-
Eswatini minister slammed for reported threat to expel LGBTQ pupils
-
Pfizer shares drop on quarterly loss
-
Norway's Kilde withdraws from Winter Olympics
-
Vonn says 'confident' can compete at Olympics despite ruptured ACL
-
Germany acquires power grid stake from Dutch operator
-
France summons Musk for questioning as X deepfake backlash grows
-
Finland building icebreakers for US amid Arctic tensions
-
Petro extradites drug lord hours before White House visit
-
Disney names theme parks chief Josh D'Amaro as next CEO
-
Disney names theme parks boss chief Josh D'Amaro as next CEO
-
Macron says work under way to resume contact with Putin
-
Prosecutors to request bans from office in Le Pen appeal trial
-
Tearful Gazans finally reunite after limited Rafah reopening
-
Iran president confirms talks with US after Trump's threats
-
Spanish skater allowed to use Minions music at Olympics
-
Fire 'under control' at bazaar in western Tehran
-
Howe trusts Tonali will not follow Isak lead out of Newcastle
-
Vonn to provide injury update as Milan-Cortina Olympics near
-
France summons Musk for 'voluntary interview', raids X offices
-
Stocks mostly climb as gold recovers
-
US judge to hear request for 'immediate takedown' of Epstein files
-
Russia resumes large-scale strikes on Ukraine in glacial temperatures
-
Fit-again France captain Dupont partners Jalibert against Ireland
-
French summons Musk for 'voluntary interview' as authorities raid X offices
-
IOC chief Coventry calls for focus on sport, not politics
-
McNeil's partner hits out at 'brutal' football industry after Palace move collapses
-
Proud moment as Prendergast brothers picked to start for Ireland
-
Germany has highest share of older workers in EU
-
Teen swims four hours to save family lost at sea off Australia
-
Ethiopia denies Trump claim mega-dam was financed by US
-
Norway crown princess's son pleads not guilty to rapes as trial opens
-
Russia resumes strikes on freezing Ukrainian capital ahead of talks
-
Malaysian court acquits French man on drug charges
-
Switch 2 sales boost Nintendo profits, but chip shortage looms
-
China to ban hidden car door handles, setting new safety standards
-
Switch 2 sales boost Nintendo results but chip shortage looms
-
From rations to G20's doorstep: Poland savours economic 'miracle'
-
Russia resumes strikes on freezing Ukrainian capital
-
'Way too far': Latino Trump voters shocked by Minneapolis crackdown
-
England and Brook seek redemption at T20 World Cup
-
Coach Gambhir under pressure as India aim for back-to-back T20 triumphs
-
'Helmets off': NFL stars open up as Super Bowl circus begins
-
Japan coach Jones says 'fair' World Cup schedule helps small teams
-
Equities and precious metals rebound after Asia-wide rout
-
Do not write Ireland off as a rugby force, says ex-prop Ross
-
Winter Olympics 2026: AFP guide to Alpine Skiing races
-
Winter Olympics to showcase Italian venues and global tensions
-
Buoyant England eager to end Franco-Irish grip on Six Nations
-
China to ban hidden car door handles in industry shift
-
Sengun leads Rockets past Pacers, Ball leads Hornets fightback
| RYCEF | 1.65% | 16.95 | $ | |
| NGG | 1.31% | 85.73 | $ | |
| BCC | 4.43% | 85.535 | $ | |
| RIO | 3.88% | 96.25 | $ | |
| SCS | 0.12% | 16.14 | $ | |
| GSK | 1.25% | 53.135 | $ | |
| RELX | -17.73% | 30.18 | $ | |
| CMSD | -0.21% | 24.03 | $ | |
| RBGPF | 0.12% | 82.5 | $ | |
| CMSC | -0.25% | 23.69 | $ | |
| VOD | 1.72% | 15.171 | $ | |
| BTI | 1.01% | 61.615 | $ | |
| AZN | 0.58% | 189.51 | $ | |
| BCE | 1% | 26.09 | $ | |
| BP | 1.4% | 38.235 | $ | |
| JRI | -0.11% | 13.135 | $ |
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
W.Nelson--AT