Dubai Telegraph - Beijing Olympics organisers say app security flaws 'fixed'

EUR -
AED 4.172469
AFN 82.254285
ALL 99.443091
AMD 442.669245
ANG 2.033568
AOA 1042.821867
ARS 1220.13733
AUD 1.80657
AWG 2.044748
AZN 1.935661
BAM 1.955664
BBD 2.288841
BDT 137.74043
BGN 1.961167
BHD 0.42777
BIF 3370.065862
BMD 1.135971
BND 1.496896
BOB 7.833456
BRL 6.659749
BSD 1.133621
BTN 97.596219
BWP 15.810902
BYN 3.709842
BYR 22265.033118
BZD 2.277042
CAD 1.575536
CDF 3265.353315
CHF 0.926352
CLF 0.02877
CLP 1119.192243
CNY 8.283619
CNH 8.27647
COP 4910.258856
CRC 581.659589
CUC 1.135971
CUP 30.103234
CVE 110.25734
CZK 25.124845
DJF 201.665989
DKK 7.469696
DOP 70.015136
DZD 149.546094
EGP 58.259952
ERN 17.039566
ETB 147.302266
FJD 2.589451
FKP 0.870523
GBP 0.868347
GEL 3.135724
GGP 0.870523
GHS 17.570779
GIP 0.870523
GMD 81.226307
GNF 9813.318212
GTQ 8.743393
GYD 237.163523
HKD 8.810422
HNL 29.369959
HRK 7.534333
HTG 148.329695
HUF 409.938323
IDR 19081.076584
ILS 4.222235
IMP 0.870523
INR 97.663012
IQD 1484.996829
IRR 47824.382762
ISK 145.295033
JEP 0.870523
JMD 179.687516
JOD 0.805522
JPY 163.035006
KES 146.799801
KGS 99.341107
KHR 4541.684463
KMF 499.263598
KPW 1022.294878
KRW 1614.4251
KWD 0.348107
KYD 0.944734
KZT 585.8193
LAK 24559.293723
LBP 101571.343247
LKR 338.136508
LRD 226.724248
LSL 21.868981
LTL 3.354228
LVL 0.687138
LYD 6.299562
MAD 10.546067
MDL 20.093604
MGA 5113.644725
MKD 61.530725
MMK 2385.0762
MNT 3994.555643
MOP 9.055971
MRU 44.687895
MUR 49.87338
MVR 17.498202
MWK 1965.663434
MXN 23.067966
MYR 5.023837
MZN 72.60034
NAD 21.868981
NGN 1814.225757
NIO 41.717102
NOK 12.117749
NPR 156.154151
NZD 1.949496
OMR 0.437393
PAB 1.133621
PEN 4.231206
PGK 4.684675
PHP 64.754939
PKR 317.835518
PLN 4.289579
PYG 9069.369898
QAR 4.133413
RON 4.979761
RSD 117.211857
RUB 94.489935
RWF 1633.886484
SAR 4.263339
SBD 9.490317
SCR 16.273869
SDG 682.154808
SEK 11.102759
SGD 1.499032
SHP 0.892695
SLE 25.877842
SLL 23820.749672
SOS 647.85499
SRD 42.083228
STD 23512.307787
SVC 9.919311
SYP 14769.561249
SZL 21.857481
THB 38.057346
TJS 12.316644
TMT 3.975899
TND 3.411763
TOP 2.660562
TRY 43.085154
TTD 7.708464
TWD 36.779567
TZS 3038.088926
UAH 46.92884
UGX 4165.710584
USD 1.135971
UYU 49.176583
UZS 14700.978637
VES 87.603875
VND 29259.775028
VUV 140.62449
WST 3.205325
XAF 655.91143
XAG 0.035181
XAU 0.000351
XCD 3.070019
XDR 0.815743
XOF 655.91143
XPF 119.331742
YER 278.657784
ZAR 21.729241
ZMK 10225.106937
ZMW 31.995777
ZWL 365.782223
  • RBGPF

    62.0100

    62.01

    +100%

  • RELX

    0.1000

    49.12

    +0.2%

  • BCC

    0.9800

    95.66

    +1.02%

  • NGG

    2.4700

    68.06

    +3.63%

  • GSK

    1.0400

    34.64

    +3%

  • BTI

    1.0200

    41.57

    +2.45%

  • RYCEF

    -0.0100

    9.12

    -0.11%

  • SCS

    -0.0300

    10.18

    -0.29%

  • CMSC

    -0.3500

    21.8

    -1.61%

  • AZN

    1.4200

    66.29

    +2.14%

  • RIO

    1.9900

    56.86

    +3.5%

  • JRI

    0.1450

    11.91

    +1.22%

  • CMSD

    -0.3000

    21.9

    -1.37%

  • BCE

    0.3800

    21.36

    +1.78%

  • VOD

    0.2800

    8.73

    +3.21%

  • BP

    0.3600

    26.59

    +1.35%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

A.El-Nayady--DT