
-
US reaching out to China for tariff talks: Beijing state media
-
Tariffs prompt Bank of Japan to lower growth forecasts
-
Kiss faces little time to set Wallabies on path to home World Cup glory
-
Serbian students, unions join forces for anti-corruption protest
-
Slow and easily beaten -- Messi's Miami project risks global embarrassment
-
Fan in hospital after falling to field at Pirates game
-
Nuclear power sparks Australian election battle
-
Tokyo stocks rise as BoJ holds rates steady
-
Bank of Japan holds rates, lowers growth forecasts
-
'Sleeping giants' Bordeaux-Begles awaken before Champions Cup semis
-
Napoli eye Scudetto as Inter hope for post-Barca bounce-back
-
Germany's 'absolutely insane' second tier rivalling Europe's best
-
PSG minds on Arsenal return as French clubs scrap for Champions League places
-
UK WWII veteran remembers joy of war's end, 80 years on
-
Myanmar junta lets post-quake truce expire
-
Rockets romp past Warriors to extend NBA playoff series
-
Messi, Inter Miami CONCACAF Cup dream over as Vancouver advance
-
UN body warns over Trump's deep-sea mining order
-
UK local elections test big two parties
-
US judge says Apple defied order in App Store case
-
Seventeen years later, Brood XIV cicadas emerge in US
-
Scorching 1,500m return for Olympic great Ledecky in Florida
-
Israel's Netanyahu warns wildfires could reach Jerusalem
-
Istanbul lockdown aims to prevent May Day marches
-
Cerrado Gold Announces Q4 And Annual 2024 Financial Results
-
Australian guard Daniels of Hawks named NBA's most improved
-
Mexico City to host F1 races until 2028
-
Morales vows no surrender in bid to reclaim Bolivian presidency
-
Ukraine, US sign minerals deal, tying Trump to Kyiv
-
Phenomenons like Yamal born every 50 years: Inter's Inzaghi
-
Ukraine, US say minerals deal ready as Kyiv hails sharing
-
Global stocks mostly rise following mixed economic data
-
O'Sullivan says he must play better to win eighth snooker world title after seeing off Si Jiahui
-
Sabalenka eases past Kostyuk into Madrid Open semis
-
Netflix's 'The Eternaut' echoes fight against tyranny: actor Ricardo Darin
-
US economy unexpectedly shrinks, Trump blames Biden
-
Barca fight back against Inter in sensational semi-final draw
-
Meta quarterly profit climbs despite big cloud spending
-
US Supreme Court weighs public funding of religious charter school
-
Climate change made fire conditions twice as likely in South Korea blazes: study
-
Amorim says not even Europa League glory can save Man Utd's season
-
Syria reports Israeli strikes as clashes with Druze spread
-
Ukraine, US say minerals deal ready as suspense lingers
-
Everything is fine: Trump's cabinet shrugs off shrinking economy
-
Chelsea boss Maresca adamant money no guarantee of success
-
Wood warns England cricketers against 'dumb' public comments
-
US economy shrinks, Trump blames Biden
-
Caterpillar so far not hiking prices to offset tariff hit
-
Japan's Kawasaki down Ronaldo's Al Nassr to reach Asian Champions League final
-
Trump praises Musk as chief disruptor eyes exit

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
S.Gregor--AMWN