Berliner Boersenzeitung - Beijing Olympics organisers say app security flaws 'fixed'

EUR -
AED 3.995362
AFN 72.879605
ALL 98.279106
AMD 421.060772
ANG 1.961671
AOA 992.037372
ARS 1079.883898
AUD 1.650502
AWG 1.957968
AZN 1.848211
BAM 1.9506
BBD 2.197642
BDT 130.07325
BGN 1.956076
BHD 0.409923
BIF 3149.065907
BMD 1.08776
BND 1.432221
BOB 7.538113
BRL 6.300416
BSD 1.088399
BTN 91.544784
BWP 14.493762
BYN 3.562202
BYR 21320.10079
BZD 2.194012
CAD 1.511932
CDF 3093.590087
CHF 0.940059
CLF 0.037622
CLP 1038.115053
CNY 7.729194
CNH 7.744086
COP 4802.461479
CRC 558.610853
CUC 1.08776
CUP 28.825646
CVE 110.570286
CZK 25.337523
DJF 193.316613
DKK 7.457728
DOP 65.755289
DZD 144.924474
EGP 53.362292
ERN 16.316404
ETB 131.730194
FJD 2.475688
FKP 0.83232
GBP 0.839365
GEL 2.975022
GGP 0.83232
GHS 17.795417
GIP 0.83232
GMD 77.774428
GNF 9387.370605
GTQ 8.409582
GYD 227.918699
HKD 8.456411
HNL 27.270436
HRK 7.493613
HTG 143.238155
HUF 408.073167
IDR 17156.80723
ILS 4.079737
IMP 0.83232
INR 91.526159
IQD 1424.96592
IRR 45800.145229
ISK 148.903481
JEP 0.83232
JMD 171.981531
JOD 0.771335
JPY 165.659408
KES 140.320912
KGS 93.328602
KHR 4432.622841
KMF 492.21194
KPW 978.983975
KRW 1499.504725
KWD 0.33341
KYD 0.907107
KZT 531.852186
LAK 23865.459643
LBP 97463.318006
LKR 319.109317
LRD 208.686872
LSL 19.04682
LTL 3.211873
LVL 0.657975
LYD 5.232249
MAD 10.711134
MDL 19.42974
MGA 5020.01397
MKD 61.608784
MMK 3533.002843
MNT 3696.209341
MOP 8.71421
MRU 43.510008
MUR 49.852176
MVR 16.748932
MWK 1887.810848
MXN 21.88318
MYR 4.752392
MZN 69.503294
NAD 19.046414
NGN 1788.049647
NIO 40.002392
NOK 11.962274
NPR 146.471575
NZD 1.820166
OMR 0.418813
PAB 1.088528
PEN 4.098953
PGK 4.361369
PHP 63.556199
PKR 302.234637
PLN 4.358541
PYG 8572.148333
QAR 3.960101
RON 4.975525
RSD 117.015772
RUB 107.688744
RWF 1483.704973
SAR 4.085607
SBD 9.035177
SCR 14.763818
SDG 654.283077
SEK 11.668624
SGD 1.434821
SHP 0.83232
SLE 24.719375
SLL 22809.784965
SOS 621.111205
SRD 37.969403
STD 22514.440879
SVC 9.523612
SYP 2733.030539
SZL 19.046919
THB 36.714631
TJS 11.592317
TMT 3.818038
TND 3.370961
TOP 2.547647
TRY 37.371852
TTD 7.378534
TWD 34.793422
TZS 2927.024714
UAH 45.11385
UGX 3983.381087
USD 1.08776
UYU 45.349108
UZS 13939.647593
VEF 3940468.630106
VES 46.559442
VND 27514.895381
VUV 129.141114
WST 3.047017
XAF 654.230992
XAG 0.032247
XAU 0.0004
XCD 2.939726
XDR 0.817643
XOF 653.199741
XPF 119.331742
YER 271.776542
ZAR 19.035368
ZMK 9791.150456
ZMW 29.197969
ZWL 350.258355
  • RBGPF

    66.4100

    66.41

    +100%

  • SCS

    0.1100

    12.25

    +0.9%

  • CMSC

    0.1100

    24.64

    +0.45%

  • BCC

    0.0500

    134.26

    +0.04%

  • NGG

    0.1900

    64.45

    +0.29%

  • BCE

    -2.9800

    29.12

    -10.23%

  • RELX

    -0.0200

    47.06

    -0.04%

  • JRI

    0.0500

    13.1

    +0.38%

  • CMSD

    0.1103

    24.92

    +0.44%

  • RYCEF

    0.0100

    7.11

    +0.14%

  • RIO

    -0.3200

    65.01

    -0.49%

  • VOD

    -0.0300

    9.32

    -0.32%

  • AZN

    0.0100

    71.43

    +0.01%

  • GSK

    0.0900

    36.97

    +0.24%

  • BP

    0.5000

    29.73

    +1.68%

  • BTI

    0.0400

    35.11

    +0.11%

Beijing Olympics organisers say app security flaws 'fixed'
Beijing Olympics organisers say app security flaws 'fixed'

Beijing Olympics organisers say app security flaws 'fixed'

An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.

Text size:

Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.

Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.

Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.

Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.

But a senior Chinese Olympic official said any bugs had now been fixed.

"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.

"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."

The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.

Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.

"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.

- Data laws -

Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.

However, Yu said organisers never saw the request because it was sent to an old email address.

China's data security laws require that health and medical data be encrypted during transmission and storage.

The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.

"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.

Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".

But organisers denied ever requesting these functions, and said they have asked the developer to look into it.

They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.

"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.

China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.

In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.

Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.

However, organisers and the Chinese government have dismissed such concerns as unfounded.

"The government will not monitor individuals' phones in any form," Yu said.

The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.

(U.Gruber--BBZ)