📡Guardians of Hong Kong
9.58K subscribers
21.6K photos
1.88K videos
27 files
9.99K links
We provide translation of news in English from local media and other sources, for academic use.
Facebook: http://bit.ly/BeWaterHongKong
Instagram: @guardiansofhk
Website: https://guardiansofhk.com/
Download Telegram
#Cybersecurity
China proposes Global Data Security Initiative, pledging not to monitor other countries and not to put "back doors" in their products.

According to the Chinese official media, Xinhua News Agency, its government presented the Global Data Security Initiatives (GDSI) at an international conference. Among the eight initiatives, there are calls to oppose the use of cyber technology to damage the infrastructure of other countries or steal important data; endanger the security of other countries; oppose the misuse of cyber technology to monitor other countries; collect personal data of citizens of other countries, and prohibit product and service providers from "installing backdoors in their provisions"; illegally obtaining user data, and controlling or manipulating user systems and equipment.

According to the Xinhua News Agency, China made the eight proposals at the "Seize the Digital Opportunity for Cooperative Development" conference in Beijing. Apart from the aforementioned initiatives, some other proposals include calling on countries to take a comprehensive and objective view on data security issues, opposing large-scale surveillance against other countries and not to request data located outside the country from enterprises or individuals without the permission of other countries' laws.

Source: Stand News #Sep08
#XinhuaNewsAgency #ChineseInternetTech #BackdoorTech
Database of a Chinese Firm Collected Personal Data of 2.4M People, Targeting at Politicians, Military Officials and Celebrities

A Shenzhen-based private company was found to collect personal data globally and sold it to state agencies. Zhenhua Data, a technology company based in Shenzhen, was allegedly to be involved and linked to the People’s Liberation Army (PLA) of China. Its database of 2.4 million people included detailed personal data of tens of thousands of well-known and influential people. The database is thought to be used by Chinese intelligence agencies and described as “Cambridge Analytica on steroids”.

Zhenhua Data was established in 2018. It was believed to be owned by China Zhenhua Electronics Group, a state-owned firm controlled by China Electronics Corporation and the State-owned Assets Supervision and Administration Commission of Guizhou Province.

The main customers of Zhenhua Data include the People's Liberation Army (PLA) and the Communist Party of China (CCP). Zhenhua collected data such as date of birth, address, marital status, photos, political connections, relatives and social media accounts, and even integrated personal account of Twitter, Facebook, LinkedIn, Instagram and TikTok. Information contained news reports, criminal and company records.

Source: Stand News #Sep14

#China #CambridgeAnalytical #Zhenhua #PLA #CCP #Cybersecurity #Shenzhen #DataProtection
#Newspaper

Swedish Technology Company Cuts Business Ties With Hong Kong

//Stockholm-based Micro Systemation AB, a Swedish firm that supplies law enforcement and government agencies with technology to extract data from mobile phones, said it has pulled its business from Hong Kong following the White House’s executive order to strip Hong Kong of its special trading status on 14 July.

//The company’s technology was used by Hong Kong authorities to examine the phone contents of pro-democracy activist Joshua Wong after he was arrested in October last year, according to a police report. The company was originally in line for additional business from the Hong Kong government.

//The company specifically stated in an email that they would no longer “supply solutions” to the Cyber Security and Technology Crime Bureau of the Hong Kong Police Force nor any other government agencies as the White House’s executive order impacts the company’s legal entity and presence in the USA.

//The company has also pulled its business from China which started in 2013 earlier in 2020 due to changes in “regulatory regimes and restrictions” related to export control laws.

//Another firm whose technology was identified in the Joshua Wong case as being used by Hong Kong authorities, Israel-based Cellebite, is facing its own kind of pressure brought by the new national security law which restricts the many types of freedom associated with Western democracies in Hong Kong.

Full Article: Bloomberg
https://bloom.bg/36aO7AY

#nationalsecuritylaw #joshuawong #cybersecurity #MSAB
India Sets up Expert Committee to Investigate Chinese Firms' Involvement in Personal Data Collection, Demands the Participation of Chinese Ambassador to India.

As tensions continue to mount between China and India, the Indian government set up an expert committee on Wednesday, to investigate the alleged collection of personal data by Chinese firm Zhenhua Data and asked the Chinese ambassador to India to participate.

The Indian Express, a local media outlet, revealed that Shenzhen Zhenhua Data Information Technology Co (ZDIT) had collected the personal data of over ten thousand Indian politicians and celebrities to build a database in preparation for a "hybrid warfare" with India. The newspaper also quoted the External Affairs Minister S Jaishankar as saying in a written response that the government has appointed the Chief Commissioner for Cyber Security, retired Army Lieutenant General Rajesh Pant, to head an expert committee. The committee will investigate and assess whether ZDIT was involved in any illegal activities and the implications thereof. The committee will submit its recommendations and report to the government within 30 days.

ZDIT, the company under investigation, was suspected of links with the Chinese government and the Chinese Communist Party. Jaishankar stressed that the Indian government took the protection of Indian citizens’ privacy and personal data very seriously. He also said that the government was deeply concerned with foreign organisations that access or seek access of citizens’ personal data without their consent.

Source: Apple Daily #Sep17

#ZhenhuaData #ChinaIndiaConflict #India #PersonalData #CyberSecurity #CCP #ZDIT #Jaishankar

https://bit.ly/3cCQs8V
Australian cybersecurity firm helped decipher Zhenhua Data leak

Canberra-based company Internet 2.0 recovered a vast trove of information from leaked but corrupted China files, revealing China's profiling of millions of people around the globe.

The company's co-founder Robert Potter said his company was able to recover the records of about 250,000 people from the leaked files, including about 52,000 Americans, 35,500 Australians and nearly 10,000 Britons - among them are politicians such as the prime ministers Scott Morrison and Boris Johnson and their relatives, the royal family, celebrities, and military figures.

Potter conceded that most of the data was based on material openly available on platforms such as Twitter, Facebook, Crunchbase and LinkedIn.

Source: The Guardian #Sep15

#China #Cybersecurity #ZhenhuaDataLeak #Australia
"China and Russia attempted to Undermine Cohesion in the West by sowing disinformation about on COVID-19 Vaccines and Cyber Attack," warns top UK general

The Chief of Defence Staff in the UK, Nick Carter, warned that Russia was attempting to undermine cohesion by sowing disinformation about on coronavirus vaccines on social media.

Carter said in an intelligence event yesterday (Sept 30) that Russia is exploiting strategic benefits by manipulating the information environment in this global pandemic crisis, including penetrating fake description in social media groups. He quote a case from the Australian Strategic Policy Institute (ASPI), which published a report in recent months, that a fake press release was circulating in mid-July about the US conducted vaccine trials on Ukrainian volunteers with death cases. This fake news was published in different countries and languages. The original source was believed having support from Russia authorities in order to stir up anti-American and anti-Ukrainian sentiments.

Carter said disinformation on the vaccine was an example of "digital authoritarianism", cooperating with Putin’s cyber and hacking attack. He also believes that a similar approach was adopted by China, where mass surveillance and "social credit scores" are being forged. Carter said Russia and China "see the strategic context as a continuous struggle in which non-military and military instruments are used unconstrained by any distinction between peace and war". "Their goal is to win without going to war: to achieve their objectives by breaking our willpower, using attacks below the threshold that would prompt a war-fighting response.", he added.

Source: The Stand News #Oct01

#China #Russia #UK #Australia #NickCarter #Putin #ASPI #CyberSecurity #Digitalauthoritarianism #Vaccine #FakeNews

https://bit.ly/3ndBdbq
The repressive ordeal of Australian journalists in China

While China's crackdown on foreign correspondents has been a recent point of contention around the world, the truth is it has been happening for a very long time. Two years after the fact, Matthew Carney - a veteran journalist from Australia - recounts his unnerving experience of how China's bureaucratic machine ventured to suppress his freedom of press and threaten his family.

Source: Standnews #Sep22

https://telegra.ph/Australian-correspondents-forced-to-leave-China-under-threat-from-government-officials-10-12

#MatthewCarney #China #Australia #FreedomOfPress #ABC #Surveillance #NationalSecurity #CyberSecurity #Censorship #InvestigativeJournalism #Journalism
Walmart-exclusive router and others sold on Amazon & eBay contain hidden backdoors to control device

CyberNews researchers have discovered that Chinese-made wifi routers have secret backdoors which allow an attacker to not only remotely control the routers, but also any devices connected to it.

Backdoors are a means for an authorized or unauthorized person to gain access to a closed system – in this case, a router – by bypassing the standard security measures and take control, which is known as root access.

These Chinese-made low-cost routers, named as Jetstream, Wavlink and Ematic, usually are sold at Walmart, Amazon, and eBay.

CyberNews has also found evidence that an attacker has attempted to add the devices to a Mirai botnet, a malware which “infects devices connected to a network, turns them into remotely controlled bots as part of a botnet, and uses them in large-scale attacks.” It’s even possible that the router can steal your passwords on your devices no matter how many times you change them.

Source: CyberNews #Nov23

https://cybernews.com/security/walmart-exclusive-routers-others-made-in-china-contain-backdoors-to-control-devices/?fbclid=IwAR3BeD54mnvJIXnpTVKOq_1WlCYZ6ZiOuxJmjawm0PebrTcf169Z_jW5wLg

#CyberSecurity #MadeInChina #Router #Amazon #eBay #Walmart
#GreatFireWall #106Crackdown
#WashingtonPost: First came political crimes. Now, a digital crackdown descends on Hong Kong

//The digital sweep showed how Hong Kong authorities are wielding their new powers under the national security law — introduced last summer — far more widely than the city’s leader promised.

Since the Jan. 6 raids, authorities have blocked at least one website, according to the site’s owner and local media reports, raising concerns that Hong Kong is headed for broader digital surveillance and censorship akin to that in mainland China.

...Shortly after the arrests and device seizures, colleagues and associates of those detained started noticing strange activity on their social media and email accounts. 

Ray Chan, a former pro-democracy lawmaker arrested at his home, said he kept receiving confirmation codessent by Telegram to a replacement phone after police confiscated his devices. The codes are used to verify the authenticity of a user trying to log into an account.

Separately, Lam Cheuk-ting and Helena Wong, two former Democratic Party lawmakers, said their staffs received notifications from Google that state-sponsored hackers were trying to breach their work accounts, which are hosted on a Gmail server. The Google alerts arrived just after their arrests, once their devices were in the hands of police.

“It is a redo of the Great Firewall,” said Lokman Tsui, an assistant professor at the Chinese University of Hong Kong who specializes in privacy and online communications. “They are testing the waters for now, so the results are uneven — but it is a question of when and how, not if.”

Glacier Kwong, founder of Keyboard Frontline, which tracks digital rights in Hong Kong, said the government clearly intends to crack down on one of the last free spaces for dissent.

“The government has actually set a precedent,” Kwong said. “As long as it is not to the liking of the regime, a website can be blocked without any reason under the national security law, which is a clear blow to the freedom of the Internet, freedom of information and freedom of speech.”//

Read the full article:
https://www.washingtonpost.com/world/asia_pacific/hong-kong-national-security-law-internet/2021/01/12/01738064-53b6-11eb-acc5-92d2819a1ccb_story.html

Source: Washington Post #Jan12

#CyberSecurity #PoliceState #HKChronicles #Internet
#Facebook: #ChineseHackers Attempt to Breach #Uyghurs Communication Devices for #Surveillance

Facebook reported that groups of Chinese hackers tried to set up fake accounts on Facebook in order to get in contact with Uyghurs overseas. After gaining their trust, they send their victims malicious links disguised as Uyghur news sites or online stores, in an attempt to install spyware on their phones for surveillance.

The report on the hacking activities was published on March 24, 2021 in which Facebook did not directly link the incident to the Chinese government, but said that the activity "had the hallmarks of a well-resourced and persistent operation". The hacking groups involved, known in the cybersecurity industry as Earth Empusa and Evil Eye, have also been involved in other surveillance activities in the past.

The hackers mainly target Uyghur human rights activists, journalists, and dissidents from Xinjiang. Most of them currently live in Turkey, Kazakhstan, the United States, Syria, Australia and Canada.

Source: Stand News #Mar25

https://www.thestandnews.com/international/facebook-中國駭客試圖入侵維吾爾族通訊工具進行監視/

#Uyghurs #Cybersecurity #ChineseHackers #MassSurveillance #BigData
#CyberSecurity #CCP
#FBI Raids Chinese Point-of-Sale Giant #PAX Technology

On October 26, 2021, FBI and #MI5 in the US raided the Florida offices of PAX Technology, a Chinese provider of point-of-sale devices used by millions of businesses and retailers globally. There are reports saying that PAX’s systems may have been involved in cyberattacks on U.S. and E.U. organizations.

The sources came from the payment processor, revealing that "the PAX terminals were being used both as a malware “dropper” — a repository for malicious files — and as “command-and-control” locations for staging attacks and collecting information.”

It is pointed out that “two major financial providers — one in the United States and one in the United Kingdom — had already begun pulling PAX terminals from their payment infrastructure.”

Federal investigations are under way.

Read full article:
https://krebsonsecurity.com/2021/10/fbi-raids-chinese-point-of-sale-giant-pax-technology/

Source: Krebs on Security; #Oct26
#Cybersecurity #FakeNews
Facebook takes down China-based network spreading false COVID-19 claims

Image: Stand News
Source: NPR #Dec1

Read more
⬇️⬇️⬇️
#Cybersecurity #FakeNews
Facebook takes down China-based network spreading false COVID-19 claims

//The parent company of #Facebook and #Instagram said on Wednesday, December 1, 2021, it has taken down more than 600 accounts, pages and groups connected to a Chinese influence operation spreading #COVID19 #disinformation, including an account purporting to be a fictitious Swiss biologist.

The China-based network was one of six #Meta, formerly know as Facebook, removed in November for abusing its platforms, a reminder that bad actors around the world are using social media to promote false information and harass opponents.

The China-based operation came to light after the company was alerted to an account purporting to be a Swiss biologist named Wilson Edwards (no such person exists). The account posted claims on Facebook and Twitter in July that the U.S. was pressuring World Health Organization scientists to blame China for the COVID-19 virus. The posts alleging U.S. intimidation soon appeared in Chinese state media stories.//

Image: Stand News
Source: NPR #Dec1
https://www.npr.org/2021/12/01/1060645940/facebook-takes-down-china-based-fake-covid-claims

#FakeIdentity #MadeInChina #CCPControls #CCP #Regime
#MadeinChina #Surveillance
Lithuania says throw away Chinese phones due to #censorship concerns

[Editor's note: The National Communications Commision of #Taiwan has confirmed the same result of Chinese censorship in China-made mobile phones in the findings released on January 6, 2022. Taiwan conducted a similar investigation after Lithuania published their report on September 21, 2021 as below]

#Lithuania's #DefenseMinistry recommended that consumers avoid buying Chinese mobile phones and advised people to throw away the ones they have now after a government report found the devices had built-in censorship capabilities.

Flagship phones sold in Europe by China's smartphone giant Xiaomi Corp (1810.HK)have a built-in ability to detect and censor terms such as "Free Tibet", "Long live Taiwan independence" or "democracy movement", Lithuania's state-run cybersecurity body said on Tuesday.

The capability in Xiaomi's Mi 10T 5G phone software had been turned off for the "European Union region", but can be turned on remotely at any time, the Defence Ministry's National Cyber Security Centre said in the report.

"Our recommendation is to not buy new Chinese phones, and to get rid of those already purchased as fast as reasonably possible," Defence Deputy Minister Margiris Abukevicius told reporters in introducing the report.

Lithuania says throw away Chinese phones due to censorship concerns.

Read the full article:
https://www.reuters.com/business/media-telecom/lithuania-says-throw-away-chinese-phones-due-censorship-concerns-2021-09-21/

#Cybersecurity #Censorship #Xiaomi

Source: Reuters #Sept21;
National Communications Commision of Taiwan #Jan6

The Report of National Communications Commision (#NCC) of Taiwan in Chinese:
https://www.ncc.gov.tw/chinese/news_detail.aspx
#WinterOlympics #MassSurveillance
Official #Beijing 2022 Olympics #MobileApp Is Marred by Security Flaws, Researchers Say

//In a report released Tuesday, Citizen Lab also said the app didn’t properly encrypt sensitive metadata transmitted through the app’s messaging function, which meant any eavesdropper operating a Wi-Fi hot spot could discover who users are communicating with and when.

The Beijing 2022 handbook for athletes and officials says My 2022 is intended to ensure the safety of all Games participants and “is in accordance with international standards and Chinese law.”//

Read the full article:
https://www.wsj.com/articles/official-beijing-2022-olympics-mobile-app-is-marred-by-security-flaws-researchers-say-11642511957

Source: WSJ #Jan19

#BigData #Regime #Cybersecurity #ChineseInternet #PoliceState #ChineseLaw
At least 13 phone firms hit by suspected Chinese hackers since 2019, say experts

At least 13 phone companies around the world have been compromised since 2019 by sophisticated hackers who are believed to come from China, a cybersecurity expert group has said.

The roaming hackers – known as LightBasin – were able to “search and find” individual mobile phones and “target accordingly”, according to CrowdStrike, a group regularly cited by western intelligence.

Hackers were also able to obtain personal subscriber information held by phone companies and metadata showing who made and received calls.

Source: The Guardian #Oct19

https://www.theguardian.com/technology/2021/oct/19/phone-firms-hit-by-suspected-chinese-hackers-lightbasin-china?CMP=Share_iOSApp_Other

#China #Hacker #Cybersecurity
A #US Federal Communications commissioner pushes #Apple and #Google to remove #TikTok from their app stores

In a letter to the companies released on Tuesday, Jine 29, 2022, #BrendanCarr, a Republican commissioner, said he believed that “TikTok’s pattern of conduct and misrepresentations regarding the unfettered access that persons in Beijing have to sensitive U.S. user data” violated Apple’s and Google’s standards and that TikTok should be taken out of the app stores...

The Biden administration has considered other measures to keep American data away from China but has not publicly pushed TikTok to cut ties with its Chinese owner.

TikTok has maintained that it is taking steps to keep employees in China from gaining access to its data. Shortly before a recent news report revealed it was struggling to do so, it said it was routing all data from its U.S. users through servers controlled by Oracle.//

Read more:
https://www.nytimes.com/2022/06/29/technology/apple-google-tiktok.html

Source: New York Times #Jun29

#CyberSecurity #DataSecurity #App #MadeinChina