Live data from Hacker News

How did Facebook intercept their competitor's encrypted mobile app traffic?

doubleagent.net

21–30 of 222 posts

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#22
post #4

The email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's…

If any of these miscreants were looking for a new job I bet the place you work would be getting in line to put them through an interview loop.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#23

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

Your work does this. This is incredibly common on basically every corporate device issued today.

The real issue is the NUX, which doesn't look like it made the data collection clear to users.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#24
post #8

Earlier quoted context omitted.

That's great for someone reading this forum to be aware of, but moms have no idea what any of the words you just wrote means. So if they were told they get a coupon for installing or some other bit of ridiculous things malware devs use, and yes I'm calling FB software malware. All of if it. Messenger, FB.app, everything. If it's from Meta, it's malicious.

Try comparing P2P OTR E2EE vs Non-CA TOFU SSH

Any app capable of installing a TLS CA is capable of writing to known_hosts (or authorized_keys, while we're at it).

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#25

Why didn't a big company like Snapchat not have certificate pinning? Something is amiss here!?

Snapchat do certificate pinning for it's main API domain. I am not exactly sure why analytics domain are different and why not have certificate pinning. (I thought analytics go through the same API domain, but it must be wrong then).

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#26

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

Our apps would be deplatformed on Android and iOS, and our businesses would be prosecuted by the DoJ and FBI.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#27
post #23

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

Your work does this. This is incredibly common on basically every corporate device issued today. The real issue is the NUX, which doesn't look like it made the data collection clear to users.

My work puts a big banner on the login screen that says up front that they can and will record and monitor everything on this machine. And IMO that's fine, because it's their machine. If they wanted to do that to my machine it would be a problem.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#28

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.

[deleted]

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#29

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.

Big tech and telecommunications companies are effectively miniature arms of the U.S. government at this point.

As seen by the "Protect America Act" of 2007[0], the government will retroactively cover their own ass and your companies' ass if deemed important enough to the intelligence apparatus. There isn't a chance in hell that Meta would be brought criminal charges for wiretapping.

0: https://en.wikipedia.org/wiki/Protect_America_Act_of_2007

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#30

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

[flagged]
Post reply on HN