Get in the KNOW
on LA Startups & Tech
X
Image from Shutterstock
Keylogging Controversy Brings TikTok Back Under US Government Scrutiny
Lon Harris
Lon Harris is a contributor to dot.LA. His work has also appeared on ScreenJunkies, RottenTomatoes and Inside Streaming.
TikTok, the social app that’s so popular that some are using it as a search engine at this point, remains as vital destination as ever for Pink Sauce connoisseurs. Still, the company’s PR headaches continued this week.
Independent research performed by developer Felix Krause found code injected by the social network’s operating system enabling it to monitor all keyboard inputs and tags, even without hitting “submit,” a process known as “keylogging.”
As Krause explained on his blog, this could potentially include recording sensitive information such as passwords and credit card numbers. And because TikTok comes with an internal browser, this functionally gives the app the ability to monitor its users as they browse around third-party websites and services.
TikTok’s certainly not alone in checking out all of your data as you type. A previous post by Krause focused on tracking code within Meta’s Facebook and Instagram iOS apps, allowing them to potentially follow users within in-app browsers as well. A recent survey of the top 100,000 most popular websites found that 1,844 logged an EU user’s email address without their consent, and 2,950 recorded a U.S. user’s email data in some form. The keylogging protocol has also been used as a way for employers to monitor the activity of remote employees.
Though it certainly sounds sinister, keylogging is not necessary by definition malicious. TikTok claims that the code in question is used for “debugging, troubleshooting, and performance monitoring,” and in a statement, a representative denied that the company even collects specific keystroke or text input data. (The company also pointed out similar code in GitHub that’s used for an alternative purpose than keylogging, as a third party example.)
Still, the very mention of privacy concerns and TikTok in the same sentence is enough to raise some eyebrows in the U.S., where the app–which is owned by the Chinese parent company ByteDance–has always operated under a dark cloud of suspicion. Allegations in 2019 that the app was hoovering up data from underage users and censoring content on behalf of China’s ruling Communist Party led to calls for investigations from high-profile politicians. In December of that year, just as TikTok was taking over as the world’s most downloaded app, the U.S. Department of Defense was recommending that all military personnel delete it from their phones.
In 2020, President Trump signed a series of executive orders banning U.S. companies from doing business with TikTok (as well as the Chinese-owned WeChat app). These orders were later reversed by the Biden administration, which nonetheless urged Americans handling sensitive information to consider the apps a “heightened risk.”
The House of Representatives’ Chief Administrative Officer (CAO) echoed these concerns just this week following the keylogging report, issuing a “cyber advisory” about security on TikTok, noting that, despite its Culver City headquarters, it’s still “a Chinese-owned company.”
So even a U.S. government that was initially inclined to be more TikTok friendly may be having second thoughts.
From Your Site Articles
- TikTok Timeline: The Rise and Pause of a Social Video Giant - dot.LA ›
- Why Snap Wants To Implement an AI Powered Search Engine - dot.LA ›
Related Articles Around the Web
Lon Harris
Lon Harris is a contributor to dot.LA. His work has also appeared on ScreenJunkies, RottenTomatoes and Inside Streaming.
A Breakdown of the Data Snapchat Collects on Users
09:46 AM | November 14, 2022
Sebastian Miño-Bucheli
Santa Monica-based app developer Snap calls itself a camera company, but it’s really in the business of social media – and more specifically, advertising.
What Data Does Snapchat Collect?
Snapchat, their primary application, collects a myriad of data on its roughly 363 million daily active users, from basics like device information to detailed location tracking. "From day one, we’ve embraced data minimization, and believed that the best way to protect user privacy is to not store data at all, and if we do have to store it, to do so for a short and fixed period of time," Snap spokesman Pete Boogaard told dot.LA.
As such, like most tech companies’ privacy policies and terms of service, the verbiage is intentionally vague or full of legalese designed to make the user gloss over and click “agree.” But Snapchat does have to provide its users some details of how it collects, stores, and uses the data it gains from interacting with the app.
Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, told dot.LA that the common phrase, “necessary to provide service,” is particularly concerning.
“These are very vague ways to basically give a green light to very permissive practices in terms of your data,” Budington explained. He pointed out the ambiguous nature of the word “necessary,” adding, “[tech companies] can deem all sorts of things necessary, [including] using your location at every moment to better tailor their services to your life.”
While Snapchat’s terms of service haven’t changed since last November, the company most recently updated its privacy policy on July 29. Let’s dive into the various types of data Snapchat collects, how it stores it (and for how long), and perhaps most importantly, how Snapchat says it’s used.
Why Does Snapchat Collect Your Location Data?
Snapchat is very invested in collecting users’ precise location data, if users allow it. Its Snap Maps feature launched in 2017 lets users opt-in to showing their Bitmoji avatar on a map corresponding to their location and also allows them to track other friends who have opted in. It’s not dissimilar to Apple’s FindMy app.
In the past, the feature has raised concerns for its ability to make it easier for bullies and stalkers to find targets. Snap Map location, however, isn’t public information. Snapchat says location on Snap Maps will disappear after 24 hours, or when a user deliberately goes into “ghost mode” to hide from friends – but that doesn’t mean the app still isn’t tracking their movements. The company noted that unless you opt-in to live location sharing, the Snap Map won’t update with your location when you’re not actively using it.
Boogaard told dot.LA that while many of Snapchat’s core features do require location tracking, “location-sharing is off by default for all users” and “Snapchatters have complete control over their location sharing.” Snapchat added that there is no option to share your location with any user you aren’t friends with and that users have to individually select friends to share their location with.
Snapchat clarified that it does use location data to provide its Geofilters – custom photo and video filters often themed around specific places or events – and show people what’s nearby (also useful for ad purposes).
“We don’t share personal data about the users of the Snapchat app with data analytics providers,” Boogaard said.
Snapchat employees can also allegedly access all this information, and more – in 2019 Motherboard reported on a tool called SnapLion that it claimed was abused by employees to “spy on users.” In response to the report, Boogaard told dot.LA, “Any perception that employees might be spying on our community is highly troubling, and wholly inaccurate." Boogaard added, "Protecting privacy is paramount at Snap. We keep very little user data, and we have robust policies and controls to limit internal access to the data we do have, including data within tools designed to support law enforcement. Unauthorized access of any kind is a clear violation of the company's standards of business conduct and, if detected, results in immediate termination."
How Does Snapchat Use Your Content?
Snapchat can see the snaps you send, who is receiving them, and how often you’re online, as well as the metadata in each image.
Snapchat’s Streak feature (which tracks how long you and friends have regularly been sending and opening each other’s content) is one reason why the app also collects data on how often you and your friends open messages or capture screenshots.
It also tracks and scans the content users upload to its Memories feature. This is to train its AI to recognize the content of user images. In its privacy policy Snapchat notes that “if there’s a dog in your photo, it may be searchable in Memories by the term ‘dog,’” as part of its goal to make image search more accessible.
Snap’s policy also dictates that any public content a user generates on Snapchat is also fair game for the company to share though it doesn’t say how it will share this content.
What Data Does Snapchat Collect From Accessing Your Camera?
Besides the typical use for taking pictures, Snapchat can also access information from Apple’s TrueDepth camera – the front-facing, high-powered cameras that Apple’s iPhone X uses to record Face ID and Memoji data.
Snapchat says it uses this data “to improve the quality of Lenses”—its filter and augmented reality feature. But it also said it doesn’t collect biometric information, much less store the data on its servers or give it to any third parties.
Still, that’s a practice that’s come under scrutiny recently. In August, Snap was sued, accused of violating Illinois’ Biometric Information Privacy Act by collecting and storing users’ biometric data without their consent. That $35 million case is expected to head to settlement next week, after a judge couldn’t rule in favor of either party. "Snap continues to vehemently deny that Lenses violate BIPA, which was designed to require notice and consent before collecting biometric information used to identify people," Boogaard told dot.LA.
How Does Snapchat Use Your Data?
Now that we know all the information Snapchat collects, what is the company doing with it?
The main use case is advertising. Snapchat has a myriad of advertisers on its platform and they are all eager to turn users into sales by showing them the most relevant ads. Ad pricing starts at a modest $5 per day, so theoretically anyone with a marketing budget and the right connections could use Snap’s tools to market to its growing audience of Gen Z and Millennials.
Snapchat promises advertisers “advanced targeting capabilities,” and the benefit of finding a target audience using its location, demographics, interest and device data.
But who’s getting this information? That’s where things get vague. Snapchat doesn’t have to tell users specifically which companies are getting access to their data. The company notes it may share information with service providers that it contracts for services like ad analytics or payments. The company also says it might share user information with “business partners that provide services and functionality” for Snapchat, but again, doesn’t elaborate any further.
Snapchat also says it will share information about users if it could help “detect and resolve any fraud or security concerns, comply with any investigations, legal processes or regulations and to investigate potential terms of service violations.”
Snapchat doesn’t have to tell users when it turns over this data, though. In fact, most apps don’t.
How Does Snapchat Store Your Data?
Snap’s Support site notes Snapchat servers are designed to delete all Snaps automatically after they’ve been viewed by every recipient; the app’s trademark fleeting quality. The servers will delete unopened Snaps between two people after 31 days, and unopened Snaps sent to a group chat after 7 days. Snaps sent to your story are wiped from the servers 24 hours after posting.
Snapchat also says that when you delete a Snap in chat, it deletes it from its servers and will “make our best attempt” to wipe it from your friends’ devices.
If you post a Snap to Memories, though, Snapchat’s servers will back them up forever – unless you delete them, in which case they’ll be erased ASAP.
So what’s the safest way to protect your personal information on Snapchat? Well, Budington recommends an easy fix: simply don’t use it. But for people who are determined to keep their account but want to access what Snapchat collects, there are ways to download your Snapchat data.
You can also opt-out of audience and activity-based ads and third-party ad networks. This will mean the ads on your Snapchat will be less relevant, but the trade-off is that the app will use less of your personal data for marketing purposes.Snap is an investor in dot.LA.
Correction: An earlier version of this article incorrectly described Snap Map's location tracking feature. The feature needs to be enabled first, and Snapchat offers the ability to turn off the feature in Map settings.
From Your Site Articles
- Snapchat Rolls Out Updates to Its AR Shopping Feature For Both Consumers and Brands ›
- How Social Media Companies Are Responding to the End of Roe V. Wade ›
- Top 10 TikTok Gadgets To Buy This Holiday Season - dot.LA ›
- Snap Announces 'My AI' Feature and We Have Concerns - dot.LA ›
- Snapchat Users Remain Controversial Over New 'My Ai' Feature - dot.LA ›
Related Articles Around the Web
Read moreShow less
Samson Amore
Samson Amore is a reporter for dot.LA. He holds a degree in journalism from Emerson College. Send tips or pitches to samsonamore@dot.la and find him on Twitter @Samsonamore.
https://twitter.com/samsonamore
samsonamore@dot.la
Big Wins: Dodgers Take the Title ⚾, ChatGPT Levels Up🚀
06:54 AM | November 01, 2024
🔦 Spotlight
Happy Friday, LA! It’s been a week of big wins, on and off the field. 🎉
⚾️ First up, let’s talk Dodgers. With a thrilling 7-6 comeback victory over the Yankees in Game 5, the Dodgers clinched their eighth World Series title, their first since 2020. The city is buzzing, and fans are ready to celebrate! A parade kicks off this morning at 11 a.m., starting at City Hall and winding down to Flower Street, with a ticketed celebration at Dodger Stadium for those wanting to keep the festivities going.
Image Source: Dodgers
💻 Meanwhile, in the tech, OpenAI just rolled out a game-changing update for ChatGPT. Plus and Enterprise users can now access real-time internet search, powered by Microsoft Bing, bringing ChatGPT's responses fully up-to-date. This means users can now ask about the latest news, hotspots, or recent LA startup announcements, and ChatGPT will pull in fresh, relevant answers directly from the web. Previously limited to information up to 2021, ChatGPT’s new browsing capabilities make it a valuable digital assistant for anyone needing real-time insights in fast-paced industries like tech and entertainment.
Image Source: ChatGPT
🔍 The real-time search feature also includes “Browse with Bing,” allowing ChatGPT to source information from multiple sites for detailed answers to complex questions. Whether you’re exploring the latest venture capital trends in LA or curious about the best local spots, ChatGPT’s new browsing power helps you stay ahead with the latest info. This leap forward in AI functionality makes ChatGPT even more versatile and powerful for everyone, from business owners to everyday users.
From the Dodgers’ World Series win to OpenAI’s latest ChatGPT update, there’s a lot to celebrate in LA this week. Here’s to champions, innovation, and a city that’s always pushing boundaries. 🌆✨
🤝 Venture Deals
LA Companies
- Final Boss Sour, a Los Angeles-based gaming-themed snack company specializing in healthier sour snacks, has raised a $3M Seed funding round led by Science Inc. to expand its product offerings and operational capabilities. - learn more
LA Venture Funds
- Smash Capital led a $50M Series B round for Read AI, a productivity-focused AI company, bringing its total funding to $81M. The company offers a platform that enhances meeting efficiency through features like note-taking, summarization, and transcription. Additionally, Read AI introduced "Read AI for Gmail," a free Chrome extension that integrates information from various applications, reducing the need to switch between apps. The funds will be used to increase the company's headcount in engineering, data science, and business teams. - learn more
- Distributed Global participated in a $25M funding round for Nillion, a company that provides decentralized privacy solutions designed to secure sensitive data using advanced technologies like secure multi-party computation. - learn more
- Alexandria Venture Investments and Tachyon Ventures participated in a $115M Series A funding round for Axonis Therapeutics, a Boston-based biotechnology company developing innovative medicines targeting KCC2, a key mediator of brain inhibition, to treat neurological disorders. - learn more
- Act One Ventures participated in a $5M Seed funding round for Latii, a construction materials supply chain startup, to enhance its platform that connects contractors with suppliers, aiming to streamline procurement processes and reduce costs in the construction industry. - learn more
- F4 Fund participated in a $3M Seed funding round for Final Boss Sour, a Los Angeles-based gaming-themed snack company specializing in healthier sour snacks. - learn more
- SmartGateVC participated in a pre-seed funding round for Ritual Dental, a company revolutionizing dental care by integrating advanced technology and microbiome science to provide personalized, preventive treatments. - learn more
Read moreShow less
RELATEDTRENDING
LA TECH JOBS