Decompiled 2022 Beijing Olympics Apps
github.com
github.com
I see a screenshot of normal app startup, some random wireshark requests, some traces of what looks like a login/account system and some localization strings. The de-minified Javascript in the screenshot that author claims he could "clearly see the data was being exfiltrated" looks to me like a random Icon with some attrs. How is this relevant to exfiltration?
(Side-note his claim that he "performed a MITM attack to capture this iOS specific data" sounds more sensational than it actually is. He just put a transparent proxy in the middle, and didn't really attack anything)
The iFlytek stuff could be relevant and is interesting but there is so much noise, big headlines and "read my full report", that it feels to me the author tried very hard to find anything to post
Not saying the app is innocent. It's important to look more into what it's phoning home, but this is just the impression I got from reading through it. Maybe the full report will have some more solid findings in it. Still very cool that the entire decompiled source has been uploaded, that will get more curious eyes on it
Found some privacy policies:
https://raw.githubusercontent.com/jonathandata1/2022_beijing...
https://my2022.beijing2022.cn/app-config-extra/protocal.html...
https://citizenlab.ca/2022/01/cross-country-exposure-analysi...
To me the scariest is the exfiltration of so much personal data to parts unknown. Often unencrypted even.
CCP got apple over the barrel. All these companies talking principles is just smoke and mirrors
If you know what the author is referring to, can you link the relevant files so we can take a look at them?
Dan Borges (aka @1njection ) wrote a blog about him last year https://lockboxx.blogspot.com/2021/10/the-shenanigans-of-jon...
I personally have not looked in to either this or his previous disclosures, but my spider sense is tingling based on the sensational language he uses in his tweets like this one https://twitter.com/jonathandata1/status/1486466958992228366
So I would maybe be a bit careful in putting too much into this before there is some more validation, I think the citizenlab article linked elsewhere in this discussion had a more balanced take on it.
Will take what he posts with a big grain of salt
It's a mixture of spam filtering ("... for sale", gambling, drugs/weapons) and swearwords, that you'd expect to find in western apps as well. But there are also a lot of phrases about the CCP, dissidents and Tibet/Taiwan.
No idea about the second one - but every single major mainland Chinese politician and ministry is on the list too, so it is probably just yet another political topic they want to monitor/suppress...
Looking through this list, I'm fairly certain that this is something like that because it also includes a bunch of Chinese government entity names that clearly would not be censored in China and also includes a lot of terms relating to pornography.
So the round about point is "88 event" likely refers to a specific string in an advertisment that was once loaded by an affiliate and found to be undesirable for one reason or another and not any sort of specifically political event or similar.
https://github.com/jonathandata1/2022_beijing/blob/main/ille...
Some on the list
> China has no freedom of speech
whoever wrote that into "illegalwords.zh-CN.en.txt" must have been aware of the irony...
Looking through this list, I'm fairly certain that this is something like that because it also includes a bunch of Chinese government entity names that clearly would not be censored in China and also includes a lot of terms relating to pornography.
As a result, while the publicised list included things that the CPC may seek to censor, the full list showed that it was mostly porn filtering and similar and included blocks for advertisements from the CPCs main newspaper (people's daily). Briefly looking through the illegal words list, it looks very much the same and also includes a wide range of Chinese government entities and so its likely not censorship functionality in the way you'd expect but more likely things the company would prefer not to advertise to users.
I've asked the original poster for more information, specifically for which classes contain the functionality he suspects but have gotten no response-- my suspicion is that he just read the strings of the program and made some assumptions, e.g. "monitor thread" probably doesn't mean what he thinks it does but I can't discern because I can't get a clear statement about what he thinks just screenshots with red arrows and him pointing to a decompiled application telling me to read it without referencing what exactly inside contains the suspect functionality.
Decompiled #Olympics2022 #iOS and #Android Apps available on Github Now. Evidence of Chinese data exfiltration although the Apple App store claims "Data Not Collected" This repo directly correlates with my full report I will be releasing.
Does anyone have the link?
I checked their twitter and couldn't see it. Though their (current) latest tweet is "After reverse engineering all of the #Beijing2022 #spyware app for @Apple #ios and @Google #Android I can definitively say all Olympian audio is being collected, analyzed and saved on Chinese servers using tech from USA blacklisted AI firm @iflytek1999".
Can't trust the Chinese Government and IOC to not fuck this up.
For those who want a tldr:
The android app for olympics allows the developers to get all your contacts, listen to your microphone, wifi & bluetooth device connections, location, files. It starts at startup, can hide and reorder itself, can REMOTELY download files and trigger all kinds of tracking and spoofing.
Basically, anyone who installs this app on their device will throw away all the privacy not just while the app is installed, but also possibly long-term since with the amount of permissions, you cannot be sure it won't leave a remotely downloaded trojan horse in your device after dumping all your files, contacts and listening to your conversations. From controlling the narrative to spying on other teams and coaches, anything goes with this one.
And it's not just that this permission list is batshit insane (remember that batman scene with all the phone data giving him a full 3D image of the city? that level of batshit insane) - its insane Google is allowing this to be published.
Most of those trigger a specific Android permission popup at runtime to grant access when actually needed/used. The app doesn't them just by the user installing it.
They've become a liability to leave in. Basically killed the entire beacon industry since some people used those to track exact location.
Whatever these apps doing in the background, it takes a lot of energy. That is probably one of the reasons why you can rent power packs literally everywhere in China.
Surprisingly, that not all of the reason, although push notifications does count. It's like Facebook's (Android) app (which famously tries to not remove something as much as possible due to bad app design), but much more heavier. This is why Chinese Android builds (without Google Services) has heavy-handed "battery optimizations" (more like killing apps).
This is mandatory in China?
So maybe it's not just the apps that make a difference, it could also be your location. Your battery can drain faster when your phone is searching more frequently for a cell signal.
And this can happen on trips because of the different local cellular operators and the different frequency bands used.
This is of course only a hypothesis.