-
Signing up to DR Congo peace is one thing, delivery another
-
'Amazing' figurines find in Egyptian tomb solves mystery
-
Palestinians say Israeli army killed man in occupied West Bank
-
McLaren will make 'practical' call on team orders in Abu Dhabi, says boss Brown
-
Norris completes Abu Dhabi practice 'double top' to boost title bid
-
Chiba leads Liu at skating's Grand Prix Final
-
Meta partners with news outlets to expand AI content
-
Mainoo 'being ruined' at Man Utd: Scholes
-
Guardiola says broadcasters owe him wine after nine-goal thriller
-
Netflix to buy Warner Bros. Discovery in deal of the decade
-
French stars Moefana and Atonio return for Champions Cup
-
Penguins queue in Paris zoo for their bird flu jabs
-
Netflix to buy Warner Bros. Discovery for nearly $83 billion
-
Sri Lanka issues fresh landslide warnings as toll nears 500
-
Root says England still 'well and truly' in second Ashes Test
-
Chelsea's Maresca says rotation unavoidable
-
Italian president urges Olympic truce at Milan-Cortina torch ceremony
-
Norris edges Verstappen in opening practice for season-ending Abu Dhabi GP
-
Australia race clear of England to seize control of second Ashes Test
-
Trump strategy shifts from global role and vows 'resistance' in Europe
-
Turkey orders arrest of 29 footballers in betting scandal
-
EU hits X with 120-mn-euro fine, risking Trump ire
-
Arsenal's Merino has earned striking role: Arteta
-
Putin offers India 'uninterrupted' oil in summit talks with Modi
-
New Trump strategy vows shift from global role to regional
-
World Athletics ditches long jump take-off zone reform
-
French town offers 1,000-euro birth bonuses to save local clinic
-
After wins abroad, Syria leader must gain trust at home
-
Slot spots 'positive' signs at struggling Liverpool
-
Eyes of football world on 2026 World Cup draw with Trump centre stage
-
South Africa rugby coach Erasmus extends contract until 2031
-
Ex-Manchester Utd star Lingard announces South Korea exit
-
Australia edge ominously within 106 runs of England in second Ashes Test
-
McIlroy survives as Min Woo Lee surges into Australian Open hunt
-
German factory orders rise more than expected
-
Flooding kills two as Vietnam hit by dozens of landslides
-
Italy to open Europe's first marine sanctuary for dolphins
-
Hong Kong university suspends student union after calls for fire justice
-
Asian markets rise ahead of US data, expected Fed rate cut
-
Nigerian nightlife finds a new extravagance: cabaret
-
Tanzania tourism suffers after election killings
-
Yo-de-lay-UNESCO? Swiss hope for yodel heritage listing
-
Weatherald fires up as Australia race to 130-1 in second Ashes Test
-
Georgia's street dogs stir affection, fear, national debate
-
Survivors pick up pieces in flood-hit Indonesia as more rain predicted
-
Gibbs runs for three TDs as Lions down Cowboys to boost NFL playoff bid
-
Pandas and ping-pong: Macron ending China visit on lighter note
-
TikTok to comply with 'upsetting' Australian under-16 ban
-
Hope's resistance keeps West Indies alive in New Zealand Test
-
Pentagon endorses Australia submarine pact
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
F.Cardoso--PC