The Fort Worth Press - Beijing Olympics organisers say app security flaws 'fixed'

USD -
AED 3.673042
AFN 65.000368
ALL 82.925041
AMD 381.210403
ANG 1.790403
AOA 917.000367
ARS 1462.800504
AUD 1.492983
AWG 1.78075
AZN 1.70397
BAM 1.679721
BBD 2.014497
BDT 122.221125
BGN 1.666695
BHD 0.378423
BIF 2963
BMD 1
BND 1.286619
BOB 6.926522
BRL 5.371804
BSD 1.000292
BTN 90.082964
BWP 13.42019
BYN 2.928733
BYR 19600
BZD 2.011569
CAD 1.39175
CDF 2260.000362
CHF 0.800925
CLF 0.022818
CLP 895.130396
CNY 6.97735
CNH 6.976041
COP 3713
CRC 497.352634
CUC 1
CUP 26.5
CVE 95.203894
CZK 20.872604
DJF 177.720393
DKK 6.42138
DOP 63.250393
DZD 130.596829
EGP 47.394835
ERN 15
ETB 155.350392
EUR 0.859504
FJD 2.275104
FKP 0.745654
GBP 0.745879
GEL 2.69504
GGP 0.745654
GHS 10.72504
GIP 0.745654
GMD 74.000355
GNF 8741.000355
GTQ 7.669383
GYD 209.229924
HKD 7.79525
HNL 26.46504
HRK 6.474704
HTG 130.997879
HUF 331.430388
IDR 16842.65
ILS 3.14804
IMP 0.745654
INR 90.26835
IQD 1310
IRR 42125.000158
ISK 126.480386
JEP 0.745654
JMD 158.396029
JOD 0.70904
JPY 157.88404
KES 129.000351
KGS 87.443504
KHR 4030.00035
KMF 424.00035
KPW 900.02684
KRW 1457.330383
KWD 0.30749
KYD 0.833502
KZT 510.950222
LAK 21600.000349
LBP 89537.871821
LKR 309.217081
LRD 180.150382
LSL 16.510381
LTL 2.95274
LVL 0.60489
LYD 5.430381
MAD 9.232504
MDL 16.953447
MGA 4582.503755
MKD 52.894615
MMK 2100.1161
MNT 3559.876367
MOP 8.031502
MRU 38.260379
MUR 46.410378
MVR 15.460378
MWK 1737.000345
MXN 17.978104
MYR 4.093504
MZN 63.903729
NAD 16.503727
NGN 1429.440377
NIO 36.775039
NOK 10.096604
NPR 144.132399
NZD 1.744288
OMR 0.385979
PAB 1.000202
PEN 3.363039
PGK 4.26375
PHP 59.296038
PKR 280.000342
PLN 3.62025
PYG 6619.08688
QAR 3.64125
RON 4.373904
RSD 100.955038
RUB 79.284922
RWF 1455
SAR 3.750336
SBD 8.130216
SCR 13.912744
SDG 601.503676
SEK 9.206704
SGD 1.287038
SHP 0.750259
SLE 24.125038
SLL 20969.503664
SOS 571.503662
SRD 38.191038
STD 20697.981008
STN 21.45
SVC 8.751551
SYP 11059.574895
SZL 16.525038
THB 31.460369
TJS 9.311857
TMT 3.5
TND 2.897504
TOP 2.40776
TRY 42.951304
TTD 6.789108
TWD 31.608304
TZS 2497.503628
UAH 43.141369
UGX 3601.119929
UYU 38.93968
UZS 12125.000334
VES 324.98266
VND 26270
VUV 120.988544
WST 2.784016
XAF 563.360287
XAG 0.012513
XAU 0.000222
XCD 2.70255
XCG 1.802613
XDR 0.700294
XOF 562.503593
XPF 102.950363
YER 238.450363
ZAR 16.48803
ZMK 9001.203584
ZMW 19.378803
ZWL 321.999592
  • SCS

    0.0200

    16.14

    +0.12%

  • CMSD

    0.1900

    23.69

    +0.8%

  • NGG

    0.6400

    80.12

    +0.8%

  • JRI

    0.0600

    13.8

    +0.43%

  • BCC

    5.0200

    83.05

    +6.04%

  • RBGPF

    0.0000

    81.57

    0%

  • CMSC

    0.2600

    23.27

    +1.12%

  • BCE

    -0.0100

    23.74

    -0.04%

  • GSK

    0.1700

    50.39

    +0.34%

  • AZN

    0.6400

    94.65

    +0.68%

  • RIO

    -3.0600

    81.13

    -3.77%

  • BTI

    1.4000

    55.19

    +2.54%

  • RYCEF

    0.3300

    17.45

    +1.89%

  • BP

    0.1600

    34.29

    +0.47%

  • VOD

    -0.3200

    13.5

    -2.37%

  • RELX

    0.7900

    43.14

    +1.83%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

W.Lane--TFWP