Skip to main content

TikTok vows more secure connections after vulnerability found

After a pair of developers discovered a security vulnerability that would allow hackers to swap fake videos into a TikTok users’ feed, the social media company said it’s rolling out more secure connections for all of its users.

The hack preys on TikTok’s use of basic unencrypted HTTP connections in some regions to distribute media through its content delivery networks. Software developers Tommy Mysk and Talal Haj Bakry found that this security gap made it easy for them to insert their own fake videos into the TikTok feeds during the connection.

In response, TikTok told Digital Trends it is rolling out the most secure HTTPS connection to all of its regions.

“TikTok prioritizes user data security and already uses HTTPS across several regions, as we work to phase it in across all of the markets where we operate,” a spokesperson told Digital Trends.

TikTok’s network in the U.S. already uses HTTPS, which means that when you look at TikTok in the U.S., no one can read the data that is streaming between your phone and TikTok’s database.

The developers who found the vulnerability were able to make videos showing false claims about the coronavirus appear on a user’s feed. They were even able to impersonate other users.

We tricked #TikTok to connect to our fake server. We hijacked the timeline so the app shows spam videos about #COVID19#Security #Cybersecurity #Hacking
For more on this: https://t.co/0e7RGyleIW pic.twitter.com/49BbkYbunq

— Mysk (@mysk_co) April 13, 2020

Because the server that the developers access is unencrypted, it’s easy to make a fake server that acts in the same way as TikTok’s, and fool the phone into displaying a fake video with incorrect information.

“This is why using HTTP is dangerous and should be considered a cybercrime nowadays,” Mysk told Digital Trends. “This is why our industry introduced HTTPS — S stands for secure. It does exactly what HTTP does but the communication is encrypted. It is hard, very hard, to impersonate servers.”

HTTPS isn’t 100% unbreakable. However, there’s a consensus to use HTTPS for transporting data that’s considered important for the safety of communities. Videos from @WHO and @RedCross must be handled as sensitive data.
Who knows! Maybe this blunder’s caused the #ToiletPaperPanic

— Tommy Mysk (@tommymysk) April 14, 2020

The effect is network-based: Mysk told Digital Trends he could trick a Wi-Fi or data network to redirect to his fake TikTok server, but it would revert to the real server once a user left the network.

This, however, could still be a problem if hackers found their way into a large network, such as a major cell or internet service provider. That bad actor could redirect the traffic of everyone using that network to their own ends.

Or if a government is controlling the internet, the regime could use this method to basically erase TikTok videos, the developers said.

The World Health Organization has partnered with TikTok to help mitigate the spread of misinformation, and in January, TikTok amended its community guidelines to say that they would be removing all “misleading” content from the platform.

Editors' Recommendations

Maya Shwayder
I'm a multimedia journalist currently based in New England. I previously worked for DW News/Deutsche Welle as an anchor and…
TikTok’s experimental third feed has been spotted out in the wild
The TikTok app on a smartphone's screen. The smartphone is sitting on a white table.

TikTok is reportedly working on adding a third feed to its popular short-form video app.

And the experimental TikTok feed has already been tweeted about. On Monday, social media consultant Matt Navarra tweeted about the experimental feature and noted that it will work "in conjunction with a new option giving creators the ability to add a location tag to videos." And then on Wednesday morning, Brendan Gahan tweeted an actual image of the new feed, which appears next to TikTok's Following and For You feeds. In Gahan's photo, the feed is called "Nearby":

Read more
The 10 most popular TikTok accounts
The TikTok app on a smartphone's screen. The smartphone is sitting on a white table.

TikTok continues to grow in popularity, and with the sheer volume of content that TikTok accounts churn out, we have to wonder: What kind of TikTok accounts have the most followers? What does it take to be one of the most popular TikTok accounts?

To help answer those questions, we put together a list of the top 10 most popular TikTok accounts. For this list, by "most popular," we mean the accounts with the most followers on TikTok. Below, we'll show you which TikTok accounts have the most followers and take a closer look at the sort of content they create.
10. Dixie D'amelio (@dixiedamelio) — 57.4 million followers
https://www.tiktok.com/@dixiedamelio/video/7104500048163114282?is_from_webapp=1&sender_device=pc&web_id=7008995637514110469

Read more
TikTok bans influencers from creating paid political ads
A person's hand holding a phone with the TikTok app on it.

Now that we're much closer to the U.S. midterm elections, over the past week or so platforms like Twitter have been announcing their plans for defending against election misinformation on their appNow, TikTok has joined its competitors in doing the same.

On Wednesday, TikTok issued a statement on its "commitment to election integrity," written by Eric Han, its Head of U.S. safety. In the statement, Han outlined TikTok's own plans for reducing election misinformation on its short-form video-sharing app.

Read more