-
Brazil court grants house arrest for jailed Bolsonaro
-
Sinner downs Michelsen to reach Miami Open quarter-finals
-
Advantage Arsenal in women's Champions League quarter-final against Chelsea
-
Garner dreams of World Cup glory in bid to replicate England under-21 success
-
New Mexico jury finds Meta liable for endangering children
-
Huge crowd in Buenos Aires marks 50 years since Argentina's coup
-
Oil, stock trading spiked before Trump's Iran remarks
-
Colombia military plane crash death toll rises to 69
-
Trump adds Columbus statue, walkway in latest White House makeover
-
Toronto unveils upgraded World Cup venue after fan scorn
-
Beerensteyn goal gives Wolfsburg edge over Lyon in women's Champions League
-
Gang crackdown carried out without 'abuses,' Guatemalan defense chief says
-
Afghanistan releases detained US citizen
-
Danish PM's left bloc leads election, but no majority
-
'Illustrious' Salah to leave Liverpool at the end of the season
-
Trump says Iran gave US 'gift' linked to Strait of Hormuz
-
US officials downplay controller 'distraction' in New York crash
-
Salah to leave Liverpool at the end of the season
-
Trump has destroyed Venezuela's socialist ideology: opposition leader
-
France urges Israel 'to refrain' from seizing south Lebanon zone
-
UN rights council to hold urgent debate on Iran's Gulf strikes
-
Russia rains drones on Ukraine, killing eight, hitting UNESCO site
-
Lukaku to miss Belgium World Cup warm-up trip to US
-
Data canary shows economy already suffering from Middle East war
-
ConocoPhillips chief seeks extra US protection of Mideast assets
-
Oil prices jump as Trump's Iran claims raise doubts
-
In world first, antimatter taken on test drive at CERN
-
New Chile president withdraws support for Bachelet UN chief bid
-
Mammals cannot be cloned infinitely, mice study discovers
-
600-year-old pinot noir grape found in medieval French toilet
-
NASA to build $20 bn moon base, pause orbital lunar station plans
-
Czech 'arks' help preserve Ukraine's cultural heritage
-
Shiffrin closes on World Cup overall title with slalom win
-
Griezmann to leave Atletico for Orlando at end of season
-
New Nice mayor poses a 'real problem' for 2030 Winter Olympics
-
Afghanistan announces release of detained US citizen
-
Meta awaits verdict in New Mexico child safety trial
-
Pinheiro Braathen wins World Cup giant slalom title after Odermatt crashes
-
Aid flotilla arrives in Cuba as US oil blockade bites
-
Residents recount guilt, chaos in hearing on deadly Hong Kong fire
-
Oil prices jump, stocks slip as Trump's Iran claims raise doubts
-
World Snooker Championship to stay at Crucible
-
Mercedes new electric VLE: Price and performance?
-
Outlook worsens for whale stranded on German coast
-
Xiaomi quarterly profit slumps despite annual EV gains
-
Iran, Israel trade strikes despite Trump talk of negotiations
-
IPL's Bengaluru to keep 11 seats empty in honour of stampede dead
-
Oil prices jump, stocks waver after Trump's Iran claim
-
'A top person': Who is the US dealing with in Iran?
-
In Lebanon's Tyre, ancient site threatened by Israeli bombs
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
W.Nelson--AT