The China Mail - Beijing Olympics organisers say app security flaws 'fixed'

USD -
AED 3.672504
AFN 69.456103
ALL 84.764831
AMD 381.290295
ANG 1.789623
AOA 916.000367
ARS 1179.376574
AUD 1.538935
AWG 1.8025
AZN 1.70397
BAM 1.692527
BBD 2.010212
BDT 121.665008
BGN 1.696633
BHD 0.375579
BIF 2964.389252
BMD 1
BND 1.278698
BOB 6.879841
BRL 5.543904
BSD 0.99563
BTN 85.673489
BWP 13.382372
BYN 3.258189
BYR 19600
BZD 1.999913
CAD 1.35865
CDF 2877.000362
CHF 0.812438
CLF 0.024131
CLP 926.026567
CNY 7.181604
CNH 7.18941
COP 4135.519882
CRC 501.838951
CUC 1
CUP 26.5
CVE 95.422093
CZK 21.500904
DJF 177.292199
DKK 6.45704
DOP 58.803167
DZD 130.034183
EGP 49.707931
ERN 15
ETB 134.317771
EUR 0.865404
FJD 2.24825
FKP 0.736781
GBP 0.737708
GEL 2.740391
GGP 0.736781
GHS 10.254857
GIP 0.736781
GMD 70.503851
GNF 8627.060707
GTQ 7.650902
GYD 208.299078
HKD 7.849415
HNL 25.985029
HRK 6.522704
HTG 130.569859
HUF 348.50504
IDR 16299.3
ILS 3.620404
IMP 0.736781
INR 86.184504
IQD 1304.227424
IRR 42100.000352
ISK 124.650386
JEP 0.736781
JMD 159.404613
JOD 0.70904
JPY 144.10604
KES 128.631388
KGS 87.450384
KHR 3992.038423
KMF 426.503794
KPW 899.999993
KRW 1367.140383
KWD 0.30622
KYD 0.829648
KZT 510.665917
LAK 21481.545584
LBP 89206.525031
LKR 298.109126
LRD 199.125957
LSL 17.917528
LTL 2.95274
LVL 0.60489
LYD 5.439834
MAD 9.103111
MDL 17.04989
MGA 4495.694691
MKD 53.251698
MMK 2099.702644
MNT 3581.705956
MOP 8.049154
MRU 39.525767
MUR 45.510378
MVR 15.405039
MWK 1726.364069
MXN 18.95075
MYR 4.245504
MZN 63.950377
NAD 17.917528
NGN 1542.440377
NIO 36.640561
NOK 9.912804
NPR 137.077582
NZD 1.661972
OMR 0.384259
PAB 0.99563
PEN 3.593613
PGK 4.159058
PHP 56.090375
PKR 282.254944
PLN 3.698316
PYG 7944.268963
QAR 3.631864
RON 4.350504
RSD 101.423565
RUB 79.779066
RWF 1437.670373
SAR 3.753593
SBD 8.347391
SCR 14.210372
SDG 600.503676
SEK 9.483995
SGD 1.281904
SHP 0.785843
SLE 22.050371
SLL 20969.503664
SOS 568.99312
SRD 37.528038
STD 20697.981008
SVC 8.711869
SYP 13001.852669
SZL 17.905759
THB 32.405038
TJS 10.055644
TMT 3.5
TND 2.945956
TOP 2.342104
TRY 39.40328
TTD 6.751763
TWD 29.520367
TZS 2573.66622
UAH 41.29791
UGX 3587.901865
UYU 40.932889
UZS 12650.253126
VES 102.167038
VND 26075
VUV 119.102168
WST 2.619186
XAF 567.657825
XAG 0.027532
XAU 0.000291
XCD 2.70255
XDR 0.705984
XOF 567.657825
XPF 103.206265
YER 243.350363
ZAR 17.92535
ZMK 9001.203587
ZMW 24.069058
ZWL 321.999592
  • CMSC

    0.0900

    22.314

    +0.4%

  • CMSD

    0.0250

    22.285

    +0.11%

  • RBGPF

    0.0000

    69.04

    0%

  • SCS

    0.0400

    10.74

    +0.37%

  • RELX

    0.0300

    53

    +0.06%

  • RIO

    -0.1400

    59.33

    -0.24%

  • GSK

    0.1300

    41.45

    +0.31%

  • NGG

    0.2700

    71.48

    +0.38%

  • BP

    0.1750

    30.4

    +0.58%

  • BTI

    0.7150

    48.215

    +1.48%

  • BCC

    0.7900

    91.02

    +0.87%

  • JRI

    0.0200

    13.13

    +0.15%

  • VOD

    0.0100

    9.85

    +0.1%

  • BCE

    -0.0600

    22.445

    -0.27%

  • RYCEF

    0.1000

    12

    +0.83%

  • AZN

    -0.1200

    73.71

    -0.16%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

H.Ng--ThChM