2 ms·
IIRC the traffic is encrypted, all TCP/IP packets but going to bytedance servers. Without interacting with the app I have no idea what it could be sending but s
by asynchronous 3y ago
IIRC the traffic is encrypted, all TCP/IP packets but going to bytedance servers. Without interacting with the app I have no idea what it could be sending but scary to speculate.
- groggo 3y agoplease speculate. I just don't understand what it would even have access to. Are you worried about it exploiting iOS bugs? Otherwise it should only have explicit access to what I grant, right? No audio, video, files, photos, contacts, location.
- asynchronous 3y agoRight, in theory iOS should sandbox it. But all the other functionality that’s exposed is probably getting sent over (think ip address, connection settings, iOS OS fingerprint). My guess is most of that data is just a keep-alive c2 style connection with ByteDance. Heaven forbid the CCP develops some iOS zero days and then has a list of every single iOS device that would be vulnerable to it.
- paulddraper 3y ago> Are you worried about it exploiting iOS bugs? Yes, or gathering information not blocked. For example, you don't need iOS permission to get general location information (IP address), or device fingerprint.
- RomanAlexander 3y agoEveryone here should know it's very easy to bypass any TLS on a device you control and sniff the traffic. if there was some malicious data being sent there's plenty of people to ring the alarm bells: the people reverse engineering the internal API to make bots, the black hats trying to steal user data, the scrapers stealing content,...