-
Emotional Dimitrov enjoys redemptive Wimbledon win over Mensik
-
Endrick says versatility could help Brazil against Norway
-
New York ready for epic Swift-Kelce fairytale wedding
-
Ghana have 'duty to Africa' to progress at World Cup, says Queiroz
-
Rubio says USA 'screwed' by World Cup red card
-
Former Celtics star Brown in shock over trade to 76ers
-
Heat dome roasts eastern US ahead of holiday weekend
-
Progress, further delay risk for Boeing Air Force One: report
-
WHO declares cruise ship hantavirus outbreak over
-
US coach Pochettino '200% Argentine' but embraces Americana
-
Sciver-Brunt and Knight take England to 169-5 in South Africa semi-final
-
Ukraine, Russia vow escalation after Moscow strikes on Kyiv kill 25
-
Trump's massive July 4 firework show raises health alarms
-
Prosecutors can review Woods medical records in DUI case: judge
-
Pogacar expects Vingegaard Tour de France battle to last 'years'
-
Japan deploys bear cameras in mountains as attacks surge
-
New York ready for epic Swift-Kelce love story wedding
-
Djokovic has history in his sights at Wimbledon
-
Wildfires rage in southern France, 3,000 people evacuated
-
Ovechkin returning to Caps for 22nd NHL season
-
Hamilton gives F1 a piece of his mind over Lego cars
-
Faster than Mbappe: Australia flyer Bos races into World Cup conversation
-
Hong Kong bookseller once held in China dies in Taiwan
-
Trump wants 'senseless killing' in Ukraine to end: US official
-
Venezuelan rescue brings hope to nation in mourning
-
Eala writes history for Philippines in 'electric' Wimbledon atmosphere
-
Macabre night in La Guaira, Venezuela's earthquake epicenter
-
Wolff urges 'perspective' as Russell chases Mercedes' teammate Antonelli
-
Tesla global auto sales jump 25% in 2nd quarter, beating expectations
-
Superb Swiatek, Zverev cruise into Wimbledon last 32
-
Zverev routs Royer to reach Wimbledon third round
-
Ukraine, Russia vow escalation after Moscow attack kills 21 in Kyiv
-
Hot spell roasts eastern US ahead of holiday weekend
-
Slowing US job growth poses midterms challenge for Trump
-
Hamilton cools fans Ferrari fervour
-
Klopp poised to replace Nagelsmann as Germany coach: reports
-
Venezuela's diaspora searches for quake victims on social media
-
More than 400 dead in DR Congo's spreading Ebola outbreak
-
Albanian clashes as protest over Trump-linked resort boils over
-
Hot spell roasts eastern US as holiday weekend approaches
-
Desire key to Pogacar dominance, says former Tour king Froome
-
Superb Swiatek storms into Wimbledon last 32, Zverev waits
-
Rescuers dig out Venezuelan man eight days after quakes
-
Russian strikes kill 21 in biggest ever attack on Kyiv, mayor says
-
Anderson closes in on record Man City move
-
Swiatek sees off Pliskova to race into Wimbledon third round
-
England change five for South Africa Test
-
Dollar down, stocks shine after disappointing US jobs data
-
Lock Alemanno to make 100th Pumas appearance against Scotland
-
US job growth slows, posing questions for Trump before midterms
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
W.Nelson--AT