Report: TikTok secretly collected device data in Android app in violation of Google policies


  • Android
  • Wednesday, 12 Aug 2020

TikTok tracked the MAC (media access control) addresses – unique hardware identifiers assigned to a network interface – of users’ Android phones, possibly for advertising purposes, per the Journal story. TikTok stopped the practice in November 2019. — Bloomberg

LOS ANGELES: TikTok collected device-specific addresses of users’ smartphones via its Android app for at least 15 months over 2018-19, using a technique that Google had banned developers from using without user consent, according to a Wall Street Journal report.

TikTok tracked the MAC (media access control) addresses – unique hardware identifiers assigned to a network interface – of users’ Android phones, possibly for advertising purposes, per the Journal story. TikTok stopped the practice in November 2019. The popular video-sharing app is facing a potential ban in the US over national-security concerns, given its ownership by Chinese Internet giant ByteDance.

The TikTok Android app didn’t notify users of the MAC-address tracking. In addition, TikTok uses an “unusual” additional layer of encryption for user data it collects and transmits back to the company’s servers, which concealed the fact it had been tracking MAC addresses, according to the Journal report.

In a statement, a TikTok spokesperson said, “Under the leadership of our chief information security officer (CISO) Roland Cloutier, who has decades of experience in law enforcement and the financial services industry, we are committed to protecting the privacy and safety of the TikTok community. We constantly update our app to keep up with evolving security challenges, and the current version of TikTok does not collect MAC addresses. We have never given any US user data to the Chinese government nor would we do so if asked.” TikTok announced the hiring of Cloutier, formerly chief security officer at ADP, in March 2020.

The TikTok rep added, “We always encourage our users to download the most current version of TikTok.”

According to the Google Play Developer Policy Center, an app’s advertising identifier “must not be connected to personally-identifiable information or associated with any persistent device identifier”– like a MAC address – “without explicit consent of the user”. In response to the WSJ story, a Google rep said, “We’re investigating these claims.”

The news about TikTok’s surreptitiously device tracking comes as parent company ByteDance is being forced by the Trump administration to divest TikTok’s US operations to an American buyer – or face a ban.

Trump last week issued an executive order that would outlaw business dealings with TikTok in the US by Sept 21 if TikTok’s US-based business isn’t sold by then. The president invoked national security concerns for the ban, noting that Chinese authorities could demand ByteDance fork over any TikTok user data.

Microsoft said it was in talks about a TikTok acquisition and Twitter reportedly has held preliminary talks about a possible merger with TikTok. – Variety/Reuters

Article type: metered
User Type: anonymous web
User Status:
Campaign ID: 18
Cxense type: free
User access status: 3
   

Did you find this article insightful?

Yes
No

77% readers found this article insightful

Across the site