
-
The 'new silent ones': Opponents lie low in Russia
-
'Beyond a game' as Pakistan face India in must-win blockbuster
-
Hong Kong and Singapore lead Asia's drive to cash in on crypto boom
-
Well-off Hong Kong daunted by record deficits
-
Trump tariffs shake up China's factory heartland
-
Germany may face long wait for new government after vote
-
Taiwan players go nuclear in Chinese invasion board game
-
Attacks, 'firewall' row, Trump: rocky run-up to German vote
-
AI opens 'endless' doors for fashion models, closes others
-
Top issues in Germany's election campaign
-
Alice Weidel, unlikely queen of German far-right AfD
-
Big turnout expected for Beirut funeral of slain Hezbollah leader
-
Friedrich Merz: conservative on verge of German chancellery
-
Messi and Miami held by New York City in MLS opener
-
Cheat sheet on Germany's colour-coded politics
-
Germans go to vote under shadow of far-right surge, Trump
-
US pipeline case heads to court in high-stakes free speech fight
-
Trump shakes transatlantic alliance with Russia pivot
-
Force coach Cron hails 'fight' as records tumble in Canberra
-
Oscars favorite Baker says indie film 'struggling' as 'Anora' tops Spirit Awards
-
Israel delays Palestinians' release after six Gaza hostages freed
-
Trump biopic director apologizes after actor's groping accusation
-
Bivol takes Beterbiev's light-heavyweight crown in Riyadh classic
-
Potgieter's lead shrinks to one shot at PGA Mexico Open lead
-
Argentina's Milei praises Trump plan for reciprocal tariffs
-
Holloway, Russell cruise to hurdles wins at US indoor championships
-
Barca battle to keep Liga lead as Atletico apply pressure
-
Barcelona claim narrow win at Las Palmas to reclaim Liga lead
-
Martinez fires Inter top of Serie A as Milan fall at Torino
-
Itoje glad of England's 'hair-raising' win over Scotland
-
'Worst is over' as Chile's 'stolen' babies reunite with mothers
-
Trump says US wants return on Ukraine aid money
-
England-born Inglis relishes 'special' century for Australia
-
Pussy Riot stages pre-election Berlin show for Ukraine
-
Leverkusen ease to victory at Kiel to trim Bayern lead
-
'Now it's over' says Hermoso after Rubiales found guilty
-
Germany on eve of vote expected to see far-right surge
-
Spurs revitalised after Ipswich rout: Postecoglou
-
Russell misses prove costly as England edge Scotland in Six Nations
-
Milei says welcomes Trump plan for reciprocal tariffs
-
Premier League title out of Arsenal's control, says 'angry' Arteta
-
Asensio double punishes Jorgensen howler as Villa beat Chelsea
-
Lille deepen Monaco's woes
-
Alvarez double takes Atletico top with Valencia win
-
Norwegian film 'Dreams', Australia's Rose Byrne win at Berlin
-
French star Jaminet returns after ban for 'stupid' racism
-
England edge Scotland in Six Nations thriller
-
England edge Scotland 16-15 in Six Nations thriller
-
Israel stalls Palestinians' release after six Gaza hostages freed
-
Pope suffers respiratory attack, condition critical: Vatican

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
S.Gregor--AMWN