News
Should governments ban TikTok? Can they? A cybersecurity expert explains the risks the app poses and the challenges to blocking it
The U.S. House of Representatives voted 352-65 on March 13, 2024, to require TikTok’s parent company, China-based ByteDance, to sell the app or face a nationwide ban on TikTok. President Joe Biden said on March 8 that he would sign the legislation if it reached his desk.
The popular video social media app had 149 million users in the U.S. as of January 2024. Many of them contacted Congress to protest the possibility of a ban.
The bill’s fate in the Senate is unclear. It’s also unclear whether any resulting legislation would survive a court challenge.
On May 17, 2023, Montana Gov. Greg Gianforte signed legislation banning TikTok in the state, the first total ban by a U.S. state government. The law would impose fines of US$10,000 per day on any app store that offers TikTok and on the app-maker itself if it operates in the state. Individual users would not be subject to penalties. The law was scheduled to go into effect Jan. 1, 2024, but a federal judge blocked it pending a trial to determine whether the state overstepped its authority and whether the law violates the First Amendment.
The federal government, along with many state and foreign governments and some companies, has already banned TikTok on work-provided phones. This type of ban can be effective for protecting data related to government work.
But a full national ban of the app is another matter, which raises a number of questions: What data privacy risk does TikTok pose? What could the Chinese government do with data collected by the app? Is its content recommendation algorithm dangerous? Is it legal for a government to impose a total ban on the app? And is it even possible to ban an app?
Vacuuming up data
As a cybersecurity researcher, I’ve noted that every few years, a newly popular mobile app raises issues of security, privacy and data access.
Apps collect data for several reasons. Sometimes the data is used to improve the app for users. However, most apps collect data that the companies use in part to fund their operations. This revenue typically comes from targeting users with ads based on the data they collect. The questions this use of data raises are: Does the app need all this data? What does it do with the data? And how does it protect the data from others?
So what makes TikTok different from the likes of Pokemon-GO, Facebook or even your phone itself? TikTok’s privacy policy, which few people read, is a good place to start. Overall, the company is not particularly transparent about its practices. The document is too long to list here all the data it collects, which should be a warning.
There are a few items of interest in TikTok’s privacy policy besides the information you give them when you create an account – name, age, username, password, language, email, phone number, social media account information and profile image – that are concerning. This information includes location data, data from your clipboard, contact information, website tracking, plus all data you post and messages you send through the app. The company claims that current versions of the app do not collect GPS information from U.S. users.
If most apps collect data, why are governments worried about TikTok? First, they worry about the Chinese government accessing data from TikTok’s 150 million users in the U.S. There is also a concern about the algorithms used by TikTok to show content.
Data in the Chinese government’s hands
If the data does end up in the hands of the Chinese government, the question is how could it use the data to its benefit. The government could share it with other companies in China to help them profit, which is no different than U.S. companies sharing marketing data. The Chinese government is known for playing the long game, and data is power, so if it is collecting data, it could take years to learn how it benefits China.
One potential threat is the Chinese government using the data to spy on people, particularly people who have access to valuable information. The Justice Department is investigating TikTok’s parent company, ByteDance, for using the app to monitor U.S. journalists. The Chinese government has an extensive history of hacking U.S. government agencies and corporations, and much of that hacking has been facilitated by social engineering – the practice of using data about people to trick them into revealing more information.
The second issue that the U.S. government has raised is algorithm bias or algorithm manipulation. TikTok and most social media apps have algorithms designed to learn a user’s interests and then try to adjust the content so the user will continue to use the app. TikTok has not shared its algorithm, so it’s not clear how the app chooses a user’s content.
The algorithm could be biased in a way that influences a population to believe certain things. There are numerous allegations that TiKTok’s algorithm is biased and can reinforce negative thoughts among younger users, and be used to affect public opinion. It could be that the algorithm’s manipulative behavior is unintentional, but there is concern that the Chinese government has been using or could use the algorithm to influence people.
Can a government ban an app?
The pending Montana law aims to use fines to coerce companies into enforcing its ban. It’s not clear if companies will comply, and it’s unlikely that this would deter users from finding workarounds.
Meanwhile, if the federal government comes to the conclusion that TikTok should be banned, is it even possible to ban it for all of its 149 million existing U.S. users? Any such ban would likely start with blocking the distribution of the app through Apple’s and Google’s app stores. This might keep many users off the platform, but there are other ways to download and install apps for people who are determined to use them.
A more drastic method would be to force Apple and Google to change their phones to prevent TikTok from running. While I’m not a lawyer, I think this effort would fail due to legal challenges, which include First Amendment concerns. The bottom line is that an absolute ban will be tough to enforce.
There are also questions about how effective a ban would be even if it were possible. By some estimates, the Chinese government has already collected personal information on at least 80% of the U.S. population via various means. So a ban might limit the damage going forward to some degree, but the Chinese government has already collected a significant amount of data. The Chinese government – along with anyone else with money – also has access to the large market for personal data, which fuels calls for stronger data privacy rules.
Are you at risk?
So as an average user, should you worry? Again, it is unclear what data ByteDance is collecting and if it can harm an individual. I believe the most significant risks are to people in power, whether it is political power or within a company. Their data and information could be used to gain access to other data or potentially compromise the organizations they are associated with.
The aspect of TikTok I find most concerning is the algorithm that decides what videos users see and how it can affect vulnerable groups, particularly young people. Independent of a ban, families should have conversations about TikTok and other social media platforms and how they can be detrimental to mental health. These conversations should focus on how to determine if the app is leading you down an unhealthy path.
This is an updated version of an article originally published on March 23, 2023, and updated on May 18, 2023.
Doug Jacobson, Professor of Electrical and Computer Engineering, Iowa State University
This article is republished from The Conversation under a Creative Commons license. Read the original article.