PanamaTimes

Friday, Jul 26, 2024

‘Weaponised app’: Is Egypt spying on COP27 delegates’ phones?

‘Weaponised app’: Is Egypt spying on COP27 delegates’ phones?

Security analysts warn smartphone app for Sharm el-Sheikh climate talks could be used for spying as it has ‘highly intrusive’ access to locations, conversations and images.

Cybersecurity concerns have been raised at the United Nations’ COP27 climate talks over an official smartphone app that reportedly has carte blanche to monitor locations, private conversations and photographs.

About 35,000 people are expected to attend the two-week climate conference in Egypt, and the app has been downloaded more than 10,000 times on Google Play, including by officials from France, Germany and Canada.

Egypt’s Ministry of Communications and Information Technology developed the app for the summit’s delegates.

It is meant to assist attendees in smoothly navigating the conference, but “the government of Egypt may have weaponised the app and now has the ability to surveil all of the summit attendees”, David Bader, an expert in data science and cybersecurity, told Al Jazeera.

Analysts warn the COP27 app can extensively monitor the user’s movement and communications, and is able to read users’ email and encrypted messages, record phone conversations, and even scan the entire device for sensitive information.

Bader noted while the developer states the app does not collect data: “Surprisingly the app does have the strange ability to access the user’s name, phone number and email address, all of the user’s email – with the ridiculous explanation for ‘app functionality’ and one’s photos for ‘account management’.

“Would you want a stranger accessing your private photos, let alone a foreign government?” Bader said, warning there could be more clandestinely going on with the app.




No ‘smoking gun’ on data collection


The majority of apps ask permission to access various aspects of a smartphone, including location for GPS functions or cameras for social media, but users need to be cautious, said Kevin Curran, professor of cybersecurity at Ulster University.

“One has to ask whether each of these permissions are necessary,” Curran said, describing the COP27 app as “highly intrusive”.

“In this case, it is difficult to identify a smoking gun. What we cannot ascertain is whether the Egyptian government is using this for data collection,” Curran told Al Jazeera.

He noted, however, the app could continue to provide information on users even after the climate conference ends on November 18.




‘Refuted completely’


According to an analysis of the app by American media group Politico, it can monitor communications even when the device is in sleep mode.

Egypt’s COP27 ambassador Wael Aboulmagd denounced the speculation, telling reporters a cybersecurity assessment was completed and, “I was told how unlikely, or physically or technically impossible” it would be to use the app so intrusively.

Since it is available on Google Play and the Apple Store, those companies “would never allow that” because of security protocols, he added.

“There has been a cybersecurity assessment done and it refuted that completely,” said Aboulmagd.

But Bader warned delegates with the app on their phones remain vulnerable. “Intelligence may be gathered not just about their positions on climate change, but also on trade negotiations, political activities and military operations,” he said.


Some rights activists have criticised the decision for Egypt to host COP27, citing a long track record of cracking down on political dissent. Tens of thousands of people are estimated to have been jailed.

A number of attendees have shared that the WiFi at the climate conference blocks access to websites such as Human Rights Watch and Egypt’s independent outlet Mada Masr, as well as Al Jazeera.

For those concerned about the COP27 app, cybersecurity experts recommend using a “burner phone”, or secondary device, while being aware their conversations and other communications could be monitored.

Those who already have the app should uninstall it as a first step, they say.


Comments

Oh ya 2 year ago
Yup 400 private jets fly in and they then tell you to stop driving your 4 cylinder Toyota. Pay more tax and buy a energy use heavy electric vehicle and all will be good. You realize your electric car is power by a fossil fuel fired power plant i hope

Newsletter

Related Articles

PanamaTimes
0:00
0:00
Close
Mexican Drug Lords El Mayo and El Chapo's Son Arrested in Texas
World's Hottest Day Recorded on July 21
Joe Biden Withdraws from 2024 US Presidential Race
A Week of Turmoil: Key Moments in US Politics
Global IT Outage Sparks Major Concerns
Global IT Outage Unveils Digital Vulnerabilities
Secret Service Criticized for Lack of Sniper Protection During Trump Shooting
Colombian Court Annuls Amazon Tribes’ Carbon Credit Deal
Sunita Williams Safe on ISS, to Address Earth on July 10
Biden Affirms Commitment To Presidential Race
Boeing Pleads Guilty Over 737 MAX Crashes
Beryl Storm Hits Texas, Killing 2 and Causing Major Power Outages
2024 Predicted to Be World's Hottest Year
Macron Faces New Political Challenges Despite Election Relief
Florida Man Arrested Over Attempt to Withdraw One Cent
Anger mounts at Biden’s top team after disastrous debate
Bolivian President Luis Arce Denies 'Self-Coup' Allegations
Steve Bannon Begins 4-Month Prison Sentence
Biden Warns of 'Dangerous Precedent' After Supreme Court Immunity Ruling in Trump Case
Elon Musk Accuses Kamala Harris of Misleading Post on Trump's Abortion Stance
Hunter Biden Sues Fox News Over 'Revenge Porn' Allegations
New York Times Editorial Board Urges Biden to Exit Presidential Race
US Supreme Court Overturns Obstruction Charges Against January 6 Rioters
US Voters Prefer Biden's Democracy Approach, Trump's Economy Plan: Report
Attempted Coup in Bolivia: President Urges Public Mobilization
Top-Secret US Underwater Drone 'Manta Ray' Revealed on Google Maps
United States Bans Kaspersky Antivirus
Inside El Salvador’s 40,000 Inmate Mega-Prison
Toyota, Mazda, Honda, and Suzuki have committed fraud; falsified safety test results
El Salvador's Bitcoin Holdings Reach $350 Million
Teens Forming Friendships with AI Chatbots
WhatsApp Rolls Out Major Redesign
Neuralink's First Brain Implant Experiences Issue
Apple Unveils New iPad Pro with M4 Chip, Misleading AI Claims
OpenAI to Announce Google Search Competitor
Apple Apologizes for Controversial iPad Pro Ad Featuring Instrument Destruction
German politician of the AFD party, Marie-Thérèse Kaiser was just convicted & fined $6,000+
Changpeng Zhao Sentenced to Four Months in Jail
Biden Administration to Relax Marijuana Regulations
101-Year-Old Woman Mistaken for a Baby by American Airlines: Comical Mix-Up during Flight Check-in
King Charles and Camilla enjoying the Inuit voice singing performance in Canada.
New Study: Vaping May Lower Fertility in Women Trying to Get Pregnant
U.S. DOJ Seeks Three-Year Sentence for Binance Founder Changpeng Zhao
Headlines - Thursday, 23 April 2024
Illinois Woman Wins $45M Lawsuit Against Johnson & Johnson and Kenvue for Mesothelioma Linked to Baby Powder
Panama's lates news for Friday, April 19
Creative menu of a Pizza restaurant..
You can be a very successful player, but a player with character is another level!
Experience the Future of Dining: My Visit to an AI-Powered Burger Joint
Stabbing rampage terror attack in Sydney, at least four people killed, early reports that a baby was among those stabbed.
×