Has tiktok_us been breached?
twitter.com
twitter.com
Pretty obvious if you look at the tables closely. And the "cabinet" means hosting cabinets (steel frames holding the machines).
Which means those dudes were basically downloading the ad logs..
> And the "cabinet" means hosting cabinets (steel frames holding the machines).
This sounds totally implausible, given:
> there's another DB in the Oracle server we're in, it's called "cabinet cloud" and it's 34GB in total
Why would you name a database after the kind of furniture housing your computers?
scraped
Cabinet = jigui in Chinese. It looks like something for operation tracking. Just look at the table names.
So unless we’re all gonna start storing copies of HN’s database(s) on our home computers and phones, a blockchain won’t help stop abuse. Speaking of which, how big would said copies be?
How do you know this?
The screenshots suggest that someone scraped public data from TikTok and then got hacked. Highly doubt any of this came directly from TikTok.
that seems very material, for the US population and Bytedance's verbal commitment to the govt. At this point, it's obvious that data of US citizens (a large chunk underage) has been heavily shared with what is perceived as a rival state
If you want data on this assertion research "capitalism with socialist characteristics." If you want the data straight from China read their 14th 5-year plan (I wish the US had these kinds of plans) translated by Georgetown University here [1]. China is very open about what they are doing in published writing.
If you want more information read "The World According to China" by Liz Economy. I can suggest about 10 other books too, but that book was published in 2022 and is the most relevant book I read. Unfortunately China's government from a Western lens is such a complex topic I can't simply link to one article about how China runs its economy and "private" organizations to prove my point. This complexity unfortunately leads to people making false assumptions about how China operates without the requisite knowledge - and then deciding how we should make policy decisions towards China.
[1] https://cset.georgetown.edu/publication/china-14th-five-year...
tiktok_users
...
It would be just called usersFor products built by outsourced teams (or if initial prototype was built by a outsourced team but then taken over by in-house), it's more common, even when building products for others.
If all traces of the renames and mergers have been scrubbed over time, then I would also expect the namespacing to have been removed (unless they expect more merger?)
Earlier this year they claimed to have discovered an NGINX 0-day RCE and tested it against a Canadian bank. Not only was it a big nothing-burger, but they ended up purging their Telegram channel aftwards with claims of infighting (screenshots for posterity: https://imgur.com/a/5AThvTv).
I think it's extremely suspicious, but often times breaches like this aren't through the core platform itself. For example, Equifax was a support site that was hosted and built separately from their main platform.
This whole thing does smell like BS to me, though as well.
You don't need to wait for Troy Hunt to tell you otherwise, even he is not always correct.
[0] https://twitter.com/MayhemDayOne/status/1566748988770066435
>UPDATE: while there is definitely a breach, it is still work in progress to confirm the origin of data, could be a third party.
Https://breached.to/Thread-TikTok-WeChat-breach
Until we get a decent sample, I remain skeptical.
Based on what I see on there, it looks like a third party, not tiktok official
EDIT: In Troy Hunt I trust, and he is currently digging through it in this thread if anyone wants to follow along https://twitter.com/troyhunt/status/1566565409939427328. So far, the data seems legit, but publicly available/scrap-able.
That's true, but there is more than just a screenshot. I looked at the sample is it looks legit.
So this right here is denial.
Edit: Looks like Troy Hunt is digging through the sample right now and coming to similar conclusions https://twitter.com/troyhunt/status/1566565409939427328
This also explains why WeChat data is in the same database. And if you are paying attention, the WeChat tables are more complex which makes sense because WeChat has a much longer history in business.
The sample has very little data for such a comparatively large claim of 2 billion.
2 billion ad views are not that big. You are likely looking at logs not the core tables.
How many DBAs do you see starting up DBeaver or SSMS in order to do database backups or restores or any large-amount-of-data action?
I submitted a different link: https://twitter.com/AggressiveCurl under the title "TikTok Hacked".
I was referring strictly to the source code, not the databases.
They literally said "It's fetching rows still". Why did TikTok not stop this once they knew someone had unauthorized access to their systems or storage.
Most of it cannot be too hard. The interesting part of tiktok to me is how they scale video storage and then how it gets back to the user so fast. That part is amazing.
The rest of it seems less interesting to me.
Isn't that problem solved by the network (CDNs etc)?
A 8TB NVMe can fit 8 million videos.
I remember reading about a guy experimenting with liking only long and high quality videos, skipping short and cheap ones. After a dozen of visualizations TikTok got the cues and started showing exactly what the guy had planned.
After five years in LinkedIn saying the plain truth, they still don't get me at all, and they just keep my feed filled with the most "interacted" content.
It fills my feed with inflammatory US based political tweets, and I'm not interested.
If a tech journalists decides to reply on a thread about the latest GoP nonsense, then as an Australian that is interested in tech news, I don't want to hear it!
It's one thing I like about Twitter. All I see are the people I followed and the people they retweet. If one of them gets annoying, unfollow or mute. And it's all in chronological order. Unless I'm missing something, nothing is getting filtered or pushed by some annoying algorithm.
For your situation, you might want to create a list of words for Twitter to block for you. That might help you avoid certain topics.
TikTok is here to stay
Instagram is dreadful right now.
Every third post in as an Ad.
The content being posted is all spammy ads.
No one that I know IRL posts anything at all anymore.
It's all dark social messaging and private shared iOS Photos albums!
Billion dollar fines and lawsuit of user data incoming.
> We at Penetrum believe that everyone should have the right to know what data is being harvested by companies and would like to give our readers a clearer understanding of what happens when you download the mobile application TikTok. From our understanding and our analysis it seems that TikTok does an excessive amount of tracking on it’s users, and that the data collected is partially if not fully stored on Chinese servers with the ISP Alibaba.
For it to happen again. Hardly shocking and very expected. But as always the TikTok fans rushing here, panicking will do anything to deny the breach and after examining the contents, sample(s) of the breach, it looks highly legit.
[0] https://penetrum.com/tiktok/Penetrum_TikTok_Security_Analysi...
I hope you read the guidelines: "Please don't comment on whether someone read an article." [0]
> one of the tens of thousands of Alibaba cloud customers had a database exposed to the internet.
Was exposed ON Alibaba Cloud and that database WAS breached. It really doesn't matter and there is little difference in that event or whatever the security researcher and I meant.
I'm assuming you must have read this before commenting: [1]
"We provide ongoing security guidelines and training to all our customers, and always advise them to protect their data by setting a secure password among other security recommendations,” an Alibaba spokesperson stated."*
Either way, if that is not a breach then I don't know what is.
[0] https://news.ycombinator.com/newsguidelines.html
[1] https://www.breakingasia.com/news/china-alibaba-shut-down-se...
They could give you recommendations, but they cannot stop you from killing yourself.
> It really doesn't matter and there is little difference in that event or whatever the security researcher and I meant.
It does matter. If you setup an unprotected server on AWS and someone hacked it. It is your fault, not AWS.
[0] https://en.wikipedia.org/wiki/Infrastructure_as_a_service
> It does matter. If you setup an unprotected server on AWS and someone hacked it. It is your fault, not AWS.
Indeed it does matter. Whoever owns the server got breached and that is that. But I didn't say the breach didn't matter. I said the difference in where it got breached doesn't matter.
In reality this has nothing to do with either Alibaba Cloud nor Tiktok.
Performance wise it's one of the toughest battle tested system you can imagine.
[1] - https://www.youtube.com/watch?v=b2F-DItXtZs [video][language]
https://insidebigdata.com/2013/09/18/googles-f1-database-mea...
1. Sharding.
2. Different DBs for different microservices. Purpose-specific. Ship analytics data out for BI.
3. Redis layer for high QPS services with repetitive queries (eg. session stores)
Unless you host about 80million Wordpress blogs, or 8 million WHMCS installs