The Japan Times - Beijing Olympics organisers say app security flaws 'fixed'

EUR -
AED 4.184217
AFN 71.778596
ALL 94.26058
AMD 418.558169
ANG 2.039871
AOA 1044.771654
ARS 1684.037898
AUD 1.652409
AWG 2.052229
AZN 1.941395
BAM 1.955605
BBD 2.29677
BDT 140.265982
BGN 1.926481
BHD 0.429957
BIF 3386.861518
BMD 1.139336
BND 1.475553
BOB 7.880212
BRL 5.89839
BSD 1.140386
BTN 107.036303
BWP 15.497451
BYN 3.307369
BYR 22330.988246
BZD 2.293471
CAD 1.616661
CDF 2583.449152
CHF 0.922605
CLF 0.026705
CLP 1051.03496
CNY 7.745378
CNH 7.752824
COP 3917.408495
CRC 517.748256
CUC 1.139336
CUP 30.192408
CVE 110.253981
CZK 24.27816
DJF 203.069705
DKK 7.480658
DOP 67.003304
DZD 152.015808
EGP 56.43136
ERN 17.090042
ETB 183.850126
FJD 2.581854
FKP 0.861788
GBP 0.863297
GEL 3.01359
GGP 0.861788
GHS 12.857715
GIP 0.861788
GMD 83.171943
GNF 9992.001402
GTQ 8.700131
GYD 238.656149
HKD 8.935301
HNL 30.511951
HRK 7.539903
HTG 149.045104
HUF 354.163079
IDR 20349.226973
ILS 3.420345
IMP 0.861788
INR 107.508332
IQD 1493.850705
IRR 1566872.020062
ISK 144.115067
JEP 0.861788
JMD 179.602051
JOD 0.807834
JPY 184.293362
KES 147.565252
KGS 99.635383
KHR 4577.542521
KMF 494.472282
KPW 1025.40292
KRW 1749.029518
KWD 0.35275
KYD 0.950305
KZT 553.304703
LAK 25030.498458
LBP 102119.294221
LKR 383.321691
LRD 207.719241
LSL 18.745127
LTL 3.364164
LVL 0.689173
LYD 7.320268
MAD 10.693231
MDL 20.218979
MGA 4823.517939
MKD 61.628841
MMK 2391.906346
MNT 4077.580531
MOP 9.211779
MRU 45.511452
MUR 53.834064
MVR 17.603174
MWK 1977.402379
MXN 19.943172
MYR 4.65765
MZN 72.807828
NAD 18.745127
NGN 1567.875065
NIO 41.965806
NOK 11.31707
NPR 171.257885
NZD 2.016346
OMR 0.438256
PAB 1.140386
PEN 3.888611
PGK 5.0045
PHP 69.855021
PKR 317.362483
PLN 4.291823
PYG 6960.304389
QAR 4.156785
RON 5.244483
RSD 117.36827
RUB 88.591146
RWF 1670.033097
SAR 4.282472
SBD 9.173881
SCR 16.016599
SDG 683.602068
SEK 11.094411
SGD 1.474533
SHP 0.850629
SLE 28.259714
SLL 23891.313258
SOS 651.734866
SRD 42.70578
STD 23581.957684
STN 24.497552
SVC 9.978003
SYP 125.933213
SZL 18.734128
THB 38.028805
TJS 10.554045
TMT 3.987676
TND 3.379962
TOP 2.743248
TRY 53.039861
TTD 7.750225
TWD 36.299026
TZS 2999.100271
UAH 51.186584
UGX 4185.581694
USD 1.139336
UYU 45.775425
UZS 13697.631062
VES 707.246307
VND 29964.540351
VUV 136.297015
WST 3.167398
XAF 655.89145
XAG 0.019435
XAU 0.00028
XCD 3.079113
XCG 2.055195
XDR 0.815718
XOF 655.89145
XPF 119.331742
YER 271.874128
ZAR 19.354809
ZMK 10255.396502
ZMW 20.541947
ZWL 366.865771
  • CMSC

    -0.1160

    21.93

    -0.53%

  • BCC

    1.2600

    81.02

    +1.56%

  • RIO

    -1.3700

    93.74

    -1.46%

  • BCE

    -0.2800

    22.92

    -1.22%

  • NGG

    -0.4100

    83.01

    -0.49%

  • GSK

    0.6100

    52.5

    +1.16%

  • RYCEF

    0.3900

    18.39

    +2.12%

  • CMSD

    -0.1600

    21.77

    -0.73%

  • AZN

    2.7300

    188.41

    +1.45%

  • JRI

    0.2100

    12.79

    +1.64%

  • RBGPF

    3.7000

    65

    +5.69%

  • VOD

    0.0300

    13.89

    +0.22%

  • RELX

    0.4200

    31.34

    +1.34%

  • BTI

    0.2800

    62.76

    +0.45%

  • BP

    -0.5900

    37.13

    -1.59%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

Y.Kato--JT