<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Privacy - STEP Software</title>
	<atom:link href="https://www.stepsoftware.com/tag/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.stepsoftware.com</link>
	<description>Custom Software Development</description>
	<lastBuildDate>Fri, 03 May 2024 16:22:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://www.stepsoftware.com/wp-content/uploads/2025/02/FaviconFoxOnDark_512-150x150.png</url>
	<title>Privacy - STEP Software</title>
	<link>https://www.stepsoftware.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Apple’s new device fingerprinting rules send clear privacy message to developers</title>
		<link>https://www.stepsoftware.com/apples-new-device-fingerprinting-rules-send-clear-privacy-message-to-developers/</link>
					<comments>https://www.stepsoftware.com/apples-new-device-fingerprinting-rules-send-clear-privacy-message-to-developers/#respond</comments>
		
		<dc:creator><![CDATA[Carmi Levy]]></dc:creator>
		<pubDate>Thu, 03 Aug 2023 20:58:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[app store]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[device fingerprinting]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[software development]]></category>
		<guid isPermaLink="false">https://stringn.com/ssweb/?p=1531</guid>

					<description><![CDATA[<p>Apple’s crusade to tighten privacy in its App Store is shifting into another gear. The company is cracking down on developers who use a technique called device fingerprinting to track user activity – even if they’ve opted out.</p>
<p>Specifically, the company wants devs to explain why they’re using certain application programming interfaces (APIs) and third-party software development kits (SDKs) in their apps. As part of its app store review process, it is also requiring developers to update their privacy documentation.</p>
<p>Those who fail to comply could find their apps denied approval in the App Store.</p>
<p>The post <a href="https://www.stepsoftware.com/apples-new-device-fingerprinting-rules-send-clear-privacy-message-to-developers/">Apple’s new device fingerprinting rules send clear privacy message to developers</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="wp-block-heading">NOT A ONE-TIME CHANGE</h3>



<p class="wp-block-paragraph">Apple is no stranger to the privacy game, as this move is only the latest in a series of policy updates designed to strengthen data access and usage policies across its platforms and devices.</p>



<p class="wp-block-paragraph">The most significant of these changes was the introduction of&nbsp;<a href="https://techcrunch.com/2021/04/26/apples-app-tracking-transparency-feature-has-arrived-heres-what-you-need-to-know/" target="_blank" rel="noreferrer noopener">App Tracking Transparency</a>&nbsp;in iOS 14.5 in 2021. That update required apps to request end-user permission to track activity across other apps and websites. Opting in allowed developers to use&nbsp;<a href="https://developer.apple.com/app-store/user-privacy-and-data-use/" target="_blank" rel="noreferrer noopener">Apple’s IDFA identifier</a>&nbsp;to share activity with third party data brokers and marketing agencies. Opting out should have stopped tracking cold – but like all privacy policies designed to return control to end-users, there was a loophole.</p>



<p class="wp-block-paragraph">By design, a number of Apple’s APIs that deliver core functionality – known as required reason APIs – also allow developers and marketing partners to track end-user activity even if they’ve specifically opted out of data sharing.</p>



<p class="wp-block-paragraph">By using a technique called fingerprinting, or data fingerprinting, developers can keep the data flowing – even after end-users had explicitly denied permission for the apps to do so.&nbsp;<a href="https://www.cultofmac.com/825411/apple-app-store-crack-down-device-fingerprinting-track-users/" target="_blank" rel="noreferrer noopener">Apple does not allow fingerprinting</a>&nbsp;regardless of whether or not the user has provided permission to track their activities.</p>



<p class="wp-block-paragraph">To close the gap, developers who use required reason APIs will have to provide additional information as part of the approval process.</p>



<p class="wp-block-paragraph">The updated policy guidance –&nbsp;<a href="https://developer.apple.com/documentation/bundleresources/privacy_manifest_files/describing_use_of_required_reason_api" target="_blank" rel="noreferrer noopener">published here on its developer website</a>&nbsp;– confirms that starting this autumn, Apple will email developers if they “upload an app to App Store Connect that uses required reason API without describing the reason in its privacy manifest file.”</p>



<p class="wp-block-paragraph">The rules get even stricter next year:</p>



<p class="wp-block-paragraph">“From Spring 2024, apps that don’t describe their use of required reason API in their privacy manifest file won’t be accepted by App Store Connect,” the statement continues.</p>



<h3 class="wp-block-heading">PREPARE NOW FOR THE INEVITABLE</h3>



<p class="wp-block-paragraph">Apple’s move is a clear signal to developers that the privacy landscape continues to tighten – as it should. It’s also a message to all developers, on any platform, that vendors are increasingly tying privacy compliance to initial approvals, and to ongoing support within their app stores and online marketplaces.</p>



<p class="wp-block-paragraph">To remain compliant, developers must not only adopt a privacy-first approach to their work, but they must educate themselves on current data stewardship rules and best practice to ensure they set appropriate expectations with stakeholders. Keep the following in mind as you initiate and manage your own development projects:</p>



<ol class="wp-block-list">
<li><strong>Follow a privacy by design approach.</strong>&nbsp;Don’t just tack privacy on at the end of a development project. Rather, build it directly into the architecture from the moment the project has been approved. Proactively identify anticipated risks and build out detailed response frameworks to minimize exposure and maximize business continuity.</li>



<li><strong>Conduct a data privacy assessment.</strong>&nbsp;Before the first line of code is written, developers and stakeholders must agree on what data will be collected, under what circumstances, how it will be processed, where it will be moved and stored, and who will have access to it. They must also agree on how data will be categorized – for example, by sensitivity and compliance requirements – and how the proposed solution will ensure compliance with applicable legislation. This assessment should form the critical framework for the entire development process.</li>



<li><strong>Minimize what you need.</strong>&nbsp;Just because you can collect certain types of data doesn’t mean you should. Place limits on the breadth and scope of personally identifiable information (PII) required to meet identified business requirements. Collect and retain only what is absolutely required to meet minimum core functionality – and no more. Ensure that users are able to provide explicit consent for their data to be collected, retained, and processed.</li>



<li><strong>Secure what you’ve captured.</strong>&nbsp;Use strong end-to-end encryption throughout the data lifecycle, and incorporate secure communication protocols, such as HTTPS, to minimize risks both at-rest and in-transit. Incorporate tighter, role-based access controls when designing database structures and procedures and include authentication details for end-user and administrator roles as part of the documentation process.</li>



<li><strong>Conduct regular security audits.</strong>&nbsp;Revisit protocols throughout the development process to ensure what was initially proposed is, in fact, supported by the evolving code base. As part of the quality assurance testing process, conduct penetration tests to identify – and resolve – vulnerabilities. Include regularly scheduled audits and reviews in documentation and maintenance procedures and incorporate these protocols into initial and ongoing end-user training.</li>



<li><strong>Build in robust authentication.</strong>&nbsp;Use two- or multi-factor authentication (2FA or MFA) wherever possible to minimize the potential for unauthorized system access and data leakage. Regularly review chosen protocols to ensure they are developed to the latest, most secure standards.</li>



<li><strong>Assess APIs and third-party integrations.</strong>&nbsp;Sure, you can build your own super-secure, privacy-aware code – but are you just as confident when incorporating another vendor’s code into your project? Assess all APIs, SDKs, and toolsets to ensure permissions and data accesses are all within project requirements. Only share data that is absolutely necessary, and review vendor performance and reputation to minimize the potential for data exposure.</li>



<li><strong>Document your privacy policy.</strong>&nbsp;Be obviously transparent about how user data is collected, processed, and used. Get explicit consent from end-users for any and all data required by the proposed system and make privacy tools and documentation easily accessible throughout the final solution.</li>



<li><strong>Ensure data is regularly deleted and anonymized.</strong>&nbsp;Build into the project plan procedures for periodic data retention and purging. Publish detailed rules for data management, and ensure data is aggregated and anonymized when used for reporting, dashboards, analytics, and research.</li>



<li><strong>Become a regulatory expert.</strong>&nbsp;You don’t have to live in Europe, California, or the U.S. to fall under the compliance requirements of GDPR, CCPA, or HIPAA, respectively. Data easily crosses borders, and solutions – and their developers – must be aware of the increasingly stringent legal requirements in the jurisdictions where their solutions will be used.&nbsp;</li>
</ol>



<h3 class="wp-block-heading">THE BOTTOM LINE</h3>



<p class="wp-block-paragraph">Apple’s move to force developers to explain why they must use certain APIs and SDKs may elicit some grumbling, but it’s being implemented for good reason.</p>



<p class="wp-block-paragraph">The age of data free-for-all is thankfully drawing to a close as vendors get serious about tightening the rules, enforcing compliance, and returning the power of data stewardship to end-users.</p>



<p class="wp-block-paragraph">Devs who proactively comply will reap the rewards – including streamlined app store approvals, higher levels of trust from stakeholders, and reduced support costs over the product lifecycle. The rest of us will have more positive control over our data, and a more secure app experience.</p>



<p class="wp-block-paragraph">Everybody wins.</p>



<p class="wp-block-paragraph">&#8212;</p>



<p class="wp-block-paragraph"><em><a href="https://www.linkedin.com/company/step-software-inc" target="_blank" rel="noopener" title="">Connect with us on LinkedIn</a> if you’re wondering about your own data privacy best practices.</em></p><p>The post <a href="https://www.stepsoftware.com/apples-new-device-fingerprinting-rules-send-clear-privacy-message-to-developers/">Apple’s new device fingerprinting rules send clear privacy message to developers</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.stepsoftware.com/apples-new-device-fingerprinting-rules-send-clear-privacy-message-to-developers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Threads privacy policies reveal need for better development best practices</title>
		<link>https://www.stepsoftware.com/threads-privacy-policies-reveal-need-for-better-development-best-practices/</link>
					<comments>https://www.stepsoftware.com/threads-privacy-policies-reveal-need-for-better-development-best-practices/#respond</comments>
		
		<dc:creator><![CDATA[Carmi Levy]]></dc:creator>
		<pubDate>Tue, 25 Jul 2023 21:06:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[StringN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[dataprivacy]]></category>
		<category><![CDATA[meta]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[threads]]></category>
		<guid isPermaLink="false">https://stringn.com/ssweb/?p=1539</guid>

					<description><![CDATA[<p>Meta’s wannabe-Twitter-killer, Threads, is having quite the ride.</p>
<p>After charging out of the gate with 100 million downloads in its first 5 days – the fastest in history, beating the previous record-holder, ChatGPT, which took two full months – engagement fell by half during its second week.</p>
<p>Normal new-product ups-and-downs notwithstanding, concerns over the new app’s appetite for end-user data are raising questions over privacy. Given the track record of its maker, Meta, on securing end-user data, it’s easy to understand why.</p>
<p>Developers might want to take notice.</p>
<p>The post <a href="https://www.stepsoftware.com/threads-privacy-policies-reveal-need-for-better-development-best-practices/">Threads privacy policies reveal need for better development best practices</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="wp-block-heading">HUNGRY, HUNGRY HIPPO</h3>



<p class="wp-block-paragraph">Now that the&nbsp;<a href="https://www.stepsoftware.com/blog/is-meta-threads-a-twitter-killer-the-answer-may-surprise-you" target="_blank" rel="noreferrer noopener">first few heady weeks of Threads’ existence</a>&nbsp;are giving way to the cold, harsh reality of long-term use, we&#8217;re beginning to get a better look at what lies underneath. And what we’re seeing – at least from the perspective of end-user privacy – merits additional discussion, because&nbsp;<a href="https://www.wired.com/story/meta-twitter-threads-bluesky-spill-hive-mastodon-privacy-comparison/" target="_blank" rel="noreferrer noopener">Threads collects significantly more data</a>&nbsp;than competing apps in the microblogging space. While apps like Twitter, Mastodon, Hive Social, and Bluesky all have their own privacy policies, all of them are far less aggressive in their data collection.&nbsp;</p>



<p class="wp-block-paragraph">It’s difficult to imagine anyone being surprised that Threads leads the way in aggressive data collection. After all, the new app comes to us from Meta, parent company of Facebook, architect of the&nbsp;<a href="https://www.wired.com/story/cambridge-analytica-facebook-privacy-awakening/" target="_blank" rel="noreferrer noopener">Cambridge Analytica scandal</a>&nbsp;that laid bare just how far a social media company might go in the pursuit of its customers’ data.</p>



<p class="wp-block-paragraph">In a digital economy largely fueled by data culled from billions of devices, apps, browsers, and services, Meta is hardly the only player pushing hard to learn as much as possible about the folks who subscribe to its services. But in a&nbsp;<a href="https://www.wired.com/story/meta-twitter-threads-bluesky-spill-hive-mastodon-privacy-comparison/" target="_blank" rel="noreferrer noopener">Wired.com comparison</a>&nbsp;of Twitter and its direct competitors, Threads was found to be collecting data from a much broader range of categories – such as third party advertising, developer marketing, analytics, product personalization, and app functionality – than the competition.</p>



<p class="wp-block-paragraph">In that respect, the scope and breadth of the data collected by Threads echoes that of Facebook. And while Threads falls under the&nbsp;<a href="https://privacycenter.instagram.com/policy/" target="_blank" rel="noreferrer noopener">common privacy policy</a>&nbsp;that covers Meta’s other social media platforms, including Facebook, Instagram, and WhatsApp, the new app also has its own&nbsp;<a href="https://help.instagram.com/515230437301944" target="_blank" rel="noreferrer noopener">supplemental privacy policy</a>.</p>



<p class="wp-block-paragraph">Among the clauses that apply uniquely to the new app is what happens if you eventually decide to delete it: the close architectural relationship between Threads and Instagram means users who choose to delete their Threads account will also be forced to delete their Instagram account, as well.</p>



<p class="wp-block-paragraph">For additional details on competitors’ privacy policies, check out the following links:</p>



<ul class="wp-block-list">
<li><a href="https://twitter.com/en/privacy" target="_blank" rel="noreferrer noopener">Twitter</a></li>



<li><a href="https://mastodon.social/privacy-policy" target="_blank" rel="noreferrer noopener">Mastodon</a></li>



<li><a href="https://www.hivesocial.app/privacy" target="_blank" rel="noreferrer noopener">Hive Social</a></li>



<li><a href="https://post.news/about/privacy_policy" target="_blank" rel="noreferrer noopener">Post News</a></li>



<li><a href="https://www.spill.com/privacy-policy" target="_blank" rel="noreferrer noopener">Spill</a></li>
</ul>



<h3 class="wp-block-heading">DEVELOPERS TAKE NOTE</h3>



<p class="wp-block-paragraph">If your business – like ours – involves software development, this issue is critically important. Consider the following best practices to limit your exposure to data-related concerns throughout the software development lifecycle:</p>



<ol class="wp-block-list">
<li><strong>Implement strong data protection measures.</strong>&nbsp;Encrypt critical data at every step of the process, including processing, transmission, and storage. Incorporate secure protocols such as TLS (HTTPS) when developing for the web. Bolster access controls with two-factor authentication (2FA) and/or multi-factor authentication (MFA).</li>



<li><strong>Follow Privacy by Design principles throughout the development process.</strong>&nbsp;Don’t just tack data privacy on at the end of the project. Consider it right from the outset, then assess and reassess at every major decision point throughout the development process. Instead of casting the widest possible data collection net, minimize data collection and retention by focusing only on what is essential to meet the documented business needs – nothing more – and ensure end-user consent is both explicit and transparent.</li>



<li><strong>Sanitize your data inputs.</strong>&nbsp;Do not use any user and third-party data that hasn’t been sanitized by your software to&nbsp;<a href="http://imgs.xkcd.com/comics/exploits_of_a_mom.png" target="_blank" rel="noopener" title="">avoid SQL injection</a>&nbsp;and/or Cross-Site Scripting (XSS) attacks.</li>



<li><strong>Regularly conduct penetration testing and security audits</strong>&nbsp;to better identify vulnerabilities and minimize the risks of potential security breaches. Incorporate third-party input into development and maintenance efforts to provide unbiased guidance and rapid resolution of identified weaknesses.</li>



<li><strong>Build transparent privacy policies</strong>&nbsp;clearly outlining how end-user data is collected, why it is collected, how it is used, who has access to it, and the context within which it is shared. Publish these policies in easily accessible locations, including the app itself, the app store, and your website. Maintain ongoing communication to update stakeholders on future policy updates.</li>



<li><strong>Use role-based access controls</strong>&nbsp;to limit access to sensitive data only to those individuals who need it for their jobs. Conduct regularly scheduled assessments to review the role matrix and revoke accesses as needs evolve.</li>



<li><strong>Ensure data is anonymized, wherever possible,</strong>&nbsp;to limit the risk of exposure. Where possible, remove identifiers or replace them with artificial identifiers like tokens to protect individual privacy while maintaining the utility of aggregated data.</li>



<li><strong>Implement robust patch management processes</strong>&nbsp;to ensure security and feature updates are efficiently deployed to stakeholder devices and systems. Review analytics to measure compliance and adjust processes as needed. Maintain thorough and frequent communications with the end-user community to ensure no one is running outdated – and possibly vulnerable – code.</li>



<li><strong>Audit third-party partners</strong>&nbsp;to ensure their products and platforms – such as APIs and SDKs – are built to the same security standards as the rest of your own homegrown solutions. Hold partners to the same privacy and data stewardship standards you’ve outlined in your own privacy policies.</li>



<li><strong>Train your people.</strong>&nbsp;Data privacy is only as effective as the people who are responsible for it. Ensure you and your entire development team have access to regular training to stay current with the latest best practices and privacy regulations.&nbsp;</li>
</ol>



<h3 class="wp-block-heading">THE BOTTOM LINE&nbsp;</h3>



<p class="wp-block-paragraph">The arrival of Threads is prompting long-overdue discussions around digital privacy and the risks associated with oversharing on social media platforms. This is a healthy process that spotlights developer accountabilities when building software – as well as best practices software development professionals need to follow to minimize the potential for data leakage – and damage to the brand.</p>



<p class="wp-block-paragraph">If you’re looking for answers in your own privacy journey, <a href="/contact-us" title="">give us a call</a>. </p><p>The post <a href="https://www.stepsoftware.com/threads-privacy-policies-reveal-need-for-better-development-best-practices/">Threads privacy policies reveal need for better development best practices</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.stepsoftware.com/threads-privacy-policies-reveal-need-for-better-development-best-practices/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>TikTok bans are a long overdue wakeup call for mobile security</title>
		<link>https://www.stepsoftware.com/tiktok-bans-are-a-long-overdue-wakeup-call-for-mobile-security/</link>
					<comments>https://www.stepsoftware.com/tiktok-bans-are-a-long-overdue-wakeup-call-for-mobile-security/#respond</comments>
		
		<dc:creator><![CDATA[STEP Software]]></dc:creator>
		<pubDate>Tue, 07 Mar 2023 15:22:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[ban]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[mobilesapps]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[tiktok]]></category>
		<guid isPermaLink="false">https://stringn.com/ssweb/?p=1630</guid>

					<description><![CDATA[<p>On the surface, TikTok is a popular video sharing app where cool kids gather virtually to share the latest viral content, from dance videos to memes and challenges.</p>
<p>It is as seemingly trivial as a socially enabled app can be.</p>
<p>Yet, after the Canadian government’s decision to ban the app on all federal employee devices, businesses everywhere must ask themselves a simple question: should their employees be allowed to use TikTok on their company devices? Or, should they follow the government’s lead and issue their own removal notice?</p>
<p>The post <a href="https://www.stepsoftware.com/tiktok-bans-are-a-long-overdue-wakeup-call-for-mobile-security/">TikTok bans are a long overdue wakeup call for mobile security</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="wp-block-heading">A GATHERING STORM</h3>



<p class="wp-block-paragraph"><a href="https://www.canada.ca/en/treasury-board-secretariat/news/2023/02/statement-by-minister-fortier-announcing-a-ban-on-the-use-of-tiktok-on-government-mobile-devices.html">The Canadian move</a>&nbsp;echoes similar moves in recent weeks by the&nbsp;<a href="https://www.reuters.com/technology/us-house-panel-approves-bill-give-biden-power-ban-tiktok-2023-03-01/">U.S. government</a>, the&nbsp;<a href="https://www.aljazeera.com/news/2023/2/28/european-parliament-to-ban-tiktok-from-staff-phones-eu-official">European Union</a>, and at least&nbsp;<a href="https://www.kcra.com/article/tiktok-access-from-government-devices-states-crack-down/42524357">half of all American states</a>. It falls short of a full-on national ban, however such legislation has been proposed in the U.S. Nevertheless, this marks a serious foreign policy rebuke from Canada to China.</p>



<p class="wp-block-paragraph">The growing global turbulence around TikTok reinforces the disparity between its populist perception as a non-threatening app, and accusations that it represents a major security threat on a personal, organizational, and national level. If we were talking about any other app, it would be a no-brainer: delete it outright and get on with our lives. But TikTok has become Gen Z’s de facto digital gathering place. Kicking its algorithmically fed habit won’t be as easy as simply quitting the platform, and the ripple effects could have a far-reaching economic impact.</p>



<h3 class="wp-block-heading">A FIRST AND FINAL WARNING FOR BUSINESSES</h3>



<p class="wp-block-paragraph">While this particular action by the Canadian government targets this one particular app, on federally issued devices, it really serves as a sobering warning to businesses, as well. More bluntly, if this specific app is worrisome to the feds, then it should be worrisome to everyone else, too.&nbsp;</p>



<p class="wp-block-paragraph">In fact, organizations whose employees use mobile devices for work – in essence, all of them – are now on notice that their corporate security could be exposed to unnecessary risk simply because workers decided to watch a viral video, or two, or ten, during their break.</p>



<p class="wp-block-paragraph">In fairness to TikTok, all apps, particularly social media ones, engage in data harvesting to a certain degree. They all ask for certain accesses and permissions – camera, mic, contacts, location information, etc. – upon installation, ostensibly to feed the multibillion-dollar marketing machine that underpins the digital economy. But most users are too focused on getting on with their day to fully read and appreciate what they’re consenting to, or the privacy implications of that consent.</p>



<p class="wp-block-paragraph">But TikTok presents two unique concerns for businesses. First, it collects far more data than equivalent social media apps. Second, unlike most American-owned social platforms, TikTok is owned by a Chinese company, ByteDance. And as Chinese companies are all required by Chinese law to hand over data if the Chinese government requests it, it presents the very real risk that an employee’s lunchtime video habit could lead directly to corporate data ending up on a Chinese server and accessed by Chinese government officials. From a cybersecurity standpoint, this is terrifying!</p>



<p class="wp-block-paragraph">This is no longer about delivering targeted ads to sell us stuff we never asked for. It’s about a foreign government with a troubling human rights track record potentially getting its hands on our organizational secrets.</p>



<p class="wp-block-paragraph">Now, ByteDance rather&nbsp;<a href="https://newsroom.tiktok.com/en-us/statement-on-tiktoks-content-moderation-and-data-security-practices">vehemently denies</a>&nbsp;end-user data is stored in China. Senior leaders have said data from North American users is&nbsp;<a href="https://newsroom.tiktok.com/en-us/delivering-on-our-us-data-governance">stored on servers in the U.S. and in Singapore</a>. They further deny they have any deal with the Chinese government, or that they’ve ever been asked to hand over data. They say if they were asked, they would refuse.</p>



<p class="wp-block-paragraph">But&nbsp;<a href="https://www.buzzfeednews.com/article/emilybakerwhite/tiktok-tapes-us-user-data-china-bytedance-access">audio recordings leaked</a>&nbsp;from dozens of internal TikTok meetings last year showed employees in China repeatedly accessed data via a number of backdoors built into the platform.</p>



<p class="wp-block-paragraph">Should organizations, then, trust that their data isn’t being stored and shared within Chinese borders? No. Should they worry that TikTok-using employees are making it possible at all for the data to be shared in the first place? Absolutely.</p>



<h3 class="wp-block-heading">A LONG OVERDUE CONVERSATION</h3>



<p class="wp-block-paragraph">To be fair, every app represents a potential source of data leakage. While TikTok’s uniquely data-hungry architecture and the geography of its ownership may raise the stakes, the broader issue – where all apps deserve tighter scrutiny – should rank higher on corporate IT’s radar than it currently does.</p>



<p class="wp-block-paragraph">Organizations that establish well-understood frameworks around appropriate mobile app usage will stay ahead of this fast-evolving threat. Acceptable use policies should clearly define what can and cannot be installed on an organizationally provided device. Similar frameworks should also be implemented for employee-owned devices that are used to access organizational resources.</p>



<p class="wp-block-paragraph">Apps should be approved based on a simple ROI basis: if the benefit to the business outweighs the risks and related drawbacks of having apps on the device in the first place, then they deserve to be considered in-scope. Similarly, it may turn out that some roles justify certain apps being installed, while others do not. For example, marketing employees responsible for maintaining an organization’s social media presence may have a legitimate reason to use TikTok. But an accountant who just wants to kill time in between meetings would not.&nbsp;</p>



<h3 class="wp-block-heading">THE BOTTOM LINE</h3>



<p class="wp-block-paragraph">Whatever the role or the use case, apps that present a clear a present danger to organizational data integrity need to be identified and carefully managed – if not outright banned. Organizations can rein in some app-related risks by dialing back the security settings on end-user devices. It is almost never an all-or-nothing proposition: most apps will continue to work – albeit somewhat less conveniently – even if data tracking and location awareness are deactivated.</p>



<p class="wp-block-paragraph">It isn’t realistic to expect over a billion people worldwide to suddenly quit TikTok cold turkey. But the rising tide of restrictive new rules being enacted by governments around the world should give pause to business leaders concerned about the pervasive risks of unchecked app use by their employees.</p>



<p class="wp-block-paragraph">At the very least, it should spark an initial conversation. As a next step, organizations would do well to start tightening their end-user security profiles as they work to educate employees to the risks these seemingly benign apps present.</p>



<p class="wp-block-paragraph">In fact, there’s nothing benign about them, and the TikTok controversy should serve as a stark reminder to organizations to start taking cybersecurity a lot more seriously than they have been to-date.</p>



<p class="wp-block-paragraph">Our STEP Software experts work closely every day with clients to identify risk areas within their software estates, then reliably address any gaps. <a href="/contact-us" title="">Reach out</a> if you’d like to discuss your own end-user needs.</p><p>The post <a href="https://www.stepsoftware.com/tiktok-bans-are-a-long-overdue-wakeup-call-for-mobile-security/">TikTok bans are a long overdue wakeup call for mobile security</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.stepsoftware.com/tiktok-bans-are-a-long-overdue-wakeup-call-for-mobile-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Privacy Concerns: New Technology to Grade Meetings Through Surveillance of Attendees</title>
		<link>https://www.stepsoftware.com/privacy-concerns-new-technology-to-grade-meetings-through-surveillance-of-attendees/</link>
					<comments>https://www.stepsoftware.com/privacy-concerns-new-technology-to-grade-meetings-through-surveillance-of-attendees/#respond</comments>
		
		<dc:creator><![CDATA[STEP Software]]></dc:creator>
		<pubDate>Thu, 04 Mar 2021 19:36:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[enterprise software]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://stringn.com/ssweb/?p=1747</guid>

					<description><![CDATA[<p>Like it or not, data collection technology is pervasive. Your online activities and purchases are tracked. Your travels are monitored, and your location history is stored. Cameras regularly capture your image in public places. Now, technology recently patented by Microsoft for the stated purpose of improving meeting efficiency in the workplace may soon be monitoring the effectiveness of your behaviour at work. The collected data is then used to evaluate meeting participants' body language and analyze the data collected to determine whether or not they are making significant contributions to the meetings they attend. Although this technology is still in its infancy and there are currently no indications of when, or even if, Microsoft plans to make it available for deployment in the workplace, concerns have been raised that it crosses a line and that, if widely implemented, it could result in changes that will negatively impact a significant percentage of the working population.</p>
<p>The post <a href="https://www.stepsoftware.com/privacy-concerns-new-technology-to-grade-meetings-through-surveillance-of-attendees/">Privacy Concerns: New Technology to Grade Meetings Through Surveillance of Attendees</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="wp-block-heading">HOW IT WORKS</h3>



<p class="wp-block-paragraph">Using sensors, cameras, and software algorithms, Microsoft&#8217;s &#8220;Meeting Insight Computing System&#8221; (MICS) will collect data on each meeting participant&#8217;s body language, expressions, and participation level. MICS will also track how much time attendees spend on activities that are not meeting-related, such as texting or reading email. For remote meeting participants, MICS factors in whether or not they activate their cameras. The system will also take environmental factors into consideration, including the temperature and level of noise in a meeting room. Meeting time is also considered. A hot meeting room, a room with a distracting level of noise, or a meeting running into lunch hour could affect the attendees&#8217; levels of participation.</p>



<h3 class="wp-block-heading">THE SYSTEM&#8217;S STATED PURPOSE ACCORDING TO MICROSOFT&#8217;S PATENT FILING</h3>



<p class="wp-block-paragraph">Statements in the application filed by Microsoft with the U. S. Patent Office, available for review at patents.google.com/patent/US10735211B2/en?oq=10735211, provide detailed information about the type of data MICS collects and how MICS uses the information to evaluate the effectiveness of meetings. The application identifies shortcomings of traditional meeting scheduling tools that do not provide any input to the organizer as to whether a meeting is likely to be productive.</p>



<p class="wp-block-paragraph">Microsoft&#8217;s patent application does not provide details regarding the protection of potentially sensitive data that MICS may collect, but the fact that this is not part of the patent application does not mean that they have not considered the issue. The application simply focuses on how MICS will increase the effectiveness of meetings, not on potential issues associated with personal privacy.</p>



<h3 class="wp-block-heading">THE ARGUMENTS FOR AND AGAINST</h3>



<p class="wp-block-paragraph">Some will assert that employees who do not like being observed and evaluated by an application like MICS can simply quit and take a job elsewhere. After all, aside from evaluating the attendees&#8217; level of interest and participation, how else could technology be used to measure the effectiveness of a meeting?</p>



<p class="wp-block-paragraph">Others, however, may be concerned that the level of surveillance capabilities to be offered by MICS is excessive and that this is a slippery slope. Should its use become common in the workplace, the negative impact could be significant. An argument can be made that, because each person is different, allowing Microsoft to establish a single set of parameters by which to evaluate all meeting attendees is not appropriate. If, for example, a 25-year-old and a 60-year-old attend a meeting, chances are good that the former will check messages on his or her phone much more often than the latter, potentially indicating that the 25-year-old is distracted and not participating. Will this later be used against the younger employee? What if the younger employee was already familiar with the material being presented and doesn&#8217;t necessarily need to pay close attention? Are the algorithms used by MICS sophisticated enough to take these factors into consideration?</p>



<h3 class="wp-block-heading">CONCLUSION</h3>



<p class="wp-block-paragraph">Despite Microsoft&#8217;s assertions in the patent application that the purpose of MICS is to evaluate meetings, not employees, concern over how the employee data could be used is to be expected. Will the information collected be considered in performance evaluations? Could repeated &#8220;low participation scores&#8221; form the basis for disciplinary actions? If so, are the MICS algorithms &#8220;intelligent&#8221; enough to take into consideration the natural differences between individuals or is everyone measured based on the same set of parameters created by Microsoft developers?</p>



<p class="wp-block-paragraph">Technology impacts virtually all aspects of daily life, with data being continuously collected, shared, sold, and stolen. When systems like MICS emerge, they naturally evoke renewed concerns about the erosion of personal privacy and how much data collection is too much.</p>



<p class="wp-block-paragraph">NOTE: This article includes only a brief summary of the information in Microsoft&#8217;s patent application regarding the data MICS would collect and how the information would be evaluated. Readers interested in learning more are encouraged to review the full text of the application, publicly available online.</p><p>The post <a href="https://www.stepsoftware.com/privacy-concerns-new-technology-to-grade-meetings-through-surveillance-of-attendees/">Privacy Concerns: New Technology to Grade Meetings Through Surveillance of Attendees</a> first appeared on <a href="https://www.stepsoftware.com">STEP Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.stepsoftware.com/privacy-concerns-new-technology-to-grade-meetings-through-surveillance-of-attendees/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
