-
Hawks guard Young poised to resume practice after knee sprain
-
Salah back in Liverpool fold as Arsenal grab last-gasp win
-
Raphinha extends Barca's Liga lead, Atletico bounce back
-
Glasgow comeback upends Toulouse on Dupont's first start since injury
-
Two own goals save Arsenal blushes against Wolves
-
'Quality' teens Ndjantou, Mbaye star as PSG beat Metz to go top
-
Trump vows revenge after troops in Syria killed in alleged IS ambush
-
Maresca bemoans 'worst 48 hours at Chelsea' after lack of support
-
Teenage pair Ndjantou, Mbaye star as PSG beat Metz to go top
-
Drone strike in southern Sudan kills 6 UN peacekeepers
-
Crime wave propels hard-right candidate toward Chilean presidency
-
Terrific Terrier backheel helps lift Leverkusen back to fourth
-
'Magic' Jalibert guides Bordeaux-Begles past Scarlets
-
Teenage pair Ndjantou and Mbaye star as PSG beat Metz to go top
-
Anglo-French star Jane Birkin gets name on bridge over Paris canal
-
US troops in Syria killed in alleged IS ambush
-
Jalibert masterclass guides Bordeaux-Begles past Scarlets
-
M23 marches on in east DR Congo as US vows action against Rwanda
-
Raphinha double stretches Barca's Liga lead in Osasuna win
-
Terrific Terrier returns Leverkusen to fourth
-
Colts activate 44-year-old Rivers for NFL game at Seattle
-
US troops in Syria killed in IS ambush attack
-
Liverpool's Slot says 'no issue to resolve' with Salah after outburst
-
'Stop the slaughter': French farmers block roads over cow disease cull
-
Stormers see off La Rochelle, Sale stun Clermont in Champions Cup
-
Maresca hails Palmer as Chelsea return to winning ways against Everton
-
Hungarian protesters demand Orban quits over abuse cases
-
Belarus frees protest leader Kolesnikova, Nobel winner Bialiatski
-
Salah sets up goal on return to Liverpool action
-
Palmer strikes as Chelsea return to winning ways against Everton
-
Pogacar targets Tour de France Paris-Roubaix and Milan-San Remo in 2026
-
Salah back in action for Liverpool after outburst
-
Atletico recover Liga momentum with battling win over Valencia
-
Meillard leads 'perfect' Swiss sweep in Val d'Isere giant slalom
-
Salah on Liverpool bench for Brighton match
-
Meillard leads Swiss sweep in Val d'Isere giant slalom
-
Indonesia flood death toll passes 1,000 as authorities ramp up aid
-
Cambodia shuts Thailand border crossings over deadly fighting
-
First urban cable car unveiled outside Paris
-
Vonn second behind Aicher in World Cup downhill at St Moritz
-
Aicher pips Vonn to downhill win at St Moritz
-
Thailand says 4 soldiers killed in Cambodia conflict, denies Trump truce claim
-
Fans vandalise India stadium after Messi's abrupt exit
-
Women sommeliers are cracking male-dominated wine world open
-
Exhibition of Franco-Chinese print master Zao Wou-Ki opens in Hong Kong
-
Myanmar junta denies killing civilians in hospital strike
-
Why SpaceX IPO plan is generating so much buzz
-
Thailand continues Cambodia strikes despite Trump truce calls
-
US envoy to meet Zelensky, Europe leaders in Berlin this weekend
-
North Korea acknowledges its troops cleared mines for Russia
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
T.Bondarenko--BTB