Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

101–110 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#101
post #36

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

So this one time, I had a bug report at a client site. The business was largely a member of _______ religion. Our images wouldn't load in the app, but did on the website. How odd I thought, that doesn't make sense! Luckily I was able to be physically present, so I hopped down with laptop in tow, ssh'd into the server and started tailing logs.... Sure enough all the API requests for data were coming through, but whene…

Holy shit they can brainwash their peers even better. Those are evil geniuses….

Sorry I meant the optimize the content for their peers and shield them from harmful content for the better of humanity // irony

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#102
post #64

Earlier quoted context omitted.

If someone consents to your clear request to read their data in the plain, then it's not evil. Still not my cup of tea, but if you clearly explain and obtain consent, it's shady but fine.

So how is that relevant in the context here. FB did not clearly request to be able to read all traffic (encrypted and nonencrypted) so how could they get consent. Unless you're arguing, "we will monitor your Internet usage", clearly means we will man-in-the-middle all your connections. Which would be a weird take.

> FB did not clearly request to be able to read all traffic (encrypted and nonencrypted) so how could they get consent.

I can't find the consent page/legalese shown to users, do you have a link?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#103

Earlier quoted context omitted.

Certificate pinning and validation in apps for one. Onavo's VPN was really clear it collected market research data. It was as informed consent as a click-through could be.

Interception of encrypted communications is beyond the expectation of what most people would consider "collecting market research data"

I would expect the exact nature of the collection to be spelled out in some TOS that users probably clicked through.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#104
post #60

If an individual had somehow done this, I expect that the Computer Fraud and Abuse Act would be used against them. With Meta, we'll see.

I heard about this a few years ago. The trial participants were informed, consented, and paid. If you consent to a root cert being installed and analytics being proxied, well, that's that.

Afaik only in some instances, in some they were not paid and informed consent is in all cases quite questionable

edit: I think this is something I wouldn't call informed consent: "Of particular concern was that users as young as 13 were allowed to participate in the program. Connecticut Senator Richard Blumenthal criticized Facebook Research, stating "wiretapping teens is not research, and it should never be permissible. This is yet another astonishing example of Facebook’s complete disregard for data privacy and eagerness to engage in anti-competitive behavior.""[1]

1: https://en.m.wikipedia.org/wiki/Onavo

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#105
post #66
post #52

Earlier quoted context omitted.

I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…

Ethically minded engineers don't go work for Facebook in the first place.

This was news … 5 years ago, I think, I don’t know why it blew up again. But context matters:

Onavo provided a compression + VPN service for people traveling; they let users use little or no data while roaming, and still get internet access. I do not know what their original business plan was, but Facebook bought them for the ability to spy on users.

Their MITM was, in fact, the raison d’etre of Onavo. And then, they were bought by Facebook. And then there was just some more analytics added. At no point, as I understand it, was it built explicitly for evil - and I suspect very few employees were in on the real reasons.

Plausible deniability works for many things.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#106
post #77

Earlier quoted context omitted.

> This is such an immense breach of trust Why do you trust it ? Do you think that others (Google, Microsoft, Apple) are not doing/would not do such a thing ? SSL is as secure as its certificates.

Honestly, yes, I don't think Microsoft Google and Apple would do something like this.

Imho, the correct way to evaluate corporate potential corporate trust is on self-interest.

In Microsoft, Google, and Apple's cases, they all have substantial enterprise business that would shit a brick if they were caught doing this.

Ergo, it's not in their best interest to do it.

Safer to rely on a company's desire to make money than any sense of "good".

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#107

Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…

Can someone explain how exactly they were able to decrypt the SSL traffic, is it possible to install a root CA without huge warnings from the OS?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#108
Whatever may be the end goal, MITM is called an 'attack', not 'research'.

I'd not last a single day at such a company who would ask me to do such things. I had worked for a national political party in IT and left the job once I found about it corrupt practices and scams.

If we, as engineers collectively upheld ethics as part of work culture, Meta wouldn't have attempted it.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#109

Earlier quoted context omitted.

Two issues. 1) Did Snapchat consented to this? And 2) did the users know what they were consenting to? Saying we’re going to do “ traffic monitoring” doesn’t carry the weight of “we are going to listen to your private conversations”.

Why would Snapchat need to consent? It's my traffic. I'd wager that most participants don't know the full details of the program, but "company pays you for your usage information" is a very old thing. You could (maybe you still can) get paid to install a box on your TV that recorded all of your viewing statistics to be used for market research. To me, the biggest concern is that this is only really viable because Fac…

Here’s how I see it. This is akin to opening your USPS mail and reading your correspondence with a friend. When instead they could’ve checked who the mails were addressed.

If Facebook wanted to learn the protocol Snapchat uses, they only needed a single test device. If they only needed to learn usage patterns, they could’ve checked where the traffic is sent to or app usage time etc.

Installing a root certificate is very intrusive and they behavior shows that if they are ever given the opportunity to be become a root certificate authority, they are likely to issue malicious certificates. As far as I know, no website can pin their certificates, so this takes us back to pre-HTTPS days where ISPs and network operators had a lot of fun reading user traffic.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#110

Facebook is not removable from many android devices... does this mean Zuckerberg has been seeing all user traffic for years regardless of tls?

Yes and No. for TLS traffic you need to also install onavo. But the app does scan your contact list every couple minutes and send diffs to their servers. Even if you have never opened the app. And on previous android versions all your recently open apps list too. But again, if you install whatsapp you must give them the contact list permission anyway otherwise the app is intentionally broken and annoying.

I really think you are a fool if you install WhatsApp. I do think you are higher intelligence than normal if you install Signal. When I hear friends talk about WhatsApp I cringe. The few who have signal I regard highly.
Post reply on HN