Live data from Hacker News

How did Facebook intercept their competitor's encrypted mobile app traffic?

doubleagent.net

91–100 of 222 posts

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#91
post #25

Why didn't a big company like Snapchat not have certificate pinning? Something is amiss here!?

Snapchat do certificate pinning for it's main API domain. I am not exactly sure why analytics domain are different and why not have certificate pinning. (I thought analytics go through the same API domain, but it must be wrong then).

The analytics domain was "sc-analytics.appspot.com" in which the lack of pinning is described at the tail end of the blog post.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#92

Reading this article I'm just thinking that Facebook has wing that's just an NSA front at this point.

People seem to forget that the research that turned into Google was initially funded by the NSA and CIA:

https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

Cars now come with Google services / Android baked into the damn infotainment system, with no possible way to pull it out. What could possibly go wrong with an advertising company seeing everywhere you go, and everyone who rides in your car?

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#93

Earlier quoted context omitted.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.

> seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? It’s not really spelled out clearly in the article, but this was a specific program where people had to choose to opt-in in exchange for compensation. This wasn’t simply Facebook hijacking random people’s traffic because they accepted the ToS or used the Facebook app Not de…

The article details how users were lied to about what was being collected and why.

If you lie to someone to get them to sign an agreement, that agreement is voided in nearly any sane jurisdiction on the planet.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#94

Earlier quoted context omitted.

Looks like this was the real reason Facebook could not comply with China's data sovereignty laws and had to abandon the market. The fact Apple and Microsoft services both work in China shows they are a little more trustworthy.

> Looks like this was the real reason Facebook could not comply with China's data sovereignty laws and had to abandon the market. How so? > The fact Apple and Microsoft services both work in China shows they are a little more trustworthy. Absolutely not. Companies apply different policies in different countries they operate in. This tells you nothing more than those companies came to a mutually beneficial agreement w…

Indeed. Even McDonalds has different menus, local workers, local employee standards, and even how their business signage looks, depending upon country/location.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#95
post #54

So just to be clear on what is being alleged, because the write-ups are omitting this detail: from what I can tell FB paid SC users to participate in “market research” and install the proxy. The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. (I’d love to get more detail on exactly what the participants were told they were getting paid for, but I’d be surpr…

From the article:

> Note this is a new case, different from the one that TechCrunch also covered in which Facebook were paying teenagers to gather data on usage habits. That resulted in the Onavo app being pulled from the app stores and fines.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#96

Earlier quoted context omitted.

seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.

> seriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? It’s not really spelled out clearly in the article, but this was a specific program where people had to choose to opt-in in exchange for compensation. This wasn’t simply Facebook hijacking random people’s traffic because they accepted the ToS or used the Facebook app Not de…

> This wasn’t simply Facebook hijacking random people’s traffic because they accepted the ToS or used the Facebook app

Do you have further insights or references on what was the "trigger condition"? This is a new case, separate to the previous litigation related to the VPN app.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#97

Reading this article I'm just thinking that Facebook has wing that's just an NSA front at this point.

People seem to forget that the research that turned into Google was initially funded by the NSA and CIA: https://qz.com/1145669/googles-true-origin-partly-lies-in-ci... Cars now come with Google services / Android baked into the damn infotainment system, with no possible way to pull it out. What could possibly go wrong with an advertising company seeing everywhere you go, and everyone who rides in your car?

Yeah... They are all connected to the "three letter agencies", in Google's case it was very early, but I believe nobody can stay popular and not have all of these agencies infiltrate then take control of them.

Apple, Google, Facebook, Twitter, Alexa, they are a gold mine for agencies, but even news sites, movie studios, and YouTubers. This is why they've been after Tik Tok for so long, they know how useful that app / network is.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#98

Reading this article I'm just thinking that Facebook has wing that's just an NSA front at this point.

People seem to forget that the research that turned into Google was initially funded by the NSA and CIA: https://qz.com/1145669/googles-true-origin-partly-lies-in-ci... Cars now come with Google services / Android baked into the damn infotainment system, with no possible way to pull it out. What could possibly go wrong with an advertising company seeing everywhere you go, and everyone who rides in your car?

This is true, but so far there are ways to disable much of this.

For example on a Ford, you can literally pull the fuse for the GSM modem. On a GM, you can pull the antenna from OnStar, and put a resister there in replacement... thus rendering it unable to communicate to home base.

This doesn't solve everything, but it at least stops the immediate phone home.

Re: How did Facebook intercept their competitor's encrypted mobile app traffic?

#99

Earlier quoted context omitted.

That’s not sufficient - you also need to intercept traffic somehow which they successfully accomplished by buying this vpn company and using them to proxy victims traffic through their infra

Victims that were being paid to participate? Edit: Not excusing Facebook here, but feel like this whole thing is in a weird grey area. It is like getting paid to have a Nielsen box monitoring your TV and then complaining when you find out it also knew what you watched on your DVD player.

Read the wording on the apk[0] - while it does mention they collect data to improve fb product it sure doesn’t mention the data includes telemetry for competitors’ apps.

[0] https://apkpure.com/onavo-protect-from-facebook/com.onavo.sp...

Post reply on HN