Live data from Hacker News

How did Facebook intercept their competitor's encrypted mobile app traffic?

doubleagent.net

41–50 of 222 posts

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#41

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.

It isn't because they have the money, it's because they have given the government access to whatever data they want. When it comes to three letter agencies it really isn't about money, it's about power and in today's digital world data is power.

To answer your specific question, this isn't okay. Both the government and large corporations have been given way too much power and we really have no hope of making any meaningful change until the people reclaim this power and put those in charge out on their ass.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#42

Earlier quoted context omitted.

Big tech and telecommunications companies are effectively miniature arms of the U.S. government at this point. As seen by the "Protect America Act" of 2007[0], the government will retroactively cover their own ass and your companies' ass if deemed important enough to the intelligence apparatus. There isn't a chance in hell that Meta would be brought criminal charges for wiretapping. 0: https://en.wikipedia.org/wiki/P…

I think The Onion nailed it in 2011: https://www.theonion.com/cias-facebook-program-dramatically-...

Which is clearly a red flag operation so that whenever someone serious tries to tout this, they'll be rebuffed as it's an article in the Onion. Those clever bastards!

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#44

Earlier quoted context omitted.

I think The Onion nailed it in 2011: https://www.theonion.com/cias-facebook-program-dramatically-...

Which is clearly a red flag operation so that whenever someone serious tries to tout this, they'll be rebuffed as it's an article in the Onion. Those clever bastards!

[deleted]

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#45
post #35

Earlier quoted context omitted.

My work puts a big banner on the login screen that says up front that they can and will record and monitor everything on this machine. And IMO that's fine, because it's their machine. If they wanted to do that to my machine it would be a problem.

I agree it's legally fine, but morally/socially there are ways to go-too-far.

there's nothing wrong with corporations tracking use of their hardware.

they have to watch for data exfiltration and attempts to download malware, etc.

don't use a corporate device for anything you don't want work to see.

use your own. that's not a hard ask.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#46

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

> If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file.

Yes. It's a good opportunity for an ambitious state attorney general to prosecute Facebook, of course.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#47
post #4

The email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's…

Their contribution to the genocide in Myanmar has said everything about Meta you'll ever need to know. It's a tragedy that working for Meta is generally seen as neutral whereas working at any defense-related companies is often met with scorn, despite the overwhelmingly greater negative impact that working at the former has.

And this doesn't even touch upon Instagram.

I guess that they pay too much and employ too much of our industry, greatly reducing criticism because we all have a friend who has worked at Meta or we may even have applied ourselves at some point. Whereas we don't know anyone who has been at e.g. Anduril at the likes.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#48
post #3

tl;dr: If you install and fully trust a root CA on your client device, of course your TLS traffic can be MITMed. edit: the problem, obviously, is that this app tricked the non-technical people into installing/trusting the root CA for malicious purposes. Clearly this was malware.

So I mean, just taking a quick look at the contents of /etc/ssl/certs and what Firefox shows me when I hit its View Certificates button, I see among dozens of other actors, Amazon, Microsoft, GoDaddy, and the Beijing Certificate Authority. No software has ever asked me if I want to trust any of these guys, they've been silently trusted during a software install I suppose. Does this mean they can all MITM my TLS traff…

Theoretically, yes, they could, I think. However, with Certificate Transparency, the fraudulent certificates these Certificate Authorities could create would have to be published in CT logs to be valid, where they would be quickly noticed, and the CA would (hopefully) lose credibility and be removed from device's trusted CA list.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#49

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.

> does agreeing to ToS mean you also agree to being spied on in a way that protects them?

This relates to a much bigger problem of courts upholding contracts even when nobody actually believes they represent an informed and voluntary agreement.

We aren't quite at the Looney-Tunes step of enforcing extra clauses that were hidden in invisibly small print, but things are drifting in that direction.

See also: https://www.law.cornell.edu/wex/adhesion_contract_(contract_...

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#50

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.

What is described in the article is not some elaborate scheme or novel work of software engineering. Rather, it's exactly what 99% of corporate networks do (proxy server with SSL inspection using a custom root certificate) "to combat cyber threats".

As coincidence would have it, this is the perfect alibi provided by a snake oil "cybersecurity" app by one of the world's largest companies.

Every tech company that has promulgated the lie that a VPN operated by a third party provides added security is indirectly responsible for this. Funneling all your traffic through a shady intermediary does no such thing, and in fact often does the opposite.

Post reply on HN