-
'Indescribable': Bosnia jubilant after securing World Cup return
-
Pakistan says holding talks with Afghan govt in China
-
Guehi tells England to 'stick together' after World Cup warm-up loss to Japan
-
Generation of Italians reeling from World Cup 'apocalypse'
-
Australian journeyman emerges as India's unlikely football saviour
-
Germany growth forecasts slashed as Mideast war hits economy
-
Spanish police open probe into anti-Muslim chants at Egypt friendly
-
Ailing Italy at new low after missing out on yet another World Cup
-
Trump says war could end in two, three weeks as Israel strikes Tehran
-
Greenpeace accuses oil companies of reaping Mideast 'war profits'
-
Australia PM warns months ahead 'may not be easy' due to Mideast war
-
Fiji part with coach Byrne 18 months before Rugby World Cup
-
Iraq plot 'shock' as famous win seals World Cup return after 40 years
-
Doncic returns with 42 as Lakers down Cavs
-
Anthropic releases part of AI tool source code in 'error'
-
Florida tourists gather to 'witness history' ahead of Moon launch
-
Israel strikes Iran's capital as Trump set to address US on war
-
Historic England win shows confident Japan can go far at World Cup
-
Iraq beat Bolivia 2-1 to claim final World Cup place
-
Russian women decry plans to therapise them into having children
-
Germany tries three over plot to overthrow government
-
Pope Leo celebrates first Easter amid Middle East war
-
Chinese robotaxis stall in apparent 'malfunction': police
-
Son under scrutiny ahead of World Cup after South Korea friendly woes
-
Japan allows joint child custody after divorce
-
NFL says will not scrap diversity measure despite Republican pressure
-
DR Congo fans dance in the rain after sealing World Cup spot
-
Far cry from 16-pixel start, Mario makes it 'so big' on screen: creator Miyamoto
-
Trump to watch Supreme Court weigh challenge to birthright citizenship
-
Konstas, Maxwell axed as Cricket Australia unveil contract list
-
Brazil down Croatia 3-1 in World Cup warm-up
-
Asian stocks rally as Trump says war to end 'very soon'
-
Spanish FA condemns anti-Muslim chants that marred Egypt friendly
-
Hong Kong's 'hero trees' lose their glory as climate warms
-
It's happening: historic Moon mission set for launch
-
Messi on target as Argentina down Zambia in World Cup send-off
-
The reality of restarting North Sea oil drilling
-
'I'm really proud': first Black astronaut candidate reflects on historic Moon mission
-
Supreme Court weighing Trump challenge to birthright citizenship
-
US auto sales seen falling as car market awaits war impact
-
Kast putting conservative stamp on Chile in first 30 days
-
Portugal down US 2-0 as World Cup hosts again fail to shine
-
AI giant Anthropic says 'exploring' Australia data centre investments
-
Tuchel faces World Cup selection dilemmas after England falter
-
At gas stations, Americans say they're 'paying the price' of Iran war
-
Woods 'stepping away' to focus on health after DUI arrest
-
DR Congo beat Jamaica 1-0 to qualify for World Cup
-
Trump says war with Iran could end in 'two weeks, maybe three'
-
Critical Elements Provides Preliminary Update on its 10,000-meter Drill Program at Rose West
-
WEED Inc (OTCQB:BUDZ) Looks to Advance a High-Value AI Data Center Opportunity for The Four Winds of Lake Erie, LLC. On Our Prime Lake Erie Waterfront Property
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
S.Gregor--AMWN