Showing posts with label data security. Show all posts
Showing posts with label data security. Show all posts

Sunday, February 2, 2020

TikTok: The Social App that Comes with a Pentagon Warning


If you’ve tuned out on yet another social media application that you’re never going to use, it’s time to take a look at TikTok. TikTok is used to create and share short-form videos. Owned by Beijing-based parent company ByteDance, it was launched in 2016 and has become wildly popular among users, including celebrities, with more than 1.3 billion downloads worldwide. 
TikTok’s popularity is fueled by the fear of missing out (FOMO) and what seems to be an insatiable desire to be seen, to have an audience, if only for a moment. TikTok promises that you can “watch endless videos customized specifically for you. A personalized video feed based on your preferences.” 
But incidents over the past year have caused privacy experts to question how data from TikTok is being collected and used, and whether it’s being censored by the Chinese government. 

There’s that data thing again

In TikTok’s case, you’re sharing data with the Chinese government, and that’s the problem. I just looked at the privacy policy, and right up front, I see that I’m volunteering: 
  • My age, username and password, language, and email and phone number.
  • If you choose to find other users through your social network contacts (which of course you will—that’s what social is all about), they will collect your public profile information, plus names and profiles of your social contacts.

There’s more, but you get the idea

As a consequence, in a December message to all military branches, the Pentagon said there was a “potential risk associated with using the TikTok app.” It advised employees to take precautions to safeguard personal information. US military branches now have banned TikTok on government-issued smartphones in an effort to secure and defend their networks.

Despite the ban, troops continue to use TikTok on their personal devices

According to cybersecurity experts, this poses many of the same security threats that were present when the app was being used on government phones. 
Spies could use video metadata to track the movements of US personnel, potentially exposing a secret mission or endangering the lives of deployed troops. Phone hacking could expose personal finances, relationships or sexting that makes them susceptible to blackmail. 

A loosely defined policy about social media usage

Policy is somewhat loose; it advises personnel not to do anything that disrespects the Army. As long as they’re not promoting products in uniform, they’re operating within the law. 

More education on TikTok’s risks

Michael Nowatkowski, an associate professor of cyber sciences at Augusta University and senior research fellow at the Army Cyber Institute believes TikTok poses a greater risks than other social-media companies because of ByteDance’s Chinese ownership. He didn’t believe the military had the resources to enforce an outright ban on personal devices. 
Instead, Nowatkowski believes the military should educate troops on the risks of downloading TikTok on their personal devices. To that point, all Department of Defense personnel take annual cyber-awareness training about the threats that social media can pose. It may or may not be enough.
That data thing just keeps popping up. For help with your social media strategy, talk with Top of Mind Marketing. We’re writers and content marketing experts.

Friday, June 7, 2019

Google Plus Calls It Quits After Data Breach


Google has finally thrown in the towel on Google Plus. No surprise here. Google launched their social media application in 2011 to compete with Facebook and it never really gained traction. By 2018, Google Plus was little more than an afterthought. But you really have to wonder why all those smart people at Google couldn’t make this work. They’re calling it quits after a data breach.

What were those circles all about anyway?

When Google Plus came out, we created accounts and gave it a try, but it wasn’t fun because, well, no one else was using it. No one really engaged. Apparently 90% of user sessions lasted fewer than five seconds. Compare that with addictive sessions on Facebook, Twitter or Instagram.

But there’s more to this story than just an application that no one wants to use

Google chose to sunset Google Plus over an issue with bigger implications. According to The New York Times, “security vulnerability exposed the private data of some 500,000 users.” Google didn’t tell us about the application’s security issue when it was discovered because it didn’t appear that anyone had gained access to user information, and the company’s Privacy & Data Protection Office decided it was not legally required to report it.

If you’re not paying attention, data security has become a very big deal

The decision to stay quiet raised eyebrows in the cybersecurity community, as it comes against the backdrop of relatively new and stricter rules in California and Europe that govern when a company must disclose a security episode.
Up to 438 applications made by other companies may have had access to the vulnerability through coding links. Outside developers could have seen user names, email addresses, information about occupation, gender and age. They apparently did not have access to phone numbers, messages, Google Plus posts or data from other Google accounts.

Google was concerned about damage control

Now, according to The Wall Street Journal, a memo prepared for senior executives by Google’s policy and legal teams warned that disclosing the problem would expose the company’s vulnerability and invite regulatory scrutiny. CEO Sundar Pichai would likely be called to testify before Congress in the same way that Facebook’s Mark Zuckerberg did after its security breach. Google had planned to announce the disclosures, but moved up the announcement date when it learned of The Journal’s article.
In May, Europe adopted new data protection laws that require companies to notify regulators of a potential leak of personal information within 72 hours. Google’s security issue occurred in March, before the new rules went into effect. And yes, this applies to Google—it’s a global company.

California is getting serious about information accountability

California’s strict new privacy law goes into effect in 2020. In the event of a data breach, consumers can sue for up to $750 for each violation. It also gives the attorney general the right to pursue companies for intentional privacy violations.
What’s next? A hearing about whether tech companies are filtering conservative voices in their products. The Republicans are going to be all over this one.