Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

21–30 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#21

why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS

Because most people are not techies.

Compared to the rest of the world, the number of people who even know what a VPS is is microscopically small.

And even those that do, the number of them with the time, desire, or skill, to do as you suggest, is even smaller.

I myself was into this sort of thing just 10 years ago. Now, as I start looking at hitting the big 6-0 in just a few years time, I’m already working on divesting myself of all this complexity,

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#22

why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS

Not everyone is savvy enough to do it, even though the process has been simplified with many hosting providers providing preconfigured VPN servers.

And it doesn't anonymize you that well. When you post a message that draws the attention of law enforcement, the IP will lead them to a VPN provider that hopefully doesn't keep any logs.

But if it leads them to a specific server, the hosting provider will disclose your account and payment data, since it is linked to your private server. Unless they accept fully pseudonymous accounts and let you pay for your VPS in cash, Monero or tumbled Bitcoins, finding you is much easier now.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#23

why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS

Oftentimes, it's not about security but about circumventing censorship. A cheap VPS comes with a fixed IP located in one fixed part of the world. Many VPN providers allow switching.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#24

Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#25

why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS

Not everyone is savvy enough to do it, even though the process has been simplified with many hosting providers providing preconfigured VPN servers. And it doesn't anonymize you that well. When you post a message that draws the attention of law enforcement, the IP will lead them to a VPN provider that hopefully doesn't keep any logs. But if it leads them to a specific server, the hosting provider will disclose your ac…

I find it so insane that people think the major VPN providers aren't all completely compromised one way or the other. As if you're really going to be able to just pass your traffic through such a business and they're going to actually keep no logs, and not have secret deals made with intelligence agencies, and aren't unknowingly completely insided/compromised by intelligence agencies. As if you can just push your traffic through a major VPN and intelligence agencies would just go "well shucks, oh man, they sure got us, we'll never know who it was, foiled again".

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#26
post #19

There's a lot of confusion around these stories these days, which reminds me of the "Gmail is looking at your emails" stories[1]. First, this is not wiretapping, come on. There's targeted man-in-the-middle (MITM) attacks, and then there's this. This is plainly "we are using advanced powers to analyze your traffic". This is not even Superfish[2] type of stuff, where Lenovo had preinstalled root certs onto laptops to d…

That might have been true in the past, but nowadays at least macOS/Android/iOS can enforce several restrictions on the apps you install, like prevent them from changing OS settings/files, limit access to only specified/opt-in directories, limit the amount of background activity, etc.

I don't know about Windows or Linux though.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#27
post #13

What do you think Cloudflare is doing with its SSL termination/offloading?

The difference is that people* know and accept that CloudFlare does this. They advertise it as a feature.

*most willing customers of CloudFlare.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#28
Direct link to PDF:

https://s3.documentcloud.org/documents/24520332/merged-fb.pd...

Here is Meta's response:

https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3...

Meta denies that they violated the Wiretap Act but offers no evidence of consent. (They try, but it is a laughable attempt.) Meta is also arguing the documents are not relevant. Meta claims the VPN app intercepting communications with other companies that sell online ad services, e.g., Snap, was not anti-competitive. It was just "market research".

Why is Meta so afraid to produce documents about "market research".

Meta does _not_ deny that they intercepted communications. From the attention this is getting on HN, MalwareBytes, etc. it seems clear no one using the VPN app would have expected Meta was conducting this interception. It is difficult to imagine how anyone could have consented to interception they would never have expected.

Additional details:

https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3...

Apparently Facebook was using a "really old" version of squid.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#29
post #13

What do you think Cloudflare is doing with its SSL termination/offloading?

Given Snowden, I have to assume Cloudfare is under the thumb of at least the NSA.

For example, all the usual arguments against backdoors are going to be used by intelligence agencies to justify "providing assistance", which isn't even merely a euphemistic excuse given how incredibly valuable it would be for normal organised crime to spy on some of the encrypted data… but also is at least a bit of a euphemism, as I have to assume the controversies about terrorist groups using Cloudfare are only pemitted to happen because someone in US intelligence knows how to squeeze secrets from those groups.

In theory, messing with SSL is one of Cloudfare's features, not a secret; in practice I suspect most end users treat all this as magic — I've directly witnessed magical thinking with the padlock icon in browsers.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#30

Earlier quoted context omitted.

Not everyone is savvy enough to do it, even though the process has been simplified with many hosting providers providing preconfigured VPN servers. And it doesn't anonymize you that well. When you post a message that draws the attention of law enforcement, the IP will lead them to a VPN provider that hopefully doesn't keep any logs. But if it leads them to a specific server, the hosting provider will disclose your ac…

I find it so insane that people think the major VPN providers aren't all completely compromised one way or the other. As if you're really going to be able to just pass your traffic through such a business and they're going to actually keep no logs, and not have secret deals made with intelligence agencies, and aren't unknowingly completely insided/compromised by intelligence agencies. As if you can just push your tra…

> I find it so insane that people think the major VPN providers aren't all completely compromised one way or the other.

For 99.9% of people a VPN is just something they use to access something in another country or because some YouTube ad scared them into believing you need a VPN as soon as you step into a coffee shop.

The threat model of most people does not include state actors or intelligence actors and they just don’t care.

Post reply on HN