Security flaws in China’s My2022 Olympics app could allow surveillance

China's My2022 App Flaws Compromise Security with Surveillance Threats | Cyber In :60 | GZERO Media

Marietje Schaake, International Policy Director at Stanford's Cyber Policy Center, Eurasia Group senior advisor and former MEP, discusses trends in big tech, privacy protection and cyberspace:

Does the Beijing 2022 Olympics app have security flaws?

Well, the researchers at the Citizen Lab of the University of Toronto do believe so. And if their revelations, this time, will set off a similar storm as they did with the forensics on NSO Group's spyware company, then there will be trouble ahead for China. The researchers found that the official My2022 app for the sports event, which attendees are actually required to download and to use for documenting their health status, has flaws in the security settings. Loopholes they found could be used for intrusion and surveillance.

Now, of course, China is not exactly known as a bastion of privacy protections. But beyond the flaws, the app also has a censorship keyword list, which has relation to terms like Tiananmen protests, the Dalai Lama, or the Uyghur Muslim minority. And in response, Dutch supporters will be provided with a burner phone. And sure, that might be a short-term solution, but I'm not sure whether other officials visiting China, now for the Olympics, or for business or politics, are always as careful. I remember attending a World Economic Forum events in China, as a member of European Parliament, and being one of the only ones to proactively take precautions.

Now, unfortunately, one of the researchers of the Citizen Lab confirmed that, "Our findings expose how My2022 security measures are wholly insufficient to prevent sensitive data from being disclosed to unauthorized third parties." But the Beijing organizing committee has stood by its app, and said it passed the examination of international mobile app markets, such as Google, Apple, and Samsung. So unfortunately, no clear solution in sight to make sure that systematically, human rights and privacy are better protected in China.

More from GZERO Media

Syrian forces head to Latakia after fighters linked to Syria's ousted leader Bashar Assad mounted a deadly attack on government forces on Thursday, March 6, 2025.

REUTERS/Mahmoud Hassano

Nearly 50 people were killed on Thursday in the deadliest clashes Syria has seen since the overthrow of Bashar Assad. Pro-Assad militants attacked security checkpoints around the western coastal town of Jableh, a stronghold of the former regime.

The Liberian-flagged tanker Ice Energy, chartered by the US government, takes Iranian oil from Iranian-flagged Lana (formerly Pegas) as part of a civil forfeiture action off the shore of Karystos, on the Island of Evia, Greece, in May 2022.
REUTERS/Costas Baltas/File Photo

The Trump administration is reportedly considering a strategy to disrupt Iran’s oil exports by stopping and inspecting Iranian oil tankers at sea. The US would use the Proliferation Security Initiative, established in 2003 to prevent the trafficking of weapons of mass destruction, as a legal justification for the inspections.

Donald Trump issues a proclamation from the Oval Office
REUTERS/Kevin Lamarque

US presidents don’t typically talk to organizations the US government has labeled terrorist groups, but Donald Trump is not a typical US president.

President Donald Trump addresses a joint session of Congress at the US Capitol on March 4, 2025.

Win McNamee/Pool via REUTERS

You didn’t need to sit through all 99 minutes of Trump’s peroration to know that he gave himself an A++ on his first six weeks in office, writes GZERO Publisher Evan Solomon. But if Trump gets to grade himself, maybe it’s time for a more objective report card — one that looks at two criteria: Trump as a dealmaker and Trump as a manager.

The Energy Security Hub at the 2025 Munich Security Conference featured in-depth discussions on energy innovation, security, and market viability. Fatih Birol, IEA executive director, discussed growing global energy demand, especially the rapid rise in electricity outpacing overall growth. He noted electricity demand is projected to increase six times faster than total energy in 10 years, underscoring the need for electrification and grid expansion. As energy systems become decentralized and digitalized, the CEO of E.ON, Leonhard Birnbaum, said: “You’re either fully digitized – or you’re done.” Key takeaways: Energy security requires developing and securing electricity grids Technological openness is a unifying element for getting to net zero Bridge the “Valley of Death” to scale markets New global partnerships will help Europe stay competitive Public acceptance will strengthen democracy You can read the full Executive Summary from the BMW Foundation here.

a crowd of people outside of a white building

In a 5-4 split decision, the US Supreme Court on Wednesday ordered the Trump administration to disburse nearly $2 billion in foreign aid funds for work completed by contractors and grant recipients under the US Agency for International Development and the State Department. Does this tell us much about how the top court will handle future Trump-related cases?