Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

China says US hacked its national time center

China has accused the US National Security Agency of carrying out cyberattacks on its National Time Service Center since March 2022.

The Ministry of State Security claimed that the agency exploited vulnerabilities in employees’ mobile phones and used stolen login credentials to access the center’s computers.

The National Time Service Center in Xi’an provides precise time data for government, civil, and industrial use, and supports international time standards.

Authorities said their investigation traced the attacks to private servers worldwide used to hide their origin.

They added that measures have been implemented to protect the center’s systems.

The allegations come amid ongoing cyber accusations between China and Western countries and follow heightened trade tensions between Beijing and Washington.

🔗 Source: Bloomberg

🧠 Food for thought

Implications, context, and why it matters.

Time synchronization attacks put more than governments at risk

  • An alleged US National Security Agency (NSA) intrusion into China’s National Time Service Center drew attention 1. Many time systems for financial transactions, encrypted sessions, Domain Name System Security Extensions (DNSSEC), or fraud checks still use unauthenticated Network Time Protocol (NTP) 1. Adoption of Network Time Security (NTS) remains sparse 1.
  • Chinese Advanced Persistent Threat (APT) groups have exploited known Common Vulnerabilities and Exposures (CVEs) in exposed edge devices (internet-facing networking gear) since at least 2021 2. Targets include gear from network security vendors such as Fortinet, Juniper, and SonicWall 2. They focus on telecommunications plus other critical infrastructure worldwide 2. A compromise of a nation-state time authority implies risk for enterprises that depend on accurate timestamps for compliance or trading operations.
  • Traditional Network Time Protocol version 4 (NTPv4) sends data without encryption, which opens spoofing plus man-in-the-middle attacks that can inject false time data 3. Attackers could manipulate timestamps to bypass security logs, undermine trust in encrypted sessions or DNSSEC, and disrupt time-sensitive operations 1.

Authenticated time opens a market for vendors

  • Network Time Security (NTS), standardized in Request for Comments (RFC) 8915 in 2020 1, uses Transport Layer Security (TLS) 1.3 plus authenticated encryption to stop spoofing and replay attacks 4. Few providers offer it, which leaves room for managed service providers and equipment vendors 1.
  • Network and security engineering teams that run latency-sensitive infrastructure such as high-frequency trading platforms, 5G networks, or industrial control systems can offer NTS rollout services 1. They can add authenticated NTP monitoring plus compliance assessments 1.
  • Network equipment makers can add NTS to routers or time servers 5. Industrial device manufacturers can do the same 5. Meinberg, a time-synchronization hardware vendor, shipped full NTS support in its NTP servers with LTOS (appliance operating system) Version 7.08 5. That move puts it ahead of rivals still on NTPv4.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.