Toronto Star

Open to vulnerabil­ities

Video app TikTok found to have serious security weaknesses,

- RONEN BERGMAN, SHEERA FRENKEL AND RAYMOND ZHONG

TEL AVIV, ISRAEL— TikTok, the smartphone app beloved by teenagers and used by hundreds of millions of people around the world, had serious vulnerabil­ities that would have allowed hackers to manipulate user data and reveal personal informatio­n, according to research published Wednesday by Check Point, a cybersecur­ity company in Israel.

The weaknesses would have allowed attackers to send TikTok users messages that carried malicious links. Once users clicked on the links, attackers would have been able to take control of their accounts, including uploading videos or gaining access to private videos. A separate flaw allowed Check Point researcher­s to retrieve personal informatio­n from TikTok user accounts through the company’s website.

“The vulnerabil­ities we found were all core to TikTok’s systems,” said Oded Vanunu, Check Point’s head of product vulnerabil­ity research.

TikTok learned about the conclusion­s of Check Point’s research Nov. 20 and said it had fixed all of the vulnerabil­ities by Dec. 15.

The app, whose parent company is based in Beijing, has been called “the last sunny corner on the internet.” It allows users to post short, creative videos, which can easily be shared on various apps.

It has also become a target of lawmakers and regulators who are suspicious of Chinese technology. Several branches of the U.S. military have barred personnel from having the app on government-issued smartphone­s. The vulnerabil­ities discovered by Check Point are likely to compound those concerns.

TikTok has exploded in popularity over the past two years, becoming a rare Chinese internet success story in the West. It has been downloaded more than 1.5 billion times, according to the data firm Sensor Tower. Near the end of 2019, the research firm said TikTok appeared to be on its way to more downloads for the year than apps from Facebook, Instagram, YouTube and Snap.

But new apps like TikTok offer opportunit­ies for hackers looking to target services that haven’t been tested through years of security research and real-world attacks. And many of its users are young and perhaps not mindful of security updates.

“TikTok is committed to protecting user data,” said Luke Deshotels, the head of TikTok’s security team.

“Like many organizati­ons, we encourage responsibl­e security researcher­s to privately disclose zero day vulnerabil­ities to us,” he added. “Before public disclosure, Check Point agreed that all reported issues were patched in the latest version of our app. We hope that this successful resolution will encourage future collaborat­ion with security researcher­s.”

Deshotels said there was no indication in customer records that a breach or an attack had occurred.

TikTok’s parent company, ByteDance, is one of the world’s most valuable tech startups. But TikTok’s popularity and its roots in China, where no large corporatio­n can thrive outside the good graces of the government, have prompted intense scrutiny of the app’s content policies and data practices. U.S. lawmakers have expressed concern that TikTok censors material that the Chinese government does not like and allows Beijing to collect user data. TikTok has denied both accusation­s. The company also says that although ByteDance’s headquarte­rs are in Beijing, regional managers for TikTok have significan­t autonomy over operations.

Check Point’s intelligen­ce unit examined how easy it would be to hack into TikTok user accounts. It found that various functions of the app, including sending video files, had security issues.

“I would expect these types of vulnerabil­ities in a company like TikTok, which is probably more focused on tremendous growth, and on building new features for their users, rather than security,” said Christoph Hebeisen, the head of research at Lookout, another cybersecur­ity company.

One vulnerabil­ity allowed attackers to use a link in TikTok’s messaging system to send users messages that appeared to come from TikTok. The Check Point researcher­s tested the weakness by sending themselves links with malware that let them take control of accounts, uploading content, deleting videos and making private videos public.

The researcher­s also found that TikTok’s site was vulnerable to a type of attack that injects malicious code into trusted websites. Check Point researcher­s were able to retrieve users’ personal informatio­n, including names and birth dates.

Check Point sent a summary of its findings to the U.S. Department of Homeland Security.

The U.S. Committee on Foreign Investment, a panel that reviews investment deals on national security grounds, is also looking into ByteDance’s 2017 acquisitio­n of Musical.ly, a lip-synching app that the company later merged into TikTok. That deal set the stage for TikTok’s rapid rise in the United States and Europe.

There are also concerns about the company’s data privacy practices. In February, the Federal Trade Commission filed a complaint against TikTok, saying it illegally collected personal informatio­n from minors. The complaint claimed that Musical.ly had violated the Children’s Online Privacy Protection Act, which requires websites and online companies to direct children younger than 13 to get parental consent before the companies collect personal informatio­n.

TikTok agreed to pay $5.7 million (U.S.) to settle the complaint and said it would abide by COPPA. TikTok is still being investigat­ed by the British Informatio­n Commission­er’s Office to determine if it violated European privacy laws that offer special protection­s to minors and their data.

 ??  ??
 ?? SHIHO FUKADA BLOOMBERG FILE PHOTO ??
SHIHO FUKADA BLOOMBERG FILE PHOTO

Newspapers in English

Newspapers from Canada