> Cyber Security Strategy - From Idea to Mobile App RealityVinova Our team will brainstorm with you on where to begin, where to go, and how to get you there. Whether you have a spark of an idea or an existing app – we can help. Getting your mobile strategy right is what our unique services are all about. We’ll wrestle with business challenges, discover new opportunities that will help you define and refine your product ideas into mobile app reality.

Mandatory Beijing Winter Olympics app has ‘devastating’ encryption flaw, cyber security watchdog says

MY2022 Beijing Winter Olympics app screenshot

An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.

The “simple but devastating flaw” in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China’s capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.

MY2022 Beijing Winter Olympics app
A screenshot of the MY2022 app available for download from the iTunes store. Photo: Screenshot

The International Olympic Committee responded to the report by saying users can disable the app’s access to parts of their phones and that assessments from two unnamed cyber security organizations “confirmed that there are no critical vulnerabilities.”

“The user is in control over what the… app can access on their device,” the committee told AFP, adding that installing it on cellphones isn’t required “as accredited personnel can log on to the health monitoring system on the web page instead.”

The committee said it had asked Citizen Lab for its report “to understand their concerns better.”

Unclear who app shares information with

Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.

“China has a history of undermining encryption technology to perform political censorship and surveillance,” Knockel wrote. 

“As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence,” he continued, adding that “the case for the Chinese government sabotaging MY2022’s encryption is problematic.”

NEW REPORT

Cross-country Exposure: Analysis of the MY2022 Olympics apphttps://t.co/g3HydeD9Aa

— Citizen Lab (@citizenlab) January 18, 2022

The flaws affect SSL certificates, which allow online entities to communicate securely. 

MY2022 doesn’t authenticate SSL certificates, meaning other parties could access the app’s data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.

While the app is transparent about the medical information it collects as part of China’s efforts to screen Covid-19 cases, he said “it is unclear with whom or which organization(s) it shares this information.”

May violate Google, Apple policies

MY2022 also contains a list called “illegalwords.txt” of “politically sensitive” phrases in China, many of which relate to China’s political situation or its Tibetan and Uighur Muslim minorities.

These include keywords like “CCP evil” and Xi Jinping, China’s president, though Knockel said it was unclear if the list was being actively used for censorship purposes.

Because of these features, the app may violate both Google and Apple policies around smartphone software, and “also China’s own laws and national standards pertaining to privacy protection, providing potential avenues for future redress,” he wrote.

hkfp support us (1)

: 100% independent, governed by an ethics code & not-for-profit, Hong Kong Free Press is #PressingOn with impartial, award-winning, frontline coverage.

This content was originally published here.

Malcare WordPress Security

ruby on rails developer singapore,mobile application developer singapore,ios developer singapore,singapore website design,web development company singapore,website developer singapore,graphic designer in singapore,web design singapore,singapore web design,app development singapore,mobile apps singapore,website design singapore,mobile developer singapore,developers in singapore,design agency singapore,mobile game developer singapore,website designer singapore,web design company singapore,mobile app developer singapore,mobile apps development singapore,web application singapore,web development singapore,singapore app developer,web design services singapore,ios app development singapore,mobile application development singapore,web designer singapore,singapore web design services,singapore mobile app developer,android developer singapore,design firms in singapore,singapore web development,singapore mobile application developer,developer in singapore,app developer singapore,website development singapore,mobile app development singapore