TikTok tells European users its staff in China get access to their data - The Guardian

https://www.theguardian.com/technology/2022/nov/02/tiktok-tells-european-users-its-staff-in-china-get-access-to-their-data

TikTok is spelling out to its European users that their data can be accessed by employees outside the continent, including in China, amid political and regulatory concerns about Chinese access to user information on the platform.

TikTok Parent ByteDance Planned To Use TikTok To Monitor The Physical Location Of Specific American Citizens

https://www.forbes.com/sites/emilybaker-white/2022/10/20/tiktok-bytedance-surveillance-american-user-data/

Chinese Government Asked TikTok for Stealth Propaganda Account - Bloomberg

https://www.bloomberg.com/news/articles/2022-07-29/chinese-government-asked-tiktok-for-stealth-propaganda-account

A Chinese government entity responsible for public relations attempted to open a stealth account on TikTok targeting Western audiences with propaganda, according to internal messages seen by Bloomberg.

FBI investigation determined Chinese-made Huawei equipment could disrupt US nuclear arsenal communications - CNN

https://edition.cnn.com/2022/07/23/politics/fbi-investigation-huawei-china-defense-department-communications-nuclear/index.html

Ny EU-lov mot overgrepsmateriale kan føre til omfattende overvåkning – NRKBeta

https://nrkbeta.no/2022/05/11/ny-eu-lov-mot-overgrepsmateriale-kan-fore-til-omfattende-overvakning/

Onsdag la EU-kommisjonen frem et forslag til en ny lov som kan få store konsekvenser for nordmenns digitale liv. Lovforslaget er ment å bedre beskytte barn mot overgrep, men rettighetsgrupper har lenge vært bekymret for at det kan undergrave retten til privatliv og sikker kommunikasjon.

[…]

– Dette forslaget legger opp til en overvåkningsmaskin som vi aldri har sett maken til i demokratiske land, og er det nærmeste vi kommer autoritær kontroll over digitalt innhold på samme måte som de gjør i Kina, sier stipendiat Tjerand Silde ved NTNU.

Den profilerte teknologen Alec Muffett lekket tirsdag et utkast til lovforslaget. Han er svært kritisk:
– I dag er dagen EU erklærer krig mot ende-til-ende kryptering, skriver Alec Muffett på Twitter.

[…]

En rekke høyt respekterte akademikere og teknologer advarte i fjor høst mot å innføre denne typen teknologi. De mente at skanning av innhold lokalt på en digital enhet, gjerne forkortet til CSS, i ytterste konsekvens kan svekke demokratiet.

– Introduksjonen av skanning på våre personlige enheter – enheter som lagrer informasjon fra våre gjørelister, tekstmeldinger og bilder – går midt imot enkeltborgeres behov for personvern. Denne formen for masseinnsamling kan føre til omfattende nedkjølingseffekter på ytringsfriheten og faktisk på selve demokratiet, skrev ekspertene i en artikkel publisert på forskningsnettstedet arXiv.

– Vi mener at CSS verken garanterer effektiv kriminalitetsbekjempelse eller forhindrer overvåkning. Faktisk er effekten det motsatte. CSS vil skape alvorlige sikkerhets- og personvernsrisikoer for hele samfunnet, men hjelpen det kan gi politimyndigheter i beste fall er problematisk, skrev de.

[…]

Leder for IT-politiskforening i Danmark, Jesper Lund, er svært kritisk til det endelige lovforslaget. Hans organisasjon samarbeider med EDRi.
– Forslaget er et åpenbart angrep på kryptering selv om EU-kommisjonen påstår noe annet, skriver han til NRK.

Journalists’ group ‘dismayed’ by treatment at Beijing Winter Olympics | The Guardian

https://www.theguardian.com/sport/2022/feb/21/journalist-beijing-winter-olympics-foreign-correspondents-club

Foreign Correspondents’ Club of China says reporters tailed and manhandled by security despite assurances from Games officials

Helseopplysninger om norske utøvere på avveie i OL: – Helt Texas – NRK Sport

https://www.nrk.no/sport/helseopplysninger-om-norske-utovere-pa-avveie-i-ol_-_-helt-texas-1.15839426

Olympiatoppens sjef, Tore Øvrebø, er kraftig oppgitt over OL-arrangørens håndtering av norske helseopplysninger. Direktøren på et av hotellene som huser norsk støttepersonell visste om smitte før den norske leiren.

– Han er en grei kar, men han skulle ikke hatt disse opplysningene før oss, sier Tore Øvrebø da han møter pressen i Zhangjikou – et par timer unna Beijing.

– Det er helt Texas, konkluderer Øvrebø.

Hotelldirektøren på Eagle Nest, der flere medlemmer av det norske støtteapparatet bor, er stadig i forkant når det kommer til koronastatus på utøverne.

Google Caught Hackers Using a Mac Zero-Day Against Hong Kong Users

https://www.vice.com/en/article/93bw8y/google-caught-hackers-using-a-mac-zero-day-against-hong-kong-users

The hackers had set up a watering hole attack, meaning they hid malware within the legitimate websites of “a media outlet and a prominent pro-democracy labor and political group” in Hong Kong. Users who visited those websites would get hacked with an unknown vulnerability—in other words, a zero-day—and another exploit that took advantage of a previously patched vulnerability for MacOS that was used to install a backdoor on their computers, according to Hernandez. 

Apple patched the zero-day used in the campaign in an update pushed out on September 23, according to the report.

Fraudsters Cloned Company Director’s Voice In $35 Million Bank Heist, Police Find

https://www.forbes.com/sites/thomasbrewster/2021/10/14/huge-bank-fraud-uses-deep-fake-voice-tech-to-steal-millions/

AI voice cloning is used in a huge heist being investigated by Dubai investigators, amidst warnings about cybercriminal use of the new technology.

In early 2020, a bank manager in the Hong Kong received a call from a man whose voice he recognized—a director at a company with whom he’d spoken before.

Lithuanian government warns about secret censorship features in Xiaomi phones - The Record

https://therecord.media/lithuanian-government-warns-about-secret-censorship-features-in-xiaomi-phones/

U.S. and key allies accuse China of Microsoft Exchange cyberattacks - Axios

https://www.axios.com/china-cyberattacks-nato-181e71d2-7414-45f3-9463-c8b1d46392c1.html

The U.S., NATO, European Union, U.K., Australia, Canada, New Zealand and Japan say they can now, “with high confidence,” attribute the March attack using the Exchange flaw to cyberattackers affiliated with China’s state security ministry. That attack crippled thousands of computers around the world.

TikTok insiders say Chinese parent ByteDance is in control

https://www.cnbc.com/2021/06/25/tiktok-insiders-say-chinese-parent-bytedance-in-control.html

Former TikTok employees say there is cause for concern when it comes to the popular social media app’s Chinese parent company.

They say ByteDance has access to TikTok’s American user data and is closely involved in the Los Angeles company’s decision-making and product development. 

Some cybersecurity experts worry that the Chinese government could use TikTok to spread propaganda or censorship to American audience, or to exercise influence over users who may come to regret what they posted on the service.

Apple’s Compromises in China: 5 Takeaways - The New York Times

https://www.nytimes.com/2021/05/17/technology/apple-china-privacy-censorship.html

To stay on the good side of the Chinese authorities, the company has made decisions that contradict its carefully curated image.

Alibaba’s Huge Browser Business Is Recording Millions Of Android And iPhone Users’ ‘Private’ Web Habits

https://www.forbes.com/sites/thomasbrewster/2021/06/01/exclusive-alibabas-huge-browser-business-is-recording-millions-of-android-and-iphone-users-private-web-habits/

on both Android and iOS versions of UC Browser, every website a user visits, regardless of whether they’re in incognito mode or not, is sent to servers owned by UCWeb.

A Hard Bargain for Apple in China

https://mjtsai.com/blog/2021/05/19/a-hard-bargain-for-apple-in-china/

At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft’s Email Software — Krebs on Security

https://krebsonsecurity.com/2021/03/at-least-30000-u-s-organizations-newly-hacked-via-holes-in-microsofts-email-software/

At least 30,000 organizations across the United States — including a significant number of small businesses, towns, cities and local governments — have over the past few days been hacked by an unusually aggressive Chinese cyber espionage unit that’s focused on stealing email from victim organizations, multiple sources tell KrebsOnSecurity. The espionage group is exploiting four newly-discovered flaws in Microsoft Exchange Server email software, and has seeded hundreds of thousands of victim organizations worldwide with tools that give the attackers total, remote control over affected systems.

By all accounts, rooting out these intruders is going to require an unprecedented and urgent nationwide clean-up effort. Adair and others say they’re worried that the longer it takes for victims to remove the backdoors, the more likely it is that the intruders will follow up by installing additional backdoors, and perhaps broadening the attack to include other portions of the victim’s network infrastructure.

KrebsOnSecurity has seen portions of a victim list compiled by running such a tool, and it is not a pretty picture. The backdoor web shell is verifiably present on the networks of thousands of U.S. organizations, including banks, credit unions, non-profits, telecommunications providers, public utilities and police, fire and rescue units.

“It’s police departments, hospitals, tons of city and state governments and credit unions,” said one source who’s working closely with federal officials on the matter. “Just about everyone who’s running self-hosted Outlook Web Access and wasn’t patched as of a few days ago got hit with a zero-day attack.”

The Global Chip Shortage - Digits to Dollars

https://digitstodollars.com/2021/03/05/youre-on-allocation/

The current shortage is driven by two things: Covid and manufacturing is hard. Last year, factories in China started shutting down early in the year. By the time they started re-opening later in the year, factories everywhere else had shut down, or at least drastically scaled back. So many Chinese factories did not scale production up in a hurry. The result was reduced output everywhere. Then early this year it became clear that pandemic was under control in China and vaccines were coming soon everywhere, and that demand for many electronic devices was stronger than ever. Companies across the supply chain suddenly had to race to catch up, but often found their suppliers were not back to producing at full scale. This caused wrinkles to spread across the industry. Finally, it appears now that shipping has become a bottleneck with air freight prices sky high (pun intended) and US ports still dealing with scaled back working conditions. You could probably also throw in the US-China Trade War, but let’s not go down that particular rabbit hole now, just chalk it up to further complicating the situation.

The best example of this, and one we commonly hear, is the proverbial $2 electric motor which prevents completion of a $50,000 car. Now multiply this by 10,000 companies all hindered in their ability to ship because of some shortage from someone else’s factory.

DOJ charges Zoom employee for helping Chinese government shut down Tiananmen Square commemorations

https://www.washingtonexaminer.com/news/doj-zoom-employee-chinese-government-shut-down-tiananmen-square-commemorations

A China-based Zoom executive was charged with coordinating with the Chinese government to shut down Zoom meetings in the United States and elsewhere on a host of religious and political topics, including the commemoration of the 31st anniversary of the Tiananmen Square massacre.

Huawei tested AI software that could recognize Uighur minorities and alert police, report says - The Washington Post

https://www.washingtonpost.com/technology/2020/12/08/huawei-tested-ai-software-that-could-recognize-uighur-minorities-alert-police-report-says/

The Chinese tech giant Huawei has tested facial recognition software that could send automated “Uighur alarms” to government authorities when its camera systems identify members of the oppressed minority group, according to an internal document that provides further details about China’s artificial-intelligence surveillance regime.

Over 700 nordmenn kartlagt av kinesisk selskap

https://nrkbeta.no/2020/09/15/over-700-nordmenn-kartlagt-av-kinesisk-selskap/

Et selskap med angivelige koblinger til kinesiske myndigheter har samlet informasjon om flere millioner mennesker verden over. NRK har fått tilgang til den norske databasen, som inneholder over 700 navn. Databasen avslører hvilke personer i Norge som er av interesse for kinesiske aktører, sier ekspert.