China orders plug for hole in Green Dam

 

Summary

The Chinese government orders makers of Green Dam censorware to rush out a patch, after researchers discovered gaping security flaws in the program.

Events

IBM Technology Conference & Expo 2012
May 22, 2012

One World Hotel, First Avenue, Bandar Utama City Centre, 47800 Petaling Jaya, Selangor

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

The Chinese government has ordered the makers of the Green Dam Youth Escort censorware to rush out a patch.

The censorship software has been downloaded over 3.5 million times since August 2008, according to its makers Jinhui Computer System Engineering. However, researchers from the University of Michigan revealed in a paper last week that the program contains gaping security flaws, which could lead to users' systems being compromised, and the creation of a massive botnet.

Jinhui on Monday told the People's Daily, an officially sanctioned Chinese publication, that the company had been ordered by a government agency to produce a patch.

"The Ministry of Industry and Information Technology told us to make the software safer as soon [as] a series of security vulnerabilities were found," said Zhang Chenmin, general manager Jinhui, on Sunday.

The Green Dam software is billed by the Chinese government as a pornography filter, primarily for use in schools.

In their paper, the University of Michigan researchers the software could allow malicious code to be uploaded to a PC, if the user visited a malicious Web site. In addition, they said the filter contains a backdoor that could allow the software's manufacturer or a third party to remotely install malware.

Jinhui plans to take legal action against the University of Michigan researchers for revealing the flaws, Zhang told the People's Daily.

"It is not responsible to crack somebody's software and publish the details, which are commercial secrets, on the Internet. [The researchers] have infringed the copyright of our product," said Zhang.

According to the University of Michigan paper, the Green Dam software includes a number of blacklists from the CyberSitter Web-filter program, which is produced by California-based Solid Oak. On Saturday, the U.S. software publisher alleged that Green Dam features Solid Oak's proprietary code, and said it will seek an injunction to prevent U.S. companies from shipping computers with the filtering software.

Zhang said while there may be similarities in the sites blocked by the two filters, Jinhui had not infringed copyright.

"I cannot deny that the two filters' databases of blacklisted URL addresses might share similarities," Zhang told the People's Daily. "After all, they are all well known international pornographic websites that all porn filters are meant to block. But we didn't steal their programming code."

The software has been mandated by the Ministry of Industry and Information Technology to be pre-installed on all new computers from July 1, while the initiative has been agreed by Lenovo, according to Jinhui.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Mac users' indifference toward security 'worrying': 59 Jakarta 10350, Indonesia In light of the recent spate of ... http://t.co/Lxgnc1wM

Pakistan lifts block on Twitter - ZDNet Asia: Pakistan lifts block on TwitterZDNet Asia59 Jakarta 10350, Indones... http://t.co/61n85ajh

Pakistan lifts block on Twitter http://t.co/WHqoJOqm http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Pakistan lifts block on Twitter: Country restores access after briefly ... http://t.co/5gqegFWK http://t.co/wiqY9ktt

Pakistan lifts block on Twitter. http://t.co/y0arswpE

Mac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn

Mac users' indifference toward security 'worrying' - ZDNet Asia: Mac users' indifference toward security 'worryi... http://t.co/CD9pvW08

RT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn

Mac users' indifference toward security 'worrying' - ZDNet Asia: USA TODAYMac users' indifference toward securit... http://t.co/4EUVidiO

Mac consumers indifferent about security, security vendors warn such mindset is "worrying" http://t.co/ZGIxdg67 #In

Mac users take note! RT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/YrLB9btb #mac #apple

RT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn

Mac users' indifference toward security 'worrying': However, Mac users ZDNet Asia spoke to expressed indifferenc... http://t.co/15DulmWS

RT @jolintan: Mac users take note! RT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/2RQkfCKt #mac #apple

APAC tech merger and acquisition in Q1 down but value up: http://t.co/V7UkMABl

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 hours ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

19 hours ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

2 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

2 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

3 days ago by wykoong on Drop the egos, copy ideas, then innovate