Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

31–40 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#32

Can we please see prison time for this. DCMA should apply and it have criminal penalties including prison.

"May I direct your honor that my client is a wealthy tech billionaire who would otherwise be at risk of being slightly annoyed if they were sent to jail for intercepting private communications of competitors..."

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#33
post #18

So how can we be sure now that todays VPNs are not tomorrows Onavos. :(

First, all VPNs spy on you, just don't believe these claims because they are forced by law to do it. Second, don't use a VPN that clearly states that they're analyzing your traffic data.

> forced by law

Which law?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#34

why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS

You have to trust someone somewhere. You're simply placing your trust in the VPS provider instead of a third party VPN provider.

Not to mention the other stuff the VPN providers give you as standard which you'd have to implement and maintain yourself.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#35

why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS

It really depends on why are you trying to do. It is not easy (or just impossible) to get the same amount of ip with that $5/mo or $10/mo VPN services by renting your own VPS at the same price.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#36

Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

So this one time, I had a bug report at a client site. The business was largely a member of _______ religion. Our images wouldn't load in the app, but did on the website. How odd I thought, that doesn't make sense! Luckily I was able to be physically present, so I hopped down with laptop in tow, ssh'd into the server and started tailing logs....

Sure enough all the API requests for data were coming through, but whenever a request for image happened - nothing would hit the servers.

What the heck I thought to myself?

I said to the client 'that can't be, that's almost impossible....the only way that's possible is if the SSL traffic is decrypted, inspected, and images blocked from being requested, which, is a MITM attack".

He redirected me to his IT provider. I phoned them up, and explained the situation.

"Ahh so they're _____"

Me: "So what does that have to do with the price of fish?"

Them : "Content filtering..., you need to talk to ____"

Sure as the day is long, the content filter was a VPN all members of ____ had to have on their mobile devices (I don't know how widespread this is, whether it was just this business, or the entire ____ )

I applied to have our system approved, it was, and just like magic the next day photos started coming through.

I'm guessing basically it detected any .jpg/.mp4 etc URL's in https requests and flagged it up and blocked them from being requested. You can be sure on those devices the VPN would have been somehow locked in with device management, and there's no way on gods green earth they were getting at Facebook/insta etc.

So, it's not just meta. That really hammered home how seamless it can be to end users that they really can't trust what's actually happening on their devices.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#37
post #31

why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS

My €5 VPN allows me to use 500 IPs in 50 countries. Give me the VPS that allows me to do that.

Which service do you use? Mullvad?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#38
post #18

So how can we be sure now that todays VPNs are not tomorrows Onavos. :(

First, all VPNs spy on you, just don't believe these claims because they are forced by law to do it. Second, don't use a VPN that clearly states that they're analyzing your traffic data.

and your ISP will not spy on you?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#39
post #36

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

So this one time, I had a bug report at a client site. The business was largely a member of _______ religion. Our images wouldn't load in the app, but did on the website. How odd I thought, that doesn't make sense! Luckily I was able to be physically present, so I hopped down with laptop in tow, ssh'd into the server and started tailing logs.... Sure enough all the API requests for data were coming through, but whene…

Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't think it compares to an app that shadily installs its own root cert on an end user's device to spy on them.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#40
post #37
post #31

Earlier quoted context omitted.

My €5 VPN allows me to use 500 IPs in 50 countries. Give me the VPS that allows me to do that.

Which service do you use? Mullvad?

That could be either Mullvad or ProtonVPN.

Both are Swiss zero log, Mullvad has a flat 5 euro/month charge that goes back to when they started to (they say) forever - you can send them cash in envolope for the next twenty years with a generated account number and you're away.

ProtonVPN has plans - the two year streaming sign up is 4.99 euro/month.

Post reply on HN