Live data from Hacker News

How did Facebook intercept their competitor's encrypted mobile app traffic?

doubleagent.net

171–180 of 222 posts

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#171
post #163

Earlier quoted context omitted.

Why would you diminish all those silent heroes who do decline the morally bankrupt job despite not making rent , or having to carry bad financial decisions? The truth is that in the US we do have some very expensive social safety nets, and it always comes back to the morals of the individual. You can rationalize just about anything against all kinds situations, but in the end we are talking about someone morally corr…

I'm not diminishing anything. I'm just not willing to condemn people without taking into account extenuating circumstances. People regularly justify things that are not justified. When there's a lot of pressure, rationalizing is very easy. It's not even easy to realize that something is being rationalized. I'm not justifying the unjustifiable. I'm saying that a person doesn't have be morally "bankrupt" to do somethin…

[dead]

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#172
post #82

Not to downplay it but at least this requires users to download the Onavo app, which isn’t so common. The one that I wonder about a lot is this: there are two (non-deprecated) types of webview you can use in iOS: WKWebview and SFSafariViewController. They’re intended for very different uses. When you tap on a link in the Facebook app they should use SFSafariViewController. It’s private (app code has no visibility int…

I wasn’t aware that WKWebView granted the app such power. Is there a way for me as a user to figure out if WKWebView or SFSafariViewController is being used if I have a web page open? Although I don’t use FB, I do use the web view of other apps and don’t want them to be able to do this either.

Yes, there are ways to distinguish between them as a user, for example you can check to see if your browser plugins are available. I also went through some of the most popular iOS apps and created a list of which app uses the correct SFSafariViewController vs the potentially malicious WKWebView.

- https://krausefx.com/blog/ios-privacy-instagram-and-facebook... - https://krausefx.com/blog/announcing-inappbrowsercom-see-wha...

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#174

Earlier quoted context omitted.

there's 5 people in my company, and we talk daily. want to split 10s since you've already doubled down? btw, I can add my crypto wallet to my bio so you can pay up if you'd like /s

How much does your company pay IC8 or equivalent per year? $2M liquid? $3M? Hard for anyone to feel moral qualms when they’re earning generational wealth.

> But some things will never change

> Try to show another way, but you stayin' in the dope game

> Now tell me, what's a mother to do?

> Bein' real don't appeal to the brother in you

> You gotta operate the easy way

> "I made a G today" But you made it in a sleazy way

> Sellin' crack to the kids.

> "I gotta get paid," well hey—

> but that's the way it is.

(Tupac - Changes)

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#175
post #112

Earlier quoted context omitted.

No, the writeup isn’t omitting anything, you’re mixing things up, which this article explicitly called out. This article is about Onavo Protect[1], “Free VPN + Data Manager”, which was not paying anyone. There was a separate program where Facebook paid teenagers money to install their Facebook Research VPN through their enterprise distribution channel, bypassing the App Store and its rules, so that paid version was e…

This is a bit tangled. I think this is new information but it’s all about Onavo. From OP: > Note this is different to what TechCrunch had revealed in 2019 in which Facebook were paying teenagers to gather data on usage habits. That resulted in the Onavo app being pulled from the app stores and fines. With the new MITM information revealed: what is currently unclear is if all app users had their traffic "intercepted"…

“Facebook Research” was the Onavo codebase, under a different name, signed by Facebook’s Enterprise certificate.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#176

Earlier quoted context omitted.

Why do people work on such projects? I mean specifically the engineers. You're still paid the same engineer salary, except now you expose yourself to criminal prosecution. The corpo is at least getting some extra returns for the risk, you as an engineer are not. So dumb.

Maybe you're on H1B and if you get let go you have to go back to Sri Lanka, whose government collapsed 2 years ago and left the country in political disarray. Some people have better choices than others. Like I wouldn't work on this project, but I have US citizenship. In college I slept over at some of my Indian friends' apartments and often they had like 8-12 guys sleeping in one bedroom, it was just a bunch of matt…

holy fuck can we please stop letting circumstances be the excuse we continuously fall back on, when enabling and reinforcing behavior with long-term impact and consequences.

imagine all of the times in history where this type of enabling of behavior reached an extreme, and now ask yourself where do you draw the line.

are you really asking me to enjoy the growing consequences of corporate overreach in the name of data, and all the sketchy ass, unethical, and invasive work all these foreign engineers are getting paid ridiculous salaries to propogate, and feel good about being held hostage because said engineers.. don't have a home.

so we are supposed to enable them to wreck mine (ours)?

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#177
post #112

Earlier quoted context omitted.

No, the writeup isn’t omitting anything, you’re mixing things up, which this article explicitly called out. This article is about Onavo Protect[1], “Free VPN + Data Manager”, which was not paying anyone. There was a separate program where Facebook paid teenagers money to install their Facebook Research VPN through their enterprise distribution channel, bypassing the App Store and its rules, so that paid version was e…

Why do people work on such projects? I mean specifically the engineers. You're still paid the same engineer salary, except now you expose yourself to criminal prosecution. The corpo is at least getting some extra returns for the risk, you as an engineer are not. So dumb.

Trying to bring an open mind, I could see a number of plausible scenarios where an engineer could do this, with various degrees of legitimacy.

It's certainly a complicated subject, but I think in general companies are really good, especially big ones, at getting people to work on things they might not be comfortable with otherwise. This thread has been talking the extremes like immigration status, but there are all kinds of subtle pressures as well. Some people might not believe they have the political capital to outright refuse a project (especially a pet project of the CEO) vs choose to accept and try to nudge the project onto more solid footing. And I suspect many engineers are terrified of being labelled as not a team player, which aids in the creation of group think, but makes it very difficult to foster a healthy culture of discussion that would bring forward the serious concerns of this work. And there is almost always some room of uncertainty as the last convincer... is it unethical to work on the project if the consumer is fully informed and offers consent to the invasion of privacy?

If there is an extreme where it's justifiable, for any reasonable engineer to accept the project, then it get's really muddy on where exactly the line is, and when it should be drawn.

I also suspect many of us envision ourselves having much more fortitude than we really do as well, imagining the heroic efforts we'd put in to changing a companies mind from a bad idea... where the more likely outcome for most of us is to fall silently into the background.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#178
post #88

Earlier quoted context omitted.

A piece of advice I've taken to heart is whenever I'm sending something in writing, to think about how I would feel if I needed to repeat the same things in court or if I found those messages in the news. Not that I've ever said anything near that egregious but it still helps.

Whenever I'm discussing something in person I think about how I would feel if it turned out my employer was breaking the law and me not putting it in writing stopped the injured parties from obtaining just compensation.

Sorry, you’re not FAANG material.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#179
post #112

Earlier quoted context omitted.

No, the writeup isn’t omitting anything, you’re mixing things up, which this article explicitly called out. This article is about Onavo Protect[1], “Free VPN + Data Manager”, which was not paying anyone. There was a separate program where Facebook paid teenagers money to install their Facebook Research VPN through their enterprise distribution channel, bypassing the App Store and its rules, so that paid version was e…

This is a bit tangled. I think this is new information but it’s all about Onavo. From OP: > Note this is different to what TechCrunch had revealed in 2019 in which Facebook were paying teenagers to gather data on usage habits. That resulted in the Onavo app being pulled from the app stores and fines. With the new MITM information revealed: what is currently unclear is if all app users had their traffic "intercepted"…

> The analysis is just a bunch of circumstantial observations that _it is possible_ FB was doing more skeezy stuff than was previously known.

No, it was already well-known way back in 2018, which is why that piece of shit app was withdrawn from App Store in the first place. Facebook’s enterprise account later got suspended in 2019 for distributing the paid piece of shit through enterprise MDM.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#180
post #179

Earlier quoted context omitted.

This is a bit tangled. I think this is new information but it’s all about Onavo. From OP: > Note this is different to what TechCrunch had revealed in 2019 in which Facebook were paying teenagers to gather data on usage habits. That resulted in the Onavo app being pulled from the app stores and fines. With the new MITM information revealed: what is currently unclear is if all app users had their traffic "intercepted"…

> The analysis is just a bunch of circumstantial observations that _it is possible_ FB was doing more skeezy stuff than was previously known. No, it was already well-known way back in 2018, which is why that piece of shit app was withdrawn from App Store in the first place. Facebook’s enterprise account later got suspended in 2019 for distributing the paid piece of shit through enterprise MDM.

The claim in the OP is that they might have been MiTM’ing arbitrary users, I believe the previously reported claims were that they only MiTM’d paid research participants. (Please share some links if you have evidence to the contrary, I’d love to get to the bottom of this.)
Post reply on HN