UK TikTok ban gives us all cause to consider social media security – ComputerWeekly.com
The UK ban on installing and using social media app TikTok on government devices brings our countrys policy in line with that of other jurisdictions including the US and member states of the European Union.
Announced yesterday in the House of Commons by Oliver Dowden, chancellor of the Duchy of Lancaster, the ban covers devices in ministerial and non-ministerial departments, and is a precautionary move that has not been taken in response to any specific incident or threat.
Its the latest step in a long-running feud between the West and China over data privacy issues, that besides TikTok has drawn in the likes of Hikvision, a manufacturer of IP surveillance cameras, and most famously, networking and comms giant Huawei, which found itself banned from the UKs core communications infrastructure in 2020.
All of these cases arise from concerns shared by Britain, the US and other Western states. Broadly speaking, these concerns centre on the possibility that the Chinese government may be able to extract sensitive data from these companies for espionage purposes.
China has a long history of industrial espionage, and its state-backed cyber operations are widely acknowledged as a particularly dangerous threat, so these concerns are not wholly unjustified, and its not a stretch to imagine how Beijing could exploit the personal data of UK government officials should it fall into their hands. In light of this, Chris Vaughan, vice-president of technical account management at Tanium, said its no surprise to see Westminster following in the footsteps of Brussels and Washington DC.
Chinese intelligence tactics are usually focused on longer-term objectives and are fuelled by the sustained collection of data, he said. The immense collection of user data, to now include commerce and purchasing information, combined with biometrics and activity tracking, feeds detailed intelligence into Chinese state departments.
This data can also be leveraged to deliver targeted, timely and often personalised psychological operations against individuals or groups of citizens. These tactics could potentially be used during election cycles and politically charged events in the coming years.
Vaughan regards the UKs TikTok ban as speaking to a wider issue around how much Chinese influence is deemed acceptable in national infrastructure and everyday life (similar issues dogged Huawei previously).
We have seen concerns increase in the West in recent months, with the use of Chinese surveillance technology being restricted, he said. There have also been numerous reports of Chinese efforts to sway politicians by way of lobbying and donations, and the public via social media and the spread of disinformation.
Historically, Russia has been the most prominent user of information operations as we saw from its activities related to the 2016 US election and the Brexit referendum. China has been more focused on stealing intellectual property which it can then use to its own advantage. However, there are indications that the CCP [Chinese Communist Party] will start to focus more on information and influence operations to achieve its strategic goals which adds to the concerns about the use of technology such as TikTok.
Any instances of these activities need to be met head-on by Western political leaders who should take a strong stance against it at the government level, rather than leaving the responsibility to individual organisations.
In her response to Dowdens statement yesterday, Labour deputy leader Angela Rayner was scathing in accusing the government of being behind the curve and making sudden U-turns, and for some in the cyber security community, there is something distinctly fishy about its decision.
Matthew Hodgson, co-founder and CEO of secure comms services provider Element, said that in one important way, the ban is downright hypocritical.
The UK government banning officials having TikTok on their phones while pushing through legislation that will give the UK government access to all UK communications screams of double standards, said Hodgson.
Outwardly it looks like theyre taking the security of data seriously by stopping China having a backdoor into UK data, albeit only for government officials currently. However, the UK government is pushing through the Online Safety Bill, which creates a very similar backdoor into every communications platform used by UK citizens.
So, its not OK for China to access government communications but it is OK to provide a route for them to access citizen communications via Online Safety Bill weaknesses? We need to protect the privacy of UK citizens today from bad actors and nation states of all shapes and sizes, he said.
Naturally, Westminsters thoughts are not shared by TikTok, which continues to stress that its never been asked to hand over data by the Chinese government, and insists it would never do so if asked.
In a statement following Dowdens announcement on 16 March, a TikTok spokesperson said: We are disappointed with this decision. We believe these bans have been based on fundamental misconceptions and driven by wider geopolitics, in which TikTok, and our millions of users in the UK,play no part.
We remain committed to working with the government to address any concerns, but should be judged on facts and treated equally to our competitors. We have begun implementing a comprehensive plan to further protect our European user data, which includes storing UK user data in our European datacentres and tightening data access controls, including third-party independent oversight of our approach.
The organisation believes it is inaccurate to describe it as Chinese-owned as its European presence is incorporated and regulated in the UK and Ireland, and its parent, Bytedance, is incorporated outside of China, so would not be subject to laws that require it to hand over data to Beijing if asked.
The firm recently announced Project Clover, a dedicated secure European enclave to harbour its UK and European Economic Area (EEA) user data. The fulfilment of this project will also see UK user data currently stored in datacentres in Singapore and the US moved within European jurisdiction.
It has also named a third-party cyber security company to audit its controls and protections, monitor data flows, and verify its compliance with relevant laws, which it believes goes beyond what any other tech platform is currently doing.
Venari Security chief technology officer Simon Mullis agrees that the TikTok ban is politically motivated, to some extent. The concerns are really rooted in the ability to assure the chain of trust of data protection from beginning to end, and at all steps in between, he said. With TikTok, this has proven to be extremely difficult for a variety of technical and political reasons.
In fairness, the ban is as much political as it is a consequence of the technical design of the application, said Mullis. Is the TikTok design and architecture so wildly different from other social media applications in widespread use as to cause massive security fears? The answer is probably not.
But Jamie Moles, senior technical manager at ExtraHop, said that given what we do know about how TikTok works, and most importantly, what we know about the data it requests and must have access to in order to run on a device, its mystifying why the UK government has dallied for so long.
Im a security expert who downloaded and used TikTok when it came out like so many others, including those working in the UK government, he said. But heres the difference: I removed it as soon as it became clear that the app could harvest anything from my phone including contacts GPS data, authentication info from other apps, and so on.
Having this app on your phone is tantamount to giving the Chinese government the keys to our economy.
Arctic Wolf chief information security officer (CISO) Adam Marr said: TikTok is collecting massive amounts of information from consumers like user location, voiceprints, calendar information and other sensitive data. The issue is we dont know what this data is being used for, or if a foreign government has access to it.
With the rise of data brokers who make a living out of selling user information, this platform can serve as a vessel for malicious actors to leverage. They can then sell this information, which can be used to target people via phishing emails, influence via propaganda, or even control or access devices. Let this be a reminder that nothing is truly free and that we should all exercise caution.
Faki Saadi, UK and Ireland sales director at SOTI, said: Any app that harvests the data you put into it should be treated with caution. Especially for people trusted with sensitive company information.
TikTok being banned from UK government devices should act as a wake-up call to other organisations do you have full visibility over the apps your employees have on their corporate devices? If not, perhaps now is the time to take stock. And it doesnt need to be a heavy lift there are solutions available that can do this for you, and wipe any unwanted apps in an instant.
Marr and Saadi both speak to a wider issue with social media in general. Other social media platforms such as Facebook and Instagram owner Meta have shown themselves repeatedly to be highly blas with regard to their user data and security policies. Twitter, under the control of the erratic Elon Musk, is heading in a similar direction.
And Robert Huber, chief security officer at Tenable, said that focusing only on TikTok means we risk missing the forest for the trees. There are hundreds of software applications used in government agencies every day that introduce risk, and unpatched known vulnerabilities are the most likely source of data breaches, he said.
The key is for security leaders to understand their organisations unique risk profile, discover where vulnerabilities exist and prioritise remediation efforts to root out those that could be the most harmful first.
Ismael Valenzuela, vice-president of threat research and intelligence at BlackBerry, said he is already seeing CISOs considering banning the use of TikTok on company devices. This is particularly relevant to those working for organisations that operate in highly regulated environments, such as the financial services sector, where companies are rightly expected to conduct their own product security testing and legal review of privacy policy positions to, at the very least, limiting use on corporate devices or by high-value users.
There is no doubt that organisations with regularly updated threat models based on contextual intelligence, mature asset management practices and integrated management endpoint solutions are better positioned to manage this risk enterprise-wide, said Valenzuela.
It underscores the importance of managing risk throughout the organisation and the need to assess, and thereby control, the impact of the introduction of new products and technologies upon overall organisational security. This includes the use of seemingly innocuous chat and social media apps.
I suspect that only a limited number of CISOs are aware of TikToks privacy policy statement, he continued. While attacks on the supply chain are a real concern today, privacy risk should also be a top priority for CISOs of high-risk organisations. This is because personal data on company executives and other important individuals can be of great value in the hands of financially motivated attackers or the state.
Ultimately, the question of whether or not security leaders should ban or restrict the use of TikTok on company-owned devices is one that only they can answer. But given the growing number of government bans being proposed or enacted, at the very least, a thorough risk assessment is in order, coupled with a wider audit of corporate social media activity.
Continue reading here:
UK TikTok ban gives us all cause to consider social media security - ComputerWeekly.com
- Heineken Turns Anti-Social - Media, That Is 04/29/2025 - MediaPost - May 2nd, 2025 [May 2nd, 2025]
- Heineken taps Joe Jonas to ditch social media and pour into real connections - Marketing-Interactive - May 2nd, 2025 [May 2nd, 2025]
- Europeans are leaving the social network Mask X en masse - Mezha.Media - May 2nd, 2025 [May 2nd, 2025]
- Elon Musks X social network lost 10% of its users from Europe in six months. Reasons - - May 2nd, 2025 [May 2nd, 2025]
- Heineken campaign imagines an influencer crisis in a world without social media followers - Campaign Brief - May 2nd, 2025 [May 2nd, 2025]
- Joe Jonas and Dude With Sign Team Up to Celebrate Life Off Social Media - That Eric Alper - May 2nd, 2025 [May 2nd, 2025]
- Joe Jonas and Heineken bring in a social media apocalypse in new ad - afaqs! - May 2nd, 2025 [May 2nd, 2025]
- Divisive forces spreading hate on social media must be identified, dealt with firmly: Mehbooba Mufti - asianewsnetwork.net - May 2nd, 2025 [May 2nd, 2025]
- Socontra: social network for AI agent-to-agent interaction set to automate online shopping - Eagle-Tribune - May 2nd, 2025 [May 2nd, 2025]
- Survey: More than four in 10 teens say social media harms their sleep - The Star - May 2nd, 2025 [May 2nd, 2025]
- Mark Zuckerberg Says Social Media Is Over - The New Yorker - April 25th, 2025 [April 25th, 2025]
- Prince Harry and Meghan Markle are 'grateful' that Prince Archie and Princess Lilibet are too young for social media - Business Insider - April 25th, 2025 [April 25th, 2025]
- Morgan Stanley believed Google would rival Facebook if the search giant could beat Mark Zuckerberg to scooping up WhatsApp - Fortune - April 25th, 2025 [April 25th, 2025]
- Australian leaders vow to stand firm on social media age limits as election nears - Reuters - April 25th, 2025 [April 25th, 2025]
- My Company Competed Against Facebook. Here's What Happened | Opinion - Newsweek - April 25th, 2025 [April 25th, 2025]
- Layboard Launches Innovative Social Network for Job Searching and Career Growth - Reuters - April 25th, 2025 [April 25th, 2025]
- Abrego Garcia family flees to safe house after Trump DHS posts home address on social media - The Real News Network - April 25th, 2025 [April 25th, 2025]
- Opinion: Morning routines are a myth and serve as social media gimmicks - lsureveille.com - April 25th, 2025 [April 25th, 2025]
- Gen Zs Underground Social Network Just Went National And Its Blowing Up - Forbes - April 25th, 2025 [April 25th, 2025]
- Fans React to Jameson Williams Not Following Lions on Social Media - Sports Illustrated - April 25th, 2025 [April 25th, 2025]
- OpenAI may be creating a new social media platform with AI-generated images - Tech Edition - April 25th, 2025 [April 25th, 2025]
- B3 partner with Reach Labs to launch user acquisition platform and GameChain - VentureBeat - April 25th, 2025 [April 25th, 2025]
- OpenAIs Reportedly Exploring Its Own AI-Based Social Network - Social Media Today - April 16th, 2025 [April 16th, 2025]
- OpenAI launches its Social Network: the new frontier of the data war - The Cryptonomist - April 16th, 2025 [April 16th, 2025]
- OpenAI is reportedly developing its own X-like social media platform - TechCrunch - April 16th, 2025 [April 16th, 2025]
- What Meta stands to lose if the FTC wins - Quartz - April 16th, 2025 [April 16th, 2025]
- Instagram and Facebook are hardly social media apps anymore. Here's the proof. - Business Insider - April 16th, 2025 [April 16th, 2025]
- FTC Antitrust Case Against Meta Heads to Trial This Week - Social Media Today - April 16th, 2025 [April 16th, 2025]
- OpenAI might be building its own social network, and we really hope they don't - TechRadar - April 16th, 2025 [April 16th, 2025]
- OpenAI Takes On Elon Musk By Creating Its Own Social Network! - Cointribune - April 16th, 2025 [April 16th, 2025]
- OpenAI is building its own social network to rival Elon Musk's X - Crypto Briefing - April 16th, 2025 [April 16th, 2025]
- OpenAI reportedly creating its own social network to take on X - Tom's Guide - April 16th, 2025 [April 16th, 2025]
- Behind the landmark trial that could reshape Metas future with Instagram - Los Angeles Times - April 16th, 2025 [April 16th, 2025]
- OpenAI is quietly working on a social network similar to Twitter, powered by ChatGPT - TechSpot - April 16th, 2025 [April 16th, 2025]
- OpenAI Reportedly Developing Social Media Platform Amid Ongoing Feud Between Musk, Altman - BW Businessworld - April 16th, 2025 [April 16th, 2025]
- OpenAI braced to challenge Elon Musks X with new social network - The Times - April 16th, 2025 [April 16th, 2025]
- Meta faces antitrust claims at trial over Instagram and WhatsApp ownership - The Guardian - April 16th, 2025 [April 16th, 2025]
- Like Musk, but with ChatGPT: OpenAI is working on its own social network similar to X - ITC.ua - April 16th, 2025 [April 16th, 2025]
- OpenAI may be turning ChatGPT into a social media platform - Android Authority - April 16th, 2025 [April 16th, 2025]
- Creative ChatGPT They are planning their own social network and it will be quite unique! LSA Magazine - Letem svtem Applem - April 16th, 2025 [April 16th, 2025]
- OpenAI is working on X-like social media network, the Verge reports - MarketScreener - April 16th, 2025 [April 16th, 2025]
- Will Meta be forced to sell Instagram and WhatsApp in FTC trial? - Bizcommunity - April 16th, 2025 [April 16th, 2025]
- Body talk on social networking sites and appearance anxiety among college students: the mediating role of self-objectification and moderating role of... - April 10th, 2025 [April 10th, 2025]
- I Tried Seven39, the Social Network That's Only Open Three Hours a Day - Lifehacker - April 10th, 2025 [April 10th, 2025]
- Mapping ISKPs Strength: Social Network Analysis of Tech-Driven Jihad - Global Network on Extremism and Technology - April 10th, 2025 [April 10th, 2025]
- ION and HyperGPT Unite to Power AI-Driven Web3 Social Networks - CoinTrust - April 10th, 2025 [April 10th, 2025]
- College Student Shares Why She Deleted All Socials and What Life Is Like Without It - The Flagler College Gargoyle - April 10th, 2025 [April 10th, 2025]
- CRD is shutting down its X account, saying platform 'rife with misinformation' - Times Colonist - April 10th, 2025 [April 10th, 2025]
- Social Network: Is the mental health of teenagers in danger? - evidencenetwork.ca - April 10th, 2025 [April 10th, 2025]
- Leo, Daily Horoscope Today, April 10, 2025: Business owners will find success through social networking - Times of India - April 10th, 2025 [April 10th, 2025]
- Daily time spent on social networking by internet users - the-star.co.ke - April 10th, 2025 [April 10th, 2025]
- Young people and the pressure to be perfect like on social media - baohaiduong.vn - April 10th, 2025 [April 10th, 2025]
- CSC urged to recall memo on social media use of gov't personnel - GMA Network - April 10th, 2025 [April 10th, 2025]
- Woman charged for hit-and-run death allegedly posted about victim on social media after the crash - KBTX News 3 - April 8th, 2025 [April 8th, 2025]
- LinkedIn reveals best places to work - 9Now - April 8th, 2025 [April 8th, 2025]
- Chamber showcase fills Union Station with real-life social networking for small biz owners - Startland News - April 5th, 2025 [April 5th, 2025]
- Beyond Bluesky: These are the apps building social experiences on the AT Protocol - TechCrunch - April 5th, 2025 [April 5th, 2025]
- Modeling the amplification of epidemic spread by individuals exposed to misinformation on social media - Nature - April 5th, 2025 [April 5th, 2025]
- Gen Z is flocking to the one social media platform millennials didn't ruin - Business Insider - April 5th, 2025 [April 5th, 2025]
- Whistlr Network: The Real-Time, Unfiltered Social Media, That - openPR.com - April 5th, 2025 [April 5th, 2025]
- EU may make an example of X by issuing $1 billion fine to Musks social network - Ars Technica - April 5th, 2025 [April 5th, 2025]
- Mark Zuckerberg Apparently Bought Jesse Eisenberg's "The Social Network" T-Shirt, And I'm A Little Weirded Out - BuzzFeed - April 5th, 2025 [April 5th, 2025]
- Is X Going To Pay The Price? Europe Is Preparing Historic Sanctions Against Elon Musk. - Cointribune - April 5th, 2025 [April 5th, 2025]
- Truth Social owner Trump Media becomes first company listed on NYSE Texas handing early win to exchange - New York Post - April 5th, 2025 [April 5th, 2025]
- Mark Zuckerberg wears iconic t-shirt from The Social Network, reveals he got it in auction - Mint - April 5th, 2025 [April 5th, 2025]
- Immigration officials look to collect social media handles from those seeking benefits. Is this new? - The Tribune-Democrat - April 5th, 2025 [April 5th, 2025]
- Cryptocurrency and Extremism: How Social Network Analysis is Used to Track Extremist Cryptocurrency Donations - GNET - March 25th, 2025 [March 25th, 2025]
- New bill would require warning labels on social media platforms - KSTP - March 25th, 2025 [March 25th, 2025]
- Japan Grapples with Risks of Social Media in Pursuing Options for Protecting Children Online - Nippon.com - March 25th, 2025 [March 25th, 2025]
- Gabe Newell had his eyes on a social network in the '90s that 'was not in a games context at all'meaning Valve-owned social media could've been a very... - March 25th, 2025 [March 25th, 2025]
- Tired of traditional social media? Here are 4 reasons why Substack is my go-to social media app - ZDNet - March 25th, 2025 [March 25th, 2025]
- Skip the post-trip laundry stress with the new features of Wingle, a free in-flight networking app for travellers - indulgexpress - March 25th, 2025 [March 25th, 2025]
- Social media's impact: Driving business strategies from marketing to ROI - ZAWYA - March 25th, 2025 [March 25th, 2025]
- What Is Meta AI? Everything You Should Know About the Social Network Giant's AI Tools - CNET - March 25th, 2025 [March 25th, 2025]
- The art and science of going viral in 2025 - Computerworld - March 25th, 2025 [March 25th, 2025]
- Agility in Marketing Teams: An Analysis of Factors Influencing the Entry Decision Into a Trendy Social Network | Newswise - Newswise - March 18th, 2025 [March 18th, 2025]
- The Rise and Fall of Terrorgram: Inside a Global Online Hate Network - ProPublica - March 18th, 2025 [March 18th, 2025]
- Why TikTok Should Be OnChain - CoinDesk - March 18th, 2025 [March 18th, 2025]
- China: Officials aim to restrict social media and screen time, youth left in divide - The Hawk - March 18th, 2025 [March 18th, 2025]
- Florida teen killed after being lured on social media to meet man, police say - USA TODAY - March 9th, 2025 [March 9th, 2025]