The teens of america are uniting!

To end war? No

To solve world hunger? Nope

To stop congress from banning TikTok? Yep

After the spyware… (ahem) after the app supplied users with numbers to call, one teen threatened “I promise you do not ban TikTok. If you want a January 6th riot, that's what's going to happen. Don't do it”

…this, after giving their full name and address at the start of the call
(Via Politico)

And the calls keep coming

We’re about to see the wackiest uprising ever 🇺🇸

@flexghost

Strange how this is a 1:1 thing w/ Mark Meta also yet no one is up in arms about doing a Meta ban. >.<

"But, the hosting provider!" 😂

@infosec_jcp @flexghost

They are not the same thing. Facebook is bad too (and actually, a platform-neutral legal restriction based on behavior would be better, credit to @maynarkh for pointing it out), but TikTok is absolutely unique in the type of threat it poses:

  • The Chinese government treats communication networks as their personal hoovering-attachment for any data they might want. Companies are required by law to operate as an arm of Chinese intelligence, both in terms of giving information and in terms of manipulating what information people on their network are allowed to see.
  • It's not just your TikTok data. It's photos and files on your phone, your contacts, your messages, basically anything that the app with its too-permissive permissions can get its hands on, can potentially go up to Chinese intelligence.
  • TikTok is not structured like any other app. It has features like custom-downloading and running arbitrary binaries from its central server that honestly don't even make much sense except as spying apparatus (consistent with #1).
  • What China might do with this unprecedented level of access to everyone's phones is malevolent in a different way than, say, Facebook's access to everyone's data. Like Facebook they have the ability to e.g. influence an election, but they also have the ability to try to blackmail an individual to compromise them, or do for-real torture in the real world (say by tracking down a dissident via TikTok spying and then having one of their little Chinese-police-in-America units grab them).
  • Citations:

  • https://thehill.com/opinion/cybersecurity/532583-for-chinese-firms-theft-of-your-data-is-now-a-legal-requirement/
  • https://www.proofpoint.com/us/blog/threat-protection/understanding-information-tiktok-gathers-and-stores
  • https://www.currentware.com/blog/block-tiktok/
  • https://www.businessinsider.com/china-hong-kong-spy-agency-official-presence-national-security-laws-report-2020-6 https://www.npr.org/2023/04/17/1170571626/fbi-arrests-2-on-charges-tied-to-chinese-outpost-in-new-york-city
  • For Chinese firms, theft of your data is now a legal requirement

    Cooperating with Chinese firms means cooperating with the Communist Party and its predatory mining of data and other property.

    The Hill

    @mozz @flexghost @maynarkh

    I'll say it again. Same. 1:1. Arguments.

    Change the company name above to Meta in your arguments.

    Same. Arguments. ☑️✅✔️

    Meta is a #malware company masquerading as a Banner AD company. No more. Definitely Less due to Leadership issues.

    TikTok is run by a former Facebook Intern who is now CEO.

    So how's that project going again, Oracle Systems? What was that project name to localize this in TX data centers for TikTok? ✔️🦉📰🗞️

    (Edit: #ProjectTexas, by #OracleSystems, a former client, on #OracleCloud !) 😂

    This: https://www.washingtonpost.com/technology/2023/02/02/ticktok-transparency-center-opens/

    TikTok launches charm offensive amid calls to ban the app

    It's part of an effort to mount a public relations campaign to counter claims the app is a threat to U.S. national security.

    The Washington Post

    @infosec_jcp @flexghost @maynarkh

    Wat

    Where in Facebook's app can it download a custom binary to an individual user's computer and run it on behalf of Chinese state intelligence?

    @mozz @flexghost @maynarkh

    So you ARE familiar with App Stores & are ASKING for a BINARY side by SIDE Analysis for #infosec purposes of Meta & TikTok apps going back to their founding as a side by side analysis, openly, in public, audited by independent third parties in a double blind study about 'spying by intelligence'? Huh.

    (Edit: #OracleCloud !) 😂

    Maybe there is a ... bear 🐻 with me on this....PRC_ORACLECLOUD_RUNAS_PROJECT_TEXAS_ADMIN cmd? Nah.

    Spoilers. It's not gonna end the way you thought.

    🔮🔎♻️ 1:1 arguments ♻️🔍🔮

    @infosec_jcp

    @flexghost

    "Citation: Trust me bro 🔮"

    Obviously, the Facebook app has been analyzed by security researchers. It's a very common thread among their comments that they say, I've analyzed a bunch of social media apps and I've never seen anything like TikTok. Downloading a custom .zip to one particular user's phone and running binaries out of it is one good example. Offhand, it's hard to think of a purpose for that that isn't nefarious (the obvious possibility being to enable functionality for one particular person you want to spy on, while shielding that functionality from the community's ability to pick it apart in a security analysis like they'd be able to do if you sent it through the App Store to everybody.)

    Yes, the exact purpose of my citations was that for that among many other reasons, TikTok is absolutely exceptional in how malicious it is, with reference to the ecosystem of other social media phone apps, which (as you do correctly note) is already terrible.

    I'm not real interested in a continued back and forth about it. If you have citations other than "🔮" for what you're saying I'm happy to read them though.

    @mozz @flexghost @maynarkh

    I've been watching the malware company called Facebook for 20+ years. Don't call me bro.

    Learn about #ForcedMDM. #MITM. #SSM™. Simple #infosec things.

    Sure. I'll put that on my to do list. Educating you. The dbl communist tech 'bro'.😂

    But in the meantime you should ' do your own research ' . (☉。☉)!

    (Edit: Learn about https://Oracle.com , first. Second, learn about #OracleCloud )

    Going into a specific like HOW the targeting works is quite a path to discuss though. Go on. Perhaps you should just search my timeline here and on Twitter. I'll wait. (☉。☉)!

    Will the #Marktanic before or after you are done though? (゚ο゚人))

    @infosec_jcp

    @flexghost @maynarkh

    I've been watching the malware company called Facebook for 20+ years.

    Oh, I randomly missed this before, but on March 10 2004, Facebook was called "The Facebook," and had been available to Harvard students for 34 days. Were you an undergrad at Harvard at the time?

    @mozz @flexghost @maynarkh

    No but I was working for, at the 2003-2004 time I started watching, Sun Microsystems where The Facebook bought the property from Oracle Systems, Inc. in 2010.

    You see SUN stands for Standford University Networks. ✌️

    @infosec_jcp

    I am pizza toppings about this. Can you tell me a little more about which property The Facebook bought from Oracle Systems, Inc.?

    @mozz @flexghost @maynarkh

    Sure Potato. Exit 404 off the US-101.

    But will you take the A or the B route? ✌️😂

    Say, do you _actually_ like working for the Astro turf PR Firm Meta hired to smear TikTok or, nah? OracleCloud isn't.. some odd plot in your mind by *checking your notes* The PRC Intelligence Apparatus, or.. nah?

    Ah, something something Emoluments Clause...

    https://infosec.exchange/@will_bunch@bird.makeup/112072697351624269

    Infosec Exchange