
-
Antonelli comes of age with podium finish in Canada
-
PSG cruise as Atletico wilt in Club World Cup opener
-
US Open resumes with Burns leading at rain-soaked Oakmont
-
Hamilton 'devastated' after hitting groundhog in Canada race
-
Piastri accepts Norris apology after Canadian GP collision
-
Heavy rain halts final round of US Open at soaked Oakmont
-
PSG cruise past Atletico to win Club World Cup opener
-
Israel pounds Iran from west to east, Tehran hits back with missiles
-
Burns leads Scott by one as dangerous weather halts US Open
-
Russell triumphs in Canada as McLaren drivers crash
-
'Magical' Duplantis soars to pole vault world record in Stockholm
-
Trump vetoed Israeli plan to kill Iranian supreme leader: US official
-
McIlroy seeks Portrush reboot after US Open flop
-
Renault boss Luca de Meo to step down, company says
-
Kubica wins 'mental battle' to triumph at Le Mans
-
Burns seeks first major title at US Open as Scott, Spaun chase
-
Merciless Bayern hit 10 against amateurs Auckland City at Club World Cup
-
'How to Train Your Dragon' soars to top of N.America box office
-
Tens of thousands rally for Gaza in Netherlands, Belgium
-
Duplantis increases pole vault world record to 6.28m
-
Israel pounds Iran from west to east in deepest strikes yet
-
Gezora wins Prix de Diane in Graffard masterpiece
-
Pogacar wins first Dauphine ahead of Tour de France title defence
-
Trump due in Canada as G7 confronts Israel-Iran crisis
-
Kubica steers Ferrari to third consecutive 24 Hours of Le Mans
-
French Open champ Alcaraz ready for Queen's after Ibiza party
-
India a voice for Global South at G7, says foreign minister
-
Tens of thousands rally in Dutch protest for Gaza
-
Sinner had 'sleepless nights' after dramatic French Open final loss
-
Gattuso named new Italy coach after Spalletti sacking
-
Relatives lament slow support, wait for remains after India crash
-
Israel vows to make Iran pay 'heavy price' as fighting rages on
-
Macron, on Greenland visit, berates Trump for threats against the territory
-
Qualifier Maria completes fairytale run to Queen's title
-
Gattuso named new Italy coach
-
Tens of thousands rally in Dutch Gaza protest
-
Israel-Iran conflict: latest developments
-
Israel keeps up Iran strikes after deadly missile barrage
-
Ex-president Sarkozy stripped of France's top honour after conviction
-
Iran missiles kill 10 in Israel in night of mutual attacks
-
'This is a culture': TikTok murder highlights Pakistan's unease with women online
-
Families hold funerals for Air India crash victims
-
US Fed set to hold rates steady in the face of Trump pressure
-
Iran launches missile barrage as Israel strikes Tehran
-
Sober clubbing brews fresh beat for Singapore Gen Z
-
Cummins flags Australia shake-up after WTC defeat as Ashes loom
-
Mexico down Dominican Republic to open Gold Cup defence
-
Pochettino defends Pulisic omission: 'I'm not a mannequin'
-
Panthers on brink of Stanley Cup repeat after 5-2 win over Oilers
-
Messi denied late winner in Club World Cup opener

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
S.Gregor--AMWN