Live data from Hacker News

Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

documentcloud.org

81–90 of 189 posts

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#81
post #60

If an individual had somehow done this, I expect that the Computer Fraud and Abuse Act would be used against them. With Meta, we'll see.

I heard about this a few years ago. The trial participants were informed, consented, and paid. If you consent to a root cert being installed and analytics being proxied, well, that's that.

Two issues. 1) Did Snapchat consented to this? And 2) did the users know what they were consenting to?

Saying we’re going to do “ traffic monitoring” doesn’t carry the weight of “we are going to listen to your private conversations”.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#83
post #7

So, the FANGs can conduct mass psyops warfare against the populace basically with impunity -- a pesky little suit now and then is inconsequential. But what will happen when they get caught stealing each other's surveillance booty?

Bear in mind that they don’t applied this to everyone, which would be practically impossible.

They hired Snapchat users (via a testing services provider ) to let meta observe their usage of Snapchat.

Something akin to paying someone to let a meta researcher sit by your side and observe while you use the app.

This happens all the time (hiring the testing services to recruit users to use your own app and analyze the patterns with screen recordings and such).

The news here is paying for someone to “test” a competitors’ app.

I hope that the testers knew they had Snapchat analyzed and not that they were told they were testing only Onavo.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#84
post #69
post #52

Earlier quoted context omitted.

I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…

You expect all people to have morals in the first place. That is an erroneous assumption.

Nah, I've met enough amoral people over the course of my career to know that's not the case. However, the overwhelming majority of people I've worked with are people who do have morals and do care about the outcomes they're creating, and that gives me great hope.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#85
post #77

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

> This is such an immense breach of trust Why do you trust it ? Do you think that others (Google, Microsoft, Apple) are not doing/would not do such a thing ? SSL is as secure as its certificates.

Honestly, yes, I don't think Microsoft Google and Apple would do something like this.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#86
post #60

Earlier quoted context omitted.

I heard about this a few years ago. The trial participants were informed, consented, and paid. If you consent to a root cert being installed and analytics being proxied, well, that's that.

Two issues. 1) Did Snapchat consented to this? And 2) did the users know what they were consenting to? Saying we’re going to do “ traffic monitoring” doesn’t carry the weight of “we are going to listen to your private conversations”.

Why would Snapchat need to consent? It's my traffic.

I'd wager that most participants don't know the full details of the program, but "company pays you for your usage information" is a very old thing. You could (maybe you still can) get paid to install a box on your TV that recorded all of your viewing statistics to be used for market research.

To me, the biggest concern is that this is only really viable because Facebook had nontrivial market penetration of a more-or-less unrelated product to their main offering. This isn't something that Snapchat could have easily done to get market research on Facebook usage, for example. This feels (to me) more like an anticompetition concern rather than a privacy concern.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#88

So how can we be sure now that todays VPNs are not tomorrows Onavos. :(

Don’t install additional root certificates.

That’s what Facebook enticed users to do here. Without that root cert they wouldn’t have been able to see as much as they did.

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#89
post #52

Earlier quoted context omitted.

That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should

I also hope that any ethically minded engineers inside Meta take a stand against this BS. The only way stuff like this happens is because engineers working on these projects decide that they can set aside whatever morals they may have had for the price of a big fat FAANG pay cheque. It's about time our profession adopted a code of ethics, like that of the ACM[1]. To the engineers who _have_ walked away despite the ob…

[deleted]

Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic

#90
post #80

Earlier quoted context omitted.

Wouldn’t Meta simply hire unlicensed “engineers”?

You simply legislate that if a company is building anything that will be used regularly by more than eg. a few thousand people, then the work must be designed and/or signed off by a licensed engineer, who will a) be subject to a code of ethics and b) be professionally liable for any failures causing loss or damage to the public. We seem to be able to manage this with bridges, planes, electrical & hydro installations…

> No reason it shouldn't be the same for critical software infrastructure.

Why do you think Meta's work is critical software infrastructure?

Post reply on HN