- Australian tennis star Purcell provisionally suspended for doping
- Asian markets track Wall St rally as US inflation eases rate fears
- Luxury Western goods line Russian stores, three years into sanctions
- Wallace and Gromit return with comic warning about AI dystopia
- Philippine military says will acquire US Typhon missile system
- Afghan bread, the humble centrepiece of every meal
- Honda and Nissan expected to begin merger talks
- 'Draconian' Vietnam internet law heightens free speech fears
- Israeli women mobilise against ultra-Orthodox military exemptions
- Asian markets track Wall St rally as US inflation eases rate worries
- Tens of thousands protest in Serbian capital over fatal train station accident
- Trump vows to 'stop transgender lunacy' as a top priority
- Daniels throws five TDs as Commanders down Eagles, Lions and Vikings win
- 'Who's next?': Misinformation and online threats after US CEO slaying
- Only 12 trucks delivered food, water in North Gaza Governorate since October: Oxfam
- InterContinental Hotels Group PLC Announces Transaction in Own Shares - December 23
- Melrose Group Publicly Files Complaint to the Ontario Securities Commission
- Langers edge Tiger and son Charlie in PNC Championship playoff
- Explosive batsman Jacobs gets New Zealand call-up for Sri Lanka series
- Holders PSG edge through on penalties in French Cup
- Slovak PM Fico on surprise visit to Kremlin to talk gas deliveries
- Daniels throw five TDs as Commanders down Eagles
- Atalanta fight back to take top spot in Serie A, Roma hit five
- Mancini admits regrets over leaving Italy for Saudi Arabia
- Run machine Ayub shines as Pakistan sweep South Africa
- Slovak PM Fico on surprise visit to Kremlin
- Gaza rescuers say Israeli strikes kill 35
- 'Incredible' Liverpool must stay focused: Slot
- Maresca 'absolutely happy' as title-chasing Chelsea drop points in Everton draw
- Salah happy wherever career ends after inspiring Liverpool rout
- Three and easy as Dortmund move into Bundesliga top six
- Liverpool hit Spurs for six, Man Utd embarrassed by Bournemouth
- Netanyahu vows to act with 'force, determination' against Yemen's Huthis
- Mbappe back from 'bottom' as Real Madrid down Sevilla
- Ali hat-trick helps champions Ahly crush Belouizdad
- France kept on tenterhooks over new government
- Salah stars as rampant Liverpool hit Spurs for six
- Syria's new leader says all weapons to come under 'state control'
- 'Sonic 3' zips to top of N.America box office
- Rome's Trevi Fountain reopens to limited crowds
- Mbappe strikes as Real Madrid down Sevilla
- 'Nervous' Man Utd humiliated by Bournemouth
- Pope again condemns 'cruelty' of Israeli strikes on Gaza
- Lonely this Christmas: Vendee skippers in low-key celebrations on high seas
- Troubled Man Utd humiliated by Bournemouth
- 2 US pilots shot down over Red Sea in 'friendly fire' incident: military
- Man Utd embarrassed by Bournemouth, Chelsea held at Everton
- France awaits fourth government of the year
- Germany pledges security inquest into Christmas market attack
- Death toll in Brazil bus crash rises to 41
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
S.Gregor--AMWN