Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

171–180 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#171

Earlier quoted context omitted.

They don't see the traffic unless they analyze the memory of your running server, because the SSL termination happens inside the server. Encrypted traffic passes through their network, which they don't have the keys for. Cloudflare, on the other paw, literally offers to do the SSL termination for you, as in they hold the private keys and perform the decryption on their servers that they control. Then they pass the de…

They can see the traffic if you're using one of their load balancers. And even if not, snooping on VMs is pretty trivial. For example this project https://github.com/KVM-VMI/kvm-vmi makes it easy to look at memory / processes on a VM.

> They can see the traffic if you're using one of their load balancers.

Only if you let them manage the SSL connection. Load balancers can easily relay individual TCP connections that are encrypted - load balancing doesn't require decryption.

> And even if not, snooping on VMs is pretty trivial.

They'd have to go out of their way to do this, and this would probably be the end of them if it were ever found out. So it's safe to assume any provider who wants to continue existing will not be doing this.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#172

Earlier quoted context omitted.

They can see the traffic if you're using one of their load balancers. And even if not, snooping on VMs is pretty trivial. For example this project https://github.com/KVM-VMI/kvm-vmi makes it easy to look at memory / processes on a VM.

> They can see the traffic if you're using one of their load balancers. Only if you let them manage the SSL connection. Load balancers can easily relay individual TCP connections that are encrypted - load balancing doesn't require decryption. > And even if not, snooping on VMs is pretty trivial. They'd have to go out of their way to do this, and this would probably be the end of them if it were ever found out. So it'…

It's not that hard for VMI and harder than you think for network.

I did work for a public cloud and we did think of VMI for diagnostics and malware checks. Once deployed and automated, it would be trivial to reuse for other purposes. I don't expect public cloud to use that daily, but I'd be surprised if they didn't have the process ready.

On the other hand, you want to process the LB traffic as fast as you can and any monitoring/reporting delay would have bad effects. Reconfiguring the filters / sinks at runtime takes effort too.

With experience in both areas, I can tell you they're comparable overall. You have to go out of your way to do it, but it's not too far.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#173
post #108

Whatever may be the end goal, MITM is called an 'attack', not 'research'. I'd not last a single day at such a company who would ask me to do such things. I had worked for a national political party in IT and left the job once I found about it corrupt practices and scams. If we, as engineers collectively upheld ethics as part of work culture, Meta wouldn't have attempted it.

> as engineers collectively upheld ethics as part of work culture Just saying, it's really hard when your job or even your future green card is on the line. When the grunt engineers are 1 mistake away from being sent away from the US and lose all their potential futures in the US, they are much more likely to bury their heads carry out what they are told from the managers. We need to go for the higher ups more.

someone committing fraud for money is same as committing fraud to keep a visa.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#174
post #65
post #40

Earlier quoted context omitted.

That could be either Mullvad or ProtonVPN. Both are Swiss zero log, Mullvad has a flat 5 euro/month charge that goes back to when they started to (they say) forever - you can send them cash in envolope for the next twenty years with a generated account number and you're away. ProtonVPN has plans - the two year streaming sign up is 4.99 euro/month.

Ah, good 'ole trustworthy Swiss companies! Like Crypto AG![1] Realistically, all VPNs are compromised. But for most people's threat model, that's irrelevant anyways. Proton for instance revealed the location of a climate activist leading to his arrest[2], with the inspiring message from the CEO that "privacy protections can be suspended", silently on a per-user basis at any time. Haven't seen anything like that for M…

The case you shared in fact shows that the Proton's encryption ensures privacy by default and that it cannot be bypassed even when we're presented with a court request that we cannot legally contest. Namely, weren't able to share any of the user's email content due to zero-access encryption which makes it inaccessible to us: https://proton.me/blog/zero-access-encryption. All we could provide was the limited metadata we need to have access to anyway in order for the email service to work properly. Additionally, the user's identity had already been known to the law enforcement. As any legally operating company, we need to comply to the local legislation.

There is also no comparison between Crypto AG and us. Our encryption occurs client-side, our cryptographic code is open source ( https://proton.me/community/open-source ), and our tech can and has been independently verified. More about this here: https://proton.me/blog/is-protonmail-trustworthy

Finally, regarding payment in cryptocurrency, you can also pay for Proton's services in Bitcoin: https://proton.me/support/payment-options#bitcoin.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#175

Earlier quoted context omitted.

> Proton for instance revealed the location of a climate activist leading to his arrest[2], with the inspiring message from the CEO that "privacy protections can be suspended", silently on a per-user basis at any time. That person isn't just a climate activist, they (and others who used that email account) broke French laws. Swiss authorities compelled the disclosure.

> broke French laws. Swiss authorities compelled the disclosure. That's a terrible reason. Torrenting breaks French law. Having the wrong bread or cheese with your wine probably breaks French law. And if your company can be compelled via gag order to give up your users' privacy whenever the authorities feel like it, well, your product isn't very effective anyways, and you should stop pretending you offer any meaningf…

Thankfully, gag orders are not permissible in Switzerland, so the scenario you are describing is impossible.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#176
post #56

Earlier quoted context omitted.

I honestly can't think of one without googling. Cloudflare is kind of everywhere. Just like Google... can't really get rid of them even if you want to.

I'm sorry but that means your nerd card will expire at the end of the month. I see you've had it for quite a while, but being unable to name any CDN companies besides Cloudflare means your nerd card will lapse. If you'd like to apply for a newer issue one, an LLM agent will be along shortly to help you.

Now obviously my comment is not about "just a CDN provider" right?

The SSL stuff that Cloudflare offers to protect your websites/APIs etc so you don't have to, their DNS products. The fact that iCloud Private Relay uses Cloudflare under the hood (and so all browsing there happens through their gateways etc).

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#177
post #176

Earlier quoted context omitted.

I'm sorry but that means your nerd card will expire at the end of the month. I see you've had it for quite a while, but being unable to name any CDN companies besides Cloudflare means your nerd card will lapse. If you'd like to apply for a newer issue one, an LLM agent will be along shortly to help you.

Now obviously my comment is not about "just a CDN provider" right? The SSL stuff that Cloudflare offers to protect your websites/APIs etc so you don't have to, their DNS products. The fact that iCloud Private Relay uses Cloudflare under the hood (and so all browsing there happens through their gateways etc).

I mean, if it's just the case that you've drank that much of the Cloudflare Kool aid that Akamai, AWS, and GCP don't have competing options in your mind, then that's a different problem entirety. Good for Cloudflare's wallet, and kudos to their marketing team though.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#178
post #155
post #120

Earlier quoted context omitted.

I was directly involved in this. I am happy to answer any questions you have about questioning or ethics at the time. Assuming that people's reaction to this was wrong, while not knowing what that reaction was, or having less than 5% of the context, isn’t going to help much. Short answer: No, there were strong arguments for it. I reached out for institutional support to answer some questions, groups that I expected t…

I understand that things are often more nuanced than they may appear, and in questions of moral judgement there will always be room for fuzziness. Personally I think the idea of compromising security for everyone in order to make life a little easier for the TLA's is not something I'd feel comfortable doing. I consider an individuals right to privacy paramount, something without which we risk unbounded tyrannical rul…

> compromising security for everyone

I don't think you understand how Onavo works.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#179
post #111

Earlier quoted context omitted.

> They hired Snapchat users (via a testing services provider ) to let meta observe their usage of Snapchat. > Something akin to paying someone to let a meta researcher sit by your side and observe while you use the app. Onavo Extend and Onavo Protect positioned themselves as providing consumer-oriented benefits (bandwidth reduction and security, respectively). > The news here is paying for someone to “test” a competi…

yeah, you should read the doc in the link, they explain why they couldn't use Onavo to simple man-in-the-middle snapchat users, hence the project to use the testing service provider to hire test subjects which would install a MITM solution to unencrypt snapchat (and later youtube and amazon). Normal Onavo users were not subject to the decryption (although they were providing Meta information about overall snapchat's…

Which doc and which link are you referring to? This isn't anywhere in the class action discovery documents as far as I can tell.

TC reported back in 2019 on Facebook using various third-party testing services to distribute their first-party Facebook Research app, so I'm not even convinced that point is new (or that they paid the third parties to do any actual research).

https://techcrunch.com/2019/01/29/facebook-project-atlas/

Facebook would probably have run up against app store policies by trying to install their root cert on existing apps, which seems to be the most likely justification for installing this additional app through third-party channels. It's also a lot easier to avoid suspicion when it's part of a bunch of click-through screens as part of app setup (especially when you're dangling money in front of users, even just $20/month).

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#180
post #179

Earlier quoted context omitted.

yeah, you should read the doc in the link, they explain why they couldn't use Onavo to simple man-in-the-middle snapchat users, hence the project to use the testing service provider to hire test subjects which would install a MITM solution to unencrypt snapchat (and later youtube and amazon). Normal Onavo users were not subject to the decryption (although they were providing Meta information about overall snapchat's…

Which doc and which link are you referring to? This isn't anywhere in the class action discovery documents as far as I can tell. TC reported back in 2019 on Facebook using various third-party testing services to distribute their first-party Facebook Research app, so I'm not even convinced that point is new (or that they paid the third parties to do any actual research). https://techcrunch.com/2019/01/29/facebook-proj…

This is in the second page of the document that started this hacker news entry.
Post reply on HN