Some Thoughts on TikTok

TikTok is a video messaging app that was developed in the People’s Republic of China and is owned by ByteDance, another PRC company. The Wall Street Journal published a Q&A on the app last Tuesday.

I have some thoughts, too.

For background, here are some of the data that TikTok collects just because you’re using it.

…location data and your internet address, according to its privacy policy, and it tracks the type of device you are using to access its platform. It stores your browsing and search history as well as the content of messages you exchange with others on the app.

How to locate your device in the Net, where you’ve been virtually, and what you say in your correspondence. That’s just for starters.

If you opt in, TikTok says it can collect your phone and social-network contacts, your GPS position, and your personal information such as age and phone number along with any user-generated content you post, such as photos and videos. It can store payment information, too. TikTok also gets a sense of what makes you tick. It can track the videos you like, share, watch….

Your physical location, and all that personally identifying information. It exposes your contacts, too, without their having any opportunity to reject “opting in.”

Now, some of the rest of the story:

Why is the US concerned?
Beijing performing mass data collection on American citizens….
…a vast database of information that could be used for espionage…if TikTok’s user data could be obtained by the Chinese government, that would enhance any such efforts. “You can use [artificial intelligence tools] to sort through it and find an awful lot of data….”

And this:

A TikTok spokesman said that the Chinese government has never asked the company for user data and that it would refuse such a request. “TikTok has an American CEO and is owned by a private company that is backed by some of the best-known US investors[.]”

This is a disingenuous claim. What the PRC has or has not done in the past in this regard is wholly irrelevant to what it can do. The more important thing, too, is what it can do. Under a PRC 2017 national intelligence law, all PRC companies and people are required to comply with any and all intel community requests for intel-related information. What is intel-related is determined by the intel community. Under the just-passed Hong Kong national security law, the PRC government has arrogated to itself the authority to go after any entity or person it deems a national security threat—wherever that entity or person is located, under whatever sovereign nation jurisdiction that entity or person resides, in the world.

TikTok, owned by ByteDance, is as subject to those laws as is ByteDance.

Does TikTok share any information with ByteDance, its China-based parent?
TikTok stores its data on American users on servers in the US and Singapore, but its website says that information can be shared with ByteDance or other affiliates.

Not only can be shared, but will be. Nor will it matter what firewalls ByteDance might claim to have erected between it and its subordinate—limiting the number of employees who have access to user data and the scenarios where data access is enabled, for instance—the parent organization can tear them down at will. And can be expected to, as necessary, to satisfy information demands from the PRC’s intel community.

As for those “other affiliates”—some of them may well be within the PRC.

What happens to your data if you quit TikTok?
Users can ask TikTok to delete their data, and the company has said in its policy that it will respond in a manner consistent with applicable law upon verifying your identity.

Users are supposed to believe TikTok’s wide-eyed innocent claim to have complied, even though they have no means of independently verifying TikTok’s assertion. But the kicker is that manner consistent with applicable law caveat. Two of those applicable laws are the PRC’s security laws mentioned above.

This is not a bit of software that should appear anywhere on anyone’s device.

Distractions

Much is being made of the cybersecurity threat, the national security threat, that the People’s Republic of China’s Huawei represents. For instance, Senator Ben Sasse (R, NE) has said it’s good for the British government to be removing Huawei from the core of the British Internet.

Senator Mark Warner (D, VA):

Huawei has been and will continue to be a national security threat….

Senator Tom Cotton (R, AR) on the Brits’ initial decision to allow Huawei into their Internet infrastructure:

[t]he Chinese Communist Party (CCP) will now have a foothold to conduct pervasive espionage on British society.

But a question arises in my peabrain.

Huawei and ZTE, with their backdoors and outright spyware, have been remarkably easy to identify. Suppose they were intended to be seen. What are we missing in Xi’s left hand while we focus on the glitter in his right? Or more aptly, are we missing Xi’s dagger while we let ourselves be distracted by his épée?

Disingenuosity

Thy name is TikTok. India has banned TikTok along with a potful of other PRC apps on national security—cybersecurity—grounds. In response, TikTok’s CEO Kevin Mayer said that

Chinese authorities had never requested the data of their Indian users, and even if they had, the company wouldn’t comply.

Right.

“Never requested” is a cynically offered non sequitur. Not having been asked is entirely separate from never will be asked.

It’s more serious than that, though. The People’s Republic of China enacted a law in 2017 that requires all PRC-domiciled companies to comply with PRC intel community requests for information. Not “pretty please,” not “strongly encouraged.” It’s “stand and deliver, stand in violation of law.”

This past week, the PRC enacted an additional law, that while nominally aimed at Hong Kong, has the effect of fleshing out that 2017 law. This latest rule by law enactment tells the PRC government that it’s authorized to go outside the nation’s borders to enter other nations to arrest and bring to the PRC for trial those who violate or threaten PRC national security. Mayer’s pious claim that TikTok wouldn’t comply with such a request would be a clear violation—in PRC government eyes—and subject him and his staff to arrest and removal to the PRC.

Article 38 of that law specifically says this:

This Law shall apply to offences under this Law committed against the Hong Kong Special Administrative Region from outside the Region by a person who is not a permanent resident of the Region.

Beijing has long said that Hong Kong is critical to the PRC’s national security—and that’s the PRC’s rationale for this additional law. From that, any company not complying with an intel request, by threatening PRC security, offends against Hong Kong.

Mayer knows that. He’s not an ignorant or oblivious man.

Occupation by Remote Control

Details of the People’s Republic of China’s overt takeover of Hong Kong via its new “security” law have been released by the government organ Xinhua News Agency. The high points, summarized by OANN, are these:

  • Hong Kong must establish a “local” national security council to enforce legislation, headed by the city’s Chief Executive, Carrie Lam
    • to be supervised and guided by a new PRC commission specially created for the purpose
    • a PRC “adviser” will be a member of the council
  • New local police and prosecution units to be set up to investigate, enforce the new law
    • backed by PRC security and intelligence officers deployed to the new commission
  • Lam will have power to appoint judges to hear cases related to national security
    • bypasses existing judicial appointment procedures

Notice the supremacy of the PRC law over Hong Kong domestic law.

Notice, too, that those entities each have a Communist Party of China apparatchik embedded.

Errant Satrap

That’s how the European Union views Great Britain as the EU continues to demand that Great Britain accede to demands they wish to impose on a sovereign nation—solely to bring that subordinate polity to heel. Examples of the EU’s demands:

  • post-Brexit sovereignty to make Britain more competitive via deregulation, environmental rules or tax reform—these must not occur
  • UK’s ability to subsidize industries in line with EU state-aid regulations—this must be curtailed

The first must not be allowed explicitly because of that competition. The second may be bad business overall, but it’s a domestic matter.

And this, regarding tariffs:

new tariff schedule London published last month eliminated levies on some 2,000 goods, or 17% of goods in the schedule, and simplified tariffs on another 40%. Measured by value, 70% of Britain’s imports from other World Trade Organization members will now be tariff-free, compared to 52% under the EU-wide tariff schedule.

Here is the EU’s attempt to prevent British competition.

And the EU’s demands regarding fishing:

bind the UK permanently in EU fisheries rules governing where British and other fishermen can cast their nets. The UK instead wants the same level of sovereignty other coastal countries enjoy to negotiate fishing rights annually.

And that’s the rub: the EU continues to demand to reach into—deep into—British national sovereignty to impose EU governance imperatives on British domestic matters. The EU does not accept Great Britain’s sovereignty.

Every one of those demands individually are deal breakers, and their aggregate demonstrate the EU’s (continued) bad faith in its “negotiations.”

The Brits should walk away from Brussels today and stop wasting their time and effort on the EU’s sham. They have better and more pressing things to do with their resources than negotiating with those who will not.