Zürcher Nachrichten - Beijing Olympics organisers say app security flaws 'fixed'

EUR -
AED 4.264049
AFN 73.147768
ALL 95.899577
AMD 434.940868
ANG 2.078014
AOA 1064.70679
ARS 1643.800847
AUD 1.644829
AWG 2.09284
AZN 1.971342
BAM 1.954153
BBD 2.326639
BDT 141.28091
BGN 1.913043
BHD 0.438344
BIF 3431.318986
BMD 1.161076
BND 1.479215
BOB 8.011247
BRL 6.042468
BSD 1.155231
BTN 106.563011
BWP 15.698835
BYN 3.376554
BYR 22757.095403
BZD 2.323242
CAD 1.578721
CDF 2507.925146
CHF 0.903184
CLF 0.026915
CLP 1062.756777
CNY 8.024321
CNH 7.999664
COP 4369.536479
CRC 549.938809
CUC 1.161076
CUP 30.768522
CVE 110.172133
CZK 24.357117
DJF 205.707489
DKK 7.471369
DOP 68.992142
DZD 152.726795
EGP 61.306222
ERN 17.416144
ETB 177.399429
FJD 2.562609
FKP 0.865672
GBP 0.865159
GEL 3.16999
GGP 0.865672
GHS 12.452503
GIP 0.865672
GMD 84.758618
GNF 10126.507689
GTQ 8.860684
GYD 241.676284
HKD 9.083088
HNL 30.576358
HRK 7.530856
HTG 151.339825
HUF 387.322337
IDR 19616.384022
ILS 3.601764
IMP 0.865672
INR 106.676613
IQD 1513.330888
IRR 1533665.679761
ISK 145.11133
JEP 0.865672
JMD 180.967457
JOD 0.823226
JPY 183.295679
KES 149.296344
KGS 101.53644
KHR 4636.012317
KMF 493.457234
KPW 1044.96832
KRW 1714.119846
KWD 0.357159
KYD 0.962693
KZT 575.247585
LAK 24746.14078
LBP 103446.002448
LKR 359.776734
LRD 210.828642
LSL 19.368574
LTL 3.428356
LVL 0.702323
LYD 7.377813
MAD 10.848356
MDL 20.019125
MGA 4797.976312
MKD 61.598992
MMK 2438.34281
MNT 4143.989737
MOP 9.299961
MRU 46.117325
MUR 53.583555
MVR 17.938836
MWK 2003.12014
MXN 20.538795
MYR 4.570028
MZN 74.204369
NAD 19.368574
NGN 1621.141029
NIO 42.514347
NOK 11.143494
NPR 170.499016
NZD 1.964582
OMR 0.446429
PAB 1.155226
PEN 4.02181
PGK 4.977825
PHP 68.770232
PKR 324.779233
PLN 4.253789
PYG 7433.733896
QAR 4.212921
RON 5.097011
RSD 117.355815
RUB 90.861728
RWF 1688.876398
SAR 4.358995
SBD 9.341071
SCR 15.771799
SDG 697.225102
SEK 10.628011
SGD 1.481011
SHP 0.871108
SLE 28.475342
SLL 24347.188636
SOS 659.044473
SRD 43.734267
STD 24031.935125
STN 24.479471
SVC 10.107524
SYP 128.39172
SZL 19.381746
THB 36.852948
TJS 11.0727
TMT 4.063767
TND 3.397695
TOP 2.795593
TRY 51.173508
TTD 7.838393
TWD 36.954386
TZS 2995.577145
UAH 50.767525
UGX 4349.333824
USD 1.161076
UYU 46.212439
UZS 14083.128934
VES 502.311387
VND 30482.897077
VUV 138.603101
WST 3.181917
XAF 655.404541
XAG 0.013026
XAU 0.000224
XCD 3.137867
XCG 2.081954
XDR 0.815116
XOF 655.407361
XPF 119.331742
YER 277.027777
ZAR 19.012967
ZMK 10451.089069
ZMW 22.325181
ZWL 373.866094
  • RBGPF

    0.1000

    82.5

    +0.12%

  • RYCEF

    -0.0600

    16.9

    -0.36%

  • GSK

    1.0000

    55.51

    +1.8%

  • CMSC

    0.0350

    23.22

    +0.15%

  • AZN

    0.7300

    194.95

    +0.37%

  • BTI

    0.4600

    58.33

    +0.79%

  • BCE

    -0.1800

    25.88

    -0.7%

  • NGG

    0.5500

    90.41

    +0.61%

  • RELX

    0.0000

    35.68

    0%

  • RIO

    0.1400

    90.35

    +0.15%

  • BP

    0.2100

    40.65

    +0.52%

  • VOD

    -0.0300

    14.48

    -0.21%

  • CMSD

    -0.0400

    23.16

    -0.17%

  • BCC

    -0.8600

    74.49

    -1.15%

  • JRI

    0.0100

    12.58

    +0.08%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

W.Vogt--NZN