Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

11–20 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#12

Facebook is not removable from many android devices... does this mean Zuckerberg has been seeing all user traffic for years regardless of tls?

Yes and No.

for TLS traffic you need to also install onavo.

But the app does scan your contact list every couple minutes and send diffs to their servers. Even if you have never opened the app. And on previous android versions all your recently open apps list too.

But again, if you install whatsapp you must give them the contact list permission anyway otherwise the app is intentionally broken and annoying.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#14
So was the plan to just yolo this out into the wild?

because the document says here that it was going to be given to trial participants as part of yougov(and others) survey. Which implies that they would have been informed/paid.

If its the former, then obviously thats unauthorised wiretapping. If its the latter so long as informed consent is given, that a shittonne better that the advertising tech we have now.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#17

So how can we be sure now that todays VPNs are not tomorrows Onavos. :(

Certificate pinning and validation in apps for one. Onavo's VPN was really clear it collected market research data. It was as informed consent as a click-through could be.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#18

So how can we be sure now that todays VPNs are not tomorrows Onavos. :(

First, all VPNs spy on you, just don't believe these claims because they are forced by law to do it. Second, don't use a VPN that clearly states that they're analyzing your traffic data.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#19
There's a lot of confusion around these stories these days, which reminds me of the "Gmail is looking at your emails" stories[1].

First, this is not wiretapping, come on. There's targeted man-in-the-middle (MITM) attacks, and then there's this. This is plainly "we are using advanced powers to analyze your traffic".

This is not even Superfish[2] type of stuff, where Lenovo had preinstalled root certs onto laptops to display ads. This is "if you opt in we will analyze your data".

Every program you install on your laptop can basically do WHATEVER it wants. This is how viruses work. When you install a program, you agree to give it ALL power. This is true on computers generally, and this is true on phones when you side-load programs. The key is that when we install something we understand the type of program we're installing, and we trust that the program doesn't do more than what it _claims to be doing_.

So the question here is not "how does Onavo manage to analyze traffic that's encrypted", it's "does Onavo abuses the trust and the contract it has with its users?"

[1]: https://variety.com/2017/digital/news/google-gmail-ads-email...

[2]: https://www.virusbulletin.com/blog/2015/02/lenovo-laptops-pr...

Post reply on HN