UK TikTok ban gives us all cause to consider social media security – ComputerWeekly.com
The UK ban on installing and using social media app TikTok on government devices brings our countrys policy in line with that of other jurisdictions including the US and member states of the European Union.
Announced yesterday in the House of Commons by Oliver Dowden, chancellor of the Duchy of Lancaster, the ban covers devices in ministerial and non-ministerial departments, and is a precautionary move that has not been taken in response to any specific incident or threat.
Its the latest step in a long-running feud between the West and China over data privacy issues, that besides TikTok has drawn in the likes of Hikvision, a manufacturer of IP surveillance cameras, and most famously, networking and comms giant Huawei, which found itself banned from the UKs core communications infrastructure in 2020.
All of these cases arise from concerns shared by Britain, the US and other Western states. Broadly speaking, these concerns centre on the possibility that the Chinese government may be able to extract sensitive data from these companies for espionage purposes.
China has a long history of industrial espionage, and its state-backed cyber operations are widely acknowledged as a particularly dangerous threat, so these concerns are not wholly unjustified, and its not a stretch to imagine how Beijing could exploit the personal data of UK government officials should it fall into their hands. In light of this, Chris Vaughan, vice-president of technical account management at Tanium, said its no surprise to see Westminster following in the footsteps of Brussels and Washington DC.
Chinese intelligence tactics are usually focused on longer-term objectives and are fuelled by the sustained collection of data, he said. The immense collection of user data, to now include commerce and purchasing information, combined with biometrics and activity tracking, feeds detailed intelligence into Chinese state departments.
This data can also be leveraged to deliver targeted, timely and often personalised psychological operations against individuals or groups of citizens. These tactics could potentially be used during election cycles and politically charged events in the coming years.
Vaughan regards the UKs TikTok ban as speaking to a wider issue around how much Chinese influence is deemed acceptable in national infrastructure and everyday life (similar issues dogged Huawei previously).
We have seen concerns increase in the West in recent months, with the use of Chinese surveillance technology being restricted, he said. There have also been numerous reports of Chinese efforts to sway politicians by way of lobbying and donations, and the public via social media and the spread of disinformation.
Historically, Russia has been the most prominent user of information operations as we saw from its activities related to the 2016 US election and the Brexit referendum. China has been more focused on stealing intellectual property which it can then use to its own advantage. However, there are indications that the CCP [Chinese Communist Party] will start to focus more on information and influence operations to achieve its strategic goals which adds to the concerns about the use of technology such as TikTok.
Any instances of these activities need to be met head-on by Western political leaders who should take a strong stance against it at the government level, rather than leaving the responsibility to individual organisations.
In her response to Dowdens statement yesterday, Labour deputy leader Angela Rayner was scathing in accusing the government of being behind the curve and making sudden U-turns, and for some in the cyber security community, there is something distinctly fishy about its decision.
Matthew Hodgson, co-founder and CEO of secure comms services provider Element, said that in one important way, the ban is downright hypocritical.
The UK government banning officials having TikTok on their phones while pushing through legislation that will give the UK government access to all UK communications screams of double standards, said Hodgson.
Outwardly it looks like theyre taking the security of data seriously by stopping China having a backdoor into UK data, albeit only for government officials currently. However, the UK government is pushing through the Online Safety Bill, which creates a very similar backdoor into every communications platform used by UK citizens.
So, its not OK for China to access government communications but it is OK to provide a route for them to access citizen communications via Online Safety Bill weaknesses? We need to protect the privacy of UK citizens today from bad actors and nation states of all shapes and sizes, he said.
Naturally, Westminsters thoughts are not shared by TikTok, which continues to stress that its never been asked to hand over data by the Chinese government, and insists it would never do so if asked.
In a statement following Dowdens announcement on 16 March, a TikTok spokesperson said: We are disappointed with this decision. We believe these bans have been based on fundamental misconceptions and driven by wider geopolitics, in which TikTok, and our millions of users in the UK,play no part.
We remain committed to working with the government to address any concerns, but should be judged on facts and treated equally to our competitors. We have begun implementing a comprehensive plan to further protect our European user data, which includes storing UK user data in our European datacentres and tightening data access controls, including third-party independent oversight of our approach.
The organisation believes it is inaccurate to describe it as Chinese-owned as its European presence is incorporated and regulated in the UK and Ireland, and its parent, Bytedance, is incorporated outside of China, so would not be subject to laws that require it to hand over data to Beijing if asked.
The firm recently announced Project Clover, a dedicated secure European enclave to harbour its UK and European Economic Area (EEA) user data. The fulfilment of this project will also see UK user data currently stored in datacentres in Singapore and the US moved within European jurisdiction.
It has also named a third-party cyber security company to audit its controls and protections, monitor data flows, and verify its compliance with relevant laws, which it believes goes beyond what any other tech platform is currently doing.
Venari Security chief technology officer Simon Mullis agrees that the TikTok ban is politically motivated, to some extent. The concerns are really rooted in the ability to assure the chain of trust of data protection from beginning to end, and at all steps in between, he said. With TikTok, this has proven to be extremely difficult for a variety of technical and political reasons.
In fairness, the ban is as much political as it is a consequence of the technical design of the application, said Mullis. Is the TikTok design and architecture so wildly different from other social media applications in widespread use as to cause massive security fears? The answer is probably not.
But Jamie Moles, senior technical manager at ExtraHop, said that given what we do know about how TikTok works, and most importantly, what we know about the data it requests and must have access to in order to run on a device, its mystifying why the UK government has dallied for so long.
Im a security expert who downloaded and used TikTok when it came out like so many others, including those working in the UK government, he said. But heres the difference: I removed it as soon as it became clear that the app could harvest anything from my phone including contacts GPS data, authentication info from other apps, and so on.
Having this app on your phone is tantamount to giving the Chinese government the keys to our economy.
Arctic Wolf chief information security officer (CISO) Adam Marr said: TikTok is collecting massive amounts of information from consumers like user location, voiceprints, calendar information and other sensitive data. The issue is we dont know what this data is being used for, or if a foreign government has access to it.
With the rise of data brokers who make a living out of selling user information, this platform can serve as a vessel for malicious actors to leverage. They can then sell this information, which can be used to target people via phishing emails, influence via propaganda, or even control or access devices. Let this be a reminder that nothing is truly free and that we should all exercise caution.
Faki Saadi, UK and Ireland sales director at SOTI, said: Any app that harvests the data you put into it should be treated with caution. Especially for people trusted with sensitive company information.
TikTok being banned from UK government devices should act as a wake-up call to other organisations do you have full visibility over the apps your employees have on their corporate devices? If not, perhaps now is the time to take stock. And it doesnt need to be a heavy lift there are solutions available that can do this for you, and wipe any unwanted apps in an instant.
Marr and Saadi both speak to a wider issue with social media in general. Other social media platforms such as Facebook and Instagram owner Meta have shown themselves repeatedly to be highly blas with regard to their user data and security policies. Twitter, under the control of the erratic Elon Musk, is heading in a similar direction.
And Robert Huber, chief security officer at Tenable, said that focusing only on TikTok means we risk missing the forest for the trees. There are hundreds of software applications used in government agencies every day that introduce risk, and unpatched known vulnerabilities are the most likely source of data breaches, he said.
The key is for security leaders to understand their organisations unique risk profile, discover where vulnerabilities exist and prioritise remediation efforts to root out those that could be the most harmful first.
Ismael Valenzuela, vice-president of threat research and intelligence at BlackBerry, said he is already seeing CISOs considering banning the use of TikTok on company devices. This is particularly relevant to those working for organisations that operate in highly regulated environments, such as the financial services sector, where companies are rightly expected to conduct their own product security testing and legal review of privacy policy positions to, at the very least, limiting use on corporate devices or by high-value users.
There is no doubt that organisations with regularly updated threat models based on contextual intelligence, mature asset management practices and integrated management endpoint solutions are better positioned to manage this risk enterprise-wide, said Valenzuela.
It underscores the importance of managing risk throughout the organisation and the need to assess, and thereby control, the impact of the introduction of new products and technologies upon overall organisational security. This includes the use of seemingly innocuous chat and social media apps.
I suspect that only a limited number of CISOs are aware of TikToks privacy policy statement, he continued. While attacks on the supply chain are a real concern today, privacy risk should also be a top priority for CISOs of high-risk organisations. This is because personal data on company executives and other important individuals can be of great value in the hands of financially motivated attackers or the state.
Ultimately, the question of whether or not security leaders should ban or restrict the use of TikTok on company-owned devices is one that only they can answer. But given the growing number of government bans being proposed or enacted, at the very least, a thorough risk assessment is in order, coupled with a wider audit of corporate social media activity.
Continue reading here:
UK TikTok ban gives us all cause to consider social media security - ComputerWeekly.com
- Substack rival Ghost connects to the open social web with its latest public release - TechCrunch - August 6th, 2025 [August 6th, 2025]
- Character.AI is adding a social feed to its app - Yahoo Finance - August 6th, 2025 [August 6th, 2025]
- NCAA Urged To Take a Hint from Overwhelming Social Media Reaction to March Madness Tournament's 'No Expansion' Vote - Pro Football & Sports... - August 6th, 2025 [August 6th, 2025]
- Mikey Madison and Jeremy Allen White are in talks for The Social Network sequel - empireonline.com - August 6th, 2025 [August 6th, 2025]
- These social media stars conquered the internet. They still wanted more. - Yahoo Home - August 3rd, 2025 [August 3rd, 2025]
- Pope Leo warns against abuse of social media in speech to young pilgrims - Crux | Taking the Catholic Pulse - August 3rd, 2025 [August 3rd, 2025]
- Jeremy Strong Circling The Social Network Part II for Aaron Sorkin, Sony (Exclusive) - The Hollywood Reporter - August 3rd, 2025 [August 3rd, 2025]
- WATCH: Which teammate would you trust to run your social media? - Steelers.com - August 3rd, 2025 [August 3rd, 2025]
- Social media ads promoting small boat crossings to UK to be banned - The Guardian - August 3rd, 2025 [August 3rd, 2025]
- Jesse Eisenberg Weighed In on The Social Network Sequel Months Before Jeremy Strong Rumors - E! Online - August 3rd, 2025 [August 3rd, 2025]
- How will Australias under-16s social media ban be enforced, and which platforms will be exempt? - The Guardian - August 3rd, 2025 [August 3rd, 2025]
- As Australias teen social media ban looms, heres how the platforms are lobbying for an exemption - The Guardian - August 3rd, 2025 [August 3rd, 2025]
- Jeremy Strong Circling Mark Zuckerberg Role in The Social Network Part II - Yahoo Home - August 3rd, 2025 [August 3rd, 2025]
- Making Friends As an Adult Is Hard. These Friendship Apps Can Help - Cosmopolitan - August 3rd, 2025 [August 3rd, 2025]
- Jeremy Strong Front-Runner To Play Mark Zuckerberg In The Social Network Part II - Deadline - August 1st, 2025 [August 1st, 2025]
- Jeremy Strong eyed to play Mark Zuckerberg in The Social Network sequel - The Guardian - August 1st, 2025 [August 1st, 2025]
- Jeremy Strong Is the 'Top Choice' to Play Mark Zuckerberg In The Social Network Part II - Esquire - August 1st, 2025 [August 1st, 2025]
- Mikey Madison & Jeremy Allen White Top Choices To Star In Social Network Part II The Dish - Deadline - August 1st, 2025 [August 1st, 2025]
- The sequel to The Social Network may have just found its lead actors - TechCrunch - August 1st, 2025 [August 1st, 2025]
- YouTube to be part of Australia's youth social media ban - BBC - August 1st, 2025 [August 1st, 2025]
- Jeremy Strong Circling Mark Zuckerberg Role in The Social Network Part II - Variety - August 1st, 2025 [August 1st, 2025]
- HTX Launches Crypto Gifts Feature: Ushering In the On-Chain Social Networking Carnival with 180,000 USDT in - Bitcoinist.com - August 1st, 2025 [August 1st, 2025]
- Jeremy Strong Eyed to Take Over Mark Zuckerberg Role from Jesse Eisenberg in The Social Network Sequel - People.com - August 1st, 2025 [August 1st, 2025]
- The Social Network 2 Shocker: Jesse Eisenberg Not Returning As Mark Zuckerberg, Emmy Winner Eyed To Replace - Screen Rant - August 1st, 2025 [August 1st, 2025]
- One of the most intense method actors of his generation is reportedly the top choice to play Mark Zuckerberg in The Social Network 2 - GamesRadar+ - August 1st, 2025 [August 1st, 2025]
- Jeremy Strong in Talks to Play Mark Zuckerberg in THE SOCIAL NETWORK PART II - BroadwayWorld.com - August 1st, 2025 [August 1st, 2025]
- The Social Network 2 confirmed: Jeremy Strong, Mikey Madison, and more in talks to join cast - The Times of India - August 1st, 2025 [August 1st, 2025]
- The Social Network Sequel Is Recasting Jesse Eisenberg's Mark Zuckerberg (And We Know The Frontrunner) - SlashFilm - August 1st, 2025 [August 1st, 2025]
- Jeremy Strong, Mikey Madison, Jeremy Allen White reportedly in the mix for The Social Network Part II [UPDATED] - AV Club - August 1st, 2025 [August 1st, 2025]
- Mikey Madison, Jeremy White in talks for Sorkins The Social Network sequel - thedailystar.net - August 1st, 2025 [August 1st, 2025]
- Fans bewildered by actor 'set to replace' Jesse Eisenberg in The Social Network sequel - Metro.co.uk - August 1st, 2025 [August 1st, 2025]
- The Social Network 2 | Mikey Madison and Jeremy Allen White in talks to star in sequel - Film Stories - August 1st, 2025 [August 1st, 2025]
- Jeremy Strong in talks to play Mark Zuckerberg in The Social Network Part II - Mint - August 1st, 2025 [August 1st, 2025]
- Mikey Madison and Jeremy Allen White in contention for The Social Network sequel - Far Out Magazine - August 1st, 2025 [August 1st, 2025]
- HTX Launches Crypto Gifts Feature: Ushering In the On-Chain - GlobeNewswire - July 30th, 2025 [July 30th, 2025]
- Assessing the Impact of Australia's Social Media Ban on Tech Giants: Opportunities in Regulatory Resilience - AInvest - July 30th, 2025 [July 30th, 2025]
- What Would Social Media Look Like if it Was Made for Women? How Women are Navigating Social Media During the Second Trump Administration - Ms.... - July 30th, 2025 [July 30th, 2025]
- Should YouTube be included in Australias social media ban for kids under 16? We asked 5 experts - The Conversation - July 30th, 2025 [July 30th, 2025]
- New Networking Social Added to Kick Off Annual Industry Gathering - Swineweb.com - July 30th, 2025 [July 30th, 2025]
- YouTubes exemption reversed as Australia expands social media ban - Law Society Journal - July 30th, 2025 [July 30th, 2025]
- How will the teen social media ban work? Here's what we know - Australian Broadcasting Corporation - July 30th, 2025 [July 30th, 2025]
- Mental health warnings on social media? Minnesota will require them next year - NPR - July 28th, 2025 [July 28th, 2025]
- Imagen Network (IMAGE) Rolls Out XRP Infrastructure to Strengthen Scalable Social Curation - TradingView - July 28th, 2025 [July 28th, 2025]
- Italy Rules on Social Media and Employee Rights - SHRM - July 28th, 2025 [July 28th, 2025]
- Is Starlink down today? Thousands affected as the service faces network disruption, social media users rea - The Economic Times - July 28th, 2025 [July 28th, 2025]
- Meta to suspend political advertising in the EU as transparency law looms - Al Jazeera - July 28th, 2025 [July 28th, 2025]
- Maharashtra Government Issues Advisory on Social Media Use by Government Officers and Employees - The Live Nagpur - July 28th, 2025 [July 28th, 2025]
- On the Record | Colbie Caillat was discovered on MySpace before social media was what it is today - RFD-TV - July 27th, 2025 [July 27th, 2025]
- Voters Approve of Mayor Lurie, But What About His Social Media? - KQED - July 27th, 2025 [July 27th, 2025]
- Behind the Scam: How Fraudsters Use Social Media, Software, and Shell Companies to Steal Millions - Organized Crime and Corruption Reporting Project |... - July 27th, 2025 [July 27th, 2025]
- Social media addiction as the central mediating variable to explore the mechanism between physical exercise and sleep quality - Nature - July 27th, 2025 [July 27th, 2025]
- Minister apologises to generation of UK children exposed to toxic online content - The Guardian - July 27th, 2025 [July 27th, 2025]
- Can a country build its own social media? - bangkokpost.com - July 27th, 2025 [July 27th, 2025]
- Evidence supports the need to protect adolescents from social media harms - Public Health Communication Centre - July 27th, 2025 [July 27th, 2025]
- Children face two-hour social media cap in screen time overhaul - The Times - July 24th, 2025 [July 24th, 2025]
- An experimental online study on the impact of negative social media comments on anxiety and mood | Scientific Reports - Nature - July 24th, 2025 [July 24th, 2025]
- "Social media is just such a false perception of reality" - Caitlin Clark shares the secrets to staying grounded in the era of social media... - July 24th, 2025 [July 24th, 2025]
- Naver targets North America with Interest-based social platform 'ThingsBook' - digitimes - July 22nd, 2025 [July 22nd, 2025]
- Inside the social networks behind Irish myths and legends - RTE.ie - July 22nd, 2025 [July 22nd, 2025]
- Social balance in directed networks - Nature - July 22nd, 2025 [July 22nd, 2025]
- The Chicago Sky are trying to protect their players on social media. Here's what that means - ABC News - July 20th, 2025 [July 20th, 2025]
- Beyond missing pets and packages: How Nextdoor plans to reshape its social network - The Spokesman-Review - July 20th, 2025 [July 20th, 2025]
- Jack Dorsey backs an open-source development collective with $10 million - Engadget - July 20th, 2025 [July 20th, 2025]
- From scraps to silence: The untold story of Orkut's meteoric rise and quiet exit - Storyboard18 - July 20th, 2025 [July 20th, 2025]
- Meta agrees to hand over data of child porn channel operators - The Witness | Your compass in the community - July 20th, 2025 [July 20th, 2025]
- Uni students warned about promoting overseas gambling websites on social media - RNZ - July 20th, 2025 [July 20th, 2025]
- UAE: Woman ordered to pay Dh30,000 for insulting another woman on social media - Khaleej Times - July 20th, 2025 [July 20th, 2025]
- This is how people in 2025 are getting their news - The World Economic Forum - July 18th, 2025 [July 18th, 2025]
- Why a VC is betting AI is 'the opposite of social media' and will forge more human connections - Business Insider - July 18th, 2025 [July 18th, 2025]
- Coinbase unveils Base App, rebrands wallet as all-in-one social and trading platform - The Block - July 18th, 2025 [July 18th, 2025]
- "I'm confused at the delusion we're having in social media" - Gilbert Arenas says people on social media would hate on prime Kobe Bryant -... - July 18th, 2025 [July 18th, 2025]
- Jack Dorsey Pledges $10Mn to and Other Stuff Collective for OpenSource Decentralised Social Media - outlookbusiness.com - July 18th, 2025 [July 18th, 2025]
- With social networking, payment, and AI all included, will Base APP become Alipay on the chain? - PANews - July 18th, 2025 [July 18th, 2025]
- "Kendrick Perkins deleted his TwitterI think that should be on my resume" - Blake Griffin links Perks social media deactivation to his... - July 18th, 2025 [July 18th, 2025]
- Imagen Network Uses RLUSD to Improve Multichain AI Utility in Personalized Social Apps - Newsfile - July 18th, 2025 [July 18th, 2025]
- "There was nothing like it" - Jim Jackson recalls the insane popularity of the Bulls in the 90s and how social media ruined the NBA today -... - July 18th, 2025 [July 18th, 2025]
- Beyond missing pets and packages: How Nextdoor plans to reshape its social network - Los Angeles Times - July 16th, 2025 [July 16th, 2025]
- Social networking service Nextdoor relaunches with news, alerts - Tech in Asia - July 16th, 2025 [July 16th, 2025]
- Nextdoor Relaunches Network With a Focus on News, Alerts and AI - Bloomberg.com - July 16th, 2025 [July 16th, 2025]
- Londons Best New Social & Networking Clubs, From Art To Wine - Country and Town House - July 16th, 2025 [July 16th, 2025]