Zürcher Nachrichten - Beijing Olympics organisers say app security flaws 'fixed'

EUR -
AED 4.049778
AFN 78.834299
ALL 99.033342
AMD 431.456343
ANG 1.973823
AOA 1005.540147
ARS 1184.510488
AUD 1.740106
AWG 1.984619
AZN 1.871047
BAM 1.951157
BBD 2.225918
BDT 133.95119
BGN 1.953417
BHD 0.415629
BIF 3226.660051
BMD 1.102566
BND 1.473074
BOB 7.618042
BRL 6.190801
BSD 1.102437
BTN 94.108603
BWP 15.256919
BYN 3.607729
BYR 21610.297969
BZD 2.214448
CAD 1.554541
CDF 3167.672699
CHF 0.949657
CLF 0.027281
CLP 1046.908381
CNY 8.028391
CNH 8.030442
COP 4581.504452
CRC 555.45727
CUC 1.102566
CUP 29.218005
CVE 110.006211
CZK 25.045922
DJF 195.947771
DKK 7.461959
DOP 69.623267
DZD 146.912551
EGP 55.769964
ERN 16.538493
ETB 145.130438
FJD 2.566609
FKP 0.849767
GBP 0.842206
GEL 3.042781
GGP 0.849767
GHS 17.089472
GIP 0.849767
GMD 78.830087
GNF 9541.515201
GTQ 8.509592
GYD 230.665979
HKD 8.575705
HNL 28.207398
HRK 7.54001
HTG 144.267713
HUF 403.661068
IDR 18465.889357
ILS 4.082247
IMP 0.849767
INR 94.030872
IQD 1444.233926
IRR 46431.844181
ISK 144.314781
JEP 0.849767
JMD 173.672773
JOD 0.781606
JPY 161.04578
KES 142.506807
KGS 95.60528
KHR 4409.646484
KMF 500.014042
KPW 992.369183
KRW 1600.661596
KWD 0.339262
KYD 0.918627
KZT 552.612033
LAK 23885.559894
LBP 98786.765454
LKR 327.39557
LRD 220.466371
LSL 20.781097
LTL 3.255591
LVL 0.666932
LYD 5.33219
MAD 10.487244
MDL 19.686991
MGA 5027.940557
MKD 61.511679
MMK 2314.787019
MNT 3851.769118
MOP 8.833576
MRU 43.813776
MUR 50.023376
MVR 16.990372
MWK 1911.842309
MXN 22.023316
MYR 4.897654
MZN 70.451818
NAD 20.780251
NGN 1695.23982
NIO 40.564638
NOK 11.404074
NPR 150.576289
NZD 1.901293
OMR 0.424466
PAB 1.102556
PEN 4.048086
PGK 4.549174
PHP 62.857624
PKR 309.248804
PLN 4.227851
PYG 8845.546281
QAR 4.019435
RON 4.978193
RSD 117.17297
RUB 92.685108
RWF 1572.964625
SAR 4.136492
SBD 9.180809
SCR 15.773594
SDG 662.092022
SEK 10.787111
SGD 1.473199
SHP 0.866444
SLE 25.171542
SLL 23120.263604
SOS 630.003648
SRD 40.298877
STD 22820.894741
SVC 9.647255
SYP 14336.339478
SZL 20.788701
THB 37.64133
TJS 12.001035
TMT 3.870007
TND 3.373498
TOP 2.582323
TRY 41.871279
TTD 7.474586
TWD 36.451059
TZS 2924.510568
UAH 45.517981
UGX 4017.56488
USD 1.102566
UYU 46.573677
UZS 14239.435486
VES 77.098718
VND 28451.721382
VUV 136.24344
WST 3.123386
XAF 654.272445
XAG 0.034516
XAU 0.000355
XCD 2.97974
XDR 0.825967
XOF 654.373081
XPF 119.331742
YER 270.845622
ZAR 20.688194
ZMK 9924.417531
ZMW 30.622794
ZWL 355.025874
  • RIO

    -1.4700

    58.43

    -2.52%

  • CMSC

    -0.2400

    22.26

    -1.08%

  • SCS

    -0.7200

    10.74

    -6.7%

  • BTI

    1.6700

    41.92

    +3.98%

  • RBGPF

    -0.2800

    67.72

    -0.41%

  • BCC

    -7.4400

    94.63

    -7.86%

  • BCE

    0.8400

    22.66

    +3.71%

  • CMSD

    -0.1600

    22.67

    -0.71%

  • RYCEF

    0.0200

    9.8

    +0.2%

  • NGG

    3.6100

    69.39

    +5.2%

  • JRI

    -0.2200

    12.82

    -1.72%

  • GSK

    1.3700

    39.01

    +3.51%

  • BP

    -2.4700

    31.34

    -7.88%

  • RELX

    0.4600

    51.44

    +0.89%

  • VOD

    0.2500

    9.37

    +2.67%

  • AZN

    1.7000

    73.92

    +2.3%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

W.Vogt--NZN