Bad configurations, insecure versions of jQuery, and poor quality cookies are some of the countless issues that independent researchers have found while checking the cybersecurity of government websites. Nothing is safe anymore, not even Apple itself.
Five Chinese researchers examined the configurations of nearly 14,000 government websites across the country and discovered concerning vulnerabilities that could lead to malicious attacks, according to a study not yet peer-reviewed published last week and that we have been able to read in The Register.
The authors, all of them from the Harbin Institute of Technology, describe the study as an examination of “the security and dependency challenges that plague China’s government web infrastructure”.
And they claim to have revealed “substantial vulnerabilities and dependencies that could hinder the digital effectiveness and security of government web systems.” This is very serious for China and fortunate for its rivals.
Researchers took into account domain name resolution, use of third-party libraries, certificate authority (CA) services, content delivery network (CDN) services, internet service providers (ISP), adoption of HTTPS, IPv6 integration, implementation of domain name system security extensions (DNSSEC), and website performance.
Researchers detected numerous serious cybersecurity issues
It was discovered that more than a quarter of the domain names used by Chinese government websites lacked Name Server (NS) records, which means they may lack effective DNS configuration and could be unreliable or inaccessible.
Another finding was a “remarkable dependency” on five DNS service providers, a lack of diversity that could expose the network infrastructure to single points of failure.
“In the event of a technical problem, a cyber attack, or regulatory action affecting one of these major providers, a significant portion of the DNS infrastructure could be compromised, impacting accessibility and security in a wide area,” the researchers wrote.
In addition, 4250 of the systems used versions of the jQuery JavaScript library vulnerable to CVE-2020-23064, which means that they were exposed to a remote attack that has been a known issue for about four years.
The study also highlights the need for “rigorous examination and periodic updates” of third-party libraries and advocates for “a diversified distribution of network nodes, which could substantially increase system resilience and performance”.
The study is likely to be poorly received in Beijing, as the Chinese government has urged the improvement of digital services and government applications, and often issues edicts on enhancing cybersecurity.