FacebookInstagramTwitterContact

 

Kate Shares New Photo Of Smiling Charlotte To Celebrate Her Ninth Birthday           >>           Reginald The Cat Has A Filthy Habit For Stealing Underwear From Strangers           >>           Travis Kelce Makes Surprise Appearance At Pre-2024 Kentucky Derby Party           >>           Anna Nicole Smith's Daughter Dannielynn Birkhead, 17, Debuts New Look At Kentucky Derby           >>           Turmeric Extract Combats The Joint-Damaging Effects Of Arthritis           >>           Cranberries Prevent Cancer And Many Other Chronic Diseases           >>           Boeing Starliner Rolls Out To Launch Pad For 1st Astronaut Flight On May 6 (Photos)           >>           Parrots in captivity seem to enjoy video-chatting with their friends on Messenger           >>           Google prohibits ads promoting websites and apps that generate deepfake porn           >>           Threads Now Lets You Control Who Can Quote Your Posts           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


A Health-Monitoring App For Olympic Attendees Reportedly Has Glaring Security Issues


Carlos Garcia Rawlins / reuters

 


 January 19th, 2022  |  11:39 AM  |   511 views

ENGADGET

 

Researchers said passport details, voice audio and other data are vulnerable in the MY2022 app.

 

Just over two weeks before the 2022 Winter Olympics are set to get underway in Beijing, researchers have issued a report claiming that an app many attendees are using has major security issues. The Citizen Lab, a research facility based at the University of Toronto's Munk School of Global Affairs and Public Policy, said a "simple but devastating flaw" made it easy to bypass encryption systems that are supposed to protect voice audio and file transfers.

 

"The worst case scenario is that someone is intercepting all the traffic and recording all the passport details, all the medical details," research associate Jeffrey Knockel told CTV.

 

The app is used for health monitoring as part of COVID-19 countermeasures. Other features include messaging, news about the Games and information about logistics. The International Olympic Committee says the local Beijing 2022 workforce is using the app for things like time-keeping and task management too.

 

"The IOC has conducted independent third-party assessments on the application from two cyber-security testing organizations," the IOC told Engadget in a statement. "These reports confirmed that there are no critical vulnerabilities." The IOC noted that instead of using the mobile app, attendees can access a web-based health monitoring system. It said it has requested the researchers' report "to understand their concerns better."

 

The Citizen Lab notes that health customs forms containing passport information and travel and medical history are also at risk. In addition, the researchers said it was possible to spoof server responses, which could let hackers provide fake instructions to users.

 

Along with determining that the app doesn't encrypt some data transmissions, the team found that the app fails to validate some SSL certificates. In such cases, the app can't "validate to whom it is sending sensitive, encrypted data." Although they were only able to create an account on the iOS app, the researchers believe the vulnerabilities exist on the Android version of MY2022 as well.

 

The Citizen Lab said it informed the organizing committee for the Games about the issues on December 3rd, and said it had 15 days to respond and 45 days to fix the issues before it published its findings. As of Tuesday, the researchers hadn't received a reply.

 

An updated iOS version of the app that was released on Sunday didn't solve the problems. According to the researchers, the developers added a feature called “Green Health Code” that asks for more travel and medical history details, which are also vulnerable to the SSL certification issue.

 

According to the researchers, the flaws could mean that the app contravenes Apple's App Store rules and Google’s Unwanted Software Policy. In addition, MY2022 may be violating China's privacy standards and laws.

 

In addition, The Citizen Lab noted that the app includes an option to report “politically sensitive” content. It has a list of 2,442 censorship keywords too, which is said to be inactive at the minute, but includes terms related to topics like Xinjiang, Tibet, Chinese government agencies and other socially sensitive matters.

 


 

Source:
courtesy of ENGADGET

by Kris Holt

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

North Korean Weapons Are Killing Ukrainians. The Implications Are Far Bigger

 2024-05-05 10:30:19

Have The Wheels Come Off For Tesla?

 2024-05-04 07:51:07