Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

41–50 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#43

Direct link to PDF: https://s3.documentcloud.org/documents/24520332/merged-fb.pd... Here is Meta's response: https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3... Meta denies that they violated the Wiretap Act but offers no evidence of consent. (They try, but it is a laughable attempt.) Meta is also arguing the documents are not relevant. Meta claims the VPN app intercepting communications with other compan…

I mean, sure, you could also do “market research” by breaking into people’s homes, reading their mail, and listening in on all their phone calls. I hope some actual criminal prosecution results from this disclosure, as it’s very clearly “hacking” and “wiretapping” and “unauthorized access”.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#44
post #19

There's a lot of confusion around these stories these days, which reminds me of the "Gmail is looking at your emails" stories[1]. First, this is not wiretapping, come on. There's targeted man-in-the-middle (MITM) attacks, and then there's this. This is plainly "we are using advanced powers to analyze your traffic". This is not even Superfish[2] type of stuff, where Lenovo had preinstalled root certs onto laptops to d…

So, your argument is that MITM/wiretapping is okay if you do it at a large enough scale?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#46
post #36

Earlier quoted context omitted.

So this one time, I had a bug report at a client site. The business was largely a member of _______ religion. Our images wouldn't load in the app, but did on the website. How odd I thought, that doesn't make sense! Luckily I was able to be physically present, so I hopped down with laptop in tow, ssh'd into the server and started tailing logs.... Sure enough all the API requests for data were coming through, but whene…

Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't t…

From the inference of the commenter, I think they were referring to an app on a mobile device and not the device itself.

It also sounds like their issue was at the ISP provider level, as well, which takes the business out of the loop of being the data controller/owner (of the collected data) at that point.

Note: I'm not saying that your comment doesn't have merit, I just don't think that the points that you made apply - specifically - in this case?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#47

Facebook is not removable from many android devices... does this mean Zuckerberg has been seeing all user traffic for years regardless of tls?

Yes and No. for TLS traffic you need to also install onavo. But the app does scan your contact list every couple minutes and send diffs to their servers. Even if you have never opened the app. And on previous android versions all your recently open apps list too. But again, if you install whatsapp you must give them the contact list permission anyway otherwise the app is intentionally broken and annoying.

> for TLS traffic you need to also install onavo.

I'd be interested to know if it shipped as part of the Facebook SDK, as well.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#48

Direct link to PDF: https://s3.documentcloud.org/documents/24520332/merged-fb.pd... Here is Meta's response: https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3... Meta denies that they violated the Wiretap Act but offers no evidence of consent. (They try, but it is a laughable attempt.) Meta is also arguing the documents are not relevant. Meta claims the VPN app intercepting communications with other compan…

Here is a quote from Facebook/Meta's legal council to the Judge. In this document "Advertisers" refers to Snapchat, YouTube and Amazon.

"... the Wiretap Act provides that an interception is not unlawful if a party to the communication “has given prior consent to such interception.” 18 U.S.C. § 2511(2)(d). Advertisers conspicuously fail to mention—and apparently do not contest—that Meta obtained participants’ prior consent to participate in the Facebook Research App, and with good reason: Participants affirmatively consented to “Facebook … collecting data about [their] Internet browsing activity and app usage” to enable Facebook to “understand how [they] browse the Internet, how [they] use the features in the apps [they’ve] installed, and how people interact with the content [they] send and receive."

So users consented?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#49
post #19

There's a lot of confusion around these stories these days, which reminds me of the "Gmail is looking at your emails" stories[1]. First, this is not wiretapping, come on. There's targeted man-in-the-middle (MITM) attacks, and then there's this. This is plainly "we are using advanced powers to analyze your traffic". This is not even Superfish[2] type of stuff, where Lenovo had preinstalled root certs onto laptops to d…

That might have been true in the past, but nowadays at least macOS/Android/iOS can enforce several restrictions on the apps you install, like prevent them from changing OS settings/files, limit access to only specified/opt-in directories, limit the amount of background activity, etc. I don't know about Windows or Linux though.

Windows applications can easily install TLS root certificates, which essentially all „anti virus“ tools (i.e. snake oil) do. On Linux, it’s obvious; if you’re installing something as root, you can add certificates. In that context, apple is doing something right and makes it rather tedious to install root certs

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#50
post #36

Earlier quoted context omitted.

So this one time, I had a bug report at a client site. The business was largely a member of _______ religion. Our images wouldn't load in the app, but did on the website. How odd I thought, that doesn't make sense! Luckily I was able to be physically present, so I hopped down with laptop in tow, ssh'd into the server and started tailing logs.... Sure enough all the API requests for data were coming through, but whene…

Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't t…

It's not corporate level it was/is religious group level (of which this particular org I'm guessing largely employed staff from that religion). They are well known within our country to be quite insular.

It certainly seemed for all intents and purposes if you were a member of _____ group (wider than the company) you had the vpn on your device, and it was filtering content. I've found other reports in other countries of that happening with the same group.

So it's not corporate content filtering, it's personal content filtering and our app got caught up in it (and approved).

It certainly made my skin crawl for anyone in that religion. That means the central filtering service could be reading messages. Not sure if they're that sophisticated but certainly they didn't want people to see random images/videos.

Post reply on HN