Friday, 15 November 2024
26.6 C
Singapore

TikTok faces a challenge as hackers inject coronavirus videos in people’s accounts

Imagine this: you are scrolling your TikTok feed, and you all over sudden notice a video that you did not upload in your account. It turns out that this is possible after a team of software developers discovered a vulnerability on TikTok that allows hackers to swap videos. Talal Haj Bakry and Tommy Mysk shared their […]

Imagine this: you are scrolling your TikTok feed, and you all over sudden notice a video that you did not upload in your account. It turns out that this is possible after a team of software developers discovered a vulnerability on TikTok that allows hackers to swap videos.

Talal Haj Bakry and Tommy Mysk shared their findings in a post, which explained that the platform uses CDNs (Content Delivery Networks) to transfer their data across the world effectively. So as to improve their performance, these CDNs transfer the data over HTTP, which is unencrypted instead of choosing HTTPS, which is more secure and doesn’t put user’s data at risk.

“Any router between the TikTok app and TikTok’s CDNs can easily list all the videos that user has downloaded and watched, exposing their watch history,” Mysk wrote. “Public Wi-Fi operators, internet service providers, and intelligence agencies can collect this data without much effort,” he further added.

Since TikTok transfers data such as profile pictures and videos via HTTP, these developers found it susceptible to attacks. Basically, attackers could alter the content in transmission, then swap the real video on an account with a fake of their choosing.

They demonstrated how problematic this issue could be by inflicting a DNS attack on a local network. Using the discovered vulnerability, the developers uploaded a video that shared coronavirus misinformation and injected it into WHO’s (World Health Organization) TikTok account. They were also able to use the same process and upload fake videos on TikTok verified accounts such as the Red Cross.

To do it, the developers tricked the TikTok app into directing to a fake server that they had set up and mimicked the CDN servers of TikTok. “This can be achieved by actors who have direct access to the routers that users are connected to,” the duo explained in their post.

However, a malicious actor can use their method and cause some real damage. “If a popular DNS server was hacked to include a corrupt DNS record…misleading information, fake news, or abusive videos would be viewed on a large scale, and this is not completely impossible,” the developers explained.

Tommy Mysk confirmed that the decision to choose HTTP over HTTPS sets TikTok apart from high-profile platforms such as YouTube, Instagram, , Twitter, and Snapchat, which all transfer their data using HTTPS.

TikTok has always claimed that it is a secure platform, but several flaws that have been discovered recently have led to some government workers in the US being banned from using the platform, and this latest security issue is definitely not good news for the company.

Hot this week

Best smartphone for 2024: Apple and Samsung, OPPO, Google phones reviewed

Explore the best 2024 smartphones: Samsung Galaxy S24 Ultra, OnePlus 12R, and OPPO Find N3 Flip. Compare AI capabilities, camera tech, and designs to find your ideal match.

Steam’s latest update introduces free gameplay recording for all users

Steam now offers free gameplay recording with easy sharing options for all users.

ChatGPT’s new voice mode brings real-time conversations to desktops

ChatGPT’s Advanced Voice Mode lets PC and Mac users enjoy real-time voice chats, adding natural interaction to AI for an improved user experience.

Meta’s collaboration with the US government fuels questions about AI use

Meta partners with US agencies to explore AI in the public sector, collaborating on projects with the State Department and Department of Education.

ChatGPT launches live search with real-time information

OpenAI launches live search for ChatGPT, enhancing AI accuracy with real-time information, no ads, and media partnerships just in time for the US elections.

Bluesky’s rapid rise: 15 million users and counting

Bluesky reaches 15M users after a sign-up surge, attracting those frustrated with big tech. Will its unique features keep the growth going?

Xiaomi Motion-Activated Night Light 2 review: Smart lighting made simple

Smart, compact, and energy-efficient, the Xiaomi Motion-Activated Night Light 2 offers responsive motion detection and long battery life for everyday convenience.

Beware: Cyber attackers target the aerospace sector with fake job offers

Cybersecurity experts have uncovered a malware campaign targeting aerospace, with fake job offers linked to Iranian hackers imitating North Korean tactics.

AMD claims Ryzen AI processor delivers 75% faster gaming than Intel

AMD’s Ryzen AI 9 HX 370 processor boasts powerful AI and game-boosting tech and claims a 75% gaming performance boost over Intel’s Core Ultra 7.

Related Articles

Popular Categories