Yeah, crap move but my concern isn't those other scoundrels, it's me / us.
Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
71–80 of 189 posts
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#72Earlier quoted context omitted.
That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should
I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#73Earlier quoted context omitted.
Why single out Cloudflare? They are not the only CDN or PaaS with SSL fronting.
I honestly can't think of one without googling. Cloudflare is kind of everywhere. Just like Google... can't really get rid of them even if you want to.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#74So, the FANGs can conduct mass psyops warfare against the populace basically with impunity -- a pesky little suit now and then is inconsequential. But what will happen when they get caught stealing each other's surveillance booty?
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#75Earlier quoted context omitted.
So, your argument is that MITM/wiretapping is okay if you do it at a large enough scale?
If someone consents to your clear request to read their data in the plain, then it's not evil. Still not my cup of tea, but if you clearly explain and obtain consent, it's shady but fine.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#76Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#77Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…
That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should
Why do you trust it ? Do you think that others (Google, Microsoft, Apple) are not doing/would not do such a thing ? SSL is as secure as its certificates.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#78What do you think Cloudflare is doing with its SSL termination/offloading?
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#79Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#80Earlier quoted context omitted.
I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…
Wouldn’t Meta simply hire unlicensed “engineers”?
We seem to be able to manage this with bridges, planes, electrical & hydro installations etc. No reason it shouldn't be the same for critical software infrastructure.