-
Nine killed in accidental explosion at Indian Kashmir police station
-
Climate protesters to rally at COP30's halfway mark
-
Fighting South Africa lose Rickelton after India 189 all out
-
Harmer leads South Africa fightback as India 189 all out
-
Prison looms for Brazil's Bolsonaro after court rejects his appeal
-
EU bows to pressure on loosening AI, privacy rules
-
India close in on lead despite South African strikes
-
Curry's 49 points propel Warriors in 109-108 win over Spurs
-
NZ boxer Parker denies taking banned substance after failed test
-
Australia setback as Hazlewood ruled out of 1st Ashes Test
-
Australia pace spearhead Josh Hazlewood ruled out of 1st Ashes Test
-
UN Security Council to vote Monday on Trump Gaza plan
-
Japan's Tomono leads after men's short program at Skate America
-
China tells citizens to avoid Japan travel as Taiwan row grows
-
Purdue Pharma to be dissolved as US judge says to approve bankruptcy
-
Iran's first woman orchestra conductor inspires
-
Wood gets all-clear in boost for England
-
Golf's world No. 8 Thomas has back surgery
-
Rebooted Harlem museum celebrates rise of Black art
-
'Desperation in the air': immigrant comics skewer Trump crackdown
-
UN regulator says shipping still wants to decarbonize -- despite US threats
-
Grant, Kim share halfway lead in LPGA Annika tournament
-
Musk's Grokipedia leans on 'questionable' sources, study says
-
Trump signs order to lower tariffs on beef, coffee, other goods
-
Croatia qualify for 2026 World Cup, Netherlands close, Germany in limbo
-
'Last Chance U' coach dies after shooting: US police
-
Sinner completes perfect ATP Finals group stage, Auger-Aliassime reaches last four
-
Woltemade sends Germany past Luxembourg in World Cup qualifier
-
Croatia qualify for 2026 World Cup with 3-1 win over Faroes
-
Kai Trump makes strides but still misses cut in LPGA debut
-
Return to bad days of hyperinflation looms in Venezuela
-
US airspace recovers as budget shutdown ends
-
Russia strike on Kyiv apartment block kills six, Ukraine says
-
Arrest made in shooting of 'Last Chance U' coach: US police
-
At COP30, senator warns US 'deliberately losing' clean tech race with China
-
US, Switzerland say deal reached on trade and tariffs
-
Fossil fuel lobbyists out in force at Amazon climate talks: NGOs
-
Returning Alldritt blames himself for France axing
-
Stocks struggle on US rates, tech rally fears
-
A rare oil CEO shows up at COP30, spars with activists
-
Trump demands probe into Epstein links to Bill Clinton
-
England great Anderson says 'weak' Australia still Ashes favourites
-
Indigenous protesters disrupt UN climate summit again
-
Gun salutes for King Charles III as he marks 77th birthday
-
Ford urges England to make their own New Zealand history
-
Acosta top in Valencia MotoGP practice as Martin returns
-
Michelle Yeoh to get honorary award at Berlin film fest
-
Bulgaria names manager to take over Russia's Lukoil refinery after US sanctions
-
Spain players on their way to becoming 'legendary': coach De la Fuente
-
US, Switzerland say reached deal on trade and tariffs
Beijing Olympics organisers say app security flaws 'fixed'
An app that Winter Olympics attendees must use has been patched, a Chinese official told AFP Thursday, after cyber security researchers said they had found a "simple but devastating" flaw that could allow data leaks.
Next month's Games are being held in a bubble that separates participants from the rest of the population as part of China's strict zero-Covid policy.
Those taking part -- from foreign athletes, delegates and media to the army of local volunteers and officials -- have to download a health-tracking app called MY2022.
Users report their health status daily through the app which collects data including vaccination status and coronavirus test results, as well as travel and passport details.
Earlier this week researchers at the University of Toronto's Citizen Lab said they discovered the app's security flaws could allow data including health information and voice messages to leak, which could then be read by "eavesdroppers" such as Wi-Fi hotspot operators.
But a senior Chinese Olympic official said any bugs had now been fixed.
"There is definitely no data leakage," Beijing Olympics Organising Committee (BOCOG) tech chief Yu Hong told AFP, adding that the app's user and privacy guidelines were reviewed by the International Olympic Committee.
"The security loopholes have already been fixed. If they existed in earlier versions, they have been fixed in the latest version."
The app's developers have been in email contact with Citizen Lab since Wednesday, Yu added, promising that there will be "relevant discussions" on follow-up work.
Yu did not deny there may have been security flaws in previous versions of the app and she suggested that BOCOG had not been aware of them.
"During development we have continued to test and use it. When new usage conditions appear some new technological imperfections may be discovered, these can be called loopholes," she said.
- Data laws -
Citizen Lab earlier said it had notified organisers about the issues in early December but received no reply.
However, Yu said organisers never saw the request because it was sent to an old email address.
China's data security laws require that health and medical data be encrypted during transmission and storage.
The Citizen Lab report claimed that the app's inadequate encryption could violate Chinese law, as well as Google and Apple mobile software policies.
"China has a history of undermining encryption technology to perform political censorship and surveillance," researcher Jeffrey Knockel wrote in the report.
Researchers also discovered the app's Android code contained an apparently inactive blacklist of over 2,400 "politically sensitive" phrases, and that it had a separate function to report other users' speech for "politically sensitive content".
But organisers denied ever requesting these functions, and said they have asked the developer to look into it.
They added that app health data would primarily be shared with virus control authorities, after the report claimed this was unclear.
"Use of data by individuals and departments is only permitted after the IOC confirms it," Yu said.
China maintains the world's most sophisticated digital tools to monitor and censor the internet for its citizens, blocking major Western platforms such as Twitter, Facebook and YouTube.
In recent days, Olympic associations in multiple Western countries have warned athletes to leave personal devices at home and bring "burner" phones to China.
Analysts have also warned of cybersecurity risks such as data theft and surveillance targeting attendees using public Wi-Fi networks and official SIM cards provided by organisers.
However, organisers and the Chinese government have dismissed such concerns as unfounded.
"The government will not monitor individuals' phones in any form," Yu said.
The app also provides a range of daily living services for users, such as translation, weather, transport schedules and accommodation booking.
G.AbuOdeh--SF-PST