UK TikTok ban gives us all cause to consider social media security – ComputerWeekly.com
The UK ban on installing and using social media app TikTok on government devices brings our countrys policy in line with that of other jurisdictions including the US and member states of the European Union.
Announced yesterday in the House of Commons by Oliver Dowden, chancellor of the Duchy of Lancaster, the ban covers devices in ministerial and non-ministerial departments, and is a precautionary move that has not been taken in response to any specific incident or threat.
Its the latest step in a long-running feud between the West and China over data privacy issues, that besides TikTok has drawn in the likes of Hikvision, a manufacturer of IP surveillance cameras, and most famously, networking and comms giant Huawei, which found itself banned from the UKs core communications infrastructure in 2020.
All of these cases arise from concerns shared by Britain, the US and other Western states. Broadly speaking, these concerns centre on the possibility that the Chinese government may be able to extract sensitive data from these companies for espionage purposes.
China has a long history of industrial espionage, and its state-backed cyber operations are widely acknowledged as a particularly dangerous threat, so these concerns are not wholly unjustified, and its not a stretch to imagine how Beijing could exploit the personal data of UK government officials should it fall into their hands. In light of this, Chris Vaughan, vice-president of technical account management at Tanium, said its no surprise to see Westminster following in the footsteps of Brussels and Washington DC.
Chinese intelligence tactics are usually focused on longer-term objectives and are fuelled by the sustained collection of data, he said. The immense collection of user data, to now include commerce and purchasing information, combined with biometrics and activity tracking, feeds detailed intelligence into Chinese state departments.
This data can also be leveraged to deliver targeted, timely and often personalised psychological operations against individuals or groups of citizens. These tactics could potentially be used during election cycles and politically charged events in the coming years.
Vaughan regards the UKs TikTok ban as speaking to a wider issue around how much Chinese influence is deemed acceptable in national infrastructure and everyday life (similar issues dogged Huawei previously).
We have seen concerns increase in the West in recent months, with the use of Chinese surveillance technology being restricted, he said. There have also been numerous reports of Chinese efforts to sway politicians by way of lobbying and donations, and the public via social media and the spread of disinformation.
Historically, Russia has been the most prominent user of information operations as we saw from its activities related to the 2016 US election and the Brexit referendum. China has been more focused on stealing intellectual property which it can then use to its own advantage. However, there are indications that the CCP [Chinese Communist Party] will start to focus more on information and influence operations to achieve its strategic goals which adds to the concerns about the use of technology such as TikTok.
Any instances of these activities need to be met head-on by Western political leaders who should take a strong stance against it at the government level, rather than leaving the responsibility to individual organisations.
In her response to Dowdens statement yesterday, Labour deputy leader Angela Rayner was scathing in accusing the government of being behind the curve and making sudden U-turns, and for some in the cyber security community, there is something distinctly fishy about its decision.
Matthew Hodgson, co-founder and CEO of secure comms services provider Element, said that in one important way, the ban is downright hypocritical.
The UK government banning officials having TikTok on their phones while pushing through legislation that will give the UK government access to all UK communications screams of double standards, said Hodgson.
Outwardly it looks like theyre taking the security of data seriously by stopping China having a backdoor into UK data, albeit only for government officials currently. However, the UK government is pushing through the Online Safety Bill, which creates a very similar backdoor into every communications platform used by UK citizens.
So, its not OK for China to access government communications but it is OK to provide a route for them to access citizen communications via Online Safety Bill weaknesses? We need to protect the privacy of UK citizens today from bad actors and nation states of all shapes and sizes, he said.
Naturally, Westminsters thoughts are not shared by TikTok, which continues to stress that its never been asked to hand over data by the Chinese government, and insists it would never do so if asked.
In a statement following Dowdens announcement on 16 March, a TikTok spokesperson said: We are disappointed with this decision. We believe these bans have been based on fundamental misconceptions and driven by wider geopolitics, in which TikTok, and our millions of users in the UK,play no part.
We remain committed to working with the government to address any concerns, but should be judged on facts and treated equally to our competitors. We have begun implementing a comprehensive plan to further protect our European user data, which includes storing UK user data in our European datacentres and tightening data access controls, including third-party independent oversight of our approach.
The organisation believes it is inaccurate to describe it as Chinese-owned as its European presence is incorporated and regulated in the UK and Ireland, and its parent, Bytedance, is incorporated outside of China, so would not be subject to laws that require it to hand over data to Beijing if asked.
The firm recently announced Project Clover, a dedicated secure European enclave to harbour its UK and European Economic Area (EEA) user data. The fulfilment of this project will also see UK user data currently stored in datacentres in Singapore and the US moved within European jurisdiction.
It has also named a third-party cyber security company to audit its controls and protections, monitor data flows, and verify its compliance with relevant laws, which it believes goes beyond what any other tech platform is currently doing.
Venari Security chief technology officer Simon Mullis agrees that the TikTok ban is politically motivated, to some extent. The concerns are really rooted in the ability to assure the chain of trust of data protection from beginning to end, and at all steps in between, he said. With TikTok, this has proven to be extremely difficult for a variety of technical and political reasons.
In fairness, the ban is as much political as it is a consequence of the technical design of the application, said Mullis. Is the TikTok design and architecture so wildly different from other social media applications in widespread use as to cause massive security fears? The answer is probably not.
But Jamie Moles, senior technical manager at ExtraHop, said that given what we do know about how TikTok works, and most importantly, what we know about the data it requests and must have access to in order to run on a device, its mystifying why the UK government has dallied for so long.
Im a security expert who downloaded and used TikTok when it came out like so many others, including those working in the UK government, he said. But heres the difference: I removed it as soon as it became clear that the app could harvest anything from my phone including contacts GPS data, authentication info from other apps, and so on.
Having this app on your phone is tantamount to giving the Chinese government the keys to our economy.
Arctic Wolf chief information security officer (CISO) Adam Marr said: TikTok is collecting massive amounts of information from consumers like user location, voiceprints, calendar information and other sensitive data. The issue is we dont know what this data is being used for, or if a foreign government has access to it.
With the rise of data brokers who make a living out of selling user information, this platform can serve as a vessel for malicious actors to leverage. They can then sell this information, which can be used to target people via phishing emails, influence via propaganda, or even control or access devices. Let this be a reminder that nothing is truly free and that we should all exercise caution.
Faki Saadi, UK and Ireland sales director at SOTI, said: Any app that harvests the data you put into it should be treated with caution. Especially for people trusted with sensitive company information.
TikTok being banned from UK government devices should act as a wake-up call to other organisations do you have full visibility over the apps your employees have on their corporate devices? If not, perhaps now is the time to take stock. And it doesnt need to be a heavy lift there are solutions available that can do this for you, and wipe any unwanted apps in an instant.
Marr and Saadi both speak to a wider issue with social media in general. Other social media platforms such as Facebook and Instagram owner Meta have shown themselves repeatedly to be highly blas with regard to their user data and security policies. Twitter, under the control of the erratic Elon Musk, is heading in a similar direction.
And Robert Huber, chief security officer at Tenable, said that focusing only on TikTok means we risk missing the forest for the trees. There are hundreds of software applications used in government agencies every day that introduce risk, and unpatched known vulnerabilities are the most likely source of data breaches, he said.
The key is for security leaders to understand their organisations unique risk profile, discover where vulnerabilities exist and prioritise remediation efforts to root out those that could be the most harmful first.
Ismael Valenzuela, vice-president of threat research and intelligence at BlackBerry, said he is already seeing CISOs considering banning the use of TikTok on company devices. This is particularly relevant to those working for organisations that operate in highly regulated environments, such as the financial services sector, where companies are rightly expected to conduct their own product security testing and legal review of privacy policy positions to, at the very least, limiting use on corporate devices or by high-value users.
There is no doubt that organisations with regularly updated threat models based on contextual intelligence, mature asset management practices and integrated management endpoint solutions are better positioned to manage this risk enterprise-wide, said Valenzuela.
It underscores the importance of managing risk throughout the organisation and the need to assess, and thereby control, the impact of the introduction of new products and technologies upon overall organisational security. This includes the use of seemingly innocuous chat and social media apps.
I suspect that only a limited number of CISOs are aware of TikToks privacy policy statement, he continued. While attacks on the supply chain are a real concern today, privacy risk should also be a top priority for CISOs of high-risk organisations. This is because personal data on company executives and other important individuals can be of great value in the hands of financially motivated attackers or the state.
Ultimately, the question of whether or not security leaders should ban or restrict the use of TikTok on company-owned devices is one that only they can answer. But given the growing number of government bans being proposed or enacted, at the very least, a thorough risk assessment is in order, coupled with a wider audit of corporate social media activity.
Continue reading here:
UK TikTok ban gives us all cause to consider social media security - ComputerWeekly.com
- Early research shows benefits of social media break - Harvard Gazette - December 18th, 2025 [December 18th, 2025]
- What to know about the merger of Trump's social media company and a nuclear fusion firm - WBUR - December 18th, 2025 [December 18th, 2025]
- Study Links Social Avoidance to Increased Risk of Problematic Social Networking Site Use - geneonline.com - December 18th, 2025 [December 18th, 2025]
- Bluesky Launches Privacy-Focused Find Friends with Opt-In Hashing - WebProNews - December 18th, 2025 [December 18th, 2025]
- New IARMJ guidelines offer practical framework for social media evidence in asylum appeals - Electronic Immigration Network - December 18th, 2025 [December 18th, 2025]
- Social Network Sues Government, Claiming Children Have Rights to Adult-Dominated Platform - Movieguide - December 18th, 2025 [December 18th, 2025]
- Otaku friendly Twitter clone Pommu partially revived after month-long suspension. Services limited to Japanese DLsite users - AUTOMATON - December 18th, 2025 [December 18th, 2025]
- The mastermind behind the 'Under 16 Social Media Ban Law' may have been an advertising agency that wanted to block the regulation of online gambling... - December 18th, 2025 [December 18th, 2025]
- If You Quit Social Media, Will You Read More Books? - The New Yorker - December 14th, 2025 [December 14th, 2025]
- Why is Trump demanding travellers social media handles; how will it work? - Al Jazeera - December 14th, 2025 [December 14th, 2025]
- Australia is banning young teens from social media. Could it happen in the US? - CNN - December 14th, 2025 [December 14th, 2025]
- Screen time and ADHD: why social media stands out from gaming and TV - News-Medical - December 14th, 2025 [December 14th, 2025]
- Whats the worst thing thats gonna happen? South Australia Premier says social media ban is about protecting children - CNN - December 14th, 2025 [December 14th, 2025]
- Australia has just relieved its anxiety over teens on social media or has it? - CNN - December 14th, 2025 [December 14th, 2025]
- Pew: Teen Social Media Habits Hold Steady As AI Chatbots Move Into The Mainstream - Net Influencer - December 14th, 2025 [December 14th, 2025]
- Could a social media ban for kids work in the United States? - CNN - December 14th, 2025 [December 14th, 2025]
- Taylor Swift's Last Album Sparked Bizarre Accusations of Nazism. It Was a Coordinated Attack - Rolling Stone - December 14th, 2025 [December 14th, 2025]
- Social media is obsessed with this dumpling 'lasagna' recipe, here's how to make it - ABC News - December 14th, 2025 [December 14th, 2025]
- Social media ban explained: when does it start in Australia, how will it work and what apps are being banned for under-16s? - The Guardian - December 14th, 2025 [December 14th, 2025]
- VIDEO INTERVIEW: Media.com CEO James Mawhinney on why fake accounts, bots and anonymous trolls aren't on his social media platform - and much more! -... - December 14th, 2025 [December 14th, 2025]
- Latin Grammy winner and Texas Dem star recruit hits House campaign with years of porn-linked posts - Fox News - December 14th, 2025 [December 14th, 2025]
- Australia bans teens from social media good luck with that - theregister.com - December 14th, 2025 [December 14th, 2025]
- 'The Social Network': The film that predicted the future of the internet - vijesti.me - December 14th, 2025 [December 14th, 2025]
- Opinion | Can We Stop Our Digital Selves From Becoming Who We Are? - The New York Times - December 7th, 2025 [December 7th, 2025]
- How Australias Social Media Ban for Children Will Work - The New York Times - December 7th, 2025 [December 7th, 2025]
- How Australia became the testing ground for a social media ban for young people - The Guardian - December 7th, 2025 [December 7th, 2025]
- Elon Musk said the EU "should be abolished" after his social network X was fined - - December 7th, 2025 [December 7th, 2025]
- YouTube says it will comply with Australia's teen social media ban - Yahoo! Finance Canada - December 7th, 2025 [December 7th, 2025]
- The European Commission fined the social network X 120 million euros for violating the Digital Services Act: the US has already expressed outrage - - December 7th, 2025 [December 7th, 2025]
- Europe fines X, Musk removes Commission account and attacks: 'The EU is the Fourth Reich' - Il Sole 24 ORE - December 7th, 2025 [December 7th, 2025]
- Exclusive: Woman suspected by France of spying has ties to Kremlin proxies, social media posts show - Reuters - December 5th, 2025 [December 5th, 2025]
- A Look Back at Social Networking Stocks' Q3 Earnings: Meta (NASDAQ:META) Vs The Rest Of The Pack - Finviz - December 5th, 2025 [December 5th, 2025]
- Rubio sharply criticized the European Commission's decision to fine Musk's social network - Online.UA - December 5th, 2025 [December 5th, 2025]
- Meta has begun shutting down kids' social media in Australia. The world is watching to see how it unfolds - CBC - December 5th, 2025 [December 5th, 2025]
- Meta says starting to remove under-16s from social media in Australia - The Daily Post-Athenian - December 5th, 2025 [December 5th, 2025]
- Teens hoping to get around Australias social media ban are rushing to smaller apps. Where are they going? - The Guardian - December 5th, 2025 [December 5th, 2025]
- What is Australia's under-16 social media ban? The world-first law explained - The University of Sydney - December 5th, 2025 [December 5th, 2025]
- Australia To Enforce Social Media Age Limit Of 16 Next Week With Fines Up To $33 Million - HuffPost - December 5th, 2025 [December 5th, 2025]
- Australia's world-first under-16s social media ban is the painful culmination of the Coalition refusing to stand up for the principles of individual... - December 5th, 2025 [December 5th, 2025]
- Social network X received a fine of 120 million euros from the EC what are the reasons? - Online.UA - December 5th, 2025 [December 5th, 2025]
- 19-minute viral video controversy sparks buzz on social media: Can sharing the clip land you in jail? Here - The Economic Times - December 5th, 2025 [December 5th, 2025]
- How would brands react if minors were banned from social media? - nssmag.com - December 5th, 2025 [December 5th, 2025]
- US Tightens H-1B Visa Vetting with New Social Media Rules - India News Network - December 5th, 2025 [December 5th, 2025]
- Social networks, the endless scroll changes the relationship with time and space - Il Sole 24 ORE - December 5th, 2025 [December 5th, 2025]
- CP3 will end his Hall of Fame career at home Clippers social media page posted this four days before the team cut him - Basketball Network - December 5th, 2025 [December 5th, 2025]
- Meet Jay Graber, the CEO of Bluesky, who is building a 'billionaire-proof' and decentralized social media platform - Business Insider - November 30th, 2025 [November 30th, 2025]
- How to support your child through the social media ban listen, be on their side and dont try to justify the new rules - The Guardian - November 30th, 2025 [November 30th, 2025]
- A Look Back at Social Networking Stocks Q3 Earnings: Snap (NYSE:SNAP) Vs The Rest Of The Pack - Yahoo Finance - November 30th, 2025 [November 30th, 2025]
- Do women really need to pretend they are men on LinkedIn to get their posts seen? - The Independent - November 30th, 2025 [November 30th, 2025]
- Awards Chatter Pod: Jeremy Allen White on Springsteen, the Categorization and Future of The Bear, and the Social Network Sequel - The Hollywood... - November 30th, 2025 [November 30th, 2025]
- X's new location feature sparks controversy, but is the data reliable? - NPR - November 26th, 2025 [November 26th, 2025]
- Study Finds Mental Health Benefit to One-Week Social Media Break - The New York Times - November 26th, 2025 [November 26th, 2025]
- Children who watch violent social media more likely to harm someone - The Telegraph - November 26th, 2025 [November 26th, 2025]
- The Social-Media Platform That Makes You Tell the Truth - The New York Times - November 26th, 2025 [November 26th, 2025]
- Paige Spiranac Breaks Her Long Silence On Social Media - Yahoo - November 26th, 2025 [November 26th, 2025]
- Human and AI collaboration is the key to building safer social media - The AI Journal - November 26th, 2025 [November 26th, 2025]
- A Look Back at Social Networking Stocks Q3 Earnings: Snap (NYSE:SNAP) Vs The Rest Of The Pack - Yahoo! Finance Canada - November 26th, 2025 [November 26th, 2025]
- Lawsuit alleges social media giants buried their own research on teen mental health harms - CNN - November 26th, 2025 [November 26th, 2025]
- Coffee Trumps Internet In Thermopolis, A Throwback To Old-School Social Networking - Cowboy State Daily - November 26th, 2025 [November 26th, 2025]
- Emerging Trends to Reshape the Social Media Management Market: - openPR.com - November 26th, 2025 [November 26th, 2025]
- Promising Social Media Stocks To Watch Now - November 24th - MarketBeat - November 26th, 2025 [November 26th, 2025]
- YouTube has become the most popular social network among adults in the US study - Mezha - November 26th, 2025 [November 26th, 2025]
- The "Child and Youth Social Network Prohibition Act (SNS) Prohibition Act," which passed the Austral.. - - November 26th, 2025 [November 26th, 2025]
- Less anxiety, depression and insomnia for kids who give up social media for a week - Il Sole 24 ORE - November 26th, 2025 [November 26th, 2025]
- Michael Bubl spars with Vancouver Canucks fans on social media - Daily Hive Vancouver - November 26th, 2025 [November 26th, 2025]
- Another country set to join Australia with ban on social media for children - The Independent - November 26th, 2025 [November 26th, 2025]
- 'Vile abuse' against MPs after Neo-Nazi demonstration referred to police - Australian Broadcasting Corporation - November 11th, 2025 [November 11th, 2025]
- Attorneys Sanctioned for Social Media Research on Prospective Jurors | EDRM - Electronic Discovery Reference Model - JD Supra - November 7th, 2025 [November 7th, 2025]
- Mark Zuckerberg says 'The Social Network' nailed his wardrobe: 'Every single shirt or fleece they had in that movie is a shirt or fleece that I own' -... - November 7th, 2025 [November 7th, 2025]
- Why TikTok Keeps You Scrolling: Baylor Research Explains the Science Behind Social Media Addiction - Baylor University - November 7th, 2025 [November 7th, 2025]
- Social media can cause stress in real life our digital thermometer helps track it - The Conversation - November 7th, 2025 [November 7th, 2025]
- Facebook Dating Is a Surprise Hit for the Social Network - The New York Times - November 7th, 2025 [November 7th, 2025]
- Dr Tariq urges youth to verify content before sharing on social media - Associated Press of Pakistan - November 7th, 2025 [November 7th, 2025]
- Heart Evangelista reveals another art piece on her social media - GMA Network - November 7th, 2025 [November 7th, 2025]
- X asks B.C. judge to throw out $100,000 fine for intimate image posting - Vancouver Sun - November 7th, 2025 [November 7th, 2025]
- How Americans trust in information from news organizations and social media sites has changed over time - Pew Research Center - October 31st, 2025 [October 31st, 2025]
- Jesse Eisenberg forced to answer Social Network question after awkward attempt to dodge: 'We both are playing chess' - Entertainment Weekly - October 31st, 2025 [October 31st, 2025]
- Boost hope and reduce stress with this simple social media trick - NPR - October 28th, 2025 [October 28th, 2025]
- Grindr receives buyout offer to take dating app private - Los Angeles Times - October 28th, 2025 [October 28th, 2025]
- Quantum stocks are rising. Why they may be the Trump White Houses next investment. - MarketWatch - October 26th, 2025 [October 26th, 2025]