Skip to main content

TikTok vows more secure connections after vulnerability found

After a pair of developers discovered a security vulnerability that would allow hackers to swap fake videos into a TikTok users’ feed, the social media company said it’s rolling out more secure connections for all of its users.

The hack preys on TikTok’s use of basic unencrypted HTTP connections in some regions to distribute media through its content delivery networks. Software developers Tommy Mysk and Talal Haj Bakry found that this security gap made it easy for them to insert their own fake videos into the TikTok feeds during the connection.

In response, TikTok told Digital Trends it is rolling out the most secure HTTPS connection to all of its regions.

“TikTok prioritizes user data security and already uses HTTPS across several regions, as we work to phase it in across all of the markets where we operate,” a spokesperson told Digital Trends.

TikTok’s network in the U.S. already uses HTTPS, which means that when you look at TikTok in the U.S., no one can read the data that is streaming between your phone and TikTok’s database.

The developers who found the vulnerability were able to make videos showing false claims about the coronavirus appear on a user’s feed. They were even able to impersonate other users.

We tricked #TikTok to connect to our fake server. We hijacked the timeline so the app shows spam videos about #COVID19#Security #Cybersecurity #Hacking
For more on this: https://t.co/0e7RGyleIW pic.twitter.com/49BbkYbunq

— Mysk 🇨🇦🇩🇪 (@mysk_co) April 13, 2020

Because the server that the developers access is unencrypted, it’s easy to make a fake server that acts in the same way as TikTok’s, and fool the phone into displaying a fake video with incorrect information.

“This is why using HTTP is dangerous and should be considered a cybercrime nowadays,” Mysk told Digital Trends. “This is why our industry introduced HTTPS — S stands for secure. It does exactly what HTTP does but the communication is encrypted. It is hard, very hard, to impersonate servers.”

HTTPS isn’t 100% unbreakable. However, there’s a consensus to use HTTPS for transporting data that’s considered important for the safety of communities. Videos from @WHO and @RedCross must be handled as sensitive data.
Who knows! Maybe this blunder’s caused the #ToiletPaperPanic

— Tommy Mysk (@tommymysk) April 14, 2020

The effect is network-based: Mysk told Digital Trends he could trick a Wi-Fi or data network to redirect to his fake TikTok server, but it would revert to the real server once a user left the network.

This, however, could still be a problem if hackers found their way into a large network, such as a major cell or internet service provider. That bad actor could redirect the traffic of everyone using that network to their own ends.

Or if a government is controlling the internet, the regime could use this method to basically erase TikTok videos, the developers said.

The World Health Organization has partnered with TikTok to help mitigate the spread of misinformation, and in January, TikTok amended its community guidelines to say that they would be removing all “misleading” content from the platform.

Maya Shwayder
I'm a multimedia journalist currently based in New England. I previously worked for DW News/Deutsche Welle as an anchor and…
TikTok Now is the latest attempt to clone BeReal
A series of three mobile screenshots showing TikTok's new TikTok Now feature.

If you liked BeReal and its daily post prompts, TikTok now offers a new feature based on a similar concept.

On Thursday, TikTok announced its own take on daily prompts via a series of tweets. Called TikTok Now, the new feature is expected to send daily notifications to users that prompt them to post a short (10 seconds) video or photo of what they're currently doing.

Read more
TikTok’s experimental third feed has been spotted out in the wild
The TikTok app on a smartphone's screen. The smartphone is sitting on a white table.

TikTok is reportedly working on adding a third feed to its popular short-form video app.

And the experimental TikTok feed has already been tweeted about. On Monday, social media consultant Matt Navarra tweeted about the experimental feature and noted that it will work "in conjunction with a new option giving creators the ability to add a location tag to videos." And then on Wednesday morning, Brendan Gahan tweeted an actual image of the new feed, which appears next to TikTok's Following and For You feeds. In Gahan's photo, the feed is called "Nearby":

Read more
The 10 most popular TikTok accounts
The TikTok app on a smartphone's screen. The smartphone is sitting on a white table.

TikTok continues to grow in popularity, and with the sheer volume of content that TikTok accounts churn out, we have to wonder: What kind of TikTok accounts have the most followers? What does it take to be one of the most popular TikTok accounts?

To help answer those questions, we put together a list of the top 10 most popular TikTok accounts. For this list, by "most popular," we mean the accounts with the most followers on TikTok. Below, we'll show you which TikTok accounts have the most followers and take a closer look at the sort of content they create.
10. Dixie D'amelio (@dixiedamelio) — 57.4 million followers
https://www.tiktok.com/@dixiedamelio/video/7104500048163114282?is_from_webapp=1&sender_device=pc&web_id=7008995637514110469

Read more