Thread was locked by
a moderator
  • Jun 29, 2022

    So apparently TikTok has been reversed engineered and yeah it’s bad.

    The TL;DR is in the bullet points of the next wall of text that comes from a reddit post. Basically, they have your location every 30 seconds, set up a proxy on your phone, etc. It also changes it behavior as you poke inside it which is really strange. On Pegasus levels of maliciousness

    Here’s the news article:

    engadget.com/fcc-commissioner-google-facebook-ban-tik-tok-064559992.html

    "TikTok is not just another video app. That's the sheep’s clothing." That's what Brendan Carr wrote in his tweet along with a copy of the letter he sent Apple and Google, asking the companies to remove TikTok from their app stores. The agency's senior Republican commissioner references a recent BuzzFeed News report that examined leaked audio from 80 internal TikTok meetings. Based on those leaked audio recordings, China-based employees of TikTok parent company ByteDance had repeatedly accessed private information on users in the US.

    One member of TikTok's Trust and Safety department reportedly said during a meeting in September 2021 that "everything is seen in China." A director said in another meeting that a Beijing-based engineer referred to as "Master Admin" has "access to everything." Just hours before BuzzFeed News published its report, TikTok announced that it migrated 100 percent of US user traffic to a new Oracle Cloud Infrastructure. It's part of the company's efforts to address concerns by US authorities about how it handles information from users in the country.

    And here’s a reddit link with a lot of details about what someone who reverse engineered found:

    I'm getting together the data now and enlisted the help of my colleagues who were also involved in the RE process. We'll be publishing data here over the next few days: reddit.com/r/tiktok_reversing. I invite any security folk who have the time to post what they've got as well - known domains and ip addresses for sysadmins to filter on, etc. I understand the app has changed quite a bit in recent versions, so my data won't be up to date.

    I understand there's a lot of attention on this post right now, but please be patient.

    So I can personally weigh in on this. I reverse-engineered the app, and feel confident in stating that I have a very strong understanding for how the app operates (or at least operated as of a few months ago).

    TikTok is a data collection service that is thinly-veiled as a social network. If there is an API to get information on you, your contacts, or your device... well, they're using it.

    • ⁠Phone hardware (cpu type, number of course, hardware ids, screen dimensions, dpi, memory usage, disk space, etc)
    • ⁠Other apps you have installed (I've even seen some I've deleted show up in their a***ytics payload - maybe using as cached value?)
    • ⁠Everything network-related (ip, local ip, router mac, your mac, wifi access point name)
    • ⁠Whether or not you're rooted/jailbroken
    • ⁠Some variants of the app had GPS pinging enabled at the time, roughly once every 30 seconds - this is enabled by default if you ever location-tag a post IIRC
    • ⁠They set up a local proxy server on your device for "transcoding media", but that can be abused very easily as it has zero authentication

    The scariest part of all of this is that much of the logging they're doing is remotely configurable, and unless you reverse every single one of their native libraries (have fun reading all of that assembly, assuming you can get past their customized fork of OLLVM!!!) and manually inspect every single obfuscated function. They have several different protections in place to prevent you from reversing or debugging the app as well. App behavior changes slightly if they know you're trying to figure out what they're doing. There's also a few snippets of code on the Android version that allows for the downloading of a remote zip file, unzipping it, and executing said binary. There is zero reason a mobile app would need this functionality legitimately.

    On top of all of the above, they weren't even using HTTPS for the longest time. They leaked users' email addresses in their HTTP REST API, as well as their secondary emails used for password resets. Don't forget about users' real names and birthdays, too. It was allllll publicly viewable a few months ago if you MITM'd the application.

    Here's the thing though.. they don't want you to know how much information they're collecting on you, and the security implications of all of that data in one place, en masse, are f***ing huge. They encrypt all of the a***ytics requests with an algorithm that changes with every update (at the very least the keys change) just so you can't see what they're doing. They also made it so you cannot use the app at all if you block communication to their a***ytics host off at the DNS-level.

    For what it's worth I've reversed the Instagram, Facebook, Reddit, and Twitter apps. They don't collect anywhere near the same amount of data that TikTok does, and they sure as hell aren't outright trying to hide exactly whats being sent like TikTok is. It's like comparing a cup of water to the ocean - they just don't compare.

    reddit.com/r/videos/comments/fxgi06/not_new_news_but_tbh_if_you_have_tiktiok_just_get

  • Jun 29, 2022

    Get some b****es NOW. Ole dusty boy…

  • Jun 29, 2022
    ·
    7 replies

    DAVIDP won

  • Jun 29, 2022
    ·
    1 reply

    Been known

  • Jun 29, 2022
    math fifty

    DAVIDP won

  • rvi
    Jun 29, 2022
    math fifty

    DAVIDP won

  • Jun 29, 2022
    ·
    1 reply

    DAVIDP, the P stand for prophet

  • eclass ⛓️
    Jun 29, 2022
    ·
    1 reply

    wasnt this the first critique when TikTok came out lol never trusted that s***

  • Jun 29, 2022
    ·
    1 reply

    Ok, now get rid of Facebook

  • Jun 29, 2022
    ·
    2 replies

    Imagine ever downloading the app

  • Jun 29, 2022
    math fifty

    DAVIDP won

  • Jun 29, 2022
    ·
    2 replies
    Undecided

    Ok, now get rid of Facebook

    i agree, but apparently Facebook doesn’t even come near the amount of data tiktok collects, doesn’t try to hide it either

    the researcher compared it to a water bottle and an ocean

  • Jun 29, 2022
    Pups

    Imagine ever downloading the app

    yeah not to be like edgy or contrarian, but i stayed away from the app personally because i didn't want it to ruin certain songs for me

  • Jun 29, 2022
    ·
    1 reply
    eclass

    wasnt this the first critique when TikTok came out lol never trusted that s***

    Yeah none of this s*** is new people just don't care

  • Jun 29, 2022
    ·
    2 replies

    Lighters up for DAVIDP

  • Jun 29, 2022
    Nute

    Been known

  • Jun 29, 2022

    This not gonna scare 1 billion users off the app cause of how entertaining, addicting, and useful all the info you can find on it lmao.

    No one gives a s***

  • Jun 29, 2022
    Fries

    Lighters up for DAVIDP

  • Jun 29, 2022
    ·
    1 reply
    hot pancakes

    i agree, but apparently Facebook doesn’t even come near the amount of data tiktok collects, doesn’t try to hide it either

    the researcher compared it to a water bottle and an ocean

    Facebook still tracks you even after you delete your account and the app.

  • Jun 29, 2022

    DAVID P and the P stands for Proletariat

  • Jun 29, 2022

    Location pinging every 30 seconds is crazy

  • Jun 29, 2022

    Dont have it

  • Jun 29, 2022
    Pups

    Yeah none of this s*** is new people just don't care

    yeah it was always said, but information from this level of reverse engineering on it wasn’t available yet

Thread was locked by
a moderator