In a report released by The University of Toronto’s Citizen Lab today, researchers analyzed the ‘My 2022’ Beijing Winter Olympics app and discovered the app is insecure when it comes to protecting the sensitive data of its users. The app’s encryption system carries a significant flaw that enables middle-men to access documents, audio and files in cleartext form. Researchers found that the ‘My 2022’ app, which is required for all athletes, members of the press and the audience to have installed, is subject to censorship based on keywords and has an unclear privacy policy that doesn’t determine who receives and processes sensitive data, thus violating Google and Apple’s App Store guidelines.
Chris Olson, CEO at The Media Trust, an enterprise digital safety platform:
“Poor app security is a leading cause of the rise in cyberattacks on mobile devices. While the security issues found in ‘My 2022’ are concerning, unfortunately they are not as unique as they appear. Not all mobile apps are susceptible to man-in-the-middle attacks, but most of them do contain undisclosed third parties who can access the same user data as the developer. Mobile users frequently assume that they are safe either because of app store policies, or because they have consented to terms of service – but third parties are not carefully checked by app reviewers, and they are rarely monitored for safety. They can be hijacked to execute phishing attacks, share sensitive data with fourth or fifth parties, suffer a data breach caused by lax security practices, or worse.”
I have to admit that if I were an athlete going to these Olympics and I read this, I may think twice about going. And it makes the move by the Dutch to have athletes keep their personal electronics at home look like a good decision.
Chinese Hackers Targeting Ukraine Says Google
Posted in Commentary with tags China, Google on March 20, 2022 by itnerdGoogle’s Threat Analysis Group (TAG) says that China has gotten involved in the Russia/Ukraine war by having its hackers target Ukraine. Google TAG Security Engineer Billy Leonard posted this to Twitter:
In case you’re wondering who Intrusion Truth are, they are a secretive group known for its work on exposing suspected Chinese hacking operations. So if they’re saying something that Google is confirming, then it’s pretty much fact.
This was backed up by Shane Huntley who runs Google’s Threat Analysis Group:
I wonder what the US Government thinks of these reports as US President Joe Biden has recently warned Chinese President Xi Jinping not to get involved in the Russian/Ukraine war. He was talking about weapons and the like. But maybe he should add this to the list as clearly China isn’t neutral when it comes to this war.
Leave a comment »