Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

51–60 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#51

Earlier quoted context omitted.

Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't t…

From the inference of the commenter, I think they were referring to an app on a mobile device and not the device itself. It also sounds like their issue was at the ISP provider level, as well, which takes the business out of the loop of being the data controller/owner (of the collected data) at that point. Note: I'm not saying that your comment doesn't have merit, I just don't think that the points that you made appl…

After re-reasing the comment I think you're right. I had a hard time grokking it it seems. But since the issue was apparently a VPN app installed on the phone, I don't know whether this was the ISP or maybe their IT service provider that did content filtering on behalf of the company (like an outsourced IT department?)

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#52

Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the obvious pressures, I salute you.

1. https://www.acm.org/code-of-ethics

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#53

Earlier quoted context omitted.

From the inference of the commenter, I think they were referring to an app on a mobile device and not the device itself. It also sounds like their issue was at the ISP provider level, as well, which takes the business out of the loop of being the data controller/owner (of the collected data) at that point. Note: I'm not saying that your comment doesn't have merit, I just don't think that the points that you made appl…

After re-reasing the comment I think you're right. I had a hard time grokking it it seems. But since the issue was apparently a VPN app installed on the phone, I don't know whether this was the ISP or maybe their IT service provider that did content filtering on behalf of the company (like an outsourced IT department?)

The VPN (much like Meta's) is doing some root cert trickery to filter content that is deemed inappropriate or potentially inappropriate. This appeared to be controlled by a Company A in another country that undoubtedly contracted to Y religion to be their central point of content filtering globally.

So, member of the church? you get this VPN on your phone, (not sure whether phone was supplied by the church, but certainly this VPN was on it) VPN is effectively content filtering and blocking content.

I had our app whitelisted by that central company (literally raised a ticket with them, next day magically fixed).

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#54

So how can we be sure now that todays VPNs are not tomorrows Onavos. :(

Certificate pinning and validation in apps for one. Onavo's VPN was really clear it collected market research data. It was as informed consent as a click-through could be.

Interception of encrypted communications is beyond the expectation of what most people would consider "collecting market research data"

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#55

why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS

> why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS

Your comment seems to infer that you're unable to empathize with people who might think/understand differently than you. It also seems to negate that you avail of other services/non-self-controlled processes without worrying about the threat models, there.

Just hand-waiving with a "Why don't people just do 'x'?" is ironic - in the sense of "Why do you do your own medical care?" or "Why don't you grow your own food and slaughter your own animals?" or "Why don't you manufacture your own phone, it's operating system - oh, and the cellular tower closest to you?".

Threat models exist, _everywhere_, and it's impossible for someone to build all of the pieces, themselves, to prevent all threat models at every possible avenue/point.

In other words, at a non-arbitrary point, doing _everything_ yourself is untenable and that's precisely why services in society exist, today (that and ease of access, use, required foreknowledge, and - most notably - cost).

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#56
post #13

What do you think Cloudflare is doing with its SSL termination/offloading?

Why single out Cloudflare? They are not the only CDN or PaaS with SSL fronting.

I honestly can't think of one without googling. Cloudflare is kind of everywhere. Just like Google... can't really get rid of them even if you want to.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#57
post #50

Earlier quoted context omitted.

Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't t…

It's not corporate level it was/is religious group level (of which this particular org I'm guessing largely employed staff from that religion). They are well known within our country to be quite insular. It certainly seemed for all intents and purposes if you were a member of _____ group (wider than the company) you had the vpn on your device, and it was filtering content. I've found other reports in other countries…

Is it like required from their religious leadership to install this? That is incredible, and I only now understand your comment to its full extent. That is brutal.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#58
post #48

Direct link to PDF: https://s3.documentcloud.org/documents/24520332/merged-fb.pd... Here is Meta's response: https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3... Meta denies that they violated the Wiretap Act but offers no evidence of consent. (They try, but it is a laughable attempt.) Meta is also arguing the documents are not relevant. Meta claims the VPN app intercepting communications with other compan…

Here is a quote from Facebook/Meta's legal council to the Judge. In this document "Advertisers" refers to Snapchat, YouTube and Amazon. "... the Wiretap Act provides that an interception is not unlawful if a party to the communication “has given prior consent to such interception.” 18 U.S.C. § 2511(2)(d). Advertisers conspicuously fail to mention—and apparently do not contest—that Meta obtained participants’ prior co…

Lawyer here.

No.

They have ...'d out an important part of 2511(2)(d).

(and they probably meant (c))

First, it starts out with: "It shall not be unlawful under this chapter for a person not acting under color of law "

This basically means a state/federal official or someone acting in their capacity as one (the color of law part basically means it applies even when they act beyond their legal authority by accident)

Which they aren't. So this doesn't apply at all. (d) has an additional requirement they ...'d out at the end, but (c) does not.

So it's both a wrong cite and a dumb one.

Second, you'll note "competitive research" or anything similar is not one of the allowage usages of collecting data that facebook got.

Third, the return argument will also be "the how matters", and users did not consent to this how, and would not have.

If I give consent to participate in collection of my internet data, it doesn't give you authorization to like, have someone live in my house and follow me around 24/7 so they can see what i do on the internet.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#60

If an individual had somehow done this, I expect that the Computer Fraud and Abuse Act would be used against them. With Meta, we'll see.

I heard about this a few years ago. The trial participants were informed, consented, and paid. If you consent to a root cert being installed and analytics being proxied, well, that's that.
Post reply on HN