Security flaws in China’s My2022 Olympics app could allow surveillance

China's My2022 App Flaws Compromise Security with Surveillance Threats | Cyber In :60 | GZERO Media

Marietje Schaake, International Policy Director at Stanford's Cyber Policy Center, Eurasia Group senior advisor and former MEP, discusses trends in big tech, privacy protection and cyberspace:

Does the Beijing 2022 Olympics app have security flaws?

Well, the researchers at the Citizen Lab of the University of Toronto do believe so. And if their revelations, this time, will set off a similar storm as they did with the forensics on NSO Group's spyware company, then there will be trouble ahead for China. The researchers found that the official My2022 app for the sports event, which attendees are actually required to download and to use for documenting their health status, has flaws in the security settings. Loopholes they found could be used for intrusion and surveillance.

Now, of course, China is not exactly known as a bastion of privacy protections. But beyond the flaws, the app also has a censorship keyword list, which has relation to terms like Tiananmen protests, the Dalai Lama, or the Uyghur Muslim minority. And in response, Dutch supporters will be provided with a burner phone. And sure, that might be a short-term solution, but I'm not sure whether other officials visiting China, now for the Olympics, or for business or politics, are always as careful. I remember attending a World Economic Forum events in China, as a member of European Parliament, and being one of the only ones to proactively take precautions.

Now, unfortunately, one of the researchers of the Citizen Lab confirmed that, "Our findings expose how My2022 security measures are wholly insufficient to prevent sensitive data from being disclosed to unauthorized third parties." But the Beijing organizing committee has stood by its app, and said it passed the examination of international mobile app markets, such as Google, Apple, and Samsung. So unfortunately, no clear solution in sight to make sure that systematically, human rights and privacy are better protected in China.

More from GZERO Media

The Meta logo is seen on a mobile phone with the Chinese flag in the background in this photo illustration.
Photo by Jaap Arriens / SIpa USA via Reuters

But because of Meta’s openness, Chinese researchers were able to develop their own AI model — for military use — using one of Meta’s Llama models.

An FPV drone with an attached portable grenade launcher is seen during a test flight conducted by Ukrainian servicemen of the 'Bulava' Unmanned Aerial Vehicles Unit of the Separate Presidential Brigade at their position near a frontline, amid Russia's attack on Ukraine, in Zaporizhzhia region, Ukraine, on Oct. 11, 2024.

REUTERS/Stringer/File Photo

Ukraine is reportedly using new AI-powered drones to fly explosives toward Russian targets.

Pens for the diabetes drug Ozempic sit on a production line to be packaged at the Danish drugmaker Novo Nordisk's site in Hillerod, Denmark.
REUTERS/Tom Little

Armed with a bunch of Ozempic money, the Novo Nordisk Foundation — along with Denmark’s Export and Investment fund — is bankrolling a new AI supercomputer called Gefion, which launched on Oct. 23 and is run by a new company called the Danish Centre for AI Innovation.

DALL-E

While neither Vice President Kamala Harris nor former President Donald Trump has given much attention to artificial intelligence on the campaign trail — and AI hasn’t completely disrupted the election process as some experts feared — there are still important questions surrounding AI and the election.

US Capitol building at in the morning sun. Washington DC, USA The US Capitol building in the early morning at sunrise.

While eyes around the globe will be on the US presidency this Election Day, there are consequential races further down the ballot that will determine how much power Kamala Harris or Donald Trump will wield.

Ukrainian service members of the 43rd Hetman Taras Triasylo Separate Artillery Brigade fire towards Russian troops in a Panzerhaubitze 2000 self-propelled howitzer, amid Russia's attack on Ukraine, at a position in Donetsk region, Ukraine October 26, 2024.
REUTERS/Viacheslav Ratynskyi

What happens if the Korean People’s Army pushes into Ukraine proper?