National Security on the hangar deck of the Intrepid, the aircraft carrier tied up as a museum on Manhattan's west side. He set out what he said adversaries were working towards: passenger trains derailed, the water supply of a major city contaminated, the power grid switched off across large parts of the country, and all of it timed to arrive beside a physical attack. The collective result, he said, could be a cyber "Pearl Harbor" — an attack, in his description, that would cause physical destruction and loss of life, and paralyse and shock the nation.
He had used the image before. At his confirmation hearing on 9 June 2011 he had told the Senate Armed Services Committee that the next Pearl Harbor the country faced could well be a cyberattack crippling its grid and its financial systems. What was new in October was the evidence. On 15 August a wiper called Shamoon had gone through Saudi Aramco and left some thirty thousand workstations useless — the company's own figure — overwriting files and, on some machines, putting up an image of a burning American flag; August's edition carries the account. A comparable attack reached the Qatari gas producer RasGas days later. Shamoon, Panetta said, was probably the most destructive attack the private sector had seen to date.
He did not name the author of the Aramco attack, saying instead that Iran had undertaken a concerted effort to use cyberspace to its advantage, and pointing to the denial-of-service floods arriving at American bank websites since 18 September, which would pause on 23 October for Eid al-Adha. The rest was about what his department meant to do. The United States had made advances in identifying attackers and could hold them to account; the department was finishing the most comprehensive revision of its rules of engagement in cyberspace, making plain that its duty ran past its own networks to the nation's defence; and if an imminent threat were detected that would cause significant physical destruction or kill American citizens, it needed the option to act at the President's direction.
Some of that had already been settled in private. That same month the President signed Presidential Policy Directive 20, a classified framework for defensive and offensive cyber effects operations, describing offensive work as offering unique capabilities with little or no warning to a target. Ellen Nakashima reported its existence in the Washington Post on 14 November; the text appeared in the Guardian on 7 June 2013 among the Snowden documents (June 2013). The public argument began at once. Jason Healey of the Atlantic Council allowed that Panetta was probably right to raise the spectre, but argued that such warnings had never been matched with specifics; others called it recycled fear, a third outing for the same image. Panetta later called it shock therapy.
The committee and the two companies
Three days earlier the House Permanent Select Committee on Intelligence published an investigation begun in November 2011. The report, from its chairman Mike Rogers and ranking member Dutch Ruppersberger, found that Huawei and ZTE could not be trusted to be free of foreign state influence, and urged that government systems exclude their equipment, that acquisitions by either be blocked, and that private firms look elsewhere. The unclassified version offered no hard proof; a classified annex, it said, held more that could not be published. Huawei said the report used rumour and speculation to prove non-existent accusations; its spokesman, William Plummer, called the suggestions baseless. ZTE said it profoundly disagreed that the Chinese government directed it, and asked why it, not much larger Western vendors, was the focus. On 17 October Reuters reported that a White House-ordered review had found no evidence of spying, though someone familiar with it called the equipment riddled with holes; a White House spokeswoman, Caitlin Hayden, said no classified inquiry had cleared any supplier. Both sat on the Federal Communications Commission's list of national-security threats a year before a Russian firm joined them in March 2022.
Ten years, and sixty-three pin pads
On 16 October the home secretary, Theresa May, told the Commons she had blocked Gary McKinnon's extradition. American prosecutors accused him of entering ninety-seven military and NASA computers between February 2001 and March 2002 and put the damage above $700,000; he said he had been looking for evidence of unidentified flying objects. May said he was accused of serious crimes but was seriously ill, with Asperger's syndrome and a depressive illness, and that extradition would carry so high a risk of him taking his life as to breach his rights. On 14 December the Director of Public Prosecutions, Keir Starmer, said he would not be tried in Britain either, citing the likelihood of acquittal: ten years of proceedings, and no verdict on the facts. Eight days later Barnes & Noble said maintenance had turned up tampered card readers in sixty-three of its shops across nine states — one device in each, fewer than one pad in a hundred — bugged to capture card numbers and PINs. Every pad in its nearly seven hundred shops had been disconnected by close of business on 14 September, six weeks before customers were told.
The tweet and the principles
Police came early in the morning on 30 October 2012 to the house of a Puducherry man who ran a small plastic packaging business, and arrested him under Section 66A of the Information Technology Act. The complaint, by e-mail, came from Karti Chidambaram, son of the finance minister, over three tweets from 2011 and 2012, one saying he had amassed more wealth than Robert Vadra. Karti said the tweet plainly implied he was corrupt, and defended having gone to the police. A magistrate remanded him; he was bailed that evening, and said afterwards he had repeated a statement already on the internet. Three weeks later two arrests in Palghar (November) took the section to the Supreme Court; his own case was still pending in March 2015, listed for the 27th — three days after the Court struck the section down (March 2015), leaving him, as he said, a free man.
A fortnight earlier, the argument's other half was written down. On 16 October a group of experts chaired by Justice A.P. Shah, a former Chief Justice of the Delhi High Court, gave the Planning Commission a report proposing a privacy statute: nine national privacy principles — notice, choice and consent, collection limitation, purpose limitation, access and correction, disclosure of information, security, openness and accountability — binding on government and private sector alike, enforced by privacy commissioners. It was written against the programmes then being built: the identity number, NATGRID. No bill followed. Privacy became a fundamental right in August 2017; the duty to report a breach arrived by direction in 2022 and the statute in 2023, eleven years on.
Nearly eleven points in Florence
On 12 October 2012 in Florence, at the ImageNet challenge's workshop during the European Conference on Computer Vision, the winner was presented: a deep convolutional network from the University of Toronto's Alex Krizhevsky, Ilya Sutskever and Geoffrey Hinton, trained for five to six days on two Nvidia gaming graphics cards. Its five best guesses missed the right label on 15.3 per cent of test images, against 26.2 for the runner-up, a University of Tokyo entry built on hand-engineered features. On 25 October in Tianjin, Microsoft's chief research officer, Rick Rashid, spoke English and had a machine transcribe it, translate it into Mandarin and say it in a synthetic voice modelled on about an hour of his recorded speech. The recogniser rested on deep neural networks worked out with Hinton's Toronto students, and by Rashid's account still misheard one word in seven or eight. Most histories date deep learning's takeover, and the graphics chip's central place in AI, from that network, later called AlexNet; the demonstration became Skype Translator, previewed in December 2014.
Windows 8 puts anti-virus in the box
Windows 8, released to manufacturing on 1 August 2012, went on general sale on 26 October: the first Windows with an anti-virus product built in and switched on. Windows Defender, an anti-spyware tool in earlier versions, now used the same engine and signatures as Microsoft Security Essentials, a free download since 2009, and scanned in real time. Microsoft cited its own telemetry: a year after launch, at least 24 per cent of Windows 7 PCs lacked current protection, which it thought reflected lapsed trials. The trials survived. Defender stayed off wherever PC makers preloaded another vendor's trial, for a fee, and Microsoft had said every interface Defender used, boot-time protection included, was open to rivals. On 16 October Eugene Kaspersky confirmed his company was writing an operating system from scratch for industrial control systems; MIT Technology Review doubted its security could be proved as promised. The argument over a scanner in the box ran on to Kaspersky's own antitrust complaint of November 2016; the operating system was offered commercially in February 2017.
⏳ Time capsule — October 2012
- On 12 October the chairman of the Norwegian Nobel Committee, Thorbjørn Jagland, announced in Oslo that the Nobel Peace Prize would go to the European Union, for six decades of contribution to peace and reconciliation, democracy and human rights in Europe.
- On 14 October, the sixty-fifth anniversary of Chuck Yeager's Bell X-1 flight, Felix Baumgartner rose by balloon from Roswell, New Mexico to 38,969 metres and stepped off, reaching 1,357.64 kilometres an hour — Mach 1.25 — and falling for four minutes and nineteen seconds before his parachute opened.
- On 28 October Sebastian Vettel won the Indian Grand Prix from pole position at the Buddh International Circuit in Greater Noida, before a crowd of about 65,000.
- Early on 29 October Hurricane Sandy came ashore near Brigantine, New Jersey as a post-tropical cyclone carrying hurricane-force winds; by 31 October more than six million customers across fifteen states were without electricity. The storm killed 254 people in the Caribbean, the United States and Canada.
The name that stuck
Fourteen years on, nothing has arrived in the shape Panetta drew: no single stroke that paralysed a country. The pieces came separately. The lights went out in western Ukraine in December 2015; a wiper dressed as ransomware stopped ports, factories and a national administration in June 2017; a pipeline company shut its own line and the American south-east queued for petrol in May 2021. Those who called the speech threat inflation can point to the absence of the catastrophe; those who defended it can point to the list. The legislation he asked for failed a second attempt at cloture on 14 November 2012, and the President signed an executive order on critical infrastructure instead, on 12 February 2013, a fortnight before Panetta left office.
The attribution he claimed took longer to appear. In March 2016 the Justice Department charged seven Iranians, working for two companies it said were sponsored by the Revolutionary Guard Corps, with the bank attacks Panetta had cited: forty-six institutions, floods on 176 separate days, hundreds of thousands of customers locked out of their accounts, tens of millions of dollars in remediation. One was also charged with reaching the control system of a small flood-control dam at Rye Brook, New York, whose sluice gate happened to be disconnected for maintenance. None was in American custody, and none has been. Naming the accused became the available punishment, and has stayed so. The phrase outlived the argument: in 2026 it is still the first thing reached for when a network fails in public.