-
Boulter stuns Rybakina to reach Queen's Club semi-finals
-
After historic rally, Knicks aim to subdue Spurs early
-
When Hockney told AFP about his lockdown 'blessing' in France
-
In partial victory, Blake Lively wins legal fees from Justin Baldoni
-
Trump calls US World Cup team before first match
-
Partey refused entry to Canada for Ghana's World Cup opener
-
EU says to resume membership talks with Ukraine on Monday
-
'We're over it': Wemby says Spurs focused on game five after historic loss
-
Bruce Springsteen music center set to open in New Jersey
-
Cuba opens more sectors to private business
-
McTominay 'ready to go' for Scotland World Cup opener
-
Ghana World Cup player Partey, facing rape trial in UK, denied Canada visa: FIFA
-
Plane trouble delays pope's return after migrant-focused Spain visit
-
Canada's World Cup moment arrives at home
-
World's first gig economy treaty adopted at the ILO
-
Ireland-Israel football fixture to be played at neutral venue
-
World Cup struggles to ignite US excitement
-
US appellate court upholds Sam Bankman-Fried criminal sentence
-
Premier League changes hair-pulling punishment for new season
-
World amateur No.1 golfer Koivun to turn pro after US Open
-
McLaren's Norris pips Russell in second Barcelona F1 practice
-
Fans hope 'Orange Street' guides Dutch to World Cup victory
-
Florence's Giotto frescoes restored to glory after renovation
-
UK faces hard choices over military spending: analysts
-
Whole England squad must feel 'loved' at World Cup: Bellingham
-
Wall Street climbs as SpaceX shares launch, oil slides on Mideast deal hopes
-
Players welcome 'step forward' after Wimbledon prize money increase
-
Contemporary art giant David Hockney dies aged 88
-
France bids farewell to girl, 11, whose killing sparked outrage
-
Van Gils claims Auvergne Tour stage as Tuckwell moves into overall lead
-
Pele's 1958 World Cup winners' medal set to fetch £500,000
-
Ebola spreading into new areas in northeast DR Congo: WHO
-
African, Asian experts denied EU visas for major midwives summit
-
Kennedy Center board, Justice Dept appeal order to remove Trump's name
-
Former world champion Tsegay banned over doping violation
-
Wall Street wobbles as SpaceX shares launch, oil slides on Mideast deal hopes
-
SpaceX lifts off in record Wall Street debut
-
US deportation flight carrying Iranians en route to C.African Republic
-
Afghans scrap protest plans as Herat city under tight security
-
'I don't want to limit myself': Chinese star Xin Zhilei on new experiences
-
New Zealand great Williamson says 'right time' to retire from international cricket
-
Ronaldo 'very positive' as Portugal head for World Cup
-
Mercedes' Russell quickest in opening Barcelona F1 practice
-
At a Libyan university once ravaged by war, students dream again
-
O'Callaghan and Short star at Australian swim trials
-
Kenya mourns schoolgirls killed in suspected dorm arson attack
-
Iran insists on nuclear enrichment under any deal with US
-
Stocks rally, oil slides on Mideast deal hopes
-
COP31 hosts urged to 'lead by example' on fossil fuels
-
Alpine's Gasly reinstated to Monaco Grand Prix podium
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
F.Cardoso--PC