-
Football, smoking and 'the boss': a G7 full of quirks
-
Spain logs third-warmest year on record in 2025
-
Queensland force State of Origin decider after rampant win
-
G7 leaders applaud Iran 'opportunity', host AI chiefs
-
'Heartbreaking': Afghan govt staff abandon smartphones
-
Gill, Kishan tons power India to 402 in Afghanistan ODI
-
Groundbreaking US astronaut Christina Koch wins top Spanish award
-
BBC eyes compulsory redundancies in cost-cutting drive
-
Trump threatens 'dropping bombs' if Iran doesn't 'behave'
-
EU lawmakers approve 'return hubs' migration reform
-
Oil steadies, stocks rise as US-Iran peace talks approach
-
Global data declaration targets illegal fishing
-
US not 'pulling away' from allies by cutting NATO commitments: Rutte
-
'I'm the boss', Trump tells G7 counterparts
-
Adidas runs out of letter 'V' as German fans snap up World Cup shirts
-
Van Aert out of Tour de France with elbow injury
-
Bernardo Silva signs two-year deal with Real Madrid
-
Louvre museum 'running out of steam', says new director
-
German grid connection deal to boost North Sea wind power
-
G7 leaders applaud Iran, Ukraine progress ahead of tackling AI
-
Sovereignty fears dog AI enthusiasm at France's Vivatech
-
England enter World Cup fray as Ronaldo makes history
-
US military footprint growing in Australia: defence minister
-
France braces for heatwave with canal swimming allowed in Paris
-
Japan puts the heat on suspected ice cream cartel
-
Sovereignty fears to dog AI enthusiasm at France's Vivatech
-
MEXC May Report: SPACEX Launchpad Oversubscribed 15.5x, US Equity Futures Volume Jumps 85%
-
MEXC Prediction Markets Launches Combo to Enable Multi-Event Combination Trading
-
'We have always won': Ebola pioneer still on front line at 84
-
World Cup goals record 'just a number', says Messi
-
Australian far-right leader slams media, 'radical Islam' in testy press briefing
-
Stuffed toys and surfboards: Japan used goods market booms overseas
-
Messi salutes 'beautiful moment' after tying World Cup goals record
-
Putin hosts ASEAN leaders amid G7 pressure on Ukraine war
-
Iranian tankers exit US blockade zone ahead of peace talks
-
'Unstable' Tasmanian devil found after 15 days on the run
-
Magical Messi equals World Cup goals record as Argentina win
-
Messi equals World Cup goalscoring record in Argentina romp
-
Restore Britain, the hard-right party troubling Nigel Farage
-
Trap, neuter, release: Jakarta battles cat-astrophic stray numbers
-
Cuba's historic homes teeter on brink as economy collapses
-
EU lawmakers to approve migrant detention and deportation boost
-
Ronaldo as excited for sixth World Cup as his first, says Martinez
-
Macron winds up G7 with AI, Trump dinner
-
Norway coach hails Haaland after World Cup double
-
US Fed set to hold rates steady at Warsh's first meeting in charge
-
Argentina's Messi plays in record sixth World Cup
-
Kane tells England 'be free in the mind' for World Cup title bid
-
France and two-goal Mbappe roar into World Cup as Messi prepares
-
Trump ballroom cost soars to $600 mn, half from taxpayers: report
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
T.Bondarenko--BTB