Governors' TikTok bans make sense, cybersecurity experts say

Photo by LOIC VENANCE/AFP via Getty Images

 

Connecting state and local government leaders

TikTok's connection to Chinese government and the app's ability to closely track user data makes the social media platform a genuine cybersecurity concern, experts say.

At least 18 states, all led by Republican governors, have banned staffers’ use on government devices of the social media app TikTok over concerns about the possible security risks posed by the Chinese-owned company. They say the app can be used to collect data from users’ devices, which the Chinese government could then access.

Some states have gone even further, banning apps and products such as WeChat, QQWallet and AliPay from other Chinese companies.

In Maryland, Republican Gov. Larry Hogan authorized his chief information security officer, Chip Stewart, to issue such an emergency directive. The directive prohibits state employees from using information technology products and platforms from four other Chinese companies and one Russian one. Agencies must remove the products from state networks and stop using them.

“A lot of states issued executive orders, saying, ‘We’re banning TikTok.’ That’s great for today,” Stewart said. “But tomorrow, what if you have a new product you want to ban? Are they going to issue an executive order for each one?”

The governors of least three other states — Georgia, New Hampshire and Virginia — also have gone beyond TikTok to ban WeChat and other apps and products from various Chinese companies.

Over the past few weeks, governor after governor has announced a TikTok ban for state employees, but none so far has been a Democrat.

However, action at the federal level has been bipartisan. Last week, the U.S. Senate unanimously passed a bill that would prohibit federal employees from using TikTok on government-owned devices. U.S. House Speaker Nancy Pelosi, a California Democrat, has said she supports such a restriction, as does House Minority Leader Kevin McCarthy, a California Republican.

Florida Republican U.S. Sen. Marco Rubio wants to go even further. He has introduced a measure, which has a bipartisan companion bill in the House, that would ban TikTok from operating in the United States, along with any other social media company in or under the influence of China, Russia and several other “countries of concern.”

Then-President Donald Trump tried in 2020 to ban TikTok from U.S. app stores, citing security concerns, but that effort was blocked by a federal judge.

This November, FBI Director Christopher Wray testified at a congressional hearing that his agency is “extremely concerned” about TikTok’s operations in the United States. He said the Chinese government could use it to collect data on users and control the app’s algorithm to manipulate content and launch influence campaigns.

This month, Wray again warned about the possibility of TikTok user data getting into the hands of a Chinese government “that doesn’t share our values,” and said China could collect it for espionage.

Cybersecurity experts say the governors’ bans are a smart move.

“States oversee law enforcement, transportation, utilities. There is good reason for governors to be involved in this,” said Anton Dahbura, executive director of Johns Hopkins Information Security Institute, a cybersecurity academic and research center. “It’s not just the obvious security that someone could bring down the power grid. It’s infiltration of systems to obtain confidential information that is quite valuable to foreign actors.”

TikTok, which allows users to create and share videos on any topic, has more than a billion users worldwide and more than 100 million in the United States. The state bans would not apply to employees’ personal devices, as long as they aren’t connected to state networks.

A TikTok spokesperson said the accusations against the company are false and that the Chinese government is not involved in its operations.

“It is unfortunate that the many state agencies, offices, and universities on TikTok in those states will no longer be able to use it to build communities and connect with constituents," spokesperson Brooke Oberwetter said in an email to Stateline.

Indeed, several state agencies — including governor’s offices, tourism boards and state universities — use TikTok to reach new, especially younger audiences.

Several federal agencies already bar staffers from using TikTok on their government phones and devices, including the State Department, the Pentagon and the Transportation Security Agency. The White House also bars the app.

“Now that states are jumping into the fray, the hypothesis could be that they want to use this as brownie points, saying, ‘Listen, if you can’t get your act together in Washington, we’re going to do it on the state level,’” said Harry Broadman, a former member of the Committee on Foreign Investment in the United States, a federal interagency body that reviews national security impacts of foreign investments in the U.S.

In Maryland, Stewart said officials had been considering banning TikTok for several months, but that Wray’s public warnings “tipped the scale for us” and led to the prohibition.

In response to the concerns in the U.S. that American users’ information can being shared with the Chinese government, TikTok announced earlier this year that it had moved all the data to Oracle, a Silicon Valley company. But TikTok said it would still store backups of that information.

Oberwetter, the TikTok spokesperson, said that although the parent company was founded in China, TikTok has offices and operations around the world and is not a state-owned enterprise or otherwise controlled by the Chinese government.

But China has laws that require private companies to provide information to the government, according to Holden Triplett, co-founder of Trenchcoat Advisors, a risk advisory firm headquartered in Washington, D.C.

“Any company located in China can have the best of intentions, but it doesn’t matter. In the end, if the Chinese government wants to force them to comply, they must,” said Triplett, who formerly was an FBI special agent and director of counterintelligence for the National Security Council.

And while it’s true that other social media companies such as Twitter and Facebook also track users’ data, the experts say TikTok is different. Those companies are based in the U.S. and are using it to market products or sell data. Law enforcement typically must go through the courts to get access.

China doesn’t require that and could easily track data for the purpose of gathering information on Americans, they say.

“TikTok can access your camera and phone, the Wi-Fi connection, contacts, GPS, storage. It can read what you are doing and the things you’ve done.” said Brian Haugli, CEO of SideChannel, a cybersecurity company headquartered in Worcester, Massachusetts. “That thing can tell you where your eyeballs are looking.”

This article was first posted on Stateline, an initiative of The Pew Charitable Trusts.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.