- Joined
- 23 Aug 2018
- Messages
- 25,761
- Solutions
- 6
- Reaction score
- 32,556
TikTok has been exploding in popularity in recent years. The latest TikTok flaw surfaced online after two iOS developers used a simple hack to trick the app into connecting to their fake server.
This was possible because TikTok uses HTTP instead of HTTPS to pull in media content from the company’s Content Delivery Networks (CDNs). Using HTTP improves data transfer performance, but the lack of encryption puts users at risk. The developers — known collectively as Mysk — were able to leverage this to switch videos published by TikTok users with different videos via a DNS attack on a local network.
These developers just hacked the TikTok app with a DNS attack
This was possible because TikTok uses HTTP instead of HTTPS to pull in media content from the company’s Content Delivery Networks (CDNs). Using HTTP improves data transfer performance, but the lack of encryption puts users at risk. The developers — known collectively as Mysk — were able to leverage this to switch videos published by TikTok users with different videos via a DNS attack on a local network.
These developers just hacked the TikTok app with a DNS attack