ONI Country Profi le
285
Jianzhou, announced that the company had access to the personal data of its users —
including the user ’ s exact whereabouts — which were given to the authorities on
demand.
127 China ’ s most popular instant messenger, QQ (owned by Tencent), was
found to have installed a keyword-blocking program in their client software that
monitored and recorded users ’ online communication. This information was given to
authorities if required.
128
In 2008, researcher Nart Villeneuve discovered that TOM-Skype, the Chinese-marketed version of Skype, had stored more than a million user records in seven types of
log fi les stored on publicly accessible servers, including IP addresses, user names, and
time-and-date stamps.
129 For call information logs dating from August 2007, the user
name and phone number of the recipient were also logged, while content fi lter logs
dating from August 2008 also contained full texts of chat messages (which themselves
contained sensitive information such as e-mail addresses, passwords, and bank card
numbers). With the information contained in the log fi les, it would be possible to
conduct politically motivated surveillance by using simple social-networking tools to
identify the relationships between users.
130
Cyber Attacks
A growing number of countries, organizations, and companies have reported cyber
attacks appearing to originate in China. These reports have ranged from instances of
targeted malware attacks against human rights groups, distributed denial of service
(DDoS) attacks against government Web sites, and high-profi le attempts to compromise Google ’ s e-mail system. While assessing attribution and motivation behind such
attacks is perennially diffi cult, there is growing concern about the security risk posed
by cyber attacks originating in China.
In January 2010, Google announced it would no longer censor search results on
Google China ( http://google.cn ) following cyber attacks on its infrastructure.
131 Google
claimed that the e-mail accounts of a number of human rights activists connected
with China were compromised by the attack, which had also targeted dozens of other
Silicon Valley fi rms.
132 Later reports suggested that the attackers had gained access to
the password system controlling the access of millions of users of Google ’ s services.
133
U.S. State Department cables leaked through Wikileaks implicated a senior member of
China ’ s government in this attack.
134 An MIIT spokesman denied the Chinese government ’ s involvement, suggesting that in fact China was the world ’ s primary victim of
cyber attacks.
135 A compromise solution between Google and the government of China
was eventually reached under which users in China were offered a link to Google ’ s
unfi ltered Chinese-language search services based in Hong Kong.
136
Google was not the only source to report attacks on human rights and civil society
organizations working on issues related to China. Malicious e-mails purporting to
Précédent

- 302/431

Suivant