Vulnerabilities / Threats
1/25/2010
04:30 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

China Denies Attacking Google

Officials in China call claims that the government had a role in the cyber attack on Google and other companies "groundless."

China's government on Monday denied involvement with the cyber attack reported by Google earlier this month and defended its regulation of the Internet.

In an interview with the state-run news organization Xinhua on Sunday, an unidentified spokesperson for the Chinese Ministry of Industry and Information Technology said that "[The] accusation that the Chinese government participated in cyber attack, either in an explicit or inexplicit way, is groundless and aims to denigrate China."

While Google has not accused the Chinese government of direct involvement in the cyber attacks that affected it and some 33 other companies, its decision to stop cooperating with Chinese censorship rules has been widely seen as a stand against the challenging business environment faced by foreign companies in China.

Some security researchers have been less diplomatic, claiming that the attacks show signs of the involvement of Chinese state entities.

China meanwhile insists that it is the biggest victim of hacking attacks.

Last week, U.S. Secretary of State Hillary Clinton spoke at length on the importance of Internet freedom and noted that last year, China, Tunisia, and Uzbekistan "stepped up their censorship of the Internet."

She asked U.S. businesses to support the U.S. government's effort to oppose censorship. "[W]e are urging U.S. media companies to take a proactive role in challenging foreign governments' demands for censorship and surveillance," she said. "The private sector has a shared responsibility to help safeguard free expression. And when their business dealings threaten to undermine this freedom, they need to consider what's right, not simply what's a quick profit."

Getting businesses to put principles above profit may prove difficult. Microsoft CEO Steve Ballmer has criticized Google's threat to leave China as an irrational business decision. He has referred to the situation as the "Google problem" rather than a challenge faced by any foreign business trying to operate in China.

According to Reuters, Microsoft chairman Bill Gates apparently shares that view, stating in an interview on Good Morning America that "The Chinese efforts to censor the Internet have been very limited."

In a statement on an official Chinese government Web site, a government spokesperson said, "China is willing to cooperate and exchange opinions on issues about Internet development and management with other countries, but opposes firmly to any defiance of Chinese laws, or intervening Chinese domestic affairs under the pretense of 'Internet management' regardless of the truth."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3407
Published: 2014-11-27
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.

CVE-2014-4829
Published: 2014-11-27
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests tha...

CVE-2014-4831
Published: 2014-11-27
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.

CVE-2014-4832
Published: 2014-11-27
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.

CVE-2014-4883
Published: 2014-11-27
resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?