Live data from Hacker News

How did Facebook intercept their competitor's encrypted mobile app traffic?

doubleagent.net

181–190 of 222 posts

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#181
post #179

Earlier quoted context omitted.

> The analysis is just a bunch of circumstantial observations that _it is possible_ FB was doing more skeezy stuff than was previously known. No, it was already well-known way back in 2018, which is why that piece of shit app was withdrawn from App Store in the first place. Facebook’s enterprise account later got suspended in 2019 for distributing the paid piece of shit through enterprise MDM.

The claim in the OP is that they might have been MiTM’ing arbitrary users, I believe the previously reported claims were that they only MiTM’d paid research participants. (Please share some links if you have evidence to the contrary, I’d love to get to the bottom of this.)

Onavo isn’t paid, it’s just a “free” VPN app. There’s no paid participation, you just download it.

https://www.bitdefender.com/blog/hotforsecurity/facebook-pul...

https://www.wsj.com/articles/facebook-to-remove-data-securit...

Edit: Typo.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#182
post #181

Earlier quoted context omitted.

The claim in the OP is that they might have been MiTM’ing arbitrary users, I believe the previously reported claims were that they only MiTM’d paid research participants. (Please share some links if you have evidence to the contrary, I’d love to get to the bottom of this.)

Onavo isn’t paid, it’s just a “free” VPN app. There’s no paid participation, you just download it. https://www.bitdefender.com/blog/hotforsecurity/facebook-pul... https://www.wsj.com/articles/facebook-to-remove-data-securit... Edit: Typo.

That doesn't mean that the MITM traffic interception would be enabled for regular users that have downloaded the app from the store. As stated both in the article and in the comments here, both "free" VPN and "paid market research" VPN used the same codebase. Is there any evidence (other than "facebook bad") that the MITM part was enabled for anyone other than consenting/getting paid participants?

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#183
post #86

Earlier quoted context omitted.

That's clearly not what was meant

No, read what they're replying-to. I wrote one sentence about how "there are ways for companies to go too far", which I think is pretty dang uncontroversial and trivially-true. However that user replied with what is clearly a disagreement, with corporate justifications and placing sole responsibility on employees to avoid the hardware. This leads to two competing options: (A) They simply can't imagine any scenario wh…

Or that the discussion was about information on and being transmitted through the devices and I was limiting my opinion on "there being nothing wrong with corporations tracking use of their hardware" to that scope, and not extending it to include spying on people in their homes using the device peripherals.

No, they shouldn't be flicking on your laptop camera or mic remotely, as these are pretty obviously violations of your privacy.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#184
post #98

Earlier quoted context omitted.

People seem to forget that the research that turned into Google was initially funded by the NSA and CIA: https://qz.com/1145669/googles-true-origin-partly-lies-in-ci... Cars now come with Google services / Android baked into the damn infotainment system, with no possible way to pull it out. What could possibly go wrong with an advertising company seeing everywhere you go, and everyone who rides in your car?

This is true, but so far there are ways to disable much of this. For example on a Ford, you can literally pull the fuse for the GSM modem. On a GM, you can pull the antenna from OnStar, and put a resister there in replacement... thus rendering it unable to communicate to home base. This doesn't solve everything, but it at least stops the immediate phone home.

You can also buy cars that don’t need an immediate debugging

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#185
post #4

The email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's…

And people that think like you are the problem. Ypu should be calling immoral asshole things out. Not frigging trying to do them and not get caught.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#186

Earlier quoted context omitted.

Maybe you're on H1B and if you get let go you have to go back to Sri Lanka, whose government collapsed 2 years ago and left the country in political disarray. Some people have better choices than others. Like I wouldn't work on this project, but I have US citizenship. In college I slept over at some of my Indian friends' apartments and often they had like 8-12 guys sleeping in one bedroom, it was just a bunch of matt…

> Why do people work on such projects? >> Maybe you're on H1B and if you get let go you have to go back to Sri Lanka... I mean that's there too, but in this case, the guy who ran this spyware op was a former IDF turned chief of Facebook in Israel, later promoted to CISO for all of Meta.

It's important to note that the "Guy" was not just with the IDF, but with Unit 8200.

Otherwise you'd be essentially saying "Hey look out, the guy who ran this op was an Israeli" (because nearly every male Israeli serves in the IDF).

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#187

Earlier quoted context omitted.

Maybe you're on H1B and if you get let go you have to go back to Sri Lanka, whose government collapsed 2 years ago and left the country in political disarray. Some people have better choices than others. Like I wouldn't work on this project, but I have US citizenship. In college I slept over at some of my Indian friends' apartments and often they had like 8-12 guys sleeping in one bedroom, it was just a bunch of matt…

holy fuck can we please stop letting circumstances be the excuse we continuously fall back on, when enabling and reinforcing behavior with long-term impact and consequences. imagine all of the times in history where this type of enabling of behavior reached an extreme, and now ask yourself where do you draw the line. are you really asking me to enjoy the growing consequences of corporate overreach in the name of data…

> so we are supposed to enable them to wreck mine (ours)?

No, we’re supposed to attack it from a different direction. Whether these people are H1B or outsourced overseas, U.S. corporations will always be able to find people in desperate enough situations (civil war-torn country with a literal famine going on). We can absolutely blame and shame the engineers who have other options for sustenance and medicine for their families, but if you want to solve this problem, it can only be solved through the legislative and executive branches.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#188
post #148
post #88

Earlier quoted context omitted.

A piece of advice I've taken to heart is whenever I'm sending something in writing, to think about how I would feel if I needed to repeat the same things in court or if I found those messages in the news. Not that I've ever said anything near that egregious but it still helps.

"Dance like no one is watching; email like it may one day be read aloud in a deposition." - Olivia Nuzzi https://web.archive.org/web/20141214193908/https://twitter.c...

The way I heard it from a corporate counsel is "The E in E-mail stands for Evidence."

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#189
post #90
post #47

Earlier quoted context omitted.

Their contribution to the genocide in Myanmar has said everything about Meta you'll ever need to know. It's a tragedy that working for Meta is generally seen as neutral whereas working at any defense-related companies is often met with scorn, despite the overwhelmingly greater negative impact that working at the former has. And this doesn't even touch upon Instagram. I guess that they pay too much and employ too much…

I have several extremely talented friends at Meta, and the one constant is they left any attachment to the output product when they entered the workplace. Whereas they previously (at other top tech companies) did take pride in their employees output. Meta is “success at all costs” and heavily metrics driven. I think that’s what contributes to things like Myanmar and other countries hate speech proliferation. When you…

> Conversely, we’ve hired many ex meta people, and they’ve always almost all unanimously said how much they NOW like having pride in the products they create, after jumping ship.

Just curious, did the ethics of their prior projects ever come up during the interview? I think I would have a problem hiring someone who worked on a product despite having ethical misgivings about how the product affected end users. Unless they could explain the extenuating circumstances that forced them to work on that product (sick family to care for, work visa being held hostage, and so on). If their response was simply, "I made metric X go up and got paid Y to do it," I don't think I could hire them in good conscience.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#190
post #45

Earlier quoted context omitted.

there's nothing wrong with corporations tracking use of their hardware. they have to watch for data exfiltration and attempts to download malware, etc. don't use a corporate device for anything you don't want work to see. use your own. that's not a hard ask.

My rights are not subordinate to my company's, if anything it should be the reverse. My employment contract is intended for mutual benefit and the company also reserves the right to privacy from me in some things, even things in the scope of my employment. It should be acceptable to do things outside the scope of your employment using corporate devices, and you should retain a reasonable expectation of privacy when d…

There are some places where I don't really have an opinion; if you work in, I dunno, pet grooming, and you and your employer agree to... "shared custody" of a device then sure. But I'm not sure that's possible in some fields. As I understand it, financial companies are legally mandated to record every single message sent/received on the machine so they can prove that nobody's doing insider trading or whatever. I would kind of expect something similar for medical field companies. I'm open to suggestions, but I can't personally see a way to uphold that obligation while giving the employees privacy if they want to use the company device to ex. check their personal email.
Post reply on HN