Saturday, 22 February 2025
25.8 C
Singapore
26.3 C
Thailand
20.3 C
Indonesia
26.1 C
Philippines

TikTok faces a challenge as hackers inject coronavirus videos in people’s accounts

Imagine this: you are scrolling your TikTok feed, and you all over sudden notice a video that you did not upload in your account. It turns out that this is possible after a team of software developers discovered a vulnerability on TikTok that allows hackers to swap videos. Talal Haj Bakry and Tommy Mysk shared their […]

Imagine this: you are scrolling your TikTok feed, and you all over sudden notice a video that you did not upload in your account. It turns out that this is possible after a team of software developers discovered a vulnerability on TikTok that allows hackers to swap videos.

Talal Haj Bakry and Tommy Mysk shared their findings in a post, which explained that the platform uses CDNs (Content Delivery Networks) to transfer their data across the world effectively. So as to improve their performance, these CDNs transfer the data over HTTP, which is unencrypted instead of choosing HTTPS, which is more secure and doesn’t put user’s data at risk.

“Any router between the TikTok app and TikTok’s CDNs can easily list all the videos that user has downloaded and watched, exposing their watch history,” Mysk wrote. “Public Wi-Fi operators, internet service providers, and intelligence agencies can collect this data without much effort,” he further added.

Since TikTok transfers data such as profile pictures and videos via HTTP, these developers found it susceptible to attacks. Basically, attackers could alter the content in transmission, then swap the real video on an account with a fake of their choosing.

They demonstrated how problematic this issue could be by inflicting a DNS attack on a local network. Using the discovered vulnerability, the developers uploaded a video that shared coronavirus misinformation and injected it into WHO’s (World Health Organization) TikTok account. They were also able to use the same process and upload fake videos on TikTok verified accounts such as the Red Cross.

To do it, the developers tricked the TikTok app into directing to a fake server that they had set up and mimicked the CDN servers of TikTok. “This can be achieved by actors who have direct access to the routers that users are connected to,” the duo explained in their post.

However, a malicious actor can use their method and cause some real damage. “If a popular DNS server was hacked to include a corrupt DNS record…misleading information, fake news, or abusive videos would be viewed on a large scale, and this is not completely impossible,” the developers explained.

Tommy Mysk confirmed that the decision to choose HTTP over HTTPS sets TikTok apart from high-profile platforms such as YouTube, Instagram, Facebook, Twitter, and Snapchat, which all transfer their data using HTTPS.

TikTok has always claimed that it is a secure platform, but several security flaws that have been discovered recently have led to some government workers in the US being banned from using the platform, and this latest security issue is definitely not good news for the company.

Hot this week

MOVA unveils innovative smart cleaning solutions in Singapore

Experience the future of smart home cleaning with MOVA’s latest innovations—the Z50 Ultra robot vacuum and X4 Pro wet & dry vacuum. Unveiled at Jewel Changi Airport, these cutting-edge appliances redefine effortless cleaning with AI-driven intelligence, advanced mopping, and powerful suction.

Humane’s AI Pin discontinued as HP acquires startup for US$116M

HP has acquired Humane for US$116M, ending AI Pin sales. Customers must back up data before devices stop working on February 28, 2025.

American Airlines introduces AirTag location sharing for lost luggage

American Airlines now supports Apple’s AirTag location sharing, making it easier for passengers to track and recover lost luggage.

Broadcom and TSMC are reportedly considering deals to break up Intel

Broadcom and TSMC are reportedly exploring deals to acquire parts of Intel, with potential concerns over foreign control of US chip factories.

Singapore businesses embrace AI to boost efficiency

Singapore businesses and government agencies use AI to improve efficiency, reduce costs, and enhance productivity, as shared at Microsoft’s AI Tour.

DJI’s RS 4 Mini stabiliser now features advanced subject tracking

DJI’s RS 4 Mini stabiliser introduces subject tracking, improved battery life, and better handling, making it an excellent tool for content creators.

American Airlines introduces AirTag location sharing for lost luggage

American Airlines now supports Apple’s AirTag location sharing, making it easier for passengers to track and recover lost luggage.

Google may launch YouTube Premium Lite in more countries

Google may launch YouTube Premium Lite in the US, Australia, Germany, and Thailand, offering a cheaper plan with fewer ads. Pricing is yet to be confirmed.

Nvidia introduces priority access for RTX 5080 and 5090 Founders Edition GPUs

Nvidia introduces Verified Priority Access for RTX 5090 and 5080 FE GPUs, letting gamers apply for an invite to buy one card per person.

Related Articles