On 20 March 2014 reporters working through a federal criminal complaint unsealed in the Western District of Washington found a passage that had little to do with the defendant. The defendant was Alex Kibkalo, a Russian national who had worked for Microsoft in Lebanon; he had been arrested in Washington state the previous day. The complaint said that in July and August 2012, after a poor performance review, he had passed pre-release updates to Windows 8 RT and code from the Microsoft Activation Server Software Development Kit to a blogger in France, moving the files through his own SkyDrive account. Microsoft confronted him that September and took what it had to the FBI in July 2013. The passage that mattered described how the company had found him.

The blogger's mailbox was a Hotmail account — Microsoft's service, on Microsoft's servers. Acting on a tip, the company's Trustworthy Computing Investigations team read the inbox and the associated instant-messenger logs, and an internal body called the Office of Legal Compliance had approved that review on 7 September 2012. No court had been asked, because the company's position was that no court could be asked. Hotmail's terms of service reserved a right to disclose the content of a user's communications in order to protect the property of Microsoft or its customers. On 20 March the deputy general counsel, John Frank, set out the reasoning plainly: courts, he wrote, do not issue orders authorising someone to search themselves. Probable cause or not, there was no warrant to apply for.

The defence lasted eight days. Microsoft first tightened the process rather than abandoning it: an outside lawyer, a former federal judge, would decide whether a court would have granted an order, and searches of this kind would be counted in the company's twice-yearly transparency report. That answered the paperwork and not the objection, which was that a provider had appointed itself the judge of its own suspicion. It landed badly for a company that had spent much of 2013 buying advertisements — the Scroogled campaign, launched in November 2012 — attacking Google for scanning the contents of Gmail. On 28 March 2014 the general counsel, Brad Smith, dropped the claim altogether. Microsoft would not inspect customer content in such cases at all; it would refer them to law enforcement.

The criminal case ended quietly. Kibkalo pleaded guilty to theft of trade secrets on 31 March 2014, agreeing to pay Microsoft $22,500; he was sentenced on 10 June to three months and deported to Russia. The blogger was never named in the filings and was not charged in the United States; he survives in the record as an enthusiast for unreleased Windows screenshots who kept his mail with the company he embarrassed. What lasted was the shorter document. The commitment of 28 March, drawn up in consultation with the Center for Democracy and Technology and the Electronic Frontier Foundation, held that a company holding a customer's mail would not read it on its own authority. Every large provider now says as much. It took a leak of screenshots to get it written down.

Also that month · 19–25 March

The list that would not stay shut

On 19 March 2014 John Cartwright posted a short note to Full Disclosure and closed it. The mailing list had run since Len Rose founded it on 9 July 2002 as an alternative to Bugtraq, and Cartwright had administered it for most of that time. He had always assumed, he wrote, that the end would arrive as a sweeping demand from some vendor for the deletion of an archive; instead the demand — for large-scale deletion of historical posts, with the threat of legal action behind it — had come from a researcher inside the security community, whom he declined to name. He would not take a virtual hatchet to the archives on the whim of an individual, and he would not fight. "I'm suspending service indefinitely. Thanks for playing." Six days later, on 25 March, Gordon Lyon — Fyodor, the author of Nmap — restarted the list on his own infrastructure at seclists.org, stating that legal intimidation would not be tolerated there and that researchers decide how to disclose their own findings. It is still running in 2026.

Also that month · 8–14 March

The plane and the attachments

Malaysia Airlines Flight 370 left Kuala Lumpur for Beijing at 00:42 on 8 March 2014 with 239 people aboard and lost contact thirty-eight minutes later. Within a day the disappearance was being used as bait. CyberSecurity Malaysia said afterwards that on 9 March a PDF attachment dressed as a news report claiming the aircraft had been found reached officials at Malaysia Airlines, the Department of Civil Aviation and the National Security Council; about thirty machines were affected, and the agency said minutes of meetings and documents relating to the investigation were sent out to an internet address in China. Its chief executive, Amirudin Abdul Wahab, described the case publicly only in August 2014. FireEye reported separately that a group it tracked as admin@338 had sent MH370-themed lures to a government in the Asia-Pacific and to an American think tank, and that on 14 March a file named "Malaysian Airlines MH370 5m Video.exe" wearing a Flash icon was mailed out in the same wave; the payloads were Poison Ivy and a downloader the firm called WinHTTPHelper. India formally joined the search on 13 March. The aircraft has never been found.

India desk · March 2014

The order with no judge in it

The argument in Redmond was whether a company may open a mailbox it hosts. In Delhi the statute had already answered that. Interception in India is authorised not by a judge but by an official — the Union Home Secretary, or a state's Home Secretary — acting under Section 5(2) of the Indian Telegraph Act of 1885 and, for computer data, Section 69 of the Information Technology Act. Standard operating procedures for lawful interception, issued by the Department of Telecommunications and in force through 2014, set out the clerical detail: sealed envelopes, a chief nodal officer at each operator, emergency orders by e-mail followed by signed hard copies, covering voice, SMS, data and voice over IP alike. Figures later obtained under the Right to Information Act put central-government interception orders at between 7,500 and 9,000 a month in 2013.

Behind the paperwork sat the Central Monitoring System, approved by the Cabinet Committee on Security on 16 June 2011, accelerated after the Mumbai attacks and funded to at least Rs 400 crore by mid-2013, built so that agencies could reach what operators intercepted without asking them each time. It was due to be working through 2014, in an election year: on 5 March the Election Commission announced the schedule for the sixteenth Lok Sabha, nine phases from 7 April to 12 May with counting on 16 May, the model code of conduct taking effect that morning. The limits came later, and from the courts rather than the ministry: Section 66A struck down on 24 March 2015, privacy made a fundamental right in August 2017, and the DPDP Act of 2023, which binds companies closely and the State only lightly.

AI Tech desk · March 2014

Four million faces, nine layers

Facebook's research group put out its face-verification work in mid-March 2014, and by 17 March it was being written up as software that matched two photographs of a stranger about as reliably as a person could. DeepFace — Yaniv Taigman, Ming Yang and Marc'Aurelio Ranzato, with Lior Wolf of Tel Aviv University — fitted each face to an explicit three-dimensional model before passing it to a nine-layer network trained on four million images of more than four thousand identities; Facebook put the accuracy on the Labeled Faces in the Wild benchmark at 97.35 per cent, and presented the paper at CVPR in June. The money arrived days later, when Vicarious closed $40 million on 21 March from Formation 8, Mark Zuckerberg, Elon Musk and Peter Thiel among the backers. On 25 March Nvidia announced NVLink and the Pascal architecture meant to carry it in 2016 — the plumbing, as it turned out, that the decade would run on.

Digital Guard desk · March 2014

The chair Symantec could not fill

Symantec dismissed its chief executive, Steve Bennett, on 20 March 2014, less than two years after installing him in place of Enrique Salem, who had gone the same way; the board made the director Michael Brown interim president and chief executive, and the shares fell sharply the following day. Symantec's chairman, Daniel Schulman, said the move was "not precipitated by any event or impropriety". Brown was confirmed in September and was gone himself by 2016. What the incumbent could not settle, others were buying. On 24 March Palo Alto Networks agreed to pay about $200 million for Cyvera, a fifty-five-person firm in Tel Aviv whose software blocked exploit techniques on the endpoint rather than recognising files, and closed the deal on 10 April; it became Traps, and later the endpoint half of Cortex XDR. The same day Microsoft published an advisory on a Word RTF flaw, CVE-2014-1761, credited to Google's security team and already in targeted use; the patch followed on 8 April.

⏳ Time capsule — March 2014

  • On 2 March the 86th Academy Awards were held at the Dolby Theatre in Los Angeles; 12 Years a Slave took Best Picture and Gravity won seven awards, and the host's group photograph, taken by Bradley Cooper, passed a million retweets within the day and briefly overwhelmed Twitter.
  • On 16 March a referendum in Crimea, rejected as illegitimate by Ukraine and Western governments, was followed on 18 March by the signing in Moscow of a treaty of accession.
  • On 25 March Facebook announced it would buy Oculus VR for about $2 billion — $400 million in cash and 23.1 million shares — pending regulatory approval.
  • On 27 March the World Health Organization certified the South-East Asia Region, India included, free of polio; the region's last case of wild poliovirus had been recorded in India on 13 January 2011.
Where it stands today — 2026

Who may open it

The promise of 28 March held in form. No large provider now claims a contractual right to read a customer's mail on its own authority, and much of the transparency reporting that followed exists because Microsoft agreed that spring to count itself. Its next fight ran the other way, over a warrant issued in December 2013 for mail held on a server in Dublin: Microsoft lost before a magistrate in April 2014, won at the Second Circuit on 14 July 2016, argued at the Supreme Court on 27 February 2018, and was made moot on 17 April 2018 by the CLOUD Act, signed on 23 March that year — four years and three days after the Hotmail disclosure. The question got a treaty, not a principle.

The other threads aged differently. Fyodor's list still carries advisories, and the argument Cartwright's note opened — whether a published archive belongs to the record or to those named in it — returns whenever a disclosure is asked to be withdrawn. MH370's search was suspended on 17 January 2017; the aircraft has not been found, and the trick that followed within a day, a catastrophe repackaged as an attachment, is now routine. The card wave ran on beneath it: Sally Beauty confirmed on 17 March that fewer than 25,000 records of card-present data were accessed, while reporting that month put the figure far higher; a breach at the California DMV surfaced on 22 March. The American answer, moving fraud liability to merchants without chip terminals, arrived on 1 October 2015.