- Head's 'good night at office' after century seals win over England
- Dubois seeks legitimacy with Joshua scalp
- Rate cut could lift consumer spirits before US elections
- Last-gasp Gimenez strike sends Atletico past Leipzig
- Barca stumble at Monaco after early red card
- Raya heroics save Arsenal in Champions League opener at Atalanta
- Cathay Airbus engine fire linked to cleaning: EU regulator
- Guardians beat Twins to secure MLB playoff berth
- Jihadist attack in Mali capital killed more than 70: security sources
- Alonso hails 'efficient' Leverkusen after Feyenoord rout
- Head's hundred seals Australia win over England in 1st ODI
- Ex-Man United striker Anthony Martial joins AEK Athens
- NFL unbeatens meet as Texans visit Vikings, Steelers host Chargers
- Head's hundred seals Australia win over England in 1st ODI after Labuschagne strikes
- Dream debut for Wirtz as Leverkusen thump dire Feyenoord
- Myanmar flood death toll climbs to 293: state media
- Israel army says West Bank air strike kills 4 militants
- LIV golfers get green light for US Ryder Cup team, PGA Championship
- US accuses social media giants of 'vast surveillance'
- Ten Hag to bed Hojlund, Mount in carefully when they return for Man Utd
- Breaking bad as McIlroy endures 'weird' day
- EU chief announces $11 bn for nations hit by 'heartbreaking' floods
- Spanish PM, Palestinian leader urge Mideast de-escalation
- New study reinforces theory Covid emerged at Chinese market
- World Bank boosts climate financing by 10 percent
- Bagnaia eyeing summit on home ground in 100th MotoGP
- 'Something was wrong', defendant in French mass rape tells court
- Hezbollah chief admits 'unprecedented' blow in device blasts
- Sales of US existing homes slip slightly in August
- Fear, panic haunt Lebanese after devices explode
- Labuschagne sparks Australia fightback in England ODI opener
- S.Africa's HIV research power couple says fight goes on
- Why is Israel focusing on border with Lebanon?
- Mpox vaccines administered in Rwanda, first in Africa
- US Fed rate cut is 'very positive sign' for economy: Yellen
- Unknown Mozart string trio discovered in Germany
- 'Are we five-year-olds?' F1 drivers won't mind their language
- Brazil judge orders X to reimpose block or face hefty fine
- Munich to rename stadium street after Beckenbauer
- Champions Italy to face Argentina in Davis Cup Final 8
- The winding, fitful path to weight loss drug Ozempic
- Italians defeat American Magic to reach Louis Vuitton Cup final
- Norris has 'nothing to lose' as he hunts Verstappen in Singapore
- Kyiv 'outraged' at Swiss showing of Russian war film
- French city renames Abbe Pierre square after abuse claims
- Footballer charged after huge cannabis seizure at UK airport
- Vatican recognises Medjugorje shrine, but not Virgin's messages
- Israel bombs Hezbollah strongholds in Lebanon after wave of deadly blasts
- Bank of England freezes rate after jumbo US cut
- Playing Nadal is 'kind of a nightmare', says Alcaraz
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
T.Bondarenko--BTB