Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

61–70 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#62
post #50

Earlier quoted context omitted.

Not that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't t…

It's not corporate level it was/is religious group level (of which this particular org I'm guessing largely employed staff from that religion). They are well known within our country to be quite insular. It certainly seemed for all intents and purposes if you were a member of _____ group (wider than the company) you had the vpn on your device, and it was filtering content. I've found other reports in other countries…

Yes, this exists. There's more than one company you can choose. It's not 'forced' but strongly recommended. Also, my love for hacking started with getting around it...

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#63
post #33
post #18

Earlier quoted context omitted.

First, all VPNs spy on you, just don't believe these claims because they are forced by law to do it. Second, don't use a VPN that clearly states that they're analyzing your traffic data.

> forced by law Which law?

National Security Letters.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#64
post #19

There's a lot of confusion around these stories these days, which reminds me of the "Gmail is looking at your emails" stories[1]. First, this is not wiretapping, come on. There's targeted man-in-the-middle (MITM) attacks, and then there's this. This is plainly "we are using advanced powers to analyze your traffic". This is not even Superfish[2] type of stuff, where Lenovo had preinstalled root certs onto laptops to d…

So, your argument is that MITM/wiretapping is okay if you do it at a large enough scale?

If someone consents to your clear request to read their data in the plain, then it's not evil. Still not my cup of tea, but if you clearly explain and obtain consent, it's shady but fine.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#65
post #40
post #37

Earlier quoted context omitted.

Which service do you use? Mullvad?

That could be either Mullvad or ProtonVPN. Both are Swiss zero log, Mullvad has a flat 5 euro/month charge that goes back to when they started to (they say) forever - you can send them cash in envolope for the next twenty years with a generated account number and you're away. ProtonVPN has plans - the two year streaming sign up is 4.99 euro/month.

Ah, good 'ole trustworthy Swiss companies! Like Crypto AG![1]

Realistically, all VPNs are compromised. But for most people's threat model, that's irrelevant anyways.

Proton for instance revealed the location of a climate activist leading to his arrest[2], with the inspiring message from the CEO that "privacy protections can be suspended", silently on a per-user basis at any time.

Haven't seen anything like that for Mullvad, but it's probably the same. At least the company takes crypto. But these things are always just surface level obscurity at best.

[1]: https://en.m.wikipedia.org/wiki/Crypto_AG

[2]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#66
post #52

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…

Ethically minded engineers don't go work for Facebook in the first place.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#68

Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

Here is what is going to happen:

1. Nobody will care in 10 days. 2. They will get a slap on the wrist at best.

Reminds me of Google driving around in StreetView cars, hacking and capturing all wifi traffic they could get their hands on. Did anything happen? Of course not!

https://www.theguardian.com/technology/2010/may/15/google-ad... https://www.wired.com/2012/05/google-wifi-fcc-investigation/

The guardian says "open" networks, apart from the fact that in 2010 networks were not secured by default in many cases. I think WEP 1 was a thing and easily hacked, and I would not be surprised if they were actually Wardriving, on the largest scale ever.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#69
post #52

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…

You expect all people to have morals in the first place. That is an erroneous assumption.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#70
post #13

What do you think Cloudflare is doing with its SSL termination/offloading?

Why single out Cloudflare? They are not the only CDN or PaaS with SSL fronting.

They explained pretty clearly why they think that's the case. You're both right though. It's likely not the case that cloud flare is the only company conducting and cooperating with government agencies to do these types of things. In my opinion it would be very silly to assume that.
Post reply on HN