🧔♂️ A friendly human may check it before it goes live. More news here
Chinese hacking contests fuel state cyber strategy
China is using domestic hacking competitions like the Tianfu Cup as part of its cybersecurity strategy. Participants must report discovered vulnerabilities to the government.
The Tianfu Cup, launched in 2018, replaced international contests like Pwn2Own, where findings were shared with developers.
New rules from 2018 and 2021 require vulnerabilities to be disclosed first to the Chinese government and limit external sharing.
Critics argue these policies let China use flaws for state purposes. A 2019 Google report linked a Tianfu Cup vulnerability to a campaign targeting Uyghur communities.
While China’s cybersecurity tactics differ from the West, other countries, including the US, also hoard vulnerabilities for intelligence use.
🔗 Source: Bloomberg
🧠 Food for thought
1️⃣ Government-directed vulnerability management as national strategy
China’s approach to vulnerability management represents a broader shift in how nations treat digital security as critical infrastructure.
After dominating international hacking competitions like Pwn2Own for years, Chinese teams withdrew following the 2017 criticism from Qihoo 360 founder Zhou Hongyi, a political advisor who argued vulnerabilities found by Chinese researchers should stay within China’s borders.
China’s 2017 Cybersecurity Law created a legal framework requiring network operators to store data domestically and permit government inspections of network operations 1.
This was followed by even stricter data security laws in 2021 that mandated all vulnerabilities discovered by Chinese researchers be reported directly to the government within 48 hours, with significant penalties for non-compliance.
The distinction between China’s approach and Western practices is substantial. As Dustin Childs noted in the article, “The NSA doesn’t force us to disclose anything along those lines to them.”
China’s cybersecurity market is projected to grow at a 21% CAGR to reach $59.32 billion by 2029, reflecting substantial government investments in establishing a cybersecurity ecosystem that serves national interests 2.
2️⃣ Diverging global frameworks for vulnerability disclosure
A significant split is emerging in global vulnerability disclosure practices, with different regions adopting contrasting approaches that reflect broader technology governance philosophies.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




