6 ms·
It's ethically dubious that the advertised function of the app is a VPN to "keep you and your data safe", while the reason it exists is so that all phone traffi
by irpapakons 9y ago
It's ethically dubious that the advertised function of the app is a VPN to "keep you and your data safe", while the reason it exists is so that all phone traffic goes to Facebook.
This is not clear from the app description -- there is only a generic message about monitored app use, to which users are so used as to not pay any attention.
> "The app's privacy policy says it may share information with "affiliates" that include its owner, Facebook. "As part of this process, Onavo receives and analyzes information about your mobile data and app use"
> A Facebook spokesman said it is clear when people download Onavo what information it collects and how it is used. "Websites and apps have used market-research services for years," the spokesman said, noting that the company also uses outside services to help it understand the market and improve services.
Then Facebook can attack the competition by seeing in real time how usage of competitive apps varies in response to new features and inform acquisition decisions.
> Onavo's data paved the way for the purchase of WhatsApp for $22 billion. Onavo showed the messaging app was installed on 99% of all Android phones in Spain -- showing WhatsApp was changing how an entire country communicated, the people said.
- thinkMOAR 9y ago"ethically dubious", i consider it criminal; though they probably got some (lawyer written) fine print to say it is not so.
- jondubois 9y agoYes, it sounds like malware. Had any other company done this, it would have caused outrage but for some reason Facebook just seems to get away with everything. I remember how big a deal the News International phone hacking scandal was; this actually seems much worse.
- willstrafach 9y agoCompanies which track app download and engagement metrics also do this via VPN apps. That is how they are able to obtain such data. Not new, but also not discussed much.
- daenney 9y agoI would be interested to hear from people with knowledge of EU and US law how shady this is in their respective jurisdictions. I'm having a hard time imagining what they did is OK, but I'm probably wrong.
- WhiteSource1 9y agoIf you can identify personal data (which if they can tie it to the user's Facebook account, that's pretty easy to do) it's likely (note: not a lawyer) a violation of the EU GDPR regulations (http://www.eugdpr.org/ http://www.eugdpr.org/)
- daenney 9y agoUnfortunately GDPR enforcement is about 9 months away. I don't think it applies retroactively.
- teej 9y agoI once sat in on a pitch from an antivirus software company who was selling the ability to look at the full browsing history of people who had visited your website. You could see all of their searches, if they visited competitors, and more. Most of the time I get annoyed of the FUD of "they're selling my data!" but this was different. It was true and it was scary.
- afandian 9y agoWhy not name them?
- devrandomguy 9y agoThat would identify the GP to within a small group (the meeting). They probably worked under an NDA. It would be great if an unrelated leak were to happen, though.
- teej 9y agoI'm not anonymous. You can identify me by going to my profile if you'd like. To be completely honest, I don't remember. It was 2 years ago and I sit on lots of these pitches. I remember pushing back on them about the methodology, hearing how the sausage was made, and noping right out. I want my team to be able to spend marketing dollars efficiently but I would never compromise my ethics to do so. Luckily I work somewhere that I can give a justified 'no' and keep my job.
- hammock 9y ago>seeing in real time how usage of competitive apps varies in response to new features and inform acquisition decisions. They could also ping you with a fb notification as soon as they see you reach for Snapchat, to get you back on their platform
- killedbydeath 9y agoFor crypto/security people on this thread, what encryption could app developers use to wrap their API call so that the least amount of information is leaked to this kind of man-in-the-middle services? I.e, is it possible to: 1) hide which apps are installed on iOS/Android; 2) hide or obfuscate how frequently the app is used; 3) hide specific API calls I assume at least #3 should be achievable with additional encryption.
- conanbatt 9y agoThis really should be anti-trust, this is not a responsible or accountable way to use this information. Shady af.