Earlier quoted context omitted.
If someone consents to your clear request to read their data in the plain, then it's not evil. Still not my cup of tea, but if you clearly explain and obtain consent, it's shady but fine.
So how is that relevant in the context here. FB did not clearly request to be able to read all traffic (encrypted and nonencrypted) so how could they get consent. Unless you're arguing, "we will monitor your Internet usage", clearly means we will man-in-the-middle all your connections. Which would be a weird take.
Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
161–170 of 189 posts
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#162Earlier quoted context omitted.
That's different. I have a lot of problems with CF, but when you sign up for a service which requires to see the traffic and you configure it explicitly to see your traffic... what's the complaint here?
Onavo users signed up, consented to their traffic data to be used for market research and were actually compensated for it. What's the complaint here ?
The difference in awareness is massive between those two use cases.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#163Earlier quoted context omitted.
The difference is that people* know and accept that CloudFlare does this. They advertise it as a feature. *most willing customers of CloudFlare.
Users cannot consent to Cloudflare seeing their traffic and it's not an issue. Users consent to Facebook seeing their traffic and it's suddenly a problem?
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#164There's a lot of confusion around these stories these days, which reminds me of the "Gmail is looking at your emails" stories[1]. First, this is not wiretapping, come on. There's targeted man-in-the-middle (MITM) attacks, and then there's this. This is plainly "we are using advanced powers to analyze your traffic". This is not even Superfish[2] type of stuff, where Lenovo had preinstalled root certs onto laptops to d…
So, your argument is that MITM/wiretapping is okay if you do it at a large enough scale?
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#165Whatever may be the end goal, MITM is called an 'attack', not 'research'. I'd not last a single day at such a company who would ask me to do such things. I had worked for a national political party in IT and left the job once I found about it corrupt practices and scams. If we, as engineers collectively upheld ethics as part of work culture, Meta wouldn't have attempted it.
Sorry but what?
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#166Earlier quoted context omitted.
Users cannot consent to Cloudflare seeing their traffic and it's not an issue. Users consent to Facebook seeing their traffic and it's suddenly a problem?
Why would you idea stop at CF? Did they consent to hetzner / digital ocean / AWS / whatever hosting company seeing the traffic? The idea that the content producer decides how the content is served on the internet is the default.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#167Earlier quoted context omitted.
Why would you idea stop at CF? Did they consent to hetzner / digital ocean / AWS / whatever hosting company seeing the traffic? The idea that the content producer decides how the content is served on the internet is the default.
They don't see the traffic unless they analyze the memory of your running server, because the SSL termination happens inside the server. Encrypted traffic passes through their network, which they don't have the keys for. Cloudflare, on the other paw, literally offers to do the SSL termination for you, as in they hold the private keys and perform the decryption on their servers that they control. Then they pass the de…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#168Earlier quoted context omitted.
Yes it's old news(1) but it has come up again in numerous HN and reddit posts for a few reasons (if you flick through HN you'll see various versions of this story holding lower ranks.) Also noteworthy is that Google were also doing something similar at the time, both were side-stepping Apple's privacy protections in iOS by using enterprise certificates that allowed the side-loading of apps without Apple's overview. I…
> To me, it's wild to think that people on HN don't know about this relatively recent history and are so naive to think that these protections were just pulled out of the air to frustrate developers, IMO we have modern journalism to thank for this sort of thing. People are so misinformed with rage bait articles that they push against policies in their own interest. But if anyone dare suggest enforcing some minimum le…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#169Earlier quoted context omitted.
Bingo. It's easy to pay for influence, especially if one can spin a story for clicks. I see a lot of cheerleading and parroted talking points against the interests of developers, particularly small and independent developers. A lot of the changes lobbied for by large developers give them an insurmountable pricing and competitive advantage over small developers and startups, yet I don't see much consideration here for…
it's almost as if there wasn’t an ethics class in the CS majors’ required courses!
Meanwhile in journalism, ethics is a strong part of the course structure but you see countless journalists writing poorly researched ragebait articles for clicks.
The "programmers don't know ethics" meme is just that, a meme. The fact that there even is a required ethics course in most universities is far more than you can say for most other majors. Nearly every single programmer knows about Therac-25, I'd wager most graduates today are also learning about MCAS, etc.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#170Earlier quoted context omitted.
it's almost as if there wasn’t an ethics class in the CS majors’ required courses!
Actually most CS majors require ethics courses. I've met very few developers that don't care about ethics, especially when they work on something product facing. We've seen entire teams at Google quit or refuse to implement something, etc. Meanwhile in journalism, ethics is a strong part of the course structure but you see countless journalists writing poorly researched ragebait articles for clicks. The "programmers…
Emphasis mine. you'd likely win that wager, I don't disagree, and that's great for today's graduating classes, but because engineer is not a protected term, especially not software engineer and definitely not prompt engineer, theres no requirement for a CS graduate to go back and do continuing education like there is in other fields, so graduates who don't seek out and do the, eg, OCW CS ethics class aren't going to find themselves in one. Curriculum has evolved over the years to include ethics as a requirement, but that meme isn't a meme because it isn't true in a vast number of cases, as evidenced by the multiple failures in, eg, this case here.