TikTok is making users give their iPhone passwords for unclear reasons
nypost.com
nypost.com
All that aside...is this an nypost article referencing a Dextero article referencing an (unsourced) reddit comment?
But obviously "tiktok = china = bad" doesn't apply, so no ragebait article.
Edit: could this be a prompt from a failed faceID authentication for the app's secure enclave storage? most of those prompts aren't cancelable, but this tiktok one is
https://www.reddit.com/r/Tiktokhelp/comments/186ipwb/tiktok_...
What native prompt does that?
Edit: Another concerning detail is that a native lock screen prompt should show a blurred copy of your phone's background image. This prompt is a single solid color.
Edit 2: perhaps a native passkey prompt with session token fallback? if tiktok is trying to upgrade everyone to passkeys, this could be them setting users up early for a smooth migration, but i'm just speculating
Edit 3: i downloaded TikTok to test, and am immediately presented with a native Passkey prompt upon opening the app (it infact shows a QR code because I don't have a passkey on my phone). It's likely to be a passkey prompt then. But I am really wondering why it's cancelable without any issues.
What is TikTok doing which triggers the OS to prompt the user for a password?
There is some chance that it's something harmless (idk. wield speculative maybe possibility: something like they use some form of passkey API from apple to do client authentication and that API had some changes where it now ask for the password in some situation).
There are many more (but unlikely) possibilities where TikTok is doing something bad or outright nefarious. But lets be honest if TikTok is intentionally doing something bad they are quite subtle about it, as not doing so would likely cause more harm for them then it does good.
But we know TikTok has in the past multiple times done things which would have gotten a "normal" app developer perm-banned due to a breach of the App stores Terms of Service in a intentional consumer harming way, so it is concerning even if they most most likely don't steal your passwords.
It’s much more likely that iOS is asking for the password.
Edit: It's almost certainly that. Users that don't have biometrics set up (or presumably also that have biometry attempts exhausted) get this behavior:
> Use Face ID or Touch ID to complete sign in. If you didn’t set up Face ID or Touch ID on your iPhone, enter your device passcode (the code you use to unlock your iPhone).
(from https://support.apple.com/guide/iphone/use-passkeys-to-sign-...)
If I had a TikTok passkey on my phone at the time, it's likely that the prompt would be an ordinary FaceID auth challenge with a PIN fallback. Perhaps OP has faceID disabled?
My uneducated guess is a keychain prompt, since I'm signed in with my apple ID via OAuth2 (with the email hidden, etc).
And since every app is essentially a full screen modal, this sort of PIN phishing would probably be difficult for a human to detect. I bet you could recreate the iOS passcode prompt in SwiftUI relatively simply.
For iOS passcode verification, you’d need both secure input (which the UI almost certainly achieves), but also trusted output of at least one bit of information: Whether the user is currently interacting with the OS (or a trusted application) or an (untrusted) application.
If you're a standard user, you'll be asked for the administrator's username/password on the secure desktop. Also, the secure desktop encompasses other parts of the system as well, like the lockscreen or the password change option on the ctrl-alt-del screen.
>For iOS passcode verification, you’d need both secure input (which the UI almost certainly achieves), but also trusted output of at least one bit of information: Whether the user is currently interacting with the OS (or a trusted application) or an (untrusted) application.
At least on windows that's provided by the secure attention key sequence. It's not enabled by default, but there's a group policy for it: https://learn.microsoft.com/en-us/windows/security/threat-pr...
Unfortunately, it's no longer the default on Windows as you mention (presumably because OS-privileged malware is now the norm, so the net benefit is probably small?), and iOS only very rarely and inconsistently uses their secure attention sequence (i.e. the double home/lock button tap used for Apple Pay).
https://www.reddit.com/r/Tiktokhelp/comments/186ipwb/tiktok_...
It would be a very bad idea to do that without clear user messaging, but not necessarily nefarious.
[1] https://developer.apple.com/documentation/security/secaccess...
Is there a missing word here? What is it?
Like..
"Experts say the reasons why TikTok (_topic of the article_) remains unclear."
Or perhaps it's referring to the previous sentence or paragraph. I do think the hyphenated subsection sets the tone too.
Made up example:
"The President today issued a statement. Experts says the reason why The President - who has issues statements in the past - remains unclear.
We've seen here in comments were people say that they access FB over their phone's browser JUST SO they don't install that data siphon to their phone.