- Global stocks struggle after Fed signals slower rate cuts
- UK economy slows, hitting government growth plans
- Primary schools empty as smog persists in Indian capital
- Palestinians turn to local soda in boycott of Israel-linked goods
- Typhoon Man-yi bears down on Philippines still reeling from Usagi
- UK growth slows in third quarter, dealing blow to Labour government
- Chris Wood hits quickfire double in NZ World Cup qualifying romp
- Markets struggle at end of tough week
- China tests building Moon base with lunar soil bricks
- Film's 'search for Palestine' takes centre stage at Cairo festival
- Oil execs work COP29 as NGOs slam lobbyist presence
- Gore says climate progress 'won't slow much' because of Trump
- 'Megaquake' warning hits Japan's growth
- Stiff business: Berlin startup will freeze your corpse for monthly fee
- Wars, looming Trump reign set to dominate G20 summit
- Xi, Biden attend Asia-Pacific summit, prepare to meet
- Kyrgios to make competitive return at Brisbane next month after injuries
- Dominican Juan Luis Guerra triumphs at 25th annual Latin Grammys
- Landslide win for Sri Lanka president's leftist coalition in snap polls
- Australian World Cup penalty hero Vine takes mental health break
- As Philippines picks up from Usagi, a fresh storm bears down
- Tropical Storm Sara pounds Honduras with heavy rain
- Pepi gives Pochettino win for USA in Jamaica
- 'Hell to heaven' as China reignite World Cup hopes with late winner
- Rebel attacks keep Indian-run Kashmir on the boil
- New Zealand challenge 'immense but fantastic' for France
- Under pressure England boss Borthwick in Springboks' spotlight
- All Blacks plan to nullify 'freakish' Dupont, says Lienert-Brown
- TikTok makes AI driven ad tool available globally
- Japan growth slows as new PM readies stimulus
- China retail sales pick up speed, beat forecasts in October
- Asian markets fluctuate at end of tough week
- Gay, trans people voicing -- and sometimes screaming -- Trump concerns
- Argentina fall in Paraguay, Brazil held in Venezuela
- N. Korean leader orders 'mass production' of attack drones
- Pakistan's policies hazy as it fights smog
- Nature pays price for war in Israel's north
- New Zealand's prolific Williamson back for England Test series
- Mexico City youth grapple with growing housing crisis
- After Trump's victory, US election falsehoods shift left
- Cracks deepen in Canada's pro-immigration 'consensus'
- Xi inaugurates South America's first Chinese-funded port in Peru
- Tyson slaps Paul in final face-off before Netflix bout
- England wrap-up T20 series win over West Indies
- Stewards intervene to stop Israel, France football fans clash at Paris match
- Special counsel hits pause on Trump documents case
- Japan's Princess Mikasa, great aunt to emperor, dies aged 101
- Cricket at 2028 Olympics could be held outside Los Angeles
- Trump names vaccine skeptic RFK Jr. to head health dept
- Ye claims 'Jews' controlling Kardashian clan: lawsuit
RBGPF | 100% | 61.84 | $ | |
RYCEF | -4.71% | 6.79 | $ | |
JRI | -0.23% | 13.21 | $ | |
SCS | -0.75% | 13.27 | $ | |
GSK | -2.09% | 34.39 | $ | |
CMSC | -0.24% | 24.55 | $ | |
RELX | -0.37% | 45.95 | $ | |
NGG | 0.4% | 62.37 | $ | |
BTI | 0.2% | 35.49 | $ | |
BCC | -1.57% | 140.35 | $ | |
RIO | -0.31% | 60.43 | $ | |
VOD | -0.81% | 8.68 | $ | |
BP | 1.65% | 29.05 | $ | |
AZN | -0.38% | 65.04 | $ | |
BCE | -1.38% | 26.84 | $ | |
CMSD | -0.02% | 24.725 | $ |
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
W.Nelson--AT