Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

181–189 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#181

Earlier quoted context omitted.

Lawyer here. No. They have ...'d out an important part of 2511(2)(d). (and they probably meant (c)) First, it starts out with: "It shall not be unlawful under this chapter for a person not acting under color of law " This basically means a state/federal official or someone acting in their capacity as one (the color of law part basically means it applies even when they act beyond their legal authority by accident) Whi…

> If I give consent to participate in collection of my internet data, it doesn't give you authorization to like, have someone live in my house and follow me around 24/7 so they can see what i do on the internet. TV ratings used to be collected from panelists using a wearable device that literally had an always-on microphone recording you 24/7 : https://en.wikipedia.org/wiki/Portable_People_Meter How is the situation…

They had explicit consent to do it?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#182

Earlier quoted context omitted.

No. Its written as a set of negatives- it shall be unlawful for someone not x to do y Here it is saying it’s illegal unless you are an official acting under color of law and there is one party consent

There’s three negatives in the sentence you quoted.

Fair, you are correct, i was mixing up c and d.

Then the part they elided from d comes into play: "unless such communication is intercepted for the purpose of committing any criminal or tortious act in violation of the Constitution or laws of the United States or of any State."

Unfair trade practice (and other things count here) since it doesn't have to be criminal, only a civil violation :)

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#184

Earlier quoted context omitted.

Meta is a known state-actor. They likely have federal immunity to most wrong-doings. (Source: https://www.vice.com/en/article/v7gd9b/facebook-helped-fbi-h... )

That article does not back up the claim that Meta is a state-actor. I hate FB, but all big platforms these days will cooperate with federal agencies in cases like the one described. Doesn't make them "state actors".

  "Facebook hired a cybersecurity consulting firm to develop a hacking tool, which cost six figures. Our sources described the tool as a zero-day exploit, which refers to a vulnerability in software that is unknown to the software developers. The firm worked with a Facebook engineer and wrote a program that would attach an exploit taking advantage of a flaw in Tails’ video player to reveal the real IP address of the person viewing the video."
They literally hired a team based on an FBI request to create a zero-day exploit. This wasn't just a "give us information" request. They actively R&D'd a tool for the government.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#185
post #95
post #61

Isn't this known since 2018? https://mashable.com/article/facebook-used-onavo-vpn-data-to...

Yes it's old news(1) but it has come up again in numerous HN and reddit posts for a few reasons (if you flick through HN you'll see various versions of this story holding lower ranks.) Also noteworthy is that Google were also doing something similar at the time, both were side-stepping Apple's privacy protections in iOS by using enterprise certificates that allowed the side-loading of apps without Apple's overview. I…

The problem is that it’s both. Apple intentionally obfuscates the two: they make privacy changes and then mix anticompetitive actions into it too, and then labels both under “security”. This harms their overall argument.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#186
post #110

Earlier quoted context omitted.

Yes and No. for TLS traffic you need to also install onavo. But the app does scan your contact list every couple minutes and send diffs to their servers. Even if you have never opened the app. And on previous android versions all your recently open apps list too. But again, if you install whatsapp you must give them the contact list permission anyway otherwise the app is intentionally broken and annoying.

I really think you are a fool if you install WhatsApp. I do think you are higher intelligence than normal if you install Signal. When I hear friends talk about WhatsApp I cringe. The few who have signal I regard highly.

Consider using a different metric to judge people than the messaging app they use ;)

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#187

Earlier quoted context omitted.

> To me, it's wild to think that people on HN don't know about this relatively recent history and are so naive to think that these protections were just pulled out of the air to frustrate developers, IMO we have modern journalism to thank for this sort of thing. People are so misinformed with rage bait articles that they push against policies in their own interest. But if anyone dare suggest enforcing some minimum le…

How do you propose enforcing journalistic ethics, without making "Journalism" subject to capture by regulation and government oversight? We had a system - Trust was placed into journalistic institutions, whose management was committed to editorial independence. It didn't work - They got bought out and chased profits.

Perhaps we could require a simple "nutrition facts" on each article about the journal's conflicting interests: for example, a ragebait article about big tech? Then the disclosure of the ad revenue conflict between big tech and media industry must be required up front (at the beginning of the article.)

We could also require a list of the journalist's qualifications to be posted clearly at the beginning of each article. If the journalist, for instance, does not have an education in the subject, the article must be prefaced with a "journalist is not experienced or qualified in this field." This would encourage traditional journalism to end, and for journalism to become more of a mandatory consultancy with experts.

Finally, we could strengthen libel and defamation laws rather significantly. For example, in Emily Steel's article[1] about ATC, she should not have named and shamed a particular controller. Furthermore, the ATC group should be able to easily sue her for inaccuracies in her article[2] misrepresenting ATC as a whole. If you can get easily litigated, you're more likely to stick to just the facts.

Ultimately a formulaic approach will not solve this problem, it can only help a little bit by discouraging nonfactual reporting. Unfortunately, this problem fundamentally comes down to journalists as an industry thinking they're paragons of righteousness, and then going on to write horrible things.

[1]: https://www.nytimes.com/2023/12/02/business/air-traffic-cont...

[2]: https://www.reddit.com/r/ATC/comments/175pwim/the_nyt_articl...

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#188
post #95

Earlier quoted context omitted.

Yes it's old news(1) but it has come up again in numerous HN and reddit posts for a few reasons (if you flick through HN you'll see various versions of this story holding lower ranks.) Also noteworthy is that Google were also doing something similar at the time, both were side-stepping Apple's privacy protections in iOS by using enterprise certificates that allowed the side-loading of apps without Apple's overview. I…

The problem is that it’s both. Apple intentionally obfuscates the two: they make privacy changes and then mix anticompetitive actions into it too, and then labels both under “security”. This harms their overall argument.

Give an example.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#189
post #188

Earlier quoted context omitted.

The problem is that it’s both. Apple intentionally obfuscates the two: they make privacy changes and then mix anticompetitive actions into it too, and then labels both under “security”. This harms their overall argument.

Give an example.

Almost all public statements about App Store review security, for example
Post reply on HN