-
SoftBank profit quadruples to $32 bn on AI investments
-
Africa must drop 'victim mentality': mogul Tony Elumelu
-
'Ungovernable' Britain? Once-stable politics in freefall
-
China tech giant Tencent sees Q1 profit jump after AI bets
-
Nissan expects return to profit after huge loss
-
World Cup broadcast deadlock ends up in Indian court
-
Asian stocks mixed on US-Iran impasse, AI setbacks
-
Besieged Starmer seeks to heal Labour divisions in King's Speech
-
After winter storms, fires now threaten Portugal's forests
-
Philippine senator seeks military support to block ICC drug war arrest
-
UK's Catherine on first official foreign trip since cancer revelation
-
'Short of blue-collar workers': Ukraine's battle for labour
-
'Don't understand it, but it looks fun': cricket bowls Japan over
-
Poor planning fuels Bangladesh contraceptive crisis
-
Fugitive financier sought in Malaysian fund scandal seeks Trump's pardon
-
World Cup comes to 'Soccer Town USA,' but locals priced out
-
Don't mention the war: Tucson prepares to welcome Team Iran for World Cup
-
Hosting World Cup evokes powerful memories for Mexico, and raises expectations
-
AI rivalry overshadows push for guardrails at Xi-Trump talks: experts
-
Asian stocks fall on US-Iran impasse, AI setbacks
-
Wembanyama leads Spurs to brink as Timberwolves routed
-
Ronaldo left waiting for Saudi title after goalkeeping gaffe
-
'Not my son's fault': The women bearing the children of Sudan's war rapes
-
'I applied to be pope': Losing grip on reality while using ChatGPT
-
EU to ease train travel with one journey, one ticket rules
-
Quick bowler Brown left out of Australia T20 World Cup squad
-
Los Angeles stadium undergoes World Cup facelift
-
Pacific nation Nauru to change name in break from colonial past
-
Messi still highest-paid player in MLS
-
Paramount defends Warner bid amid California probe
-
Who Is the Best Plastic Surgeon in U.S.?
-
Birkenstock Reports Fiscal Second Quarter 2026 Results with Revenue Growth Of 14% In Constant FX Despite War, Tariffs and Inflation; Confirms Full-Year Target Of 13-15%
-
Greer Injury Lawyers Secures $38,816,500 Verdict for Client and Family
-
Guardian Metal Resources PLC Announces Tempiute Historical Mine Tailings Update
-
Tocvan Announces New Surface Gold-Silver Results, Outlining New Target 3 Kilometers East of Main Zone at Gran Pilar Gold-Silver Project
-
InterContinental Hotels Group PLC Announces Transaction in Own Shares - May 13
-
Agnete Kirk Kristiansen Appointed Chair of the LEGO Foundation
-
Blister worry hits McIlroy as PGA start looms at Aronimink
-
Tens of thousands demonstrate in Argentina over Milei university cuts
-
Ex-NBA player Jason Collins dies after brain cancer battle
-
Foot blister forces McIlroy to cut short PGA practice round
-
Man City boss Guardiola urges players to make VAR irrelevant
-
Favourites Finland, Israel through at Eurovision semis
-
Revitalized Rose sets aside Masters loss for top PGA form
-
Musk 'wanted 90%' of OpenAI, Altman tells tech titan trial
-
Former Honduras mayor arrested over murder of environmental activist
-
Conan O'Brien to host 2027 Oscars: organisers
-
Oil prices advance, stocks mostly fall on US-Iran deadlock
-
'Bittersweet' runner-up run has Scheffler inspired at PGA
-
Lakers would welcome return of LeBron James
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
W.Nelson--AT