Security

CSO

European Commission bans TikTok from staff gadgets

Cyber Europe cyber worried about cyber threats, doesn't cyber use the other C word (China)


The European Commission on Thursday banned the use of the TikTok short video app on corporate devices and on the personal devices of employees enrolled in the commission's mobile device management service.

The ban was enacted to enhance cyber security at the behest of the commission's Corporate Management Board, which oversees and coordinates management issues for the EU's executive arm.

"This measure aims to protect the commission against cybersecurity threats and actions which may be exploited for cyber-attacks against the corporate environment of the Commission," the EC said in a statement. "The security developments of other social media platforms will also be kept under constant review."

The commission's statement cites the need to protect staff from a rising number of cyber threats but fails to explain while TikTok was singled out.

The security developments of other social media platforms will also be kept under constant review

For the other government entities around the global that have disallowed TikTok for their respective employees or more broadly – India, Taiwan, at least 19 US State governments, including Maryland, South Carolina, and South Dakota, the US House of Representatives, and the US military, among others – the rationale for banning the social media app has been concern the software could facilitate remote spying on behalf of Chinese authorities.

TikTok is owned by ByteDance, a Chinese company based in Beijing and incorporated in the Cayman Islands. The ByteDance leadership team operates largely out of Singapore, and TikTok's parent is currently 65 percent owned by Western investment firms. 

Despite this ostensibly distributed corporate footprint, the assumption among Western governments is Beijing could demand access to the data TikTok collects outside the Middle Kingdom or could demand the alteration of TikTok source code to facilitate intelligence gathering. And due to the unchecked power of the Chinese Communist Party within China, it's unlikely any company based there could get away with refusing to cooperate. 

Given the extent of data gathering by the US and its allies and the ease with which technology products can be turned into surveillance devices – to say nothing of the decades trying to convince China to respect foreign intellectual property claims or the recent Trump-initiated trade war – it's hardly surprising there's not much trust between America and China. This mistrust in turn, occurring amid China's effort to assert itself as a global superpower, has led to efforts to exclude China from the technology supply chain and has fueled China's aspiration to achieve technological self-sufficiency. 

TikTok, caught in the middle of the emerging geopolitical divide, has made gestures to mitigate security concerns, such as turning to Oracle to host the data of US users. But executives with the app's parent company have failed to provide the answers that US lawmakers would like to hear. 

In a Senate hearing last September, TikTok chief operating officer Vanessa Pappas was asked by Senator Rob Portman (R-OH) whether she "will commit to cutting off all data and metadata flows to China, Chinese-based TikTok employees, ByteDance employees, or any other party located in China?"

Pappas declined to make that commitment, instead promising only that "our final agreement with the US government will satisfy all national security concerns."

TikTok's cause has not been helped by a recent report that ByteDance employees had tracked the locations of journalists who had published articles critical of the company.

TikTik did not respond to a request for comment about the European Commission ban, though on Wednesday the company published a rebuttal to a report from US-Australian cybersecurity firm Internet 2.0 that rated TikTok as the worst app in terms of data collection among 23 chat and social media apps tested.

In its response the developer challenged Internet 2.0's methods and conclusions.

"Their results contained a number of inaccuracies that should cast doubt on the validity of their findings," TikTok said, adding, "We take our responsibility to safeguard people's privacy and security seriously and devote considerable resources to achieve this goal."

If only reassurance were enough. ®

Send us news
23 Comments

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

The Russians are coming! Err, they've already infiltrated UK, US inboxes

Belgian man charged with smuggling sanctioned military tech to Russia and China

Indictments allege plot to shift FPGAs, accelerometers, and spycams

UK government denies China/Russia nuke plant hack claim

Report suggests Sellafield compromised since 2015, response seems worryingly ignorant of Stuxnet

Dump C++ and in Rust you should trust, Five Eyes agencies urge

Memory safety vulnerabilities need to be crushed with better code

China gamifies censorship and surveillance with national internet law quiz

I'm not a regular government, I'm a cool government

US lawmakers want blanket denial for sensitive tech export licenses to China

Committee worries licenses are being issued to boost and suit business, not national security

Proposed US surveillance regime would enlist more businesses

Expanded service provider definition could force cafes and hotels to spy for the feds

Polish train maker denies claims its software bricked rolling stock maintained by competitor

Says it was probably hacked, which isn't good news either

Today's 'China is misbehaving online' allegations come from Google, Meta

Zuck boots propagandists, Big G finds surge of action directed at Taiwan

EU lawmakers finalize cyber security rules that panicked open source devs

PLUS: Montana TikTok ban ruled unconstitutional; Dollar Tree employee data stolen; critical vulnerabilities

ByteDance slides around Indonesian social commerce ban with $1.5 billion buy

Takes huge stake in local superapp Tokopedia, for the good of the small business community

China's first undersea datacenter sinks – as planned

PLUS: India's landmark digital law delayed; Singaporean banks de-digitize some accounts; AUKUS to unleash AI