TIKTOK
January 25, 2024: iPhone apps abuse iOS push notifications to collect user data by Bill Toulas for Bleeping Computer. Security firm Mysk found some apps that use a trick to run in the background. The apps further abuse things by spying on us while running in the background. The apps they called out were TikTok, Facebook, X (Twitter), LinkedIn, and Bing. The defense is to disable notifications for these apps. To do so: Settings -> Notifications -> select an app -> disable "Allow Notifications".
FYI: October 14, 2023. Our continued actions to protect the TikTok community during the Israel-Hamas war from TikTok.
March 2, 2023: TikTok spies on people much like Facebook does. We Found 28,000 Apps Sending TikTok Data. Banning the App Won't Help. by Thomas Germain for Gizmodo
--"Joe Biden gave federal agencies 30 days to remove TikTok from government devices earlier this week. Until now, most politicians intent on punishing TikTok have focused solely on banning the app itself, but ... federal agencies must also 'prohibit internet traffic from reaching the company.' That’s a lot more complicated than it sounds."
-- The article is wrong about this, for a competent techie this is not difficult at all. DNS makes it fairly easy, more on this below.
--"Gizmodo has learned that tens of thousands of apps ... use code that sends data to TikTok. Some 28,251 apps use TikTok’s software development kits, (SDKs), tools which integrates apps with TikTok’s systems - and send TikTok user data" Many websites also send data to TikTok.
USE THE WEBSITE, NOT THE MOBILE APP
The safest first step is to use the tiktok.com website without having an account.
- TikTok Browser Can Track Users' Keystrokes, According to New Research
by Paul Mozur, Ryan Mac and Chang Che for the New York Times (August 2022). Quoting: "The web browser used within the TikTok app can track every keystroke made by its users, according to new research ..."
- More on this from Felix Krause: iOS Privacy: Announcing InAppBrowser.com - see what JavaScript commands get injected through an in-app browser (August 2022).
- FBI director says he's 'extremely concerned' about China's ability to weaponize TikTok
by Suzanne Smalley for Cyberscoop (November 2022). Quoting: "Chinese companies are forced to 'basically do whatever the Chinese government wants to do in terms of sharing information or serving as a tool of the Chinese government ... APIs in TikTok could be harnessed by China to control software on millions of devices, meaning the Chinese government could conceivably technically compromise Americans' personal devices ... China could 'control data collection of millions of users or control the recommendation algorithm, which can be used for influence operations.'
"
- If you do use the website, do it in private browsing mode. Better still, use a Chromebook in Guest Mode.
CREATE AN ACCOUNT WITH MAXIMUM PRIVACY
- Instead of your regular/main email account, use one that is auto-forwarded and not used anywhere else. For more on this see, the page on multiple email addresses.
- Do not give TikTok your phone number, it is not needed to create an account.
- Do not put your real name in your profile
- Give you account a nickname that is not used anywhere else
SETTINGS FOR MAXIMUM PRIVACY
- Make your account Private so that you can approve who follows you: Settings and Privacy -> Privacy -> turn on Private Account
- Make it hard for people to find you: Settings and Privacy -> Privacy -> Suggest Your Account to Others -> Turn off the four toggles
- Hide the people that you follow: Settings and Privacy -> Privacy -> Safety section -> Following List -> Only Me
- Hide the videos you like: Settings and Privacy -> Privacy -> Safety section -> Liked Videos -> Only Me
- Ad Personalization: Settings and Privacy -> Privacy -> Ads Personalization -> Use of Off-TikTok Activity for Ad Targeting -> turn off
- Do not share your contacts/friends: Settings and Privacy -> Privacy -> Sync Contacts and Facebook Friends. In addition, both Android and iOS should let you block the app from being able to access your contacts.
PROTECTING KIDS
- October 2023: There is a Restricted Mode that blocks content with realistic violence, firearms and other such imagery. With the Israel Gaza war this became more important. When Restricted Mode is on, TikTok only shows content that it deems suitable for all audiences. That means videos with mild profanity are blocked and it may block too much. There is no perfect happy medium. You turn on Restricted Mode in the mobile app with:
tap your profile -> tap the horizontal lines in the upper right corner -> Tap Settings and privacy -> Content preferences -> Restricted Mode
You then set a passcode, so a child can not just turn Restricted Mode off.
- From TikTok: Restricted Mode. Topics: What is Restricted Mode on TikTok? How to manage Restricted Mode How does Restricted Mode work? What types of content aren't available under Restricted Mode?
- From TikTok: Age-restricted content on TikTok LIVE
- If parents and kids have their own TikTok accounts, then parents can use the Family Pairing
feature to restrict age-inappropriate content on their kids' accounts. They can also limit a childs' ability to search for content as well as enable the "Restricted Mode" discussed above. Parents can also filter out videos with words or hashtags they don’t want their kids to see.
From TikTok: What is Family Pairing?
BLOCKING TIKTOK DOMAINS
- If you can control DNS, then block not only tiktok.com and www.tiktok.com, but also block ads.tiktok.com and analytics.tiktok.com.
- If you can control DNS generically, then block these domains, as per Steve Gibson in his Security Now podcast
from March 7, 2023
*.tiktok.com
*.tiktok.org
*.tiktokv.com
*.tiktokcdn.com
*.musical.ly
*.p16-tiktokcdn-com.akamaized.net
*.TikTokcdn-com.akamaized.net
CORPORATE PERSONALITY
May 5, 2023: TikTok Tracked Users Who Watched Gay Content, Prompting Employee Complaints by Georgia Wells and Byron Tau for the Wall Street Journal. Quoting: "TikTok workers in the U.S., U.K. and Australia in 2020 and 2021 raised concerns about this practice to higher-level executives, saying they feared employees might share the data with outside parties, or that it could be used to blackmail users... " The company claims to have ended this dashboard in 2022.
Another article on the subject: TikTok had a 'list' of users who viewed LGBTQ posts - raising alarm as the company faces scrutiny over ties to China by Sindhu Sundar for Business Insider.
December 22, 2022. TikTok Spied On Forbes Journalists by Emily Baker-White for Forbes. The author covers TikTok. She was leaked information about the company from someone who works there. TikTok did not like what she wrote, so they set out to find her source. They spied on her location, and then, after another leak, they lied about doing this. One way they tracked the reporter's location was by her public IP address, so use a VPN when using TikTok. And, as the section below says, use their website rather than their app to limit the amount of spying they can do. Make sure that either the browser or the Operating System has no access to your location. That means, using a VPN from an Ethernet-connected device. If the device supports WiFi or GPS, turn them both off.
LINKS
- Screen time from TikTok. Undated. Topics: What is daily screen time on TikTok? About screen time breaks on TikTok What are sleep reminders on TikTok? How to manage sleep reminders About weekly screen time updates About screen time dashboard
- June 10, 2023: Why 16 Should Be the Minimum Age for Social Media by Julie Jargon for the Wall Street Journal. The age 16 is the opinion of Ms. Jargon, one formed after speaking to assorted experts. Quoting: "The same science that tells us kids under 16 shouldn’t operate motor vehicles also suggests they should probably stay off TikTok, Instagram and Snapchat."
The American Psychological Association recommends that parents have ongoing conversations with their children about the content they see on social media and that they limiting social media during certain hours so it does not interfere with their sleep and physical activity.
- May 2023: Health advisory on social media use in adolescence from the American Psychological Association. It has 10 recommendations.
- May 23, 2023: Surgeon General Issues New Advisory About Effects Social Media Use Has on Youth Mental Health. There are ample indicators that social media can pose a risk of harm to the mental health and well-being of children and adolescents.
- In March 2023, Shou Zi Chew, head of TikTok testified before the US Congress. Opinion on this: How TikTok failed to make the case for itself by Casey Newton. March 24, 2023. After a rocky appearance before Congress, the company has reason to reflect.
- September 29, 2022: How TikTok Tracks You Across the Web, Even If You Don’t Use the App by Thomas Germain for Consumer Reports. No date for when it was first written. Germain wrote a similar story which is discussed at the top of this page. The company uses some of the same techniques as Google, Meta, and other companies to collect personal data.
- July 2022: Turns Out TikTok Does Have an Alarming Level of Access to Your Phone by Asha Barbaschow. TikTok requests almost complete access to the contents of a phone while the app is in use. That data includes calendar, contact lists and photos.
- July 2022: Senators Ask FTC to Investigate TikTok for Deceptive Conduct Regarding Chinese Access to U.S. User Data by Raquel Leslie and Brian Liu for Lawfareblog.com
- January 2022: TikTok privacy settings to change now by Heather Kelly for the Washington Post. The social media app is all about your personal data, likes and habits. Here’s how to limit what it gathers about you. Focused on the mobile app, not the website.
- January 2021: TikTok Is Watching You - Even If You Don't Have an Account by Riccardo Coluccini for Vice. The reporter submitted a request under the GDPR, and was shocked to see what data the app had been recording. No defense offered. You can ask TikTok for the data it has on you. In the mobile app: Settings -> Privacy -> Download your Data.
- May 2021: A TikTok Quick Guide for Parents from Connect Safely (2 page PDF).
- Privacy and Security on TikTok from TikTok. Undated.