-
Nvidia to buy AI platform Hugging Face for $12.9 bn: report
-
Desperate families search for missing after Nepal floods
-
Palace intrigue in Uganda as succession battle heats up
-
The missing in Nepal-Tibet flash floods
-
'Housing First' approach gets Swedish city's homeless off streets
-
Search for 1,300 missing after deadly Nepal-Tibet floods
-
Czech duo Muchova and Mensik win US Open mixed doubles title
-
Once a top export, prized Kashmir carpet fades
-
Japan's 'polka dot queen' artist Yayoi Kusama dies aged 97
-
Search for 1,000 missing after deadly Nepal-Tibet floods
-
Nepal-Tibet disaster: what we know
-
Park So-yeon first woman to play for eSports powerhouse South Korea
-
China deploys record number of ships around Taiwan as pressure grows
-
Yayoi Kusama: Japan's kaleidoscopic, troubled 'polka dot queen'
-
Ruthless Bayern target treble as rivals reboot on Bundesliga return
-
Euro champ Hunt 'on her toes' against world's best in Zurich 100m
-
What experts know so far about Nepal's deadly floods
-
Asian chip firms lifted by Nvidia forecast but broader markets struggle
-
UEFA set to withdraw FIFA boycott threat ahead of Champions League draw
-
Search for missing after Nepal-Tibet floods kill 165
-
Sumo moves to beat Japan summer heat as temperatures rise
-
Qantas says profits slump as fuel costs surge
-
'Be more honest': Markets crave clarity from cryptic Fed chair
-
Lofty bond yields, Bessent's intervention pose challenge to Fed's Warsh
-
Climate change leaves its mark on America's largest reservoir
-
The foreigners missing in Nepal's flash floods
-
CIA director warned Russia not to attack NATO members: US media
-
Bond yields are surging: Here's why that could spell trouble
-
Search for missing after Nepal-Tibet floods kills at least 160
-
Fed's Cook rejects Trump mortgage fraud claims
-
Empire Metals Limited Announces Interim Results
-
Guardian Metal Resources PLC Announces Pilot Mountain Technical Report Summary
-
InterContinental Hotels Group PLC Announces Transaction in Own Shares - August 27
-
Meta, US states agree $18 bn settlement in landmark teen safety case
-
Police probe 'assault allegations' after Carse's nightclub incident
-
What scientists know so far about Nepal's deadly floods
-
How we might hear new Dolly Parton music in the future
-
US general visits Colombia to discuss war on drugs
-
Nvidia doubles revenue, forecasts even more AI spending
-
Meta settlement puts social media industry on notice: 'There will be more'
-
Canada renews push to boycott US products
-
NFL owners approve record Seahawks sale
-
Savio scores on debut as Spurs set-up League Cup tie with Liverpool
-
Nigerian armed groups net nearly $6 mn in ransoms: study
-
Brazil sues Discord over child safety measures, demands $100 mln in damages
-
Savio scores on debut as Spurs advance in League Cup
-
Alberta NDP Urges Smith to Postpone Separation Vote Amid Trade War
-
Mbappe hits treble as Real Madrid thrash Real Sociedad
-
Fenerbahce stun Lyon in Champions League as AEK crush Levski
-
At Dollywood, superfans honor the late singer and local hero
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
W.Nelson--AT