{"id":27661,"date":"2019-12-23T16:22:28","date_gmt":"2019-12-23T21:22:28","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=27661"},"modified":"2020-01-07T16:41:27","modified_gmt":"2020-01-07T21:41:27","slug":"totok-and-tiktok","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2019\/12\/23\/totok-and-tiktok\/","title":{"rendered":"ToTok and TikTok"},"content":{"rendered":"<p><a href=\"https:\/\/www.nytimes.com\/2019\/12\/22\/us\/politics\/totok-app-uae.html\">Mark Mazzetti, Nicole Perlroth, and Ronen Bergman<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.nytimes.com\/2019\/12\/22\/us\/politics\/totok-app-uae.html\"><p>It <a href=\"https:\/\/apps.apple.com\/ae\/app\/totok-hd-video-calls-chats\/id1470928669\">is billed<\/a> as an easy and secure way to chat by video or text message with friends and family, even in a country that has restricted popular messaging services like WhatsApp and Skype.<\/p><p>But the service, ToTok, is actually a spying tool, according to American officials familiar with a classified intelligence assessment and a New York Times investigation into the app and its developers. It is used by the government of the United Arab Emirates to try to track every conversation, movement, relationship, appointment, sound and image of those who install it on their phones.<\/p><p>[&#8230;]<\/p>\n<p>Apple removed ToTok from its App Store on Friday and was still researching the app, a spokesman said.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/objective-see.com\/blog\/blog_0x52.html\">Patrick Wardle<\/a> (<a href=\"https:\/\/twitter.com\/objective_see\/status\/1208869949155856384\">tweet<\/a>):<\/p>\n<blockquote cite=\"https:\/\/objective-see.com\/blog\/blog_0x52.html\"><p>The main goal of this blog post is to provide the technical details, about how one may go about triaging an iOS application, using ToTok as a &ldquo;case-study&rdquo;<\/p>\n<p>[&#8230;]<\/p>\n<p>It&rsquo;s reviews (over 32,000!) are largely positive, and mostly laud the fact that this application is not blocked in the UEA (Skype, WhatsApp, etc. are blocked, while using VPNs to access blocked services is illegal).<\/p>\n<p>[&#8230;]<\/p>\n<p>Based on these embedded strings it&rsquo;s relatively clear that <code>ToTok<\/code> is largely composed of code from <a href=\"http:\/\/www.yeecall.com\/en\/index.html\">YeeCall<\/a>. According to <a href=\"https:\/\/www.crunchbase.com\/organization\/yeecall\">CrunchBase<\/a> YeeCall is &ldquo;a software company that has developed Yeecall messenger app for video &amp; voice calling.&rdquo; It is rather unsurprising that <code>ToTok<\/code>s is simply based on existing code\/an product (vs. written entirely from scratch).<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/rndHashValue\/status\/1209001196696014848\">Random Hash Value<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/rndHashValue\/status\/1209001196696014848\">\n<p>As a side note.... A good description why locked down platforms make security harder. Needing a jailbreak to reverse a suspect software just to bypass the device vendor is Corp policy gone wrong.<\/p>\n<\/blockquote>\n\n<p>ToTok is not to be confused with with TikTok.<\/p>\n\n<p><a href=\"https:\/\/rufposten.de\/blog\/2019\/12\/05\/privacy-analysis-of-tiktoks-app-and-website\/\">Matthias Eberl<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=21725139\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/rufposten.de\/blog\/2019\/12\/05\/privacy-analysis-of-tiktoks-app-and-website\/\"><p>I did a detailed privacy check of the app TikTok and its corresponding website. Multiple law infringements, trust, transparency and data protection breaches were found.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.reuters.com\/article\/us-usa-tiktok-navy\/u-s-navy-bans-tiktok-from-government-issued-mobile-devices-idUSKBN1YO2HU\">M.B. Pell, Echo Wang<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=21851680\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.reuters.com\/article\/us-usa-tiktok-navy\/u-s-navy-bans-tiktok-from-government-issued-mobile-devices-idUSKBN1YO2HU\">\n<p>Earlier this week the United States Navy banned the social media app TikTok from government-issued mobile devices, saying the popular short video app represented a &ldquo;cybersecurity threat.&rdquo;<\/p>\n<p>[&#8230;]<\/p>\n<p>TikTok is hugely popular with U.S. teenagers, but has come under scrutiny from U.S. regulators and lawmakers in recent months. The U.S. government has opened a national security review of the app&rsquo;s owner Beijing ByteDance Technology Co&rsquo;s $1 billion acquisition of U.S. social media app Musical.ly, Reuters first reported last month.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/08\/06\/hacker-friendly-iphones-and-mac-bug-bounty-program\/\">Hacker-Friendly iPhones and Mac Bug Bounty Program<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2017\/07\/31\/apple-pulls-vpn-apps-from-china-app-store\/\">Apple Pulls VPN Apps From China App Store<\/a><\/li>\n<\/ul>\n\n<p id=\"totok-and-tiktok-update-2020-01-06\">Update (2020-01-06): <a href=\"https:\/\/medium.com\/@billmarczak\/how-tahnoon-bin-zayed-hid-totok-in-plain-sight-group-42-breej-4e6c06c93ba6\">Bill Marczak<\/a>:<\/p>\n<blockquote cite=\"https:\/\/medium.com\/@billmarczak\/how-tahnoon-bin-zayed-hid-totok-in-plain-sight-group-42-breej-4e6c06c93ba6\">\n<p>This report examines the corporate structure of ToTok, a Voice over IP (VoIP) app associated with an Abu Dhabi-based company, Breej Holding Ltd. In December 2019, the New York Times reported that American officials said that the UAE Government spies on ToTok&rsquo;s users, and that Breej was connected to UAE companies involved in earlier spying attempts. Google and Apple removed the app from their app stores, and ToTok has begun to aggressively fight the charges, calling them &ldquo;defamat[ory],&rdquo; a &ldquo;shameless fabrication,&rdquo; &ldquo;vicious rumours,&rdquo; &ldquo;deranged,&rdquo; and &ldquo;absurd.&rdquo;<\/p>\n<\/blockquote>\n\n<p id=\"totok-and-tiktok-update-2020-01-07\">Update (2020-01-07): <a href=\"https:\/\/twitter.com\/josephfcox\/status\/1214261195668152323\">Joseph Cox<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/josephfcox\/status\/1214261195668152323\">\n<p>ToTok, a social media\/messaging app that is reportedly a secret surveillance tool for the UAE, is back on the Google Play Store. Originally Google said the app violated policies; now the app makes it explicit it gathers your contact information.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Mark Mazzetti, Nicole Perlroth, and Ronen Bergman: It is billed as an easy and secure way to chat by video or text message with friends and family, even in a country that has restricted popular messaging services like WhatsApp and Skype.But the service, ToTok, is actually a spying tool, according to American officials familiar with [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2019-12-23T21:22:31Z","apple_news_api_id":"3d8c9a8c-b675-4b80-b8b8-f605ef34f3e8","apple_news_api_modified_at":"2020-01-07T21:41:32Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAQ==","apple_news_api_share_url":"https:\/\/apple.news\/APYyajLZ1S4C4uPYF7zTz6A","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[91,130,827,31,1667,26,688,355,1904,1905],"class_list":["post-27661","post","type-post","status-publish","format-standard","hentry","category-technology","tag-appstore","tag-rejection","tag-chat","tag-ios","tag-ios-13","tag-iosapp","tag-jailbreak","tag-privacy","tag-tiktok","tag-totok"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/27661","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=27661"}],"version-history":[{"count":3,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/27661\/revisions"}],"predecessor-version":[{"id":27801,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/27661\/revisions\/27801"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=27661"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=27661"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=27661"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}