Did they want to protect themselves before alerting anyone?
Did they want to use this to infiltrate others?
Did they want to protect themselves before alerting anyone?
Did they want to use this to infiltrate others?
Note that the article is misleading as the rule doesn't require the disclosure must be made to the government first.
http://www.gov.cn/gongbao/content/2021/content_5641351.htm
Here is a machine translation of the relevant section that seems to agree with the GP:
>Article 7 Network product providers shall perform the following network product security vulnerabilities management obligations, ensure that their product security vulnerabilities are repaired in a timely manner and reasonably released, and guide and support product users to take preventive measures:
>(1) After discovering or learning about the security vulnerabilities in the provided network products, they should immediately take measures and organize verification of the security vulnerabilities to assess the degree of harm and the scope of the security vulnerabilities; for the security vulnerabilities in their upstream products or components, they should Notify the relevant product provider immediately.
>(2) The relevant vulnerability information should be reported to the Ministry of Industry and Information Technology's cyber security threat and vulnerability information sharing platform within 2 days. The content of the submission shall include the product name, model, version, and the technical characteristics, harm, and scope of the vulnerability that have security loopholes in network products.
>(3) Remediation of network product security vulnerabilities should be organized in a timely manner. For product users (including downstream manufacturers) that need to take measures such as software and firmware upgrades, network product security vulnerabilities and repair methods should be promptly informed of the product users who may be affected , And provide the necessary technical support.
Probably yes.
> Did they want to use this to infiltrate others?
Also probably yes.
The NSA does the same thing. They stockpile security vulnerabilities and selectively tell the software vendors about some of them. They like to keep the "high value" vulnerabilities to themselves for use in exploits.
The WannaCry ransomware (see https://en.wikipedia.org/wiki/WannaCry_ransomware_attack and https://en.wikipedia.org/wiki/EternalBlue) did worldwide economic damage and was built on an NSA developed exploit. The NSA knew about this vulnerability in Windows for years and never told Microsoft.
Unfortunately all intelligence agencies everywhere will continue to take this cowboy approach. Until we can get these bad actors under control, their constant undermining of internet infrastructure will continue to hinder efforts to improve internet security.
And even if the end result has some overlap, there's a bit of an ethical difference between:
* developing an exploit that you keep quiet
* preventing others from talking about exploits they discover
I don't care which bunch of spies does it more. I don't want spies doing it at all.
Yah, I guess by not searching for new exploits tonight for public disclosure, I'm putting the entire software world marginally more at risk by "grubby inaction."
> I don't care which bunch of spies does it more. I don't want spies doing it at all.
I care: some bad actors in my government vs. forcing an entire massive economy to participate in bad actions will have massively different magnitudes of effect.
There's always going to be bad actors, but preventing 15% of the world's population from being good actors surely is a pretty significant thing.
It's not ethical. It's not professional. It's school boy stuff.
* Google Project Zero researcher: "we found a bug!"
* NSA (internally): "Damnit, scratch that one off the list boys.."
I guess everyone has forgotten wikileaks and Snowden already.