On 2 January 2015 President Barack Obama signed Executive Order 13687. Its finding named the provocative, destabilizing, and repressive actions and policies of the Government of North Korea, including its destructive, coercive cyber-related actions during November and December 2014 — about as close as an American legal instrument had come to putting a computer intrusion in a preamble. The White House was blunter than the order. The statement issued by the press secretary that day said the order answered the destructive and coercive cyber attack on Sony Pictures Entertainment, an attack whose purpose had been to threaten artists and other individuals with the goal of restricting their right to free expression. Then came the sentence the next decade would test: today's actions are the first aspect of our response.

What the Treasury did was block property. Its Office of Foreign Assets Control designated three entities — the Reconnaissance General Bureau, the country's intelligence service; the Korea Mining Development Trading Corporation, North Korea's primary arms dealer; and the Korea Tangun Trading Corporation, a defence procurement arm — and ten individuals. Kil Jong Hun represented KOMID in Namibia, Jang Song Chol in Russia, Kim Yong Chol and Jang Yong Son in Iran, Ryu Jin and Kang Ryong in Syria; Kim Kwang Chun represented the Korea Ryungseng Trading Corporation in Shenyang, across the Chinese border. None of the ten was accused of any part in the Sony intrusion. They dealt in missiles and the parts of missiles, and their assets in American jurisdiction were frozen because their government was said to have wiped a studio's hard drives.

The attribution the order rested on was two weeks old and openly disputed. On 19 December 2014 the FBI had said it held enough information to conclude that the North Korean government was responsible, citing malware, techniques and infrastructure that resembled tools used before against South Korean targets. Parts of the security industry did not accept it. Marc Rogers, Kurt Stammberger, Hector Monsegur and the reporter Kim Zetter all questioned the evidence in public; the most repeated alternative held that insiders had done it, people who already knew where Sony kept things, and others doubted that a country with so little internet could mount an operation of that size. The Bureau published little more. Pyongyang denied doing it at all — the intrusion, KCNA had suggested, might be a righteous deed of the country's supporters and sympathisers — offered a joint investigation, and called the designations a groundless stirring-up of bad blood. The sanctions arrived on 2 January without waiting for the argument to end.

In hindsight the doubters lost the fact and kept the point. On 6 September 2018 the Justice Department charged Park Jin Hyok, a programmer for a North Korean front company called Chosun Expo, linked to a military intelligence unit, with conspiracy over both the Sony attack and the WannaCry ransomware of May 2017 (September 2018); the same cluster, by then called Lazarus, had already been tied to the theft from Bangladesh Bank in February 2016. Park has never appeared in a courtroom, and neither has anyone named on 2 January 2015. What the first aspect bought was a habit. Three months later a second order, signed on 1 April, gave Washington a standing power to sanction people for malicious cyber activity, and it has been used ever since.

Also that month · 7–20 January

No means of communication

On 7 January gunmen attacked the Paris offices of the satirical magazine Charlie Hebdo and killed twelve people. On Monday 12 January David Cameron asked whether Britain should permit a means of communication between two people which, even in extremis with a signed warrant from the home secretary personally, the state cannot read, and answered himself: no, we must not. He never said which law would achieve it, which was the whole of the objection. The same day President Obama went to the Federal Trade Commission to propose a national thirty-day breach-notification standard, and on 13 January to the National Cybersecurity and Communications Integration Center in Arlington to propose liability protection for firms sharing threat data with the government; both went into the State of the Union on 20 January. Also on 12 January, US Central Command's Twitter and YouTube accounts were taken over by an account calling itself CyberCaliphate, which posted a threat to American soldiers before the accounts were suspended within the hour; nothing operational was touched. The information-sharing half became law in December 2015; the notification bill did not, and Cameron's question moved to a California courthouse (February and March 2016).

Also that month · 4–27 January

The exchange, the lizards and the ghost

On 4 January the exchange Bitstamp found an operational wallet emptied and suspended trading the next day; its co-founder, Nejc Kodrič, said fewer than 19,000 bitcoin, about $5 million, had gone, that most of its holdings sat in cold storage, and that balances held before the suspension would be honoured in full. They were. On 16 January Brian Krebs reported an arrest in Southport and the breaking-open of LizardStresser, the attack-for-hire service advertised by its Christmas assault on Xbox Live and the PlayStation Network: 14,241 registered usernames and passwords, all stored in plain text. Ten days later the same name sat on Malaysia Airlines' home page above a taunt at a still-missing aircraft; the airline said its DNS records had been interfered with, its servers intact, and the threatened dump never came. Then on 27 January Qualys disclosed GHOST, a buffer overflow in glibc reachable through the old gethostbyname calls. It had been there since November 2000 and had been fixed upstream on 21 May 2013 — but not labelled a security fix, so Debian, Red Hat, CentOS and Ubuntu shipped it for another twenty months. Adobe had shipped two emergency Flash patches in the days before, on 22 and 24 January.

India desk · January 2015

Thirty-two addresses, then twenty-eight

On 17 December 2014 the Department of Telecommunications ordered every licensed internet provider in India to block thirty-two web addresses under section 69A of the Information Technology Act, 2000, acting on an advisory from the Anti-Terrorism Squad about anti-India material posted by supporters of Islamic State. The list took in Pastebin, GitHub, Vimeo, Dailymotion, Weebly and the Internet Archive. Subscribers noticed around the turn of the year, when the sites simply stopped answering; the order itself first circulated as a photographed screenshot on Twitter, and providers were told to file compliance reports. The ministry announced on 31 December 2014 that four of them had undertaken to keep such material off their services, and over 1 and 2 January 2015 the block lifted on GitHub, Vimeo, Dailymotion and Weebly — sites that had removed the objectionable content or cooperated with the investigation were being unblocked, officials said — leaving twenty-eight in place.

The month's argument looked different from Delhi. While a prime minister in London asked whether any message should be unreadable, Indian internet providers already worked under licence conditions allowing encryption keys of up to forty bits, anything stronger requiring written permission and the deposit of decryption keys with the department. The blocking power then survived its first constitutional test almost at once: on 24 March 2015 the Supreme Court struck down section 66A of the same Act as vague and overbroad, but upheld section 69A as narrowly drawn and adequately safeguarded (March 2015). The machinery of January stood, and the pattern it set — an order to intermediaries, effective at once, explained afterwards, never published in full — is the one India has legislated in ever since, through to the six-hour reporting rule CERT-In imposed on the whole economy in 2022.

AI Tech desk · January 2015

The letter from Puerto Rico

The first weekend of 2015 put about seventy researchers in a hotel in San Juan, Puerto Rico, at a conference convened by the Future of Life Institute, and what came out of it was a document. On 12 January the institute published Research Priorities for Robust and Beneficial Artificial Intelligence: An Open Letter, a short text over a twelve-page annexe sorting the field's problems into verification, validity, security and control. More than 150 people signed, among them Stephen Hawking, Elon Musk, Google's research director Peter Norvig and Berkeley's Stuart Russell — some who took superintelligence for an existential risk, some who signed to correct a press interested in nothing else. On 15 January Musk gave the institute $10 million to award as grants; Facebook's research laboratory open-sourced its Torch deep-learning modules on 16 January; and on 28 January Bill Gates told a Reddit audience he was in the camp concerned about super intelligence. The mainstream argument about AI safety dates from that fortnight, and the institute has reached for the same instrument in every wave since.

Digital Guard desk · January 2015

Two days before the patch

Google's Project Zero ran a ninety-day clock on every bug it reported, and in January it ran out twice on Microsoft: a Windows 8.1 elevation-of-privilege flaw went public on 29 December 2014, and a second two days before Microsoft's scheduled fix of 13 January. On 11 January Chris Betz of the Microsoft Security Response Center answered with a post arguing for coordinated disclosure: Microsoft had asked Google to wait for the patch, and the refusal, he wrote, felt less like principles than like a gotcha, with customers the ones who might suffer; what was right for Google was not always right for customers. Google did not move, and published a third Windows flaw days later. Three days before the post Microsoft had itself stopped publishing advance notice of Patch Tuesday's contents outside its premier support and security programmes, which Rapid7's Ross Barrett called an assault on IT and IT security teams everywhere. Project Zero added a fourteen-day grace period on 13 February 2015; the ninety-day deadline itself survived, and became the industry's default.

⏳ Time capsule — January 2015

  • On 15 January the Swiss National Bank abandoned the cap of 1.20 francs to the euro it had defended since September 2011; the franc rose about 30 per cent within minutes, and brokers from Alpari to Global Brokers NZ collapsed or had to be rescued.
  • King Abdullah of Saudi Arabia, admitted to hospital in Riyadh on 31 December 2014 and announced on 2 January to be suffering from pneumonia, died there on 23 January at the age of 90; his half-brother Salman succeeded him.
  • Greece voted on 25 January and gave Syriza 36.34 per cent and 149 of the 300 seats; a coalition with the Independent Greeks followed the next day, and Alexis Tsipras became prime minister.
  • On 26 January Barack Obama was chief guest at India's Republic Day parade in New Delhi — the first American president invited to that place.
Where it stands today — 2026

The first aspect, and the rest

Eleven years on, the order of 2 January 2015 reads less as a punishment than as a template. Sanctioning named foreigners for what a state's computers did became ordinary: the standing authority arrived on 1 April 2015, and indictments and designations have followed against operators tied to North Korea, Russia, China and Iran in most years since. The attribution held. The cluster the FBI pointed at in December 2014 took Bangladesh Bank's money in February 2016 and released WannaCry in May 2017, and a named programmer was charged in September 2018. What has never arrived is anyone in a dock, or a public account of the second aspect of the response.

The other argument of that month is still open. Cameron's question has been asked again in every jurisdiction that matters and answered in none of the ways he suggested; encryption is still legal, still default, still contested, and the fight the Charlie Hebdo murders reopened ran through a California courthouse in 2016 and has not stopped. India's blocking power, upheld two months after it was exercised, is now the instrument of first resort. One housekeeping note: The Vault's restoration currently begins here. The batches run forward from January 2015 through to the relaunch issue of August 2026, and the archive will continue backwards into 2014 and earlier as those months are restored.