The China Mail - Beijing Olympics organisers say app security flaws 'fixed'

USD -
AED 3.673031
AFN 69.00009
ALL 83.749772
AMD 383.559735
ANG 1.789783
AOA 917.000232
ARS 1313.806102
AUD 1.52896
AWG 1.8015
AZN 1.696617
BAM 1.670289
BBD 2.020291
BDT 121.578055
BGN 1.669899
BHD 0.377052
BIF 2955
BMD 1
BND 1.280733
BOB 6.914192
BRL 5.397103
BSD 1.000623
BTN 87.500907
BWP 13.354
BYN 3.308539
BYR 19600
BZD 2.009949
CAD 1.376995
CDF 2890.000042
CHF 0.805503
CLF 0.024296
CLP 953.129797
CNY 7.17455
CNH 7.181485
COP 4023.57
CRC 506.076159
CUC 1
CUP 26.5
CVE 94.549995
CZK 20.895602
DJF 177.719964
DKK 6.377505
DOP 61.650177
DZD 129.782864
EGP 48.323004
ERN 15
ETB 139.875011
EUR 0.85456
FJD 2.24875
FKP 0.740335
GBP 0.736935
GEL 2.694991
GGP 0.740335
GHS 10.524985
GIP 0.740335
GMD 72.500499
GNF 8674.99995
GTQ 7.674834
GYD 209.338372
HKD 7.849935
HNL 26.34985
HRK 6.436204
HTG 130.976882
HUF 337.782499
IDR 16104
ILS 3.379795
IMP 0.740335
INR 87.45045
IQD 1310
IRR 42125.000214
ISK 122.370232
JEP 0.740335
JMD 160.359029
JOD 0.709011
JPY 147.479498
KES 129.501049
KGS 87.350613
KHR 4007.000207
KMF 420.496888
KPW 899.937534
KRW 1379.540161
KWD 0.30548
KYD 0.833846
KZT 538.471721
LAK 21600.000095
LBP 89549.999875
LKR 301.058556
LRD 201.501099
LSL 17.57971
LTL 2.95274
LVL 0.60489
LYD 5.424967
MAD 9.033019
MDL 16.705097
MGA 4439.99983
MKD 52.55472
MMK 2099.235265
MNT 3596.390082
MOP 8.090214
MRU 39.939797
MUR 45.63956
MVR 15.402749
MWK 1736.498405
MXN 18.64523
MYR 4.207501
MZN 63.960193
NAD 17.579897
NGN 1533.396617
NIO 36.749822
NOK 10.205055
NPR 140.001281
NZD 1.674635
OMR 0.384499
PAB 1.000576
PEN 3.52625
PGK 4.147399
PHP 56.667501
PKR 282.449834
PLN 3.63295
PYG 7494.865215
QAR 3.640502
RON 4.324406
RSD 100.138999
RUB 79.449318
RWF 1444
SAR 3.752333
SBD 8.230592
SCR 14.744178
SDG 600.496859
SEK 9.54839
SGD 1.280625
SHP 0.785843
SLE 23.204424
SLL 20969.49797
SOS 571.500141
SRD 37.548993
STD 20697.981008
STN 21.35
SVC 8.755396
SYP 13001.950021
SZL 17.580109
THB 32.337984
TJS 9.330344
TMT 3.51
TND 2.878497
TOP 2.3421
TRY 40.769703
TTD 6.795221
TWD 29.95399
TZS 2604.999941
UAH 41.545432
UGX 3560.296165
UYU 40.070542
UZS 12537.498292
VES 132.75255
VND 26290
VUV 119.550084
WST 2.658125
XAF 560.208896
XAG 0.025987
XAU 0.000298
XCD 2.70255
XCG 1.803361
XDR 0.702337
XOF 563.501522
XPF 102.598647
YER 240.274986
ZAR 17.519645
ZMK 9001.199513
ZMW 23.03905
ZWL 321.999592
  • CMSC

    0.0900

    23.17

    +0.39%

  • SCU

    0.0000

    12.72

    0%

  • RIO

    0.4700

    63.57

    +0.74%

  • SCS

    0.1700

    16.36

    +1.04%

  • JRI

    0.0200

    13.4

    +0.15%

  • BCC

    3.8900

    88.15

    +4.41%

  • RBGPF

    0.0000

    73.08

    0%

  • RYCEF

    -0.1000

    14.7

    -0.68%

  • CMSD

    0.1500

    23.71

    +0.63%

  • NGG

    0.2500

    70.53

    +0.35%

  • BTI

    -0.8100

    57.11

    -1.42%

  • BCE

    0.6100

    25.11

    +2.43%

  • RELX

    -0.0600

    47.77

    -0.13%

  • BP

    0.2400

    34.31

    +0.7%

  • AZN

    2.6000

    77.94

    +3.34%

  • VOD

    0.1100

    11.65

    +0.94%

  • GSK

    0.9100

    39.13

    +2.33%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

H.Ng--ThChM