Live data from Hacker News

How did Facebook intercept their competitor's encrypted mobile app traffic?

doubleagent.net

161–170 of 222 posts

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#161

Earlier quoted context omitted.

> Why do people work on such projects? >> Maybe you're on H1B and if you get let go you have to go back to Sri Lanka... I mean that's there too, but in this case, the guy who ran this spyware op was a former IDF turned chief of Facebook in Israel, later promoted to CISO for all of Meta.

Yes, I generally blame management. But sometimes I blame the engineers when its obvious they had other good options.

I think its fair to blame both, usually. Got enough hate left in my heart for it

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#162
post #70

Earlier quoted context omitted.

Victims that were being paid to participate? Edit: Not excusing Facebook here, but feel like this whole thing is in a weird grey area. It is like getting paid to have a Nielsen box monitoring your TV and then complaining when you find out it also knew what you watched on your DVD player.

> Victims that were being paid to participate I believe you might be referring to what happened in 2019? [1] This is a separate issue. [2] I do clarify this in the blog post, although it might be better to move the relevant text near the introduction rather then in the middle of the post. EDIT: I have also added a remark to the post that it is not clear if all users were MITM'd or just a subset [1] https://techcrunch…

I think what is missing is a timeline and clarity about the actual steps users had to take.

1) Onavo was a (free?) VPN app acquired by FB in 2014. Facebook used it to collect “market research data.” People chose to download this, but thought it was a security product.

2) At some point (it looks like 2016?) they launched an iOS app called Research, using the same tech, which required users to install a certificate meant for internal Facebook employees. They paid these users to monitor their traffic.

Are you saying that the MITM was happening for users of (1) or (2) or both?

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#163
post #136

Earlier quoted context omitted.

Or a person with a sick kid, or who is about to be evicted, or who made some bad financial decisions or for some other reason is about to run out of food money. In those situations it's very easy to rationalize that the good outweighs the bad. I've only been in a similar situation once. I could barely sleep at night for a week before I finally told them that I couldn't do it. In my situation I would have taken a fina…

Why would you diminish all those silent heroes who do decline the morally bankrupt job despite not making rent , or having to carry bad financial decisions? The truth is that in the US we do have some very expensive social safety nets, and it always comes back to the morals of the individual. You can rationalize just about anything against all kinds situations, but in the end we are talking about someone morally corr…

I'm not diminishing anything. I'm just not willing to condemn people without taking into account extenuating circumstances.

People regularly justify things that are not justified. When there's a lot of pressure, rationalizing is very easy. It's not even easy to realize that something is being rationalized.

I'm not justifying the unjustifiable. I'm saying that a person doesn't have be morally "bankrupt" to do something bad. Condemning people as morally bankrupt without taking into account extenuating circumstances is certainly not justified.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#164

Earlier quoted context omitted.

> Why do people work on such projects? >> Maybe you're on H1B and if you get let go you have to go back to Sri Lanka... I mean that's there too, but in this case, the guy who ran this spyware op was a former IDF turned chief of Facebook in Israel, later promoted to CISO for all of Meta.

Yes, I generally blame management. But sometimes I blame the engineers when its obvious they had other good options.

> I blame the engineers when its obvious they had other good options

Their manager was promoted to c-suite for running a covert worldwide spyware op (that also informed the company's M&A strategy). I'd reserve most of my blame on corporate culture that incentivized & rewarded such orgs and its management.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#165

Earlier quoted context omitted.

You really think the engineers working on this will be personally liable for this? That would honestly surprise me, the worst i can imagine is punishment for the company as an entity.

Yes, we do. Just look at how the engineers get thrown under the bus in a high profile case like the VW car-emissions scandal. Example: engineers blamed is the title in [1]. [1] https://www.nbcnews.com/business/autos/vw-scandal-top-u-s-ex...

Saying stuff like that in a hearing to deflect blame doesn’t surprise me, but were any individual engineers punished for this?

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#166
post #45
post #35

Earlier quoted context omitted.

I agree it's legally fine, but morally/socially there are ways to go-too-far.

there's nothing wrong with corporations tracking use of their hardware. they have to watch for data exfiltration and attempts to download malware, etc. don't use a corporate device for anything you don't want work to see. use your own. that's not a hard ask.

My rights are not subordinate to my company's, if anything it should be the reverse. My employment contract is intended for mutual benefit and the company also reserves the right to privacy from me in some things, even things in the scope of my employment. It should be acceptable to do things outside the scope of your employment using corporate devices, and you should retain a reasonable expectation of privacy when doing so.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#167

This is why we should be doing dual-server-client TLS certificate exchange before stuffing damaging info over Internet. But, alas, nooooooooo.

How would mutual TLS have helped here?

Mutual TLS dutifully breaks if there is a transparent HTTPS proxy like SSLbump or Squid.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#168
post #2

Ooooooooh, SSLbump. There has to be a court precedent that criminalized sniffing network traffic on the customer’s side. Should be one of those many cases involving wiretapping for banking info.

Doesn't the computer fraud and abuse act cover this?

Not ... really ...

It is about intent versus capability set that CFAA does poorly with differentiation in court.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#169
post #54

So just to be clear on what is being alleged, because the write-ups are omitting this detail: from what I can tell FB paid SC users to participate in “market research” and install the proxy. The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. (I’d love to get more detail on exactly what the participants were told they were getting paid for, but I’d be surpr…

> The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case.

All the best/most effective hacks involve convincing someone to download something they shouldn't that lets you sidestep security.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#170
post #54

So just to be clear on what is being alleged, because the write-ups are omitting this detail: from what I can tell FB paid SC users to participate in “market research” and install the proxy. The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. (I’d love to get more detail on exactly what the participants were told they were getting paid for, but I’d be surpr…

SC == Snapchat
Post reply on HN