Quick News Bit

Report: Mandatory Olympic app has serious security flaws

0
Report: Mandatory Olympic app has serious security flaws
A woman looks at her phone as she passes an Olympic logo inside the main media center for the Beijing Winter Olympics Tuesday, Jan. 18, 2022, in Beijing. Credit: AP Photo/David J. Phillip

A smartphone app that athletes and others attending next month’s Winter Games in Beijing must install has glaring security problems that could expose sensitive data to interception, according to a report published Tuesday.

Citizen Lab, an internet watchdog group, said in its report the MY2022 app has seriously flawed encryption that would make users’ sensitive data—and any other data communicated through it—vulnerable to being hacked. Other important user data on the app wasn’t encrypted at all, the report found.

That means the data could be read by Chinese internet service providers or telecommunications companies through Wi-Fi hotspots at hotels, airports and Olympic venues.

China is requiring all international Olympic attendees—including coaches and journalists—to download and start using the app 14 days before their departure. The app allows users to submit required health information on a daily basis and is part of China’s aggressive effort to manage the coronavirus pandemic while hosting the games, which begin Feb. 4. The multipurpose app also includes chat features, file transfers, weather updates, tourism recommendations and GPS navigation.

Citizen Lab’s report comes amid heightened concerns over athletes’ data and privacy. Many countries are advising their athletes not to take their normal smartphones to China, but instead to bring temporary—or burner—phones that do not store any sensitive personal data, according to news reports.

The U.S. Olympic & Paralympic Committee issued an advisory to athletes telling them to “assume that every device and every communication, transaction, and online activity will be monitored.”

Report: Mandatory Olympic app has serious security flaws
A woman pushing a dog in a pram stops to take a photo of a Beijing Winter Olympics poster on the Olympic Green in Beijing, China, Tuesday, Jan. 18, 2022. China has locked down parts of Beijing’s Haidian district following the detection of three cases, just weeks before the capital is to host the Winter Olympic Games. Credit: AP Photo/Ng Han Guan

“There should be no expectation of data security or privacy while operating in China,” the advisory said.

China has a well-documented history of conducting muscular surveillance of its citizens and aggressive cyber-spying on others. But Citizen Lab said there was no evidence that the easily discoverable security flaws in the MY2022 app were placed intentionally by the Chinese government. For one, much of the sensitive health information held on the app is required to be submitted directly to authorities on health customs forms, the report said.

Citizen Lab said the security vulnerabilities found in MY2022 app are similar to those found in popular Chinese web browsers and noted that “insufficient protection of user data is endemic to the Chinese app ecosystem.”

“In light of previous work analyzing popular Chinese apps, our findings concerning MY2022 are, while concerning, not surprising,” the report said.

Citizen Lab said it reported the security issues to the Beijing Organizing Committee last month but did not receive a response. The report also said the app’s security flaws could run afoul of Apple’s and Google’s policies for software used on iPhones and Android devices. The two companies did not immediately return a request for comment.

The Android version of the MY2022 app included a list named “illegalwords.txt” that included 2,442 keywords, including some that could be politically sensitive and relate to China’s actions toward Tibet and the Uyghur ethnic group.

The report said despite having the list bundled with the app, it does not appear to function. The Chinese government has long required tech companies to censor content and keywords deemed politically sensitive or inappropriate.


Researchers find privacy problems in popular Baidu browser


© 2022 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed without permission.

Citation:
Report: Mandatory Olympic app has serious security flaws (2022, January 18)
retrieved 18 January 2022
from https://techxplore.com/news/2022-01-mandatory-chinese-olympics-app-devastating.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! NewsBit.us is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.

Leave a comment