Report, be careful if you use TikTok!

Two developers regarding TikTok have claimed that the company uses an insecure network to send its data stores, putting the privacy of TikTok users at risk. Both of them are iOS developers and they say that TikTok allegedly uses “insecure HTTP” to download media content, which puts users’ privacy at risk. To put it simply, if HTTP If traffic is unencrypted, it can be easily tracked and even altered by hackers. This means that TikTok users’ data, including their watch history, can be accessed by hackers. Let us tell you that the company has not yet given any response regarding the security negligence being done by both the developers in TikTok.

TikTok app has recently crossed the mark of 1 billion i.e. 100 crore downloads on Google Play Store. If this statement of negligence in security of both the developers is true then it is obvious that at present the privacy of crores of people is in danger.

The developers, Talal Haj Berry and Tommy Misik, created a blog post It is reported that due to the use of insecure HTTP, hackers can “replace videos shared by TikTok users with any other video they want, even if the video is from a verified account.” It has also been said that this negligence can also expose the watch history of the users.

In their blog post regarding the threat to the security of TikTok users, the developers have further said that like any other social media portal, TikTok also depends on external servers or content delivery networks (CDN) to deliver its data. Could. The post says that TikTok’s CDN opts for unencrypted (insecure) HTTP to transfer video and other media data.

This simply means that anyone who can see this network traffic passing through the Wi-Fi router can also easily read the information coming from TikTok’s servers and use it to copy any other video without the users knowing. Can change with.

The developers say that this flaw is currently only working on one version of TikTok, which includes iOS version 15.5.6 and Android version 15.7.4.

Leave a Reply

Your email address will not be published. Required fields are marked *