Headlines
  • While Iran's economy, military, and leadership have all significantly deteriorated, US President Donald Trump claims that the Strait of Hormuz is in "extremely good shape," adding that "it doesn't mean we won't smack them to see what happens."
  • An apparent mentally unstable woman was shot and killed by New York City police after allegedly stabbing two people in Times Square.
  • Leaders from more than a dozen countries, including Iran's Masoud Pezeshkian, China's Xi Jinping, India's Narendra Modi, and Russia's Vladimir Putin, gathered in Kyrgyzstan on Monday for the Shanghai Cooperation Organization summit.
  • On Monday, Pedro Sanchez, the prime minister of Spain, accused Russian and Israeli-linked social media platforms of spreading disinformation regarding the July refugee crisis in the Spanish enclave of Ceuta.
  • On Monday, US President Donald Trump's administration was given permission by the US Supreme Court to proceed with the $400 million White House ballroom construction project.
  • At least 750 people killed and another 3000 went missing on Wednesday after landslides caused by a glacial collapse unleashed a torrent of mud and water across Nepal and China's autonomous region of Tibet.

More Details

Independent Audit of Hong Kong COVID Tracking System Discloses Vulnerabilities

Review of ‘Leave Home Safe’ apps finds that confidential communications aren’t always secure.

By Roseanne Gerin for RFA English

Hong Kong Kowloon Tong Cornwall Street Park Leave Home Safe sign

An independent audit of the Hong Kong government’s digital COVID-19 contact-tracing apps found significant security issues with the software but said the flaws weren’t necessarily intentionally added to allow for unauthorized tracking. 

The “Leave Home Safe” mobile apps became available for download in November 2020, allowing users to scan a QR code at more than 9,000 locations in Hong Kong, including both public and private venues, and on identification labels in 18,000 taxis to record their movements.

The apps also notified users if a person confirmed with contagious respiratory virus had recently visited those places.

7ASecurity, a Poland-based computer network security and testing firm, conducted a privacy and a security audit of the Leave Home Safe Android and iOS apps in April and May on behalf of an unnamed third party.

Its work was funded by the Open Technology Fund (OTC), a U.S. nonprofit that supports global internet freedom technologies and, like Radio Free Asia, is part of the United States Agency for Global Media, an independent agency of the U.S. government that broadcasts news and information in 63 languages. 

The parties issued the 55-page report on Wednesday.

When the Hong Kong government rolled out the apps, people there raised concern about potential security and privacy risks that they could introduce. Some feared the apps would be used to control Hongkongers amid a citywide crackdown on public protest and dissent over China’s aggressive policies in the special administrative region, according to a previous report by RFA.

Less than half a million downloads of apps occurred during the first two weeks due in part to privacy concerns among city’s roughly 7.5 million people, and many acquired a second mobile device to avoid having sensitive content on the same phone, OTC said in an announcement on its website.

As of Nov. 1, 2021, the Chinese government made use of the apps mandatory for anyone entering government-run buildings, including courts, swimming pools, public markets, hospitals, shopping malls and places of worship. The apps recently began requesting real name registration and tracking users’ movements.

The goal of the audit was to have an independent third party verify whether the official Leave Home Safe privacy and security claims are accurate.

On Wednesday, OTC issued 7ASecurity’s report on the audit results with 12 findings, eight of which are classified as security vulnerabilities and four as general weaknesses with lower exploitation potential. Three of these findings had an estimated severity level of high or critical.

“While no clear privacy violation could be conclusively proven during the audit at runtime, a number of application artifacts, likely inherited from underlying dependencies or simply security vulnerabilities introduced by mistake, were found during this exercise,” the report says.

The privacy audit could not conclusively prove malicious intent or unauthorized tracking of Hongkongers, it says.

One of the identified vulnerabilities was that the Android app failed to validate certificates that secure internet connections by encrypting data sent between a browser, website and website server, allowing communications between two parties to be intercepted by a malicious user without any user warnings.

7ASecurity also found that the Android app stores COVID vaccination and test status images in the mobile device’s Secure Digital (SD) memory storage cards when users try to import such QR Codes from safer locations, such as Google Drive. Android SD Cards are inappropriate locations for sensitive data because thieves can remove them and plug them into a computer to read the data.

Additionally, the audit determined that the Leave Home Safe Android app uses several cryptographic functions with known security weaknesses, either directly or through inherited libraries.

The iOS app does not implement available Data Protection features in iOS, so that most files have a default encryption that keeps the decryption key in memory while the device is locked — the least secure form of data protection available on iOS because a malicious attacker with physical access to the device could use it to read the decryption key from memory and gain access to local app data files, without needing to unlock the device.

Other significant shortcomings were a lack of Hong Kong health code system credentials, valid Hong Kong COVID vaccination QR codes, and valid Hong Kong COVID test QR codes.

“This poor result strongly suggests that the Leave Home Safe mobile apps have not been audited by any competent security firm previously,” OTC said in its announcement. “This is in stark contrast to the documentation in the official Leave Home Safe website, which indicates the mobile applications were audited previously on December 10th 2021, and only a single ‘low’ priority issue was identified.”

7ASecurity recommended that the issues raised in the report be addressed to strengthen the security aspects of the Leave Home Safe platform, and that a thorough review, including a full code audit, be conducted. The firm also suggested regular testing of the platform at least once a year or when substantial changes are to be deployed, to ensure new features do not introduce security vulnerabilities. 

RFA previously reported on Hong Kong police in Hong Kong investigating the origins of a fake app after the government made the Leave Home Safe app compulsory for those entering government-run facilities.

Copyright © 1998-2020, RFA. Used with the permission of Radio Free Asia, 2025 M St. NW, Suite 300, Washington DC 20036. https://www.rfa.org

Related Article

Taiwan Steps Up AI Defenses as…

China is likely to use artificial intelligence to influence Taiwan’s Nov. 28 local elections.Taiwa ...
September 1, 2026

Marianas Voices Demand a Seat at…

As the U.S. government moves forward with plans to open more than 65 million acres of federal waters ...
August 30, 2026

Satellite Imagery Shows Extensive Damage from…

Satellite imagery taken at the Nepal-Tibet border shows extensive destruction from flooding and land ...
August 28, 2026

Hong Kong Court Verdict Aims to…

A Hong Kong court this month convicted two leaders of a dissolved pro-democracy group to erase the m ...
August 26, 2026

China ‘Likely’ Ran Targeted Campaign to…

China “very likely” coordinated a targeted campaign across the Pacific to demonstrate that local ...
August 22, 2026

Proposed US-Led Tech Hub in the…

A U.S. plan to build a critical technology hub in the Philippines is a symbolic return to the site o ...
August 19, 2026

Other Article

Pet Corner

Great Dane

The Great Dane is a working dog breed that developed in Germany and was used for boar hunting.Black, ...
September 1, 2026
Prevent Cyber Crime

Hyperparameters

In machine learning, hyperparameters are a type of configuration variable used to train models effec ...
News & Views

Taiwan Steps Up AI Defenses as…

China is likely to use artificial intelligence to influence Taiwan’s Nov. 28 local elections.Taiwa ...
Pick of the Day

UN General Assembly Holds 109th Plenary…

Kairat Umarov, Permanent Representative of the Republic of Kazakhstan to the United Nations, introdu ...
Bizzare News

For Having Longest Ears of Any…

At 17.12 inches (43.50 cm), Hank, a 16-year-old farm animal from Muncy, Pennsylvania, USA, holds the ...
August 31, 2026
Pet Corner

Basset Hound Dog Breed

The Basset Hound originated in France, however it developed in England.These dogs have wrinkled fore ...

Top