纽约时报:震惊!tiktok员工用lark泄露用户隐私?!

Employees of the Chinese-owned video app have regularly posted user information on a messaging and collaboration tool called Lark, according to internal documents.

2 个赞

tiktok的users为什么给这些信息。

围魏救赵了 meta才被罚钱 NYT赶快whataboutism一下

3 个赞

盲猜实名以后就可以开通赚钱功能(参考OnlyFans)

1 个赞

例如各种原因联络客服,客服要的个人资料便给共享了 :wulian:

In August 2021, TikTok received a complaint from a British user, who flagged that a man had been “exposing himself and playing with himself” on a livestream she hosted on the video app. She also described past abuse she had experienced.

To address the complaint, TikTok employees shared the incident on an internal messaging and collaboration tool called Lark, according to company documents obtained by The New York Times. The British woman’s personal data — including her photo, country of residence, internet protocol address, device and user IDs — were also posted on the platform, which is similar to Slack and Microsoft Teams.

Her information was just one piece of TikTok user data shared on Lark, which is used every day by thousands of employees of the app’s Chinese owner, ByteDance, including by those in China. According to the documents obtained by The Times, the driver’s licenses of American users were also accessible on the platform, as were some users’ potentially illegal content, such as child sexual abuse materials. In many cases, the information was available in Lark “groups” — essentially chat rooms of employees — with thousands of members.

这真是草台得可以
所以个人资料都共享给北京字节员工了 :yaoming:

The profusion of user data on Lark alarmed some TikTok employees, especially since ByteDance workers in China and elsewhere could easily see the material, according to internal reports and four current and former employees. Since at least July 2021, several security employees have warned ByteDance and TikTok executives about risks tied to the platform, according to the documents and the current and former workers.

“Should Beijing-based employees be owners of groups that contain secret” data of users, one TikTok employee asked in an internal report last July.

“Lark shows you that all the back-end processes are overseen by ByteDance,” he said. “TikTok is a thin veneer on ByteDance.”

ByteDance introduced Lark in 2017. The tool, which has a Chinese-only equivalent known as Feishu, is used by all ByteDance subsidiaries, including TikTok and its 7,000 U.S. employees. Lark features a chatting platform, videoconferencing, task management and document collaboration features. When Mr. Chew was asked about Lark in the March hearing, he said it was like “any other instant messaging tool” for corporations and compared it to Slack.

2 个赞

这种是为了工程师解决case吧。不给信息怎么办呢?
端对端加密?

3 个赞

想像 Amex 要关卡,online chat 客服要求直接明文报 driver license
还把 license 分享到 amex 工作 slack channel 上
可以接受这种情况吗? :wulian:

工程师要解决 case 只要 user id 和 error message
不用给 PII

country of residence, internet protocol address, device and user IDs
这几个东西,任何一个packet里都有。这种算啥personal info

再说,万一是几个group不同的engineers在讨论怎么解决呢?

她的 case 是投诉另一用户
要处理问题不需要她任何个人资料,把她资料发到工作群组没有合理解释

In August 2021, TikTok received a complaint from a British user, who flagged that a man had been “exposing himself and playing with himself” on a livestream she hosted on the video app

仔组看内文
分享的有 driver’s licenses 这些东西

就算需要他个人资料 这种PII也是Need to know based, 而不是随便发到上千人的聊天群

1 个赞

agreed。我看不了全文。只能看到前面的一小段大概猜一下。以为是triage network issue之类的。

2 个赞

是的 我看到paywall 就退出了 :cry:

1 个赞

虽然知道这个公司对隐私都是不存在的态度,也知道李罗宾的言论是有群众基础的,但是作为数据工作者还是非常震惊TT居然在风口上干这种事情……

只能说涉及隐私的问题最好就是别让中国团队碰,因为法制和文化里就不存在隐私保护

3 个赞

全文
https://archive.is/EJ7dT

1 个赞

妥妥的违反了欧洲的GDPR,啥时候罚钱呢?