news.volyx.in

How did Facebook intercept their competitor's encrypted mobile app traffic? (doubleagent.net)

503 points by haxrob · 744 days ago · 209 comments on HN

Article summary

A technical investigation into Facebook's acquisition of Onavo, a VPN app, reveals that the company used the app to intercept encrypted traffic from users' devices, potentially breaching the Wiretap Act. The app, Onavo Protect, had over 10 million Android installations and contained code to prompt users to install a Facebook-issued certificate authority certificate, allowing Facebook to decrypt TLS traffic. This technique, known as 'ssl bump', was used to gain competitive insights into other companies, including Snapchat, YouTube, and Amazon. The investigation is based on court documents and reverse engineering of archived Onavo Protect app packages for Android.

Main themes

  • Facebook data collection
  • Onavo VPN app
  • Encrypted traffic interception
  • Wiretap Act
  • Competitor intelligence
  • Mobile app security

What commenters say

  • The use of Onavo to intercept encrypted traffic is a clear violation of users' privacy and potentially illegal.
  • The fact that users were paid to participate in the data collection does not excuse Facebook's actions, as they were not fully informed about the nature of the data being collected.
  • The incident highlights the need for greater transparency and regulation of tech companies' data collection practices.
  • Some argue that Facebook's actions, although questionable, were not necessarily malicious, but rather a misguided attempt to gather market research data.
  • The use of certificate authority certificates to intercept encrypted traffic is a serious security risk, and users should be aware of the potential dangers of installing such certificates.
  • The incident raises questions about the ethics of working for companies like Facebook, and whether employees have a responsibility to speak out against potentially harmful practices.
  • The fact that Facebook considered using the Accessibility API to intercept traffic is particularly troubling, as it would have exploited a feature intended to help people with disabilities.
  • The use of Onavo to intercept traffic is just one example of a broader pattern of tech companies prioritizing profits over user privacy and security.