Risk
7/29/2008
06:56 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Chinese Authorities Order Olympic Hotels To Install Spy Gear

Kansas Sen. Sam Brownback claims foreign-owned hotels have been asked to install Internet monitoring equipment to spy on hotel guests during the Beijing Games.

In an apparent mistranslation of the concept of hospitality, Chinese authorities have ordered foreign-owned hotels to install Internet monitoring equipment to spy on hotel guests during the Olympic Games, U.S. Sen. Sam Brownback, R-Kansas, charged on Tuesday.

"I am very disappointed that the Chinese government will not follow through on its promise to the International Olympic Committee to maintain an environment free of government censorship during the Games," Brownback said in a statement. "The Chinese government has put in place a system to spy on and gather information about every guest at hotels where Olympic visitors are staying. This means journalists, athletes' families and other visitors will be subjected to invasive intelligence gathering by the Chinese Public Security Bureau."

According to a news release issued by the senator's office, Chinese authorities have ordered foreign-owned hotels to install a software program and a hardware device to help the Public Security Bureau spy on hotel guests. Several hotel chains have reportedly confirmed the existence of this order and provided documentation to Brownback.

A spokesperson for Brownback was not immediately available.

News service Reuters quoted one of the documents thus: "In order to ensure the smooth opening of Olympic in Beijing and the Expo in Shanghai in 2010, safeguard the security of Internet network and the information thereon in the hotels ... it is required that your company install and run the Security Management System."

Brownback said that the hotels have asked not to be named for fear of reprisals.

Chinese authorities have been accused of similar behavior before. In May, The Associated Press reported that Chinese officials may have covertly copied the contents of a U.S. government laptop computer that was left unattended during a visit by Commerce Secretary Carlos M. Gutierrez.

Given that the U.S. National Security Agency has been monitoring Internet and telephone communications since warrantless wiretapping was authorized in 2001, there seems to be more resignation than outrage among potential visitors to China.

As one person commenting on Reuters' coverage remarked, "Bad enough I have the U.S. government snooping on my Internet and telephone activity. To heck with going to China to have them do it to me too. Think I'll save my money and blood pressure and just stay home and watch them on the TV."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Cybersecurity's 'Broken' Hiring Process
Kelly Jackson Higgins, Executive Editor at Dark Reading,  10/11/2017
How Systematic Lying Can Improve Your Security
Lance Cottrell, Chief Scientist, Ntrepid,  10/11/2017
Ransomware Grabs Headlines but BEC May Be a Bigger Threat
Marc Wilczek, Digital Strategist & CIO Advisor,  10/12/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.