At about two in the morning UTC on Thursday 26 March 2015, traffic to github.com began to climb and kept climbing. The next day Jesse Newland, writing on the company's blog, said GitHub was living through the largest denial-of-service attack in its history, made of many methods and one new one: the web browsers of people who had no idea they were involved were being made to flood the site. The company believed the intent was to persuade it to remove a specific class of content. Two pages took the weight. One belonged to GreatFire, which monitors and evades Chinese censorship; the other, cn-nytimes, was GreatFire's mirror of the Chinese-language New York Times. Both existed so that readers inside China could reach what the Great Firewall blocked.
Anyone outside China who opened a page carrying one of Baidu's advertising or analytics scripts received a small file back from Baidu's servers — usually. A fraction of those requests, between one and two per cent by the counts Netresec and Citizen Lab later made, got a script that told the browser to fetch the two GitHub pages again and again. The forged replies carried time-to-live values no Baidu server produced, which placed the injection on the path inside China rather than at Baidu. Baidu denied any involvement, and said it had found no security problem in its own systems.
GreatFire had been under the same flood since 16 March; within days it said the traffic was peaking at some 2.6 billion requests an hour against the mirrors it rented on Amazon's CloudFront, at about $30,000 a day in bandwidth. GitHub's status page tracked the attack shifting shape through the weekend; by the morning of Tuesday 31 March, just under five days in, the site reported normal operation and both pages were reachable. On 10 April Citizen Lab, with Berkeley's ICSI and Princeton, gave the weapon its name (April 2015). The Great Cannon was not the Great Firewall: the firewall watches from beside the path and can only break a connection; this sat in the path and could rewrite unencrypted content at will.
The two systems shared locations on China Telecom and China Unicom and left matching fingerprints, pointing to shared code and a common operator; the same machine, the report noted, could as easily plant an exploit on a single chosen address, much as the NSA's QUANTUM system did. Its authors called this an escalation: censorship enforced by turning users into weapons. Their remedy was ordinary — encrypt everything, since the cannon could only rewrite what travelled in the clear. Quartz reported that the US State Department treated it as an attack on American infrastructure; Beijing rejected the charge, the foreign ministry calling it odd that Chinese hackers were blamed whenever a site abroad went down, and no Chinese authority ever acknowledged the tool. The cannon fired again — at Mingjing News in 2017, at the Hong Kong forum LIHKG in December 2019, at a mining pool in 2021 — each time at a plaintext web that was disappearing under it.
Flaws older than the software
Two of the month's discoveries had no vendor to blame. FREAK, disclosed on 3 March by researchers at INRIA, Microsoft Research and IMDEA, was a relic of 1990s American export policy, which had capped exported encryption at 512-bit RSA keys the state could break. The keys were long dead; the code that still accepted them was not. An attacker sitting between a vulnerable browser and server could push both down to export grade, then factor the key for about $100 of rented cloud time. Safari, Android's browser, OpenSSL and Windows were affected, as were more than a third of tested HTTPS sites, nsa.gov among them; Apple patched on 9 March, Microsoft on 10 March. That same 9 March, Google's Project Zero published Mark Seaborn and Thomas Dullien's Rowhammer work: hammer one row of DRAM often enough and bits flip in its neighbours, a physical fact Yoongu Kim's group had measured in 2014 across 110 of the 129 modules it tested. The pair turned it into a sandbox escape and a Linux kernel privilege escalation by flipping bits in page tables; about half of the twenty-nine laptops they tried obliged.
Nine months inside an insurer
On 17 March Premera Blue Cross said an intruder had been in its systems since 5 May 2014 and was found only on 29 January 2015, with potential access to about eleven million people's names, dates of birth, Social Security numbers, bank details, claims records and clinical information. Premera said its investigation had not determined that any data was removed or misused; it called in outside investigators and the FBI, and named no attacker. Researchers were less reticent: ThreatConnect had noted that the look-alike domain prennera.com used the doubled-letter trick of we11point.com from the Anthem breach, and a shared Chinese espionage group was widely inferred; it was never confirmed. The smaller disclosures were about passwords. Twitch said on 23 March there may have been unauthorised access to account information, and expired every password and stream key. Slack said on 27 March that an intruder had spent about four days in February inside a database of usernames, email addresses and hashed passwords, and switched on two-factor authentication. That week Motherboard found Uber logins on the AlphaBay market at a dollar each; Uber said it had found no evidence of a breach.
The section that jailed a Facebook post
Section 66A of the Information Technology Act was added by an amendment passed without debate in December 2008. It made sending grossly offensive or menacing information, or false information meant to cause annoyance, punishable by up to three years in prison, and defined none of those words. In November 2012, after Bal Thackeray's funeral shut Mumbai down, Shaheen Dhada of Palghar asked on Facebook why; Rinu Srinivasan liked the post. Both were arrested on 19 November; a clinic run by Shaheen's uncle was vandalised; the state police said within days that no charge sheet would follow, and a Palghar court closed the case only in early 2013. Shreya Singhal, a law student, took the section to the Supreme Court that month. Days before judgment a Class XI student in Uttar Pradesh sat in custody under 66A over a post attributed to a state minister; he was bailed within the week, and the bench, which had reserved its verdict in February, asked the state to explain.
On 24 March 2015 Justices J. Chelameswar and Rohinton Nariman struck Section 66A down entirely as vague, over-broad and chilling to the speech Article 19(1)(a) protects. They upheld Section 69A, the blocking power, for its written safeguards, and read down Section 79 so an intermediary lost protection only by ignoring a court order or a government notice, not a complaint. The blocking power has been used freely since: the bans of 59 Chinese apps in June 2020 and 54 more in February 2022 rested on it. The dead section lived on: the Internet Freedom Foundation's Zombie Tracker counted 1,307 fresh cases registered under 66A after the judgment, 745 of them, on a count taken to 10 March 2021, still live in eleven states when PUCL carried the figure back to court that July; on 5 July 2021 the bench called that shocking, on 14 July the Home Ministry told every state to stop, and only on 12 October 2022 did the court order every pending prosecution closed.
Nvidia Puts Deep Learning First
Nvidia's GPU Technology Conference ran in San Jose from 17 to 19 March 2015, and Jen-Hsun Huang used the opening keynote to move deep learning from a research sideline to the company's stated purpose. Three products carried the argument: the GeForce GTX Titan X, twelve gigabytes and, by Nvidia's figures, seven teraflops of single-precision compute for $999; the DIGITS training software, with a $15,000 DevBox holding four of those cards; and Drive PX, a $10,000 board with two Tegra X1 processors and twelve camera inputs for self-driving prototypes. Elon Musk joined Huang on stage, likened autonomous cars to elevators, and repeated that machine learning did not trouble him but "big intelligence" would. On 19 March Tesla said an update due in about ten days would add automatic emergency braking to the Model S over the air, and that a later release would let the car steer itself down a motorway; that one shipped in October. IBM had bought AlchemyAPI for Watson on 4 March. The GPU era every later desk in this archive assumes was being sold that week.
Kaspersky Answers a Businessweek Cover
On 19 March 2015 Bloomberg Businessweek published Carol Matlack's "The Company Securing Your Internet Has Close Ties to Russian Spies". The article claimed that since 2012 senior Kaspersky Lab managers had been replaced by people closer to Russia's military and intelligence services, that a unit under the chief legal officer helped the FSB with criminal investigations, and that Eugene Kaspersky shared a regular banya with intelligence officials. He answered the next day in a post headed "A practical guide to making up a sensation": the piece was speculation and conspiracy theory, and bad journalism, the Russians-only hiring email it described had never existed, and he had been a software engineer at the defence ministry, not a KGB or military intelligence officer. Nothing was settled, and the argument ran to the ban written into American statute in December 2017 and the Commerce Department's sales prohibition of June 2024. Nine days earlier Microsoft had shipped MS15-020, closing the LNK flaw Stuxnet used in 2010: the original patch, a researcher showed, had left working attack paths open for five years.
⏳ Time capsule — March 2015
- On 6 March NASA's Dawn probe entered orbit around Ceres, the first spacecraft to orbit a dwarf planet.
- On 9 March in San Francisco, Apple finally put a date and a price on the Apple Watch: pre-orders from 10 April, on sale 24 April, the gold Edition line listed from $10,000. India waited until November.
- On 24 March Germanwings Flight 9525 came down in the French Alps on its way from Barcelona to Düsseldorf; all 150 people aboard were killed. French investigators concluded in their final report a year later that the co-pilot had brought the aircraft down deliberately.
- On 26 March India's defence of the Cricket World Cup ended in Sydney, where Australia won by 95 runs after India had won all seven of its earlier matches; on 29 March Australia beat New Zealand by seven wickets at the Melbourne Cricket Ground before 93,013 people, a record one-day crowd for the country.
The cannon, the chips and the section
Eleven years on, March 2015 reads as the month the browser was conscripted — and the answer held: encryption. The plaintext web the cannon fed on has largely gone behind HTTPS, and its later shots — a Hong Kong forum in 2019, a mining pool in 2021 — found less and less to rewrite. Volume moved elsewhere. Mirai's cameras and recorders pushed floods towards a terabit in September 2016 and broke Dyn that October; a memcached reflection knocked GitHub offline for nine minutes at 1.35 Tbps in February 2018; Cloudflare blocked 7.3 Tbps in May 2025; and by the close of that year the largest it had disclosed ran at 29.7 Tbps, out of a botnet researchers put at up to four million devices (December 2025). The machines changed; the conscription of other people's devices did not.
The foundations kept cracking. FREAK's export-grade relic was joined on 20 May by Logjam (May 2015): a deliberate weakness outlives the policy that made it. Rowhammer became a field of its own — Drammer rooted Android phones in 2016, TRRespass got past DDR4's defences in 2020, ZenHammer reached AMD and the first DDR5 parts in 2024, Phoenix broke DDR5's refresh mitigations in September 2025. Premera settled with a coalition of thirty state attorneys general for $10 million in July 2019 and paid again the following year. And Section 66A, struck down in March 2015, needed a second order in October 2022 before police stopped using it — while Section 79, as that same judgment read it down, became the hinge of every platform-liability argument India has had since.