Earlier quoted context omitted.
With a buffer overflow, you can write your own code into a chunk of memory that ends up being run by the application. In this case, since WhatsApp already had SMS read privileges as part of the signup auth flow, the attacker also had those privileges. The article has some detail about the remote code execution part of this exploit. “What this means is that there was a software flaw in the WhatsApp code for handling M…
So the payload would be some corrupted video file sent to Bezo's phone. Would the attack look something like: 1) Discover/buy/steal Bezo's Whatsapp number (how did they do that...) 2) Discover/buy/steal a 0-day bug in Whatsapp. 3) Write and compile a program that reads SMS from the OS and beacons it to some server you control. 4) Create a corrupted video file that would trigger the video parsing bug, and within that…
Amazon says email banning TikTok from employee phones was ‘sent in error’
461–470 of 496 posts
Re: Amazon says email banning TikTok from employee phones was ‘sent in error’
#462Earlier quoted context omitted.
I'm not so sure. Reddit skews young, yet the narrative there is that TikTok and the Chinese gov are just shy of evil. The iOS clipboard bug in particular has startled reddit into a wave of self-reinforcing "TikTok is spyware" stories and comments. A story like this one just reinforces that narrative, and I'm not sure there's any way TikTok is coming back from it.
I'd guesstimate the average redditor is somewhere in their late 20s to mid 30s. Compared to Congress, that's certainly young. But that's about twice the age of what I imagine the average tiktok user to be (teens.)
Re: Amazon says email banning TikTok from employee phones was ‘sent in error’
#463Earlier quoted context omitted.
Someone goes through all the trouble of typing that explicit email and it's a mistake? Sounds more like 'pulled after huge feedback'. Though personally I'd agree with this decision. TikTok seems to be a particularly bad apple: https://www.reddit.com/r/videos/comments/fxgi06/not_new_news...
I keep seeing that Reddit thread linked (even the NYT is citing it now?) but still cannot for the life of me figure out what substantially TikTok does that is a concern compared to other popular apps? The guy has like 10 paragraphs of stories but no actual evidence? What is TikTok doing that somehow is flying under the app store guidelines of both Google and Apple but still a "national security concern"? Why is the o…
https://penetrum.com/tiktok/Penetrum_TikTok_Security_Analysi...
https://penetrum.com/tiktok/tiktok_15.2.3_static_analysis.pd...
Things they found - Excessive data collection - Privacy policies that allow distribution of said data - Execution of OS commands - Insecure cryptography usage - Potential SQL injection code from user defined variables - Storing of API tokens - Webview enabled by default along with insecure webview enabled - App copies data to clipboard. Sensitive data should not be copied to clipboard as other applications can access it. - Files may contain hardcoded informations like usernames, passwords, keys etc.
Re: Amazon says email banning TikTok from employee phones was ‘sent in error’
#464Earlier quoted context omitted.
I keep seeing that Reddit thread linked (even the NYT is citing it now?) but still cannot for the life of me figure out what substantially TikTok does that is a concern compared to other popular apps? The guy has like 10 paragraphs of stories but no actual evidence? What is TikTok doing that somehow is flying under the app store guidelines of both Google and Apple but still a "national security concern"? Why is the o…
Honestly I can't figure it out either. We found out other apps too (like LinkedIn) constantly check the clipboard, and one HN commenter here said it was due to a text editing library, nothing intentional. Literally the only fact is that it's a Chinese company. And it's not like there's even much it seems like they could do, with how sandboxed phone apps are. I'm not saying iOS or Android are perfectly secure, but it'…
https://penetrum.com/tiktok/Penetrum_TikTok_Security_Analysi...
https://penetrum.com/tiktok/tiktok_15.2.3_static_analysis.pd...
Things they found - Excessive data collection - Privacy policies that allow distribution of said data - Execution of OS commands - Insecure cryptography usage - Potential SQL injection code from user defined variables - Storing of API tokens - Webview enabled by default along with insecure webview enabled
Re: Amazon says email banning TikTok from employee phones was ‘sent in error’
#465Earlier quoted context omitted.
Honestly I can't figure it out either. We found out other apps too (like LinkedIn) constantly check the clipboard, and one HN commenter here said it was due to a text editing library, nothing intentional. Literally the only fact is that it's a Chinese company. And it's not like there's even much it seems like they could do, with how sandboxed phone apps are. I'm not saying iOS or Android are perfectly secure, but it'…
I don’t think it just hate for China, or politics. Real security researchers are finding really bad things. https://penetrum.com/research https://penetrum.com/tiktok/Penetrum_TikTok_Security_Analysi... https://penetrum.com/tiktok/tiktok_15.2.3_static_analysis.pd... Things they found - Excessive data collection - Privacy policies that allow distribution of said data - Execution of OS commands - Insecure cryptography u…
Other social networking and entertainment apps are crammed full of tracking code, analytics, advertising networks, that all collect excessive user data, don't put it in their privacy policies, etc. And similarly, we hear about bad use of cryptography and SQL all the time.
Apps can be pretty bad in general with these things.
Now obviously, apps and code in general should be improved.
But the question here is, is TikTok really that much worse? That it's such a worse threat than others, that it needs to be banned? Because that's what I still don't see evidence of.
Re: Amazon says email banning TikTok from employee phones was ‘sent in error’
#466Earlier quoted context omitted.
It is literally a checkbox item for PCI DSS.
Can you share the requirement from PCI DSS? [it's not]
Re: Amazon says email banning TikTok from employee phones was ‘sent in error’
#467Earlier quoted context omitted.
My understanding was that TikTok was basically the Chinese response to periscope and vine, which was popular, but couldn't make money. TikTok's scheme is to be spyware that even puts Facebook to shame, in a way that I'm not convinced isn't just government spyware disguised as social media where the point isn't to make a profit to begin with. If similar attempts have failed because of monetization struggles, I don't s…
Some extra info to establish your point which I totally agree with: https://www.reddit.com/r/videos/comments/fxgi06/not_new_news... TikTok is really exceptionally bad in this regard.
Re: Amazon says email banning TikTok from employee phones was ‘sent in error’
#468I feel like this TikTok backlash is so overblown. I don't think TikTok is spying on US consumers/business, and I don't think TikTok is sharing any US private data with CCP... I believe this because there's no evidence to the contrary, and out of principle you shouldn't assume malintent. In fact, TikTok explicitly left Hong Kong because if they didn't they would have to share private data with CCP to comply with new l…
Some light reading: https://rufposten.de/blog/2019/12/05/privacy-analysis-of-tik... https://docs.google.com/document/d/1QEyWqAiTE_5xzCs_X3tjDCQx... https://www.reddit.com/r/videos/comments/fxgi06/not_new_news... https://www.washingtonpost.com/world/tiktoks-owner-is-helpin... https://www.thetimes.co.uk/article/video-app-linked-to-china... https://www.wired.com/story/tiktok-is-the-latest-window-into... https://thehill.…
"... the device information, usage time and list of watched videos are being sent to Appsflyer and Facebook."
Hardly a smoking gun. Not only is this standard industry practice but the analytics servers in question here are American. The author says this violates European law (it doesn't). Then they go on to describe device fingerprinting which is also standard practice and has legitimate uses.
The second article's main point is that there are Chinese IP addresses in the APK and the privacy policies of different Chinese companies allow for data sharing.
The author doesn't witness any communication with these IP addresses. There are plenty of non-malicious reasons why a URL or IP address of a different company (Chinese or otherwise) would be in an APK. Maybe there is a library being used or the code in question might not even pertain to non-Chinese region versions. It would be like accusing a website of stealing data because they could use a Google font (interaction with Google IP address) and Google has such and such a privacy policy or history.
The famous Reddit comment which everyone seems to love is clearly fake. The author provided zero evidence when asked, saying that the hard drive on their MacBook failed and it is too difficult to "reverse engineer" the apps again. The accusations and methods are irredeemably vague. If the United States is going to become like China and start banning apps then it shouldn't be over a Reddit comment written by someone whose dog ate their homework.
Re: Amazon says email banning TikTok from employee phones was ‘sent in error’
#469Earlier quoted context omitted.
From what I read, I think the issue is people keep claiming it does all this various "spyware" stuff, when it sounds like it's doing nothing that any other app could do, given the (what appear to be) lax permissions of android/ios. If people are so worried about what tiktok can be gathering outside of the app, that is a problem for apple & google. For this, I think it's 100% overblown what people think tiktok is doin…
This wasn't just the clipboard thing though. Some more elaboration: https://www.reddit.com/r/videos/comments/fxgi06/not_new_news...
Re: Amazon says email banning TikTok from employee phones was ‘sent in error’
#470Earlier quoted context omitted.
Gen Z was addicted to Vine before it. And it will be addicted to anything else that comes after it. No addiction is greater than national security. And the US Government is not obligated to TikTok in any way, shape or form. It can ban without any consideration to the number of people "addicted" to the platform.
> No addiction is greater than national security. I'm tired of "national security" being thrown around willy nilly. If the US government has proof that this is a security risk, they need to be public and transparent with their proof. Anything short of that and I'm not on board with "a ban". That said, I agree that young kids and those who compulsively use social networks are fickle and are likely to move onto another…
You don't need proof when the CCP is itself giving you so much evidence. Infact I should be asking Americans as to what is wrong with you guys that you are supporting a totalitarian government? The CCP passed a new cyber security law in January of this year (called the MLPS 2.0) where it has given itself full power to have unrestricted access to any data transmitted or stored within CCP.
“There will be no secrets,” writes Steve Dickinson on the China Law Blog. “No VPNs. No private or encrypted messages. No anonymous online accounts. No confidential data. Any and all data will be available and open to the Chinese government….there will be no place for foreign-owned companies to hide.” [1]
What about foreign investors? It gets even worse!
"It’s exactly as bad as it sounds, and it gets worse. The MLPS 2.0 is supported by two additional pieces of legislation, both of which strip away any protections, safeguards, and loopholes that might once have been used to maintain the sanctity of corporate data. Both went into effect at the beginning of this month.
The first is a new Foreign Investment Law which, as Dickinson notes, treats foreign investors exactly the same as Chinese investors. Although this has been billed as a means of simplifying the investment process, in practice it strips foreign investors of many of the rights they previously enjoyed. Areas of the market previously closed to foreign companies will remain closed.
The second, as reported by Engadget, establishes a new set of guidelines surrounding encryption. Again, on the surface, these seem like they were proposed with the common good in mind. It’s only on closer examination that cracks start to appear." [1]
And you are telling me here that this isn't a threat to the National Security? TikTok is obligated to share your data without even being asked for because of this Chinese law. And before you say that TikTok operates in US and not in China, its parent company ByteDance is a Chinese company. You cannot form a Chinese company without adhering to these laws! Do you really want the US Government to come out and confirm this when China has itself passed such a law?
[1]: https://www.datacenterdynamics.com/en/opinions/chinas-new-cy...