Skip to content
The Point of Failure

Episode 12 · Telecom and Emergency Lines · 1:40

The Expired Certificate That Silenced 11 Countries

01:10 · Point of failure

On 6 December 2018, an expired certificate in Ericsson core-network software disrupted operators across 11 countries. O2 and SoftBank were among the networks affected by the same dated dependency.

Incident

Topics
certificate expiry · telecom · shared dependencies · reliability
Point of failure
The certificate's expiry date was written down years in advance, and no system or person was watching the calendar for it.

Transcript

234 words · 1 min read

The outage

Tens of millions of phones in two countries lost data on the same morning. The cause had been scheduled for years. This is The Point of Failure, episode twelve.

December 6th, 2018. In the UK, O2's network wakes up broken. No mobile data for tens of millions. Buses can't show arrival times. Card machines fail. And weirdly at the same time, Japan. SoftBank. Same morning, same failure.

The shared dependency

Two countries, one cause. Both networks ran core software from Ericsson. And inside the software sat a digital certificate. A certificate is like an ID card that machines show each other to prove they can be trusted. And every ID card has an expiry date printed on it the day it is issued.

The expiry date

The date arrived and the certificate expired. And the machines did exactly what they were designed to do with an expired ID. They stopped trusting each other. The network did not break. It refused.

Watching the calendar

Point of failure

A full day to restore. Compensation reportedly in the tens of millions. And the maddening part, an expiry date is the single most predictable event in computing. It is literally written down years in advance. It just needed one system or one person watching the calendar.

Every failure has a story. Every story was preventable. I'm Kevin. See you at the next one.

Sources

3 sources

  1. O2 poised to receive millions from Ericsson over software failure

    The Guardian · 2018

    Compensation was reported as prospective, not a confirmed settlement.

  1. 10

    The Disaster That Never Happened

    Two-digit years made the millennium rollover a real software risk. Years of remediation and testing helped keep the disruption limited, leaving successful prevention looking like an unnecessary warning.

  2. 19

    The Morning the Internet's Address Book Failed

    On 19 and 20 October 2025 a latent race condition between two components of AWS's DNS automation left the DynamoDB endpoint in us-east-1 with an empty DNS record. Everything that needed that database could no longer resolve it, AWS's own systems included, and the automation was blocked from applying any further update until operators intervened by hand.

  3. 20

    Entirely Preventable

    On 7 March 2017 a critical Apache Struts vulnerability was disclosed with a patch the same day. Equifax circulated the alert but never patched the one internet facing system that needed it, neither scan run to find that system detected it, and the appliance that should have inspected the traffic had been blind for nineteen months behind an expired certificate. Attackers were inside for 76 days.