Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
1–10 of 189 posts
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#2Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018.
The goal of Facebook’s SSL bump technology was the company’s acquisition, decryption, transfer, and use in competitive decision making of private, encrypted in-app analytics from the Snapchat, YouTube, and Amazon apps, which were supposed to be transmitted over a secure connection between those respective apps and secure servers (sc-analytics.appspot.com for Snapchat, s.youtube.com and youtubei.googleapis.com for YouTube, and *.amazon.com for Amazon).
This code, which included a client-side “kit” that installed a “root” certificate on Snapchat users’ (and later, YouTube and Amazon users’) mobile devices, see PX 414 at 6, PX 26 (PALM-011683732)(“we install a root CA on the device and MITM all SSL traffic”), also included custom server-side code based on “squid” (an open-source web proxy) through which Facebook’s servers created fake digital certificates to impersonate trusted Snapchat, YouTube, and Amazon analytics servers to redirect and decrypt secure traffic from those apps for Facebook’s strategic analysis, see PX 26 at 3-4 (Sep. 12, 2018: “Today we are using the Onavo vpn-proxy stack to deploy squid with ssl bump the stack runs in edge on our own hosts (onavopp and onavolb) with a really old version of squid (3.1).”); see generally http://wiki.squid-cache.org/Features/SslBump
Malware Bytes Article: https://www.malwarebytes.com/blog/news/2024/03/facebook-spie...
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#3Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#4Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#5Documents and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump t…
That's appalling to say at least. But Snapchat implemented certificate-pinning since 2015. Does that mean either the analytics endpoint was not covered or somehow the certificate-pinning is circumvented in this case?
This sounds most likely
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#6Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#7But what will happen when they get caught stealing each other's surveillance booty?
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#8Some recent related discussion: https://news.ycombinator.com/item?id=39860486
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#9Facebook is not removable from many android devices... does this mean Zuckerberg has been seeing all user traffic for years regardless of tls?
https://en.wikipedia.org/wiki/Onavo is slightly more readable than the legal document submitted as the link.
Re: Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
#10Facebook is not removable from many android devices... does this mean Zuckerberg has been seeing all user traffic for years regardless of tls?
Then your YouTube, Snapchat analytics would get man in the middled