Comment by areoform

10 hours ago

The TikTok ban is security theater through and through.

Chinese spy agencies don't have to make an app that millions of American teens use to harvest data on them. American companies have been doing the job for them.

They — just like the FBI, NSA, American police departments and almost every TLA — can just buy the data from a broker, https://arstechnica.com/tech-policy/2024/01/nsa-finally-admi...

https://www.eff.org/deeplinks/2022/06/how-federal-government...

The brokers don't care. They'll sell to anyone and everyone. And the people they sell to don't care either. They'll process and re-sell it too. And on and on, until it ends up in the hands of every interested party on Earth, i.e. everyone.

So don't worry, the Chinese already have a detailed copy of your daily routine & reading habits. Just love this new world that we've created to make $0.002/click.

EDIT — if it makes you feel any better, the Chinese are doing it too!

https://www.wired.com/story/chineses-surveillance-state-is-s...

> The vendors in many cases obtain that sensitive information by recruiting insiders from Chinese surveillance agencies and government contractors and then reselling their access, no questions asked, to online buyers. The result is an ecosystem that operates in full public view where, for as little as a few dollars worth of cryptocurrency, anyone can query phone numbers, banking details, hotel and flight records, or even location data on target individuals.

- harvesting data: sure the CCP could buy some data from data brokers; but that data is very limited compared to the data that TikTok itself has on its users

but data harvesting is not the real problem

the big problem is that you have a social network to which millions of your citizens are connected and used daily, which is under the control of a foreign adversary; it's a bit like if CBS was owned by the CCP

  • > the big problem is that you have a social network to which millions of your citizens are connected and used daily, which is under the control of a foreign adversary; it's a bit like if CBS was owned by the CCP

    You mean... like the rest of the world countries are. Look, you make a point here, but the only solution here is to completely cut-off the internet and for the government to run a single TV channel akin to Korea.

    The US has been tirelessly working to "infiltrate" other countries media and influence them. That was heralded as "bringing freedom". How the times have changed.

  • > data harvesting is not the real problem

    You may not think this but it was one of the two arguments the made to SCOTUS.

  • Don't we need to have a pretty low opinion of the average american cognitive skill to feel the need to protect them from foreign propaganda for fear it would take a hold on them?

    If the general public is that stupid and that this kind of protection is really needed, then it also means that democracy is no longer a viable form of government because the public is also too stupid to vote.

    • > Don't we need to have a pretty low opinion of the average american cognitive skill to feel the need to protect them from foreign propaganda for fear it would take a hold on them?

      No. Influential foreign propaganda is inconspicuous. There’s nothing to be mindful of other than “who benefits if this is widely believed?” and it’s not a low opinion to think most people aren’t mindful of that.

    • > Don't we need to have a pretty low opinion of the average american cognitive skill to feel the need to protect them from foreign propaganda for fear it would take a hold on them

      that's naive. Literally leaving CNN on in your living room 3 days a week will eventually change you opinions. Our minds absorb things we hear repetitively, even if we now they might be half truths or lies.

      1 reply →

    • Foreign propaganda is much easier to spot. It is the domestic propaganda that was legalized in the 2012 Smith-Mundt Modernization act that concerns me.

    • > Don't we need to have a pretty low opinion of the average american cognitive skill

      Well, half the country voted for a convicted felon who _illegally tried to overturn the results of an election_, so yeah, it's pretty low.

      > democracy is no longer a viable form of government because the public is also too stupid to vote.

      "Democracy is the worst form of government, except for all the others" -- Churchill

      It's flawed, but still miles better than what China has. At least there are still some safeguards on Trump, unlike Xi.

    • > If the general public is that stupid and that this kind of protection is really needed, then it also means that democracy is no longer a viable form of government because the public is also too stupid to vote.

      They are, it is, and it never was, for that exact reason.

That's a convenient fig leaf.

There are 2 separate problems:

   - Lack of US privacy legislation
   - Security-sensitive systems and infrastructure owned by competitor nations

The existance of a different problem is not a justification to avoid progress on the original one.

PS: Curious how many total comments there are on this article. Either everyone is 3x as likely to comment on it as usual or something else is different. Ijs.

  • But neither of those problems are addressed by a TikTok ban. If privacy legislation was enacted and it banned TikTok as a result the conversation would be very different.

    • Forcing TikTok to divest from mainland Chinese control absolutely solves the second, in TikTok's case.

      That there exist other problems is not a justification for inaction on this particular problem.

      21 replies →

    • Privacy legislation only works because companies have to worry about whistleblowers leaking violations to the media, which would cause them to be fined. China can disappear any whistleblowers and has full control over their media. If CCP compromising TikTok is proven despite this, then it's over for TikTok anyways and fines are irrelevant.

  • > Either everyone is 3x as likely to comment on it as usual or something else is different. Ijs.

    Or maybe this story is hugely relevant to a lot more people than your average story? I find it hard to believe china is waging a huge phsyop on HN

    • The “it cant happen to here” is strong in America. I saw a guy videotaping the palisades fire instead of packing and vacating. People thinks it only happens in the movies but on my time on earth reality is far stranger than fiction

    • I find it easy to believe. If Russia can run a psyop to sway opinion towards supporting their interests why can’t China? HN is hardly some tiny unknown forum.

      2 replies →

It's less about bare privacy and more about the fact that it's a closed loop system.

Meta collects your data and advertisers can indirectly use that data to serve you ads. In addition, government actors can use Meta's advertising tools to spread propaganda.

But TikTok is an all-in-one solution. The government have direct control over the algorithm in addition to having access to all of the data. They don't have to go through a third party intermediary like Meta and aren't only limited by a public advertising API.

I doubt it is about data. It should be about digital heroin and psychological warfare.

  • Yeah it's simply an incredibly powerful way to influence US youth in ways that are favorable to the CCP.

    I don't understand how or why this is hard for people to grasp? It's no different than Radio Free Europe being secretly funded by the CIA, except it's even more powerful.

    • Radio Free Europe was covertly funded by the CIA into the 1970s, but your comment should say “having been” instead of “being”, because its current funding is not a secret: that comes from the US Agency for Global Media, an openly acknowledged part of the US government.

The value is in the ability to influence what your enemy sees, and to push whatever narratives are best for you and worst for your enemy. They don’t give a shit about the data.

> American companies have been doing the job for them.

This right here is the answer. People just don’t care about this type of privacy because they assume some American company already has their data. Combine that with us being two generations removed from the Cold War and the average TikTok user doesn’t see any reason why the owner of this specific data being Chinese matters and frankly I’m sympathetic to that argument. If you live in the US, someone like Musk is going to have a greater influence on your life than the Chinese government and I see no reason to trust him any more or less than the Chinese government. So any discussion of this being a matter of national security just rings hollow.

  • I worry less about the data and more about how a lot of kids, teens, and young adults get their news from TikTok (and social media in general).

    That's the real value of TikTok. Having the eyeballs of young people and being able to (subtly or not) influence their perception of the world is valuable in a way that massive amounts of data aren't.

    I do also worry about this with Musk, but I also acknowledge that taking away social media ownership from a foreign company is different than taking it away from a US company.

    • I am a fairly active consumer of TikTok content. It's a huge app with many many different niches that have their own little communities. Mostly, the algorithm has decided that what I need to see is woodworking videos, car videos, and some dad jokes. But there certainly is a very interesting undercurrent of "information". One really interesting wave was when the TikTok ban passed Congress. Suddenly my feed was filled with absolutely random people saying how bad this is and how it just doesn't make sense, etc. Like if you are an influencer on a platform that just got banned, of course you'll have some feelings about it. But interestingly most people who do regularly show up (the woodworkers, car guys, etc.) who do have big followings pretty much didn't talk about it. Even this week when the ban is about to happen, the popular and established accounts that aren't politics-focused are not talking about it. But now there is a new wave of completely random people talking about "how much is the US government freaking out that we are all moving to Red Note?" And at this point I don't trust that all of them are actual humans, let alone humans who haven't been paid, or if they are AI-generated personas meant to really overtly drive people like me to the new app.

      My point isn't that there is some grand conspiracy here, just that if you wanted to have outsized influence on people who are there just for entertainment, you could do it and make it look organic. Inception has to be the target's idea and all that.

      In a similar vein I see talking heads of people in their kitchens contemplate world issues. Russia/Ukraine, Israel/Palestine, life in China: you can get in-depth opinions on all those issues from a hairdresser in Nebraska or a mechanic in Michigan, and they all will present them well enough. So I think there is something there.

      But the clear damn solution is to pass laws that prohibit a bunch of this stuff across the board. The fact that Instagram Reels can do exactly what TikTok is doing but with ties to a different world power makes this ban seem shameless. Ban them all. Or none. Or regulate them like they should be regulated. But don't pretend like this security theater is somehow going to fix anything meaningful.

      10 replies →

    • > I worry less about the data and more about how a lot of kids, teens, and young adults get their news from TikTok (and social media in general).

      Fox News* is America's most watched television news source. Is this the kind of alternative you are envisioning?

      *Also owned by a foreign national

      1 reply →

    • I just find this line of argument incredibly ironic because it is fundamentally an anti-free speech argument in defense of both the US and Musk while making the defense of the Chinese app with strong censorship a pro-free speech position. That doesn’t necessarily make the argument invalid, but it certainly makes it feel a little disingenuous to the general public.

      2 replies →

  • > If you live in the US, someone like Musk is going to have a greater influence on your life than the Chinese government and I see no reason to trust him any more or less than the Chinese government. So any discussion of this being a matter of national security just rings hollow.

    Just because Musk is a f*ing problem for all Americans, doesn't mean that the CCP isn't a problem. Not much you can do about "President" Musk -- so you have to work with what you can control.

it's not just about data harvesting, it's about propaganda as well, and no, you can't "just buy" as much data as tiktok gathers on people, tiktok most likely has some of the richest data gathered from users, because they can get away with it.

I am in favor of banning TikTok, but not strictly because they harvest data. I am far more concerned about them manipulating people on a large scale, I think TikTok is an effective tool for manipulating public opinion and I have no doubt that they're actively engaged and consciously engaging America in a form of psychological warfare. We are facing the very real threat of a military conflict with China, I do not want the Chinese government in this position of power.

I frankly don't understand why I keep seeing on social media people like yourselves push the idea that it's okay because other companies are also harvesting the data. It is obviously not about the data. It is about China being in a position to manipulate information flow.

  • The rationalizations and justifications are more a window into people's thought process than they are actual arguments. This person has decided that TikTok isn't that bad, and you are witnessing how they reverse engineer from that view point back to the argument.

    That's why arguing in this sense never works. Someone isn't trying to work something out, they've already decided and are trying to explain the decision to you. That's not the same thing as thinking through something.

For anyone reading this who is knowledgeable about this topic, where, specifically, can a regular citizen buy personal data about people from data brokers?

I mean let's not pretend that an app on the vast majority of peoples phones isn't a non-trivial vector for a zero-day attack.

If there is an invasion of Taiwan, I don't think it would be unthinkable that everyone's phones being broken wouldn't be a major tactical and political advantage of shifting the US's priorities and political will in the short run.

Sure, it burns the asset in the process, but I mean... this has been a priority for an entire century.

  • i dont think fhats the right attack? the influential use of tiktok sould be sharing propaganda like the US did about the iraq war "we did it and the taiwanese people are excited to be liberated and reunified with china"

    along with details about how the US has no defensive alliance with taiwan, and that the US does not need to intervene

    • I agree; the Tiktok algorithm would be used to subtly shift public opinion rather than something overt that burns their assets

      This is a very realistic scenario. It doesn't mean people will suddenly see messages from the CCP on their screens. It could mean that posts that are critical of China are subtly downweighted (not banned, that would be too obvious and problematic) while those favorable towards China would be upweighted.

      One thing the CCP is quite good at, from its long experience of always controlling the narrative in China, is this type of social media manipulation.

    • Ehh... I just disagree, even if I agree that my concern is wildly speculative. The isolationist right already has them covered there. If they can take the island, it's over. The US is not going to mount an invasion to save Taiwan, but will sell them weapons and help defend it.

      If they can't take the island quickly, then maybe propaganda helps. I just think neutering or nuking everyone's phones for a few days is enough to genuinely split the attention of the American people. I think it's very safe to say our culture cares much more about it's butter than it's guns right now. We are decadent.

  • That's every popular app.

    • Yes, but my point is that TikTok is the most downloaded app in the United States, with apparently about 100 million installs. I'm just looking at reports on various sites.

      Edit: other sites put YouTube, and others higher with TikTok at 40% of phones.

      Nothing else controlled by the CCP looks like it even comes close to that in America.

> just buy the data from a broker

A surprising (and funny) example of this is how the open-source intelligence community and sites like Bellingcat used purchased or leaked data from private Russian commercial data brokers to identify and track the detailed movements of elite Russian assassination squads inside Russia as well as in various other countries. They learned the exact buildings where they go to work every day as well as who they met with and their home addresses. https://www.newyorker.com/news/dispatch/how-bellingcat-unmas...

Volunteer open-source researchers also used these readily available data sources to identify and publicly out several previously unknown Russian sleeper agents who'd spent years hiding in Western countries while building cover identities and making contacts. https://www.bellingcat.com/news/2022/08/25/socialite-widow-j...

To your point, if volunteer internet hobbyists can use commercial broker data to identify and track elite Russian assassins and undercover sleeper agents, in Russia and around the world, China having direct access to US Tiktok data, which Tiktok sells to anyone through brokers anyway, doesn't seem like an existential intelligence threat to our national security. Forcing TikTok to divest Chinese ownership would, at most, make Chinese intelligence go through an extra step and pay a little for the data.

If politicians were really worried about foreign adversaries aggregating comprehensive data profiles on everyone, just addressing China's access to TikTok is a side show distraction. Why didn't they pass legislation banning all major social media services from selling or sharing certain kinds of data and requiring the anonymization of other kinds of data to prevent anyone aggregating composite profiles across multiple social platforms or data brokers? That would actually reduce the threat profile somewhat.

Obviously, they aren't doing that because the FBI, CIA, NSA, TSA, INS, IRS, Homeland Security and their Five Eyes international partners are aggressively buying data broker info on all US residents at massive scale every day and aggregating it into comprehensive profiles - all with no warrants, probable cause or oversight. The US Constitution doesn't apply because it's just private commercial data, not government data. Any such law would have to explicitly carve out exceptions allowing US and allied intelligence agencies to continue doing this. Alternatively, they could put such use under the secret FISA intelligence court. US intelligence has thoroughly co-opted FISA oversight but jumping through the FISA hoop is extra work and filling out the paperwork to be rubber-stamped is annoying. They much prefer remaining completely unregulated and unsupervised like they are now, collecting everything on everyone all the time without limit. They've certainly already automated collecting all the data they want from every broker.

So yeah... let's very publicly make a big show of slapping just China and only about TikTok - and loudly proclaim we really did something to protect citizen privacy and reduce our national data aggregation attack surface. This is the intelligence community cleverly offering a fig leaf of plausible deniability to politicians who can now claim they "did something", while leaving the US intelligence community free to pillage every last shred of citizen privacy in secret.

  • This sounds super cool where can I get/buy this data? Would be a fun dataset to mess around with

    Any idea why it is unidirectional? If the data is openly available why can't the Russians track US/Ukrainian agents the same way?

    • As far as I understand, many of those brokers are specific to Russia, and get their data specifically from Russian sources which Ukrainians are unlikely to be involved with.

      Russian officials / employees are easier to bribe, so there are brokers selling access to car ownership / license plate records, cell phone location records and call logs, passport records etc.

      There's a good Bellingcat article on this at https://www.bellingcat.com/resources/2020/12/14/navalny-fsb-...

      3 replies →

  • Again, how does this change any of the realities of TikTok? "Leave them alone because other abuses exist" is not an argument.

But what is the point of all this data? People don’t live forever or have unlimited exploitable LTV, so there is a very narrow window of time for where this data is useful for a given population. Is the goal to just use it to influence elections?

It’s this - anyone saying otherwise simply does not know, or is pushing some kind of an agenda. I fully believe some people in the US government buy the whole “security” angle, but it’s very obviously bogus. So is the idea of selling it - china is very protective of chinese user data, there’s no way they are going to trust an american investor to play by their rules, even if a serious price was offered, which it hasn’t been. this entire thing feels like theater, honestly.

  • TikTok is being banned because of the algorithm, not user data. Though that’s a nice side benefit.

    • That’s theater too - at least without acknowledging the clear harm that american algorithm does as well. The logic simply doesn’t add up, unfortunately - I am for banning all social media apps.

      Like foreign adversaries can already run influence campaigns on american media platforms, often, the american ones will even cooperate with it. It’s just theater. They dont need tiktok to do whatever people are saying the reason is.

      3 replies →