
-
Where Trump's tariffs could hurt Americans' wallets
-
Trump says 'very close to a deal' on TikTok
-
Trump tariffs on Mexico: the good, the bad, the unknown
-
Postecoglou denies taunting Spurs fans in Chelsea defeat
-
Oscar-winning Palestinian director speaks at UN on Israeli settlements
-
With tariff war, Trump also reshapes how US treats allies
-
Fernandez fires Chelsea into fourth as pressure mounts on Postecoglou
-
South Korea court to decide impeached president's fate
-
Penguin memes take flight after Trump tariffs remote island
-
E.T., no home: Original model of movie alien doesn't sell at auction
-
Italy's Brignone has surgery on broken leg with Winter Olympics looming
-
Trump defiant as tariffs send world markets into panic
-
City officials vote to repair roof on home of MLB Rays
-
Rockets forward Brooks gets one-game NBA ban for technicals
-
Pentagon watchdog to probe defense chief over Signal chat row
-
US tariffs could push up inflation, slow growth: Fed official
-
New Bruce Springsteen music set for June 27 release
-
Tom Cruise pays tribute to Val Kilmer
-
Mexico president welcomes being left off Trump's tariffs list
-
Zuckerberg repeats Trump visits in bid to settle antitrust case
-
US fencer disqualified for not facing transgender rival
-
'Everyone worried' by Trump tariffs in France's champagne region
-
Italy's Brignone suffers broken leg with Winter Olympics looming
-
Iyer blitz powers Kolkata to big IPL win over Hyderabad
-
Russian soprano Netrebko to return to London's Royal Opera House
-
French creche worker gets 25 years for killing baby with drain cleaner
-
UK avoids worst US tariffs post-Brexit, but no celebrations
-
Canada imposing 25% tariff on some US auto imports
-
Ruud wants 'fair share' of Grand Slam revenue for players
-
Lesotho, Africa's 'kingdom in the sky' jolted by Trump
-
Trump's trade math baffles economists
-
Gaza heritage and destruction on display in Paris
-
'Unprecedented crisis' in Africa healthcare: report
-
Pogacar gunning for blood and thunder in Tour of Flanders
-
Macron calls for suspension of investment in US until tariffs clarified
-
Wall St leads rout as world reels from Trump tariffs
-
Mullins gets perfect National boost with remarkable four-timer
-
Trump tariffs hammer global stocks, dollar and oil
-
Authors hold London protest against Meta for 'stealing' work to train AI
-
Tate Modern gifted 'extraordinary' work by US artist Joan Mitchell
-
Mexico president welcomes being left off Trump's new tariffs list
-
Tonali eager to lead Newcastle back into Champions League
-
Lesotho hardest hit as new US tariffs rattle Africa
-
Stellantis pausing some Canada, Mexico production over Trump auto tariffs
-
Rising odds asteroid that briefly threatened Earth will hit Moon
-
Italy reels from Brignone broken leg with Winter Olympics looming
-
Is the Switch 2 worth the price? Reviews are mixed
-
Ancelotti’s tax trial wraps up in Spain with prosecutors seeking jail
-
Civilians act to bring aid to Myanmar earthquake victims
-
US trade gap narrows in February ahead of bulk of Trump tariffs

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
W.Nelson--AT