Earlier quoted context omitted.
Wouldn’t Meta simply hire unlicensed “engineers”?
You simply legislate that if a company is building anything that will be used regularly by more than eg. a few thousand people, then the work must be designed and/or signed off by a licensed engineer, who will a) be subject to a code of ethics and b) be professionally liable for any failures causing loss or damage to the public. We seem to be able to manage this with bridges, planes, electrical & hydro installations…
Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
91–100 of 189 posts
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#92Earlier quoted context omitted.
That could be either Mullvad or ProtonVPN. Both are Swiss zero log, Mullvad has a flat 5 euro/month charge that goes back to when they started to (they say) forever - you can send them cash in envolope for the next twenty years with a generated account number and you're away. ProtonVPN has plans - the two year streaming sign up is 4.99 euro/month.
Ah, good 'ole trustworthy Swiss companies! Like Crypto AG![1] Realistically, all VPNs are compromised. But for most people's threat model, that's irrelevant anyways. Proton for instance revealed the location of a climate activist leading to his arrest[2], with the inspiring message from the CEO that "privacy protections can be suspended", silently on a per-user basis at any time. Haven't seen anything like that for M…
That person isn't just a climate activist, they (and others who used that email account) broke French laws. Swiss authorities compelled the disclosure.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#93Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…
That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#94Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…
That is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#95Isn't this known since 2018? https://mashable.com/article/facebook-used-onavo-vpn-data-to...
Also noteworthy is that Google were also doing something similar at the time, both were side-stepping Apple's privacy protections in iOS by using enterprise certificates that allowed the side-loading of apps without Apple's overview. In response Apple more thoroughly restricted how these certificates can be used.
Interestingly I've noticed in the DMA threads people suggesting that a company exploiting side-loading to dodge Apple's privacy protections was nothing more than fear mongering. As if this is a red line developers won't cross.
To me, it's wild to think that people on HN don't know about this relatively recent history and are so naive to think that these protections were just pulled out of the air to frustrate developers, and not a reaction to an on-going arms war against consumer's right to privacy.
(1) https://www.extremetech.com/internet/284770-apple-kills-face...
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#96Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#97Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#98Earlier quoted context omitted.
Which service do you use? Mullvad?
That could be either Mullvad or ProtonVPN. Both are Swiss zero log, Mullvad has a flat 5 euro/month charge that goes back to when they started to (they say) forever - you can send them cash in envolope for the next twenty years with a generated account number and you're away. ProtonVPN has plans - the two year streaming sign up is 4.99 euro/month.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#99Earlier quoted context omitted.
Here is a quote from Facebook/Meta's legal council to the Judge. In this document "Advertisers" refers to Snapchat, YouTube and Amazon. "... the Wiretap Act provides that an interception is not unlawful if a party to the communication “has given prior consent to such interception.” 18 U.S.C. § 2511(2)(d). Advertisers conspicuously fail to mention—and apparently do not contest—that Meta obtained participants’ prior co…
Lawyer here. No. They have ...'d out an important part of 2511(2)(d). (and they probably meant (c)) First, it starts out with: "It shall not be unlawful under this chapter for a person not acting under color of law " This basically means a state/federal official or someone acting in their capacity as one (the color of law part basically means it applies even when they act beyond their legal authority by accident) Whi…
Did you miss the "not" part?
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#100"Meta" is The Evil Online Empire at this point, it's company history is a litany is decidedly immoral if not outright evil actions.
(Source: https://www.vice.com/en/article/v7gd9b/facebook-helped-fbi-h...)