-
Digital G7 reaches limited deal on child protection, AI energy impact
-
Lula blasts US for labelling Brazil crime factions as terrorists
-
Sooryavanshi's 96 in vain as Gujarat down Rajasthan to reach final
-
Colombian army looks to outsmart guerrillas with drone warfare
-
Trump says making final decision on Iran deal
-
'Age doesn't matter' says veteran Curacao boss Advocaat
-
Unrest outside US immigration detention center, 9 arrested
-
Chancellor swap? Rumours swirl about German leader Merz's future
-
Arteta urges Arsenal to 'own' Champions League final
-
British naked chalk giant gets spruced up
-
Trump mocks Jill Biden over debate 'stroke' claim
-
French Open to fine Vallejo for criticising woman umpire
-
Deschamps guards against World Cup over-confidence
-
Trump says now making 'final determination' on Iran deal
-
Poison? More artists flee Trump's US anniversary concerts
-
Vingegaard nears Giro triumph as teammate Kuss takes stage 19
-
Oil falls, stocks mixed on US-Iran truce prospects
-
Trump says making final decision on proposed Iran deal
-
PSG, Arsenal final has no favourite: Luis Enrique
-
PSG more 'hungry' for Champions League after first taste of glory
-
'I'm afraid for my life': Romanians in shock after drone crash
-
PSG still 'hungry' for Champions League glory: Dembele
-
Iran says no trust in US 'words', waiting for Washington to act
-
Swiatek advances at French Open as Djokovic faces Fonseca
-
Photo and video journalists in Gaza to receive 'Golden Pen' award
-
Trees taking drastic measures to survive climate-driven heat
-
Andreeva sweeps into last 16 at French Open
-
McCullum urges England to 'box smart' like New Zealand
-
Oil falls further, stocks mixed on US-Iran truce prospects
-
France rugby star Drean to have heart surgery
-
Narvaez drops out of Giro d'Italia, points jersey bid over
-
Anti-Israel tennis ball protest disrupts Ireland-Qatar football tie
-
Swiatek qualifies for French Open last 16
-
Vance says progress made as US-Iran deal awaits Trump green light
-
France defender Konate set to leave Liverpool: reports
-
German ex-minister faces perjury charges over failed car toll plan
-
Kanye West cleared to play in Netherlands
-
Loyalty could be fatal to Argentina's World Cup title defence, says Bertoni
-
Stocks rise, oil eases on hopes of US-Iran truce deal
-
Polka-dots and hypnotic riffs fuel viral duo Angine de Poitrine
-
NATO, EU outrage as drone hits Romania apartment block
-
French GDP slips 0.1% in first quarter, raising spectre of recession
-
WHO chief in capital of Ebola-hit DR Congo
-
Azmoun: Iran's absent talisman unafraid of controversy
-
PNG leader says no foreign bases as Australia's defence presence grows
-
Russian drone hits Romania apartment block, drawing NATO, EU outrage
-
Migrants try to flee to Bangladesh fearing India crackdown
-
Digital G7 discusses online child protection
-
'If Ebola comes, we'll be wiped out': DR Congo conflict-displaced
-
'Biggest circus in town' the World Cup set for betting frenzy
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
T.Bondarenko--BTB