Cyber Security blog

IPdatatech CyberSecurity Blog

TikTok Fined $16 Million For Misusing U.K. Children’s Data

Robert Hart

Forbes Staff, Forbes April 04, 2023

TOPLINE

TikTok has been fined nearly $16 million for “misusing children’s data,” Britain’s data watchdog announced on Tuesday, the latest blow for the wildly popular platform as it faces intensifying scrutiny over its links to China and potentially harmful impact on younger users.

KEY FACTS

The Information Commissioner’s Office said it had fined TikTok $15.9 million (£12.7 million) for numerous “breaches of data protection law” and for failing to protect the privacy of kids.

TikTok allowed as many as 1.4 million U.K. children under the age of 13 to use its platform in 2020, the regulator estimated, despite the company’s own policies barring children that young from creating accounts.

In addition to breaking its own policies, the regulator said TikTok also fell foul of British data protection laws, which require organizations using the personal data of kids under the age of 13 to gain parental consent.

The regulator criticized TikTok for failing to seek parental consent and said the company “ought to have been aware that under 13s were using its platform,” adding that it failed to carry out the necessary checks to identify and remove underaged users.

The magnitude of the fine, one of the largest levied by the ICO, “reflects the serious impact” of TikTok’s failure, explained U.K. Information Commissioner John Edwards, stressing that the failure has potentially exposed kids to “harmful, inappropriate content” and may have allowed them to be tracked and profiled.

TikTok did not immediately respond to Forbes’ request for comment.

CRUCIAL QUOTE

“There are laws in place to make sure our children are as safe in the digital world as they are in the physical world. TikTok did not abide by those laws,” Edwards said when explaining the ICO’s decision. “TikTok should have known better. TikTok should have done better,” he added.

BIG NUMBER

$33.7 million (£27 million). That’s the size of the fine the ICO said it planned to levy on TikTok for the infractions when it originally announced its intention to penalize the company last year. The regulator said it decided not to pursue a provisional finding from its investigation related to the unlawful use of special category data, which includes information like ethnic background, political opinions, health data and sexual orientation.

NEWS PEG

TikTok is particularly popular among younger people and the potential for it—as well as other social media platforms like Instagram, YouTube and Facebook—to harm young users has come under intense scrutiny in recent years. Aspects of TikTok’s platform, such as how its algorithms suggest content that can harm users’ mental and physical wellbeing, are considered particularly problematic for younger children, many of whom use the platform without supervision or permission. While many platforms are stepping in with policies to safeguard younger users, they have been sharply criticized for failing to adequately monitor who uses their services and what content is posted, as well as failing to remove both users who should not have been able to join in the first place and harmful content placing them at risk.

KEY BACKGROUND

Such scrutiny over TikTok’s impact on kids comes amid mounting unease from Western governments over the company’s ties to China. The platform is owned by Chinese company ByteDance and lawmakers fear its popularity could be exploited by Beijing to spy on users outside its borders. Though TikTok strenuously denies it would ever do so and says it keeps data separate, many lawmakers fear Chinese authorities could force its hand. Governments, including the federal government, most state governments and a string of European countries, have already banned the app from official devices over security concerns. U.S. lawmakers are considering banning TikTok entirely to safeguard national security.

UK watchdog warns chatbot developers over data protection laws

Dan Milmo and Alex Hern

Writers, The Guardian April 03, 2023

Concerns have arisen over tech firms using masses of unfiltered personal data culled from the internet to ‘train’ generative AI

Britain’s data watchdog has issued a warning to tech firms about the use of people’s personal information to develop chatbots after concerns that the underlying technology is trained on large quantities of unfiltered material scraped from the web.

The intervention from the Information Commissioner’s Office came after its Italian counterpart temporarily banned ChatGPT over data privacy concerns.

The ICO said firms developing and using chatbots must respect people’s privacy when building generative artificial intelligence systems. ChatGPT, the best-known example of generative AI, is based on a system called a large language model (LLM) that is “trained” by being fed a vast trove of data culled from the internet.

“There really can be no excuse for getting the privacy implications of generative AI wrong. We’ll be working hard to make sure that organisations get it right,” said Stephen Almond, the ICO’s director of technology and innovation.

In a blogpost, Almond pointed to the Italy decision and a letter signed by academics last week, including Elon Musk and the Apple co-founder Steve Wozniak, that called for an immediate pause in the creation of “giant AI experiments” for at least six months. The letter said there were concerns that tech firms were creating “ever more powerful digital minds” that no one could “understand, predict, or reliably control”.

Almond said his own conversation with ChatGPT had led to the chatbot telling him generative AI had “the potential to pose risks to data privacy if not used responsibly”. He added: “It doesn’t take too much imagination to see the potential for a company to quickly damage a hard-earned relationship with customers through poor use of generative AI.”

Referring to the LLM training process, Almond said data protection law still applied when the personal information being processed came from publicly accessible sources.

A checklist published by the ICO on Monday stated that under UK General Data Protection Regulation (GDPR), there must be a lawful basis for processing personal data, such as an individual giving their “clear consent” for their data to be used. There were also other alternatives that did not require consent, such as having a “legitimate interest”, the checklist said.

It added that companies had to carry out a data protection impact assessment and mitigate security risks such as personal data leaks and so-called membership inference attacks, whereby rogue actors try to identify whether a certain individual was used in the training data for an LLM.

The Italian data protection watchdog announced a temporary ban on ChatGPT on Friday, citing a data leak last month and concerns about the use of personal data in the system underpinning the chatbot. The watchdog said there appeared to be “no legal basis underpinning the massive collection and processing of personal data in order to ‘train’ the algorithms on which the platform” relied.

In response to the Italian ban, Sam Altman, the chief executive of ChatGPT-developer OpenAI, said: “We think we are following all privacy laws.” But the company has refused to share any information about what data was used to train GPT-4, the latest version of the underlying technology that powers ChatGPT.

The previous version, GPT-3, was trained on 300bn words scraped from the public internet, as well as the contents of millions of ebooks and the whole of English-language Wikipedia

Microsoft unveils Security Copilot built on GPT-4

David Jones

Reporter, Cybersecurity Dive March 28, 2023

Microsoft is launching Security Copilot, a tool that combines artificial intelligence with a security platform that company officials say will provide advanced capabilities to protect IT networks from sophisticated threats. 

The technology is backed by OpenAI’s generative AI GPT-4, and combines Microsoft’s global threat intelligence capabilities and vast security network, which generates more than 65 trillion daily signals, Microsoft said Tuesday. 

For Microsoft executives, the copilot offers a solution for a vastly outnumbered security workforce, which has 3.4 million unfilled positions globally. 

The remaining security operations staff have in many cases found themselves fighting an endless battle of chasing down sophisticated nation-state and criminal adversaries who can generate new threat activity faster than network defenders can weed out false signals. 

“The volume and velocity of attacks requires us to continually create new technologies that can tip the scales in favor of defenders,” Vasu Jakkal, Microsoft’s corporate VP of security, compliance, identity and management, said in a blog post released Tuesday. “Security professionals are scarce, and we must empower them to disrupt attackers’ traditional advantages and drive innovation for their organizations.”

The learning model will enable new skills development over time, improving detection capabilities and speed, according to Microsoft. Security Copilot will integrate with other Microsoft security products and over time integrate with an ecosystem of third-party products. 

The arrival of generative AI ups the ante for both defensive and offensive cybersecurity use cases, according to Avivah Litan, VP distinguished analyst at Gartner. 

Threat actors have used AI in the past to construct attacks with more speed and effectiveness, and network defenders have used AI for years in various security products and services, including detection and response, endpoint security, user behavior analytics and other services. 

“In the end it becomes a cat and mouse game that moves much faster than it does now,” Litan said via email. “Whoever has the most effective, generative AI cybersecurity offense or defensive capability wins in the short run.”

Microsoft plans to protect customer data from unauthorized use. Customer data will not be used to enrich or train AI models used by others, Jakkal said.


Follow My Blog

Get new content delivered directly to your inbox.

Design a site like this with WordPress.com
Get started