Under the new rules by the Cyberspace Administration of China, zero-day vulnerabilities must be disclosed to the government, which will decide what repairs to make. No one in China may 'collect, sell or publish information on network product security vulnerabilities' and this information cannot be given to 'overseas organisations or individuals' other than the product's manufacturer. It means that private sector experts won't be able to sell the zero-day weaknesses they find.
Experts commented that this might lead to Chinese found zero days being passed to Chinese ATP groups. Further, it is not certain that the Chinese government will inform the manufacturer about the vulnerabilities in their products. Finally, it is not certain if the rules will ban the participation of Chinese nationals in bug bounty programmes or pwn2own competitions, which could lead to a smaller number of discovered vulnerabilities.
Зарегистрируйтесь по электронной почте сейчас для еженедельной акции акции
100% free, Unsubscribe any time!Add 1: Room 605 6/F FA YUEN Commercial Building, 75-77 FA YUEN Street, Mongkok KL, HongKong Add 2: Room 405, Building E, MeiDu Building, Gong Shu District, Hangzhou City, Zhejiang Province, China
Whatsapp/ тел: +8618057156223 * телефон: *: 0086 571 86729517 Tel in HK: 00852 66181601
Электронная почта: [email protected]