So just to be clear on what is being alleged, because the write-ups are omitting this detail: from what I can tell FB paid SC users to participate in “market research” and install the proxy. The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. (I’d love to get more detail on exactly what the participants were told they were getting paid for, but I’d be surpr…
> The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. All the best/most effective hacks involve convincing someone to download something they shouldn't that lets you sidestep security.
How did Facebook intercept their competitor's encrypted mobile app traffic?
211–220 of 222 posts
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#212Earlier quoted context omitted.
That's great for someone reading this forum to be aware of, but moms have no idea what any of the words you just wrote means. So if they were told they get a coupon for installing or some other bit of ridiculous things malware devs use, and yes I'm calling FB software malware. All of if it. Messenger, FB.app, everything. If it's from Meta, it's malicious.
That's a very good point. I have within recent memory installed my own internal CA that I run on Android devices that I own and trust, and the process on android 11+ is sufficiently daunting that 99.5% of peoples' moms could not do it in one or two clicks. You have to go deep into system settings and manually import the CA. This requires first file-transferring the CA file somewhere onto local /sdcard storage and pos…
Despite being hard-up I don't think the vast majority of these low-income individuals would agree to being so egregiously wiretapped and data mined for future political ads on youtube or bundled into some other product without better compensation.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#213Earlier quoted context omitted.
Why do people work on such projects? I mean specifically the engineers. You're still paid the same engineer salary, except now you expose yourself to criminal prosecution. The corpo is at least getting some extra returns for the risk, you as an engineer are not. So dumb.
I was talking about this with friends the other night. If you've been in the industry long enough, you've probably been party to creating something horrible. It takes a while for the reality of horribleness to crack the glamour of creation and monetary reward, but once it does, everyone I personally know has quit and lived with the regret. I know people who have worked for adtech, gambling and HFT industries who now…
Sounds like getting to feel good after grabbing the bag. Particularly the first three considering how much they pay (even moreso if the gambling was crypto related).
> everyone I personally know has quit and lived with the regret.
Quit for a significantly lower wage job? Or quit in 2021 when they could trivially get another job likely with a raise?
I sound aggressive but these are serious, not rhetorical, questions. I don't know your friends, maybe they're the real deal, in which case massive kudos to them, I'm very happy to see others doing the same and I wish more were like us. But "living with the regret" is empty words if meaningful sacrifices haven't been made to atone for those sins.
FWIF, I left a job that paid more than twice what I'm able to get anywhere else without moving across the globe, for ethics reasons. And the industry wasn't as bad as the ones you've named besides HFT, which is imo pretty average when it comes to societal negative externalities for a tech company.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#214Earlier quoted context omitted.
> The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. All the best/most effective hacks involve convincing someone to download something they shouldn't that lets you sidestep security.
It was fully clear and fully remunerated. It was no way a hack and thats disingenuous wording so you can hate on FB. If you install a vpn then you are affirmatively giving control of your traffic tot he vpn. FB isnt under any obligation to explain how networks work. In the same way we don't explain dns or routing. Is your boss obligated to tell you ACH transactions are in the clear and anyone can watch settlement? No…
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#215Earlier quoted context omitted.
there's 5 people in my company, and we talk daily. want to split 10s since you've already doubled down? btw, I can add my crypto wallet to my bio so you can pay up if you'd like /s
How much does your company pay IC8 or equivalent per year? $2M liquid? $3M? Hard for anyone to feel moral qualms when they’re earning generational wealth.
Excusing people’s ethics because of money makes it worse not better IMO. Especially in the context of tech where there are plenty of well paying jobs that don’t make money through increased misery.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#216Earlier quoted context omitted.
I have several extremely talented friends at Meta, and the one constant is they left any attachment to the output product when they entered the workplace. Whereas they previously (at other top tech companies) did take pride in their employees output. Meta is “success at all costs” and heavily metrics driven. I think that’s what contributes to things like Myanmar and other countries hate speech proliferation. When you…
> Conversely, we’ve hired many ex meta people, and they’ve always almost all unanimously said how much they NOW like having pride in the products they create, after jumping ship. Just curious, did the ethics of their prior projects ever come up during the interview? I think I would have a problem hiring someone who worked on a product despite having ethical misgivings about how the product affected end users. Unless…
Most of them just bury their heads in the sand and say that the negative effects weren’t made known to them, and they started looking for new work after they found out. Short of interrogating them, you can’t really suss out of its true.
Instead we ask what they’d do in hypothetical scenarios around our own products.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#217The email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's…
So you'd rather they were smarter and able to hide the traces of their malicious behaviour? The real problem here is the complete absence of any kind of ethics. It sounds like the kind of place where if you consider ethics to be a blocker you'd be laughed out of the room, or fired. Corporate culture is to chase profit above anything else. It's especially bad in software, though, as so many people don't even seem to t…
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#218Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#219Earlier quoted context omitted.
because it won’t—entertaining the question legitimises these snake-oil peddlers
Where did I mention a specific blockchain or coin? How can I monetize my previous comment? It is deceptive to infer that there is a financial benefit. My idea is purely practical. It doesn't align with any mainstream financial interest, unlike yours which only serves incumbents.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#220Earlier quoted context omitted.
> Why do people work on such projects? >> Maybe you're on H1B and if you get let go you have to go back to Sri Lanka... I mean that's there too, but in this case, the guy who ran this spyware op was a former IDF turned chief of Facebook in Israel, later promoted to CISO for all of Meta.
It's important to note that the "Guy" was not just with the IDF, but with Unit 8200. Otherwise you'd be essentially saying "Hey look out, the guy who ran this op was an Israeli " (because nearly every male Israeli serves in the IDF).
Good thing they're less Fascist and more upstanding & liberal, yeah? https://www.nytimes.com/interactive/2014/09/12/world/middlee...
> every male Israeli serves in the IDF
Shame on them if they continue to be associated with an institution found guilty by the International courts of occupation, torture, sexual assault, dispossession, crimes against humanity.
https://x.com/wattheactualfuq/status/1818340892651975052 / https://ghostarchive.org/archive/sx6lC
The burden is not mine or anyone else's.