
-
Shai outguns Jokic with 40pts as Thunder roll past Nuggets
-
Swiatek crushes Yastremska in pursuit of Indian Wells three-peat
-
England's Lawrence out of Six Nations finale with Achilles injury
-
Real Madrid capitalise as Atletico stumble in Liga title race
-
Syria vows accountability after reports of mass killings
-
Arsenal title bid fades after Man Utd draw as Chelsea go fourth
-
Arsenal held by Man Utd in latest blow to Premier League title bid
-
India's Rohit says 'not retiring' from ODIs
-
Lakers star LeBron James to miss one to two weeks - report
-
After Poland spat, Musk vows Ukraine can keep Starlink
-
'You think football is just PlayStation?': Maresca defends Chelsea
-
Black comedy from award-winning 'Parasite' director tops N.America box office
-
Seventh heaven for Ingebrigtsen as Mahuchikh and Bol also shine at Euro indoors
-
Spurs must show fighting spirit against Alkmaar: Postecoglou
-
Syria announces probe after reports of mass killings
-
EU chief sees US as 'allies' despite 'differences'
-
Street celebrations after India win Champions Trophy final
-
Israel halts Gaza electricity supply ahead of new truce talks
-
Mbappe, Vinicius help Real Madrid shade Rayo Vallecano
-
Napoli refresh title hopes with win over Fiorentina
-
Canada Liberal Party to choose new leader to replace Trudeau as PM
-
England maintain Six Nations title hopes with Italy win
-
Rohit and stingy spin attack lead India to Champions Trophy title
-
Ingebrigtsen wins 3,000m for third Euro indoor double gold
-
South Africa's taboo-breaking playwright Athol Fugard
-
Chelsea go fourth as Spurs salvage Bournemouth draw
-
Syria security forces disperse rival protests in Damascus
-
Rubio heads to Saudi Arabia to gauge if Ukraine has shifted
-
Trump declines to rule out 2025 US recession
-
Tim Merlier sprints to victory in Paris-Nice first stage
-
Getafe stun Atletico with Arambarri double
-
French research groups urged to welcome scientists fleeing US
-
US envoy says Gaza hostage deal possible 'within weeks'
-
Journalist quits broadcaster after comparing French actions in Algeria to Nazi massacre
-
'New challenge' for Dupont after announcing torn knee ligaments
-
Russia claims counter-offensive into Ukraine's Sumy region
-
Casteels retires from Belgium duty over Courtois return
-
First World Cup win for Truppe in Are as Shiffrin breaks another record
-
New Zealand reach 251-7 against India in Champions Trophy final
-
Highlights from Paris Women's Fashion Week
-
Paris claims super-G in Kvitfjell as Odermatt edges closer to title
-
Israeli air strike in Gaza ahead of new talks on truce with Hamas
-
Ailing pope thanks doctors as condition improves
-
Dominik Paris claims the super-G in Kvitfjell
-
Japan's Takeda equals course record in dominant China LPGA win
-
US ends waiver for Iraq to buy Iranian electricity
-
China-US trade war heats up with Beijing's tariffs to take effect
-
Garcia sends Ryder Cup message to captain Donald with LIV victory
-
Israel to send team to Doha as Hamas pushes for phase two of Gaza truce
-
Art lovers mob Paris's Pompidou Centre ahead of five-year closure

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
T.Bondarenko--BTB