-
Bagnaia pips Marquez to French Grand Prix pole
-
Tchouameni can play Clasico despite Valverde clash: Real Madrid's Arbeloa
-
Conflict inflames tensions at Venice Biennale of Art
-
'No home left' for Gazans stranded in West Bank since Oct 7
-
Indonesia rescuers search for hikers killed in volcanic eruption
-
Magyar to become Hungary's 'regime change' PM
-
Wembanyama powers Spurs past T-Wolves as Knicks beat Sixers
-
Trapped seafarers traumatised by Gulf fighting: charities
-
European minnows bid to challenge social media giants
-
Red-hot Knicks open 3-0 playoff lead against Sixers
-
At 100th major, Aussie Scott sees best as yet to come
-
Scheffler and McIlroy fancied for PGA Championship title
-
Acting US attorney general pursues Trump grievances at Justice Dept
-
Spirit exit likely to lead to higher US airfares, experts say
-
World Cup to hold trio of star-studded opening ceremonies
-
Defending champ Jeeno grabs three-shot lead at windy Mizuho Americas Open
-
McIlroy says PGA should be open to returns from LIV Golf
-
Im leads Fleetwood by one at Quail Hollow
-
Peru presidential hopeful says electoral 'coup' underway
-
Mexico to cut school year short ahead of World Cup
-
Lens secure Champions League spot and send Nantes down
-
Dortmund down Frankfurt to push Riera close to the edge
-
Costa Rica's new leader vows 'firm land' against drug gangs
-
Messi says Argentina up against 'other favorites' in World Cup repeat bid
-
Global stocks diverge, oil rises as fresh US-Iran clashes hit peace hopes
-
Ailing Djokovic falls to early Italian Open exit ahead of Roland Garros
-
Costa Rica leader sworn in with tough-on-crime agenda
-
UK PM Starmer vows to fight on after local polls drubbing
-
Formula One engines to change again in 2027
-
Djokovic falls in Italian Open second round to qualifier Prizmic
-
NFL reaches seven-year deal with referees
-
Real Madrid fine Tchouameni and Valverde 500,000 euros over bust-up
-
Hantavirus scare revives Covid-era conspiracy theories
-
Report revives speculation China Eastern crash was deliberate
-
Allen ton powers Kolkata to fourth win in a row in IPL
-
Zarco dominates Le Mans qualifying as Marquez struggles
-
'Worst whistle' - Lakers coach blasts refs over LeBron treatment
-
French couple from virus-hit ship describe voyage as 'unlikely adventure'
-
Van der Breggen soars into women's Vuelta lead with stage six win
-
WHO says hantavirus risk low as countries prep repatriation flights
-
Stocks diverge, oil rises as fresh US-Iran clashes hit peace hopes
-
Zverev and Swiatek move into Italian Open third round
-
Celtic driven by fear of failure in Hearts chase, says O'Neill
-
Selling factories to Chinese partners: risky road for European carmakers
-
Rubio urges Europeans to share the Iran burden
-
France's Magnier sprints to victory in crash-hit Giro opener
-
Is there anybody out there? Pentagon releases secret UFO files
-
US job growth beats expectations but consumer confidence at all-time low
-
US fires on Iran tankers as talks hang in balance
-
German sports car maker Porsche to cut 500 jobs
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
F.Cardoso--PC