The China Mail - Beijing Olympics organisers say app security flaws 'fixed'

USD -
AED 3.673099
AFN 71.025985
ALL 86.949831
AMD 389.450198
ANG 1.80229
AOA 916.000203
ARS 1164.994971
AUD 1.56509
AWG 1.8025
AZN 1.701759
BAM 1.71838
BBD 2.002943
BDT 121.466383
BGN 1.71689
BHD 0.376938
BIF 2973.281671
BMD 1
BND 1.309998
BOB 6.907549
BRL 5.619785
BSD 0.999671
BTN 85.150724
BWP 13.648225
BYN 3.271568
BYR 19600
BZD 2.008127
CAD 1.382625
CDF 2878.000017
CHF 0.823455
CLF 0.024644
CLP 945.690037
CNY 7.269498
CNH 7.26815
COP 4197
CRC 505.37044
CUC 1
CUP 26.5
CVE 97.14957
CZK 21.893987
DJF 177.719903
DKK 6.552957
DOP 58.850011
DZD 132.28903
EGP 50.803098
ERN 15
ETB 131.849836
EUR 0.87781
FJD 2.290499
FKP 0.746656
GBP 0.74558
GEL 2.745035
GGP 0.746656
GHS 15.297057
GIP 0.746656
GMD 71.500526
GNF 8656.000059
GTQ 7.699235
GYD 209.77442
HKD 7.758725
HNL 25.824996
HRK 6.615497
HTG 130.805895
HUF 354.894502
IDR 16717.55
ILS 3.623935
IMP 0.746656
INR 85.17125
IQD 1310
IRR 42100.000123
ISK 128.229838
JEP 0.746656
JMD 158.360167
JOD 0.709201
JPY 142.322502
KES 129.504675
KGS 87.450007
KHR 4002.999591
KMF 432.250165
KPW 900.101764
KRW 1431.070178
KWD 0.30622
KYD 0.833088
KZT 511.373521
LAK 21619.999738
LBP 89549.99972
LKR 299.461858
LRD 199.525007
LSL 18.560047
LTL 2.95274
LVL 0.60489
LYD 5.455025
MAD 9.26225
MDL 17.204811
MGA 4510.00033
MKD 54.016924
MMK 2099.785163
MNT 3572.381038
MOP 7.988121
MRU 39.725023
MUR 45.195004
MVR 15.405152
MWK 1735.999776
MXN 19.551245
MYR 4.324002
MZN 64.009864
NAD 18.559961
NGN 1603.189819
NIO 36.702674
NOK 10.376205
NPR 136.24151
NZD 1.684466
OMR 0.384994
PAB 0.999671
PEN 3.666498
PGK 4.030502
PHP 56.070013
PKR 281.049939
PLN 3.74768
PYG 8005.869096
QAR 3.641499
RON 4.368904
RSD 102.971863
RUB 81.998675
RWF 1417
SAR 3.750917
SBD 8.361298
SCR 14.236431
SDG 600.498111
SEK 9.645325
SGD 1.307665
SHP 0.785843
SLE 22.75011
SLL 20969.483762
SOS 571.498004
SRD 36.850246
STD 20697.981008
SVC 8.747337
SYP 13001.961096
SZL 18.560117
THB 33.448986
TJS 10.556725
TMT 3.51
TND 2.974021
TOP 2.342102
TRY 38.48222
TTD 6.782788
TWD 32.336697
TZS 2689.999794
UAH 41.532203
UGX 3663.759967
UYU 42.093703
UZS 12944.999923
VES 86.54811
VND 26005
VUV 121.306988
WST 2.770092
XAF 576.326032
XAG 0.030331
XAU 0.000301
XCD 2.70255
XDR 0.715661
XOF 575.000121
XPF 105.250222
YER 245.049681
ZAR 18.54225
ZMK 9001.195433
ZMW 27.966701
ZWL 321.999592
  • RBGPF

    -0.4500

    63

    -0.71%

  • VOD

    0.0100

    9.58

    +0.1%

  • NGG

    0.1900

    73.04

    +0.26%

  • CMSC

    -0.0800

    22.24

    -0.36%

  • GSK

    0.9100

    38.97

    +2.34%

  • RELX

    0.4300

    53.79

    +0.8%

  • BTI

    0.4700

    42.86

    +1.1%

  • BP

    -1.0600

    28.07

    -3.78%

  • RYCEF

    -0.1300

    10.12

    -1.28%

  • RIO

    0.0100

    60.88

    +0.02%

  • JRI

    0.1300

    12.93

    +1.01%

  • SCS

    0.1500

    10.01

    +1.5%

  • CMSD

    -0.1300

    22.35

    -0.58%

  • BCC

    -0.8300

    94.5

    -0.88%

  • BCE

    0.1100

    21.92

    +0.5%

  • AZN

    1.7800

    71.71

    +2.48%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

H.Ng--ThChM