- Cash-keen Taliban betting on Afghanistan's mines
- Seeking light in dark times four years after Myanmar coup
- Autos, electronics: What will Trump's tariffs impact?
- Three things we learned in the Six Nations
- Russia and Ukraine trade blame for attack on Kursk school
- For world's poorest, fears for long-term setbacks after Trump aid cut
- Chappell Roan: the splashy pop supernova
- Has Trump changed tack on Venezuela?
- Trump unveils sweeping US tariffs on Canada, Mexico, China
- McIlroy and Lowry charge at Pebble Beach but Straka leads
- Russian attacks on Ukraine kill 15
- Japan beat Britain in Davis Cup as Danish rally stops Serbia
- US unveils sweeping tariffs on Canada, Mexico, China
- Kim holds on to lead at LPGA season-opener
- Thousands of Argentines march in defense of diversity
- Real Madrid fall at Espanyol as Atletico cut Liga gap
- Ex-Charlie Hebdo artist wins top prize at comics festival
- At least 56 killed as fighting grips Sudan's capital
- Russian attacks on Ukraine kill 14
- Netanyahu to begin talks on 2nd phase of Gaza truce
- Doris proud as faltering champions Ireland beat England in Six Nations opener
- Swiss Britschgi wins European figure skating gold
- Trump tariff deadline looms, Canada told levies coming Tuesday
- Russian attacks on Ukraine kill 13
- US Democrats anoint new leader to take on Trump for 'working people'
- Atletico beat Mallorca to stay on Real Madrid's tail
- Ireland start Six Nations title defence with gritty England win
- Ireland start Six Nations title defence with England win
- Serbia protesters mark three months since deadly roof collapse
- Japan beat Britain in Davis Cup as Serbia lose to Denmark
- Egypt's Sisi tells Trump world 'counting on' him for Middle East peace
- Pakistan separatist militants kill 18 paramilitaries in ambush
- In-form Dembele hits hat-trick again as PSG thump Brest
- At least 56 killed as fighting grips greater Khartoum
- Toll rises to 7 dead, 19 hurt in Philadelphia plane crash
- Scots held nerve to beat Italy, says satisfied Townsend
- Salah takes Liverpool nine clear, Forest hit Brighton for seven
- Serbia protesters mark three-months since roof collapse with mass rally
- Bayern survive late Kiel fightback to go nine points clear
- Salah's controversial penalty fires Liverpool nine points clear
- Russia fires deadly barrage on Ukraine as it presses on key city
- Jones hat-trick secures Scots opening Six Nations win over Italy
- Trump tariff deadline looms over Canada, Mexico, China trade
- Hamas and Israel complete fourth Gaza ceasefire swap
- Ex-England coach Lancaster leaves Racing 92
- Wood hits hat-trick as flying Forest thrash Brighton 7-0
- Horst Koehler, German ex-president and IMF chief, dead at 81
- DR Congo conflict risks broader regional war, Burundi warns
- Britain's Tom Pidcock wins Al-Ula Tour
- Man Utd's Rashford close to Aston Villa loan: reports
CMSC | -0.89% | 23.47 | $ | |
RIO | -0.83% | 60.41 | $ | |
NGG | -0.55% | 61.4 | $ | |
GSK | -0.26% | 35.27 | $ | |
AZN | -0.68% | 70.76 | $ | |
CMSD | -1.59% | 23.84 | $ | |
BTI | -0.1% | 39.64 | $ | |
BCC | -1.98% | 126.16 | $ | |
BCE | -0.46% | 23.79 | $ | |
RYCEF | -0.81% | 7.43 | $ | |
BP | -1.77% | 31.06 | $ | |
SCS | -1.39% | 11.48 | $ | |
RBGPF | 100% | 67.27 | $ | |
RELX | -0.92% | 49.89 | $ | |
VOD | -0.82% | 8.54 | $ | |
JRI | -0.32% | 12.53 | $ |
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
T.Bondarenko--BTB