Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

161–170 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#161
post #64

Earlier quoted context omitted.

If someone consents to your clear request to read their data in the plain, then it's not evil. Still not my cup of tea, but if you clearly explain and obtain consent, it's shady but fine.

So how is that relevant in the context here. FB did not clearly request to be able to read all traffic (encrypted and nonencrypted) so how could they get consent. Unless you're arguing, "we will monitor your Internet usage", clearly means we will man-in-the-middle all your connections. Which would be a weird take.

Yes they did. Participants were even compensated for it IIRC

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#162

Earlier quoted context omitted.

That's different. I have a lot of problems with CF, but when you sign up for a service which requires to see the traffic and you configure it explicitly to see your traffic... what's the complaint here?

Onavo users signed up, consented to their traffic data to be used for market research and were actually compensated for it. What's the complaint here ?

Did they? I mean, did they understand the privacy violation possible in this case? Or was the technical point they wouldn't understand somewhere in the middle of an agreement nobody reads anyway?

The difference in awareness is massive between those two use cases.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#163

Earlier quoted context omitted.

The difference is that people* know and accept that CloudFlare does this. They advertise it as a feature. *most willing customers of CloudFlare.

Users cannot consent to Cloudflare seeing their traffic and it's not an issue. Users consent to Facebook seeing their traffic and it's suddenly a problem?

Why would you idea stop at CF? Did they consent to hetzner / digital ocean / AWS / whatever hosting company seeing the traffic? The idea that the content producer decides how the content is served on the internet is the default.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#164
post #19

There's a lot of confusion around these stories these days, which reminds me of the "Gmail is looking at your emails" stories[1]. First, this is not wiretapping, come on. There's targeted man-in-the-middle (MITM) attacks, and then there's this. This is plainly "we are using advanced powers to analyze your traffic". This is not even Superfish[2] type of stuff, where Lenovo had preinstalled root certs onto laptops to d…

So, your argument is that MITM/wiretapping is okay if you do it at a large enough scale?

Is little snitch on mac a virus?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#165
post #108

Whatever may be the end goal, MITM is called an 'attack', not 'research'. I'd not last a single day at such a company who would ask me to do such things. I had worked for a national political party in IT and left the job once I found about it corrupt practices and scams. If we, as engineers collectively upheld ethics as part of work culture, Meta wouldn't have attempted it.

> MITM is called an 'attack', not 'research'

Sorry but what?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#166

Earlier quoted context omitted.

Users cannot consent to Cloudflare seeing their traffic and it's not an issue. Users consent to Facebook seeing their traffic and it's suddenly a problem?

Why would you idea stop at CF? Did they consent to hetzner / digital ocean / AWS / whatever hosting company seeing the traffic? The idea that the content producer decides how the content is served on the internet is the default.

They don't see the traffic unless they analyze the memory of your running server, because the SSL termination happens inside the server. Encrypted traffic passes through their network, which they don't have the keys for. Cloudflare, on the other paw, literally offers to do the SSL termination for you, as in they hold the private keys and perform the decryption on their servers that they control. Then they pass the decrypted traffic through their network in order to do things like "optimize" your images, or inject JavaScript into your pages. Website owners consent to this, but I guess the question here is whether users should need to consent to this website's traffic being handled in decrypted form by Cloudflare before that is actually done.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#167

Earlier quoted context omitted.

Why would you idea stop at CF? Did they consent to hetzner / digital ocean / AWS / whatever hosting company seeing the traffic? The idea that the content producer decides how the content is served on the internet is the default.

They don't see the traffic unless they analyze the memory of your running server, because the SSL termination happens inside the server. Encrypted traffic passes through their network, which they don't have the keys for. Cloudflare, on the other paw, literally offers to do the SSL termination for you, as in they hold the private keys and perform the decryption on their servers that they control. Then they pass the de…

They can see the traffic if you're using one of their load balancers. And even if not, snooping on VMs is pretty trivial. For example this project https://github.com/KVM-VMI/kvm-vmi makes it easy to look at memory / processes on a VM.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#168
post #95

Earlier quoted context omitted.

Yes it's old news(1) but it has come up again in numerous HN and reddit posts for a few reasons (if you flick through HN you'll see various versions of this story holding lower ranks.) Also noteworthy is that Google were also doing something similar at the time, both were side-stepping Apple's privacy protections in iOS by using enterprise certificates that allowed the side-loading of apps without Apple's overview. I…

> To me, it's wild to think that people on HN don't know about this relatively recent history and are so naive to think that these protections were just pulled out of the air to frustrate developers, IMO we have modern journalism to thank for this sort of thing. People are so misinformed with rage bait articles that they push against policies in their own interest. But if anyone dare suggest enforcing some minimum le…

How do you propose enforcing journalistic ethics, without making "Journalism" subject to capture by regulation and government oversight? We had a system - Trust was placed into journalistic institutions, whose management was committed to editorial independence. It didn't work - They got bought out and chased profits.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#169
post #145

Earlier quoted context omitted.

Bingo. It's easy to pay for influence, especially if one can spin a story for clicks. I see a lot of cheerleading and parroted talking points against the interests of developers, particularly small and independent developers. A lot of the changes lobbied for by large developers give them an insurmountable pricing and competitive advantage over small developers and startups, yet I don't see much consideration here for…

it's almost as if there wasn’t an ethics class in the CS majors’ required courses!

Actually most CS majors require ethics courses. I've met very few developers that don't care about ethics, especially when they work on something product facing. We've seen entire teams at Google quit or refuse to implement something, etc.

Meanwhile in journalism, ethics is a strong part of the course structure but you see countless journalists writing poorly researched ragebait articles for clicks.

The "programmers don't know ethics" meme is just that, a meme. The fact that there even is a required ethics course in most universities is far more than you can say for most other majors. Nearly every single programmer knows about Therac-25, I'd wager most graduates today are also learning about MCAS, etc.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#170

Earlier quoted context omitted.

it's almost as if there wasn’t an ethics class in the CS majors’ required courses!

Actually most CS majors require ethics courses. I've met very few developers that don't care about ethics, especially when they work on something product facing. We've seen entire teams at Google quit or refuse to implement something, etc. Meanwhile in journalism, ethics is a strong part of the course structure but you see countless journalists writing poorly researched ragebait articles for clicks. The "programmers…

> I'd wager most graduates today are also learning about MCAS

Emphasis mine. you'd likely win that wager, I don't disagree, and that's great for today's graduating classes, but because engineer is not a protected term, especially not software engineer and definitely not prompt engineer, theres no requirement for a CS graduate to go back and do continuing education like there is in other fields, so graduates who don't seek out and do the, eg, OCW CS ethics class aren't going to find themselves in one. Curriculum has evolved over the years to include ethics as a requirement, but that meme isn't a meme because it isn't true in a vast number of cases, as evidenced by the multiple failures in, eg, this case here.

Post reply on HN