Live data from Hacker News

How did Facebook intercept their competitor's encrypted mobile app traffic?

doubleagent.net

11–20 of 222 posts

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#11
post #8
post #3

tl;dr: If you install and fully trust a root CA on your client device, of course your TLS traffic can be MITMed. edit: the problem, obviously, is that this app tricked the non-technical people into installing/trusting the root CA for malicious purposes. Clearly this was malware.

That's great for someone reading this forum to be aware of, but moms have no idea what any of the words you just wrote means. So if they were told they get a coupon for installing or some other bit of ridiculous things malware devs use, and yes I'm calling FB software malware. All of if it. Messenger, FB.app, everything. If it's from Meta, it's malicious.

That's a very good point. I have within recent memory installed my own internal CA that I run on Android devices that I own and trust, and the process on android 11+ is sufficiently daunting that 99.5% of peoples' moms could not do it in one or two clicks. You have to go deep into system settings and manually import the CA. This requires first file-transferring the CA file somewhere onto local /sdcard storage and possibly having a file system explorer app installed to be able to view its location on "disk" and pick it.

As is pointed out in the article, I would presume that Google saw the threat from allowing an app to install and trust a root CA as well, and removed the ability for a "one click" install of a root CA:

"KeyChain.createInstallIntent() stopped working in Android 7 (Nougat). A user would have to manually install the certificate. It would no longer be possible to have Facebook's CA cert installed directly in the app."

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#12
post #9
post #4

The email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's…

Billionaire bosses are all surrounded by opportunists and flatterers. Over time like the Great Pacific Garbage Patch the size of this group grows to unmanageable dimensions, cause anyone acting moderately sane will be treated as an existential threat to their lives of fantasy, domination, manipulation, luxury, leisure etc and pushed out.

Thankfully our fearless American regulators would never shy away from hanging these scoundrels out to dr- hey wait, where are the lawyers going off to?

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#13
If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file.

Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#15
post #9
post #4

The email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's…

Billionaire bosses are all surrounded by opportunists and flatterers. Over time like the Great Pacific Garbage Patch the size of this group grows to unmanageable dimensions, cause anyone acting moderately sane will be treated as an existential threat to their lives of fantasy, domination, manipulation, luxury, leisure etc and pushed out.

To paraphrase Clarke's three laws, a sufficiently advanced quantity of yes-men and tech industry bro "move fast and break things" types is indistinguishable from a hostile malware actor.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#16
post #9

Earlier quoted context omitted.

Billionaire bosses are all surrounded by opportunists and flatterers. Over time like the Great Pacific Garbage Patch the size of this group grows to unmanageable dimensions, cause anyone acting moderately sane will be treated as an existential threat to their lives of fantasy, domination, manipulation, luxury, leisure etc and pushed out.

Thankfully our fearless American regulators would never shy away from hanging these scoundrels out to dr- hey wait, where are the lawyers going off to?

The lawyers are off in the Hamptons this summer with the same people who are the root cause of the 2008 financial crisis.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#17
post #8
post #3

tl;dr: If you install and fully trust a root CA on your client device, of course your TLS traffic can be MITMed. edit: the problem, obviously, is that this app tricked the non-technical people into installing/trusting the root CA for malicious purposes. Clearly this was malware.

That's great for someone reading this forum to be aware of, but moms have no idea what any of the words you just wrote means. So if they were told they get a coupon for installing or some other bit of ridiculous things malware devs use, and yes I'm calling FB software malware. All of if it. Messenger, FB.app, everything. If it's from Meta, it's malicious.

Try comparing P2P OTR E2EE vs Non-CA TOFU SSH

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#19
post #8

Earlier quoted context omitted.

That's great for someone reading this forum to be aware of, but moms have no idea what any of the words you just wrote means. So if they were told they get a coupon for installing or some other bit of ridiculous things malware devs use, and yes I'm calling FB software malware. All of if it. Messenger, FB.app, everything. If it's from Meta, it's malicious.

Try comparing P2P OTR E2EE vs Non-CA TOFU SSH

hell, even I don't know what the "words" you just used mean!

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#20

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay?

pithy "because they have all the monies" replies not wanted.

Post reply on HN