The Japan Times - Beijing Olympics organisers say app security flaws 'fixed'

EUR -
AED 4.240257
AFN 73.32143
ALL 96.053795
AMD 433.817139
ANG 2.066822
AOA 1058.764604
ARS 1599.696819
AUD 1.675026
AWG 2.078272
AZN 1.967396
BAM 1.955877
BBD 2.317892
BDT 141.205579
BGN 1.973561
BHD 0.434817
BIF 3418.53506
BMD 1.154596
BND 1.481959
BOB 7.981315
BRL 6.067751
BSD 1.150845
BTN 109.078309
BWP 15.865627
BYN 3.425635
BYR 22630.074075
BZD 2.314491
CAD 1.604715
CDF 2635.36902
CHF 0.917923
CLF 0.027055
CLP 1068.301597
CNY 7.980392
CNH 7.989998
COP 4229.267091
CRC 534.421114
CUC 1.154596
CUP 30.596784
CVE 110.269357
CZK 24.603629
DJF 204.928096
DKK 7.496448
DOP 68.502706
DZD 153.573067
EGP 60.780401
ERN 17.318934
ETB 177.904429
FJD 2.606389
FKP 0.869078
GBP 0.866456
GEL 3.094767
GGP 0.869078
GHS 12.609498
GIP 0.869078
GMD 84.867224
GNF 10090.398654
GTQ 8.807348
GYD 240.899518
HKD 9.036039
HNL 30.555207
HRK 7.557064
HTG 150.85596
HUF 390.276858
IDR 19617.503194
ILS 3.622683
IMP 0.869078
INR 109.51363
IQD 1507.559561
IRR 1516272.693223
ISK 144.047794
JEP 0.869078
JMD 181.147157
JOD 0.818654
JPY 185.066713
KES 149.485906
KGS 100.96983
KHR 4609.182101
KMF 494.167328
KPW 1039.139472
KRW 1741.130593
KWD 0.355512
KYD 0.959038
KZT 556.361981
LAK 25029.988892
LBP 103054.87152
LKR 362.514322
LRD 211.168343
LSL 19.761581
LTL 3.409221
LVL 0.698404
LYD 7.34629
MAD 10.755925
MDL 20.213799
MGA 4796.189489
MKD 61.642435
MMK 2423.302931
MNT 4123.225669
MOP 9.285467
MRU 45.949815
MUR 54.000874
MVR 17.838939
MWK 1995.478838
MXN 20.923702
MYR 4.530678
MZN 73.836825
NAD 19.761581
NGN 1597.337286
NIO 42.351673
NOK 11.20288
NPR 174.524895
NZD 2.015881
OMR 0.443458
PAB 1.150845
PEN 4.008858
PGK 4.973196
PHP 69.911197
PKR 321.19049
PLN 4.298271
PYG 7524.297272
QAR 4.195866
RON 5.111746
RSD 117.404638
RUB 93.863708
RWF 1680.566396
SAR 4.33291
SBD 9.285301
SCR 17.363686
SDG 693.912357
SEK 10.938258
SGD 1.49255
SHP 0.866246
SLE 28.345751
SLL 24211.30527
SOS 657.725986
SRD 43.413994
STD 23897.798134
STN 24.500968
SVC 10.069398
SYP 127.614745
SZL 19.759781
THB 37.518628
TJS 10.995934
TMT 4.041085
TND 3.392934
TOP 2.779989
TRY 51.310654
TTD 7.819309
TWD 36.998328
TZS 2969.117305
UAH 50.443693
UGX 4287.169379
USD 1.154596
UYU 46.58184
UZS 14034.554481
VES 540.268027
VND 30409.162038
VUV 137.841886
WST 3.204561
XAF 655.982917
XAG 0.0165
XAU 0.000256
XCD 3.120353
XCG 2.074082
XDR 0.815832
XOF 655.982917
XPF 119.331742
YER 275.490657
ZAR 19.766689
ZMK 10392.750198
ZMW 21.663856
ZWL 371.779317
  • RBGPF

    -13.5000

    69

    -19.57%

  • VOD

    -0.1400

    14.49

    -0.97%

  • GSK

    -0.1000

    53.84

    -0.19%

  • RELX

    -0.1000

    31.97

    -0.31%

  • RIO

    0.8500

    86.64

    +0.98%

  • NGG

    -0.4800

    81.92

    -0.59%

  • BTI

    0.3749

    57.8

    +0.65%

  • CMSC

    -0.0500

    22.77

    -0.22%

  • RYCEF

    -0.5900

    14.65

    -4.03%

  • AZN

    5.0200

    188.42

    +2.66%

  • BP

    0.5100

    46.68

    +1.09%

  • JRI

    -0.2700

    11.8

    -2.29%

  • BCC

    0.1400

    74.43

    +0.19%

  • CMSD

    -0.0900

    22.66

    -0.4%

  • BCE

    -0.2200

    25.25

    -0.87%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

Y.Kato--JT