{"id":280092,"date":"2024-05-03T04:13:00","date_gmt":"2024-05-03T11:13:00","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=331600"},"modified":"2025-07-01T16:35:10","modified_gmt":"2025-07-01T23:35:10","slug":"despite-their-fame-chinese-government-websites-are-very-easy-to-hack","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/despite-their-fame-chinese-government-websites-are-very-easy-to-hack\/","title":{"rendered":"Despite their fame, Chinese government websites are very easy to hack"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Bad configurations, insecure versions of jQuery, and poor quality cookies are some of the countless issues that independent researchers have found while checking the cybersecurity of government websites. <a href=\"https:\/\/en.softonic.com\/articles\/apples-incredibly-private-safari-is-not-so-private-in-europe\" target=\"_blank\" rel=\"noopener\" title=\"Nothing is safe anymore, not even Apple itself\">Nothing is safe anymore, not even Apple itself<\/a>.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"TotalAV Essential Antivirus\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/67ba28ff-606a-4044-a59c-197f04c43299\/2072679578\/totalav-essential-antivirus-logo.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">TotalAV Essential Antivirus<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/url.totalav.com\/633febf126f5c\/click\/SFT\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/url.totalav.com\/633febf126f5c\/click\/SFT\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Five Chinese researchers examined the configurations of nearly 14,000 government websites across the country and discovered concerning vulnerabilities<\/strong> that could lead to malicious attacks, according to a study not yet peer-reviewed published last week and that we have been able to read in <a href=\"https:\/\/www.theregister.com\/2024\/05\/03\/china_gov_web_vuln\/\" target=\"_blank\" rel=\"noopener nofollow\" title=\"The Register\">The Register<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The authors, all of them from the Harbin Institute of Technology, describe <a href=\"https:\/\/www.researchsquare.com\/article\/rs-4275987\/v1\" target=\"_blank\" rel=\"noopener nofollow\" title=\"the study\">the study<\/a> as an examination of &#8220;the security and dependency challenges that plague China&#8217;s government web infrastructure&#8221;.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Chinese government website security is often worryingly bad, say Chinese researchers <a href=\"https:\/\/t.co\/iF6OAyjpSL\">https:\/\/t.co\/iF6OAyjpSL<\/a><\/p>&mdash; The Register (@TheRegister) <a href=\"https:\/\/twitter.com\/TheRegister\/status\/1786223546148249958?ref_src=twsrc%5Etfw\">May 3, 2024<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">And they claim to have revealed &#8220;substantial vulnerabilities and dependencies that could hinder the digital effectiveness and security of government web systems.&#8221; <strong>This is very serious for China and fortunate for its rivals.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Researchers took into account domain name resolution, use of third-party libraries, certificate authority (CA) services, content delivery network (CDN) services, internet service providers (ISP), adoption of HTTPS, IPv6 integration, implementation of domain name system security extensions (DNSSEC), and website performance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Researchers detected numerous serious cybersecurity issues<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It was discovered that more than <strong>a quarter of the domain names used by Chinese government websites lacked Name Server (NS) records<\/strong>, which means they may lack effective DNS configuration and could be unreliable or inaccessible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another finding was <strong>a &#8220;remarkable dependency&#8221; on five DNS service providers<\/strong>, a lack of diversity that could expose the network infrastructure to single points of failure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;In the event of a technical problem, a cyber attack, or regulatory action affecting one of these major providers, a significant portion of the DNS infrastructure could be compromised, impacting accessibility and security in a wide area,&#8221; the researchers wrote.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition, 4250 of the systems used versions of the jQuery JavaScript library vulnerable to CVE-2020-23064, which means that <strong>they were exposed to a remote attack that has been a known issue for about four years.<\/strong><\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"TotalAV Essential Antivirus\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/67ba28ff-606a-4044-a59c-197f04c43299\/2072679578\/totalav-essential-antivirus-logo.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">TotalAV Essential Antivirus<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/url.totalav.com\/633febf126f5c\/click\/SFT\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/url.totalav.com\/633febf126f5c\/click\/SFT\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The study also highlights the need for &#8220;rigorous examination and periodic updates&#8221; of third-party libraries and advocates for &#8220;a diversified distribution of network nodes, which could substantially increase system resilience and performance&#8221;.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The study is likely to be poorly received in Beijing<\/strong>, as the Chinese government has urged the improvement of digital services and government applications, and often issues edicts on enhancing cybersecurity.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Poor configurations, insecure versions of jQuery, and low-quality cookies are some of the countless issues. China has a problem.<\/p>\n","protected":false},"author":9265,"featured_media":280094,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-280092","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/280092","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9265"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=280092"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/280092\/revisions"}],"predecessor-version":[{"id":313413,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/280092\/revisions\/313413"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/280094"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=280092"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=280092"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=280092"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=280092"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=280092"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=280092"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}