Live data from Hacker News

How did Facebook intercept their competitor's encrypted mobile app traffic?

doubleagent.net

71–80 of 222 posts

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#71
post #52
post #45

Earlier quoted context omitted.

there's nothing wrong with corporations tracking use of their hardware. they have to watch for data exfiltration and attempts to download malware, etc. don't use a corporate device for anything you don't want work to see. use your own. that's not a hard ask.

> there's nothing wrong with corporations tracking use of their hardware. As written, that means they can secretly enable the camera and microphone to surveil my house, supposedly to check the usage (or non-usage) of the hardware. Surely that's very "wrong", if not also illegal in most places. Not everything about or near the hardware is fair game.

That's clearly not what was meant

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#72
post #54

So just to be clear on what is being alleged, because the write-ups are omitting this detail: from what I can tell FB paid SC users to participate in “market research” and install the proxy. The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. (I’d love to get more detail on exactly what the participants were told they were getting paid for, but I’d be surpr…

Neilson does something similar with TV where they install capture boxes in people’s houses to determine what they’re watching for their panels: https://www.nytimes.com/athletic/3194414/2022/03/22/the-ulti...

I hope they were upfront about what they were collecting. The article didn’t show what the consent screen was before installing the proxy.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#73

Earlier quoted context omitted.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.

What is described in the article is not some elaborate scheme or novel work of software engineering. Rather, it's exactly what 99% of corporate networks do (proxy server with SSL inspection using a custom root certificate) "to combat cyber threats". As coincidence would have it, this is the perfect alibi provided by a snake oil "cybersecurity" app by one of the world's largest companies. Every tech company that has p…

Doesn't change anything, consent and whether you own the device is everything.

The comparison with VPNs doesn't hold either, because for all their faults VPNs do not decrypt traffic going through them.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#74
post #36

Earlier quoted context omitted.

That might be an increasingly common view on the shop floor, but how confident are you that it filters up through all levels of your org?

there's 5 people in my company, and we talk daily. want to split 10s since you've already doubled down? btw, I can add my crypto wallet to my bio so you can pay up if you'd like /s

How much does your company pay IC8 or equivalent per year? $2M liquid? $3M? Hard for anyone to feel moral qualms when they’re earning generational wealth.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#76

Earlier quoted context omitted.

Big tech and telecommunications companies are effectively miniature arms of the U.S. government at this point. As seen by the "Protect America Act" of 2007[0], the government will retroactively cover their own ass and your companies' ass if deemed important enough to the intelligence apparatus. There isn't a chance in hell that Meta would be brought criminal charges for wiretapping. 0: https://en.wikipedia.org/wiki/P…

I'm assuming they were doing it for the federal government at this point. There's no reason for them to spy on another app, they can hire almost any developer they want.

Hiring another dev does not give them access to the raw numbers. It's not the same thing at all

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#77
post #2

Ooooooooh, SSLbump. There has to be a court precedent that criminalized sniffing network traffic on the customer’s side. Should be one of those many cases involving wiretapping for banking info.

Doesn't the computer fraud and abuse act cover this?

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#78
post #6

[flagged]

I'll entertain this, how does blockchaining DNS solve anything? Edit: Why is this down voted? I really don't understand how blockchain would help DNS.

because it won’t—entertaining the question legitimises these snake-oil peddlers

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#79
post #23

Earlier quoted context omitted.

Your work does this. This is incredibly common on basically every corporate device issued today. The real issue is the NUX, which doesn't look like it made the data collection clear to users.

My work puts a big banner on the login screen that says up front that they can and will record and monitor everything on this machine. And IMO that's fine, because it's their machine. If they wanted to do that to my machine it would be a problem.

It's "fine" in the way that I would leave that company at the first opportunity.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#80

If you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.

Our apps would be deplatformed on Android and iOS, and our businesses would be prosecuted by the DoJ and FBI.

Looks like this was the real reason Facebook could not comply with China's data sovereignty laws and had to abandon the market.

The fact Apple and Microsoft services both work in China shows they are a little more trustworthy.

Post reply on HN