Live data from Hacker News

TikTok requests access to devices on local network

twitter.com

131–140 of 158 posts

Re: TikTok requests access to devices on local network

#131
post #31

Earlier quoted context omitted.

For MS I suspect either incompetence or laziness and just checking all the permissions (because a lot of Teams seems poorly thought out and designed by committee, probably an “agile” one too). As for Tick Tock it’s obviously spyware meant for direct user identification. How anyone can use it when it’s uploading their biometric information (face, voice) to the CCP is beyond stupidity.

It's TikTok* and do you have any evidence to support what you're saying or you're just pulling this from thin air?

So far from what I’ve seen, it is mostly along the lines of “they technically can, so I assume they do.”

Even when it comes to someone like me, who is very strongly anti-CCP, it definitely irks me a bit. Mostly because making strong accusations like that without any reasoning other than “they can, so they definitely do it” only makes that position look weaker and more difficult to align with. Why make up those things and accusations, when there are so many other valid points for criticism there? There is a reason for why “the boy who cried wolf” is a very commonly referenced parable.

Re: TikTok requests access to devices on local network

#132

Microsoft Teams does this as well, purportedly for video calling (!?) Was there ever an explanation why the permissions are needed?

It saves Microsoft traffic if people are in the same office building / corporate VPN and can exchange audio/video streams directly vs having to go through a MS-provided STUN/TURN intermediate server.

Re: TikTok requests access to devices on local network

#133
post #111

Earlier quoted context omitted.

I honestly don’t know what exactly irony means. unironically = sincerely/earnestly

Right; I wasn't playing grammar gotcha. I use my laptop for non-work activities, and I guess I do so sincerely. Do people use their laptops or desktops for non-work activities somehow insincerely?

Sure, for example as a last resort when your phone or whatever has died, but the charger is over there, ugh.

Re: TikTok requests access to devices on local network

#134
post #97

Earlier quoted context omitted.

I would argue the point was the opposite. It began with a request for authorization.

I don't see how this is any different than walking into a building and telling the concierge you're a maintenance worker.

Because the IoT devices are invited, EULA and all. You aren't invited just because you walked in.

Re: TikTok requests access to devices on local network

#135
post #13

Earlier quoted context omitted.

Any discussion of intent is always going to be speculation. All we can think about is what such a thing would be capable of if it were somehow malicious. The first possibility that comes to my mind would be sniffing Ethernet MAC addresses because it could be done without any sort of device-specific support built in to the app. Assuming your local devices’ manufacturers are following Da Rulez, the first part of their…

If I was a state intelligence service I would love TikTok. Especially if it was legally banned in my country so was used almost exclusively by foreigners. One better was if the government had a controlling stake in the company [0] and laws requiring the company to be virtually transparent to demands from state security agencies [1]. Not only does TikTok have a ton of overt data about users but also contemporaneous da…

The only actual issue with this setup for citizens of the US is that US citizens like to be the people with access to the data and doing the spying. What you have described, a state intelligence service with access to loads of user data that they happily use for spying is what the US has normalized. Collecting all this data is par for the course (Snowden exposed that pretty conclusively) and non US citizens have no rights as far as the US is concerned. Are they (china) doing it, probably not, seems like a lot of effort for very little gain I mean you find out that I like puppy videos and mostly stay in my house. It's a fun app though :) - also to the original person's tweet, most of the apps on my iphone pop this up from time to time, so if we are going to accuse TikTok of spying on me we should be accusing Calm and Insight Timer too (to randomly pick two).

Re: TikTok requests access to devices on local network

#136

Earlier quoted context omitted.

The cool thing about phones is that you can MITM yourself and see what apps are sending, assuming they don't certificate pin (which TikTok doesn't). The person that reported this during the beta period didn't find any evidence when doing so. https://old.reddit.com/r/videos/comments/fxgi06/not_new_news...

Can you actually still widely do this? Last time I checked on the latest versions of Android apps don't accept user certificates so you can't really do much about any https traffic, which really is the bulk.

There is a way to do it where you recompile the APK to enable trusting user CAs, see https://daksh.github.io/MITM/.

Re: TikTok requests access to devices on local network

#137

For some technical context: this dialog pops up the first time an app attempts to send a packet to a local device. A "common" reason why this happens are actually your own network devices if you're connected on wifi. For instance sending a custom DNS query to the wifi advertised DNS server (if it's the router) will cause that dialog. Same thing happens if you happen to have a router redirect certain resources to itse…

I‘ve had many apps, even very trustworthy ones, show me this permission prompt when my internet connection was down and the router was directing all requests to an error page. So it‘s possible for this prompt to appear without the app developer doing anything bad. Not giving TikTok much benefit of doubt though.

Re: TikTok requests access to devices on local network

#138
post #97

Earlier quoted context omitted.

I don't see how this is any different than walking into a building and telling the concierge you're a maintenance worker.

Because the IoT devices are invited, EULA and all. You aren't invited just because you walked in.

Most people I know never invited network scanning. They were surprised by a Trojan holding their new TV hostage though (if they even noticed.)

Re: TikTok requests access to devices on local network

#139

Just to add: Scanning networks to gather data seems pretty popular these days - smart tvs have done so, and even the ebay site used to portscan visitors [1]. [edit] And of course, there's WebRTC leaking your local IP - which ublock origin can specifically block [2]. [1] https://www.bleepingcomputer.com/news/security/ebay-port-sca... [2] https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-l...

Iirc the ebay thing was yet another way to fingerprint you to re-identify fraudulent account creators.

That might be a justification you could slip past a judge who doesn't understand...

I wonder if I could rob a bank, then if I got caught claim "I was just checking to make sure they had enough money to cover my deposits!"

Re: TikTok requests access to devices on local network

#140

Earlier quoted context omitted.

If I was a state intelligence service I would love TikTok. Especially if it was legally banned in my country so was used almost exclusively by foreigners. One better was if the government had a controlling stake in the company [0] and laws requiring the company to be virtually transparent to demands from state security agencies [1]. Not only does TikTok have a ton of overt data about users but also contemporaneous da…

The only actual issue with this setup for citizens of the US is that US citizens like to be the people with access to the data and doing the spying. What you have described, a state intelligence service with access to loads of user data that they happily use for spying is what the US has normalized. Collecting all this data is par for the course (Snowden exposed that pretty conclusively) and non US citizens have no r…

AFAIK Calm and Insight don't have hundreds of millions of users nor is the CCP on their corporate boards. But with explanations provided by the apps as to why they want network device access they probably shouldn't be trusted.

As for the data collection, TikTok/ByteDance is definitely going to store it. They wouldn't collect it otherwise. To the utility of the data, if they've got MAC addresses of devices on your home network they can tell many of the brands of devices you own. They know when you get a new computer even if you never use TikTok on it. If you launch the app at your office they get the same information about your office network. In aggregate their network scanning will collect vast amounts of data.

The TikTok app is turning every user into a passive network scanner. Even if you want to ignore the CCP's influence on ByteDance I don't think there is any reason to give them the benefit of the doubt about their data collection. They'll sell their users and anyone around them. I have the same problem with Facebook and their damn shadow profiles and covert data collection.

Post reply on HN