Beijing 2022 Winter Olympics app bursting with privacy risks

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,190
The official app for Beijing 2022 Winter Olympics, 'My 2022,' was found to be insecure when it comes to protecting the sensitive data of its users.
Most importantly, the app's encryption system carries a significant flaw that enables middle-men to access documents, audio, and files in cleartext form.

'My 2022' is also subject to censorship based on a list of keywords and has an unclear privacy policy that doesn't determine who exactly receives and processes all the sensitive data users have to upload to it.
As such, it is violating Google's software policy and Apple's App Store guidelines, yet it is available in both stores. Finally, the app violates China's own laws regarding privacy protection.
In a detailed report by Citizen Lab, researchers analyzed the 'My 2022' app for potential privacy and security issues and found that the app collects the following sensitive information:
  • Device identifiers and model
  • Cellular service provider information
  • Installed apps on the device
  • WLAN status
  • Real-time location
  • Audio information
  • Device storage access
  • Location access
 

show-Zi

Level 36
Verified
Top Poster
Well-known
Jan 28, 2018
2,463
Information gathering competitions may also be included in the Olympics.
Global events are a feeding ground for information seekers.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top