4 ms·
Not to defend this practice, but some missing context here (AFAIK, I wasn't involved): this isn't the FB app, but apparently "Onavo Protect" followed by "Facebo
by evmar 3y ago
Not to defend this practice, but some missing context here (AFAIK, I wasn't involved): this isn't the FB app, but apparently "Onavo Protect" followed by "Facebook Research" apps, the latter of which reportedly explicitly paid people to install it for the express purpose of collecting this kind of data.
- jrockway 3y agoYeah, it's tough to figure out who was harmed here. "Can we install an SSL MITM attack on your device?" "Sure, for money!" "Here's some money." I mean, this is literally every big company IT department. The best argument I could see that would lead to this succeeding is if someone at Facebook accepted the Snapchat ToS and it said "you can't use MITM to intercept our traffic". Otherwise, fair game, done billions of times a day. (Pin your certs friends.)
- pseudo0 3y agoIt seems like the logic for the lawsuit is that Snapchat and other advertisers had something in their ToS with words to the effect of "thou shalt not let our competitors packet capture our traffic" and Facebook induced the customers to breach that agreement. The Wiretap Act stuff seems like nonsense though. If the consumer installed software with their informed consent to record their phone use, that's not illegal wiretapping.
- FateOfNations 3y agoAt least not federal wiretapping. It would be wiretapping in the subset of states that require all parties to the communication to consent to monitoring/recording, which includes California, where Facebook/Meta is headquartered.
- 1letterunixname 3y agoWith user consent and communication, it's not as evil as others are trying to make it sound. The arguable legal gray area is: If a user gives unlimited permission to do so, is decrypting another company's network traffic on device legal? I fall on the side of the fence that it's okay with consent because not even that other company has unlimited and exclusive ownership of a user's data or network packets preflight on their own device. Btw at Meta/Facebook, even the data about employee devices has privacy filters on collected analytics because location, IP address, MAC address, serial number could be used maliciously by a rogue employee targeting other individual employees if there weren't protections (like Twitter was). Instead, almost all data at Meta is uniformly stored with hard privacy ACLs that, by default, prevent casual exploration. In other words, if I worked at Facebook and knew your Facebook accounts' graph FBID, I would be presented with minimal-to-no information about it and a "make a request for access for business use" dialog that is rarely granted by an appropriate manager or senior trusted person except for actual business needs. Even browsing my own Facebook account by FBID in the graph, I couldn't see all of the details, just a bunch of uninteresting housekeeping and general details. In general, they took at-rest storage of personal information seriously.
- okr 3y ago(It makes me wonder, if iam forced to communicate to a remote api, does this communication belong to this company? Hmm. And when someone talks with me, my human interface, developed and refined over years, can i charge for it? :)