Sensible Thoughts on TikTok Security
TikTok is a total privacy mess, but certainly not a national security emergency. Calling it such is bad policy - and here's why.

Sensible Thoughts on TikTok Security

If you are a typical teen, then you waste about an hour or so each day on TikTok. As a parent, I can confirm that this time is, in fact, truly wasted, because all of the content on TikTok is utterly ridiculous. And look – I watched Gilligan’s Island and The Brady Bunch as a youngster, so I have no right to complain. But it is nevertheless perfectly accurate to point out that TikTok content is basically created by, and for, a bunch of juveniles.

And so, it’s interesting to see the uproar recently, particularly from the resident of the Oval Office, that if we don’t do something quickly about TikTok, our national security will be at serious risk. While channel surfing recently, I paused on the Fox News channel (yea, I know) and watched a few minutes of a segment designed to terrify me that the Chinese are using TikTok to collect valuable and critical secrets about our society.

Now – before we address this point, let’s examine the snoopware causing the fuss. First, recognize that TikTok does canvas fingerprinting, where your device draws some graphic, and a unique hash is stuffed into a cookie based on how the image is created. This includes the sub-pixel rendering by your operating system, as well as the compression level and image export options in your browser. The result is a fingerprint – and yes, it’s a bit creepy.

Similarly, TikTok is the poster child for every bad privacy decision a designer could conjure: It logs and shares usage time, watched videos, and search terms to Appsflyer and (possibly) Facebook. It resolves short URLs to simplify review of who’s sharing what videos. It also does audio fingerprinting where sounds are made internally and the bitstream becomes the unique designator. And the app uses Google Analytics without anonymizing IP data.

All this ignores the non-privacy related issue (perhaps bordering on evilness) of the parent company censoring any posted TikTok videos that might be considered subversive or culturally problematic to the Chinese government. This is bad stuff, none of which will ever be welcomed by American users. So, if a teenager or parent chooses to stay away from the app on these moral grounds, then that seems a perfectly mature decision.

That said – I think it would be wise to take a moment to address the severity of actual risk here. We’ve already established that kids post a bunch of silly crap to TikTok, so their search term history and video usage logs would do nothing more than make it clear that all of my daughters and nieces enjoy watching Charli dance (look it up). Since businesses don’t use TikTok, I just don’t see much more risk here than one finds with Instagram or Snapchat.

If you read this TAG Cyber column, then you know that we do not approve of Spyware in software, and we are 100% opposed to hidden Trojans in applications that normal users would not have accepted. This is bad practice, and should be addressed by customers simply by not downloading or using that software. But turning the TikTok situation into some invented national security situation dilutes our ability to spot real emergencies.

And on the matter of Trump’s obsession with this app, two things come to mind: First, it is obvious that by picking on the Chinese for any reason, he wins political points with his base, which is an increasingly shrinking minority of Americans. But second, I can’t help but wonder if Kelly Anne Conway’s daughter trolling the President (and her mom) on TikTok didn’t absolutely infuriate him. (Don’t laugh – anything is possible these days.)

Here's my advice to you: Since there is nothing any of us can do other than watch to see if Microsoft wastes $20B on a company that I predict will be worth zero in a few years, the best we can all do is just crank down the xenophobia. The United States and China will be intertwined for the next century, whether either of us like it or not. So, it would just seem like a good idea to me that we all start finding ways to cooperate when it comes to tech.

Stay safe and healthy.

Sorry, I don't see any difference between Tik Tok and Facebook but it is politics! If US has benefits (??) from Tik Tok it will support it and defend it. Let me give you an example Facebook SDK is almost in every Mobile App so people can be tracked anytime even if they are offline, they don't need to get your MAC ??

赞
回复
Marcelo Mansur

I build teams out of Pwn2Own, Pwnie Award and DEF CON CTF winners

4 å¹´

It’s as if it doesn’t occur to you that it might be backdoored.

Eric Hess

Digital Assets, Exempt Offerings, Capital Markets, Broker Dealer/Investment Adviser, FinTech, AML.

4 å¹´

Insightful. The broader point is about picking your fights wisely....or at least consistently. Comments are well thought out but it is hard to take the position that the decision was anything but entirely politically motivated. Maybe if it were a part of a broader national privacy policy versus an obvious political exercise it would have more credibility....and be more moderate in application.

Hi Ed, Teenagers don’t stay teens forever. What a great way to develop profiles on people for a surveillance state and carry that on thru their entire life especially in their active professional career.

要查看或添加评论,请登录

Edward Amoroso的更多文章

  • Protecting the U.S. Bitcoin Reserve and Stockpile from Cyber Threats

    Protecting the U.S. Bitcoin Reserve and Stockpile from Cyber Threats

    As you no doubt have heard, plans are in place to establish a Strategic Bitcoin Reserve and Digital Asset Stockpile…

    15 条评论
  • Parable of Network Observability

    Parable of Network Observability

    I’d like to discuss here a common problem we see in our work at TAG every day – namely, the deployment of “network…

    23 条评论
  • Parable of the Cyber Industrial Complex

    Parable of the Cyber Industrial Complex

    Preamble In 1961, Eisenhower gave a famous speech that warned of the dangers of the so-called military-industrial…

    34 条评论
  • The Challenges of CISOs Working for Cybersecurity Vendors

    The Challenges of CISOs Working for Cybersecurity Vendors

    (Note to Reader: Normally these reports are available only to TAG Research as a Service (RaaS) subscribers. But with…

    27 条评论
  • Have Uncle Joe Read This Before He Invests in Crypto

    Have Uncle Joe Read This Before He Invests in Crypto

    I’ve been lecturing to my graduate students on the foundations of cryptocurrency and blockchain for years. Starting…

    15 条评论
  • Why TAG is Now Rating Cybersecurity Vendors

    Why TAG is Now Rating Cybersecurity Vendors

    by Edward Amoroso The first time I ever paid attention to an analyst quadrant – fully two decades ago, I found myself…

    11 条评论
  • Predicting the Impact of Trump’s Election on Cyber

    Predicting the Impact of Trump’s Election on Cyber

    Below are seven predictions from our team at TAG for how the recent Trump election of 2024 will impact U.S.

    83 条评论
  • Five Tips for Working CISOs

    Five Tips for Working CISOs

    Our team at TAG has been coaching CISOs for years – and this includes private discussions just about every day of every…

    11 条评论
  • The SEC is Weakening the Cybersecurity Posture of the United States. Here is Why.

    The SEC is Weakening the Cybersecurity Posture of the United States. Here is Why.

    Preface During May and June of 2024, draft versions of this article were shared with Chief Information Security…

    123 条评论
  • Sad Loss Today

    Sad Loss Today

    Several years ago, before the Pandemic, I received a friendly call from a law firm I’d done some business with – and…

    9 条评论

社区洞察

其他会员也浏览了