Live data from Hacker News

U.S. Navy bans TikTok from government-issued mobile devices

reuters.com

51–60 of 170 posts

Re: U.S. Navy bans TikTok from government-issued mobile devices

#51
post #38
post #26

Why's "ban" needed? Government should have full control over government issued devices and only whitelisted modifications should be allowed. If it's not this way - someone at government should be held accountable for jeopardizing the security of the nation.

> A Navy spokesman said Naval and Marine personnel who use government issued smart devices are generally allowed to use popular commercial apps, including common social media apps, but from time to time specific programs that present security threats are banned. Should the Navy whitelist Ebay and Amazon? What about the Walmart app? If Target has one should they then apply to get whitelisted? What about navy personal…

> the bureaucratic overhead would be either really cumbersome or the value of so small...

Oh, I see you are already familiar with how the U.S. government operates.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#52
post #47
post #44

Earlier quoted context omitted.

One off bans makes more sense, a whole unit set up to pre-approve millions of potential apps is crazy-town. Then they use Google Chrome and hit a phishing-hole site and get their phone owned. But don't worry, they weren't allowed to install Netflix! The problem here is open-source intelligence because TikTok is very popular among young members who spend all their free time in their bunk on their phone. Limiting the a…

So because it adds a layer of security rather than 100% watertight perfection, it is bad?

Explain to me how it's useful for security? Because I can guarantee you it will be a giant time-and-money waster with plenty of arbitrary rules that do nothing for security.

There's millions of apps and tons come out every year. This nation-wide 'unit' will have to be constantly 'measuring them for security'. This isn't going to accomplish much of anything.

Either have a secure phone with pre-installed apps (ie, just a browser plus encrypted phone/messenger, military mapping tools, etc) and let them install nothing (which means they'll just use their private phone any way for the OPSEC fail stuff). Or let them do whatever and selectively ban the ones like TikTok which are massive surveillance potential just based on its popularity alone. These one-off or watching for bad-stuff and react approach makes far more sense to me.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#54
post #26

Why's "ban" needed? Government should have full control over government issued devices and only whitelisted modifications should be allowed. If it's not this way - someone at government should be held accountable for jeopardizing the security of the nation.

I'm guessing those phones are to ensure their owners have a dedicated communication channel and a platform to run non-critical tech necessary for their job.

Apps for non-sensitive emails, schedules, maps, org directories, etc.

If the government is putting sensitive military data on an Android or iOS phone, you should be concerned. A whitelist would not be a sufficient safeguard.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#55

Not surprising. For several days now TikTok has left the information of 700 million of their users available via an open S3 bucket. It is online now at this very moment and includes IDFAs from Apple as well as interestingly, although I bet American companies do this to, the MAC Addresses. This is significant because my understanding is that Apple rotates / randomizes the MAC address because those can be used to, quit…

What is the link to the open S3 bucket?

Re: U.S. Navy bans TikTok from government-issued mobile devices

#56
post #52
post #47

Earlier quoted context omitted.

So because it adds a layer of security rather than 100% watertight perfection, it is bad?

Explain to me how it's useful for security? Because I can guarantee you it will be a giant time-and-money waster with plenty of arbitrary rules that do nothing for security. There's millions of apps and tons come out every year. This nation-wide 'unit' will have to be constantly 'measuring them for security'. This isn't going to accomplish much of anything. Either have a secure phone with pre-installed apps (ie, just…

They have identified TikTok as a threat, and so they have removed that threat.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#57
post #52
post #47

Earlier quoted context omitted.

So because it adds a layer of security rather than 100% watertight perfection, it is bad?

Explain to me how it's useful for security? Because I can guarantee you it will be a giant time-and-money waster with plenty of arbitrary rules that do nothing for security. There's millions of apps and tons come out every year. This nation-wide 'unit' will have to be constantly 'measuring them for security'. This isn't going to accomplish much of anything. Either have a secure phone with pre-installed apps (ie, just…

I'm not sure why they would evaluate any apps other than the ones they want to consider allowing people to install. It certainly does sound wasteful to evaluate something no one wants.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#59
post #56
post #52

Earlier quoted context omitted.

Explain to me how it's useful for security? Because I can guarantee you it will be a giant time-and-money waster with plenty of arbitrary rules that do nothing for security. There's millions of apps and tons come out every year. This nation-wide 'unit' will have to be constantly 'measuring them for security'. This isn't going to accomplish much of anything. Either have a secure phone with pre-installed apps (ie, just…

They have identified TikTok as a threat, and so they have removed that threat.

Yes and I'm advocating to continue taking that one-off approach instead of making some "ministry of apps" in the Navy to pre-approve every one of them.

Re: U.S. Navy bans TikTok from government-issued mobile devices

#60

Doesn't matter, they have it on their personal phone. App security is so bad that you pretty much need to virtualize the phone and feed it fake sensor data. The whole idea of unrestricted network access is stupid.

> The whole idea of unrestricted network access is stupid. I've been coming around to a similar idea. I'd like a setup something like this for my desktop: 1. Some devices representing network connections. One or more are "real"; others may be VPNs. 2. Per-application settings governing which network devices, if any, the application may use. Default to none. For example, the common way to use a VPN is like this: 1. St…

This behavior is a function of Berkeley Sockets style APIs and the nature of routing tables/default routes.
Post reply on HN