- Palestinians welcome ICC arrest warrants for Israeli officials
- Senegal ruling party wins parliamentary majority: provisional results
- Fiji's Loganimasi in for banned Radradra against Ireland
- New proposal awaited in Baku on climate finance deal
- Brazil police urge Bolsonaro's indictment for 2022 'coup' plot
- NFL issues security alert to teams about home burglaries
- Common water disinfectant creates potentially toxic byproduct: study
- Chimps are upping their tool game, says study
- US actor Smollett's conviction for staged attack overturned
- Fears rise of gender setbacks in global climate battle
- 'World's best coach' Gatland 'won't leave Wales' - Howley
- Indian PM Modi highlights interest in Guyana's oil
- Israel strikes kill 22 in Lebanon as Hezbollah targets south Israel
- Argentina lead Davis Cup holders Italy
- West Bank city buries three Palestinians killed in Israeli raids
- Fairuz, musical icon of war-torn Lebanon, turns 90
- Jones says Scotland need to beat Australia 'to be taken seriously'
- Stock markets push higher but Ukraine tensions urge caution
- IMF sees 'limited' impact of floods on Spain GDP growth
- Fresh Iran censure looms large over UN nuclear meeting
- Volkswagen workers head towards strikes from December
- 'More cautious' Dupont covers up in heavy Parisian snow before Argentina Test
- UK sanctions Angola's Isabel dos Santos in graft crackdown
- Sales of existing US homes rise in October
- Crunch time: What still needs to be hammered out at COP29?
- Minister among 12 held over Serbia station collapse
- Spurs boss Postecoglou hails 'outstanding' Bentancur despite Son slur
- South Sudan rejects 'malicious' report on Kiir family businesses
- Kyiv claims 'crazy' Russia fired nuke-capable missile
- Australia defeat USA to reach Davis Cup semis
- Spain holds 1st talks with Palestinian govt since recognising state
- Stock markets waver as Nvidia, Ukraine tensions urge caution
- Returning Vonn targets St Moritz World Cup races
- Ramos nears PSG return as Sampaoli makes Rennes bow
- Farrell hands Prendergast first Ireland start for Fiji Test
- Gaza strikes kill dozens as ICC issues Netanyahu arrest warrant
- Famed Berlin theatre says cuts will sink it
- Stuttgart's Undav set to miss rest of year with hamstring injury
- Cane, Perenara to make All Blacks farewells against Italy
- Kenya scraps Adani deals as Ruto attempts to reset presidency
- French YouTuber takes on manga after conquering Everest
- Special reunion in store for France's Flament against 'hot-blooded' Argentina
- 'World of Warcraft' still going strong as it celebrates 20 years
- Fritz pulls USA level with Australia in Davis Cup quarters
- New Iran censure looms large over UN nuclear meeting
- The first 'zoomed-in' image of a star outside our galaxy
- ICC issues arrest warrants for Netanyahu, Gallant, Deif
- Minister among 11 held over Serbia station collapse
- Historic gold regalia returned to Ghana's king
- Kyiv accuses Russia of launching intercontinental ballistic missile attack
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
T.Bondarenko--BTB