- EU's top diplomat backs Trump call to boost defence spending
- Simmering anger as Turkey begins burying 76 fire victims
- Masa Son, Trump's Japanese buddy with the Midas Touch
- Borussia Dortmund sack Sahin after Champions League setback
- US govt workers in diversity jobs to be put on leave as programs ordered shut
- Shelton grinds past Sonego into Australian Open semi-final
- Borussia Dortmund sack coach Nuri Sahin after Champions League setback
- Markets rise after Trump AI pledge but China tariff fears return
- 'Did not push hard enough': Navalny lawyer speaks of regrets
- Bulgaria court ruling turns spotlight on gambling addiction
- Inoue focused on Korean with bright lights of Vegas on horizon
- Mauricio Funes: journalist turned El Salvador president
- Navarro urges rule change after double-bounce furore in Melbourne
- Asian traders cheer Trump AI pledge but China tariff woes return
- Lesotho's king pitches green energy to Davos elites
- Buttler rejects calls for England to boycott Afghanistan match
- 'I believe': Swiatek surges into Australian Open semi with Keys
- Indonesia rescuers search for survivors as landslide kills 19
- Triple-doubles for Jokic and James fuel lopsided NBA wins
- Five things about the 2025 World Rally Championship
- 'Love for humanity': Low-crime Japan's unpaid parole officers
- Indonesia rescuers search for survivors as landslide kills at least 17
- Trump targets opponents, faces criticism from cathedral pulpit
- S. Korea to overhaul some airports after Jeju Air crash
- Resilient Keys 'really proud' to be back in Melbourne semis
- Bloodied Welsford fights back from crash to win another Tour stage
- Swiatek sweeps into Melbourne semis, Sinner faces home test
- Rampant Swiatek sweeps into Australian Open semi-final with Keys
- Lanterns light up southern Chinese city ahead of Lunar New Year
- 'Worst ever' Man Utd turn to Europa League as saving grace
- Brazil saw 79% jump in area burned by fires in 2024: monitor
- Resilient Keys beats Svitolina to reach Australian Open semi-finals
- Most Asian markets rise after Trump AI pledge but China tariff woes return
- Djokovic mentally ready for Zverev but worried about creaking body
- As Trump takes aim at EVs, how far will rollback go?
- No home, no insurance: The double hit from Los Angeles fires
- Trump targets opponents, faces criticism from catherdral pulpit
- Ichiro becomes first Japanese player elected to MLB Hall of Fame
- Relentless Swiatek, dizzy Sinner eye Australian Open semi-finals
- Colombian forces edge into guerrilla strongholds
- Netflix reports surge in subscribers, new price hikes
- Panama complains to UN over Trump canal threat, starts audit
- Rubio, on first day, warns China with Asian partners
- Ichiro, the Japanese Hall of Famer who helped redefine baseball
- Ichiro becomes first Japanese elected to MLB Hall of Fame
- CORRECTION - Pantheon Resources PLC Announces Preliminary Log, Core and Cuttings Analysis
- Borussia Dortmund and Nuri Sahin End Their Collaboration
- ZeroPath Corp. Launches Next-Generation Code Security Platform Powered by Artificial Intelligence
- Guardian Metal Resources PLC Announces Presidential Executive Order
- Cashmere Valley Bank Reports Annual Earnings of $28.2 Million and Increases Semi-Annual Dividend
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
S.Gregor--AMWN