Earlier quoted context omitted.
there's nothing wrong with corporations tracking use of their hardware. they have to watch for data exfiltration and attempts to download malware, etc. don't use a corporate device for anything you don't want work to see. use your own. that's not a hard ask.
> there's nothing wrong with corporations tracking use of their hardware. As written, that means they can secretly enable the camera and microphone to surveil my house, supposedly to check the usage (or non-usage) of the hardware. Surely that's very "wrong", if not also illegal in most places. Not everything about or near the hardware is fair game.
How did Facebook intercept their competitor's encrypted mobile app traffic?
71–80 of 222 posts
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#72So just to be clear on what is being alleged, because the write-ups are omitting this detail: from what I can tell FB paid SC users to participate in “market research” and install the proxy. The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. (I’d love to get more detail on exactly what the participants were told they were getting paid for, but I’d be surpr…
I hope they were upfront about what they were collecting. The article didn’t show what the consent screen was before installing the proxy.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#73Earlier quoted context omitted.
seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.
What is described in the article is not some elaborate scheme or novel work of software engineering. Rather, it's exactly what 99% of corporate networks do (proxy server with SSL inspection using a custom root certificate) "to combat cyber threats". As coincidence would have it, this is the perfect alibi provided by a snake oil "cybersecurity" app by one of the world's largest companies. Every tech company that has p…
The comparison with VPNs doesn't hold either, because for all their faults VPNs do not decrypt traffic going through them.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#74Earlier quoted context omitted.
That might be an increasingly common view on the shop floor, but how confident are you that it filters up through all levels of your org?
there's 5 people in my company, and we talk daily. want to split 10s since you've already doubled down? btw, I can add my crypto wallet to my bio so you can pay up if you'd like /s
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#75Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#76Earlier quoted context omitted.
Big tech and telecommunications companies are effectively miniature arms of the U.S. government at this point. As seen by the "Protect America Act" of 2007[0], the government will retroactively cover their own ass and your companies' ass if deemed important enough to the intelligence apparatus. There isn't a chance in hell that Meta would be brought criminal charges for wiretapping. 0: https://en.wikipedia.org/wiki/P…
I'm assuming they were doing it for the federal government at this point. There's no reason for them to spy on another app, they can hire almost any developer they want.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#77Ooooooooh, SSLbump. There has to be a court precedent that criminalized sniffing network traffic on the customer’s side. Should be one of those many cases involving wiretapping for banking info.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#78Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#79Earlier quoted context omitted.
Your work does this. This is incredibly common on basically every corporate device issued today. The real issue is the NUX, which doesn't look like it made the data collection clear to users.
My work puts a big banner on the login screen that says up front that they can and will record and monitor everything on this machine. And IMO that's fine, because it's their machine. If they wanted to do that to my machine it would be a problem.
Re: How did Facebook intercept their competitor's encrypted mobile app traffic?
#80If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.
Our apps would be deplatformed on Android and iOS, and our businesses would be prosecuted by the DoJ and FBI.
The fact Apple and Microsoft services both work in China shows they are a little more trustworthy.