. Military Space News .
CYBER WARS
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
by AFP Staff Writers
Washington (AFP) Jan 18, 2022

An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.

The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.

The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."

"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."

The committee said it had asked Citizen Lab for its report "to understand their concerns better."

Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.

"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.

"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."

The flaws affect SSL certificates, which allow online entities to communicate securely.

MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.

While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."

MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.

These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.

Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


CYBER WARS
quub To Demonstrate Cybersecurity with Smallsat
Akron, PA (SPX) Jan 12, 2022
Scheduled to launch on a SpaceX Falcon 9 rocket on January 13, 2022, quub's pocketqube smallsat will serve as a proof of concept for the prevention of data hacks. Data breaches cost millions of dollars every year. IBM's annual Data Breach Report indicates that the average worldwide cost per breach in 2020 was $3.86 million. In the U.S., the average cost per breach was $8.64 million. IBM cites Internet-of-things (IoT) devices and third-party breaches as among several key cost-amplifying facto ... read more

Comment using your Disqus, Facebook, Google or Twitter login.



Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

CYBER WARS
ULA launches two new Space Force tracking satellites into orbit

L3Harris Completes Final US Missile Defense Agency Satellite Design Milestone

Northrop and Raytheon complete Next Generation Interceptor review

Northrop Grumman completes environmental testing for Next Gen OPIR GEO payload

CYBER WARS
Israel Knocks out simulated Iranian missile using Arrow-3 Interceptor

IMDO, MDA complete flight tests for the Arrow Weapon System and Arrow 3 Interceptor

North Korea tests 'tactical guided missiles' in military push

US calls on N.Korea to 'cease' its 'unlawful' missile launches

CYBER WARS
Airbus teams with Japan telcos to study connectivity services from high-altitude platforms

Defibrillator drone helps save Swedish heart attack patient

Two drones shot down targeting Iraq base: anti-IS coalition

Australia's First MQ-4C Triton Takes Shape

CYBER WARS
Teaming up to deliver a new Airborne ISR SATCOM capability for MilGov Operators

SES Government Solutions Launches On-Demand X-band Service Platform

Intelsat buys 2 Software-Defined Satellites from Thales Alenia Space to boost 5G solution

SPAINSAT NG program successfully passes Critical Design Review

CYBER WARS
AFRL'S PNT AgilePod achieves flight test objectives

Two Russian paratroopers die in Belarus drills jump

CYBER WARS
US presses for Myanmar arms embargo after massacre

Japan unveils record annual budget and defence spend

UAE protests stringent Biden conditions for jet fighters

Cambodian PM orders US weapons destroyed after arms embargo

CYBER WARS
Romania, Bulgaria say Russia demand for troop removal 'unacceptable'

Russia to hold naval drills in Atlantic, Pacific, Arctic, Mediterranean

Baltic states authorised to rush US-made weapons to Ukraine

NATO eyes shoring up southern flank as Russia demands withdrawal

CYBER WARS
The secret of ultralight but stiff sandwich nanotubes

AFRL Nano Team takes lead in building stronger ties with India









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.