Amazon Makes Employees Delete TikTok From Phones, Citing Security Risk [Update] (nytimes.com) 64
Amazon has asked its employees to delete the Chinese-owned video app TikTok from their cellphones, citing "security risks," according to a company email sent on Friday. From a report: In the email, which was obtained by The New York Times, Amazon officials said that employees must delete the app from any devices that "access Amazon email." Employees had to remove the app by Friday to remain able to obtain mobile access to their Amazon email, the note said. Amazon workers are still allowed to view TikTok from their laptop browser, the company added. Amazon and TikTok did not immediately respond to requests for comment. TikTok, which has been popular with young audiences in the United States, is owned by the Chinese tech company ByteDance. It has been under scrutiny in Washington for security reasons because of its ownership. Mike Pompeo, the Secretary of State, said on Monday that the Trump administration was considering blocking some Chinese apps, which he has called a threat to national security. Updated at 21:01GMT: In a statement, Amazon said the email was sent by accident. "This morning's email to some of our employees was sent in error. There is no change to our policies right now with regard to TikTok."
Makes perfect sense (Score:5, Interesting)
Re: (Score:2)
Is there any evidence that it is Chinese spyware? That is my real question. We get people saying TicTok BAD CHINESE COMPANY!!!! But what are the actual security problems found.
Re: Makes perfect sense (Score:2)
Apps are sandboxed
History is Evidence. (Score:5, Informative)
China is not some poor, misunderstood country. It is a Communist Dictatorship.
Every business exists by leave of the communist government.
Any company that can potentially provide information useful to the goals of the communist state will be required to do so.
Any security risks you can imagine in TikTok or any other Chinese software has certainly been imagined by the Communist Government also and likely leveraged to gather information, however mundane.
Re: (Score:2, Insightful)
Re: (Score:3)
Re: (Score:2)
If they used a court, it probably wasn't illegal.
Re: (Score:2)
Re: (Score:2)
Get TikTok, make videos. I don't give a fuck what you do.
Re:History is Evidence. (Score:4)
How is this different from say US govt? What kind of dictatorship is US of A?
In China, the government owns the corporations. In the USA, the corporations own the government. Therefore it's not a dictatorship but an oligarchy.
Re: (Score:1)
Very true. I would argue that both are a form of fascism in the classical definition of the word (Mussolini, WW2 style)
Re: (Score:2)
When the taxpayers are forced to hand over their money to corporations to the tune of hundreds of billions of dollars each year and are repeatedly told they have to bail out multi-billion dollar corporations, yes, that is fascism.
Re: (Score:3)
While that is compatible with fascism, it is not diagnostic. Fascism is more about flows of control than flows of money. IIRC (it's been awhile) for fascism money is merely a detail of implementation.
Re: (Score:3)
In China, the government owns the corporations. In the USA, the corporations own the government.
Sounds like the new take of the phrase, "Under capitalism, man exploits man. Communism it is the other way around."
Re: (Score:2)
Re: (Score:3)
Actually and IIUC, China is also an oligarchy. In China the oligarchy just functions through their control of the CCP (and thus of the government).
Re: (Score:2)
"TikTok is led by an American CEO, with hundreds of employees and key leaders across safety, security, product, and public policy here in the U.S. We have no higher priority than promoting a safe and secure app experience for our users. We have never provided user data to the Chinese government, nor would we do so if asked."
Re: (Score:2)
That doesn't answer the question of what are problems with Tic-Tok
Even the worse countries on earth often had a duality with them. They may want to spy on the United States, but they also want to sell their goods and services to us. It would be like I will not buy Food because it was grown by farmers and farmers for the Most part are Conservatives, and Conservatives hate all people who live in Blue States, so my food is likely poisoned.
Re: (Score:2)
Re:Makes perfect sense (Score:5, Informative)
But what are the actual security problems found.
A person from Reddit who does hum-drum reverse engineering on apps reported on TikTok once back in 2019. Typically person on Reddit is usually saying something like "Oh looks like Twitter is updating their REST API" or "Oh look Facebook is changing the optimization on libpng" or usually some really cut and dry level stuff like that. So the person's posts are about as exciting as a Calculus lecture on any given day.
However, they reversed engineered as much as TikTok as they could and what was found was highly questionable. You can see a lot of that here [twitter.com]. So when the person was like "you all should not be using this app" that was definitely eyebrow rising. Especially considering the most alarming thing usually coming from the person is "Oh no! Their cert is about to expire!"
Re: (Score:3)
There's also the problem of recertifying updates. Even if you know the current version is safe, an updated version may not be. So it's a threat under the control of someone who is not trustworthy. (Yeah, that describes a lot of software. I usually block javascript.)
So. That may not justify legal intervention by the courts, but it's quite sufficient for a company to decide "We don't want that app accessing our system.".
OTOH, if you're willing to run MSWindows, I can't see why you'd have problems with Ti
Re: (Score:2)
Re: (Score:2)
TikTok was on a list we had a few days ago of apps that read the clipboard for no good reason.
Re: (Score:2)
Amazon gives threat credibility to me. (Score:5, Insightful)
Tiktok has become a political football, some saying it is anti-republican, now young'uns are using TikTok in order to retaliate against President Trumps call for banning the app. https://time.com/5865261/tikto... [time.com]
You may be right, but the fact that a large private company is enforcing this among their employees makes me think there are credible risks. Jeff Bezos is not known for doing things against his interests to appease Trump. I still don't know why TikTok is bad, but seeing private companies who employ lots of security experts place such severe restrictions makes me think there is at least something to be concerned about.
Re: (Score:2)
A large private company who has a primary income stream from capturing and selling personal data is worried about... competition. If you have a "smart" phone or use Amazon or Google or Facebook, you have nothing to worry about. Your data is already being captured and sold to the highest bidder, anyway. Why would you care if the Chinese government have it if litera
Re: (Score:2)
You have the choice between US spyware and Chinese spyware, so which to pick is a matter of preference.
Though what most people seem to completely miss is that this isn't so much about spyware and censorship, but rather who spies and who censors.
You want to make jokes that are really funny yet have these past few years been impossible to make? Use TikTok.
Want to repeat what every professor teaches, every late-night host jokes about, every politician espouses, every multi-national corporation stands behinds?.
National security? (Score:3, Funny)
Is the Chinese military going to recruit 14 year old American children? Their goal is to weaponize memes, memes so dank that they can KILL.
Re: (Score:2)
Perhaps it is part of some Propaganda, to show how Stupid Americans are.
Because you know 14 year olds in other parts of the world are so much wiser and don't do silly dances.
Re: (Score:2)
We make a pretty penny exporting those silly dances you know.
Re: (Score:3)
Their goal is to weaponize memes, memes so dank that they can KILL.
All I can think of is this [youtube.com].
Re: (Score:2)
Yes. They are. Already have. Just watch videos of the BLM riots, and you'll see.
Re: (Score:2)
South Park did it
"Try to bomb harbor! Ready? Go! Defeat American Imperialism!"
Does Amazon supply employee's with phones? (Score:3)
Re: (Score:2)
You beat me to it, that was my first thought exactly.
Re:Does Amazon supply employee's with phones? (Score:5, Insightful)
Re: (Score:1)
Put a . after the .com in the URL. You're welcome.
Re: (Score:2)
It said in the article it asked them to remove it, but they must do so to retain access to mobile company email.
So, I can keep my freedom of choice and not be expected to be chained to the company communications system on my own time? Apart from the spywire-laden app thing, I don't see a lot of downside.
Re: (Score:2)
In my company, supposedly for "security purposes", if you install their email app and other doc access apps YOU MUST accept their management system on your phone, even if personal, which can track usage and remote wipe if need be.
They do offer a company provided phone otherwise.
Ironically I can access the email via the web browser so I didn't bother.
Re:Does Amazon supply employee's with phones? (Score:4, Informative)
I always opt for company supplied phone, just so I can turn if off when I am not at work.
Re: (Score:2)
Re: (Score:1)
It can depend. If the only access granted is to be able to wipe company data, then that isn't too bad. However, it's more likely that it is a case of "we reserve the right to poke through, copy, delete or otherwise interfere with any of your stuff", in which case I reserve the right to tell them to go fuck themselves.
Re: (Score:2)
How are you going to know what the capabilities are before they use them to wipe your phone?
I've got a huge amount of resistance to installing ANY apps on my phone, and all I use it for is a phone and an alarm clock. If I had anything vital on it...well, it would be a lot more stripped down than the supplied software is. And possibly I'd have a virtual machine jail to run any required software that I needed to install. (They do have those for phones don't they? I haven't gone looking.)
Re: (Score:2)
Your device is MDM managed then. Android/iOS managed devices have OS policies that allow them to configure their email and doc apps to prevent "data leakage" from those apps to "unmanaged" apps that you download yourself, like TikTok.
Access to OWA email throught the browser can be managed and even VPN tunneled with their MDM.
It is possible I'm boring you. :)
Re: (Score:2)
Yeah, this is begging for a lawsuit if they're not providing the devices.
Just tell them to leave it in their locker.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
If it's MDM managed, depending on how the device is registered (company owned, employee owned) dictates how much the employer can restrict on the phone. Company apps and data are containerized separately from the user's personal apps and data. Compliance policies can be put into place on employee owned devices that say "if we notice you have TikTok installed, we're shutting off access to company email" and things like that.
However, considering how Jeff Bezos himself got his phone compromised by WhatsApp a
People actually USE TikTok after what we know? (Score:3)
Re: (Score:2)
To be fair there is no proof that what he said is true. A lot of it are conjectures. They could be true, they could be wrong.
Re: (Score:2)
Re: (Score:3)
TikTok is a data collection service that is thinly-veiled as a social network. If there is an API to get information on you, your contacts, or your device... well, they're using it.
* Phone hardware (cpu type, number of course, hardware ids, screen dimensions, dpi, memory usage, disk space, etc)
* Other apps you have installed (I've even seen some I've deleted show up in their analytics payload - maybe using as cached value?)
* Everything network-related (ip, local ip, router mac, your mac, wifi access point name)
* Whether or not you're rooted/jailbroken
* Some variants of the app had GPS pinging enabled at the time, roughly once every 30 seconds - this is enabled by default if you ever location-tag a post IIRC
* They set up a local proxy server on your device for "transcoding media", but that can be abused very easily as it has zero authentication
And a new subreddit: Reversing and documenting all things TikTok [reddit.com]
Gotta delete the TikTok app from your phone (Score:2)
It must be stressful to be China (Score:2)
China runs a firewall and spies on people... This must be some effort for them to keep this up. Just imagine what they could do if they used their men power for something good.
But what do I really know?! Perhaps when one is a powerful communist then paranoia feels better than happiness!
Yet... (Score:2)
Re: (Score:2)
A valid point. There's also no reason to trust Amazon. For some people they make an informal cost/benefit analysis and decide in favor of Amazon. I may think they're wrong, but I don't know the weights they put on things. (Of course I *suspect* that they're just denying things that would be inconvenient to believe, but I don't *know* that's what's going on.)
Sounds like an app store bug (Score:1)
Which is it? "Ask" or "Make"? (Score:2)
Jeez, folks. If you're going to tell us something that isn't true, could you at least be consistent?
This one, maybe two, misstatements does get old.