Category Archives: China

Alibaba to Join Microsoft’s Fight Against Pirate Software in China

Microsoft and Chinese online commerce giant Alibaba have signed a memorandum of understanding that will see the Chinese firm take measures to help protect Microsoft’s intellectual property in its online stores.

Microsoft has long struggled with software piracy in China, with then-CEO Steve Ballmer saying in 2011 that the company was missing something like 95 percent of potential revenue due to lax protection of intellectual property rights.

With the new agreement in place, Alibaba will remove counterfeit and unlicensed software from its eBay-like Taobao marketplace and its Tmall B2C site. The two companies will also work together to tell consumers that counterfeit software poses risks to their security and privacy, with Alibaba also helping the unwitting buyers of unlicensed software seek compensation from sellers. A Microsoft-sponsored study claimed that some 85 percent of PCs sold with pirated software in China were infected with malware.

Read 1 remaining paragraphs | Comments

Chinese Government Launches Man-in-Middle Attack Against iCloud

A screen capture shows the warning of a fake iCloud.com certificate—signed by an official Chinese certificate authority.

GreatFire.org, a group that monitors censorship by the Chinese government’s national firewall system (often referred to as the “Great Firewall”), reports that China is using the system as part of a man-in-the-middle (MITM) attack on users of Apple’s iCloud service within the country. The attacks come as Apple begins the official rollout of the iPhone 6 and 6 Plus on the Chinese mainland.

The attack, which uses a fake certificate and Domain Name Service address for the iCloud service, is affecting users nationwide in China. The GreatFire.org team speculates that the attack is an effort to help the government circumvent the improved security features of the new phones by compromising their iCloud credentials and allowing the government to gain access to cloud-stored content such as phone backups.

Chinese iCloud users attempting to log in with Firefox and Chrome browsers would have been alerted to the fraudulent certificate. However, those using Mac OS X’s built-in iCloud login or another browser may not have been aware of the rerouting, and their iCloud credentials would have been immediately compromised. Using two-step verification would prevent the hijacking of compromised accounts.

Read 1 remaining paragraphs | Comments