Dubai Telegraph - Beijing Olympics organisers say app security flaws 'fixed'

EUR -
AED 4.228897
AFN 72.544603
ALL 96.183662
AMD 434.229157
ANG 2.061288
AOA 1055.928483
ARS 1608.200783
AUD 1.625385
AWG 2.075586
AZN 1.956154
BAM 1.959533
BBD 2.316513
BDT 141.128872
BGN 1.968276
BHD 0.434856
BIF 3414.980192
BMD 1.151504
BND 1.471235
BOB 7.976196
BRL 6.034567
BSD 1.150196
BTN 106.089037
BWP 15.682946
BYN 3.426227
BYR 22569.474238
BZD 2.313207
CAD 1.576633
CDF 2608.156684
CHF 0.906193
CLF 0.026536
CLP 1047.776192
CNY 8.010147
CNH 7.929762
COP 4265.757296
CRC 540.24567
CUC 1.151504
CUP 30.51485
CVE 110.475953
CZK 24.447343
DJF 204.811085
DKK 7.472275
DOP 70.205887
DZD 152.237997
EGP 60.200932
ERN 17.272557
ETB 181.174658
FJD 2.547069
FKP 0.865734
GBP 0.863685
GEL 3.131737
GGP 0.865734
GHS 12.518905
GIP 0.865734
GMD 84.639353
GNF 10083.517103
GTQ 8.815834
GYD 240.758681
HKD 9.02418
HNL 30.449068
HRK 7.536477
HTG 150.750475
HUF 391.080654
IDR 19547.928299
ILS 3.595824
IMP 0.865734
INR 106.424571
IQD 1506.670433
IRR 1521194.078995
ISK 143.201496
JEP 0.865734
JMD 180.925476
JOD 0.816406
JPY 183.220375
KES 149.234346
KGS 100.698929
KHR 4611.886464
KMF 493.994725
KPW 1036.403966
KRW 1714.0307
KWD 0.353201
KYD 0.958426
KZT 555.408136
LAK 24682.022961
LBP 102995.121174
LKR 358.152334
LRD 210.470063
LSL 19.349464
LTL 3.400091
LVL 0.696533
LYD 7.372077
MAD 10.805486
MDL 20.012126
MGA 4788.142922
MKD 61.653234
MMK 2418.334396
MNT 4116.047513
MOP 9.275872
MRU 45.857361
MUR 53.68307
MVR 17.80246
MWK 1994.007542
MXN 20.353348
MYR 4.511602
MZN 73.586935
NAD 19.349464
NGN 1575.601776
NIO 42.322837
NOK 11.08236
NPR 169.747291
NZD 1.972077
OMR 0.442684
PAB 1.150191
PEN 3.970264
PGK 4.959556
PHP 68.741757
PKR 321.293307
PLN 4.26821
PYG 7465.417237
QAR 4.204128
RON 5.094269
RSD 117.401537
RUB 94.518744
RWF 1678.605284
SAR 4.321598
SBD 9.271517
SCR 16.144156
SDG 692.054169
SEK 10.733385
SGD 1.471432
SHP 0.863926
SLE 28.330837
SLL 24146.471141
SOS 656.152919
SRD 43.263728
STD 23833.803528
STN 24.547513
SVC 10.064174
SYP 127.674013
SZL 19.33492
THB 37.259785
TJS 11.041287
TMT 4.036021
TND 3.397187
TOP 2.772544
TRY 50.902244
TTD 7.79986
TWD 36.722026
TZS 3002.549389
UAH 50.705321
UGX 4342.272682
USD 1.151504
UYU 46.75888
UZS 13906.49396
VES 513.854247
VND 30264.398299
VUV 137.705052
WST 3.171483
XAF 657.211941
XAG 0.014246
XAU 0.000229
XCD 3.111996
XCG 2.072849
XDR 0.817361
XOF 657.211941
XPF 119.331742
YER 274.636692
ZAR 19.256299
ZMK 10364.926801
ZMW 22.398673
ZWL 370.78375
  • RBGPF

    0.1000

    82.5

    +0.12%

  • CMSD

    -0.0400

    22.95

    -0.17%

  • CMSC

    0.0000

    22.99

    0%

  • BCC

    1.7200

    71.72

    +2.4%

  • NGG

    -0.0100

    90.89

    -0.01%

  • RIO

    2.0300

    89.86

    +2.26%

  • JRI

    -0.0500

    12.54

    -0.4%

  • AZN

    2.1100

    192.01

    +1.1%

  • RELX

    0.3300

    34.47

    +0.96%

  • BCE

    0.6521

    25.9

    +2.52%

  • GSK

    0.3800

    53.77

    +0.71%

  • BP

    0.2300

    42.9

    +0.54%

  • RYCEF

    0.3800

    16.5

    +2.3%

  • VOD

    0.1900

    14.6

    +1.3%

  • BTI

    1.0100

    60.94

    +1.66%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

A.El-Nayady--DT