comscore TikTok hacked by 2 developers to highlight security flaws | BGR India
News

TikTok hacked: Popular short-video app hacked by 2 developers to display security vulnerabilities

TikTok still uses HTTP instead of HTTPS to pull in media content from the company’s CDNs. This could be easily exploited by attackers.

  • Updated: April 15, 2020 5:08 PM IST
Tiktok

One of the most downloaded apps of last year, TikTok has been increasing in popularity recently. The short video making platform stood second only to WhatsApp in net Android downloads in 2019. However, with a larger user base come larger privacy concern. Two iOS developers recently used a simple trick to trick the app and connected it to their own fake server. Also Read - TikTok crosses 1 billion downloads on Google Play Store

The hack was largely possible because TikTok uses HTTP instead of HTTPS to pull in media content from the company’s CDNs (Content Delivery Networks). Using HTTP improves data transfer performance. However, it puts users at a risk because of the lack of data encryption. Also Read - Indian government reportedly asked TikTok, Facebook to remove misinformation on coronavirus

Watch: Top 5 apps providing free services during coronavirus pandemic

The developers who hacked the app did something scary following the hack. Mysk (their collective name) proceeded to switch videos posted by TikTok users with their own videos via the DNS attack. The duo managed to switch in videos that shared fake information on the ongoing Coronavirus outbreak. This showed how dangerous the risks here can be. The videos with the fake information could be swapped out for some other video posted by, say the WHO, American Red Cross, or another reputed source of information. Also Read - TikTok donates medical equipment and supply worth Rs 100 crore to fight COVID-19 pandemic

The hack, however, affected only the users directly connected to the developer’s server. Mysk had no malicious intent and only wanted to prove that the attack is possible. The point to be taken here is that if they could do it, so can other attackers with ill-intent. Moreover, not switching to HTTPS would also put TikTok against a bunch of other HTTP-related security vulnerabilities. The hack affected the Android TikTok app version 5.7.4 and the iOS app version 15.5.6.

A couple of days ago, TikTok achieved a new milestone, crossing over a billion downloads on the Google Play Store. Hence it is known that the app has a large user base and then again, this is just the Android user share. The app also has quite a few iOS users. Things get more disturbing when you realize that people are using social media platforms like the app more when in lockdown. This increases the chance of wrong information posted via the app through an attacker.

For the latest tech news across the world, latest PC and Mobile games, tips & tricks, top-notch gadget reviews of most exciting releases follow BGR India’s Facebook, Twitter, subscribe our YouTube Channel.
  • Published Date: April 15, 2020 5:08 PM IST
  • Updated Date: April 15, 2020 5:08 PM IST



new arrivals in india

Realme Narzo 20A
Realme Narzo 20A

8,499

Realme Narzo 20
Realme Narzo 20

10,499

Realme Narzo 20 Pro
Realme Narzo 20 Pro

14,999

Oppo F17
Oppo F17

17,990

Samsung Galaxy M51
Samsung Galaxy M51

24,999

Poco M2
Poco M2

10,999

Oppo F17 Pro
Oppo F17 Pro

22,990

Realme 7 Pro
Realme 7 Pro

19,999

Realme 7
Realme 7

14,999

Xiaomi Redmi 9A
Xiaomi Redmi 9A

6,799

Vivo Y20
Vivo Y20

12,990

Xiaomi Redmi 9
Xiaomi Redmi 9

8,999

Nokia 5.3
Nokia 5.3

13,999

Motorola Moto G9
Motorola Moto G9

11,499

Realme C15
Realme C15

9,999

Realme C12
Realme C12

8,999

Samsung Galaxy Note 20
Samsung Galaxy Note 20

77,999

Xiaomi Redmi 9 Prime
Xiaomi Redmi 9 Prime

9,999

Oppo Reno4 Pro
Oppo Reno4 Pro

34,990

Samsung Galaxy M01 Core
Samsung Galaxy M01 Core

5,499

Realme 6i
Realme 6i

12,999

Asus Rog Phone 3
Asus Rog Phone 3

49,999

OnePlus Nord
OnePlus Nord

24,999

Infinix Smart 4 Plus
Infinix Smart 4 Plus

7,999

Xiaomi Redmi Note 9
Xiaomi Redmi Note 9

11,999

Samsung Galaxy M01s
Samsung Galaxy M01s

9,999

Vivo X50 Pro 5G
Vivo X50 Pro 5G

49,990

Vivo X50 5G
Vivo X50 5G

34,990

Realme C11
Realme C11

7,499

Poco M2 Pro
Poco M2 Pro

13,999

Realme X3
Realme X3

24,999

Realme X3 SuperZoom
Realme X3 SuperZoom

27,999

Tecno Spark Power 2
Tecno Spark Power 2

9,999

Oppo A12
Oppo A12

9,990

Oppo A52
Oppo A52

16,990

Samsung Galaxy A21s
Samsung Galaxy A21s

15,999

Oppo Find X2
Oppo Find X2

64,990

Motorola One Fusion Plus
Motorola One Fusion Plus

17,499

Samsung Galaxy A31
Samsung Galaxy A31

20,999

Samsung Galaxy M01
Samsung Galaxy M01

8,999

Samsung Galaxy M11
Samsung Galaxy M11

10,999

Infinix Hot 9 Pro
Infinix Hot 9 Pro

9,999

LG Velvet
LG Velvet

Price Not Available

Xiaomi Mi Note 10 Lite
Xiaomi Mi Note 10 Lite

Price Not Available

Apple iPhone SE 2020
Apple iPhone SE 2020

42,500

Honor 30 Pro
Honor 30 Pro

Price Not Available

Honor 30
Honor 30

Price Not Available

OnePlus 8
OnePlus 8

44,999

OnePlus 8 Pro
OnePlus 8 Pro

54,999

Xiaomi Redmi Note 9 Pro
Xiaomi Redmi Note 9 Pro

13,999

Motorola Moto E4
Motorola Moto E4

8,999

Samsung Galaxy On Max
Samsung Galaxy On Max

9,775

nubia N2
nubia N2

15,999

Karbonn K9 Kavach 4G
Karbonn K9 Kavach 4G

5,290

Motorola Moto C Plus
Motorola Moto C Plus

6,999

Best Sellers