Hopp til innhold

Everyone going to the World Cup must have this app - experts are now sounding the alarm

Security experts believe Qatar's required mobile app will be like giving the World Cup country's authorities the key to your house.

Qatar illustrasjon

There are some apps that everyone going to Qatar must have in order to enter the country. Experts advise everyone who will be travelling there to be aware of what they are agreeing to.

Foto: Montasje NTB / skjermdump Apple Store

Norwegian version

It's not my job to give travel advice, but personally I would never bring my mobile phone on a visit to Qatar.

That's what NRK's head of security Øyvind Vasaasen says after a thorough review of the apps.

Everyone travelling to Qatar during the football World Cup will be asked to download two apps called Ehteraz and Hayya.

Briefly, Ehteraz is an covid-19 tracking app, while Hayya is an official World Cup app used to keep track of match tickets and to access the free Metro in Qatar.

In particular, the covid-19 app Ehteraz asks for access to several rights on your mobile., like access to read, delete or change all content on the phone, as well as access to connect to WiFi and Bluetooth, override other apps and prevent the phone from switching off to sleep mode.

The Ehteraz app, which everyone over 18 coming to Qatar must download, also gets a number of other accesses such as an overview of your exact location, the ability to make direct calls via your phone and the ability to disable your screen lock.

The Hayya app does not ask for as much, but also has a number of critical aspects. Among other things, the app asks for access to share your personal information with almost no restrictions. In addition, the Hayya app provides access to determine the phone's exact location, prevent the device from going into sleep mode, and view the phone's network connections.

EHTERAZ

The Ehteraz app, which everyone over the age of 18 going to Qatar must download, is receiving particular criticism.

Foto: Faksimile / Appstore

They can simply change the contents of your entire phone and have full control over the information that is there, is the conclusion of NRK's security manager.

It has come to NRK’s attention that since Vasaasens comments were based on the privacy statement of the app, this fact was not sufficiently emphasized. The head of security made statements on the legal framework of the app, not its technical capacities.

As part of the media house's preparations for the Qatar WC, he has reviewed these apps.

Vasaasen is downright frightened by what NRK's security review has uncovered.

When you download these two apps, you accept the terms stated in the contract, and those terms are very generous. You essentially hand over all the information in your phone. You give the people who control the apps the ability to read and change things, and tweak it. They also get the opportunity to retrieve information from other apps if they have the capacity to do so, and we believe they do.

– You're giving them the opportunity

The security chief explains that it is essentially like the authorities getting full access to your house.

You're saying that it is perfectly fine for the authorities to enter your home. They get a key, and they can get in. You don't know what they're doing there. They say they might not make use of the chance, but you're giving them the opportunity. And you would never do that, Vasaasen points out.

Øyvind Vasaasen leder DAB-arbeidet i NRK.

Øyvind Vasaasen, Head of Security at NRK.

Foto: Anne Liv Ekroll

NRK has asked Bouvet and Mnemonic, two independent IT security companies, to review the apps and give us their conclusions.

– Can do quite a lot of bad things

The Ehteraz app in particular receives criticism, and it is compared to the first Smittestopp (Stop Infection) app in Norway.

It was, after all, a privacy scandal. If someone has slightly more evil intentions than the Institute of Public Health, then you can do quite a lot of bad things with the information that the app collects in the first place, says Martin Gravåk at the Bouvet company.

He explains that the app tracks where you go, and the mobile phones that are near you. In this way, they can cross-link the information and find out who you are meeting and talking to.

If you're hunting the opposition, gays, or others you don't like, an app like this will make it much easier for you," Gravåk states.

Arab Cup - Final - Tunisia v Algeria

The world cup starts november 20th.

Foto: IBRAHEEM AL OMARI / Reuters

The Mnemonic company also compares the Ehteraz app with the first version of Smittestopp.

The consequences for individuals and groups if data from Ehteraz goes astray can be significant," says Tor Erling Bjørstad of Mnemonic to NRK.

He has downloaded the apps and analysed what is in the application packages, and does not think the apps are hair-raising compared to "normal apps" that most people use.

At the same time, they process data, particularly linked to GPS and position, which has a high potential for abuse. In a way, you have to trust the people who develop or own the apps, and it is not a given that you particularly want to trust the authorities in Qatar.

However, his technical analysis found no signs that they can actually change things that are stored locally on the mobile device, but nevertheless warns that the reason may be that it has not yet been implemented.

NRK has submitted the findings about the apps' security holes to FIFA. They tell us that they do not wish to comment on the matter.

Les også Qatar forbereder seg på fengslede VM-fans – supporterunion slår sikkerhetsalarm

Fotballsupportere utenfor Lusail stadion, der VM-finalen skal spilles 18. desember.

Increases the risk

Naomi Lintvedt, research fellow at the Faculty of Law at the University of Oslo, has reviewed the apps at the request of NRK.

She agrees with NRK's head of security that there is much that is problematic, and describes the apps as «very intrusive».

You cannot consent to parts of the use, just everything. If I understand the apps correctly, there will also be limited options to change permissions there. This means that if you want to go to the WC, you have no choice. This is a mandatory app, with no options," she points out.

Lintvedt says bluntly that if she were an employer, she would not allow employees to take their work mobile phone to Qatar.

Even as a private person, she would have been very sceptical about using her own phone in the World Cup host country.

What is the main criticism against these apps, as you see it?

They go far too far in terms of what data is recorded and used. They get far too broad of access to change and take over functionality on your mobile phone, which appears to be completely unnecessary. It allows for government surveillance, and since it is Qatar, that has to be considered as well. This increases the risk that data will be used for purposes other than pure infection tracking, she believes.

Sportsnyheter

Jan Jönsson

Treneren stormet banen, ble utvist og prøvde å klemme dommer: – Ikke akseptabel oppførsel

I kampen mellom Vålerenga og Stabæk ble det baluba på overtid. I sentrum: Stabæk-trener Jan Jönsson.

Siste nytt

  • Grøvdal vraker 10.000 meter i EM – går for ny distanse

    Karoline Bjerkeli Grøvdal (33) endrer konkurranseplanen for sommerens europamesterskap i Roma.

    Hun dropper 10.000 meter og planlegger for å løpe halvmaraton.

    Det bekrefter hun overfor NRK.

    Nå satser hun på å løpe 5000 meter fredag 7. juni og halvmaraton 9. juni – og regnes som en sterk medaljekandidat på begge distansene.

    – Det kan være en morsom kombo det, sier Grøvdal, som presiserer at hun vil ta en endelig avgjørelse etter det første løpet.

    Hun vant nylig New York halvmaraton på tiden 1.09.09 minutter. Hun er rangert som den femte beste europeeren i kategoriene 5000 meter og gateløp.

    Grøvdal har vel å merke ikke tatt EM-kravet på 32 minutter på 10.000 meter, men det ville vært for en formalitet å regne. Hun har løpt minuttet raskere to ganger på asfalt, men måtte tatt på seg piggsko for å kvalifisere seg til europamesterskapet. Det ønsker hun ikke å prioritere i en viktig treningsperiode inn mot EM- og OL-sesongen.

    Den erfarne langdistanseprofilen har bronse på 10.000 meter og 3000 meter hinder fra tidligere europamesterskap, samt at hun har vunnet EM i terrengløp tre år på rad.

    Halvmaraton er ikke en tradisjonell mesterskapsøvelse, men arrangeres i EM i år som sammenfaller med OL.

    PS! EM i Roma og OL i Paris ser du på NRK.

    Friidretts-VM 2023: Pressetreff
    Foto: Beate Oma Dahle / NTB
  • Storhamar sikret gullet etter «sliteseier»: – Ekstrem lettelse

    Storhamar vant den femte NM-finalen med 4-3 over Vålerenga i forlengning. Med 4-1 i kamper kunne vertene juble for tittelen.

    Eirik Salsten ble helten med scoring 50 sekunder ut i spilleforlengelsen. Da eksploderte det på Hamar – som hadde «mætt fjøs» med over 7100 tilskuere.

    For veteran Patrick Thoresen ble det ekstra spesielt å vinne foran familien på tribunen.

    – Det er helt magisk. Jeg har jo vært med på veldig mange finaler, dessverre tapt veldig mange de siste par åra, så det var en ekstrem lettelse å få være med å vinne. Jeg har drømt om dette. Dette har vært et stort, stort mål de siste åra mine, sier Thoresen til NRK.

    – Det er helt sykt at det er 7000 mennesker her som har fulgt oss i tykt og tynt mer eller mindre i hele år.

    Med tirsdagens triumf er Storhamars åttende kongepokal i boks. Vålerenga er fortsatt ledende i Norge med sine 26 «bøtter».

    Tross tapet, lar Storhamar-trener Petter Thoresen seg imponere av motstanden og kaller tirsdagens kamp for en «sliteseier».

    – Imponert av Vålerenga. De har mistet flere sentrale spillere og kriget mot Oilers i syv kamper. Jeg er faktisk imponert over det de leverer, skal jeg være helt ærlig, sier Thoresen til NRK.

    Og det var gjestene fra hovedstaden som kom best i gang i den femte kampen i NM-sluttspillet. Lagets storscorer Thomas Olsen satte 1-0 etter tre og ett halvt minutt. Da Storhamar fikk muligheten i overtall i midtperioden satte Peter Quenneville inn utligningen. Storhamar gikk så opp til 2-1, før Magnus Brekke Henriksen utlignet for Vålerenga.

    55 minutter og 25 sekunder ut i kampen sendte Jakob Berglund Storhamar nok en gang opp i ledelsen, men 12 sekunder før slutt sikret Vålerenga spilleforlengelse da Christopher Bengtson satte 3-3. I spilleforlengelsen sørget Saltsten for seier til Storhamar. (NRK/NTB)

    NM finale Ishockey Storhamar IL - Vålerenga IF i CC Amfi. SIL - VIF
    Foto: Cornelius Poppe / NTB
  • Sævik med ny scoring da Vålerenga beholdt tabelltoppen

    Både Karina Sævik og Iris Omarsdottir scoret sitt fjerde mål for sesongen da Vålerenga slo Stabæk 3-2 på hjemmebane i Toppserien tirsdag.

    Kampen skulle opprinnelig spilles i september, men ble framskyndet for å legge til rette for Vålerengas deltakelse i mesterligakvalifiseringen. Med tirsdagens seier ligger Vålerenga og Rosenborg på topp med tolv poeng, men VIF har bedre målforskjell. Deretter følger Røa med ni.

    Vålerengas hjemmeseier tirsdag kom etter scoringer av Olaug Tvedten, Ylinn Tennebø og Sævik, som scoret sitt fjerde mål for sesongen. For gjestene sto spisstalentet Omarsdottir for begge nettkjenningene – den siste fem minutter før slutt. 20-åringen har i likhet med Sævik scoret fire ganger denne sesongen.

    Stabæk står med seks poeng etter to seirer og tre tap hittil. Vålerenga har byderby mot Lyn til helgen, mens Stabæk får besøk av Brann. (NTB)

    Toppserien fotball 2023: Vålerenga - LSK Kvinner
    Foto: Lise Åserud / NTB

Sendeplan

Kl. Program Kanal