The China Mail - Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst

USD -
AED 3.67315
AFN 63.502706
ALL 82.273708
AMD 368.41983
ANG 1.79046
AOA 917.999765
ARS 1432.325699
AUD 1.42452
AWG 1.8
AZN 1.700977
BAM 1.695219
BBD 2.013062
BDT 122.940376
BGN 1.66992
BHD 0.37715
BIF 2990
BMD 1
BND 1.287845
BOB 6.906385
BRL 5.138902
BSD 0.999467
BTN 95.66054
BWP 13.564934
BYN 2.758689
BYR 19600
BZD 2.010202
CAD 1.398555
CDF 2292.999885
CHF 0.798245
CLF 0.023011
CLP 905.729547
CNY 6.77625
CNH 6.77314
COP 3503.43
CRC 456.265195
CUC 1
CUP 26.5
CVE 95.874986
CZK 20.946901
DJF 177.720102
DKK 6.472675
DOP 58.650501
DZD 133.325013
EGP 52.002598
ERN 15
ETB 157.491148
EUR 0.86604
FJD 2.218801
FKP 0.746898
GBP 0.747205
GEL 2.650051
GGP 0.746898
GHS 11.144
GIP 0.746898
GMD 73.000267
GNF 8755.081345
GTQ 7.618833
GYD 209.046428
HKD 7.83706
HNL 26.720521
HRK 6.522036
HTG 130.638849
HUF 307.010981
IDR 17962
ILS 2.96371
IMP 0.746898
INR 95.50795
IQD 1309.335494
IRR 1375174.999803
ISK 124.539535
JEP 0.746898
JMD 158.132641
JOD 0.709002
JPY 160.197998
KES 129.649843
KGS 87.450301
KHR 4025.274982
KMF 426.999919
KPW 899.855249
KRW 1523.669926
KWD 0.30851
KYD 0.832965
KZT 488.144819
LAK 22002.834322
LBP 89505.207092
LKR 333.07764
LRD 181.910375
LSL 16.509654
LTL 2.95274
LVL 0.60489
LYD 6.384509
MAD 9.271147
MDL 17.401253
MGA 4195.143515
MKD 53.363978
MMK 2099.64258
MNT 3578.820105
MOP 8.067989
MRU 39.620188
MUR 47.869442
MVR 15.449885
MWK 1736.999796
MXN 17.33325
MYR 4.0673
MZN 63.89768
NAD 16.509725
NGN 1360.960205
NIO 36.785036
NOK 9.50287
NPR 153.058854
NZD 1.72139
OMR 0.384524
PAB 0.999467
PEN 3.400276
PGK 4.375374
PHP 61.272034
PKR 278.133264
PLN 3.68845
PYG 6140.111378
QAR 3.643881
RON 4.5371
RSD 101.622014
RUB 71.975352
RWF 1467.786532
SAR 3.754683
SBD 8.045573
SCR 14.089811
SDG 600.498309
SEK 9.488205
SGD 1.286565
SHP 0.746601
SLE 24.65012
SLL 20969.502105
SOS 571.200735
SRD 37.337503
STD 20697.981008
STN 21.235747
SVC 8.745547
SYP 110.532098
SZL 16.505738
THB 32.862009
TJS 9.320447
TMT 3.51
TND 2.934607
TOP 2.40776
TRY 46.153203
TTD 6.791972
TWD 31.604201
TZS 2619.997955
UAH 44.913108
UGX 3767.795619
UYU 40.373398
UZS 12003.675037
VES 566.973195
VND 26326.5
VUV 119.611663
WST 2.745884
XAF 568.563157
XAG 0.015274
XAU 0.000242
XCD 2.70255
XCG 1.801311
XDR 0.706825
XOF 568.553301
XPF 103.369072
YER 238.649507
ZAR 16.39015
ZMK 9001.156022
ZMW 17.265963
ZWL 321.999592
  • RBGPF

    0.0000

    60.72

    0%

  • CMSC

    0.0500

    22.35

    +0.22%

  • BCC

    2.3500

    70.66

    +3.33%

  • RYCEF

    0.5600

    17.05

    +3.28%

  • RIO

    4.5800

    103.64

    +4.42%

  • BTI

    0.2700

    61.39

    +0.44%

  • GSK

    1.6900

    52.86

    +3.2%

  • BCE

    -0.1400

    24.57

    -0.57%

  • RELX

    -0.8700

    33.11

    -2.63%

  • NGG

    1.1400

    81.52

    +1.4%

  • VOD

    0.2100

    15.26

    +1.38%

  • JRI

    -0.0300

    12.83

    -0.23%

  • AZN

    3.3200

    182.28

    +1.82%

  • CMSD

    0.0100

    22.3

    +0.04%

  • BP

    -0.2700

    42.68

    -0.63%

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst

An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.

Text size:

The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.

The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."

"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."

The committee said it had asked Citizen Lab for its report "to understand their concerns better."

Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.

"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.

"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."

The flaws affect SSL certificates, which allow online entities to communicate securely.

MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.

While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."

MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.

These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.

Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.

O.Tse--ThChM