China Chat Log Leak Shows Scope of Surveillance

Advertisement
By Agence France-Presse | Updated: 7 March 2019 17:19 IST

A leak of around 364 million online records in a Chinese database, including private messages and ID numbers, has again highlighted the size and scope of Beijing's mass surveillance system.

The files show a wealth of information linked to online accounts, including GPS locations, file transfers, and chat logs, according to the database discovered by Victor Gevers, a security researcher at Dutch non-profit GDI Foundation.

The data collection appears indiscriminate - some conversations are simply banter between teenagers, like one commenting on someone's weight and clothing size.

Advertisement

"They know exactly who, when, where and what," Gevers told AFP, explaining that thousands of records were piped daily to different databases for local law enforcement to review.

Advertisement

Government procurement documents and database records shared by Gevers show that the database is linked to an "Internet cafe management system" developed by HeadBond.com, a tech firm based in eastern Shandong province.

In 2017, the public security bureau in Yancheng city, eastern Jiangsu province - where at least one Internet cafe named in the database is based - contracted HeadBond for a system that monitors online activity at Internet cafes. 

Advertisement

On its website, the company calls its Internet cafe management system "the best solution" for identifying online users for police on its website.

HeadBond declined to comment, and the Yancheng city government and public security bureau did not respond to AFP's request for comment.

Advertisement

Internet cafe dragnet
Over the past decade, the Chinese government has cracked down on Internet cafes -- especially underground venues that serve minors - over concerns of game addiction and crime.

Chinese law requires Internet cafes to record the identities and "relevant" online activity of users, and provide them to the public security bureau on request -- which has resulted in an entire market of Internet cafe monitoring systems like those offered by HeadBond.

"This also explains why data leaks that involve personal information are more prevalent in China," said Lokman Tsui, an expert on Internet policy at the Chinese University of Hong Kong. 

"Beijing requires most network services to register their users with real names," he told AFP.

"This means that every single mobile phone operator, Internet cafe, social media website, and so on, are legally required to have databases filled with personal information, and all these databases are potentially vulnerable to attacks and leaks." 

The capture of extensive user data, such as chat logs, also extends well beyond the stated purpose of catching minors surfing the Web or playing games. 

A government procurement notice posted last month by Liaoyuan city in northeastern Jilin province, for instance, outlines specifications for another "Internet cafe management system" for local police, with explicit requirements for features that support querying and analysis of content on QQ, a popular messaging app in China.

"It's shocking the amount of personal data that is being collected on Chinese people," said Bob Diachenko, a security researcher who has reported on exposed databases in the US and Europe for the past few years, and is now looking at cases in China.

In particular, it is surprising to see the amount of additional data that is linked with a user's login data, Diachenko told AFP, such as their IP address, name, and even information about their family members. 

"Sometimes it's just big data and it doesn't even make sense to collect that from a user perspective," he said.

GPS tracker
Last month, Gevers had found another publicly accessible database containing personal information such as ethnicity and GPS tracking data of 2.6 million people in Xinjiang. Access to the database has since been closed.

The restive northwestern region is home to most of China's Uighur ethnic minority, which has been under heavy police surveillance in recent years after violent inter-ethnic tensions.

"I would argue that good personal data protection is neither in the interest of the companies who gather the data for profit, nor the government who can (ab)use that data for power and surveillance,"  Tsui wrote in an email.

"It is the people in China and their basic human rights, in this case privacy, who end up drawing the short stick."

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: China, Surveillance
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S24 Ultra Deal Revealed Ahead of Amazon GIF Sale
  2. Nothing Ear 3 With 'Super Mic' Feature, Up to 45dB ANC Launched: See Price
  3. Xiaomi Announces Offers on These Products Ahead of Amazon, Flipkart Sales
  4. DJI Mini 5 Pro With 1-Inch Camera Sensor Launched at This Price
  5. Amazon Sale 2025: Check Top Deals on These iQOO Smartphones
  6. These Samsung Phones Will Get Price Drops Ahead of Festive Season
  7. Garmin Venu 4, Instinct Crossover AMOLED Debut With New Lifestyle Logging Feature
  8. Here's How Xbox Full-Screen Mode Can be Enabled on All Windows Handhelds
  9. iOS 26's Liquid Glass Design Causes Optical Illusions, Users Claim
  10. iQOO 15 Design Leak Reveals Colour-Changing Panel: See Benchmark Scores
  1. Sun Shows Signs of Rising Activity Following Decades of Weakening, Study Finds
  2. IMAP Space Weather Mission to Lift Off Soon, NASA Confirms Broadcast Plans
  3. Microsoft's Xbox Full-Screen Experience Leaks on Other Windows Handhelds Ahead of ROG Xbox Ally Debut
  4. Cellecor Comet CBS-05 Pro Bluetooth Speaker Launched in India: Price, Features
  5. Samsung Galaxy S24 Ultra, Galaxy S24 FE, Galaxy A55 5G and More to Go on Sale With Discounts During Festive Season
  6. Coinbase Urges US DOJ Action as SEC Mulls Dropping Lawsuit Against Crypto Exchange
  7. Vivo V60 Lite 4G Design, Specifications Leaked; Tipped to Launch With Snapdragon 685 SoC, 6,500mAh Battery
  8. Nothing Ear 3 Launched With Super Mic Feature, Up to 45dB Active Noise Cancellation: Price, Features
  9. Nvidia Bets Big on Intel With $5 Billion Stake and Chip Partnership
  10. Samsung Project Moohan XR Headset Launch Reportedly Postponed to October
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.