Beijing 2022 – Olympics: The smartphone app that athletes will be required to use to report health and travel data when in China for the Olympics next month has serious encryption flaws, according to a new report, raising security questions about the systems Beijing plans to use to monitor the Covid-19 pandemic.
See also: Microsoft Patch Tuesday January 2022: Fixes over 90 vulnerabilities

Parts of the app that would transmit coronavirus test results, travel information and other personal data failed to verify the signature used in encrypted transfers or did not encrypt the data at all, according to the Citizen Lab report. The company's team found that the app includes a series of political terms that are flagged as censorship in its code, although it does not appear to be actively using the list to filter communications.
China is in the final stages of planning for the Winter Olympics, which will seek to control the spread of Covid-19 by keeping athletes and other participants away from the majority of the Chinese population. The app, called MY2022, was designed to bolster those precautions by allowing electronic links between the government and participants to communicate in the event of an outbreak.
See also: WordPress 5.8.3 security update fixes four vulnerabilities
The new concerns about the app underscore broader concerns about censorship and surveillance that could take place during the Olympics in China, which has one of the world's most sophisticated surveillance and censorship systems. Officials have already said that athletes will be provided with mobile services that will allow them to bypass widespread blocks on sites such as Facebook, Google and Twitter.

See also: Netgear has not patched six vulnerabilities in its Nighthawk router
In its report, Citizen Lab said it disclosed the security flaws to the Beijing Organizing Committee on December 3 but had not received a response. A software update released in January did not fix the problems.
Source of information: nytimes.com
