Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

141–150 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#141
post #108

Whatever may be the end goal, MITM is called an 'attack', not 'research'. I'd not last a single day at such a company who would ask me to do such things. I had worked for a national political party in IT and left the job once I found about it corrupt practices and scams. If we, as engineers collectively upheld ethics as part of work culture, Meta wouldn't have attempted it.

> as engineers collectively upheld ethics as part of work culture

Just saying, it's really hard when your job or even your future green card is on the line. When the grunt engineers are 1 mistake away from being sent away from the US and lose all their potential futures in the US, they are much more likely to bury their heads carry out what they are told from the managers.

We need to go for the higher ups more.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#143
post #60

If an individual had somehow done this, I expect that the Computer Fraud and Abuse Act would be used against them. With Meta, we'll see.

I heard about this a few years ago. The trial participants were informed, consented, and paid. If you consent to a root cert being installed and analytics being proxied, well, that's that.

Could malware authors add a clickthrough EULA and be off the hook?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#144
post #29
post #13

What do you think Cloudflare is doing with its SSL termination/offloading?

Given Snowden, I have to assume Cloudfare is under the thumb of at least the NSA. For example, all the usual arguments against backdoors are going to be used by intelligence agencies to justify "providing assistance", which isn't even merely a euphemistic excuse given how incredibly valuable it would be for normal organised crime to spy on some of the encrypted data… but also is at least a bit of a euphemism, as I ha…

that isn't even so much of a conspiracy theory if you look at what happened to qwest

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#145
post #95

Earlier quoted context omitted.

Yes it's old news(1) but it has come up again in numerous HN and reddit posts for a few reasons (if you flick through HN you'll see various versions of this story holding lower ranks.) Also noteworthy is that Google were also doing something similar at the time, both were side-stepping Apple's privacy protections in iOS by using enterprise certificates that allowed the side-loading of apps without Apple's overview. I…

> To me, it's wild to think that people on HN don't know about this relatively recent history and are so naive to think that these protections were just pulled out of the air to frustrate developers, IMO we have modern journalism to thank for this sort of thing. People are so misinformed with rage bait articles that they push against policies in their own interest. But if anyone dare suggest enforcing some minimum le…

Bingo. It's easy to pay for influence, especially if one can spin a story for clicks.

I see a lot of cheerleading and parroted talking points against the interests of developers, particularly small and independent developers. A lot of the changes lobbied for by large developers give them an insurmountable pricing and competitive advantage over small developers and startups, yet I don't see much consideration here for that, nor the wishes of bona fide consumers.

Epic is particularly barefaced here, since they claim they are fighting for developers, when their proposals are not altruistic. Each clearly puts them at an advantage over smaller developers and consumers. Do we have such a short memory that we forget that this is the same Epic that settled with the FTC for using dark patterns and violating childrens' privacy for the purpose of tricking kids into accidental Fortnite purchases.(1) That was only 15 months ago.

While I'd expect reddit to be less informed, I'm not so charitable with HN: it's a forum where the bulk of participants claim to be developers.

(1) https://www.ftc.gov/news-events/news/press-releases/2022/12/...

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#146
post #56

Earlier quoted context omitted.

Why single out Cloudflare? They are not the only CDN or PaaS with SSL fronting.

I honestly can't think of one without googling. Cloudflare is kind of everywhere. Just like Google... can't really get rid of them even if you want to.

I'm sorry but that means your nerd card will expire at the end of the month. I see you've had it for quite a while, but being unable to name any CDN companies besides Cloudflare means your nerd card will lapse. If you'd like to apply for a newer issue one, an LLM agent will be along shortly to help you.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#147
post #145

Earlier quoted context omitted.

> To me, it's wild to think that people on HN don't know about this relatively recent history and are so naive to think that these protections were just pulled out of the air to frustrate developers, IMO we have modern journalism to thank for this sort of thing. People are so misinformed with rage bait articles that they push against policies in their own interest. But if anyone dare suggest enforcing some minimum le…

Bingo. It's easy to pay for influence, especially if one can spin a story for clicks. I see a lot of cheerleading and parroted talking points against the interests of developers, particularly small and independent developers. A lot of the changes lobbied for by large developers give them an insurmountable pricing and competitive advantage over small developers and startups, yet I don't see much consideration here for…

it's almost as if there wasn’t an ethics class in the CS majors’ required courses!

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#148

Earlier quoted context omitted.

> person *not* acting under color of law Did you miss the "not" part?

No. Its written as a set of negatives- it shall be unlawful for someone not x to do y Here it is saying it’s illegal unless you are an official acting under color of law and there is one party consent

There’s three negatives in the sentence you quoted.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#149
I used to work for a startup that did very similar kind of thing. We paid people to install our app and our root cert. We had our own VPN server through which all traffic of the panelists (people who participate in a panel) went and we were able to decrypt all traffic that used the PKI that the operating system provided. Some apps used some other kind of encryption (banking apps eg.) so that could not be decrypted. Then we also collected additional data, for example we took screenshots of whatever was currently on the screen and tried to map those to applications for which we recorded screenshots. This was done to know what app the user was running at what time.

I didn't work with the data collection, so my info is a bit limited. Facebook was our customer even though they had already bought Onavo.

I can answer some questions if you have any.

The company did go bankrupt and the technology was sold.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#150
post #80

Earlier quoted context omitted.

You simply legislate that if a company is building anything that will be used regularly by more than eg. a few thousand people, then the work must be designed and/or signed off by a licensed engineer, who will a) be subject to a code of ethics and b) be professionally liable for any failures causing loss or damage to the public. We seem to be able to manage this with bridges, planes, electrical & hydro installations…

> No reason it shouldn't be the same for critical software infrastructure. Why do you think Meta's work is critical software infrastructure?

It's perhaps not 'critical' in the sense that losing it would matter much, but it is worth caring about because of the number of people who are affected if/when things go wrong.
Post reply on HN