Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

71–80 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#71
Did the bury the lede? Sure this a blow against "competitors" but that is ultimately a competition for the collection of data, user data. In doing this FB has expanded its ability to hoover up more data at the individual user level, correct?

Yeah, crap move but my concern isn't those other scoundrels, it's me / us.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#72
post #52

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…

Wouldn’t Meta simply hire unlicensed “engineers”?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#73
post #56

Earlier quoted context omitted.

Why single out Cloudflare? They are not the only CDN or PaaS with SSL fronting.

I honestly can't think of one without googling. Cloudflare is kind of everywhere. Just like Google... can't really get rid of them even if you want to.

You can’t think of anybody else in the CDN or DoS mitigation business other than cloudflare?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#75
post #64

Earlier quoted context omitted.

So, your argument is that MITM/wiretapping is okay if you do it at a large enough scale?

If someone consents to your clear request to read their data in the plain, then it's not evil. Still not my cup of tea, but if you clearly explain and obtain consent, it's shady but fine.

So how is that relevant in the context here. FB did not clearly request to be able to read all traffic (encrypted and nonencrypted) so how could they get consent. Unless you're arguing, "we will monitor your Internet usage", clearly means we will man-in-the-middle all your connections. Which would be a weird take.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#77

Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

> This is such an immense breach of trust

Why do you trust it ? Do you think that others (Google, Microsoft, Apple) are not doing/would not do such a thing ? SSL is as secure as its certificates.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#78
post #13

What do you think Cloudflare is doing with its SSL termination/offloading?

That's different. I have a lot of problems with CF, but when you sign up for a service which requires to see the traffic and you configure it explicitly to see your traffic... what's the complaint here?

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#80
post #52

Earlier quoted context omitted.

I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…

Wouldn’t Meta simply hire unlicensed “engineers”?

You simply legislate that if a company is building anything that will be used regularly by more than eg. a few thousand people, then the work must be designed and/or signed off by a licensed engineer, who will a) be subject to a code of ethics and b) be professionally liable for any failures causing loss or damage to the public.

We seem to be able to manage this with bridges, planes, electrical & hydro installations etc. No reason it shouldn't be the same for critical software infrastructure.

Post reply on HN