How did Facebook intercept their competitor's encrypted mobile app traffic?
1–10 of 222 posts
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#2There has to be a court precedent that criminalized sniffing network traffic on the customer’s side.
Should be one of those many cases involving wiretapping for banking info.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#3edit: the problem, obviously, is that this app tricked the non-technical people into installing/trusting the root CA for malicious purposes. Clearly this was malware.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#4Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#5Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#6Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#7tl;dr: If you install and fully trust a root CA on your client device, of course your TLS traffic can be MITMed. edit: the problem, obviously, is that this app tricked the non-technical people into installing/trusting the root CA for malicious purposes. Clearly this was malware.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#8tl;dr: If you install and fully trust a root CA on your client device, of course your TLS traffic can be MITMed. edit: the problem, obviously, is that this app tricked the non-technical people into installing/trusting the root CA for malicious purposes. Clearly this was malware.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#9The email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's…
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#10[flagged]