[HN Gopher] TikTok Can Circumvent Apple & Google Privacy Protect...
       ___________________________________________________________________
        
       TikTok Can Circumvent Apple & Google Privacy Protections, Access
       Full User Data
        
       Author : hammock
       Score  : 25 points
       Date   : 2022-02-22 21:27 UTC (1 hours ago)
        
 (HTM) web link (www.yahoo.com)
 (TXT) w3m dump (www.yahoo.com)
        
       | olliej wrote:
       | Wow, that headline is clickbait nonsense, and the article make
       | numerous .
       | 
       | They do not have access to "all user data", that is blatantly
       | false, even in the article's own claims.
       | 
       | > "Once one advertiser has a device ID that's correlated, all
       | privacy is gone,"
       | 
       | What? That's only a single Ad network, and no one has the scope
       | of surveillance google has (and uses) except maybe Facebook.
       | 
       | Likewise, they do not have access to keychain data - they use
       | keychain sync to link a user across multiple devices (the whole
       | point of keychain sync is to sync data across multiple devices) -
       | keychain does not provide arbitrary access to any app, and even
       | if they had raw access to the local keychain db file[s] it's
       | encrypted. It's probably worth adding an easy way to remove an
       | app's keychain data (this would be an entirely UI feature).
       | 
       | The various device ID methods used are likewise the standard
       | scummy ad industry practices that all the "freemium" apps use,
       | and many of the ones you pay for as well.
       | 
       | It changes the way it behaves using javascript etc. Presumably
       | it's just another WebView app, so that kind of goes without
       | saying, and is again not unique to TikTok.
       | 
       | "On the Apple app, the studies indicated TikTok made its own
       | version of a video player presumably to ensure the code runs
       | properly -- but Lockerman said it's also likely used to hide
       | things"
       | 
       | Wow. Just wow.
       | 
       | Anyway, this seems like yet another china-bogeyman article making
       | absurdly broad claims about the breadth of data collected while
       | describing the much more limited techniques they're actually
       | using. Essentially it's is trying very hard to act like what
       | TikTok is doing is somehow worse or more nefarious than other
       | companies (e.g. google and Facebook).
       | 
       | While there may be actual legitimate concerns about TikTok,
       | articles like this undermine the credibility of actual
       | researchers.
        
       | sascha_sl wrote:
       | Bad headline, and no link to the original research. Needs better
       | link.
        
       | Clent wrote:
       | The cover story is they collect no more than Facebook (others)
       | but they have a sweetheart deal with Apple and Google to
       | circumvent the app sandbox under dubious conditions.
       | 
       | Facebook is jealous of the revenue potential. Epic is pseudo-
       | concerned for the oppressed developer community.
        
         | olliej wrote:
         | I don't see any claim of any apple deal?
        
       | jazzyjackson wrote:
       | I don't see anything in the article that jibes with the headline,
       | appears they are fingerprinting a unique device ID. The assertion
       | that this "gives TikTok's Beijing-based parent company ByteDance
       | full access to user data" is uncorroborated. It's unclear to me
       | why these studies were shared "exclusively" with this
       | entertainment news outlet.
       | 
       | > "Consequentially, just because the application doesn't do
       | anything bad today, doesn't mean that it won't do bad things in
       | the future," one study said.
       | 
       | Nothing new.
        
       ___________________________________________________________________
       (page generated 2022-02-22 23:01 UTC)