https://mashable.com/article/facebook-used-onavo-vpn-data-to...
Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
61–70 of 189 posts
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#62Earlier quoted context omitted.
Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't t…
It's not corporate level it was/is religious group level (of which this particular org I'm guessing largely employed staff from that religion). They are well known within our country to be quite insular. It certainly seemed for all intents and purposes if you were a member of _____ group (wider than the company) you had the vpn on your device, and it was filtering content. I've found other reports in other countries…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#63Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#64There's a lot of confusion around these stories these days, which reminds me of the "Gmail is looking at your emails" stories[1]. First, this is not wiretapping, come on. There's targeted man-in-the-middle (MITM) attacks, and then there's this. This is plainly "we are using advanced powers to analyze your traffic". This is not even Superfish[2] type of stuff, where Lenovo had preinstalled root certs onto laptops to d…
So, your argument is that MITM/wiretapping is okay if you do it at a large enough scale?
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#65Earlier quoted context omitted.
Which service do you use? Mullvad?
That could be either Mullvad or ProtonVPN. Both are Swiss zero log, Mullvad has a flat 5 euro/month charge that goes back to when they started to (they say) forever - you can send them cash in envolope for the next twenty years with a generated account number and you're away. ProtonVPN has plans - the two year streaming sign up is 4.99 euro/month.
Realistically, all VPNs are compromised. But for most people's threat model, that's irrelevant anyways.
Proton for instance revealed the location of a climate activist leading to his arrest[2], with the inspiring message from the CEO that "privacy protections can be suspended", silently on a per-user basis at any time.
Haven't seen anything like that for Mullvad, but it's probably the same. At least the company takes crypto. But these things are always just surface level obscurity at best.
[1]: https://en.m.wikipedia.org/wiki/Crypto_AG
[2]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#66Earlier quoted context omitted.
That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should
I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#67Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#68Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…
That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should
1. Nobody will care in 10 days. 2. They will get a slap on the wrist at best.
Reminds me of Google driving around in StreetView cars, hacking and capturing all wifi traffic they could get their hands on. Did anything happen? Of course not!
https://www.theguardian.com/technology/2010/may/15/google-ad... https://www.wired.com/2012/05/google-wifi-fcc-investigation/
The guardian says "open" networks, apart from the fact that in 2010 networks were not secured by default in many cases. I think WEP 1 was a thing and easily hacked, and I would not be surprised if they were actually Wardriving, on the largest scale ever.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#69Earlier quoted context omitted.
That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should
I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#70What do you think Cloudflare is doing with its SSL termination/offloading?
Why single out Cloudflare? They are not the only CDN or PaaS with SSL fronting.