cross-posted from: https://scribe.disroot.org/post/2653687

Archived version

Hackathons are common, but Chinese hacking competitions are different.

In 2017, Zhou Hongyi, the founder of Chinese cybersecurity giant Qihoo 360, publicly criticised the practice of sharing vulnerability discoveries internationally, arguing that such strategic assets should stay within China. His sentiments, supported by the Chinese government, gave birth to the national hacking competition called the Tianfu Cup. The contest is focused on discovering vulnerabilities in global tech products like Apple iOS, Google’s Android, and Microsoft systems.

How is Tianfu Cup different?

A 2018 rule mandates participants of the Tianfu Cup to hand over their findings to the government, instead of the tech companies.

Dakota Cary, a China-focused consultant at the US cybersecurity company SentinelOne, said, “In practice, this meant vulnerabilities were passed to the state for use in operations.”

This approach effectively turned hacking competitions into a government pipeline for acquiring zero-day vulnerabilities — software flaws unknown to vendors and extremely valuable for cyber-espionage.

In recent years, China’s hacking competitions have increasingly shifted focus toward breaching domestic products, including Chinese-made electric vehicles, phones, and security software.

    • randomnameOP
      link
      fedilink
      English
      arrow-up
      9
      ·
      21 hours ago

      … criticised the practice of sharing vulnerability discoveries internationally, arguing that such strategic assets should stay within China.

      A 2018 rule mandates participants of the Tianfu Cup to hand over their findings to the government, instead of the tech companies.

      Which countries do have something similar to a ‘Tianfu Cup?’

        • randomnameOP
          link
          fedilink
          English
          arrow-up
          12
          arrow-down
          1
          ·
          21 hours ago

          As I asked already in this thread: Why is it that whenever one posts something critical of China here on Lemmy, there is some commentary arguing that the US is doing the same? I don’t understand that.

          That’s whataboutery back and forth.

          • Maeve@kbin.earth
            link
            fedilink
            arrow-up
            5
            arrow-down
            9
            ·
            20 hours ago

            Because if we’re focused on other governments’ misdeeds, we ignore our own, and our own is the more immediate treat, afaict

            Eta unless that’s the point

            • randomnameOP
              link
              fedilink
              English
              arrow-up
              7
              ·
              20 hours ago

              That’s an absurdly bad take to justify whataboutism.

              • Maeve@kbin.earth
                link
                fedilink
                arrow-up
                3
                arrow-down
                3
                ·
                20 hours ago

                You can and will obviously do what you like. My take is, neglecting our own business to focus too much on others’ is precisely what got us here. The Red Scare is old tricks and we still refuse to learn from our own mistakes.

    • Samskara@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      19 hours ago

      For some it’s an ambition, but not a priority. Germany simply doesn’t pay skilled people enough to serve as cyber soldier.

        • Samskara@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          19 hours ago

          It could help. Mandatory service typically gets you young people straight from school. That means you need to train them. To be good at cybersecurity and cyber warfare takes years though. Not something you can teach over the course of a year of service.

          • Maeve@kbin.earth
            link
            fedilink
            arrow-up
            1
            ·
            19 hours ago

            If they get them straight from Gymnasium, there’s still time to pound the whole "love of country/fellow countrymen,” too. I don’t know because current generations are leaning alarmingly right.

    • Samskara@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      19 hours ago

      For some it’s an ambition, but not a priority. Germany simply doesn’t pay skilled people enough to serve as cyber soldier.