Skip to main content
Cybersecurity

TikTok Reversal Sparks Mobile Security Concerns

Smartphone with blank screen on neutral-colored surface.

"Despite the fact that TikTok now has a U.S. entity, its privacy policy is still very invasive in terms of what the platform automatically collects and how that information can be used," said Matt Stern, Hypori CSO and mobile security expert.

The Department of Justice decision

Last month the Department of Justice (DOJ) concluded that TikTok should no longer be banned from government devices. That reversal follows changes to the app's U.S. operations that, according to the DOJ, remove the app from the specific legal parameters that triggered a prohibition under the No TikTok on Government Devices Act.

How U.S. control changed — Oracle and a group of American investors

The DOJ's change of position followed the acquisition of United States operations of the app by a group of American investors that includes the software organization Oracle. The source material states that those investors "took over United States operations of the app," and that shift is presented by the DOJ as the factual basis for revisiting the prior ban.

What the No TikTok on Government Devices Act covered

The No TikTok on Government Devices Act, the law cited by the DOJ, prohibited versions of the app that were developed or offered by ByteDance, a Beijing-based organization. Because the U.S. app is now operated independently of ByteDance, the DOJ determined the statutory prohibition no longer applies.

ByteDance's remaining stake

Even with the change in operating control, the source notes a crucial detail: ByteDance still retains nearly 20% of the joint U.S. venture. That retained equity is explicitly recorded in the reporting and is part of the context for continued scrutiny.

Security assessment: what Matt Stern recommends and why agencies should care

Matt Stern, identified in the report as Hypori CSO and a mobile security expert, framed his judgment around the app's data practices and the clash with operational security. Stern's statement in full: "Any application that collects significant amounts of device, location, and user data introduces additional exposure, and agencies should be extremely cautious about allowing that risk onto endpoints used for government work."

He went on to describe TikTok as "fundamentally an information-sharing platform" and said that characterization is "difficult to reconcile with the principles of operational security." Stern concluded bluntly: "TikTok is not compatible with secure government communications and should not be used on government devices." Those remarks identify two concrete concerns: the volume and types of data TikTok automatically collects under its privacy policy, and the platform's basic design as an information-sharing service.

What this means for government agencies, technologists, and end users

  • Government agencies: The DOJ's legal determination removes the categorical ban tied to ByteDance development or offering, but agencies will now weigh Stern's operational-security concerns about device, location, and user data when setting policy for government endpoints.
  • Technologists and security teams: The shift in legal status does not, in Stern's view, change the underlying privacy posture of the application. Security teams are therefore being urged to examine privacy policies and data-collection behaviors before permitting the app on devices used for government work.
  • End users: The presence of an independently operated U.S. entity does not alter Stern's assessment that TikTok's privacy policy remains "very invasive" and that the platform's information-sharing nature creates exposure for sensitive communications conducted on the same devices.

The DOJ has treated the statutory language and the changed ownership structure as dispositive for the ban; security professionals represented by Stern treat the app's data practices and platform design as the decisive issues for operational security. The record in the source material therefore leaves two clear threads to follow: legal status and statutory fit on one hand, and an unchanged privacy profile and information-sharing architecture on the other.

Link to the original story: https://www.securitymagazine.com/articles/102503-tiktok-ban-on-government-devices-reversed-mobile-security-expert-weighs-in