-
Belgian prison tour lays bare grim reality of life behind bars
-
Iran, US race to find crew member of crashed American fighter jet
-
Brown, Tatum fuel Celtics over Bucks, Mavs teen Flagg scores 51
-
Sri Lanka struggles to avert economic collapse over Mideast war
-
Coughlin builds five-shot lead at LPGA Aramco Championship
-
58 tortillas, five hot sauces and one toilet: life aboard spacecraft Orion
-
Artemis mission shares office space -- and physics -- with Apollo
-
Rice will not face NFL action after probe into abuse claims
-
Injured Lakers star Doncic out for rest of NBA regular season
-
Injured Lakers star Doncic out for rest of NBA regular season: team
-
Tirante topples top seed Shelton to reach Houston ATP semi-finals
-
'Extraordinary' views of home as astronauts head towards Moon
-
Pope leads torch-lit Colosseum procession before Easter
-
Vanessa Trump posts supportive message after boyfriend Woods's arrest
-
Northampton edge Castres in 13-try Champions Cup battle
-
Iran hunts crew of crashed US jet, one reported rescued
-
Dembele leads PSG to victory ahead of Liverpool tie
-
MacIntyre seizes Texas Open lead as Masters looms
-
14 dead as Russia launches new daytime attacks on Ukraine
-
French, Japanese ships cross Strait of Hormuz in first since war
-
Pegula reaches WTA Charleston semis with latest three-setter
-
Iran hunts crashed US jet crew, as reports say one rescued
-
Iyer guides Punjab past Chennai to go top of IPL
-
'Sport of the future'? Padel's Miami boom augurs US expansion
-
Wary of news media, Silicon Valley builds its own
-
Iran searches for downed US jet crew, as US media says one member rescued
-
French court rules to extradite Russian who owned Portsmouth football club
-
Senegal-Morocco friendship put to test by Africa Cup of Nations title turmoil
-
For some around Trump, war on Iran is a Christian calling
-
Cuba begins prisoner release after mass pardon
-
US registers strong job growth in boost to Trump
-
10 dead as Russia launches new daytime attacks on Ukraine
-
Arteta hopes League Cup loss will 'fuel' Arsenal season run-in
-
Pogacar welcomes Evenepoel challenge in Flanders
-
US registers strong job growth in March in boost to Trump
-
Judge dismisses Lively sex harassment claim against Baldoni
-
'Line crossed': Chelsea's Fernandez dropped for two matches
-
Liverpool's Alisson to miss Man City, PSG matches, says Slot
-
New Paris mayor vows end to sexual violence in schools
-
Gattuso resigns as Italy coach after World Cup flop
-
Toyota bZ7: Luxury EVs in China
-
EU under pressure as fertiliser costs soar on Middle East war
-
Israel using AI to fine-tune air raid alert system
-
Hegseth fires top US army general in new shake-up
-
Myanmar junta chief elected president by pro-military MPs
-
Greece names new ministers after EU farm scandal resignations
-
Ukraine says six killed in 'massive' Russian daytime attacks
-
Kane ruled out of Bayern match with injury, says Kompany
-
Container ship declaring French ownership passes through Hormuz strait
-
Human remains found on Thai ship attacked in Hormuz strait: firm
Beijing Olympics organisers say app security flaws 'fixed'
An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.
Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.
Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.
Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.
Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.
But a senior Chinese Olympic official said any bugs had now been fixed.
"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.
"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."
The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.
Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.
"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.
- Data laws -
Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.
However, Yu said organisers never saw the request because it was sent to an old email address.
China's data security laws require that health and medical data be encrypted during transmission and storage.
The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.
"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.
Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".
But organisers denied ever requesting these functions, and said they have asked the developer to look into it.
They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.
"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.
China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.
In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.
Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.
However, organisers and the Chinese government have dismissed such concerns as unfounded.
"The government will not monitor individuals' phones in any form," Yu said.
The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.
W.Morales--AT