
Tving is applying zero-trust security principles across its services and cloud environment, an approach that trusts no access by default and continuously verifies users, devices and privileges.
The streaming platform said on the 23rd that it is rebuilding its security framework around zero trust and devoting full resources to strengthening protection of customer information. Tving said it has set four core principles — strict access verification, least privilege, assume breach and continuous validation — and is reinforcing its security framework across the board.
For strict access verification, the company has applied authentication token checks across all segments of its app and website and has forced updates of older app versions. It is also reviewing technology that detects and blocks tampered apps.
Under the least privilege principle, Tving is strengthening access controls by breaking down access rights to systems and services by job function and systematically managing the scope and validity period of each privilege.
Based on the assume-breach principle, the company reviewed its incident response framework by scenario and made response procedures more specific. For continuous validation, it built a system that detects abnormal activity in the cloud environment in real time and sends alerts when irregular access occurs.
Tving is also pursuing follow-up measures to further upgrade its zero-trust security framework. It plans to assess the adoption of credential management tools and source code analysis and vulnerability management solutions, and to expand the scope of penetration testing and vulnerability assessments to cloud accounts and privilege areas. The company will also upgrade its scenario-based incident response framework and is reviewing the introduction of a bug bounty program.
Work on a next-generation security framework is accelerating as well. Tving said it will strengthen integrated cloud security inspection and apply AI-based technology to detect and block security threats, continuously raising its capacity to respond to threats in real time.
The company has also carried out reinforcement work in core security areas. It moved secrets embedded in code to a dedicated management system and built a framework that automatically blocks secrets at the source code storage stage and detects irregular access. Next-generation endpoint detection and response (EDR) solutions have been installed on all employee PCs.
To protect customer information, Tving replaced its app signing keys and digital rights management keys. It is upgrading its login and session verification structure and switching its password storage algorithm to one based on bcrypt.
A joint public-private investigation team under the Ministry of Science and ICT earlier announced that its probe into the Tving breach found that information affecting 39.54 million accounts had been leaked, a figure that counts active, dormant and closed accounts separately and may include duplicate users.
A Tving official said the company places the protection of customer information as its top priority and is continuously reviewing its security framework to ensure that measures are actually implemented. The official said Tving will upgrade access and privilege management and its breach response framework based on zero-trust principles, and will continue investing in next-generation security technology such as AI-based threat detection to build a safer service environment.







