ByteDance used TikTok to track my location — and the locations of two of my colleagues — to try to find our sources. We reported on this back in October, but kept things vague to protect sources. Today ByteDance admitted it, so we can say much more:

https://www.forbes.com/sites/emilybaker-white/2022/12/22/tiktok-tracks-forbes-journalists-bytedance/

EXCLUSIVE: TikTok Spied On Forbes Journalists

ByteDance confirmed it used TikTok to monitor journalists’ physical location using their IP addresses, as first reported by Forbes in October.

Forbes
@ebakerwhite Wow, the depths these people go to is unbelievable ☹️ Good report and great to see more tech reporters on here 🙂

I've just deactivated my TikTok account.

@ebakerwhite

@ebakerwhite Given what's been found about TikTok it's not surprising but still shocking going from "I think they would" to "here is proof they are".
@ebakerwhite Well this is certainly a freaking mess. Okay, how does one totally disable TikTok off of an iPhone?
@smartfilming @ebakerwhite Thanks. Just deleted it. Thank you. I just hope that there’s nothing still lurking.
@John_G_R_Wilson @smartfilming @ebakerwhite I wouldn't trust it until I did a factory reset personally...
@ebakerwhite It is a reminder to be cautious with the apps we install on our phones. Especially those with strong ties to an authoritarian government pose more risks than most might realize. Now is the perfect time to go through your apps and see how much you really know about the people that have created them.
@almost @ebakerwhite An inconvenient but valuable reminder!

@ebakerwhite
"according to current and former employees, as well as internal materials reviewed by Forbes, Cloutier’s efforts to build out a robust security team were hamstrung by ByteDance’s Internal Audit and Risk Control department, which is led by Song Ye, an executive in Beijing."

Holy cats.

This is a Hell of a series of articles. My hat's off to you.

@ebakerwhite Does anyone actually believe Liang didn't authorize or at least know this was happening?

@ebakerwhite

“In this case individuals misused their authority to obtain access to TikTok user data.” —TikTok General Counsel

Right. So what are you, TikTok, doing now to ensure that this data is not there in future, to tempt other “individuals”?

Firing your staff doesn't do it. Merely by collecting the identifying data on people, it's inevitably going to be used against them. You need to stop collecting that #ToxicData in the first place. When do we hear that from you, TikTok?

@ebakerwhite I'm struck by this notion: in other instances, transnational mob turns to outside-surveillance dickheads like NSO group to track folk they don't like... in the case of TikTok the app *is* the spying
@ebakerwhite oh this seals it for me. The owners of tiktok can go down the drain.

@ebakerwhite

“We also have very strict access controls around the type of data that they can access and where that data is stored, which is here in the United States. And we’ve also said under no circumstances would we give that data to China.” - Vanessa Papas, Tikatok COO, in testimony before Congress, in September.
Wonder if she has been removed or resigned.

@ebakerwhite Not surprising at all. Maybe something to think about @taylorlorenz
@ebakerwhite Yikes! I'm curious, in your experience how seriously to tech reporters take cybersecurity? I.e. hardened phones, separate accounts, ect?

@ebakerwhite I don't understand why the Internal Audit and Risk Control team at Bytedance approved the surveillance campaign and so few people were terminated.

Who holds this internal Bytedance team responsible?

@0bondo7

"Who holds this internal Bytedance team responsible?"

@ebakerwhite "I'm shocked -- shocked I tell you -- to find there is illegal surveillance going on here."

Uh-huh.

Good work. Another reason to avoid TikTok altogether.

@ebakerwhite TikTok can do that? 👀 👁 😵 I have only done a few videos. I don't want them used for all that.

@ValkyrieKerry @ebakerwhite It's not about making videos, it's a result of having the app installed on your phone.

Disabling location services for the app would probably help a bit, but developers have lots of ways of backing out your location and other personal info once they have an app on your phone. And most users are bad about ignoring privilege-request popups.

General rule: Do not install apps on your phone unless you trust the developers/owners of that app.

@ebakerwhite Terrible. And also, sadly, not shocking. It seems TikTok isn’t just the name of the app; it’s also the ambient sound I imagine as I wait for that company’s inevitable privacy explosion.
@ebakerwhite
Great piece of journalism Emily.

@ebakerwhite I don't understand why location tracking is a surprise. It's right there on the App Store.

Aren't employers required to have data safeguards in place for technology? I presume Forbes provides you with a phone and computer for work use and limits what you can install on those devices.

By all means, blame China. But recognize that many younger people use TikTok as a news source, so taking away the app reduces the flow of information and exchange of ideas.

@ebakerwhite Social media needs to be regulated. Going after the way they use private data is likely the best approach. @Maddow @donieosullivan
@ebakerwhite Is this substantially different from what Uber did to some reporters?
@ebakerwhite thank you for sharing this, excellent reporting. It’s good to have a resource to point friends & family toward when fielding TikTok safety questions

@ebakerwhite Facial tracking and numberplate tracking, pnone tracking and payment card tracking. It does not take a genius to know that it is entirely possible for the government to know where we are each second of the day, who we are with and be able to listen in via our phones to what we are doing. This is the very sinister world that George Orwell wrote about and which seems to have come to pass. Edward Snowden also warned about the spying going on in every facet of people's lives.

It is of little surprise to find anybody any everybody can use the online tracking methods to find people.

@ebakerwhite yame as all the #PRISM collaborators aka. #GAFAM|s do.

Please take proper #consequences and don't put #Govware on your devices FFS!

@ebakerwhite Until reading your post, I had figured it was all Republican hype to shut down the Gen Z communicator. I think that’s still probably the main reason they’re against it, but your example is chilling.
@ebakerwhite Emily, do we know whether TikToc is encrypting user data and, if so, whether it's using global or Chinese encryption algorithms?

@ebakerwhite @nus the problem is deeply rooted, not with just a few bad players.

"This misbehavior is unacceptable, and not in line with our efforts across TikTok to earn the trust of our users."

Too late. The trust is lost already!

@ebakerwhite Doesn't google, snapchat, any app you grant location access to have the same capability? Why do Americans always have to have a boogieman?

I'm not a fan of his this is framed as "scary Chinese people have access to Americans' data...." The more correct lens IMO is that effectively unregulated (in China buy also in the US) corporate entities are teaching down journalists reporting on them. After all, a US company like Microsoft that operates on China had the same kind of potential access to foreign nationals' private data, and we should be equally concerned about that, but somehow (i.e., because of nationalism and white supremacy) we aren't.

This is not to deligitimize the point of the article that corporations shouldn't be spying on anyone, let alone journalists trying to cover them...

@ebakerwhite Proprietary software.
Stallman was predicting this for decades, and people called him paranoid.
@ebakerwhite Truly scary and mind-boggling how siloed groups within companies can go so off-track. Either way, companies dealing with personal info need to have their feet held to the fire, not just the bad actors within. This isn't the first, and won't be the last. Although, the national security concern here definitely hits differently
@ebakerwhite a backdoor purposefully installed, likely similar to how the us gov did with skype
@ebakerwhite this is why I have never signed up for Tik Tok nor opened a Tik Tik video.
@ebakerwhite the biggest reason I have never used that app and immediately delete it from any device I purchase.
@ebakerwhite Kind of surprised how shocked people seem to be by this. I mean seriously, what did you all expect a big tech company from an authoritarian country would be doing? There have been questions and warnings about them for years, but people still keep using the app.
@ebakerwhite kinda surprising tiktok Is still a thing in the us
@ebakerwhite government needs to wake up and ban the shit out of TikTok
@ebakerwhite Thank you for your reporting. I’m not very surprised by this (is anyone?) and think the more interesting question is: how does a journalistic institution like Forbes prepare for this? As someone who reports on sensible issues and works with sources - why do you use TikTok? How are you trained when it comes to cyber security and espionage? Chinese spies are not surprising (see eg https://www.goodreads.com/book/show/41857894-chinese-spies), do you talk about such issues?
Chinese Spies

In 1920s Shanghai, Zhou Enlai founded the first Chinese communist spy network, operating in the shadows against nationalists, Western pow...

@ebakerwhite

Why did you use it in the first place? It was obviously insecure.

@ebakerwhite I imagine it's very unsettling to have it confirmed, even if it's not entirely surprising. I'm sorry you've been targeted in this way. It's so creepy.

VicForests, a state-owned business in Victoria, Aust, hired a private detective to follow someone who (rightly) pointed out poor practices. They also created a "dossier" full of another critic's social media activity, just to spook them.

A government entity, in an ostensibly free society.

@ebakerwhite a good reason for everyone to deinstall if they use it. Wonder how far such abuse is used to locate soldiers in the Ukraine for example?
@ebakerwhite
Chit. They're going to ruin the fun stuff on TikTok, aren't they?
@ebakerwhite So, sounds like something Elmo will demand that coders must implement on the bird site tomorrow, if not yesterday?
@ebakerwhite The add trackers in the Forbes website block me from reading your story.
@ebakerwhite How Tiktok is not banned in US ? Learn from India may be ?