
-
Israel says expands Gaza offensive to seize 'large areas'
-
Curry drops 52 as Warriors win, Jokic bags career-high 61 in Denver loss
-
South Korea mobilising 'all resources' for violence-free Yoon verdict
-
Myanmar quake victim rescued after 5 days as aid calls grow
-
Real Madrid coach Ancelotti tax fraud trial set to begin
-
Warner showcases 'Superman' reboot, new DiCaprio film
-
'Incredible' Curry scores 52 as Warriors down Grizzlies, Bucks edge Suns
-
Asian markets edge up but uncertainty rules ahead of Trump tariffs
-
Nintendo's megahit Switch console: what to know
-
Nintendo to unveil upgrade to best-selling Switch console
-
China practises hitting key ports, energy sites in Taiwan drills
-
Oil, sand and speed: Saudi gearheads take on towering dunes
-
All eyes on Tsunoda at Japan GP after ruthless Red Bull move
-
'Image whisperers' bring vision to the blind at Red Cross museum
-
Hay shines as New Zealand make 292-8 in Pakistan ODI
-
Other governments 'weaponising' Trump language to attack NGOs: rights groups
-
UK imposes online entry permit on European visitors
-
How a Brazilian chief is staving off Amazon destruction
-
Meme politics: White House embraces aggressive alt-right online culture
-
China launches military drills in Taiwan Strait
-
US senator smashes record with 25-hour anti-Trump speech
-
Brazil binman finds newborn baby on garbage route
-
US senator smashes record with marathon anti-Trump speech
-
Trump advisor Waltz faces new pressure over Gmail usage
-
Niger junta frees ministers of overthrown government
-
Trump set to unleash 'Liberation Day' tariffs
-
Boeing chief to acknowledge 'serious missteps' at US Senate hearing
-
Real Madrid hold Real Sociedad in eight-goal thriller to reach Copa del Rey final
-
Nuno salutes 'special' Elanga after stunning strike fires Forest
-
PSG survive scare against Dunkerque to reach French Cup final
-
Sundowns edge Esperance as crowd violence mars quarter-final
-
Nottingham Forest beat Man Utd, Saka scores on Arsenal return
-
Elanga wonder-goal sinks Man Utd as Forest eye Champions League berth
-
Stock markets mostly advance ahead of Trump tariffs deadline
-
US movie theaters urge 45-day 'baseline' before films hit streaming
-
Saka scores on return as Arsenal beat Fulham
-
Third-division Bielefeld shock holders Leverkusen in German Cup
-
Ball-blasting 'Torpedo bats' making waves across MLB opening weekend
-
Newsmax shares surge more than 2,000% in days after IPO
-
Thousands of Hungarians protest against Pride ban law
-
GM leads first quarter US auto sales as tariffs loom
-
Tesla sales tumble in Europe in the first quarter
-
No 'eye for an eye' approach to US tariffs: Mexico
-
NFL club owners back dynamic kickoffs, delay tush push vote
-
Trump 'perfecting' new tariffs as nervous world braces
-
Trump nominee says to press UK on Israel arms
-
French court says Le Pen appeal ruling could come before presidential vote
-
The battle to control assets behind Bosnia crisis
-
Prabhsimran powers Punjab to IPL win over Lucknow
-
Mass layoffs targeting 10,000 jobs hit US health agencies

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
S.Gregor--AMWN