westvirginiadigitalnews.com
Advertisement
No Result
View All Result
No Result
View All Result
westvirginiadigitalnews.com
No Result
View All Result
Home ECONOMY

Banning TikTok Could Weaken Personal Cybersecurity

admin by admin
April 14, 2023
in ECONOMY
0
Mexican Drug Cartel Imposes Price Controls on Corn Tortillas, As Inflation Surges to 21-Year High
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


Yves here. Despite the anodyne title, this article described some of the technical means that could be used to implement a TikTok ban and how users might circumvent them. Note this piece steers clear of surveillance state provisions in the RESTRICT Act that extend well beyond TikTok.

By Robert Olson, Senior Lecturer of Computing Security, Rochester Institute of Technology. Originally published at The Conversation

TikTok is not be the first app to be scrutinized over the potential exposure of U.S. user data, but it is the first widely used app that the U.S. government has proposed banning over privacy and security concerns.

So far, the discussion has focused on whether TikTok should be banned. There has been little discussion of whether TikTok could be banned, and there has been almost no discussion of the effects on cybersecurity that a TikTok ban could cause, including encouraging users to sidestep built-in security mechanisms to bypass a ban and access the app.

As a cybersecurity researcher, I see potential risks if the U.S. attempts to ban TikTok. The type of risk depends on the type of ban.

Blocking TikTok in the Network

Blocking access to TikTok by filtering traffic destined for addresses believed to be owned by TikTok is possible but would be difficult to accomplish. Server addresses can be changed and a TikTok ban could devolve into a game of cat and mouse.

Additionally, this sort of block could be bypassed using virtual private networks (VPNs), which encrypt data flowing between servers and devices. VPNs can be used to shield traffic between servers in other countries and devices in the U.S. VPNs were once widely recommended for people using public Wi-Fi, and people are already using VPNs to access blocked streaming services. While security experts no longer recommend VPNs for public Wi-Fi, many people have used them and so are familiar with a tool that would help them bypass a TikTok ban.

DNS sinkholes are another technique that could be used in TikTok bans. DNS, the Domain Name System, is a network protocol that behaves like the internet’s phone book. Computers need to know the IP address of a server in order to communicate with it. DNS allows a computer to look up that address using a name convenient for humans to remember, such as www.google.com.

How the Domain Name System works.

DNS sinkholes stop that lookup. DNS sinkholes don’t directly block access to a server. Rather, they stop other computers from being able to look up the server’s address. It’s fair to think of a DNS sinkhole as removing someone’s name from a phone book.

DNS sinkholes are often used to stop malware and advertisements. They could be used in a TikTok ban. However, DNS sinkholes only work if lookups are confined to DNS servers that are configured to be sinkholes. A ban using DNS sinkholes would likely cover most DNS servers that people’s computers use by default.

However, you can relatively easily change DNS settings on your computer to circumvent a ban based on DNS sinkholes. There are many public DNS servers that people could use instead of their current DNS servers, which are commonly maintained by internet service providers. Blocking TikTok with DNS sinkholes would require significant international cooperation to make it difficult for people to find DNS servers that could access TikTok.

People circumventing a ban by looking for an alternate DNS server would be at risk. Unless a DNS server uses an uncommon extension named DNSSEC, you can’t verify the integrity of a DNS response. A malicious DNS server could reply to a lookup with an IP address of a server that’s under criminal control. This opens the door for a number of different kinds of attacks that could put your data at risk.

Banning TikTok from Your Phone

Another way TikTok could be banned is by blocking the TikTok mobile app. This would not affect U.S. users’ ability to access the TikTok website, but it could change how and how often people access TikTok. Blocking the app could address the concern that TikTok could be used without the user’s knowledge to access other systems on a network that a mobile device is connected to. This has been the motivation for some local TikTok bans.

Removing TikTok from app stores is unlikely to succeed by itself. Both Android and iOS devices have the ability to install apps from alternative sources, a technique known as sideloading. While this added step may discourage some people, sideloading tutorials are widely available online, and there is already popular software that must be sideloaded to be used on a phone.

How to sideload Android apps.

Mobile devices assume that mobile apps are coming from a trusted source. Both Google and Apple audit mobile apps prior to the app being available for download. While these reviews aren’t perfect, they help ensure apps don’t contain vulnerabilities or malware. When app stores aren’t involved, security responsibilities change. Sideloading makes users responsible for verifying an app’s legitimacy, and criminals could trick users into installing malicious apps from third-party sources.

But what about the millions of people who already have TikTok installed on their phones? Enforcing a TikTok app ban would likely require that it be removed from mobile devices. Apple has long had the ability to remove software from iPhones, and Google could remove apps using Google Play Protect. These tools are important security controls that, at least on Android devices, can remove malware even if it was sideloaded. Enforcing a ban using security controls could motivate users to disable these controls, which would weaken the security of their devices.

Users might even be motivated to “jailbreak” their iOS devices or “root” their Android devices to prevent Apple or Google from removing the TikTok app, which would further weaken security. Jailbreaking an iOS device allows users to bypass security restrictions in the operating system. Rooting an Android device means gaining the highest level security access, which allows users to make changes to the operating system. Jailbreaking and rooting are prohibited by Apple and Google. Both actions void the user’s warranty and undermine the security controls that limit criminals’ access to mobile devices.

Why you should not ‘root’ your phone.

Security Tradeoffs

I find it unlikely that a TikTok ban would be technologically enforceable. Even China struggles with content filtering. These difficulties may be why proposed legislation includes significant punishments for bypassing the ban.

Even if the punishments are not aimed at the average TikTok user, this proposed legislation – aimed at improving cybersecurity – could motivate users to engage in riskier digital behavior.

Print Friendly, PDF & Email



Source link

RELATED POSTS

2:00PM Water Cooler 12/6/2023 | naked capitalism

2:00PM Water Cooler 11/27/2023 | naked capitalism

ShareTweetPin
admin

admin

Related Posts

2:00PM Water Cooler 12/6/2023 | naked capitalism

2:00PM Water Cooler 12/6/2023 | naked capitalism

by admin
December 6, 2023
0

By Lambert Strether of Corrente. Bird Song of the Day Highland Tinamou, Huila, Colombia. * * * Politics “So many...

2:00PM Water Cooler 11/27/2023 | naked capitalism

2:00PM Water Cooler 11/27/2023 | naked capitalism

by admin
November 27, 2023
0

By Lambert Strether of Corrente. Bird Song of the Day Horned Screamer, Hato El Milagro, Cojedes, Venezuela. ” Neotropical Institute...

Links 11/18/2023

Links 11/18/2023

by admin
November 18, 2023
0

Source link

Links 11/9/2023 | naked capitalism

Links 11/9/2023 | naked capitalism

by admin
November 9, 2023
0

Translucent microbe deviates from universal genetic code PNAS Why My Recession Rule Could Go Wrong This Time Claudia Sahm, Bloomberg....

Links 10/31/2023 | naked capitalism

Links 10/31/2023 | naked capitalism

by admin
October 31, 2023
0

How to make NYC work better for its winged inhabitants Economist (David L) ‘Excruciating’ hornet sting leaves Rome dinner party...

Next Post
TotalEnergies’s carbon storage venture gets first customer

Treasury yields ease ahead of retail sales data

Join with us to develop your Business / Apps Lanka

Join with us to develop your Business / Apps Lanka

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Fivver Ads

RECOMMENDED

Mortgage Rates Edge Up On Surprisingly Strong Jobs Report

Mortgage Rates Edge Up On Surprisingly Strong Jobs Report

December 9, 2023
S&P 500 extends rally to six straight weeks (NYSEARCA:SPY)

S&P 500 extends rally to six straight weeks (NYSEARCA:SPY)

December 9, 2023
  • 647 Followers
  • 23.9k Followers

MOST VIEWED

  • Oil Rallies With OPEC+ Decision, G-7 Cap Plan Dominating Trading

    Oil Rallies With OPEC+ Decision, G-7 Cap Plan Dominating Trading

    0 shares
    Share 0 Tweet 0
  • Bed Bath & Beyond CFO Gustavo Arnal falls to his death from New York skyscraper

    0 shares
    Share 0 Tweet 0
  • No Escape From Biggest Bond Loss in Decades as Fed Keeps Hiking

    0 shares
    Share 0 Tweet 0
  • Trump wins special master ruling from federal judge over seized documents by FBI

    0 shares
    Share 0 Tweet 0
  • How much does the average Gen Z worker make? Results by state

    0 shares
    Share 0 Tweet 0
westvirginiadigitalnews.com

CATEGORY

  • APPS
  • ARTS & THEATER
  • BUSINESS
  • CELEBRITY
  • CRYPTO
  • CULTURE
  • ECONOMY
  • Education
  • ENTERTAINMENT
  • FASHION
  • FINANCE
  • FOOD
  • GADGET
  • Gambling
  • GAMING
  • HEALTH
  • HISTORY
  • LIFESTYLE
  • MARKET
  • MOBILE
  • MONEY
  • MOVIE
  • MUSIC
  • Nature
  • News
  • PRESS RELEASE
  • REAL ESTATE
  • Religion
  • SCIENCE
  • Shopping
  • SHOWS
  • SPORTS
  • TECH
  • TRAVEL

Mortgage Rates Edge Up On Surprisingly Strong Jobs Report

S&P 500 extends rally to six straight weeks (NYSEARCA:SPY)

SYLVESTER STALLONE : THE FAMILY STALLONE – OFFICIAL TRAILER (HD) IN ENGLISH A PARAMOUNT TV + SERIES

Shohei Ohtani signing affects more than his new team

olive oil brownies – smitten kitchen

BUSTED! We caught Kayla Lemieux at a shopping mall. He was NOT sporting his 'real' Z-cup breasts!

Time to buy? Why the prices of Rolex and other luxury Swiss watches keep falling.

How Selena Gomez Found Rare Beauty Fans in Steve Martin, Martin Short

Route 66 Road Trip: A Family-Friendly Adventure

Messenger finally gets end-to-end encryption by default

KOTOR 2 DLC Abandoned On Switch, Devs Apologize With Free Games

Inbuilt Content Creation Tool: When To Use

Varda Space puts off orbital factory reentry pending Air Force and FAA green light

Border Patrol: 8 migrants found dead in Rio Grande at Texas

Taylor Swift’s ‘Bejeweled’ Music Video Easter Eggs Explained

Classic car show fanatics channel, I travel the USA documenting car shows #shorts

A Cookie Swap | Cup of Jo

How self-centered shopping has made me happier with the things I buy

Cynthia Weil, Songwriter for the Ronettes, Chaka Khan, and the Righteous Brothers, Dies at 82

What Is a Wetland Worth?

© 2022 Westvirginiadigitalnews.com

No Result
View All Result

© 2022 Westvirginiadigitalnews.com