Beijing fingers foreign spies for data mischief, with help from consulting firm
- Reference: 1636091111
- News link: https://www.theregister.co.uk/2021/11/05/china_claims_foreign_spies_stole_data/
- Source link:
State-sponsored [1]Xinhua News Agency described the breaches as "endangering the security of important data" and said by disclosing them, the Ministry sought to build awareness of non-traditional security and, by doing so, better maintain national security.
The announcement, which deliberately coincides with the seventh anniversary of the country's [2]anti-espionage law , described airline data stolen by an overseas intelligence agency, shipping data collected by a consulting firm that provided it to a foreign spy agency, and the construction of weather devices to transfer sensitive meteorological data abroad. It is unclear whether one or more foreign intelligence agencies conducted the alleged attacks, or if the actions were linked.
[3]
"Data security is related to national security and public interest, and is an important aspect of non-traditional security," reads a machine translation of the Xinhua piece, which goes on to encourage the public to report suspicious events to authorities.
[4]
[5]
The Middle Kingdom's anti-espionage law came into effect in 2014 and has been amended since. An April 2021 change imposed [6]new responsibilities on groups and organizations, making it clear the onus is on the public to watch out for, prevent, and report foreign espionage activity.
"The regulations … clarify that agencies, groups, enterprises and institutions and other social organizations have the main responsibility for the unit's anti-espionage security prevention work," [7]stated the official newspaper of the Central Committee of the Chinese Communist Party (CCP), People’s Daily Online .
[8]
Chinese journalists Zhixin Wan and Zichen Wang have pointed out that foreign media have all but ignored the attacks.
"Whereas the US and other Western security sources are not infrequent contributors to Western media reports on China, usually detailing what's described as Chinese influence, threats, espionage, or hacking, the same simply can't be said of this side. Also, press content with those intelligence sources is almost always quite prominent in the news," [9]wrote the duo.
[10]140 million Chinese punters adopt Digital Yuan and spend up big
[11]Beijing lashes USA's China Telecom ban – but quite gently
[12]Latest Loongson chip is another step in China's long road to semiconductor freedom
Beijing has lately rewritten its rules to prevent data making its way outside of China, with [13]new regulations and a [14]proposal that businesses proposing to transfer data overseas must first undergo national security screening.
Paradoxically, the Middle Kingdom [15]applied this week for entry into the three-country Digital Economy Partnership Agreement (DEPA), a digitally focused trade agreement that would require China to allow free flow of information across its borders.
China's swift march to digitising its economy and government services has created a boom market for security services: analyst firm IDC recently [16]reported revenue won by China's IT security service providers increased by 110 per cent year-on-year in the first half of 2021.
[17]
Xinhua did not name the nation(s) alleged to have attacked Chinese organisations. Other nations have no trouble naming China as a source of attacks, as demonstrated when it and Russia were not invited to last month's [18]National Security Council Counter-Ransomware Initiative , a two-day meeting consisting of over 30 countries and the EU. Both countries were name-checked in a pre-event press call as sources of recent cybermalice. ®
Get our [19]Tech Resources
[1] http://www.news.cn/2021-10/31/c_1128014674.htm
[2] http://www.gov.cn/zhengce/2014-11/01/content_2775484.htm
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YYlXy010dQ87xLoCixnR9gAAAIM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YYlXy010dQ87xLoCixnR9gAAAIM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YYlXy010dQ87xLoCixnR9gAAAIM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] http://legal.people.com.cn/n1/2021/0426/c205462-32088423.html
[7] http://legal.people.com.cn/n1/2021/0426/c205462-32088423.html
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YYlXy010dQ87xLoCixnR9gAAAIM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pekingnology.substack.com/p/ministry-of-state-security-revealed
[10] https://www.theregister.com/2021/11/05/digital_yuan_140m_wallets/
[11] https://www.theregister.com/2021/11/04/beijing_lashes_usas_china_telecom/
[12] https://www.theregister.com/2021/11/02/china_loongson_mips/
[13] https://www.theregister.com/2021/10/01/china_data_protection_law_taxonomies/
[14] http://www.cac.gov.cn/2021-10/29/c_1637102874600858.htm
[15] https://www.theregister.com/2021/11/02/china_free_trade/
[16] https://www.theregister.com/2021/10/12/idc_china_storage_security_server_market_data/
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YYlXy010dQ87xLoCixnR9gAAAIM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[18] https://www.theregister.com/2021/10/14/virtual_counter_ransomware_initiative_meeting/
[19] https://whitepapers.theregister.com/
Re: It doesn't surprise me...
But some of them are still hypocritically giving lessons to others.
Re: It doesn't surprise me...
Your "lessons" are what some call "freedom of speech." One can't exist without the other...
Metrological data
I cannot understand why metrological data would be an issue. Surely this can be picked up from all those satellites circling above.
Re: Metrological data
but perhaps it's Chinese weather detailing the words "smog" and "pollution"? Perhaps cargo manifests listed "cheap tat for the UK Christmas buying muppets" or "iPhone clones", or airline manifests detailing "holiday jaunts for the autocracy"?
None of them are "security issues" in Western eyes but all would be 'sensitive information' for the Chinese authorities.
Re: Metrological data
Fortunately we thwarted the cunning plan to use 5G to compromise England's meteorological security, and report back to Beijing that it is presently raining.
Re: Metrological data
If a cyclist pedals in Beijing does that mean it will rain in Manchester? That would explain a lot :-)
Re: Metrological data
Nope, maybe not a cyclist, but one of the hundreds of new cement manufacturing plants might. In 3 years, China used 6+ billion tonnes of concrete, 40% more than USA did in the whole 20th century.
Re: Metrological data
If satellites could do the job as well as ground stations nobody with a satellite would be paying all that money to maintain all those ground stations.
I imagine there are lots of things which are probably difficult to measure accurately remotely, such as air pressure, humidity, wind speed, amount of precipitation, etc. You might get estimates, but getting good, consistent readings under all weather conditions can probably only be done from instruments on the spot. If it could be done remotely to the degree of accuracy required, then like I said they wouldn't spend so much money on local weather stations.
Also, a lot of satellite data can't be interpreted properly without on the spot references. I have read about satellite temperature readings having to be calibrated by comparing the satellite readings to on the spot temperatures. This then lets them interpolate the satellite readings for use in areas which don't have weather stations.
Good weather data has important military uses, as it is used to plan when operations are feasible. Also, knowing the weather in one location can help you predict the weather somewhere else days later. In WWII the Germans went so far as to establish secret remote unmanned automated weather stations in uninhabited parts of Greenland and Labrador which would make radio reports which were used to plan U boat operations. The weather stations were found after the war by following up on German records.
"a digitally focused trade agreement that would require China to allow free flow of information across its borders."
I've not read it, but I bet that like is commonly done in agreements, there are possible exemptions available, typically in the name of national security or some such. It's likely not that paradoxical when all the fine print.
You Keep Using That Word, I Do Not Think It Means What You Think It Means
In China where even the wonton production numbers are considered a National Security Secret, "free flow of information" doesn't mean what the West thinks it means.
The point of these trade agreements is to agree on what things are permissible to transfer abroad and which are not.
Well, there is the minor fact that China has a habit of classifying commonly shared information between Universities as "classified" and requiring approvals. So when they call something a "security" breach, it has me wondering if it wasn't just someone helping themselves through a pre-configured access to the data they are SUPPOSEDLY authorized to have.
It would certainly not be the first time I've heard there was a disconnect between the politboro and the people doing the work.
It doesn't surprise me...
We do hear about this that and other hacked in the west, but it no doubt happens everywhere.
Take Wannacry, Russia was far worse hit than any other country and their banks are constantly hit.
Pretty sure NK with its tiny Internet presence is hit all the time as well.
In short, everyone is hacking everyone else