13 ms·
Has tiktok_us been breached?
- nathanaldensr 4y agoIs there any third-party verification of this? Anyone can mock up screenshots to look like a TikTok database.
- xcdzvyn 4y agoThe author suggests it has been verified by a certain underground hacking forum. Look at his recent tweets.
- aaron695 4y ago
- ItIsWhatItIs2 4y agoI am a bit wary of the claim/the validity of the hack. It seems rather short on details of what, and I haven't seen independent verification from someone reputable. The hack seems plausible though so who knows ¯\_(ツ)_/¯ EDIT: In Troy Hunt I trust, and he is currently digging through it in this thread if anyone wants to follow along https://twitter.com/troyhunt/status/1566565409939427328 https://twitter.com/troyhunt/status/1566565409939427328. So far, the data seems legit, but publicly available/scrap-able.
- nathanaldensr 4y agoFWIW, I asked my question in good faith. For a hack such as this, which appears to include massive databases of one of the most highly-visible companies in the world, I'd expect a bit more meat.
- ItIsWhatItIs2 4y agoI agree, it seems like if this hack is true, it'd be possibly one of the largest breaches of user data ever only behind the Yahoo breach. I'd hope they'd include more info to corroborate their claim. So, I agree with being a bit cautious to begin with
- rvz 4y ago> Anyone can mock up screenshots to look like a TikTok database. That's true, but there is more than just a screenshot. I looked at the sample is it looks legit. So this right here is denial.
- radiojasper 4y agoWhy am I not surprised?
- rvz 4y agoYeah, it is unsurprising since even another security researcher knew that all of TikTok's user data is being harvested on Alibaba Cloud which that already got breached resulting in a 900GB file being dumped somewhere as they collect the IMEI numbers of many users as found in the Android app. From [0] > We at Penetrum believe that everyone should have the right to know what data is being harvested by companies and would like to give our readers a clearer understanding of what happens when you download the mobile application TikTok. From our understanding and our analysis it seems that TikTok does an excessive amount of tracking on it’s users, and that the data collected is partially if not fully stored on Chinese servers with the ISP Alibaba. For it to happen again. Hardly shocking and very expected. But as always the TikTok fans rushing here, panicking will do anything to deny the breach and after examining the contents, sample(s) of the breach, it looks highly legit. [0] https://penetrum.com/tiktok/Penetrum_TikTok_Security_Analysis_whitepaper.pdf https://penetrum.com/tiktok/Penetrum_TikTok_Security_Analysi...
- prvit 4y agoDid you actually read what you linked? Alibaba cloud wasn't breached, one of the tens of thousands of Alibaba cloud customers had a database exposed to the internet. Same happens with AWS and Azure all the time.
- rvz 4y ago> Did you actually read what you linked? I hope you read the guidelines: "Please don't comment on whether someone read an article." [0] > one of the tens of thousands of Alibaba cloud customers had a database exposed to the internet. Was exposed ON Alibaba Cloud and that database WAS breached. It really doesn't matter and there is little difference in that event or whatever the security researcher and I meant. I'm assuming you must have read this before commenting: [1] "We provide ongoing security guidelines and training to all our customers, and always advise them to protect their data by setting a secure password among other security recommendations,” an Alibaba spokesperson stated."* Either way, if that is not a breach then I don't know what is. [0] https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html [1] https://www.breakingasia.com/news/china-alibaba-shut-down-server-after-data-leak/ https://www.breakingasia.com/news/china-alibaba-shut-down-se...
- rzz3 4y agoShocked to see them using MySQL here. I can’t imagine it working very well at their scale.
- bognition 4y agoWhy not? MySQL can be extremely performant at scale. I’ve seen tiny MySQL databases serve in ver 50k req/sec.
- makeitdouble 4y agoMySQL gets a bad rap because of it's casual wrangling of data types and query formats. Performance wise it's one of the toughest battle tested system you can imagine.
- kcb 4y agoBut is it Web Scale?
- LinuxBender 4y agoAdding the reference [1] in case it is obscure for some. [1] - https://www.youtube.com/watch?v=b2F-DItXtZs https://www.youtube.com/watch?v=b2F-DItXtZs [video][language]
- blinding-streak 4y agoIt works if you rig it to work well at that scale. Google used a modified version of MySQL to host AdWords for a long time. A very large database with massive qps: https://insidebigdata.com/2013/09/18/googles-f1-database-means-big-data/ https://insidebigdata.com/2013/09/18/googles-f1-database-mea...
- deleted 4y ago[deleted]
- polio 4y agoFacebook uses it for user data
- marcooliv 4y agoIs this the start of the end of TikTok?
- keepquestioning 4y agoYes. No doubt the much vaunted algorithm will make their way to competitors, through digital fencers.
- altdataseller 4y agoThe algorithm is almost useless without the vast number of creators they have who are interested in creating mostly for tiktok
- krapp 4y agoThe algorithmic black market. The only place to get the really primo data structures.
- bognition 4y agoLol no. The company makes billions of dollars and is funded by the Chinese government. TikTok is here to stay
- Laaas 4y agoIt's only the source code. Who cares?
- altdataseller 4y agoYeah if this was user data, different story. They should just open source the entire backend code.
- pcbro141 4y agoThis looks like user data: https://twitter.com/AggressiveCurl/status/1566173696842256384 https://twitter.com/AggressiveCurl/status/156617369684225638...
- Kukumber 4y agoRight after the US "inspection", fishy story
- tonetheman 4y agoI am not sure I care much about tiktok's source code really. Most of it cannot be too hard. The interesting part of tiktok to me is how they scale video storage and then how it gets back to the user so fast. That part is amazing. The rest of it seems less interesting to me.
- weird-eye-issue 4y agoFor starters their algorithm seems to work pretty well
- amelius 4y ago> The interesting part of tiktok to me is how they scale video storage and then how it gets back to the user so fast. Isn't that problem solved by the network (CDNs etc)?
- Cyph0n 4y agoCDNs are designed to easily handle relatively static content (e.g., Netflix-like streaming services). Scaling user-generated video serving is a much more challenging problem.
- amelius 4y agoI bet most tiktok videos can be categorized into a few classes and all users just watch the videos in one of those classes. So basically, it is very much like Netflix. Also, the videos are much shorter.
- withinboredom 4y agoYou need to process the video before that, as not every phone/browser has the right codecs to stream from every other phone. Then you need to ship that to POPs and serve it. That’s some industrial strength bandwidth and computer power, not to mention the feature tagging the AI is doing to show the videos to the right audience.
- 4y ago
- EMIRELADERO 4y agoSo is this guy going to download and "leak" the source or not? Considering the current US-China relations, it wouldn't be a stretch to suggest they might not face consequences
- boomboomsubban 4y agoReleasing private information about millions of Americans or Chinese is likely going to get you into trouble no matter where in the world you are. Maybe they'd avoid hacking charges, if caught they'd face civil charges at least.
- EMIRELADERO 4y ago> Releasing private information about millions of Americans or Chinese is likely going to get you into trouble no matter where in the world you are. I was referring strictly to the source code, not the databases.
- boomboomsubban 4y agoFair, for no good reason I mistook "source" to mean everything. My mistake.
- tway223 4y agoIt is not a TikTok leak. It is more like from a system which is integrated with TikTok/WeChat for marketing / e-commerce usage. Pretty obvious if you look at the tables closely. And the "cabinet" means hosting cabinets (steel frames holding the machines). Which means those dudes were basically downloading the ad logs..
- jw1224 4y agoThe tables looked fictional in the first screenshot, but after seeing the rest in the replies I’m not so sure. There are enough relevant tables for an app of this scale to make this seem pretty legit.
- tway223 4y agoThey are legit. But just not from TikTok. Think of a system where you can manage your ad spending and user growth with TikTok/WeChat (like product promotions, referring from a friend etc.)
- duskwuff 4y agoIt occurs to me that this could be the database for one of those shady "buy TikTok likes" services. That'd neatly explain a lot of the features we see in the dump.
- deleted 4y ago[deleted]
- smrtinsert 4y agoQuartz scheduler tables suggested to me a real system at least
- jstanley 4y agoHow do you explain that it has 2 billion user records? > And the "cabinet" means hosting cabinets (steel frames holding the machines). This sounds totally implausible, given: > there's another DB in the Oracle server we're in, it's called "cabinet cloud" and it's 34GB in total Why would you name a database after the kind of furniture housing your computers?
- croes 4y ago"We've downloaded the user information tables from the database. Looks like it's the system log now, which is 790GB. Also, current user entries is 2.05 billion." Https://breached.to/Thread-TikTok-WeChat-breach
- nabakin 4y ago> WeChat (Which is state owned) is within the same database as the TikTok DB (which claims not to give such information to their government). Until we get a decent sample, I remain skeptical.
- croes 4y ago
- ffhhj 4y agoHoneypot?
- deleted 4y ago[deleted]
- sonicgear1 4y agoWe need the source code
- deleted 4y ago[deleted]
- jw1224 4y ago> Edit 3: It's been 11 hours since the contact, about 1.37 billion entries have been pulled. DBeaver has crashed multiple times and we've left it running. It's "fetching rows" still. So I guess there's still more. Considering the entries are from all over the world, it is unlikely we will sell or release this. Lastly, this data contains a lot of under aged people. Releasing such information, along with the data that is being stored without user's knowledge is so dire that we think it could spark something dangerous. Example: WeChat (Which is state owned) is within the same database as the TikTok DB (which claims not to give such information to their government). Via https://breached.to/Thread-TikTok-WeChat-breach https://breached.to/Thread-TikTok-WeChat-breach
- nabakin 4y agoThey have this data and aren't going to sell/release it? Their provided sample doesn't seem to have any critical user data like passwords and phone numbers. All the user data is publicly available. Not to mention there are very few sample rows for 2 billion records. Not sure how to confirm the PayPal data. So far, I'm skeptical. Edit: Looks like Troy Hunt is digging through the sample right now and coming to similar conclusions https://twitter.com/troyhunt/status/1566565409939427328 https://twitter.com/troyhunt/status/1566565409939427328
- jw1224 4y agoI saw someone confirm passwords were hashed with bcrypt, but I can’t find it now. Nonetheless this is very interesting to see unfold.
- nabakin 4y agoI don't see passwords anywhere in the sample and Troy hasn't found any either so I doubt unless they can be pointed out
- tway223 4y agoThe data could be very likely legit. But they are not TikTok's user database. It is more like TikTok's ad/activity log for some customers. The passwords are for the logins from those customers if any. This also explains why WeChat data is in the same database. And if you are paying attention, the WeChat tables are more complex which makes sense because WeChat has a much longer history in business.
- deleted 4y ago[deleted]
- IceWreck 4y agoWait, so they were downloading stuff from TikTok's servers/storage and giving info out live. They literally said "It's fetching rows still". Why did TikTok not stop this once they knew someone had unauthorized access to their systems or storage.
- ripper1138 4y agobecause it’s not from TikTok servers.
- ff7c11 4y agoI don't believe the kids behind this Twitter account. I don't know why they're doing it exactly, probably some form of clout or to scam buyers on darknet marketplaces, but I know that many of their screenshots are faked. I know people at one of the companies they claimed to have hacked - they posted a Ruby on Rails directory structure as proof of hacking them but the company does not have Ruby code. So I would not trust any of their tweets.
- richbell 4y agoI don't trust them (AgainstTheWest, not Troy Hunt) either — and frankly I'm surprised to see that they're still active. Earlier this year they claimed to have discovered an NGINX 0-day RCE and tested it against a Canadian bank. Not only was it a big nothing-burger, but they ended up purging their Telegram channel aftwards with claims of infighting (screenshots for posterity: https://imgur.com/a/5AThvTv https://imgur.com/a/5AThvTv).
- ajsfoux234 4y agoThe original submission link was https://twitter.com/AggressiveCurl/status/1566161198248509440 https://twitter.com/AggressiveCurl/status/156616119824850944... , it was changed since this comment was posted
- charles_kaw 4y ago> they posted a Ruby on Rails directory structure as proof of hacking them but the company does not have Ruby code I think it's extremely suspicious, but often times breaches like this aren't through the core platform itself. For example, Equifax was a support site that was hosted and built separately from their main platform. This whole thing does smell like BS to me, though as well.
- rvz 4y agoThe TikTok breach is completely real. [0] Despite the hilarious denial spirals in the comment section. You don't need to wait for Troy Hunt to tell you otherwise, even he is not always correct. [0] https://twitter.com/MayhemDayOne/status/1566748988770066435 https://twitter.com/MayhemDayOne/status/1566748988770066435
- jacooper 4y agoHere is a more informative thread by haveibeenpwned's creator, Troy hunt. https://twitter.com/troyhunt/status/1566565409939427328 https://twitter.com/troyhunt/status/1566565409939427328
- dang 4y agoOk, we'll change to that from https://twitter.com/AggressiveCurl/status/1566161198248509440 https://twitter.com/AggressiveCurl/status/156616119824850944.... Thanks!
- geuis 4y agoJust spitballing, but this changing of source url reminds me of an idea I had a while back. In cases like this, where the url is changed from source, the old url should still be linked. Maybe as a sub title, or perhaps there should be a separate "changed" link on posts like this. The changed link could show title or url source changes.
- pvg 4y agoThe old url is linked in the url-changed comment. Sometimes there's a pinned topcomment with the old url or the url of a merged thread, if the url change is likely to really confuse.
- mgdlbp 4y agoI'm curious if anyone's been keeping track of title and url changes. HN's small enough that one could easily hold the data. Someone has a page showing recent title changes,[1] but without retention. In that thread is a link to a browser extension that does the same, but I can't tell if its scraping is client-side (probably) or if there's a server. 1 https://news.ycombinator.com/item?id=21617016 https://news.ycombinator.com/item?id=21617016
- hackernewds 4y agoThese kinds of edits, without edit history, seem ripe for abuse
- keyle 4y agoI find it strange that if I were designing tiktok's tables, I wouldn't call it tiktok_users ... It would be just called users
- ollien 4y agoIt's been a long while, but I believe Django names tables with that exact convention.
- jorl17 4y agoIndeed it does. At a previous job we used to get rid of the convention. I've since thrown in the towel and said "meh"
- rtpg 4y agomore specifically for people who don't use it, the general naming is "module_modelname" (so for example "payments_paypaltransaction"). Django's term for what one might call a module is "app", which is also a bit of a loaded term, but the simple way of seeing it is that Django projects have many sub directories each managing a set of models (which map to DB tables, generally).
- LecroJS 4y agoHad the exact same thought, but after reading another comment it could make sense assuming it’s a 3rd party service integrated with tiktok
- hackernewds 4y agoMore plausible that there's WeChat_users and tiktok_users, as they don't just run 1 enterprise
- capableweb 4y agoAs a consultant/free-lancer I've seen this in plenty of SaaS businesses, even if they only have one product. The DB url would be "product-name.db.domain.tld/product-name", the database would be named "product-name" and the table would be called "product_name_users". Not really sure how it came to be, but it's not super uncommon. For products built by outsourced teams (or if initial prototype was built by a outsourced team but then taken over by in-house), it's more common, even when building products for others.
- RobRivera 4y ago
- chocolatkey 4y agoHere's the gogs git instance referred to: https://code.qsyunying.com/explore/repos https://code.qsyunying.com/explore/repos Based on what I see on there, it looks like a third party, not tiktok official
- _a9 4y agoGood find, that's probably where they got the credentials for whatever dbs they're dumping. Not tiktok, just some 3rd party
- deleted 4y ago[deleted]
- unknownaccount 4y agoThis isn't what I submitted. I submitted a different link: https://twitter.com/AggressiveCurl https://twitter.com/AggressiveCurl under the title "TikTok Hacked".
- polygamous_bat 4y agoYes, it's been edited by dang, the moderator. See this comment thread: https://news.ycombinator.com/item?id=32719385 https://news.ycombinator.com/item?id=32719385
- unknownaccount 4y agoNot sure how I feel about the mods editing my posts and creating the illusion that I posted something I didn’t tbh.
- Cthulhu_ 4y agoIt's whether you consider it a personal submission or more like a news submission that HN ran with and changed as it developed.
- philliphaydon 4y agoIf it’s not a personal submission then remove names and karma.
- yakkomajuri 4y agoIt's still attached to the user though. At the _very least_ it should be flagged as edited. Still a bit iffy either way.
- HereIGoAgain 4y agoThis could get quite interesting if true.