China proposes ‘Global Initiative on Data Security’ forbidding stuff it and Huawei are accused of doing already
- Reference: 1599546548
- News link: https://www.theregister.co.uk/2020/09/08/china_global_initiative_on_data_security/
- Source link:
The code was revealed today in a speech by state councilor and foreign minister Wang Yi at an event called the International Seminar on Global Digital Governance. China has only ten state councilors and the body is analogous to the Cabinet in a democracy, which we mention to indicate that Yi has gravitas and authority – China did not assign the enunciation of this idea to a lowly functionary.
Yi outlined an eight-point code that China hopes the world will adopt. The elements of the plan are:
Approach data security with an objective and rational attitude, and maintain an open, secure and stable global supply chain.
Oppose using ICT activities to impair other States' critical infrastructure or steal important data.
Take actions to prevent and put an end to activities that infringe upon personal information, oppose abusing ICT to conduct mass surveillance against other States or engage in unauthorized collection of personal information of other States.
Ask companies to respect the laws of host countries, desist from coercing domestic companies into storing data generated and obtained overseas in one's own territory.
Respect the sovereignty, jurisdiction and governance of data of other States, avoid asking companies or individuals to provide data located in other States without the latter's permission.
Meet law enforcement needs for overseas data through judicial assistance or other appropriate channels.
ICT products and services providers should not install backdoors in their products and services to illegally obtain user data.
ICT companies should not seek illegitimate interests by taking advantage of users' dependence on their products.
Yi said the plan is needed because the world economy’s move to online activity has increased data security challenges that “ … have put national security, public interests and personal rights at stake, and posed new challenges to global digital governance.”
The resulting inconsistent national laws “pushed up the compliance costs for global businesses,” he complained, before suggesting “To reduce the deficit in global digital governance, countries face a pressing need to step up communication and coordination, build up mutual trust and deepen cooperation with one another.”
We have not and will not ask Chinese companies to transfer data overseas to the government in breach of other countries' laws,
Some sections of Yi’s speech seem designed to address the allegation that Chinese firms are beholden to the nation’s government. “We have not and will not ask Chinese companies to transfer data overseas to the government in breach of other countries' laws,” Yi said.
“I hope the Chinese initiative will serve as a basis for international rules-making on data security and mark the start of a global process in this area,” Yi said. “We look forward to the participation of national governments, international organizations and all other stakeholders, and call on States to support the commitments laid out in the Initiative through bilateral or regional agreements. We are also open-minded to good ideas and suggestions from all sides.
Comment
Some of Yi’s remarks will be well-received: his second point is close to the goals of the [1]Global Commission on the Stability of Cyberspace (GCSC) . But his sixth point, the call to “Meet law enforcement needs for overseas data through judicial assistance or other appropriate channels” is tricky given it could impinge on sovereignty.
The call for an end to corporate espionage may also ring a little hollow, at least if western intelligence agencies are to be believed.
At the time of writing The Register has not encountered any responses to China’s proposal. And of course anything said in the next 24 hours is irrelevant, as Yi’s call for regional or bilateral agreements to adopt China’s plan will require extensive negotiations.
US, China manage to keep a straight face while promising to not hack each other's corps [2]READ MORE
As did the China-USA no-hack-pact of 2015, which was quickly seen as not much more than tawdry security theatre as both nations continued to probe each other whenever deemed necessary and failed to prevent the Trump administration later creating its [3]“Clean Network” plan on grounds that all of China’s technology companies represent a national security risk. ®
Get our [4]Tech Resources
[1] https://www.theregister.com/2018/03/22/global_commission_on_the_stability_of_cyberspace/
[2] https://www.theregister.com/2015/09/25/us_china_promise_to_stop_hacking/
[3] https://www.theregister.com/2020/08/17/trump_alibaba_ban_thought_bubble/
[4] https://whitepapers.theregister.com/
Re: Judical assistance
The OECD has been promulgating as from several decades ago what has already acquired its own acronym : "AEOI" viz. Automatic Exchange Of Information. Almost all countries have signed up. The Tax Office in one territory may send a request to the Tax Office in another territory regarding presumed Miscreant X and the second territory may use all its powers of investigation against X as if he is a local taxpayer (which he may be but not necessarily).
You can challenge the actions locally but this can kick off with a simple letter from Tax Office 1 to Tax Office 2.
And of course not just tax.
There is no privacy any more.
Re: Judical assistance
If both countries have independent judiciaries and strong Rule of Law, no problem. But China has neither, and may never given the party's willingness to ruthlessly do anything to maintain power.
" Oppose using ICT activities to impair other States' critical infrastructure or steal important data "
HAHAHAHAHAHAHA, *choke!*, HAHAHAHAHA ... oh, wait. You're serious???
It's a shame we can't post pictures, there's a great one from Futurama that would've fit perfectly here.
It's the one where Bender laughs in Leela's face, stops and ask "Wait, you're serious?" "let me laugh even harder!"
https://media1.tenor.com/images/05ce0a63eb335d9d333f65a2ddfa26c4/tenor.gif?itemid=12163274
Ingenuous stance
This is the same ingenuous stance Russia takes: they propose to keep certain treaties in tact whilst they themselves have no intent on keeping by the rules. Their intention is to weaken their adversaries this way.
China is probably hoping to avert the collapse of Huawei with this proposal, which is probably one of the attached strings.
Simply ignore these moves by China and Russia and move on.
".. keep certain treaties in tact .."
That's very diplomatic of them.
So you don't want data security?
The initiative is all about making the Chinese look good and the Americans, when they inevitably refuse to sign up, look bad.
At which point the Chinese say "So what part of data security do you object to?".
Quickly followed by telling the rest of the world that it's obvious that the US can't be trusted, and the NSA abuses US citizens' rights.
Idea!
If you believe that, I have a great pyramid sche.. ehr.... great opportunity for you to make money!
Item 1?
What does the first item on the list actually mean?
"1. Approach data security with an objective and rational attitude, and maintain an open, secure and stable global supply chain"
As for the PRC promoting ICT security, well, everyone is in favour of that, but who believes that any state actually practices what they preach on this subject? Respecting other states' sovereignty is all very well, until you reckon that there is information they have which would protect your sovereignty. The USA is quite adamant in declining to join the ICC, because it would mean USA soldiers could be prosecuted for 'war crimes' in a court outside the control of the USA Supreme Court.
I can only assume it is some sort of PR event by the Chinese until they prosecute a Chinese company for helping the Chinese Communist Party obtain data from a foreign entity without the foreign state's approval.
Sorry, errors occurred while scanning a photocopy of the official statement though the translator
For DO read DO NOT and vice versa
Easy mistake to make and we hope this hasn't caused any confusion
I think we all got the message wrong: The Chinese government is saying the most secure network are the ones by Huawei .
Just sayin'.
Spying on me would be of no interest to the Chinese.
I don't trust our government, with it being run by unelected power hungry bureaucrats, or the USA run by Trump.
Sorry, Cisco, and other Western companies, but "Huawei" you go. I'd rather use my Huawei devices than your NSA hacked kit.
"Spying on me would be of no interest to the Chinese."
"Spying on me would be of no interest to the Chinese."
"Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say." - Edward Snowden
Judical assistance
But his sixth point, the call to “Meet law enforcement needs for overseas data through judicial assistance or other appropriate channels” is tricky given it could impinge on sovereignty.
Among many countries this is already a possibility. When you need access to data there is a process to go through, involving judical oversight (probably and hopefully) in both countries. So I do not see these issues as impingeing in souvereignity, at least not more than what is currently done among several countries already. There is even a process between the EU and the US, which the US now unilaterally replaced by the CLOUD act. Data could be requested already before, but these requests had to pass through the other country's judical system, which the US of course does not like - they make the rules, and everybody is subject to them (and woe betide those that investigate war crimes allegedly[*] commited by US soldiers).
[*] innocent until proven guilty etc., but we all know the reports, ffs, people even openly admitted these!