Keylogging Controversy Brings TikTok Back Under US Government Scrutiny
Image from Shutterstock

Keylogging Controversy Brings TikTok Back Under US Government Scrutiny

TikTok, the social app that’s so popular that some are using it as a search engine at this point, remains as vital destination as ever for Pink Sauce connoisseurs. Still, the company’s PR headaches continued this week.

Independent research performed by developer Felix Krause found code injected by the social network’s operating system enabling it to monitor all keyboard inputs and tags, even without hitting “submit,” a process known as “keylogging.”


As Krause explained on his blog, this could potentially include recording sensitive information such as passwords and credit card numbers. And because TikTok comes with an internal browser, this functionally gives the app the ability to monitor its users as they browse around third-party websites and services.

TikTok’s certainly not alone in checking out all of your data as you type. A previous post by Krause focused on tracking code within Meta’s Facebook and Instagram iOS apps, allowing them to potentially follow users within in-app browsers as well. A recent survey of the top 100,000 most popular websites found that 1,844 logged an EU user’s email address without their consent, and 2,950 recorded a U.S. user’s email data in some form. The keylogging protocol has also been used as a way for employers to monitor the activity of remote employees.

Though it certainly sounds sinister, keylogging is not necessary by definition malicious. TikTok claims that the code in question is used for “debugging, troubleshooting, and performance monitoring,” and in a statement, a representative denied that the company even collects specific keystroke or text input data. (The company also pointed out similar code in GitHub that’s used for an alternative purpose than keylogging, as a third party example.)

Still, the very mention of privacy concerns and TikTok in the same sentence is enough to raise some eyebrows in the U.S., where the app–which is owned by the Chinese parent company ByteDance–has always operated under a dark cloud of suspicion. Allegations in 2019 that the app was hoovering up data from underage users and censoring content on behalf of China’s ruling Communist Party led to calls for investigations from high-profile politicians. In December of that year, just as TikTok was taking over as the world’s most downloaded app, the U.S. Department of Defense was recommending that all military personnel delete it from their phones.

In 2020, President Trump signed a series of executive orders banning U.S. companies from doing business with TikTok (as well as the Chinese-owned WeChat app). These orders were later reversed by the Biden administration, which nonetheless urged Americans handling sensitive information to consider the apps a “heightened risk.”

The House of Representatives’ Chief Administrative Officer (CAO) echoed these concerns just this week following the keylogging report, issuing a “cyber advisory” about security on TikTok, noting that, despite its Culver City headquarters, it’s still “a Chinese-owned company.”

So even a U.S. government that was initially inclined to be more TikTok friendly may be having second thoughts.

Exclusive: Meg Whitman Talks Quibi, L.A.'s Tech Scene, and Hollywood's Renaissance

Quibi launched this week into a world turned upside down by the novel coronavirus. How do things look on day two? dot.LA caught up with Chief Executive Officer Meg Whitman – former boss of eBay and Hewlett-Packard, and one-time California gubernatorial candidate – to discuss.

Whitman shares her reaction to the initial flow of real-time data on Quibi users, what she'll be watching closely over the next few months, and what the well-heeled company's future may hold. She also forecasts how the streaming wars may play out, reflects on lessons learned about the tech world, and reveals her thoughts on the burgeoning innovation ecosystem in Los Angeles.

Read moreShow less
Sam Blake

Sam primarily covers entertainment and media for dot.LA. Previously he was Marjorie Deane Fellow at The Economist, where he wrote for the business and finance sections of the print edition. He has also worked at the XPRIZE Foundation, U.S. Government Accountability Office, KCRW, and MLB Advanced Media (now Disney Streaming Services). He holds an MBA from UCLA Anderson, an MPP from UCLA Luskin and a BA in History from University of Michigan. Email him at samblake@dot.LA and find him on Twitter @hisamblake

https://twitter.com/hisamblake
samblake@dot.la
🛡️Meet the Defense Unicorn That Just Raised $250M to Stop Drone Swarms

🔦 Spotlight

Hello, Happy Friday!

For this week's spotlight story, we're turning our attention to a monumental leap in defense technology achieved by Epirus, a dynamic startup based in Torrance that specializes in groundbreaking anti-drone systems. Recently, Epirus successfully secured a whopping $250 million in Series D funding, raising its total capital to over $550 million and solidifying its status as a unicorn in the defense tech sector.

Read moreShow less
RELATEDTRENDING
LA TECH JOBS
interchangeLA