Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…
Can someone explain how exactly they were able to decrypt the SSL traffic, is it possible to install a root CA without huge warnings from the OS?
Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
121–130 of 189 posts
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#122Earlier quoted context omitted.
Why would Snapchat need to consent? It's my traffic. I'd wager that most participants don't know the full details of the program, but "company pays you for your usage information" is a very old thing. You could (maybe you still can) get paid to install a box on your TV that recorded all of your viewing statistics to be used for market research. To me, the biggest concern is that this is only really viable because Fac…
That box on your TV would have been a Nielsen box which sat on your TV and was connected to your landline. It didn’t collect anything automatically: every time you turned the TV on you were contractually obligated to press a button every 20 minutes to have the box call Nielsen and log a datapoint. Those boxes have been phased out in favour of “Personal People Meters”[0], which are basically a pager with a SIM card th…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#123"Meta" is The Evil Online Empire at this point, it's company history is a litany is decidedly immoral if not outright evil actions.
Meta is a known state-actor. They likely have federal immunity to most wrong-doings. (Source: https://www.vice.com/en/article/v7gd9b/facebook-helped-fbi-h... )
I hate FB, but all big platforms these days will cooperate with federal agencies in cases like the one described. Doesn't make them "state actors".
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#124Whatever may be the end goal, MITM is called an 'attack', not 'research'. I'd not last a single day at such a company who would ask me to do such things. I had worked for a national political party in IT and left the job once I found about it corrupt practices and scams. If we, as engineers collectively upheld ethics as part of work culture, Meta wouldn't have attempted it.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#125Earlier quoted context omitted.
Two issues. 1) Did Snapchat consented to this? And 2) did the users know what they were consenting to? Saying we’re going to do “ traffic monitoring” doesn’t carry the weight of “we are going to listen to your private conversations”.
Why would Snapchat need to consent? It's my traffic. I'd wager that most participants don't know the full details of the program, but "company pays you for your usage information" is a very old thing. You could (maybe you still can) get paid to install a box on your TV that recorded all of your viewing statistics to be used for market research. To me, the biggest concern is that this is only really viable because Fac…
Now, Meta decides to MITM the communications that I intentionally encrypted so that it can gain a competitive advantage…well, remember when meta kicked out researchers what had obtained consent from users to perform research on its platform? That was not even illegal. This is.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#126Earlier quoted context omitted.
Can someone explain how exactly they were able to decrypt the SSL traffic, is it possible to install a root CA without huge warnings from the OS?
By using mitm, basically "pretending" you're the site the victim wants to connect to and trasparently connecting to the actual upstream site. Basically decrypting the traffic locally for inspection before sending it back out. https://en.wikipedia.org/wiki/Man-in-the-middle_attack . You don't need a root CA, you just need to poison the DNS to point to the mitm server and just present any old valid cert for the domain…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#127Earlier quoted context omitted.
That box on your TV would have been a Nielsen box which sat on your TV and was connected to your landline. It didn’t collect anything automatically: every time you turned the TV on you were contractually obligated to press a button every 20 minutes to have the box call Nielsen and log a datapoint. Those boxes have been phased out in favour of “Personal People Meters”[0], which are basically a pager with a SIM card th…
Had them here in the UK, used to get a free TV license for the inconvenience. My mate always pressed the same button despite what channel we were watching though, so there is that...
“They like Itchy, they like Scratchy, one kid seems to love the Speedo man… what more do they want?"
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#128Earlier quoted context omitted.
Why would Snapchat need to consent? It's my traffic. I'd wager that most participants don't know the full details of the program, but "company pays you for your usage information" is a very old thing. You could (maybe you still can) get paid to install a box on your TV that recorded all of your viewing statistics to be used for market research. To me, the biggest concern is that this is only really viable because Fac…
They would because the communications involve 2 parties. Your consent to someone snooping on my calls with you should not be enough, because for example, you still need my consent to record calls I have with you. Now, Meta decides to MITM the communications that I intentionally encrypted so that it can gain a competitive advantage…well, remember when meta kicked out researchers what had obtained consent from users to…
The whole thing's a mess, but it's funny to me that people would get indignant over a user letting another party intercept analytics data. "Hey, that's my data from spyware! Get your own!" As if their "consent" to collect the data in the first place were any less flimsy than Facebook's.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#129Earlier quoted context omitted.
Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't t…
It's not corporate level it was/is religious group level (of which this particular org I'm guessing largely employed staff from that religion). They are well known within our country to be quite insular. It certainly seemed for all intents and purposes if you were a member of _____ group (wider than the company) you had the vpn on your device, and it was filtering content. I've found other reports in other countries…
You could imagine a standard for a network to signal to a client that it does not allow certain privacy features like ECH, and then clients can accept that or not. Instead I expect browsers will eventually mandate ECH, so people will have to MITM instead.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#130Earlier quoted context omitted.
Ah, good 'ole trustworthy Swiss companies! Like Crypto AG![1] Realistically, all VPNs are compromised. But for most people's threat model, that's irrelevant anyways. Proton for instance revealed the location of a climate activist leading to his arrest[2], with the inspiring message from the CEO that "privacy protections can be suspended", silently on a per-user basis at any time. Haven't seen anything like that for M…
> Proton for instance revealed the location of a climate activist leading to his arrest[2], with the inspiring message from the CEO that "privacy protections can be suspended", silently on a per-user basis at any time. That person isn't just a climate activist, they (and others who used that email account) broke French laws. Swiss authorities compelled the disclosure.
That's a terrible reason. Torrenting breaks French law. Having the wrong bread or cheese with your wine probably breaks French law.
And if your company can be compelled via gag order to give up your users' privacy whenever the authorities feel like it, well, your product isn't very effective anyways, and you should stop pretending you offer any meaningful level of protection.