
Mandatory Chinese Olympics App Has 'devastating' Encryption Flaw: Analyst
Fahad Shabbir (@FahadShabbir) Published January 18, 2022 | 11:32 PM

An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday
Washington, (APP - UrduPoint / Pakistan Point News - 18th Jan, 2022 ) :An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities." "The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead." The committee said it had asked Citizen Lab for its report "to understand their concerns better." Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic." The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information." MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
Related Topics
Recent Stories

National Licensing Exam held at JSMU

Severe Hunger Threatens 18Mln People in Sahel During Summer - OCHA

Foolproof security for sensitive installations, foreign nationals : IGP

EPA KP launches crackdown against private hospitals, BBQ shops

OCS to stream TWG 2022 at Olympics.com

Rwp police arrest three POs
More Stories From World
-
Severe Hunger Threatens 18Mln People in Sahel During Summer - OCHA
2 seconds ago -
NATO's Intelligence Studying Protection of Russian IT Facilities - Patrushev
5 minutes ago -
Ukraine to Receive 15 Gepard Anti-Aircraft Weapons from Germany in July - Reports
5 minutes ago -
Germany rejects pooling EU debt to rebuild Ukraine
7 minutes ago -
Canada to Provide New $195Mln Loan to Ukraine - Freeland
7 minutes ago -
Belarus Not Going to Be Part of Armed Conflict in Ukraine - Prime Minister
7 minutes ago -
Russia Faced Real Cyberwar Unleashed After Start of Special Operation in Ukraine - Putin
7 minutes ago -
European Council President Endorses Albania for Accession Talks, Fast Integration
11 minutes ago -
Canada Sanctions 14 Russians, Bans Trade in Luxury Goods With Russia
11 minutes ago -
Blinken to Meet With Saudi Deputy Defense Chief in Washington on Friday - State Dept.
11 minutes ago -
UN rights chief begins landmark China trip from Monday
14 minutes ago -
US Climate Envoy Kerry Heads to Switzerland, Germany to Discuss Climate
14 minutes ago
Education - Urdu News - Car Prices - Breaking News - English News - Live Tv Channels - Urdu Horoscope - Horoscope in Urdu - Muslim Names in Urdu - Urdu Poetry - Love Poetry - Sad Poetry - Prize Bond - Mobile Prices in Pakistan - PTV Sports - English to Urdu - Big Ticket - Translate English to Urdu - Ramadan Calendar - Prayer Times - DDF Raffle - Islamic Calendar - Events - Today Islamic Date - Travel - UAE Raffles - Travel Guide - Arabic - Urdu Cooking Recipes - Directory - Pakistan Results - Past Papers - BISE - Schools in Pakistan - Academies & Tuition Centers
UrduPoint Network is the largest independent digital media house from Pakistan, catering the needs of its users since year 1997. We provide breaking news, Pakistani news, International news, Business news, Sports news, Urdu news and Live Urdu News
© 1997-2022, UrduPoint Network
All rights of the publication are reserved by UrduPoint.com. Reproduction without proper consent is not allowed.