- Indonesia's Mount Ibu erupts more than 1,000 times this month
- Sumo to stage event in Paris as part of global push
- Deadly strikes on Gaza after Israel says ceasefire delayed
- Badosa 'loves Coco' but is gunning for 'revenge' in Melbourne quarters
- Sabalenka, Gauff on Melbourne collision course as Alcaraz moves on
- Alcaraz into Australian Open quarters after Draper retires
- Sabalenka uses fighting spirit to banish Australian Open blues
- Sabalenka, Gauff on Melbourne collision course after reaching quarters
- Swiss rider Ruegg wins opening UCI World Tour event in Australia
- Mitchell scores 36 as Cavs bounce back, Celtics downed
- Sabalenka a happy snapper at Australian Open
- Gauff turns up heat on Bencic to reach Australian Open quarters
- Commanders stun Lions in NFL thriller, Chiefs advance
- Protesters storm S. Korea court after president's detention extended
- TikTok notifies US users of shutdown as Trump seeks last-ditch solution
- Ceasefire in Israel-Hamas war to begin at 0630 GMT
- Wuhan keen to shake off pandemic label five years on
- Sabalenka imperious as Djokovic, Alcaraz on Melbourne collision course
- 'Generational problem': Youth still struggling in pandemic's shadow
- Vaccine misinformation: a lasting side effect from Covid
- Sabalenka blows away Andreeva to reach Melbourne quarter-finals
- Hope, fear at Paris rally for Gaza hostages
- Separated by LA wildfires, a happy reunion for some pets, owners
- France's Moutet 'collapsed in shower' before Australian Open match
- In US, teleworkers don't want to turn back
- Covid's origins reviewed: Lab leak or natural spillover?
- Trump arrives in Washington ahead of Monday's inauguration
- Steady Straka takes four-shot lead in PGA Tour's American Express
- Kelce, Mahomes double-act leads Chiefs past Texans in NFL playoffs
- Barcelona's Balde complains of racist abuse in Getafe draw
- Frustrated Barca fail to capitalise on Atletico La Liga slip
- More Kenyan police land in Haiti to bolster security mission
- McGlynn leads youthful USA to friendly win over Venezuela
- Barcelona stumble to frustrating Getafe draw in title setback
- Lukaku fires Napoli six points clear at Atalanta, Juve sink Milan
- Milder winds help LA firefighters as Trump vows to visit
- S. Korean court extends impeached president's detention, angering supporters
- Wirtz has Leverkusen on Bayern's heels to keep repeat title 'dream' alive
- Arsenal must take blame for Villa fightback: Arteta
- Nunez late show extends Liverpool's lead, Arsenal held by Aston Villa
- Russian attacks kill six across Ukraine, Kyiv says
- Northampton, Leinster claim Champions Cup pool top spots
- Arsenal's title bid rocked by Villa fightback
- Superb Wirtz keeps Leverkusen on pace with leaders Bayern
- Detention extended for S. Korea's impeached president
- Thousands attend funeral of Liberian ex-warlord Prince Johnson
- Barcola strikes as PSG fight back to beat Lens
- Juventus into Serie A Champions League spots with victory over AC Milan
- Kane calls on Bayern to extend with pal Dier
- Kenya sends 217 more police officers to Haiti mission
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
W.Nelson--AT