Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

111–120 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#111
post #83
post #7

So, the FANGs can conduct mass psyops warfare against the populace basically with impunity -- a pesky little suit now and then is inconsequential. But what will happen when they get caught stealing each other's surveillance booty?

Bear in mind that they don’t applied this to everyone, which would be practically impossible. They hired Snapchat users (via a testing services provider ) to let meta observe their usage of Snapchat. Something akin to paying someone to let a meta researcher sit by your side and observe while you use the app. This happens all the time (hiring the testing services to recruit users to use your own app and analyze the pa…

> They hired Snapchat users (via a testing services provider ) to let meta observe their usage of Snapchat.

> Something akin to paying someone to let a meta researcher sit by your side and observe while you use the app.

Onavo Extend and Onavo Protect positioned themselves as providing consumer-oriented benefits (bandwidth reduction and security, respectively).

> The news here is paying for someone to “test” a competitors’ app.

Facebook acquired Onavo in 2013, so this was 100% a first-party effort to turn their first-party products into spyware.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#112
post #36

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

So this one time, I had a bug report at a client site. The business was largely a member of _______ religion. Our images wouldn't load in the app, but did on the website. How odd I thought, that doesn't make sense! Luckily I was able to be physically present, so I hopped down with laptop in tow, ssh'd into the server and started tailing logs.... Sure enough all the API requests for data were coming through, but whene…

There are even ‘safe’ (filtered) ISPs aimed at religious communities.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#114

Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…

[deleted]

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#116

Earlier quoted context omitted.

Two issues. 1) Did Snapchat consented to this? And 2) did the users know what they were consenting to? Saying we’re going to do “ traffic monitoring” doesn’t carry the weight of “we are going to listen to your private conversations”.

Why would Snapchat need to consent? It's my traffic. I'd wager that most participants don't know the full details of the program, but "company pays you for your usage information" is a very old thing. You could (maybe you still can) get paid to install a box on your TV that recorded all of your viewing statistics to be used for market research. To me, the biggest concern is that this is only really viable because Fac…

That box on your TV would have been a Nielsen box which sat on your TV and was connected to your landline. It didn’t collect anything automatically: every time you turned the TV on you were contractually obligated to press a button every 20 minutes to have the box call Nielsen and log a datapoint.

Those boxes have been phased out in favour of “Personal People Meters”[0], which are basically a pager with a SIM card that you wear which has a microphone listening 24/7 for TV broadcasts. You must keep it on you, listening at all times.

Nielsen will pay you $250/year (less than a dollar a day) for the data you provide.

[0] https://en.wikipedia.org/wiki/Portable_People_Meter

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#117
post #110

Earlier quoted context omitted.

Yes and No. for TLS traffic you need to also install onavo. But the app does scan your contact list every couple minutes and send diffs to their servers. Even if you have never opened the app. And on previous android versions all your recently open apps list too. But again, if you install whatsapp you must give them the contact list permission anyway otherwise the app is intentionally broken and annoying.

I really think you are a fool if you install WhatsApp. I do think you are higher intelligence than normal if you install Signal. When I hear friends talk about WhatsApp I cringe. The few who have signal I regard highly.

Real life is full of compromises. If your grandma is on WhatsApp, and you want to talk to her, it might be a good idea to install WhatsApp.

(However, if you have time on your hand and principles, you can use WhatsApp on a burner phone, I guess?)

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#118
post #117
post #110

Earlier quoted context omitted.

I really think you are a fool if you install WhatsApp. I do think you are higher intelligence than normal if you install Signal. When I hear friends talk about WhatsApp I cringe. The few who have signal I regard highly.

Real life is full of compromises. If your grandma is on WhatsApp, and you want to talk to her, it might be a good idea to install WhatsApp. (However, if you have time on your hand and principles, you can use WhatsApp on a burner phone, I guess?)

Or educate grandma on why she should use signal and that fools use WhatsApp since meta is balls deep inside the app and watching what you do.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#120
post #52

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…

I was directly involved in this.

I am happy to answer any questions you have about questioning or ethics at the time. Assuming that people's reaction to this was wrong, while not knowing what that reaction was, or having less than 5% of the context, isn’t going to help much.

Short answer: No, there were strong arguments for it. I reached out for institutional support to answer some questions, groups that I expected to be a lot more supportive than the ACM, but I found the reaction seriously lacking. Your intuition that groups like the ACM should offer assistance is sensible but completely overlooks many problems: geopolitics, different types of security, and individual capacities, among others. Each institution has its priorities; those are not always compatible, and it’s unclear who should have precedence. The ACM won’t help you if the argument is the kind of compromise with the devil that spy agencies often make or if problematic tools are used in efforts to dismantle large criminal groups.

Post reply on HN