cross-posted from: https://scribe.disroot.org/post/2653687

Archived version

Hackathons are common, but Chinese hacking competitions are different.

In 2017, Zhou Hongyi, the founder of Chinese cybersecurity giant Qihoo 360, publicly criticised the practice of sharing vulnerability discoveries internationally, arguing that such strategic assets should stay within China. His sentiments, supported by the Chinese government, gave birth to the national hacking competition called the Tianfu Cup. The contest is focused on discovering vulnerabilities in global tech products like Apple iOS, Google’s Android, and Microsoft systems.

How is Tianfu Cup different?

A 2018 rule mandates participants of the Tianfu Cup to hand over their findings to the government, instead of the tech companies.

Dakota Cary, a China-focused consultant at the US cybersecurity company SentinelOne, said, “In practice, this meant vulnerabilities were passed to the state for use in operations.”

This approach effectively turned hacking competitions into a government pipeline for acquiring zero-day vulnerabilities — software flaws unknown to vendors and extremely valuable for cyber-espionage.

In recent years, China’s hacking competitions have increasingly shifted focus toward breaching domestic products, including Chinese-made electric vehicles, phones, and security software.

  • Sylvartas@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    3
    ·
    17 hours ago

    It doesn’t. But it irks me that when the USA does the same shit, if not worse, and just as blatantly, no one cares. But when it’s China it’s instantly nefarious and dangerous, when in reality it’s a world superpower doing exactly what the “good ones” are also doing in this case.

    And I’m not pretending that China is less autocratic than our western democracies. But our state surveillance has nothing to envy to theirs.

    • randomname@scribe.disroot.orgOP
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      16 hours ago

      when the USA does the same shit, if not worse, and just as blatantly, no one cares.

      This is outright false. Just the most recent post in this community is about the NSA spying on air-gapped networks. And there is an awful lot more news on Lemmy criticizing the US, EU, or other Western democracies. (However, there’s no whataboutism in these cases. Why?)

      • Sylvartas@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        edit-2
        16 hours ago

        Because criticizing china on that stuff is like beating a dead horse. Of course the autocratic country is gonna spy on their citizens and other countries, and engage in state sponsored hacking (and, mind you, I think it’s ok for a State to use hacking defensively). But our leaders are criticizing them for that and foaming at the mouth to do the same shit domestically, which makes us look hypocritical as fuck and opens us up to stupid headlines like “Putin blasts France for police violence during recent protests” (which is very tangentially related but a very common one over here)

        I guess I got jumpy because I recently watched a video about this that ended with the usual “the state pulled out an obscure old law and shut down the lawsuit and possibly proceeded to secretly fuck with the whistleblower for a while”.

      • Maeve@kbin.earth
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        16 hours ago

        Don’t let the right hand know what the left hand is doing is great for tricks.