Copy
Chinese makers of network software and hardware must alert Beijing within two days of learning of a security vulnerability in their products under rules coming into force in China this year.
Details of holes cannot be publicized until the bugs are fixed. Malicious or weaponized exploit code cannot be released. There are restrictions on disclosing details of flaws to foreign organizations. And vendors will be under pressure to address these vulnerabilities as soon as they can and set up bounty programs to reward researchers.
The regulations are intended to tighten up the nation's cyber-security defenses, crack down on the handling and dissemination of bugs, and keep China's elite up to speed on exploitable flaws present in Chinese-made communications systems, wherever in the world that technology may be deployed.