UK TikTok ban gives us all cause to consider social media security – ComputerWeekly.com
The UK ban on installing and using social media app TikTok on government devices brings our countrys policy in line with that of other jurisdictions including the US and member states of the European Union.
Announced yesterday in the House of Commons by Oliver Dowden, chancellor of the Duchy of Lancaster, the ban covers devices in ministerial and non-ministerial departments, and is a precautionary move that has not been taken in response to any specific incident or threat.
Its the latest step in a long-running feud between the West and China over data privacy issues, that besides TikTok has drawn in the likes of Hikvision, a manufacturer of IP surveillance cameras, and most famously, networking and comms giant Huawei, which found itself banned from the UKs core communications infrastructure in 2020.
All of these cases arise from concerns shared by Britain, the US and other Western states. Broadly speaking, these concerns centre on the possibility that the Chinese government may be able to extract sensitive data from these companies for espionage purposes.
China has a long history of industrial espionage, and its state-backed cyber operations are widely acknowledged as a particularly dangerous threat, so these concerns are not wholly unjustified, and its not a stretch to imagine how Beijing could exploit the personal data of UK government officials should it fall into their hands. In light of this, Chris Vaughan, vice-president of technical account management at Tanium, said its no surprise to see Westminster following in the footsteps of Brussels and Washington DC.
Chinese intelligence tactics are usually focused on longer-term objectives and are fuelled by the sustained collection of data, he said. The immense collection of user data, to now include commerce and purchasing information, combined with biometrics and activity tracking, feeds detailed intelligence into Chinese state departments.
This data can also be leveraged to deliver targeted, timely and often personalised psychological operations against individuals or groups of citizens. These tactics could potentially be used during election cycles and politically charged events in the coming years.
Vaughan regards the UKs TikTok ban as speaking to a wider issue around how much Chinese influence is deemed acceptable in national infrastructure and everyday life (similar issues dogged Huawei previously).
We have seen concerns increase in the West in recent months, with the use of Chinese surveillance technology being restricted, he said. There have also been numerous reports of Chinese efforts to sway politicians by way of lobbying and donations, and the public via social media and the spread of disinformation.
Historically, Russia has been the most prominent user of information operations as we saw from its activities related to the 2016 US election and the Brexit referendum. China has been more focused on stealing intellectual property which it can then use to its own advantage. However, there are indications that the CCP [Chinese Communist Party] will start to focus more on information and influence operations to achieve its strategic goals which adds to the concerns about the use of technology such as TikTok.
Any instances of these activities need to be met head-on by Western political leaders who should take a strong stance against it at the government level, rather than leaving the responsibility to individual organisations.
In her response to Dowdens statement yesterday, Labour deputy leader Angela Rayner was scathing in accusing the government of being behind the curve and making sudden U-turns, and for some in the cyber security community, there is something distinctly fishy about its decision.
Matthew Hodgson, co-founder and CEO of secure comms services provider Element, said that in one important way, the ban is downright hypocritical.
The UK government banning officials having TikTok on their phones while pushing through legislation that will give the UK government access to all UK communications screams of double standards, said Hodgson.
Outwardly it looks like theyre taking the security of data seriously by stopping China having a backdoor into UK data, albeit only for government officials currently. However, the UK government is pushing through the Online Safety Bill, which creates a very similar backdoor into every communications platform used by UK citizens.
So, its not OK for China to access government communications but it is OK to provide a route for them to access citizen communications via Online Safety Bill weaknesses? We need to protect the privacy of UK citizens today from bad actors and nation states of all shapes and sizes, he said.
Naturally, Westminsters thoughts are not shared by TikTok, which continues to stress that its never been asked to hand over data by the Chinese government, and insists it would never do so if asked.
In a statement following Dowdens announcement on 16 March, a TikTok spokesperson said: We are disappointed with this decision. We believe these bans have been based on fundamental misconceptions and driven by wider geopolitics, in which TikTok, and our millions of users in the UK,play no part.
We remain committed to working with the government to address any concerns, but should be judged on facts and treated equally to our competitors. We have begun implementing a comprehensive plan to further protect our European user data, which includes storing UK user data in our European datacentres and tightening data access controls, including third-party independent oversight of our approach.
The organisation believes it is inaccurate to describe it as Chinese-owned as its European presence is incorporated and regulated in the UK and Ireland, and its parent, Bytedance, is incorporated outside of China, so would not be subject to laws that require it to hand over data to Beijing if asked.
The firm recently announced Project Clover, a dedicated secure European enclave to harbour its UK and European Economic Area (EEA) user data. The fulfilment of this project will also see UK user data currently stored in datacentres in Singapore and the US moved within European jurisdiction.
It has also named a third-party cyber security company to audit its controls and protections, monitor data flows, and verify its compliance with relevant laws, which it believes goes beyond what any other tech platform is currently doing.
Venari Security chief technology officer Simon Mullis agrees that the TikTok ban is politically motivated, to some extent. The concerns are really rooted in the ability to assure the chain of trust of data protection from beginning to end, and at all steps in between, he said. With TikTok, this has proven to be extremely difficult for a variety of technical and political reasons.
In fairness, the ban is as much political as it is a consequence of the technical design of the application, said Mullis. Is the TikTok design and architecture so wildly different from other social media applications in widespread use as to cause massive security fears? The answer is probably not.
But Jamie Moles, senior technical manager at ExtraHop, said that given what we do know about how TikTok works, and most importantly, what we know about the data it requests and must have access to in order to run on a device, its mystifying why the UK government has dallied for so long.
Im a security expert who downloaded and used TikTok when it came out like so many others, including those working in the UK government, he said. But heres the difference: I removed it as soon as it became clear that the app could harvest anything from my phone including contacts GPS data, authentication info from other apps, and so on.
Having this app on your phone is tantamount to giving the Chinese government the keys to our economy.
Arctic Wolf chief information security officer (CISO) Adam Marr said: TikTok is collecting massive amounts of information from consumers like user location, voiceprints, calendar information and other sensitive data. The issue is we dont know what this data is being used for, or if a foreign government has access to it.
With the rise of data brokers who make a living out of selling user information, this platform can serve as a vessel for malicious actors to leverage. They can then sell this information, which can be used to target people via phishing emails, influence via propaganda, or even control or access devices. Let this be a reminder that nothing is truly free and that we should all exercise caution.
Faki Saadi, UK and Ireland sales director at SOTI, said: Any app that harvests the data you put into it should be treated with caution. Especially for people trusted with sensitive company information.
TikTok being banned from UK government devices should act as a wake-up call to other organisations do you have full visibility over the apps your employees have on their corporate devices? If not, perhaps now is the time to take stock. And it doesnt need to be a heavy lift there are solutions available that can do this for you, and wipe any unwanted apps in an instant.
Marr and Saadi both speak to a wider issue with social media in general. Other social media platforms such as Facebook and Instagram owner Meta have shown themselves repeatedly to be highly blas with regard to their user data and security policies. Twitter, under the control of the erratic Elon Musk, is heading in a similar direction.
And Robert Huber, chief security officer at Tenable, said that focusing only on TikTok means we risk missing the forest for the trees. There are hundreds of software applications used in government agencies every day that introduce risk, and unpatched known vulnerabilities are the most likely source of data breaches, he said.
The key is for security leaders to understand their organisations unique risk profile, discover where vulnerabilities exist and prioritise remediation efforts to root out those that could be the most harmful first.
Ismael Valenzuela, vice-president of threat research and intelligence at BlackBerry, said he is already seeing CISOs considering banning the use of TikTok on company devices. This is particularly relevant to those working for organisations that operate in highly regulated environments, such as the financial services sector, where companies are rightly expected to conduct their own product security testing and legal review of privacy policy positions to, at the very least, limiting use on corporate devices or by high-value users.
There is no doubt that organisations with regularly updated threat models based on contextual intelligence, mature asset management practices and integrated management endpoint solutions are better positioned to manage this risk enterprise-wide, said Valenzuela.
It underscores the importance of managing risk throughout the organisation and the need to assess, and thereby control, the impact of the introduction of new products and technologies upon overall organisational security. This includes the use of seemingly innocuous chat and social media apps.
I suspect that only a limited number of CISOs are aware of TikToks privacy policy statement, he continued. While attacks on the supply chain are a real concern today, privacy risk should also be a top priority for CISOs of high-risk organisations. This is because personal data on company executives and other important individuals can be of great value in the hands of financially motivated attackers or the state.
Ultimately, the question of whether or not security leaders should ban or restrict the use of TikTok on company-owned devices is one that only they can answer. But given the growing number of government bans being proposed or enacted, at the very least, a thorough risk assessment is in order, coupled with a wider audit of corporate social media activity.
Continue reading here:
UK TikTok ban gives us all cause to consider social media security - ComputerWeekly.com
- Hearing on Government Social Media Censorship - C-SPAN - October 9th, 2025 [October 9th, 2025]
- Scott Galloway says the key to landing jobs is be as social as possible: '70% of the time, the person they pick is someone with an internal advocate'... - October 9th, 2025 [October 9th, 2025]
- Denmark will BAN social media for under 15s as PM warns it is 'robbing our children of their childhood' - Daily Mail - October 9th, 2025 [October 9th, 2025]
- Rolling Ray, Social Media And Zeus Network Star, Cause Of Death Revealed - VIBE.com - October 9th, 2025 [October 9th, 2025]
- Politically aggressive social media users are creating most of the anti-immigrant content - The Conversation - October 7th, 2025 [October 7th, 2025]
- 'The Social Network' Sequel Has Already Forgotten What Made the Original So Influential - Collider - October 7th, 2025 [October 7th, 2025]
- Researchers Created A Social Network With AI Bots To Try And Solve Online Toxicity. It Failed. - TwistedSifter - October 7th, 2025 [October 7th, 2025]
- Actor Han So-hee said it was a "mistake" amid controversy over political colors by clicking "like" o.. - - October 7th, 2025 [October 7th, 2025]
- ICE Plans to Add a Social Media Surveillance Team to Hunt for Leads on Wanted Individuals - Tech Times - October 7th, 2025 [October 7th, 2025]
- Social Gaming Market : Emerging Trends and Opportunities in End-Use Industries - openPR.com - October 7th, 2025 [October 7th, 2025]
- Controversy Erupts on Social Media Over Massive Mistake in Vikings-Browns Game in London - Pro Football & Sports Network - October 7th, 2025 [October 7th, 2025]
- 'A force for alienation': How The Social Network predicted the future of tech - BBC - October 4th, 2025 [October 4th, 2025]
- Telegram's CEO explains his philosophy for using a phone as little as possible and allocating 11 to 12 hours for sleep - Business Insider Africa - October 4th, 2025 [October 4th, 2025]
- Before Making Its Sequel, Aaron Sorkin Actually Directed One Scene in the Original 'Social Network' - Collider - October 4th, 2025 [October 4th, 2025]
- 15 Years Later, The Social Network Remains A Masterpiece of the 21st Century - That Hashtag Show - October 4th, 2025 [October 4th, 2025]
- Ollywan v. Meta: A Startup Takes on Big Tech Over Alleged Monopolization - thefashionlaw.com - October 4th, 2025 [October 4th, 2025]
- FRND, a made-in-India social media and dating app focussed on non-metro cities, is in the process of raising $25 million from new and existing... - October 4th, 2025 [October 4th, 2025]
- Everything is fake on Silicon Valleys hottest new social network - The Washington Post - October 4th, 2025 [October 4th, 2025]
- How Social Media Is Changing the Narrative of the Israel-Gaza War - The New York Times - October 2nd, 2025 [October 2nd, 2025]
- Could making silly AI videos of your friends be social media's next frontier? Let's talk about OpenAI's Sora. - Business Insider - October 2nd, 2025 [October 2nd, 2025]
- 15 Years On, The Social Network Feels Like The Warning We All Ignored - Screen Rant - October 2nd, 2025 [October 2nd, 2025]
- System lets people personalize online social spaces while staying connected with others - MIT News - October 2nd, 2025 [October 2nd, 2025]
- The Social Network Turns 15: Max Minghella Reflects on Working With David Fincher - Nerdtropolis - October 2nd, 2025 [October 2nd, 2025]
- The Social Network at 15: Aaron Sorkin recalls why he signed on to write the original - Gold Derby - October 2nd, 2025 [October 2nd, 2025]
- The Social Network 2: An Iconic Actor Missing, and It Makes Sense - 3DVF - October 2nd, 2025 [October 2nd, 2025]
- Graffiti framework lets people personalize online social spaces while staying connected with others - Tech Xplore - October 2nd, 2025 [October 2nd, 2025]
- VR and social media create blurred realities that negatively affect well-being. - Psychology Today - October 2nd, 2025 [October 2nd, 2025]
- The Social Network 15 years later: No one listened to David Finchers warning - Far Out Magazine - October 2nd, 2025 [October 2nd, 2025]
- 15 Years Of The Social Network | Revisiting Anxieties Around The Internet & Human Connection - Outlook India - October 2nd, 2025 [October 2nd, 2025]
- Connectivist knowledge production and learning success in distributed social networks: structural equation modeling approach - Taylor & Francis... - September 30th, 2025 [September 30th, 2025]
- Andrew Garfield Wont Be Returning for The Social Network Sequel: Eduardo Saverin Is in Singapore Having a Good Time - Variety - September 30th, 2025 [September 30th, 2025]
- OpenAIs New Social Network Is Reportedly TikTok If It Was Just an AI Slop Feed - Gizmodo - September 30th, 2025 [September 30th, 2025]
- Andrew Garfield Shuts Down The Social Network Part II Return, Gives Update On Eduardo Saverin - Deadline - September 30th, 2025 [September 30th, 2025]
- The Social Network: Who will star in the Facebook sequel? - numero.com - September 30th, 2025 [September 30th, 2025]
- Andrew Garfield Finally Addresses Possible Return for The Social Network Follow-Up - Comic Book Resources - September 30th, 2025 [September 30th, 2025]
- Jeremy Allen White Has Read the Script for 'The Social Network' Sequel - IndieWire - September 30th, 2025 [September 30th, 2025]
- A psychology expert's guide to creating the right social network, finding lasting friendships and building community - CNBC - September 30th, 2025 [September 30th, 2025]
- Andrew Garfield Addresses If He Will Return In The Social Network Sequel - Screen Rant - September 30th, 2025 [September 30th, 2025]
- Why Andrew Garfield Won't Return In 'The Social Network 2' Here's All We Know - BollywoodShaadis - September 30th, 2025 [September 30th, 2025]
- Andrew Garfield reveals if he will return for 'The Social Network: Part II' - Entertainment Weekly - September 30th, 2025 [September 30th, 2025]
- Zohos Arattai Tops App Store Social Networking List: What It Offers, How to Use, And Is It Free? - News18 - September 30th, 2025 [September 30th, 2025]
- Social Network 2: Is Andrew Garfield going to feature in it? Heres what the actor said - Masala.com - September 30th, 2025 [September 30th, 2025]
- Andrew Garfield Isn't Returning in Social Network Sequel and Eduardo Saverins Wild Life Explains Why - Collider - September 30th, 2025 [September 30th, 2025]
- Inside the everyday Facebook networks where far-right ideas grow - The Guardian - September 30th, 2025 [September 30th, 2025]
- Zohos homegrown messaging app Arattai has climbed to the top spot on Apples App Store social networking chart in India, overtaking global rivals such... - September 30th, 2025 [September 30th, 2025]
- Eduardo Saverins Absence Shifts Focus in The Social Network Sequel - Azat TV - September 30th, 2025 [September 30th, 2025]
- Andrew Garfield on Whether Hell Return for The Social Network Sequel: Eduardo Is in Singapore Having a Good Time - Yahoo News UK - September 30th, 2025 [September 30th, 2025]
- Andrew Garfield reveals if he would return for The Social Reckoning: 'Eduardo is in Singapore having a good time' - Cinema Express - September 30th, 2025 [September 30th, 2025]
- Andrew Garfield To Return In The Social Network Part 2? Actor Breaks Silence - News18 - September 30th, 2025 [September 30th, 2025]
- Mikey Madison will play a Facebook whistleblower in Aaron Sorkin's Social Network follow-up - ABC News - Breaking News, Latest News and Videos - September 28th, 2025 [September 28th, 2025]
- Wait, Theres a Social Network 2 and Bill Burr Might Be in It? - Pajiba - September 28th, 2025 [September 28th, 2025]
- The Social Network Part II Gets New Title and 2026 Fall Release - The Hollywood Reporter - September 28th, 2025 [September 28th, 2025]
- The Social Network follow-up has a new title and release date - The Verge - September 28th, 2025 [September 28th, 2025]
- Aaron Sorkin's Social Network Follow-Up Gets New Title, Release Date, and Confirmed Cast - Consequence of Sound - September 28th, 2025 [September 28th, 2025]
- Jesse Eisenberg replaced by A-lister in Aaron Sorkins long-awaited The Social Network sequel - The Independent - September 28th, 2025 [September 28th, 2025]
- New Title and October 2026 Release Date for The Social Network Sequel - The Movie Blog - September 28th, 2025 [September 28th, 2025]
- Bill Burr Could Be Logging On for The Social Network 2 - Complex - September 28th, 2025 [September 28th, 2025]
- Aaron Sorkin's Social Network Follow-Up Gets Major Update 15 Years After the Original - Comic Book Resources - September 28th, 2025 [September 28th, 2025]
- Successions Jeremy Strong to play Mark Zuckerberg in The Social Network sequel - Dawn Images - September 28th, 2025 [September 28th, 2025]
- The Social Network 2 Gets Official Title, Synopsis, & Cast: Jeremy Strong to Replace Jesse Eisenberg - Just Jared - September 28th, 2025 [September 28th, 2025]
- Cast revealed for The Social Network sequel - The Independent - September 28th, 2025 [September 28th, 2025]
- The social network sequel titled The Social Reckoning set for 2026 release - The Express Tribune - September 28th, 2025 [September 28th, 2025]
- Are users happy with 'Arattai' app? Here's what social media chatter is saying - theweek.in - September 28th, 2025 [September 28th, 2025]
- If all that st was around back then, Id be a fking billionaire Dennis Rodman admits he wishes social media and TMZ existed in his heyday - Basketball... - September 25th, 2025 [September 25th, 2025]
- The Social Network Part II: Bill Burr in Talks to Join Jeremy Allen White, Mikey Madison (Exclusive) - The Hollywood Reporter - September 25th, 2025 [September 25th, 2025]
- Tanzanias social media clampdown and the elections whats at risk - The Conversation - September 25th, 2025 [September 25th, 2025]
- The Social Network Part II cast members: Bill Burr to join Jeremy Allen White and Mikey Madison - Repor - Times of India - September 25th, 2025 [September 25th, 2025]
- Bill Burr circling role in Aaron Sorkins The Social Network Part II with Jeremy Allen White and Mikey Madison - Cinema Express - September 25th, 2025 [September 25th, 2025]
- Intercom cofounder says TikTok and 'The Social Network' led some founders to start companies for the wrong reasons - Business Insider - September 25th, 2025 [September 25th, 2025]
- Teens charged in connection with 'dangerous' social media car stunts: DA - ABC News - Breaking News, Latest News and Videos - September 25th, 2025 [September 25th, 2025]
- The Social Network Part II: Bill Burr In Final Talks To Join Cast Of Aaron Sorkins Film - theplaylist.net - September 25th, 2025 [September 25th, 2025]
- Why this startup founder scrapped her dating app to build a LinkedIn rival powered by AI - Business Insider - September 25th, 2025 [September 25th, 2025]
- Social Network Software Market Set to Grow Significantly, Driven by the Rise of Remote Work and E-commerce - openPR.com - September 25th, 2025 [September 25th, 2025]
- Social media age restrictions may go further than you thought. Heres how - The Conversation - September 25th, 2025 [September 25th, 2025]
- 'The Social Network' sequel to be shot in Vancouver without key actor - Daily Hive Vancouver - September 25th, 2025 [September 25th, 2025]
- Neon, the No. 2 social app on the Apple App Store, pays users to record their phone calls and sells data to AI firms - TechCrunch - September 25th, 2025 [September 25th, 2025]
- What is the rapture, and why is social media expecting it? - NewsNation - September 23rd, 2025 [September 23rd, 2025]
- Trump pushes Bondi to pursue cases against his foes as he ramps up retribution campaign - PBS - September 23rd, 2025 [September 23rd, 2025]
- Murdochs, burned on MySpace, seek return to social with TikTok - Fortune - September 23rd, 2025 [September 23rd, 2025]
- White House promises US-controlled TikTok algorithm - The Standard (HK) - September 23rd, 2025 [September 23rd, 2025]