TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Guy Who Reverse-Engineered TikTok Reveals the Scary Things He Learned

367 点作者 ko3us将近 5 年前

23 条评论

Thorrez将近 5 年前
2 days ago: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23665084" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23665084</a><p>4 days ago: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23638129" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23638129</a>
creato将近 5 年前
I don&#x27;t doubt at all that TikTok is super shady, but<p>&gt; I&#x27;m getting a lot of DM&#x27;s asking me to prove the majority of this with a paper and snippets of the offending code. I have a decent amount of my notes on my other laptop that recently had a motherboard failure and the majority of that data is on the laptop&#x27;s SSD. It&#x27;s a macbook pro, so recovering the data isn&#x27;t exactly super simple. I have some frida scripts that I pushed to my git server as well as some markdown files + conversation logs I&#x27;ve had with exploit devs, but not much else. In order to get everyone the proof they require, I&#x27;ll likely need to reverse the app all over again which isn&#x27;t something I have time for right now.<p>Just sounds like &quot;my dog at my homework&quot;.
评论 #23686810 未加载
评论 #23688466 未加载
评论 #23688065 未加载
评论 #23685930 未加载
评论 #23687047 未加载
评论 #23687943 未加载
评论 #23689189 未加载
评论 #23688467 未加载
评论 #23685727 未加载
评论 #23687032 未加载
est将近 5 年前
Disclosure: am a dev working in the MCN business.<p>The &quot;private data&quot; the app collected, is used, for most part, fingerprint the unique user.<p>In every MCN app, there was a huge fake user problem. If an app collect zero identifiable fingerprint, then a spammer can easily fake millions of views and manipulate ranked content. The app developers are asked think clever to collect every piece of info they can, while spammers spent night and days spoof every parameter in a virtual machine or even on a matrix of remote controlled real phones.<p>For example, if a iPhone 11 user logs in, but only with screen resolution of 320x240, is it legit? I have caught tens of thousands of fake users with simple checks like this. However the tricks expires pretty quickly, you have to move on with new feature checks, together with decision trees and bayesian networks.<p>Some of the fingerprint collecting SDKs are even using native code to check some ARM specific instructions to tell if the device is fake or not. The parameters check had to be done in every important API calls, or spammers can easily pretend be good citizen during parameter checking process and swap the session to a cheaper VM&#x2F;phone or spam the targeted API with scripts.<p>Chinese companies all have their own team dealing with frauds or spamming on daily basis, the same way as everything can be faked in China.<p>Think cyber attacks from Chinese IPs are bad? Now imagine doing business in China and all users of your product are bots, what methods do you have to filter out the real human users? Good luck.<p>Many ads network SDKs are collecting user data in the same way. Otherwise it&#x27;s easy to spoof fake clicks and page views.<p>I not stating if it&#x27;s the right or wrong thing to do, I am just saying it&#x27;s how things are done in current state of business.
评论 #23686393 未加载
评论 #23687072 未加载
评论 #23686509 未加载
评论 #23687245 未加载
评论 #23688040 未加载
评论 #23688387 未加载
评论 #23688251 未加载
namelosw将近 5 年前
There has been a lot of bash on TikTok recently. TikTok is by no means good, but I&#x27;m yet to see it proofed much worse than counterparts from Western companies.<p>A lot of videos and articles make me feels more like pure anti-China sentiments, just like many similar campaigns did to Huawei last year.<p>It&#x27;s fine call out the risk in terms of personal privacy, or national security.<p>It&#x27;s also fine to have and express anti-China sentiments, since everyone has his&#x2F;her own opinions.<p>But it annoys me there are a lot of people charging with only assumptions, or play double standards just to make every Chinese business or Chinese person looks evil. It&#x27;s just hypocritical.
评论 #23688092 未加载
评论 #23687192 未加载
评论 #23687442 未加载
评论 #23689115 未加载
wslh将近 5 年前
Show me the reversed code... and show your work in reversing FB, WP, IG. This is how security works you need to show actual reversing.
mrlala将近 5 年前
Here&#x27;s what I don&#x27;t get about this.. I&#x27;ve seen all these various claims, and to be frank I did uninstall tiktok just recently as I only enjoyed it for about a week or so then lost interest, and there&#x27;s all this stuff coming up about it....<p>All these claims I see sound like EVERY SINGLE APP could be doing the same thing. Are both iOS&#x2F;Android really <i>that</i> exposed that they can just get all of this info without explicitly asking for permission? If they are bypassing shit and recording your mic under the radar.. how the hell would apple&#x2F;google be letting a billion user+ app be doing this?<p>Something just doesn&#x27;t pass the smell test here.
评论 #23687880 未加载
RantyDave将近 5 年前
So, TikTok on my (Android) phone has a grand total of zero permissions. And even if it is able to download and run some code, isn&#x27;t it running in a sandbox? I don&#x27;t really understand the panic here...
评论 #23687738 未加载
评论 #23687570 未加载
评论 #23687729 未加载
bllguo将近 5 年前
surprised people are so willing to accept these claims without proof, especially here, where I imagine the number of people who could actually do the work this person claimed to is disproportionately high
评论 #23687347 未加载
jb775将近 5 年前
So is the primary concern about the lengths TikTok goes to scrape user data? Or more-so that it&#x27;s a Chinese company scraping user data?<p>I&#x27;d assume apps like fb&#x2F;twitter&#x2F;snapchat&#x2F;etc scrape just as much. And since the US gov basically forces them to install backdoors, isn&#x27;t that worse than this whole TikTok privacy conversation? Maybe I&#x27;m missing something though.
评论 #23687187 未加载
mdrabla将近 5 年前
Here&#x27;s a mirror of the video (from the OP of that thread):<p><a href="http:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=I_fyz5rOwFc" rel="nofollow">http:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=I_fyz5rOwFc</a>
leptoniscool将近 5 年前
Extraordinary claims require extraordinary proof.
评论 #23689096 未加载
znpy将近 5 年前
«Sorry, this post has been removed by the moderators of r&#x2F;videos.»<p>Also, the video is unavailable on youtube.
评论 #23685403 未加载
skee0083将近 5 年前
Annnd all the links have been removed...
评论 #23690098 未加载
tragiclos将近 5 年前
What makes this so much more objectionable than the myriad ad tracking networks on most web pages?
sAbakumoff将近 5 年前
&gt;&gt; I have a decent amount of my notes on my other laptop that recently had a motherboard failure and the majority of that data is on the laptop&#x27;s SSD. It&#x27;s a macbook pro, so recovering the data isn&#x27;t exactly super simple.<p>Isn&#x27;t it an excellent sample of &quot;the cat ate my code&quot; excuse?
dancemethis将近 5 年前
Imagine when it&#x27;s done with Discord.
nix23将近 5 年前
&gt;thinly-veiled as a social network<p>I think i read that exact sentence here on HN, oh and my Dog eat all the proofs. No need to do it again ;)
crzydreamwalkr将近 5 年前
The link has been removed from both reddit and Youtube, is there any other link available to read the actual post.
FooBarWidget将近 5 年前
From a legal perspective, it seems that Tiktok is mostly (but not completely) covered. They mention these activities in their privacy statement. The statement is not clear enough on what each individual activity is used for: they put a lot of activities under an umbrella reason such as &quot;providing tech support&quot; and &quot;collection for analytics partners&quot;.<p>It doesn&#x27;t make their activities right, of course. But it&#x27;s debatable whether <i>legally</i> speaking, they are in violation of privacy laws.<p>I think they have a higher chance of violating EU privacy laws than US ones. GDPR is quite strict: you need to have a good reason for doing something, not merely mentioning that you&#x27;ll do something.<p>I think it&#x27;s also interesting to know that Tiktok&#x27;s servers are in Singapore.
greatjack613将近 5 年前
Not surprised at all, Tik Tok has clear ties to china and with all things china comes the governments control. chances are china was using Tik Tok as a global surveillance tool.
评论 #23685634 未加载
dathinab将近 5 年前
Uhm, video disappeared or silently geo-blocked.
bobbydreamer将近 5 年前
It&#x27;s there a tiktok proxy app.
chrischen将近 5 年前
This guy&#x27;s comment (prosound2000) pretty much tells it like it is:<p>&gt; The problem here is Facebook, Instagram and Twitter are US based companies that are beholden to the government. While sure you have lobbying going on, they are ultimately separate from the government, and if are found in violation of certain laws will be prosecuted or at least brought in front of congress and can face stiff penalties in the US. TikTok IS the Chinese government. They are beholden to no one. They can&#x27;t break the law since they are the law.<p>Well, he almost has it figured out. We are all actually beholden to our governments. Even Apple allegedly held off on iCloud encryption because of FBI pressure, not to mention constant right-wing efforts to destroy encryption and force companies to insert backdoors. China has a stronger central authority (therefore easier to force companies to do things), but the US is itching to go that route as well. Fighting it means preserving an actual ideological backbone, rather than simply consolidate all power to destroy our enemies.<p>If we lose our sights on encryption, separation of our corporate entities from our government, then we are just China but in a different location.