Earlier quoted context omitted.
Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't t…
From the inference of the commenter, I think they were referring to an app on a mobile device and not the device itself. It also sounds like their issue was at the ISP provider level, as well, which takes the business out of the loop of being the data controller/owner (of the collected data) at that point. Note: I'm not saying that your comment doesn't have merit, I just don't think that the points that you made appl…
Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
51–60 of 189 posts
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#52Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…
That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#53Earlier quoted context omitted.
From the inference of the commenter, I think they were referring to an app on a mobile device and not the device itself. It also sounds like their issue was at the ISP provider level, as well, which takes the business out of the loop of being the data controller/owner (of the collected data) at that point. Note: I'm not saying that your comment doesn't have merit, I just don't think that the points that you made appl…
After re-reasing the comment I think you're right. I had a hard time grokking it it seems. But since the issue was apparently a VPN app installed on the phone, I don't know whether this was the ISP or maybe their IT service provider that did content filtering on behalf of the company (like an outsourced IT department?)
So, member of the church? you get this VPN on your phone, (not sure whether phone was supplied by the church, but certainly this VPN was on it) VPN is effectively content filtering and blocking content.
I had our app whitelisted by that central company (literally raised a ticket with them, next day magically fixed).
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#54So how can we be sure now that todays VPNs are not tomorrows Onavos. :(
Certificate pinning and validation in apps for one. Onavo's VPN was really clear it collected market research data. It was as informed consent as a click-through could be.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#55why people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS
Your comment seems to infer that you're unable to empathize with people who might think/understand differently than you. It also seems to negate that you avail of other services/non-self-controlled processes without worrying about the threat models, there.
Just hand-waiving with a "Why don't people just do 'x'?" is ironic - in the sense of "Why do you do your own medical care?" or "Why don't you grow your own food and slaughter your own animals?" or "Why don't you manufacture your own phone, it's operating system - oh, and the cellular tower closest to you?".
Threat models exist, _everywhere_, and it's impossible for someone to build all of the pieces, themselves, to prevent all threat models at every possible avenue/point.
In other words, at a non-arbitrary point, doing _everything_ yourself is untenable and that's precisely why services in society exist, today (that and ease of access, use, required foreknowledge, and - most notably - cost).
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#56What do you think Cloudflare is doing with its SSL termination/offloading?
Why single out Cloudflare? They are not the only CDN or PaaS with SSL fronting.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#57Earlier quoted context omitted.
Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't t…
It's not corporate level it was/is religious group level (of which this particular org I'm guessing largely employed staff from that religion). They are well known within our country to be quite insular. It certainly seemed for all intents and purposes if you were a member of _____ group (wider than the company) you had the vpn on your device, and it was filtering content. I've found other reports in other countries…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#58Direct link to PDF: https://s3.documentcloud.org/documents/24520332/merged-fb.pd... Here is Meta's response: https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3... Meta denies that they violated the Wiretap Act but offers no evidence of consent. (They try, but it is a laughable attempt.) Meta is also arguing the documents are not relevant. Meta claims the VPN app intercepting communications with other compan…
Here is a quote from Facebook/Meta's legal council to the Judge. In this document "Advertisers" refers to Snapchat, YouTube and Amazon. "... the Wiretap Act provides that an interception is not unlawful if a party to the communication “has given prior consent to such interception.” 18 U.S.C. § 2511(2)(d). Advertisers conspicuously fail to mention—and apparently do not contest—that Meta obtained participants’ prior co…
No.
They have ...'d out an important part of 2511(2)(d).
(and they probably meant (c))
First, it starts out with: "It shall not be unlawful under this chapter for a person not acting under color of law "
This basically means a state/federal official or someone acting in their capacity as one (the color of law part basically means it applies even when they act beyond their legal authority by accident)
Which they aren't. So this doesn't apply at all. (d) has an additional requirement they ...'d out at the end, but (c) does not.
So it's both a wrong cite and a dumb one.
Second, you'll note "competitive research" or anything similar is not one of the allowage usages of collecting data that facebook got.
Third, the return argument will also be "the how matters", and users did not consent to this how, and would not have.
If I give consent to participate in collection of my internet data, it doesn't give you authorization to like, have someone live in my house and follow me around 24/7 so they can see what i do on the internet.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#59Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#60If an individual had somehow done this, I expect that the Computer Fraud and Abuse Act would be used against them. With Meta, we'll see.