Skip to main content
  1. Home
  2. Social Media
  3. News

TikTok vows more secure connections after vulnerability found

Add as a preferred source on Google
 

After a pair of developers discovered a security vulnerability that would allow hackers to swap fake videos into a TikTok users’ feed, the social media company said it’s rolling out more secure connections for all of its users.

Recommended Videos

The hack preys on TikTok’s use of basic unencrypted HTTP connections in some regions to distribute media through its content delivery networks. Software developers Tommy Mysk and Talal Haj Bakry found that this security gap made it easy for them to insert their own fake videos into the TikTok feeds during the connection.

In response, TikTok told Digital Trends it is rolling out the most secure HTTPS connection to all of its regions.

“TikTok prioritizes user data security and already uses HTTPS across several regions, as we work to phase it in across all of the markets where we operate,” a spokesperson told Digital Trends.

TikTok’s network in the U.S. already uses HTTPS, which means that when you look at TikTok in the U.S., no one can read the data that is streaming between your phone and TikTok’s database.

The developers who found the vulnerability were able to make videos showing false claims about the coronavirus appear on a user’s feed. They were even able to impersonate other users.

We tricked #TikTok to connect to our fake server. We hijacked the timeline so the app shows spam videos about #COVID19#Security #Cybersecurity #Hacking
For more on this: https://t.co/0e7RGyleIW pic.twitter.com/49BbkYbunq

— Mysk 🇨🇦🇩🇪 (@mysk_co) April 13, 2020

Because the server that the developers access is unencrypted, it’s easy to make a fake server that acts in the same way as TikTok’s, and fool the phone into displaying a fake video with incorrect information.

“This is why using HTTP is dangerous and should be considered a cybercrime nowadays,” Mysk told Digital Trends. “This is why our industry introduced HTTPS — S stands for secure. It does exactly what HTTP does but the communication is encrypted. It is hard, very hard, to impersonate servers.”

HTTPS isn’t 100% unbreakable. However, there’s a consensus to use HTTPS for transporting data that’s considered important for the safety of communities. Videos from @WHO and @RedCross must be handled as sensitive data.
Who knows! Maybe this blunder’s caused the #ToiletPaperPanic

— Tommy Mysk (@tommymysk) April 14, 2020

The effect is network-based: Mysk told Digital Trends he could trick a Wi-Fi or data network to redirect to his fake TikTok server, but it would revert to the real server once a user left the network.

This, however, could still be a problem if hackers found their way into a large network, such as a major cell or internet service provider. That bad actor could redirect the traffic of everyone using that network to their own ends.

Or if a government is controlling the internet, the regime could use this method to basically erase TikTok videos, the developers said.

The World Health Organization has partnered with TikTok to help mitigate the spread of misinformation, and in January, TikTok amended its community guidelines to say that they would be removing all “misleading” content from the platform.

Maya Shwayder
I'm a multimedia journalist currently based in New England. I previously worked for DW News/Deutsche Welle as an anchor and…
Reddit may ask you to prove you’re human as it cracks down on bot accounts
Suspicious activity could trigger human verification
Reddit

Reddit is stepping up its fight against bots, and now your account could be asked to prove it is human if the platform detects fishy behaviour.

Reddit CEO Steve Huffman says these checks will be rare, but they are meant to protect what makes Reddit work in the first place – real people talking to real people.

Read more
You are about to see a flood of product recommendations on Instagram and Facebook
Meta’s new tools let creators plug products directly in content, with Amazon and Shopee leading the first wave of in-feed buying.
facebook

The line between content and commerce just got a lot harder to see, as your Instagram and Facebook feeds are about to shift in a noticeable way.

Meta is rolling out new affiliate tools that let creators tag items directly inside posts and Reels, which means more recommendations will show up right where you’re already scrolling.

Read more
Reddit wants to check if you’re using the iPhone’s Face ID camera
The company is considering new identity tools to tackle its growing bot problem
Reddit app on iPhone

Reddit may soon ask users to prove they’re human, and it might involve your face. During a TBPN podcast, Reddit's CEO, Steve Huffman, confirmed that the platform is exploring new identity verification methods, including using Face ID or Touch ID-style authentication, to tackle its growing bot problem.

https://twitter.com/alexisohanian/status/2035154057942245514?s=20

Read more