The Fort Worth Press - Beijing Olympics organisers say app security flaws 'fixed'

USD -
AED 3.67315
AFN 62.508602
ALL 82.901415
AMD 377.320103
ANG 1.790083
AOA 917.000446
ARS 1397.45603
AUD 1.43901
AWG 1.80225
AZN 1.700706
BAM 1.687977
BBD 2.01456
BDT 122.73608
BGN 1.709309
BHD 0.377588
BIF 2967.5
BMD 1
BND 1.279846
BOB 6.926967
BRL 5.284006
BSD 1.000203
BTN 93.723217
BWP 13.705842
BYN 2.961192
BYR 19600
BZD 2.011712
CAD 1.378275
CDF 2277.500338
CHF 0.791905
CLF 0.023254
CLP 918.179579
CNY 6.892698
CNH 6.90259
COP 3705.94
CRC 466.057627
CUC 1
CUP 26.5
CVE 95.375002
CZK 21.140432
DJF 177.720285
DKK 6.458295
DOP 59.874991
DZD 132.744974
EGP 52.575297
ERN 15
ETB 157.374952
EUR 0.864097
FJD 2.2267
FKP 0.74705
GBP 0.748095
GEL 2.714977
GGP 0.74705
GHS 10.905012
GIP 0.74705
GMD 73.000221
GNF 8780.00019
GTQ 7.659677
GYD 209.341164
HKD 7.82618
HNL 26.519884
HRK 6.514398
HTG 131.152069
HUF 338.600498
IDR 16919
ILS 3.12535
IMP 0.74705
INR 94.12285
IQD 1310
IRR 1315049.999853
ISK 124.289869
JEP 0.74705
JMD 157.845451
JOD 0.708962
JPY 159.145006
KES 129.505219
KGS 87.448496
KHR 4015.000082
KMF 425.000187
KPW 899.971148
KRW 1501.980286
KWD 0.30663
KYD 0.833571
KZT 482.866057
LAK 21550.000246
LBP 89549.999464
LKR 314.407654
LRD 183.602089
LSL 16.849649
LTL 2.95274
LVL 0.60489
LYD 6.395021
MAD 9.361979
MDL 17.4948
MGA 4164.999916
MKD 53.274154
MMK 2099.628947
MNT 3568.971376
MOP 8.061125
MRU 40.110041
MUR 49.241272
MVR 15.450211
MWK 1736.999739
MXN 17.821301
MYR 3.956501
MZN 63.899281
NAD 16.820108
NGN 1379.906022
NIO 36.720467
NOK 9.72285
NPR 149.95361
NZD 1.723707
OMR 0.384506
PAB 1.000203
PEN 3.473017
PGK 4.305501
PHP 60.074007
PKR 279.249903
PLN 3.69763
PYG 6526.476592
QAR 3.643996
RON 4.402503
RSD 101.500987
RUB 80.49933
RWF 1460
SAR 3.753711
SBD 8.051718
SCR 14.408321
SDG 600.99945
SEK 9.363065
SGD 1.280945
SHP 0.750259
SLE 24.550032
SLL 20969.510825
SOS 571.500489
SRD 37.340116
STD 20697.981008
STN 21.63
SVC 8.752314
SYP 110.977546
SZL 16.849782
THB 32.743003
TJS 9.597587
TMT 3.5
TND 2.904952
TOP 2.40776
TRY 44.34383
TTD 6.795811
TWD 31.96405
TZS 2569.999672
UAH 43.928935
UGX 3745.690083
UYU 40.762429
UZS 12205.000254
VES 456.504355
VND 26357
VUV 119.458227
WST 2.748874
XAF 566.134155
XAG 0.014408
XAU 0.000228
XCD 2.70255
XCG 1.802694
XDR 0.704159
XOF 568.499098
XPF 103.401522
YER 238.649518
ZAR 17.08035
ZMK 9001.198055
ZMW 18.929544
ZWL 321.999592
  • RBGPF

    -13.5000

    69

    -19.57%

  • RYCEF

    -0.4500

    15.6

    -2.88%

  • CMSC

    -0.0100

    22.87

    -0.04%

  • RELX

    -1.3500

    32.46

    -4.16%

  • BTI

    -0.1600

    57.76

    -0.28%

  • NGG

    0.2700

    82.33

    +0.33%

  • AZN

    1.7100

    185.78

    +0.92%

  • RIO

    0.9300

    86.77

    +1.07%

  • GSK

    0.9600

    52.95

    +1.81%

  • VOD

    0.1800

    14.66

    +1.23%

  • BCE

    0.0700

    25.83

    +0.27%

  • CMSD

    -0.1100

    22.63

    -0.49%

  • JRI

    0.1800

    11.86

    +1.52%

  • BP

    1.2200

    44.79

    +2.72%

  • BCC

    1.6900

    73.57

    +2.3%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

W.Lane--TFWP