Live data from Hacker News

How did Facebook intercept their competitor's encrypted mobile app traffic?

doubleagent.net

31–40 of 222 posts

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#32
post #22
post #4

The email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's…

If any of these miscreants were looking for a new job I bet the place you work would be getting in line to put them through an interview loop.

I'll take that bet. Of course, you have no idea where I work and I do, so you're not a good gambler. The stench of social companies is noticeable by people that do not have their heads in the sand. Companies that still believe that ex-FAANG are automatically gawds deserve what they get.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#33
post #23

Earlier quoted context omitted.

Your work does this. This is incredibly common on basically every corporate device issued today. The real issue is the NUX, which doesn't look like it made the data collection clear to users.

My work puts a big banner on the login screen that says up front that they can and will record and monitor everything on this machine. And IMO that's fine, because it's their machine. If they wanted to do that to my machine it would be a problem.

No place I’ve worked has ever told their employees that they do this, but most of them do. Some employees I’ve spoken to are quite surprised that their “encrypted” connections are being monitored.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#34
post #3

tl;dr: If you install and fully trust a root CA on your client device, of course your TLS traffic can be MITMed. edit: the problem, obviously, is that this app tricked the non-technical people into installing/trusting the root CA for malicious purposes. Clearly this was malware.

So I mean, just taking a quick look at the contents of /etc/ssl/certs and what Firefox shows me when I hit its View Certificates button, I see among dozens of other actors, Amazon, Microsoft, GoDaddy, and the Beijing Certificate Authority. No software has ever asked me if I want to trust any of these guys, they've been silently trusted during a software install I suppose. Does this mean they can all MITM my TLS traffic if they so choose?

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#35
post #23

Earlier quoted context omitted.

Your work does this. This is incredibly common on basically every corporate device issued today. The real issue is the NUX, which doesn't look like it made the data collection clear to users.

My work puts a big banner on the login screen that says up front that they can and will record and monitor everything on this machine. And IMO that's fine, because it's their machine. If they wanted to do that to my machine it would be a problem.

I agree it's legally fine, but morally/socially there are ways to go-too-far.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#36
post #22

Earlier quoted context omitted.

If any of these miscreants were looking for a new job I bet the place you work would be getting in line to put them through an interview loop.

I'll take that bet. Of course, you have no idea where I work and I do, so you're not a good gambler. The stench of social companies is noticeable by people that do not have their heads in the sand. Companies that still believe that ex-FAANG are automatically gawds deserve what they get.

That might be an increasingly common view on the shop floor, but how confident are you that it filters up through all levels of your org?

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#37

Earlier quoted context omitted.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.

Big tech and telecommunications companies are effectively miniature arms of the U.S. government at this point. As seen by the "Protect America Act" of 2007[0], the government will retroactively cover their own ass and your companies' ass if deemed important enough to the intelligence apparatus. There isn't a chance in hell that Meta would be brought criminal charges for wiretapping. 0: https://en.wikipedia.org/wiki/P…

I think The Onion nailed it in 2011:

https://www.theonion.com/cias-facebook-program-dramatically-...

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#38
post #9
post #4

The email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's…

Billionaire bosses are all surrounded by opportunists and flatterers. Over time like the Great Pacific Garbage Patch the size of this group grows to unmanageable dimensions, cause anyone acting moderately sane will be treated as an existential threat to their lives of fantasy, domination, manipulation, luxury, leisure etc and pushed out.

> acting moderately sane will be treated as an existential threat [...] and pushed out.

Or converted, by making them take actions so that "if we go down you're going down with us."

Organized crime works that way too, come to think of it. They may call it "loyalty", but it really means "give us a way to coerce you into compliance."

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#39

If there is a god we'll be compensated through a class action settlement for a $5 meta ad voucher.

Gotta hire Illinois lawyers. They got their residents $435 per user: https://www.chicagotribune.com/2023/10/20/illinois-facebook-...

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#40
post #36

Earlier quoted context omitted.

I'll take that bet. Of course, you have no idea where I work and I do, so you're not a good gambler. The stench of social companies is noticeable by people that do not have their heads in the sand. Companies that still believe that ex-FAANG are automatically gawds deserve what they get.

That might be an increasingly common view on the shop floor, but how confident are you that it filters up through all levels of your org?

there's 5 people in my company, and we talk daily. want to split 10s since you've already doubled down?

btw, I can add my crypto wallet to my bio so you can pay up if you'd like /s

Post reply on HN