Earlier quoted context omitted.
> Why do people work on such projects? >> Maybe you're on H1B and if you get let go you have to go back to Sri Lanka... I mean that's there too, but in this case, the guy who ran this spyware op was a former IDF turned chief of Facebook in Israel, later promoted to CISO for all of Meta.
Yes, I generally blame management. But sometimes I blame the engineers when its obvious they had other good options.
How did Facebook intercept their competitor's encrypted mobile app traffic?
161–170 of 222 posts
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#162Earlier quoted context omitted.
Victims that were being paid to participate? Edit: Not excusing Facebook here, but feel like this whole thing is in a weird grey area. It is like getting paid to have a Nielsen box monitoring your TV and then complaining when you find out it also knew what you watched on your DVD player.
> Victims that were being paid to participate I believe you might be referring to what happened in 2019? [1] This is a separate issue. [2] I do clarify this in the blog post, although it might be better to move the relevant text near the introduction rather then in the middle of the post. EDIT: I have also added a remark to the post that it is not clear if all users were MITM'd or just a subset [1] https://techcrunch…
1) Onavo was a (free?) VPN app acquired by FB in 2014. Facebook used it to collect “market research data.” People chose to download this, but thought it was a security product.
2) At some point (it looks like 2016?) they launched an iOS app called Research, using the same tech, which required users to install a certificate meant for internal Facebook employees. They paid these users to monitor their traffic.
Are you saying that the MITM was happening for users of (1) or (2) or both?
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#163Earlier quoted context omitted.
Or a person with a sick kid, or who is about to be evicted, or who made some bad financial decisions or for some other reason is about to run out of food money. In those situations it's very easy to rationalize that the good outweighs the bad. I've only been in a similar situation once. I could barely sleep at night for a week before I finally told them that I couldn't do it. In my situation I would have taken a fina…
Why would you diminish all those silent heroes who do decline the morally bankrupt job despite not making rent , or having to carry bad financial decisions? The truth is that in the US we do have some very expensive social safety nets, and it always comes back to the morals of the individual. You can rationalize just about anything against all kinds situations, but in the end we are talking about someone morally corr…
People regularly justify things that are not justified. When there's a lot of pressure, rationalizing is very easy. It's not even easy to realize that something is being rationalized.
I'm not justifying the unjustifiable. I'm saying that a person doesn't have be morally "bankrupt" to do something bad. Condemning people as morally bankrupt without taking into account extenuating circumstances is certainly not justified.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#164Earlier quoted context omitted.
> Why do people work on such projects? >> Maybe you're on H1B and if you get let go you have to go back to Sri Lanka... I mean that's there too, but in this case, the guy who ran this spyware op was a former IDF turned chief of Facebook in Israel, later promoted to CISO for all of Meta.
Yes, I generally blame management. But sometimes I blame the engineers when its obvious they had other good options.
Their manager was promoted to c-suite for running a covert worldwide spyware op (that also informed the company's M&A strategy). I'd reserve most of my blame on corporate culture that incentivized & rewarded such orgs and its management.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#165Earlier quoted context omitted.
You really think the engineers working on this will be personally liable for this? That would honestly surprise me, the worst i can imagine is punishment for the company as an entity.
Yes, we do. Just look at how the engineers get thrown under the bus in a high profile case like the VW car-emissions scandal. Example: engineers blamed is the title in [1]. [1] https://www.nbcnews.com/business/autos/vw-scandal-top-u-s-ex...
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#166Earlier quoted context omitted.
I agree it's legally fine, but morally/socially there are ways to go-too-far.
there's nothing wrong with corporations tracking use of their hardware. they have to watch for data exfiltration and attempts to download malware, etc. don't use a corporate device for anything you don't want work to see. use your own. that's not a hard ask.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#167Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#168Ooooooooh, SSLbump. There has to be a court precedent that criminalized sniffing network traffic on the customer’s side. Should be one of those many cases involving wiretapping for banking info.
Doesn't the computer fraud and abuse act cover this?
It is about intent versus capability set that CFAA does poorly with differentiation in court.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#169So just to be clear on what is being alleged, because the write-ups are omitting this detail: from what I can tell FB paid SC users to participate in “market research” and install the proxy. The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. (I’d love to get more detail on exactly what the participants were told they were getting paid for, but I’d be surpr…
All the best/most effective hacks involve convincing someone to download something they shouldn't that lets you sidestep security.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#170So just to be clear on what is being alleged, because the write-ups are omitting this detail: from what I can tell FB paid SC users to participate in “market research” and install the proxy. The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. (I’d love to get more detail on exactly what the participants were told they were getting paid for, but I’d be surpr…