Budapest Post

Cum Deo pro Patria et Libertate
Budapest, Europe and world news

The surveillance concerns around China’s Winter Olympics app – explained

The surveillance concerns around China’s Winter Olympics app – explained

A report found the app that will be used to monitor athletes’ health and travel data has a ‘devastating’ encryption flaw
With the Beijing Olympics just weeks away, concerns are mounting over a mandatory health app for competing athletes, after a new report revealed the app contains security flaws and a list of “politically sensitive” words that have been marked for censorship.

The report, published by University of Toronto’s research and strategic policy unit Citizen Lab, found that the My2022 app, which will be used to monitor athletes’ health and travel data, has a “devastating” encryption flaw that leaves users’ files and media vulnerable.

The problem, researchers say, is twofold: first, the app does not always verify that the servers where encrypted data is being sent are the intended servers, which could enable malicious actors to spoof or mimic that server’s identity to access those files. That could allow the attacker to, for instance, “read a victim’s sensitive demographic, passport, travel, and medical information sent in a customs health declaration or to send malicious instructions to a victim after completing a form”, the report said. Second, the app is not encrypting some sensitive data at all. Effectively, that means some sensitive data within the app, “including the names of messages’ senders and receivers and their user account identifiers”, is being transmitted without any security.

“Such data can be read by any passive eavesdropper, such as someone in range of an unsecured wifi access point, someone operating a wifi hotspot, or an internet service provider or other telecommunications company,” the report reads.

The Beijing Olympics are already taking place under a cloud of controversy. The US announced in December that it would stage a diplomatic boycott of the games over human rights concerns, as China continues to deny its years-long campaign against Uyghur minorities. US lawmakers have also proposed new legislation that would strip the International Olympics Committee’s (IOC) tax-exempt status over its refusal to challenge China on its human rights violations.

The encryption flaws in the app have raised further concerns, but how worried should visiting countries and athletes be? Though experts say general concerns about surveillance during the Olympics and the app are warranted, the reality is the app’s security flaws are probably more a reflection of poor design rather than sinister intent to surveil. In other words, athletes and others visiting the country during the Olympics should be as careful as they normally would when visiting China.

“The main thing that Citizen Lab has told us is that there is a substance behind our fears and concerns, but it’s also true that we have a tendency to demonize China,” said Jon Callas, the director of technology projects at the Electronic Frontier Foundation, a non-profit digital right group.

Callas and other experts say the Chinese government should certainly fix the security flaw, but that the flaw doesn’t necessarily open the athletes up to a higher risk of being surveilled by the government. And it’s not likely the encryption is faulty by design, said Kenton Thibaut, the resident China fellow of the Atlantic Council’s Digital Forensic Research Lab. It’s unlikely anyone intentionally sabotaged the encryption of the app in order to more easily access user information, she pointed out, because all the information is going to the government anyway.

“If you’re using Chinese apps, even if you’re not in China, they’ll still have access to the information that you submit because the data is ending up in a place where the government has control over and access to,” Thibaut said. “The app itself is made by a government entity, there would be no reason to do that.”

That said, the Olympics are a hugely important event for Beijing, Thibaut said, and it’s fair to expect a certain degree of monitoring, “especially for athletes who have perhaps indicated displeasure about not being able to speak out or displeasure about the IOC’s stance on China”.

Citizen Lab reported that there was a list of 2,422 political keywords described in the app’s codebase as “illegalwords.txt”. Though the function to censor these words did not appear to be active, the report said the keywords varied from references to pornography, mentions of the Tiananmen movement to some words in Uyghur including “the Holy Quran”, “injections”, and “forced demolitions”.

This is not unexpected, Callas said. “China does an awful lot of blocking of chat from absolutely everything and they throw their weight around in ways that are objectionable, with stuff like how much you can even mention that Taiwan exists,” he said. “They’re not going to allow free and unrestricted speech because they’re not that country.”

“When we agreed to let the Olympics happen in Beijing, we agreed implicitly that these are some of the things that were going to happen,” he continued.

However, there are regular precautions that those traveling to China, during the Olympics or otherwise, should take, Callus said. National Olympic Committees around the world have advised their teams to leave their personal devices behind and take burner phones instead.

“It should be assumed that every text, email, online visit, and application access can be monitored or compromised,” the United States Olympic and Paralympic Committee said in an advisory.

Callus said this should always be the case when traveling to China because all your personal information – from your contact list to your pictures – can be compromised.

“One reason for making sure you use a burner phone is your address book slash contacts list has sensitive information in it – in the sense that anybody who has your address book has, to some level of accuracy, your social graph and who you’re connected to,” he said. “What we learned from, for example, those Snowden drops nearly 10 years ago now, is that governments are far more interested to know who you are connected to and who you regularly talk to than what it is that you say.”

For athletes looking to communicate with their family or friends outside the country – particularly given families are not permitted to attend the Olympics due to Covid – Callus said they should use a “reasonably secure” encrypted messaging app, including iMessage, Signal or WhatsApp.

“If the Chinese [government] has not shut it down, it’s probably OK,” he said. “That’s probably the best way to talk to people back home.”
AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

0:00
0:00
Close
One in Three Europeans Now Uses TikTok, According to the Chinese Tech Giant
Could AI Nursing Robots Help Healthcare Staffing Shortages?
NATO Deploys ‘Eastern Sentry’ After Russian Drones Violate Polish Airspace
The New Life of Novak Djokovic
German police raid AfD lawmaker’s offices in inquiry over Chinese payments
Volkswagen launches aggressive strategy to fend off Chinese challenge in Europe’s EV market
France Erupts in Mass ‘Block Everything’ Protests on New PM’s First Day
Poland Shoots Down Russian Drones in Airspace Violation During Ukraine Attack
Apple Introduces Ultra-Thin iPhone Air, Enhanced 17 Series and New Health-Focused Wearables
Macron Appoints Sébastien Lecornu as Prime Minister Amid Budget Crisis and Political Turmoil
Vatican hosts first Catholic LGBTQ pilgrimage
Apple Unveils iPhone 17 Series, iPhone Air, Apple Watch 11 and More at 'Awe Dropping' Event
France joins Eurozone’s ‘periphery’ as turmoil deepens, say investors
France Faces New Political Crisis, again, as Prime Minister Bayrou Pushed Out
Nayib Bukele Points Out Belgian Hypocrisy as Brussels Considers Sending Army into the Streets
France, at an Impasse, Heads Toward Another Government Collapse
The Country That Got Too Rich? Public Spending Dominates Norway Election
EU Proposes Phasing Out Russian Oil and Gas by End of 2027 to End Energy Dependence
More Than 150,000 Followers for a Fictional Character: The New Influencers Are AI Creations
EU Prepares for War
Trump Threatens Retaliatory Tariffs After EU Imposes €2.95 Billion Fine on Google
Tesla Board Proposes Unprecedented One-Trillion-Dollar Performance Package for Elon Musk
Gold Could Reach Nearly $5,000 if Fed Independence Is Undermined, Goldman Sachs Warns
Uruguay, Colombia and Paraguay Secure Places at 2026 World Cup
Trump Administration Advances Plans to Rebrand Pentagon as Department of War Instead of the Fake Term Department of Defense
Big Tech Executives Laud Trump at White House Dinner, Unveil Massive U.S. Investments
Tether Expands into Gold Sector with Profit-Driven Diversification
‘Looks Like a Wig’: Online Users Express Concern Over Kate Middleton
Florida’s Vaccine Revolution: DeSantis Declares War on Mandates
Trump’s New War – and the ‘Drug Tyrant’ Fearing Invasion: ‘1,200 Missiles Aimed at Us’
"The Situation Has Never Been This Bad": The Fall of PepsiCo
At the Parade in China: Laser Weapons, 'Eagle Strike,' and a Missile Capable of 'Striking Anywhere in the World'
The Fashion Designer Who Became an Italian Symbol: Giorgio Armani Has Died at 91
Putin Celebrates ‘Unprecedentedly High’ Ties with China as Gazprom Seals Power of Siberia-2 Deal
China Unveils New Weapons in Grand Military Parade as Xi Hosts Putin and Kim
Rapper Cardi B Cleared of Liability in Los Angeles Civil Assault Trial
Google Avoids Break-Up in U.S. Antitrust Case as Stocks Rise
Couple celebrates 80th wedding anniversary at assisted living facility in Lancaster
Information Warfare in the Age of AI: How Language Models Become Targets and Tools
The White House on LinkedIn Has Changed Their Profile Picture to Donald Trump
"Insulted the Prophet Muhammad": Woman Burned Alive by Angry Mob in Niger State, Nigeria
Trump Responds to Death Rumors – Announces 'Missile City'
Druzhba Pipeline Incident Sparks Geopolitical Tensions
Cost of Opposition Leader Péter Magyar's Economic Plan Revealed
Germany in Turmoil: Ukrainian Teenage Girl Pushed to Death by Illegal Iraqi Migrant
United Krack down on human rights: Graham Linehan Arrested at Heathrow Over Three X Posts, Hospitalised, Released on Bail with Posting Ban
Asian and Middle Eastern Investors Avoid US Markets
Ray Dalio Warns of US Shift to Autocracy
Eurozone Inflation Rises to 2.1% in August
Russia and China Sign New Gas Pipeline Deal
×