An app that all attendees of the Beijing 2022 Winter Olympics must use has a flaw that allows the encryption of sensitive data to be sidestepped and also censors words related to the Chinese regime’s human rights abuses of ethnic and religious minority groups, according to a Canadian study.
Concerns of User Data Leaks
China requires all international and domestic attendees of the Games to download the app 14 days prior to their arrival. Users must monitor and submit their health status through the app on a daily basis.The Citizen Lab report says the app—which collects the users’ public-facing documents and a range of highly sensitive medical data—contains a “simple but devastating flaw,” allowing the encryption that protects the information to be “trivially sidestepped.”
“MY2022 fails to validate SSL certificates, thus failing to validate to whom it is sending sensitive, encrypted data,” study author Jeffrey Knockel wrote.
Censored Words
MY2022’s description on Apple’s App Store says the mobile app provides a wide range of communication functions such as instant messaging and other information services for travel, accommodations, and food.Among the list of censored keywords were the terms “Falun Gong,” “World Uyghur Congress,” “Tibet Freedom,” and “Tiananmen massacre”—words referring to ethnic and religious minority groups persecuted by the CCP and human rights atrocities the regime has committed.
The list also includes the Chinese terms for The Epoch Times, and its sister media outlet NTD. Neutral references to the names of current and former Chinese leaders as well as government agencies also are listed, the report states.
“Internet platforms operating in China are legally required to control content communicated over their platforms or face penalties,” Knockel wrote.
No Response
Citizen Lab said it informed the Beijing Organizing Committee for the 2022 Olympic and Paralympic Winter Games of the MY2022 security issues on Dec. 3, 2021. As of Jan. 18, it had not received a response. The lab also noted that while the app developers released an update on Jan. 17, the vulnerabilities remained unresolved.While that raises questions about whether MY2022’s encryption was “intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence,” Knockel said the case for deliberate sabotaging of MY2022’s encryption is problematic, as data collected through the app is already being directly submitted to the government.
“While it is possible that weakness in the encryption of health customs information was collateral damage from the intentional weakening of the encryption of other types of data that the Chinese government would have an interest in intercepting, our prior work suggests that insufficient protection of user data is endemic to the Chinese app ecosystem,” he wrote.
“While some work has ascribed intentionality to poor software security discovered in Chinese apps, we believe that such a widespread lack of security is less likely to be the result of a vast government conspiracy but rather the result of a simpler explanation, such as differing priorities for software developers in China.”