TikTok data breach claims put ByteDance’s short video app back in spotlight amid controversy over Chinese ownership | South China Morning Post

TikTok data breach claims put ByteDance’s short video app back in spotlight amid controversy over Chinese ownership
Cybersecurity analysts tweeted about the discovery of an insecure server on Monday, but claims of leaked personal data are inconclusive
TikTok said claims about the breach were incorrect and that the code was ‘completely unrelated’ to its back-end source code



Why you can trust SCMP
TOP PICKS


Tech

China looks for silver lining in latest US restrictions on advanced chips

4 Sep 2022

Washington has banned certain high-end chips from being exported to China. Photo illustration: Shutterstock Images
Tech

How Taiwanese chip tycoon Robert Tsao made an about-turn and angered Beijing

6 Sep 2022

Taiwanese chip tycoon Robert Tsao (right), founder of United Microelectronics Corp (UMC). Photo: EPA-EFE
News

‘Stop stealing’: China slams US over alleged Trojan virus hacking

6 Sep 2022

China has accused US- based hackers of malicious cyberattacks on Chinese networks controlling ‘tens of thousands’ of devices, from servers to firewalls. Photo: Shutterstock
News

Death toll rises to more than 30 in China’s quake-hit Sichuan province

6 Sep 2022

Firefighters get ready for rescue work in Luding county of southwest China’s Sichuan province. Photo: CCTV via AP
Coronavirus

Health chief slams report on quarantine row; Hong Kong logs 10,683 Covid cases

4 Sep 2022

Secretary for Health Lo Chung-mau does not name news outlet but says report had cost the media its integrity. Photo: Sam Tsang
News

Why is retirement beckoning for 11 members of China’s Politburo?

5 Sep 2022

Illustration: Perry Tse
China Macro Economy

China cuts banks’ forex reserve ratio as yuan hits 2-year low against US dollar

6 Sep 2022

China’s yuan has reached a more-than-two-year low against the US dollar. Photo: EPA-EFE
News

Will US Chips Act force academics, tech companies to ‘pick sides’?

3 Sep 2022

A Taiwan Semiconductor Manufacturing Company (TSMC) factory in Nanjing, China. Analysts say new US legislation to lure semiconductor investment is the latest effort to curb collaboration with Chinese researchers. Photo: AFP
Lifestyle

Military Prosecutor Doberman: legal K-drama ends strongly

29 Apr 2022

Ahn Bo-hyun as Do Bae-man in a still from Military Prosecutor Doberman, the popular military legal Korean drama series that has finished with a bang.
Lifestyle

How long do K-dramas run? Your complete guide to show duration

15 Aug 2021

Shin Hye-sun (left) and Kim Jung-hyun in a still from Mr. Queen. K-dramas on prime-time used to run 50+ episodes long. Now, period dramas like Mr. Queen tend to be no more than 20 episodes.

2
2
TikTok’s logo seen on a smartphone in this illustration photo taken on August 22, 2022. Photo: Reuters
TikTok’s logo seen on a smartphone in this illustration photo taken on August 22, 2022. Photo: Reuters
TikTok, the short-video sensation that’s among the world’s most downloaded apps, is coming under increased scrutiny about its data security as it guards the personal information of over a billion users.
On Monday, several cybersecurity analysts tweeted about the discovery of what was purportedly a breach of an insecure server that allowed access to TikTok’s storage, which they believe contained personal user data. Only days earlier, Microsoft Corp said it had found a “high-severity vulnerability” in TikTok’s Android application, “which would have allowed attackers to compromise users’ accounts with a single click”.
ByteDance Ltd’s TikTok surpassed a billion monthly users a year ago and now ranks as many young people’s favourite app. That makes it an enticing target for hackers who may seek to hijack popular accounts or resell sensitive information. It was identified as a privacy threat by the Trump administration in 2020 and nearly banned because of concern about potential links between its Beijing-based parent company and the Chinese government.
TikTok facing fresh scrutiny about possible state influence after Forbes report
12 Aug 2022

TikTok said the claims of a breach discovered over the weekend were incorrect. “Our security team investigated this statement and determined that the code in question is completely unrelated to TikTok’s back-end source code,” a spokesperson said.

Troy Hunt, an Australian web security consultant, went through some of the data samples listed in the leaked files and found matches between user profiles and videos posted under those IDs. But some details included in the leak were “publicly accessible data that could have been constructed without breach”.
“This is so far pretty inconclusive; some data matches production info, albeit publicly accessible info. Some data is junk, but it could be non-production or test data,” he posted on Twitter. “It’s a bit of a mixed bag so far.”
The vulnerability identified by Microsoft is a narrower issue that could have affected mobile phones running Android. It may have allowed attackers to access and modify “TikTok profiles and sensitive information, such as by publicising private videos, sending messages and uploading videos on behalf of users,” wrote Dimitrios Valsamaras from the Microsoft 365 Defender Research Team.
A TikTok spokesperson said the company had responded quickly to Microsoft’s findings and fixed the security flaw, which was found “in some older versions of the Android app”.

00:01 / 00:29
Oracle reaches deal to become TikTok’s ‘technology partner’, after Microsoft offer is rejected
However inconclusive or small the issues may be, there will be intense focus on TikTok and its parent firm at a time when the US may step up its measures against businesses with links to China. In June, nine US senators wrote a public letter to TikTok’s chief executive officer asking him to explain alleged security breaches.
SATURDAY
Inside China Tech Newsletter
By submitting, you consent to receiving marketing emails from SCMP. If you don't want these, tick here
By registering, you agree to our T&C and Privacy Policy
President Joe Biden is expected to sign an executive order that would restrict US investment in Chinese tech companies and separate action targeting TikTok is a possibility, with the administration paying close attention to whether the Chinese government has access to American customer data. The company has told US lawmakers that it has taken steps to protect that data through a contract with Oracle Corp.
“There’s a lot of attention on the way TikTok operates and there’s a big gap between how it operates and how it says it operates,” said Robert Potter, co-CEO of Australian-US cybersecurity firm Internet 2.0 Inc.
In July, Potter’s team said in a report that it had found “excessive data harvesting” carried out by TikTok on user devices, that the app checks device location at least once an hour and it has code that collects serial numbers for both the device and the SIM card.
Biden weights curbs on US investment in China tech
3 Sep 2022

The report received wide attention in Australia, and Clare O’Neil, the new Minister for Home Affairs, announced on Monday that she has ordered her department to investigate what data TikTok acquires and who can access it.
“We’ve got this basic problem here where we’ve got technology companies that are based in countries with a more authoritarian approach to the private sector,” O’Neil said in emailed remarks. “TikTok is not the beginning and the end of this. It’s one of the very large number of issues that’s given rise to by these very dominant technology companies and the role they are playing in our lives.”