-
Paramount acquires Warner Bros. in $110 bn mega-merger
-
Rosenior eyes extended stay to stabilise Chelsea
-
Spurs struggling physically admits Tudor
-
Lens held by Strasbourg in blow to Ligue 1 title chances
-
NFL salary cap passes $300 mn for first time
-
Wolves secure rare win to dent Villa's bid for Champions League place
-
Oil prices jump on Iran attack fears while US stocks fall
-
Two dead, dozens injured as tram derails in Milan
-
Trump tells US govt to 'immediately' stop using Anthropic AI tech
-
Court orders Greenpeace to pay $345 mn to US oil pipeline company
-
IAEA stresses 'urgency' to verify Iran's nuclear material
-
UN urges action to prevent full civil war in South Sudan
-
Hackers steal medical details of 15 million in France
-
Susan Sarandon praises Spain’s stance on Gaza
-
Murray adamant size isn't everything despite losing Wales place
-
Messi knocked down by fan in Puerto Rico pitch invasion
-
Two killed, dozens injured as tram derails in Milan
-
O'Neill taken aback by Rangers boss Rohl's comments on Celtic
-
Ukrainian, Slovak leaders hold call amid energy spat
-
French hard-left firebrand sparks row with 'antisemitic' Epstein jibe
-
Ahmed, Jacks blast England to thrilling win over New Zealand
-
UK police arrest man after Churchill statue sprayed with graffiti
-
Bill Clinton denies wrongdoing at grilling on Epstein ties
-
Red Cross urges Afghanistan-Pakistan 'de-escalation'
-
Coup role revelations revive calls for return of Spain's ex king
-
Oil prices jump on Iran attack fears, Wall Street slips on AI
-
TikTok disinformation: the other weapon in Mexico violence
-
Carmaker BMW to trial humanoid robots at German factory
-
NASA announces overhaul of Artemis lunar program amid technical delays
-
Golfer Pavan undergoes surgery after freak lift fall
-
Bill Clinton faces grilling on extensive ties to Epstein
-
For Roberto Cavalli designer, dreams come in all black
-
Macron to set out how France's nuclear arms could protect Europe
-
Spin-heavy England restrict New Zealand to 159-7 in Super Eights
-
Starmer vows to fight 'extremes' after UK Labour election drubbing
-
New Pokemon titles on horizon as 30th anniversary approaches
-
Arteta backs Gyokeres to impact Arsenal's trophy charge
-
55 Ghanaians killed after being lured into Ukraine war: govt
-
OpenAI raises $110 bn in record funding round
-
Medvedev swats Auger-Aliassime aside to reach Dubai final
-
Stocks slide, oil jumps tracking AI and Iran
-
France warns of 'provocation' if Russian drone buzzed aircraft carrier
-
At Milan Fashion Week, industry's darker side goes unmentioned
-
'Impressive' Maguire has Man Utd future says Carrick
-
'Games you live for': Rosenior relishes Chelsea's PSG tie
-
'Sacrificed futures': German chemical workers protest looming job cuts
-
Scientists discover giant bird-like dinosaur in Niger desert
-
Pakistan promise final flourish as they await T20 World Cup fate
-
Kurdish Iranian groups in Iraq eye opportunity for change at home
-
Suter wins as Aicher closes gap on absent Vonn in downhill title race
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
F.Cardoso--PC