DEFENSE DOSSIER

ISSUE 30

A VISION FOR 5G COMPETITION MAY David A. Gross, Megan L. Brown, and Tawanna D. Lee 2021 PROTECTING THE U.S. SUPPLY CHAIN FROM CHINA Alexander B. Gray

COUNTERING CHINA IN AFRICA Jacob McCarty

THE CHALLENGE OF CHINA’S RIGHTS ABUSES Olivia Enos

THE CHINESE THREAT TO PRIVACY Klon Kitchen

AMERICAN FOREIGN POLICY COUNCIL DEFENSE DOSSIER

AMERICAN FOREIGN POLICY COUNCIL Explaining the World. Empowering Policymakers. The Chinese Threat to Privacy Klon Kitchen

hese days, it is widely understood that, in the words But Beijing likewise knows that American techno- Tof The Economist, “the world’s most valuable re- logical leadership will not be easily overtaken, and that source is no longer oil, but data.”1 The massive scope of China’s domestic technology industries are not robust cyber-enabled data theft perpetrated by China over just or mature enough to win on their own. The CCP, the last decade supports this assessment. Already back therefore, is pursuing a strategy of “military-civil fu- in 2011, the Office of the National Counterintelligence sion,” where the Chinese government and the country’s Executive was assessing that “Chinese actors are the industries partner on mutually-beneficial priorities and world’s most active and persistent perpetrators of eco- objectives—often leveraging state monetary and espio- nomic espionage.”2 Ten years later, it has been discov- nage capabilities in the process. ered that Chinese hackers have compromised more than To put it simply, Beijing is attempting to prove a 400,000 Microsoft Exchange servers in 115 nations, new concept of governance that links the wealth of its including more than 30,000 in the United States, giv- version of capitalism with the stability and security of ing Beijing full access to the victims’ emails and leaving technological totalitarianism. If successful, China will them vulnerable to further exploitation.3 likely find a host of would-be authoritarians around the If the United States is going to prevent China from world eager to sign up for this new model, and it would systematically syphoning “the world’s most valuable be well-positioned to supply the capabilities and infra- resource,” it must understand the strategic rationale of structure needed for its implementation in those plac- the Chinese Communist Party (CCP) for hoarding data, es. Indeed, techno-totalitarianism could become a key how that data is subsequently employed, how it is being export along China’s Belt & Road. collected, and what can be done to mitigate the threat. At the root of this strategy is the acquisition and use of data, which the CCP uses to build wealth, to secure itself, and to shape the international environment. CHINA’S TARGETING OF DATA IS RATIONAL

China is like every other nation in the history of the THE THREE ROLES OF DATA world in that it seeks to build and wield geopolitical influence to secure itself and its interests. The CCP has Data is not valuable in and of itself. Data must be ex- also determined that collecting and using this influ- amined, assessed, and leveraged toward some broader ence will, in part, depend on the nation’s leadership in objective. But, when this is done effectively, data can emerging technologies that are shaping modern gover- provide a decisive advantage. To this end, the CCP’s nance and economics. It has specifically identified the data acquisition efforts can be understood as supporting following industries as priorities: information technol- three goals. ogies, robotics, “green” energy, aerospace, ocean engi- First, data is key for economic energy. Harvard profes- neering, power equipment, new materials, medicine, sor and business strategist Michael Porter observes, “In- and agriculture.4 novation is the central issue in economic prosperity.”5

Klon Kitchen is a resident fellow at The American Enterprise Institute where he focuses on technology and national security. You can follow him on at @klonkitchen and you can subscribe to his weekly newsletter at www.thekitchensync.tech

20 This is certainly true for the United States, where every monitoring of Uyghur Muslims, primarily in China’s consumer technology sector job supports almost three Xinjiang Province, is staggering. It is also emblematic of non-tech jobs in the American economy, and where the the government’s willingness to use data to monitor, ha- U.S. tech sector supplies $1.3 trillion in annual wages, rass, and target anyone deemed a threat to the state. In $503 billion in tax revenue, and contributes nearly 12% Xinjiang, Uyghurs are under nearly-total surveillance, of national GDP (~$2.3 trillion).6 regularly have their devices searched and copied, and Similarly, in China, electronics and technology sales are even required to download government surveillance revenues topped $630 billion in 2019, and nine of the software on their mobile phones. Their communica- world’s 20 largest internet companies are Chinese.7 tions, images, medical data, economic spending, online While economic numbers coming out of China are no- viewing, and their family and social interactions are toriously suspect, a Tufts University survey8 ranks the known by the government – often with the help of the nation as the world’s most rapidly evolving digital econ- country’s leading tech companies, which collect, process, omy. There can be no doubt that the nation’s financial and analyze this data. future is inextricably linked to its technology industry. Thus, the systematic and sustained gathering of intellectual property, propri- etary secrets, trade secrets, and other data is critical for China’s economic growth. One Beijing is attempting to prove a in five North American-based companies now say China has stolen their intellectual new concept of governance that property.9 As of 2019, this was projected links the wealth of its version to have cost the U.S. economy more than of capitalism with the stability $600 billion.10 Beijing has clearly concluded that its prosperity is best achieved by lever- and security of technological aging that of others. totalitarianism. Second, data is seen as essential for in- ternal social strength. It can be said that the CCP’s primary concern is its own stability and security, and that data harvesting is a key means of achieving these ends. Specifically, data col- Finally, the third goal of China’s data collection is “ lection is used by the CCP to manipulate public attitudes external political power. Aggressive data collection and and behavior, and to suppress anyone who is thought to exploitation not only facilitates economic growth and challenge the government’s authority. government stability, it also enables all of the other Beijing’s social credit score regime exemplifies the elements of national power. Traditional and corporate nation’s cultural shaping operations. Here, the CCP espionage are the backbone of China’s military industri- leverages wide-scale surveillance and data collection to al base, its diplomatic strategies, its intelligence enter- monitor citizen’s economic, social, political, and online prise, and its international treaties and trade practices. habits in an effort to incentivize “good” behavior and Put another way, a robust pipeline of data feeds China’s constrain “bad” behavior. If you advance the Party’s engagement with the world by informing and shaping priorities, your social score goes up—giving you greater its ends, ways, and means. freedom of movement and increased access to benefits like public services and travel. If you engage in unap- THREE WAYS IN WHICH DATA IS COLLECTED proved behaviors, however, you may not be allowed to apply for certain jobs or to leave your home town. The Chinese government draws data from three prima- The situation is even worse for religious and political ry sources: open-source data stores, government espio- minorities. The sheer scope of the CCP’s ubiquitous nage, and corporate espionage.

21 “has 300 data segments for nearly every U.S. consumer.” Another “has information on 1.4 The systematic and sustained billion consumer transactions and over 700 gathering of intellectual billion aggregated data elements.” And still another “adds three billion new records each property, proprietary secrets, month to its databases.”12 trade secrets, and other data That data can enable a near-total recon- is critical for China’s economic struction of an individual’s identity, location history, interpersonal relationships and growth. One in five North networks, entertainment and purchasing American-based companies preferences and habits, and even future eco- nomic, social, and political outcomes. And all now say China has stolen their of it is available for sale to anyone willing to intellectual property. As of 2019, cut a check. “this was projected to have cost Or to steal it. Data brokers are a key target for the CCP. In 2017, suspected Chinese the U.S. economy more than hackers compromised the Equifax credit $600 billion. Beijing has clearly brokerage firm, exposing critical informa- tion for hundreds of millions of people. Two concluded that its prosperity is years prior, China broke into the Anthem best achieved by leveraging that Inc. insurance company and stole the names, of others. birthdates, addresses, social security num- bers, and employment data for more than 78 million customers. While Americans are in- First, in discussing open-source information, consider creasingly concerned about how data collec- the following statistics from 2020:11 tion affects their domestic freedoms and privacy, there • Nearly 90% of the word’s data has been created is still too little understanding of the national security in the last two years; implications of these practices. • Every minute of every day, 500 hours of new Traditional government espionage is another primary video are uploaded to YouTube, 147,000 photos source of data for the CCP. In July 2020, FBI Director are posted to , 41 million messages Christopher Wray noted publicly that: are shared on WhatsApp, and more than 212 million emails are sent; • Humans produce 2.5 quintillion bytes of data ev- If you are an American adult, it is more likely ery day (for perspective: 2.5 quintillion pennies, than not that China has stolen your personal if laid flat, would cover the earth’s surface five data … We’ve now reached the point where the times); and, FBI is opening a new China-related counter- • It is projected that people will produce 463 exa- intelligence case about every 10 hours. Of the bytes every day by 2025 (again, for reference, if a nearly 5,000 active FBI counterintelligence cases gigabyte is the size of the earth, an exabyte is the currently under way across the country, almost size of the sun). half are related to China.13 The majority of the data discussed above is generated In terms of military and intelligence compromises by, and exists within, unclassified networks that con- alone, the CCP has stolen American plans for super- stitute the heart of the “knowledge economy.” At the sonic anti-aircraft missiles, stealth technology, and, of core of this economy are an array of “data brokers” who course, troves of personally identifiable information compile, analyze, and sell this data. Just one of these on Americans within the U.S. Intelligence Community data brokers, estimates the Federal Trade Commission, when it hacked the Office of Personnel Management in

22 2015. Chinese hacking of defense contractors and others tial liability that must be addressed urgently and com- in the private sector is so pervasive that last year, the prehensively. Department of Homeland Security issued a Data Securi- ty Business Advisory, with the following warning: RECOMMENDATIONS FOR THE NEW ADMINISTRATION Businesses expose themselves and their cus- tomers to heightened risk when they share In its March 2021 Interim National Security Strategic sensitive data with firms located in the PRC, or Guidance, the Biden administration promised to “con- use equipment and software developed by firms front unfair and illegal trade practices, cyber theft, and with an ownership nexus in the PRC, as well as coercive economic practices that hurt American work- with firms that have PRC citizens in key leader- ers, undercut our advanced and emerging technologies, ship and security-focused roles (together, “PRC and seek to erode our strategic advantage and national firms”). Due to PRC legal regimes and known competitiveness.”15 Here are three broad steps that are PRC data collection practices, this is particularly needed in order to see this policy through. true for data service providers and data infra- structure.14 The third source of data leveraged by China, corporate espionage, is perhaps the Beijing’s social credit score most poorly understood—and least well addressed—vector of Chinese data theft. regime exemplifies the nation’s It obviously includes traditional efforts by cultural shaping operations. companies to steal intellectual property and other secrets. However, the CCP is going Here, the CCP leverages wide- even further by enacting national security scale surveillance and data and cybersecurity laws that apply to every collection to monitor citizen’s company inside China and to every Chinese company, wherever it operates. economic, social, political, and In January 2020, for example, a new cy- online habits in an effort to bersecurity law required all companies op- incentivize “good” behavior and erating in China—including foreign-owned “ companies—to arrange and manage their constrain “bad” behavior. computer networks so that the Chinese government has access to every bit and byte of data that is stored on, transits over, or in any other way touches China’s information infra- First, stop the bleeding. The United States is hem- structure. Laws like this one are at the root of American orrhaging data to the Chinese. The nation cannot be concerns about Chinese companies such as Huawei and secure as long as these losses continue at their current TikTok operating in the United States. These com- pace. In addition to ongoing efforts to increase scrutiny panies do not need to have “backdoors” that Chinese of Chinese investment and operations in the United hackers can access. Nor do they need to be malevolent States, the Biden administration should investigate the in their intentions. They simply need to be compliant national security equities at stake in the data broker- with Chinese law. And, in China, anyone who is not age industry, and offer a path forward that can be fully compliant is not in business for long. implemented within 18 months. Washington should Any one of these sources of data constitutes a critical also develop a coherent framework for evaluating what capability for Beijing, and a critical vulnerability for the technologies and platforms are truly strategically essen- United States. Taken in total, they constitute an existen- tial—and therefore in need of aggressive defense—and

23 those which are valuable, but where losses or depen- lia. The specific forms this alliance could take may vary, dency are not catastrophic to American strength. The but such a construct is essential and must be pursued as methodology offered the China Strategy Group (CSG) a core objective of American foreign policy. of former Google CEO Eric Schmidt and Jigsaw CEO Finally, the United States must prepare for a 16 Jared Cohen is an excellent place to start. Finally, in “splinternet.” As has been discussed above, Washing- the context of traditional government espionage, there ton and Beijing have two increasingly different notions is already a great deal of effort underway in the classi- of modern governance, but both understand data and fied environment. Thus far, however, we do not appear networks as being critical for securing and spreading to have changed Beijing’s strategic calculus regarding those visions. In much the same way that the world was increasingly aggressive cyber operations. This must divided into competing spheres of influence between change, and we must be prepared to use every element the West and the Soviet Union during the Cold War, of national power to force this evolution on the CCP. the world’s networks may soon be divided between a Western and a Chinese internet – each with its own norms, rules, and infrastructure. To be sure, such a development would be Washington should develop incredibly disruptive to globalized econ- a coherent framework for omies and to the digital global commons more generally. Yet the techno-totalitarian evaluating what technologies model being pioneered by China requires and platforms are truly at least some decoupling from the Western strategically essential – and world. China, Russia, and other nations are already building regional internets in the therefore in need of aggressive name of cybersecurity, and there is little defense – and those which the United States can do to prevent these efforts from maturing. American bans on are valuable, but where Chinese companies like ZTE and Huawei losses or dependency are not are being mirrored by Chinese bans on catastrophic to American Western equipment. These are all telltale “ signs of the coming “splinternet.” strength. GETTING SERIOUS ABOUT DATA The world is awash in data, and this deluge will only Next, we have to build an alliance for the trust- deepen in the foreseeable future. Nations that har- ed development and deployment of emerging ness and secure this new strategic resource will be technologies. Even if the United States were able to unilaterally dominate emerging technologies for the best positioned to thrive in the emerging geopolitical next century, our national security and foreign influence environment. Those that do not will face existential would be critically weakened if our global partners and challenges. The Chinese government is heeding the allies fail to keep pace—or even worse, it they are sub- ancient adage: “To secure ourselves against defeat lies sumed by Chinese technological expansion. Here again, in our own hands, but the opportunity of defeating the the CSG offers a helpful suggestion by calling for a new enemy is provided by the enemy himself.”18 The United multilateral forum to “bring together key countries to States, however, has been too slow in securing itself, and coordinate responses to technological competition.”17 because it has it risks ceding its security and interests to This “T-12” should include the United States, Japan, the nation’s chief international rival. Even so, there is Germany, France, Britain and Canada, the Netherlands, now growing consensus in the United States around this South Korea, Finland, Sweden, India, Israel, and Austra- challenge, and there is good reason to expect a more se-

24 rious approach in the weeks and months ahead. In order Advisory: Risks and Considerations for Businesses using Data Ser- for one to materialize, however, we must understand vices and Equipment from Firms Linked to the People’s Republic the strategic value of data, and protect it accordingly. of China,” n.d., https://www.dhs.gov/sites/default/files/publica- tions/20_1222_data-security-business-advisory.pdf. ENDNOTES 15 White House, Interim National Security Strategic Guidance, March 2021, https://www.whitehouse.gov/wp-content/uploads/2021/03/ 1 “Regulating the internet giants: The world’s most valuable NSC-1v2.pdf. resource is no longer oil, but data,” The Economist, May 6, 2017, 16 China Strategy Group, Asymmetric Competition: A Strategy for https://www.economist.com/leaders/2017/05/06/the-worlds- China & Technology, Fall 2020, https://www.documentcloud.org/ most-valuable-resource-is-no-longer-oil-but-data. documents/20463382-final-memo-china-strategy-group-axios-1. 2 Office of the National Counterintelligence Executive, Foreign 17 Ibid. Spies Stealing US Economic Secrets in Cyberspace: Report to Congress on 18 Sun Tzu, The Art of War, Samuel B. Griffith (trans) (Oxford: Foreign Economic Collection and Industrial Espionage, 2009-2011, Octo- Clarendon Press, 1963). ber 2011, https://www.hsdl.org/?view&did=720057. 3 “A Basic Timeline of the Exchange Mass-Hack,” Krebs on Security, March 8, 2021, https://krebsonsecurity.com/2021/03/a-basic- timeline-of-the-exchange-mass-hack/. 4 Scott Kennedy, “Made in China 2025,” Center for Strategic & International Studies, June 1, 2015, https://www.csis.org/analysis/ made-china-2025. 5 Barry Jaruzelski, “Innovation’s New World Order,” Forbes, November 16, 2015, https://www.forbes.com/sites/strateg- yand/2015/11/16/innovations-new-world-order/. 6 “PRESS RELEASE: Tech Sector Supports 18 Million U.S. Jobs, Represents 12% of GDP ....” Consumer Technology Association, April 29, 2019, https://www.cta.tech/Resources/Newsroom/Me- dia-Releases/2019/April/Tech-Sector-Supports-18-Million-U-S- Jobs,-Represe. 7 “How Dominant are Chinese Companies Globally?” CSIS ChinaPower, n.d., https://chinapower.csis.org/chinese-compa- nies-global-500/. 8 “Digital Evolution Index,” Tufts University Digital Planet, n.d., https://sites.tufts.edu/digitalplanet/tag/digital-evolution-index/. 9 Eric Rosenbaum, “1 in 5 companies say China stole their IP with- in the last year: CNBC CFO survey,” CNBC, March 1, 2019, https:// www.cnbc.com/2019/02/28/1-in-5-companies-say-china-stole- their-ip-within-the-last-year-cnbc.html. 10 James Lewis, “China’s addiction to intellectual property theft,” Hinrich Foundation, March 25, 2021, https://www.hinrichfounda- tion.com/research/tradevistas/us-china/china-ip-theft/. 11 Jacquelyn Bulao, “How Much Data Is Created Every Day in 2021?” TechJury, March 18, 2021, https://techjury.net/blog/how- much-data-is-created-every-day/; “Data Never Sleeps 8.0,” Domo, n.d., https://www.domo.com/learn/data-never-sleeps-8. 12 Federal Trade Commission, Data Brokers: A Call for Transparency and Accountability, May 2014, https://www.ftc.gov/system/files/ documents/reports/data-brokers-call-transparency-accountabili- ty-report-federal-trade-commission-may-2014/140527databroker- report.pdf. 13 Christopher Wray, Speech before the Hudson Institute, Wash- ington, DC, July 7, 2020, https://www.fbi.gov/news/speeches/ the-threat-posed-by-the-chinese-government-and-the-chinese- communist-party-to-the-economic-and-national-security-of-the- united-states. 14 U.S. Department of Homeland Security, “Data Security Business

25 AMERICAN FOREIGN POLICY COUNCIL Explaining the World. Empowering Policymakers.

26