Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

131–140 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#131
post #13

What do you think Cloudflare is doing with its SSL termination/offloading?

The difference is that people* know and accept that CloudFlare does this. They advertise it as a feature. *most willing customers of CloudFlare.

Users cannot consent to Cloudflare seeing their traffic and it's not an issue.

Users consent to Facebook seeing their traffic and it's suddenly a problem?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#132
post #95
post #61

Isn't this known since 2018? https://mashable.com/article/facebook-used-onavo-vpn-data-to...

Yes it's old news(1) but it has come up again in numerous HN and reddit posts for a few reasons (if you flick through HN you'll see various versions of this story holding lower ranks.) Also noteworthy is that Google were also doing something similar at the time, both were side-stepping Apple's privacy protections in iOS by using enterprise certificates that allowed the side-loading of apps without Apple's overview. I…

> To me, it's wild to think that people on HN don't know about this relatively recent history and are so naive to think that these protections were just pulled out of the air to frustrate developers,

IMO we have modern journalism to thank for this sort of thing. People are so misinformed with rage bait articles that they push against policies in their own interest.

But if anyone dare suggest enforcing some minimum level of journalistic ethics they'll get attacked because somehow journalists have painted themselves as some sort of unassailable paragon of righteousness.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#133
post #110

Earlier quoted context omitted.

Yes and No. for TLS traffic you need to also install onavo. But the app does scan your contact list every couple minutes and send diffs to their servers. Even if you have never opened the app. And on previous android versions all your recently open apps list too. But again, if you install whatsapp you must give them the contact list permission anyway otherwise the app is intentionally broken and annoying.

I really think you are a fool if you install WhatsApp. I do think you are higher intelligence than normal if you install Signal. When I hear friends talk about WhatsApp I cringe. The few who have signal I regard highly.

Security SWE here. I have worked with WhatsApp's security engineers, I donate hundreds to the Signal Foundation every year, and I like to think I have a good amount of experience by now in the security industry.

> you are a fool if you install WhatsApp [...] meta is balls deep inside the app and watching what you do.

WhatsApp uses the same protocols as Signal under the hood. The Signal team even helped WhatsApp implement it. Furthermore, the app has been extensively RE'd by third parties to validate it's doing what it says on the tin.

https://signal.org/blog/whatsapp-complete/

> When I hear friends talk about WhatsApp I cringe. The few who have signal I regard highly.

Your clear lack of knowledge on the subject matter combined with your judgement of others says far more about you than your friends. It seems that you have fallen victim to the Dunning-Kruger curve, so consider not judging people until that is rectified.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#134

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

Here is what is going to happen: 1. Nobody will care in 10 days. 2. They will get a slap on the wrist at best. Reminds me of Google driving around in StreetView cars, hacking and capturing all wifi traffic they could get their hands on. Did anything happen? Of course not! https://www.theguardian.com/technology/2010/may/15/google-ad... https://www.wired.com/2012/05/google-wifi-fcc-investigation/ The guardian says "ope…

I did not really need a reminder that this website is filled with morons, just like Reddit. But I get it anyway every time I post something negative.

Remind me when anything more than a slap in the wrist happens. And my definition of slap on the wrist is adjusted to how big Meta actually is, they make more than some countries!

You just hate facts, just like the idiots on Reddit, I am supposed to praise big tech criminals and just make positive stuff up, then I get all the upvotes.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#135
post #118
post #117

Earlier quoted context omitted.

Real life is full of compromises. If your grandma is on WhatsApp, and you want to talk to her, it might be a good idea to install WhatsApp. (However, if you have time on your hand and principles, you can use WhatsApp on a burner phone, I guess?)

Or educate grandma on why she should use signal and that fools use WhatsApp since meta is balls deep inside the app and watching what you do.

outside of the imperium center, you'd be lucky to have one provider of some product or service. and usually they will only be reachable via whatsapp. because metabook used whatsbook as a backdoor for for their failed oneinternet(?) project.

remember the backlash fb got when they offered free internet in india and africa but only for the Facebook app?

well, everywhere in the world you get free whatsapp traffic, so everyone now is on whatsapp.

good luck convincing a business who get hundreds of sales call via WhatsApp tobuse signal.

or convincing people who can barely afford their water bill that they now need a data plan to use signal instead of free whatsapp.

metabook won on this.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#136

Earlier quoted context omitted.

The difference is that people* know and accept that CloudFlare does this. They advertise it as a feature. *most willing customers of CloudFlare.

Users cannot consent to Cloudflare seeing their traffic and it's not an issue. Users consent to Facebook seeing their traffic and it's suddenly a problem?

> Users cannot consent to Cloudflare seeing their traffic

Users consent to the website seeing their traffic and the website consents to Cloudflare doing the SSL termination. This isn't too much different from the website consenting to analytics scripts monitoring webpage activity (i.e. Hotjar). If they did something shady, then users & the website would both be rightfully mad at them. But Cloudflare hasn't, so far at least.

Meanwhile, Facebook is known to do literally everything shady that is possible to do with a user's data, as well as plenty of things that weren't even a thing before they invented entirely new methods of tracking and selling data, so it's rightfully insane to trust them with anything, especially website traffic that they have no rights to.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#137
post #110

Earlier quoted context omitted.

I really think you are a fool if you install WhatsApp. I do think you are higher intelligence than normal if you install Signal. When I hear friends talk about WhatsApp I cringe. The few who have signal I regard highly.

Security SWE here. I have worked with WhatsApp's security engineers, I donate hundreds to the Signal Foundation every year, and I like to think I have a good amount of experience by now in the security industry. > you are a fool if you install WhatsApp [...] meta is balls deep inside the app and watching what you do. WhatsApp uses the same protocols as Signal under the hood. The Signal team even helped WhatsApp imple…

> Furthermore, the app has been extensively RE'd by third parties to validate it's doing what it says on the tin.

thats a freaking lie and you should feel bad for repeating it.

it was barely reviewd years ago. before all the shady features that even caused the original founder to leave the company (and a few billions worth of golden handcuffs) with an open letter about how fb destroyed privacy in WhatsApp.

EU and all sane state actors forbid its use (some recommends signal)

all recent political leaks was from fb (e.g. brazil, italy)

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#138
post #108

Whatever may be the end goal, MITM is called an 'attack', not 'research'. I'd not last a single day at such a company who would ask me to do such things. I had worked for a national political party in IT and left the job once I found about it corrupt practices and scams. If we, as engineers collectively upheld ethics as part of work culture, Meta wouldn't have attempted it.

As an ethical engineer, there is a further duty to also sabotage the organization once we uncover dirt on it. Never for profit. Sometimes for ego. And always because if every engineer took a stand against BS, then the world would be a much better place.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#139
post #111
post #83

Earlier quoted context omitted.

Bear in mind that they don’t applied this to everyone, which would be practically impossible. They hired Snapchat users (via a testing services provider ) to let meta observe their usage of Snapchat. Something akin to paying someone to let a meta researcher sit by your side and observe while you use the app. This happens all the time (hiring the testing services to recruit users to use your own app and analyze the pa…

> They hired Snapchat users (via a testing services provider ) to let meta observe their usage of Snapchat. > Something akin to paying someone to let a meta researcher sit by your side and observe while you use the app. Onavo Extend and Onavo Protect positioned themselves as providing consumer-oriented benefits (bandwidth reduction and security, respectively). > The news here is paying for someone to “test” a competi…

yeah, you should read the doc in the link, they explain why they couldn't use Onavo to simple man-in-the-middle snapchat users, hence the project to use the testing service provider to hire test subjects which would install a MITM solution to unencrypt snapchat (and later youtube and amazon).

Normal Onavo users were not subject to the decryption (although they were providing Meta information about overall snapchat's marketshare).

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#140

Earlier quoted context omitted.

Lawyer here. No. They have ...'d out an important part of 2511(2)(d). (and they probably meant (c)) First, it starts out with: "It shall not be unlawful under this chapter for a person not acting under color of law " This basically means a state/federal official or someone acting in their capacity as one (the color of law part basically means it applies even when they act beyond their legal authority by accident) Whi…

> person *not* acting under color of law Did you miss the "not" part?

No. Its written as a set of negatives- it shall be unlawful for someone not x to do y

Here it is saying it’s illegal unless you are an official acting under color of law and there is one party consent

Post reply on HN