Berliner Boersenzeitung - Beijing Olympics organisers say app security flaws 'fixed'

EUR -
AED 4.298587
AFN 79.896722
ALL 97.290363
AMD 447.399374
ANG 2.094905
AOA 1073.330424
ARS 1519.860648
AUD 1.795917
AWG 2.107742
AZN 1.992538
BAM 1.956226
BBD 2.359994
BDT 142.010329
BGN 1.956029
BHD 0.441264
BIF 3485.629543
BMD 1.17048
BND 1.498614
BOB 8.076759
BRL 6.32516
BSD 1.168845
BTN 102.223395
BWP 15.642274
BYN 3.899316
BYR 22941.40764
BZD 2.347791
CAD 1.615707
CDF 3388.539825
CHF 0.943637
CLF 0.028765
CLP 1128.472421
CNY 8.406507
CNH 8.40723
COP 4718.216511
CRC 590.623618
CUC 1.17048
CUP 31.01772
CVE 110.289497
CZK 24.471342
DJF 208.143564
DKK 7.463291
DOP 71.945058
DZD 151.758198
EGP 56.534653
ERN 17.5572
ETB 164.619355
FJD 2.638025
FKP 0.863313
GBP 0.863188
GEL 3.148827
GGP 0.863313
GHS 12.681817
GIP 0.863313
GMD 84.908107
GNF 10134.121073
GTQ 8.964991
GYD 244.444295
HKD 9.160902
HNL 30.596404
HRK 7.533558
HTG 152.942011
HUF 394.747901
IDR 18947.027655
ILS 3.966932
IMP 0.863313
INR 102.301593
IQD 1531.120464
IRR 49291.885743
ISK 143.208308
JEP 0.863313
JMD 187.029145
JOD 0.829889
JPY 172.466709
KES 151.167876
KGS 102.275135
KHR 4681.979939
KMF 492.18837
KPW 1053.431983
KRW 1620.599475
KWD 0.357535
KYD 0.974004
KZT 633.142517
LAK 25298.403028
LBP 104668.907219
LKR 351.813635
LRD 234.349049
LSL 20.554778
LTL 3.456123
LVL 0.708012
LYD 6.321323
MAD 10.529794
MDL 19.490246
MGA 5200.088379
MKD 61.534473
MMK 2456.845352
MNT 4208.740114
MOP 9.419371
MRU 46.753786
MUR 53.232897
MVR 18.037555
MWK 2026.724194
MXN 21.93301
MYR 4.940642
MZN 74.787599
NAD 20.554602
NGN 1791.009604
NIO 43.009002
NOK 11.932482
NPR 163.557233
NZD 1.971252
OMR 0.450034
PAB 1.168855
PEN 4.166272
PGK 4.863018
PHP 66.786391
PKR 331.615207
PLN 4.2582
PYG 8559.791566
QAR 4.261447
RON 5.064316
RSD 117.166004
RUB 93.303586
RWF 1692.454231
SAR 4.39227
SBD 9.625762
SCR 17.256727
SDG 702.867751
SEK 11.181841
SGD 1.500668
SHP 0.919814
SLE 27.276359
SLL 24544.377599
SOS 667.9398
SRD 43.963588
STD 24226.57243
STN 24.505129
SVC 10.227141
SYP 15218.276003
SZL 20.548301
THB 37.98159
TJS 10.899381
TMT 4.108385
TND 3.416059
TOP 2.741382
TRY 47.873808
TTD 7.93066
TWD 35.09275
TZS 3051.169752
UAH 48.241397
UGX 4160.924205
USD 1.17048
UYU 46.760386
UZS 14706.077984
VES 158.565333
VND 30766.066318
VUV 139.464646
WST 3.237872
XAF 656.094321
XAG 0.030743
XAU 0.000349
XCD 3.163281
XCG 2.106541
XDR 0.815971
XOF 656.094321
XPF 119.331742
YER 281.237109
ZAR 20.581919
ZMK 10535.722215
ZMW 27.087669
ZWL 376.894077
  • RBGPF

    2.8400

    75.92

    +3.74%

  • SCS

    -0.0500

    16.15

    -0.31%

  • NGG

    -0.1300

    71.43

    -0.18%

  • BP

    0.1892

    34.33

    +0.55%

  • RELX

    0.2700

    47.96

    +0.56%

  • BTI

    -0.2700

    57.15

    -0.47%

  • RYCEF

    -0.2100

    14.71

    -1.43%

  • GSK

    0.5581

    39.36

    +1.42%

  • CMSC

    0.0300

    23.12

    +0.13%

  • RIO

    0.2000

    61.24

    +0.33%

  • AZN

    0.7000

    79.17

    +0.88%

  • JRI

    0.0835

    13.36

    +0.62%

  • CMSD

    0.0505

    23.34

    +0.22%

  • BCE

    0.2400

    25.61

    +0.94%

  • BCC

    -0.6300

    85.99

    -0.73%

  • VOD

    0.0300

    11.67

    +0.26%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

(U.Gruber--BBZ)