June 4, 2024 By Jennifer Gregory 3 min read

President Joe Biden signed a bill on April 24, 2024, giving Byte Dance, the Chinese parent company of TikTok, two options: sell TikTok within nine months or face a ban on the app in the United States.

The bill comes after years of concerns that the app increases cybersecurity risk. In March 2024, the House passed a bill banning TikTok, but it was not passed by the Senate. However, in April, Speaker Mike Johnson included the House TikTok bill into a $95 billion foreign aid supplemental plan.

DoD details TikTok cybersecurity concerns

An April 2024 release from the Department of Defense details the federal government’s reasons for putting a ban into action. John F. Plumb, the Assistant Secretary of Defense for Space Policy and Principal Cyber Advisor to the Secretary of Defense, describes TikTok as a potential threat vector to the United States. Unlike American-based social media platforms, the Chinese government states that they will touch data from the platform at any time. According to Plumb, China has used its cyber capabilities to steal sensitive information, intellectual property and research from U.S. public- and private-sector institutions, including the defense industrial base, for decades.

“Chinese cyber intrusions are the most prolific in the world. In crisis, PRC [China’s] leaders believe that achieving information dominance will enable them to seize and keep the strategic initiative, disrupt our ability to mobilize, to project and sustain the joint force and to ensure the PRC’s desired end state,” Plumb said.

Additionally, the concern has increased due to the large number of people using the application. Every day, 150 million users access the app, which equates to one-third of adults and one-sixth of kids. In addition to entertainment and funny videos, many people use TikTok for news and product endorsements, which means the app has a wide influence on users. Army General Paul M. Nakasone, Commander of U.S. Cyber Command, Director of the National Security Agency and Chief of the Central Security Service, said the wide usage provides a foreign nation with a platform for information operations and surveillance and raises concerns in regards to who controls that data.

Review threat detection & response solutions

What happens next with the bill

The bill faces significant challenges, including legal challenges, anti-trust hurdles and public backlash. According to experts, the ban could take years to go into effect if it does. Additionally, questions remain about the FTC’s ability to be involved in the approval of a sale of the company.

Shou Zi Chew, TikTok’s CEO, stated that the company would begin legal challenges to the bill. In a TikTok post, Chew said, “Make no mistake, this is a ban, a ban on TikTok and a ban on you and your voice… We are confident, and we will keep fighting for your rights in the courts. The facts and the Constitution are on our side, and we expect to prevail.” He went on to tell users to share stories about how TikTok impacts their lives to showcase exactly what they are fighting for.

As the bill is written, it will not be illegal for U.S. citizens to have the TikTok app on their phones or to use the social media platform in the country. However, people will no longer be able to download the app from the United States. According to Time, users will still be able to use the app but will not be able to update the app with new versions, security patches and bug fixes, which means that the app will eventually not be usable or secure. While it may be possible to perform these functions over a Virtual Private Network, there are questions about this workaround.

Although a bill has been signed, it will not take effect for at least nine months from now. United States users can still download the app in the country without issue. However, TikTok users should continue to monitor the progress and news regarding the bill.

More from News

Insights from CISA’s red team findings and the evolution of EDR

3 min read - A recent CISA red team assessment of a United States critical infrastructure organization revealed systemic vulnerabilities in modern cybersecurity. Among the most pressing issues was a heavy reliance on endpoint detection and response (EDR) solutions, paired with a lack of network-level protections. These findings underscore a familiar challenge: Why do organizations place so much trust in EDR alone, and what must change to address its shortcomings? EDR’s double-edged sword A cornerstone of cyber resilience strategy, EDR solutions are prized for…

DHS: Guidance for AI in critical infrastructure

4 min read - At the end of 2024, we've reached a moment in artificial intelligence (AI) development where government involvement can help shape the trajectory of this extremely pervasive technology. In the most recent example, the Department of Homeland Security (DHS) has released what it calls a "first-of-its-kind" framework designed to ensure the safe and secure deployment of AI across critical infrastructure sectors. The framework could be the catalyst for what could become a comprehensive set of regulatory measures, as it brings into…

Apple Intelligence raises stakes in privacy and security

3 min read - Apple’s latest innovation, Apple Intelligence, is redefining what’s possible in consumer technology. Integrated into iOS 18.1, iPadOS 18.1 and macOS Sequoia 15.1, this milestone puts advanced artificial intelligence (AI) tools directly in the hands of millions. Beyond being a breakthrough for personal convenience, it represents an enormous economic opportunity. But the bold step into accessible AI comes with critical questions about security, privacy and the risks of real-time decision-making in users’ most private digital spaces. AI in every pocket Having…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today