國際人權組織 ARTICLE 19 談論他們的2025年報告《中國特色的網路安全》Cybersecurity with Chinese Characteristics,分析中國如何利用數位建設以推廣中國特色的數位治理,達到最終改變世界秩序的目的:
- 多邊主義:中國推廣多邊主義 multilateralism、摒棄多元利害關係人的參與 multi-stakeholderism。中國雖強調與不同國家多邊合作,並主張各國自主決定科技發展的方向,但在這個模式下中國拒絕如民間社會及學術界的參與。
- 新的國際秩序:中國嘗試推動以中國領導的跨區域或全球的組織以取代現在以民主國家領導的國際機構,像是中國提出的「全球安全倡議」。
全球中國計畫主任 Michael Caster 和亞洲地區專員劉以正講解這項有關中國推廣數位威權主義的研究、三個案例國家(印尼、巴基斯坦、越南)的擴張情況、中國推廣數位治理準則的脈絡、以及台灣的另類典範。
數位絲路
2014年成為中國「數位絲路」計畫的一個重要轉折點。為落實「一帶一路」的野心,中國成立了中國國家互聯網信息辦公室(簡稱中央網信辦 Cyberspace Administration of China, CAC),同時發布了《周邊國家互聯互通基礎設施建設規畫》首次將「數位絲路」名詞公開,表達要全力打造「數位絲路」的野心,將中國的科技發展成果推廣至全世界。在法規層面,中國也發展了由北京主導的監控與審查機制,近幾年更加修訂和宣布法規,規範中國科技公司該如何協助政府,例如:
- 2017年《網路安全法》:賦予中央網信辦 CAC 檢視企業網路安全的權力,並講述了資料在地化 data localization、實名驗證及網路封鎖的規範。
- 2021年《數據安全法》:賦予中央網信辦 CAC 要求私人企業提供必要資料的權力。若國外的資料涉及損害國家利益,中央網信辦也有權力追究法律責任。
推廣中國特色的數位治理模式
中國想重塑全球數位生態的野心,我們聊到2014年於浙江烏鎮、由中央網信辦 CAC 主辦的第一屆「世界互聯網大會」World Internet Conference,與會者包括許多國際科技大廠如蘋果及Microsoft。中國官員在午夜時刻,將一份「烏鎮宣言」草案悄悄地塞進與會者居住的飯店房門門縫底下,當時多名代表質疑及反對這份宣言。最後在閉幕式時,中國官方沒有提及到這份宣言,而這一系列的怪異舉動也被視為一個嘗試強迫民主國家接受中國是網路治理準則的舉動。
在2014年之後,中國將目標放在發展中國家,因這些國家有發展不同數位科技的需求,而印太地區成了中國伸出橄欖枝的目標之一。
ARTICLE 19 在2024年發布《數位絲路:中國與印太地區崛起的數位壓迫》The Digital Silk Road: China and the rise of Digital Repression in the Indo-Pacific 報告指出了中國以交流、合作、投資等名義,在這些國家推出不同合作及投資計畫,包括5G、衛星、海底纜線、人才交流等計畫。舉例來說,儘管美國當時強烈建議盟友禁止接受來自中國的電信技術,泰國仍然是華為在東南亞測試5G技術的第一個國家。華為也在2019年與泰國最大的電信供應商 Advanced Info Service 簽署合作備忘錄。
印尼
印尼面臨包括人才及資源短缺的挑戰,而這使印尼大量依賴中國提供的數位科技。2017年為中印資安合作的重要里程碑。中國國家計算機網絡應急技術處理小組(簡稱:CNCERT/CC)在舉辦於青島的中國—東協資安研討會議中,簽署了合作意向書。會議中強調區域合作;研討會中指出印尼在強化資安危機處理技術上的需求;在合作意向書中,要求兩國定期交換網路威脅的資訊、舉辦工作坊及培訓課程,也強調網路主權的重要性。
印尼開始轉變政策面向,漸漸對中國主導及研發的科技產生依賴。2019年,印尼網路與情報局與中國中央網信辦 CAC 簽訂合作意向書,並於2021及2023年續約。在這份意向書裡,華為扮演重要角色,幫助印尼提高國家資安技術,意向書中也提到不同合作模式,包括專業培訓、技術共享等計畫。這個日益加深的合作引起許多學者們的疑慮,因這些「資安治理」的協助會接觸到具敏感性的資料。
巴基斯坦
巴基斯坦在治理、技術的套用上向中國靠攏。技術層面上,中國在巴基斯坦的投資可從十多年前追溯:2013年巴基斯坦啟用「一帶一路」的「中巴經濟走廊」,也同時使用「中國北斗衛星導航系統」,成為第一個採用該技術的合作國家。巴基斯坦也採用中國特色的網路治理模式。巴基斯坦國家網路緊急應對小組 National Cyber Emergency Response Team of Pakistan (PKCERT) 在2023年宣布的規範中,賦予了資料蒐集及監控的權利。
從法律層面來說,2016年訂定的《電子犯罪預防法》Prevention of Electronic Crimes Act (PECA) 為著名的案例。該法訂定的初衷為抑止恐怖主義,巴基斯坦政府在近幾年雖然有權力輪替的現象,但 PECA 被不同黨派的政府濫用,成為打壓異己的工具。該法賦予了巴基斯坦電信管理局權力要求社群媒體下架及封鎖任何批判該國安全及國防的言論,使當地記者面臨巨大挑戰。PECA 也在2025年一月通過了新增條例,對於在網路上散佈「不實資訊」並造成「恐慌、恐懼、混亂及動亂」的行為,可被判處$200萬盧比(約莫$7,150美元、或約$21萬台幣)或是三年監禁。
ARTICLE 19 研究發現,PECA與中國於2017年通過的《網路安全法》有高度的相似性。除此之外,巴基斯坦規範了一套VPN白名單,只有經政府授權的VPN才能夠在當地使用。巴基斯坦政府也試圖打造一個「防火長牆」。2024年,巴基斯坦電信管理局宣布於該國網頁管理系統升級加入深層封包檢測技術,可使政府在網路閘道層級管制網路流量。根據當地媒體報導,政府已在兩個最主要的網路交換點設置防火牆。這使各界擔心巴基斯坦政府在資安治理上的透明性。
越南
越南和中國在政治意識形態上有高度的相似性,兩國皆主張一黨專制。在資安治理上,越南在這十幾年間向中國學習、合作。兩國於2024年1月簽署合作意向書,目的為共同打擊網路上誹謗、危害安全及公共秩序的活動。越南更將合作稱作「全面戰略夥伴關係」comprehensive strategic cooperative partnership。越南和中國一樣皆強調保衛數位主權的重要性。2012年成立負責資訊科技的軍事部門,其職責包括在數位空間保護國家主權。在2013年發布的第72/2013/NĐ-CP號法令中也規範,外國公司在提供越南國民公共資訊時需遵守這些法規。
越南在治理層面受中國影響最深的例子為2018年《資安法》。早在2011年,越南官媒《人民報》就針對中國的防火牆、內容審查等網路治理層面進行分析。該法在法律層面上與中國特色的資安治理法律有高度相似性,舉例來說,越南《資安法》禁止反對政府、煽動暴亂、危害公共秩序等內容。越南與中國皆要求境外科技公司將資料在地化,也規範社交平台的使用者需實名註冊。此外,《資安法》也規範網路使用者有檢舉網路上「危害言論」的義務,科技公司及社群平台也有義務在政府要求時主動提供使用者資訊。
根據 ARTICLE 19 的觀察,《資安法》內部條文用詞不明確且欠缺獨立機構監督,這也導致執法單位可以任意解釋如「危害言論」的意義。
台灣為另類典範
在《中國特色的網路安全》 Cybersecurity with Chinese Characteristics 報告中,ARTICLE 19 提出台灣資安治理經驗為世界國家借鏡。台灣近幾年來無論是國防或是資安都受到了極大的威脅挑戰。中國透過介於戰爭與和平的「灰色地帶戰術」Gray Zone Tactics 不斷展開軍事演習及散佈統戰資訊在台灣社會中。
台灣受到的網路攻擊與日俱增。ARTICLE 19 發現,這些網路威脅最早針對政府機構,現在逐漸分散至產業界。從網路基礎設施的攻擊層面來說,報告中提出了海底纜線的例子。根據台灣審計部2023年中央政府總決算審核報告,當年度海底纜線斷裂次數為12次。於國安局發布的「2024中共網駭手法分析」報告中提到,政府服務網遭騷擾的次數為平均每日240萬次,是2023年次數的兩倍左右。著名的資安攻擊包括了2022年美國時任眾議院議長 Nancy Pelosi 訪台時中國所發動的一系列攻擊。除了大規模的軍事演習,台灣也受到大規模的分散式阻斷服務攻擊 Distributed Denial of Service (DDoS)、不實資訊的騷擾等等。
在治理上,台灣除了要有效應對來自中國的網路干預,同時也須顧慮言論自由及保護隱私權等民主價值。
台灣資安治理的制度、法規化可從2016年開始說起。2016年的《國家資通訊安全發展方案》試圖落實兼具民主核心的治理模式,《國家資通訊安全發展方案》目標強化數位設施、打擊數位犯罪、也強調國際及公私部門間的合作。此方案規範三個政府執行單位,國家通訊傳播委員會 NCC、國家安全會議管轄的資安辦公室、及行政院資通安全處(現為數發部資通安全署,簡稱資安署)。此外,2016年蔡英文總統第二任期上任後,台灣也啟動了「資安即國安 1.0」計畫,更在2021年也啟動第二階段「資安即國安 2.0」,將上述的執行單位及國防、調查、刑事警察等不同部門納入在台灣資安防護的框架中,也著重部門的相互合作。
台灣政府也在法規上強化資安治理的框架。2018年《資通安全管理法》規範了數發部資安署的監管職責。2023年數發部推動《資通安全管理法》的修法,強化政府單位對關鍵基礎設施提供者的問責、監管機制,擴大了稽核範圍。資安署也在本次修法中被要求提供年度稽核計畫,審核的稽核計畫副本也被送至由學者專家等來自非政府部門組成的國家資通安全會報存查。由此可知,台灣的資安治理納入不同利害關係人,也從法律層面規範了所有利害關係人的職責。
數發部的治理策略以言論自由作為首要目標。在治理社群平台上,首任數位部部長唐鳳曾表示,政府僅與社群平台以交換理念為原則進行交流,並非直接介入或強制管控。此外,數位部也積極擴大台灣在全球資安治理的參與,像是由台灣、美國、日本、加拿大及澳洲組成的「全球合作暨訓練架構」,唐鳳在2018年的專題演講中表示,在處理爭議內容時依舊要堅守基本的言論自由。
台灣網路治理
在網路治理中,台灣民間社會的參與是抵禦網路攻擊的重要因子,ARTICLE 19 舉「公共政策網路參與平台」為例子,台灣將公共意見加入到立法過程,是一種兼顧大眾意見及抵禦資安威脅的作法。如上述的《資訊安全管理法》的改革,就是以「公共政策網路參與平台」作為社會大眾與政府之間溝通的橋樑。這個做法實踐在「開放議會」等計畫,讓大眾可參與如議會等國家決策平台。民間團體的參與,像是 MyGoPen 與 CoFacts 等事實查核組織為抵禦來自中國的不實資訊的前線之一。台灣有不同的草根計畫像是課程、培訓、黑客松等計畫使更多人能進一步了解國際資安挑戰,也使資安人才互相交流。
在政策的問責上,民間社會團體扮演著處理人權侵犯疑慮的角色。ARTICLE 19 在報告中提到電子國民身分證的案例,台灣人權促進會警示電子身分證可能有侵犯隱私權的疑慮,於2020年發起連署主張應同時保留現行換發身分證的做法。這獲得許多專家們的支持,電子身分證的換發計畫也宣布暫停。
劉以正說到,台灣以多方利害關係人參與的模式也有不完美之處,因數發部的行政權力有限,數發部推動《資訊安全管理法》時,需以極大的心力說服所有政府部門實踐且協調更全面的網路安全實務。此外,《資訊安全管理法》修正法案目前仍在討論的階段,現任數發部部長黃彥男在今年四月底的備詢中指出,《資訊安全管理法》自2019年實施以來尚未進行修法,而現有部分法條已無法全面回應當前全球的資安危機。
朝野間的溝通、支持,會是使《資訊安全管理法》付諸行動的關鍵。
結論
在訪談最後,兩位專家說到,對抗中國於全世界持續擴大的數位威權,需要所有不同民主社會的團結和支持。除了持續關注數位威權的議題,提供研究單位資源及支持也是一種幫助。對本次訪談內容有興趣的聽眾,可以下載兩個研究成果:
2025:《中國特色的網路安全》(Cybersecurity with Chinese Characteristics)- 探討中國特色的網路治理模式在印尼、巴基斯坦及越南的擴張情況
2024年:《數位絲路:中國與印太地區崛起的數位壓迫》(暫譯)(The Digital Silk Road: China and the rise of Digital Repression in the Indo-Pacific)- 研究由中國主導的「數位絲路」計畫如何助長數位威權於柬埔寨、泰國、尼泊爾及馬來西亞的勢力:(英文版)
Michael Caster (Head of Global China Programme) and I-Chen Liu (Asia Programme Officer) are researchers from the international non-profit organization ARTICLE 19, whose report “Cybersecurity with Chinese Characteristics” (2025) outlines PRC’s influence over cybersecurity norms in 3 Indo-Pacific countries: Indonesia, Pakistan, and Vietnam; and with a Taiwan alternative.
The Digital Silk Road is an umbrella concept that includes policies, priorities, tools, technologies, and tactics of a digital nature under the larger Belt and Road Initiative. Launched in 2015, it’s how PRC promotes its cybersecurity and digital governance norms and technical standards across the world.
It does this through public and private partnerships with Chinese tech companies that provide capacity-building initiatives: 5G cyber security test labs in Malaysia, mobile payment in Thailand, data centers in Nepal, surveillance cameras in Phnom Penh and Kathmandu, submarine cables in Cambodia, and satellite systems for Thailand. While receiving such technology, recipient countries have also adopted PRC-style censorship and regulations into their legal framework. Examples include Vietnam’s 2018 cybersecurity law, which regulates aspects including content moderation and data localization.
The PRC is now pushing for multilateral cooperation through institutions like the UN, ASEAN, and other state-led forums. It has established additional bodies like the Global Security Initiative, Global Development Initiative, and Global Civilization Initiative to further the standardization of PRC-style norms.
The researchers warn of the impact on democracy and freedom of speech this could have on the recipient country. “When China talks about multilateralism, they're doing it as a renouncing multi-stakeholderism approach; Denying civil society, the tech sector, academia, other independent actors. They're denying them a seat at the table”, says Caster.
The PRC-style of digital government becomes a toolkit for the authoritarian actor on how to use cybersecurity laws in the name of promoting safety or national security; but it’s actually introducing potentially humanitarian disaster laws that will impact the right to freedom of expression and the right to privacy.
Notable is the upcoming United Nations Cybercrime Convention in Vietnam, dubbed The Hanoi Convention, which has been rescheduled from July to October, 2025.
The Cybersecurity with Chinese Characteristics report ends with Taiwan’s democratic model of defending cybersecurity, which ensures the participation of civil society, as an alternative model to curb digital authoritarianism.
This report follows “The Digital Silk Road: China and the Rise of Digital Repression in the Indo-Pacific” (2024) which includes case studies from Cambodia, Malaysia, Nepal, and Thailand.
To access this report: https://www.article19.org/resources/china-taiwan-cybersecurity/
Support Ghost Island Media: http://patreon.com/taiwan
Follow and tag us on social media:
Ghost Island Media | Instagram | Facebook | Twitter
Emily Y. Wu | Twitter @emilyywu
A Ghost Island Media production: www.ghostisland.media
Support the show: https://patreon.com/Taiwan
See omnystudio.com/listener for privacy information.
逐字稿
WU: At Article 19, you've been tracking how countries have been adopting China's style and standards of digital authoritarianism. You've analyzed cases of seven countries: Malaysia, Nepal, Thailand, Cambodia, Indonesia, Pakistan, and Vietnam. Before we talk about China's priorities and how they have shifted over the years, can you give us a bird's eye view on how this began?
CASTER: It began really a decade ago with -the sort of formal calling into existence of- the Digital Silk Road, which we argue isn't necessarily best thought of as a distinct foreign policy on its own, but an umbrella concept wrapping together all of the policies, priorities, tools, technologies, tactics of a digital nature under the larger Belt and Road Initiative (BRI).
In 2015, Digital Silk Road was formally established under the BRI, but its first instance came in 2014 when the Ministry of Industry and Information Technology (MIIT) first started calling for raising awareness of the need to take China's digital priorities and activities and efforts in informatization and put it under the BRI.
2014 is really a critical date in understanding a lot of this. Because it's also the year that the State Internet Information Office was rebranded as the Cyberspace Administration of China (CAC), and the first year that China hosted the World Internet Forum in Wuzhen.
So over the last decade, what we've seen is a combination of various state and party institutions like the CAC, the MIIT and others, working together with the erstwhile private sector - like Huawei and ZTE - and a range of other actors from United Front Work (UFWD) organizations, sort of people-to-people exchange. What we've seen is over a decade, China really going through its BRI partnerships, pushing a variety of digital priorities from digital infrastructure development, and with those, have often come the adoption of digital governance norms.
WU: As China helps developing countries build out their digital infrastructure, it's things like internet connectivity, mobile payment, cable networks. These are great technologies that can really benefit citizens on the ground. But what has been the risk for these countries? What does China get in return?
LIU: When China is persuading countries to adopt the Chinese version of digital governance norms, what we are seeing is actually a shift of global norms on digital governance. Before [this], I think the general consensus [had been] that the internet should be stateless, decentralized. But China is introducing a different digital governance norms by cooperation with these countries, by providing them with capacity building initiatives.
These countries may [have needed] to develop their own cyber security defense capabilities [...] But when they turn to China, they're adopting these practices, and eventually also promoting these norms that were different from what we originally pictured of digital governance norms that promote multi-stakeholderism in a more decentralized model.
WU: Is there an example from countries that really illustrate this?
LIU: Indonesia... [...] China provides capacity building to its cyber and crypto agency, State Cyber and Signal Agency (BSSN), and the Ministry of Information and Communication [...] After the 2017 MOU between BSSN, and CNCRT (National Computer Network Emergency Response Technical Team), it emphasized that [...] they will introduce cyber sovereignty in this data security governance. After that, joint trainings, programs, capacity building initiatives started. And a lot of practices are normalizing the PRC version of cyber security governance norms in Indonesia. (Editor's note: CNCRT is China's core coordination organization of the cybersecurity emergency response system)
Huawei plays a crucial role in introducing these norms when they are developing Indonesia's 5G networks. They also help shape Indonesia's cyber incident response and cybersecurity standards. [...] Also, there were concerns about how this may lead to backdoor access and dependence on PRC technologies.
CASTER: Thinking more from guidance from the party or directives from the party in 2020, the Central Committee also issued its opinions on strengthening the United Front work of the private economy in the new era [...] It required them to play a role in United Front work activities, which means promoting not just a positive image of China, but unswervingly following the party to quote, and to promote party priorities and policies in all of their engagements.
It directed them to take a more active role in BRI construction, which includes, Digital Silk Road related – and any number of other cooperations. But what we see from this 2020 document is really an explicit directive from the party to the so-called private sector in all of their engagements in digital cooperations, in developing out the tools and technologies with these countries; with a lens to how is it promoting the party; how is it especially promoting its priorities, which lead to adopting and normalizing its digital governance norms, which are very much away from universal values and principles and things like this.
WU: What was the point you really saw signs that China was ready to elevate from country-to-country bilateral relations to international systems, to the United Nations, to ASEAN?
CASTER: Early on in the documents, guiding opinions, five-year plans, documents that have come out over the last decade of Digital Silk Road activities. Early on, there was identifying China to regional blocks or multilateral bodies.
ASEAN is a critical sort of regional bloc that China has identified as having a strategic priority under this. The Indo-Pacific region. So while obviously pursuing development, cooperation, memorandums of understanding on anything from rolling out 5G to smart cities, a lot of this is done through the regional level. There's a value in that, because if China is engaging with ASEAN as a bloc of 10 member countries, then it seeks to normalize its practices for all 10. Then you scale that out to the global level, right? It's like the old Maoist adage: circling the city from the countryside around it.
What we identify in the latest report and what we argue is not just that multilateralism is a norm of China's digital governance, but what that means is very concerning [...] It means two things.
One is that when China talks about multilateralism, they're doing it as a renouncing multi-stakeholderism approach: denying civil society, the tech sector, academia, independent actors, denying them a seat at the table.
The second is that China's not just talking about working through the existing regional and multilateral bodies to pursue these objectives. They're creating and positioning their own to ultimately supplant those that have existed for decades, or some that go back all the way 80 years to the original post-war international rules based system. Examples of new China-created regional or global multilateral bodies are the Global Security Initiative, the Global Development or Global Civilization Initiatives, or the World Internet Conference.
WU: Later this year in July 2025, the United Nations Cybercrime Convention is expected to be signed. This is a resolution that was sponsored by Russia and backed by regimes like China, Cambodia, Belarus, Iran, Nicaragua, Syria, and Venezuela. How much of a landmark is this? And what should we be looking out for?
CASTER: The first UN General Assembly resolution calling for the creation of this cybercrime treaty goes back to 2019. This current process has been going on for a number of years. Article 19 has put out a number of analyses, and our colleagues and other teams have engaged in the process. We have been clear from the beginning that there's a number of concerning provisions; some have to do with normalizing the retention of user data law enforcement cooperation.
Cyber enabled crimes rather than cyber dependent crimes – which basically means things that can be done on or offline, but there is enhanced sentencing if they're done online – which are used often in countries from Thailand to Pakistan, for example, to further restrict freedom of expression online, and so forth.
There's a number of concerns within the convention itself. The fact that the resolution was first called to a vote by, basically a who's who in terms of Internet freedom predators. The history, the origins of this convention, are quite concerning. The fact also that Vietnam is hosting the signing and that it will presumably henceforth be known as the Hanoi Convention [...] The concern with this convention that's flawed to begin with, being signed now in Vietnam, will not just potentially risk whitewashing Vietnam's record. But because we see China's sort of shadowy influence along a lot of this normative shift, it will then further risk normalizing this approach to cybercrime and cybersecurity that China has been promoting.
So, countries like the United States and some others who begrudgingly perhaps accepted the text as it was last year, they of course did so with certain reservations that look at more human rights safeguards that can then be put into place at a state by state level. But the convention itself is what it is, and we know that globally it's normalizing a certain approach that will not see national level safeguards put into place by the countries that pushed it to be what it is today.
LIU: I think the case of Vietnam shows that China's influence is not only in the economic sectors and investments, but also influencing countries' legal frameworks and how they govern their own digital sphere and cybersecurity. In Vietnam's 2018 cybersecurity law, the legislation and legal frameworks a lot of times are very similar to the cybersecurity laws in the PRC. The influence of that can actually trace back to 2011, where an article was published in the Vietnamese newspaper where it analyzed the PRC laws and regulations on content moderation, real name registration, and also the use of firewalls in Vietnam.
A lot of the studies and research were already done from Vietnam, and also they can incorporate PRC's legal framework, which led to the controversial legislation of the 2018 cybersecurity law. In these cybersecurity laws, we see that not only in the murals, China cybersecurity laws requiring data localization, real name registration, and also providing governance on some kind of backdoor access for the user data. It encourages the provisions to combat anti-state speech, which may also lead to a stronger censorship and also other problematic human rights issues. [...]
WU: You mentioned real name registration when it comes to internet use. Do you look at how China continues to update those laws versus how it's being adopted abroad to make comparisons and recommendations?
CASTER: 2017 cybersecurity law in China placed the legal requirements for real name registration that were drawing on some previous guidelines. A few years after the cybersecurity law in China, the Ministry of Industry and Information Technology (MIIT) put out its guidelines on VPN registration, basically creating a whitelist of accepted VPNs. Some people have been imprisoned for up to five years for distributing VPNs that were not part of this whitelist. More recently – cut forward to just last year – the Cyberspace Administration of China (CAC) put forward draft guidelines. One of the newest would require a national internet ID.
We do see this as one of the normative shifts. The approach to digital governance that China has pushed is this effort to require identity verification at every step of possible online activity, which makes it almost impossible to have online anonymity. In a report a few years ago, the former Special Rapporteur on Freedom of Expression, David Kaye, was quite explicit that the right to freedom of expression is intrinsically linked to the ability to be secure and safe online. At times that requires anonymity or protection of article 17 of the International Covenant on Civil and Political Rights: Protection for the Right to Privacy.
This approach, it’s a chipping away of your right to privacy, it's supercharged surveillance, and it obviously disincentivizes people from expressing themselves or gaining information freely [...]
But it's not just happening in China. Through its cooperation agreements, its efforts to promote "best practices," which is a code for China's practices in these partnerships, we again see emulation of all of these types of things taking place. Just in our latest report, Cybersecurity with Chinese Characteristics, two of the country case studies we look at, Vietnam and Pakistan, we've seen a number of these same policies and requirements being put into force.
Vietnam has required through a few decrees under its cybersecurity law, the same type of requirement for real name registration. The Pakistan Telecommunications Authority has also, just as of last year, really been calling for an approach to whitelisting VPNs in the same way that we've seen from the MIIT in China.
We see this in a number of other places. For example, with the White Paper Protests in November two years ago, one of the ways that people were spreading information, promoting the protests, was through a feature in Apple AirDrop. It allowed people to quite freely share information in their close vicinity. To close this hole that was available for evading censorship in China, China put out policies requiring that particular type of protocol for AirDrop would require identity verification, contact listing, more ephemeral messaging.
So they put out a number of policies, but again, one of them relates directly to this issue about real name identity verification and requirements. Apple later rolled out some similar changes, which it was criticized for doing potentially in pressure from China. [...]
WU: If China's leading the charge in digital authoritarianism, who is leading the charge on the other side? What is the state of the internet divide going forward? In your report, I-Chen, you had a section on using Taiwan's case studies.
LIU: While China is framing the big needs for national security, Taiwan also suffers a very real national security threat, and a lot of threats in the cybersecurity governance. Taiwan is one of the most targeted countries for cyber attacks. According to the National Security Bureau, Taiwan suffers 2.4 million attacks per day targeting government agencies. So that's a lot of cyber attacks.
WU: 2.4 million a day. 2.4 million attacks?
LIU: 2.4 million attacks per day. Yeah.
I think that's double the number from a year before, so they have also upscaled their cyber attacks. Taiwan has been the country that’s most affected by disinformation, according to V-Dem (Varieties of Democracy) Institute. Not to mention, gray-zone tactics from cyber operations and the different disinformation influence campaigns. The newest trend is the attacks on the physical layer, where our undersea cables will be cut multiple times throughout the year. So the threat is very real for Taiwan.
But under these circumstances, Taiwan still develops its own cybersecurity governance norms that try to balance the threat and also the commitments to human rights.
The Cybersecurity Management Act was set as a cornerstone. When Taiwan was developing these legal frameworks and making amendments to fit the newest trends of cyber attacks, we see that public consultation is applied. When Cybersecurity Management Act is making new amendments, these amendments are put online on the Public Policy Participation Platform, which is a website for people to comment and respond. People would question whether amendments have too many audits or too little intelligence sharing. We do see that government officials, civil society, and people from the tech sectors will interact in online public consultation platforms. They will exchange ideas on how to balance concerns of human rights, public accountability, transparency, and how Taiwan should develop its own cybersecurity capabilities.
We're not trying to frame Taiwan as a perfect example. It’s a continual struggle to balance between national security and also human rights.
WU: What sense do you get of Taiwan's participation in the global cybersecurity discussions that are countering China's style? If China's leading this initiative, and they have signed agreements and partnerships with close to 100 countries, how should we be paying attention to this space to see that there is a counter on the global stage to China's dominance?
CASTER: One of our prevailing recommendations is for Taiwan to play a more engaged role in international internet and broader digital governance; which is not necessarily an easy thing to say. Because of course, through coordinated political, economic sharp power and other influence campaigns and threats from China, Taiwan has been intentionally isolated and sidelined in the global governance space.
Obviously, to say that Taiwan should be playing a more active role is challenging to follow through on. But certainly, things like the UN Internet Governance Forum taking place explores opportunities to ensure that representatives from Taiwan can join into these critical conversations. That's happening later this year in Norway, for example. Last year it was in Saudi Arabia. So the global digital rights community largely boycotted the proceedings. The year before that it was in Japan. Unlike some previous years, the Japanese government and local organizers did make some concessions to allow for participants from Taiwan to join. This is one forum. Certainly, there's a number of other places where this is taking place.
What we would like to see is greater inclusion at the regional and at the global level. It's not just the Taiwanese government, but Taiwanese civil society [...] I think certainly this is one place where there is a large gap in terms of the knowledge, the experience, the expertise that can be brought into global conversations that just isn't happening [...]
In terms of who's leading the charge - unfortunately, to engage in such a massive mission of both digital infrastructure development and the promotion of governance norms - requires vast amounts of resources that require a state to have the political will behind allocating necessary resources and participation, and adherence to universal values and international norms. Previously, the United States was putting effort into cybersecurity and other infrastructure development. Unfortunately, those efforts were already inadequate to properly combat China's influence in this space. Now most recently, because a lot of those efforts were actually overseen by and funded by the US Agency for International Development, USAID, the slashing of their budget will have a negative impact on the US role in a lot of the efforts to counteract what China's doing, from the infrastructure to the governance space.
The European Union has a Global Gateway initiative, which is firstly promoted as sort of a European values driven counter to the Belt and Road Initiative, but has digital components in it as well. This is one place where we would like to see greater attention placed on ensuring that the human rights based digital governance norms are mainstreamed in the other digital infrastructure and other infrastructure cooperation that the EU has through the Global Gateway Initiative.
Japan is a major development partner, not just in the Indo-Pacific but around the world. Traditionally, they have been very quiet. They haven't been as self-promoting as China has; which again is because development is very much part of China's soft power projections and narrative and information operations. So while Japan has in some cases actually invested more money in development around the Indo-Pacific, the awareness of that level of support isn't necessarily there. But in recent times, the Japanese development strategies have also shifted to more support for digital-related development cooperations. Then also, with certain companies that might be the ones engaged in, say, 5G rollout like Ericsson from Sweden and others, as well as ensuring that multi-stakeholder approach is there.
This is not just a matter of marshaling high budgets from states. We also need to ensure that civil society, academia, other independent actors, certainly journalists, have a critical role, not just in ensuring that there's transparency around procurements, or sites of satellite base stations, or fiber optic landing stations. All of this on the ground.
In Taiwan, we talk about the whole of society approach. But really, in terms of the global resistance to ensuring that human rights are maintained, that internet freedom principles are maintained, we also need a global, whole of society approach. Because certainly, the assault championed by China is systematic and coherent and strategic, attacking at all sorts of pillars, and so we need to be equally strategic in our response.
WU: What can we look out for next from Article 19?
CASTER: We do have a report forthcoming on transnational repression. We're looking at, in particular, China's acts of transnational repression against protesters around the world. We have case studies in 11 countries or so in Asia, North America, and Europe, looking at Hong Kong or Uyghur, Tibetan, other diaspora communities protesting around Chinese state visits outside of embassies and consulates, forms of digital transnational repression against protesters, as well as some of the psychosocial impact that comes with that.
This report is forthcoming, so we're excited about that. We're also doing a bit more building out some work in terms of lessons learned in Taiwan from FIMI in Taiwan, and then linkages with some of the lessons learned from Ukrainian civil society and being targeted by Russian FIMI.
LIU: We are starting a project to bridge Ukrainian expertise and Taiwanese civil expertise countering FIMI. Since Ukrainians are the people that know Russian FIMI the best, and Taiwanese may be the people who knows PRC FIMI the best, I think it's great that we have an opportunity to bridge these two groups and combine forces on learning not only how Russia and China is having a convergence in terms of information operations, but also exchange skillsets and provide capacity building initiatives providing better opportunities for the civil societies on both sides. As the conflict in Ukraine continues, I believe a lot of Taiwanese will still have the urge to learn from Ukraine, but also to help Ukrainians in their circumstances.
Episode Credits: Producer and host, Emily Y. Wu. Research and writing, Zack Chiang. Video and audio editing, Wayne Tsai. Transcription, Charis Hayward.

主持人 - 吳怡慈
主持人 - 吳怡慈
吳怡慈是鬼島之音監製,她於2019年創立鬼島之音獨立媒體討論社會議題並促進跨國文化交流。她主持的 PODCASTS 節目包括 The Taiwan Take、Metalhead Politics,以及 Game Changers with Emily Y. Wu 電視節目。吳怡慈曾在台灣公共電視及香港商壹傳媒集團服務。
