34 ms·
Meta's Onavo VPN removed SSL encryption of competitor's analytics traffic
- wordhydrogen 3y agoDocuments and testimony show that this “man-in-the-middle” approach—which relied on technology known as a server-side SSL bump performed on Facebook’s Onavo servers—was in fact implemented, at scale, between June 2016 and early 2019. Facebook’s SSL bump technology was deployed against Snapchat starting in 2016, then against YouTube in 2017-2018, and eventually against Amazon in 2018. The goal of Facebook’s SSL bump technology was the company’s acquisition, decryption, transfer, and use in competitive decision making of private, encrypted in-app analytics from the Snapchat, YouTube, and Amazon apps, which were supposed to be transmitted over a secure connection between those respective apps and secure servers (sc-analytics.appspot.com for Snapchat, s.youtube.com and youtubei.googleapis.com for YouTube, and *.amazon.com for Amazon). This code, which included a client-side “kit” that installed a “root” certificate on Snapchat users’ (and later, YouTube and Amazon users’) mobile devices, see PX 414 at 6, PX 26 (PALM-011683732)(“we install a root CA on the device and MITM all SSL traffic”), also included custom server-side code based on “squid” (an open-source web proxy) through which Facebook’s servers created fake digital certificates to impersonate trusted Snapchat, YouTube, and Amazon analytics servers to redirect and decrypt secure traffic from those apps for Facebook’s strategic analysis, see PX 26 at 3-4 (Sep. 12, 2018: “Today we are using the Onavo vpn-proxy stack to deploy squid with ssl bump the stack runs in edge on our own hosts (onavopp and onavolb) with a really old version of squid (3.1).”); see generally http://wiki.squid-cache.org/Features/SslBump http://wiki.squid-cache.org/Features/SslBump Malware Bytes Article: https://www.malwarebytes.com/blog/news/2024/03/facebook-spied-on-snapchat-users-to-get-analytics-about-the-competition https://www.malwarebytes.com/blog/news/2024/03/facebook-spie...
- liuliu 3y agoThat's appalling to say at least. But Snapchat implemented certificate-pinning since 2015. Does that mean either the analytics endpoint was not covered or somehow the certificate-pinning is circumvented in this case?
- KomoD 3y ago> analytics endpoint was not covered This sounds most likely
- leononame 3y agoThat is insane and I would be inclined to not believe it if someone had told me this. This is such an immense breach of trust that even for me, who has a very low opinion of Meta, it is unexpected. I hope this will blow up as much as it should
- RowanH 3y agoSo this one time, I had a bug report at a client site. The business was largely a member of _______ religion. Our images wouldn't load in the app, but did on the website. How odd I thought, that doesn't make sense! Luckily I was able to be physically present, so I hopped down with laptop in tow, ssh'd into the server and started tailing logs.... Sure enough all the API requests for data were coming through, but whenever a request for image happened - nothing would hit the servers. What the heck I thought to myself? I said to the client 'that can't be, that's almost impossible....the only way that's possible is if the SSL traffic is decrypted, inspected, and images blocked from being requested, which, is a MITM attack". He redirected me to his IT provider. I phoned them up, and explained the situation. "Ahh so they're _____" Me: "So what does that have to do with the price of fish?" Them : "Content filtering..., you need to talk to ____" Sure as the day is long, the content filter was a VPN all members of ____ had to have on their mobile devices (I don't know how widespread this is, whether it was just this business, or the entire ____ ) I applied to have our system approved, it was, and just like magic the next day photos started coming through. I'm guessing basically it detected any .jpg/.mp4 etc URL's in https requests and flagged it up and blocked them from being requested. You can be sure on those devices the VPN would have been somehow locked in with device management, and there's no way on gods green earth they were getting at Facebook/insta etc. So, it's not just meta. That really hammered home how seamless it can be to end users that they really can't trust what's actually happening on their devices.
- leononame 3y agoNot that I'm a fan of it, but in corps it's pretty standard praxis to have a custom root cert installed on all devices and enforce VPN connections on devices outside the network to be able to MITM all requests and do stuff like content filtering (e.g. NSFW, swearwords and obviously malware). It's the company's device and they give it to you for work specific purpose, you shouldn't use it for personal stuff. I don't think it compares to an app that shadily installs its own root cert on an end user's device to spy on them.
- bcye 3y agoCan someone explain how exactly they were able to decrypt the SSL traffic, is it possible to install a root CA without huge warnings from the OS?
- _joel 3y agoBy using mitm, basically "pretending" you're the site the victim wants to connect to and trasparently connecting to the actual upstream site. Basically decrypting the traffic locally for inspection before sending it back out. https://en.wikipedia.org/wiki/Man-in-the-middle_attack https://en.wikipedia.org/wiki/Man-in-the-middle_attack. You don't need a root CA, you just need to poison the DNS to point to the mitm server and just present any old valid cert for the domain so it doesn't trigger a self-signed warning or whatever.
- bcye 3y agoHow can you take any old valid cert though? I presume they have some sort of private key you don't have access to and it would still trigger an expired cert warning?
- deleted 3y ago[deleted]
- keikobadthebad 3y agoFacebook is not removable from many android devices... does this mean Zuckerberg has been seeing all user traffic for years regardless of tls?
- eru 3y agoOnly when they used Onavo, it seems? https://en.wikipedia.org/wiki/Onavo https://en.wikipedia.org/wiki/Onavo is slightly more readable than the legal document submitted as the link.
- douglasmoore 3y agoI might be wrong but I think you need the onavo VPN installed Then your YouTube, Snapchat analytics would get man in the middled
- 1oooqooq 3y agoYes and No. for TLS traffic you need to also install onavo. But the app does scan your contact list every couple minutes and send diffs to their servers. Even if you have never opened the app. And on previous android versions all your recently open apps list too. But again, if you install whatsapp you must give them the contact list permission anyway otherwise the app is intentionally broken and annoying.
- felsokning 3y ago> for TLS traffic you need to also install onavo. I'd be interested to know if it shipped as part of the Facebook SDK, as well.
- 14 3y agoI really think you are a fool if you install WhatsApp. I do think you are higher intelligence than normal if you install Signal. When I hear friends talk about WhatsApp I cringe. The few who have signal I regard highly.
- eru 3y agoReal life is full of compromises. If your grandma is on WhatsApp, and you want to talk to her, it might be a good idea to install WhatsApp. (However, if you have time on your hand and principles, you can use WhatsApp on a burner phone, I guess?)
- adtac 3y agoLol the irony of publicly announcing the addition of end-to-end encryption in one app (Whatsapp) while secretly breaking TLS in another, all in the same year #Tethics
- imglorp 3y agoSo, the FANGs can conduct mass psyops warfare against the populace basically with impunity -- a pesky little suit now and then is inconsequential. But what will happen when they get caught stealing each other's surveillance booty?
- deleted 3y ago[deleted]
- motoboi 3y agoBear in mind that they don’t applied this to everyone, which would be practically impossible. They hired Snapchat users (via a testing services provider ) to let meta observe their usage of Snapchat. Something akin to paying someone to let a meta researcher sit by your side and observe while you use the app. This happens all the time (hiring the testing services to recruit users to use your own app and analyze the patterns with screen recordings and such). The news here is paying for someone to “test” a competitors’ app. I hope that the testers knew they had Snapchat analyzed and not that they were told they were testing only Onavo.
- vitus 3y ago> They hired Snapchat users (via a testing services provider ) to let meta observe their usage of Snapchat. > Something akin to paying someone to let a meta researcher sit by your side and observe while you use the app. Onavo Extend and Onavo Protect positioned themselves as providing consumer-oriented benefits (bandwidth reduction and security, respectively). > The news here is paying for someone to “test” a competitors’ app. Facebook acquired Onavo in 2013, so this was 100% a first-party effort to turn their first-party products into spyware.
- motoboi 3y agoyeah, you should read the doc in the link, they explain why they couldn't use Onavo to simple man-in-the-middle snapchat users, hence the project to use the testing service provider to hire test subjects which would install a MITM solution to unencrypt snapchat (and later youtube and amazon). Normal Onavo users were not subject to the decryption (although they were providing Meta information about overall snapchat's marketshare).
- userbinator 3y ago...with the consent of the users who installed this. Some recent related discussion: https://news.ycombinator.com/item?id=39860486 https://news.ycombinator.com/item?id=39860486
- dddddaviddddd 3y agoIf an individual had somehow done this, I expect that the Computer Fraud and Abuse Act would be used against them. With Meta, we'll see.
- xvector 3y agoI heard about this a few years ago. The trial participants were informed, consented, and paid. If you consent to a root cert being installed and analytics being proxied, well, that's that.
- itopaloglu83 3y agoTwo issues. 1) Did Snapchat consented to this? And 2) did the users know what they were consenting to? Saying we’re going to do “ traffic monitoring” doesn’t carry the weight of “we are going to listen to your private conversations”.
- UncleMeat 3y agoWhy would Snapchat need to consent? It's my traffic. I'd wager that most participants don't know the full details of the program, but "company pays you for your usage information" is a very old thing. You could (maybe you still can) get paid to install a box on your TV that recorded all of your viewing statistics to be used for market research. To me, the biggest concern is that this is only really viable because Facebook had nontrivial market penetration of a more-or-less unrelated product to their main offering. This isn't something that Snapchat could have easily done to get market research on Facebook usage, for example. This feels (to me) more like an anticompetition concern rather than a privacy concern.
- itopaloglu83 3y agoHere’s how I see it. This is akin to opening your USPS mail and reading your correspondence with a friend. When instead they could’ve checked who the mails were addressed. If Facebook wanted to learn the protocol Snapchat uses, they only needed a single test device. If they only needed to learn usage patterns, they could’ve checked where the traffic is sent to or app usage time etc. Installing a root certificate is very intrusive and they behavior shows that if they are ever given the opportunity to be become a root certificate authority, they are likely to issue malicious certificates. As far as I know, no website can pin their certificates, so this takes us back to pre-HTTPS days where ISPs and network operators had a lot of fun reading user traffic.
- cabirum 3y agoWhat do you think Cloudflare is doing with its SSL termination/offloading?
- supriyo-biswas 3y agoWhy single out Cloudflare? They are not the only CDN or PaaS with SSL fronting.
- isodev 3y agoI honestly can't think of one without googling. Cloudflare is kind of everywhere. Just like Google... can't really get rid of them even if you want to.
- akerl_ 3y agoYou can’t think of anybody else in the CDN or DoS mitigation business other than cloudflare?
- fragmede 3y agoI'm sorry but that means your nerd card will expire at the end of the month. I see you've had it for quite a while, but being unable to name any CDN companies besides Cloudflare means your nerd card will lapse. If you'd like to apply for a newer issue one, an LLM agent will be along shortly to help you.
- isodev 3y agoNow obviously my comment is not about "just a CDN provider" right? The SSL stuff that Cloudflare offers to protect your websites/APIs etc so you don't have to, their DNS products. The fact that iCloud Private Relay uses Cloudflare under the hood (and so all browsing there happens through their gateways etc).
- fragmede 3y agoI mean, if it's just the case that you've drank that much of the Cloudflare Kool aid that Akamai, AWS, and GCP don't have competing options in your mind, then that's a different problem entirety. Good for Cloudflare's wallet, and kudos to their marketing team though.
- KaiserPro 3y agoSo was the plan to just yolo this out into the wild? because the document says here that it was going to be given to trial participants as part of yougov(and others) survey. Which implies that they would have been informed/paid. If its the former, then obviously thats unauthorised wiretapping. If its the latter so long as informed consent is given, that a shittonne better that the advertising tech we have now.
- vincnetas 3y agoSo how can we be sure now that todays VPNs are not tomorrows Onavos. :(
- mgiampapa 3y agoCertificate pinning and validation in apps for one. Onavo's VPN was really clear it collected market research data. It was as informed consent as a click-through could be.
- forgotusername6 3y agoInterception of encrypted communications is beyond the expectation of what most people would consider "collecting market research data"
- hiatus 3y agoI would expect the exact nature of the collection to be spelled out in some TOS that users probably clicked through.
- baby 3y agoFirst, all VPNs spy on you, just don't believe these claims because they are forced by law to do it. Second, don't use a VPN that clearly states that they're analyzing your traffic data.
- asimpleusecase 3y agoCan we please see prison time for this. DCMA should apply and it have criminal penalties including prison.
- Simon_ORourke 3y ago"May I direct your honor that my client is a wealthy tech billionaire who would otherwise be at risk of being slightly annoyed if they were sent to jail for intercepting private communications of competitors..."
- r0ks0n 3y agoIT;S DMCA NOT DCMA
- baby 3y agoThere's a lot of confusion around these stories these days, which reminds me of the "Gmail is looking at your emails" stories[1]. First, this is not wiretapping, come on. There's targeted man-in-the-middle (MITM) attacks, and then there's this. This is plainly "we are using advanced powers to analyze your traffic". This is not even Superfish[2] type of stuff, where Lenovo had preinstalled root certs onto laptops to display ads. This is "if you opt in we will analyze your data". Every program you install on your laptop can basically do WHATEVER it wants. This is how viruses work. When you install a program, you agree to give it ALL power. This is true on computers generally, and this is true on phones when you side-load programs. The key is that when we install something we understand the type of program we're installing, and we trust that the program doesn't do more than what it _claims to be doing_. So the question here is not "how does Onavo manage to analyze traffic that's encrypted", it's "does Onavo abuses the trust and the contract it has with its users?" [1]: https://variety.com/2017/digital/news/google-gmail-ads-emails-1202477321/ https://variety.com/2017/digital/news/google-gmail-ads-email... [2]: https://www.virusbulletin.com/blog/2015/02/lenovo-laptops-pre-installed-software-adds-its-own-root-ca-certificate/ https://www.virusbulletin.com/blog/2015/02/lenovo-laptops-pr...
- jasonvorhe 3y agoThat might have been true in the past, but nowadays at least macOS/Android/iOS can enforce several restrictions on the apps you install, like prevent them from changing OS settings/files, limit access to only specified/opt-in directories, limit the amount of background activity, etc. I don't know about Windows or Linux though.
- felixg3 3y agoWindows applications can easily install TLS root certificates, which essentially all „anti virus“ tools (i.e. snake oil) do. On Linux, it’s obvious; if you’re installing something as root, you can add certificates. In that context, apple is doing something right and makes it rather tedious to install root certs
- skywhopper 3y agoSo, your argument is that MITM/wiretapping is okay if you do it at a large enough scale?
- tigrezno 3y agowhy people pay for 3rd party VPNs? It's far more secure to create your own wireguard/openvpn/whatever with a cheap VPS
- MissTake 3y agoBecause most people are not techies. Compared to the rest of the world, the number of people who even know what a VPS is is microscopically small. And even those that do, the number of them with the time, desire, or skill, to do as you suggest, is even smaller. I myself was into this sort of thing just 10 years ago. Now, as I start looking at hitting the big 6-0 in just a few years time, I’m already working on divesting myself of all this complexity,
- orthoxerox 3y agoNot everyone is savvy enough to do it, even though the process has been simplified with many hosting providers providing preconfigured VPN servers. And it doesn't anonymize you that well. When you post a message that draws the attention of law enforcement, the IP will lead them to a VPN provider that hopefully doesn't keep any logs. But if it leads them to a specific server, the hosting provider will disclose your account and payment data, since it is linked to your private server. Unless they accept fully pseudonymous accounts and let you pay for your VPS in cash, Monero or tumbled Bitcoins, finding you is much easier now.
- thegrim000 3y agoI find it so insane that people think the major VPN providers aren't all completely compromised one way or the other. As if you're really going to be able to just pass your traffic through such a business and they're going to actually keep no logs, and not have secret deals made with intelligence agencies, and aren't unknowingly completely insided/compromised by intelligence agencies. As if you can just push your traffic through a major VPN and intelligence agencies would just go "well shucks, oh man, they sure got us, we'll never know who it was, foiled again".
- dewey 3y ago
- 1vuio0pswjnm7 3y agoDirect link to PDF: https://s3.documentcloud.org/documents/24520332/merged-fb.pdf https://s3.documentcloud.org/documents/24520332/merged-fb.pd... Here is Meta's response: https://ia802908.us.archive.org/29/items/gov.uscourts.cand.369872/gov.uscourts.cand.369872.749.0.pdf https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3... Meta denies that they violated the Wiretap Act but offers no evidence of consent. (They try, but it is a laughable attempt.) Meta is also arguing the documents are not relevant. Meta claims the VPN app intercepting communications with other companies that sell online ad services, e.g., Snap, was not anti-competitive. It was just "market research". Why is Meta so afraid to produce documents about "market research". Meta does _not_ deny that they intercepted communications. From the attention this is getting on HN, MalwareBytes, etc. it seems clear no one using the VPN app would have expected Meta was conducting this interception. It is difficult to imagine how anyone could have consented to interception they would never have expected. Additional details: https://ia802908.us.archive.org/29/items/gov.uscourts.cand.369872/gov.uscourts.cand.369872.741.0.pdf https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3... Apparently Facebook was using a "really old" version of squid.
- skywhopper 3y agoI mean, sure, you could also do “market research” by breaking into people’s homes, reading their mail, and listening in on all their phone calls. I hope some actual criminal prosecution results from this disclosure, as it’s very clearly “hacking” and “wiretapping” and “unauthorized access”.
- renaudg 3y agoTV ratings used to be collected from panelists using a wearable device that literally had an always-on microphone recording you 24/7 : https://en.wikipedia.org/wiki/Portable_People_Meter https://en.wikipedia.org/wiki/Portable_People_Meter How is Onavo worse ?
- mctt 3y agoHere is a quote from Facebook/Meta's legal council to the Judge. In this document "Advertisers" refers to Snapchat, YouTube and Amazon. "... the Wiretap Act provides that an interception is not unlawful if a party to the communication “has given prior consent to such interception.” 18 U.S.C. § 2511(2)(d). Advertisers conspicuously fail to mention—and apparently do not contest—that Meta obtained participants’ prior consent to participate in the Facebook Research App, and with good reason: Participants affirmatively consented to “Facebook … collecting data about [their] Internet browsing activity and app usage” to enable Facebook to “understand how [they] browse the Internet, how [they] use the features in the apps [they’ve] installed, and how people interact with the content [they] send and receive." So users consented?
- ChrisArchitect 3y ago[dupe] Lots more discussion on the various aspects of this: https://news.ycombinator.com/item?id=39832952 https://news.ycombinator.com/item?id=39832952
- bobcostas55 3y agoSeems like a straight-forward CFAA violation, no?
- _ink_ 3y agoIsn't this known since 2018? https://mashable.com/article/facebook-used-onavo-vpn-data-to-watch-snapchat-and-whatsapp https://mashable.com/article/facebook-used-onavo-vpn-data-to...
- quitit 3y agoYes it's old news(1) but it has come up again in numerous HN and reddit posts for a few reasons (if you flick through HN you'll see various versions of this story holding lower ranks.) Also noteworthy is that Google were also doing something similar at the time, both were side-stepping Apple's privacy protections in iOS by using enterprise certificates that allowed the side-loading of apps without Apple's overview. In response Apple more thoroughly restricted how these certificates can be used. Interestingly I've noticed in the DMA threads people suggesting that a company exploiting side-loading to dodge Apple's privacy protections was nothing more than fear mongering. As if this is a red line developers won't cross. To me, it's wild to think that people on HN don't know about this relatively recent history and are so naive to think that these protections were just pulled out of the air to frustrate developers, and not a reaction to an on-going arms war against consumer's right to privacy. (1) https://www.extremetech.com/internet/284770-apple-kills-facebooks-internal-ios-apps-after-latest-privacy-blunder https://www.extremetech.com/internet/284770-apple-kills-face...
- xvector 3y ago> To me, it's wild to think that people on HN don't know about this relatively recent history and are so naive to think that these protections were just pulled out of the air to frustrate developers, IMO we have modern journalism to thank for this sort of thing. People are so misinformed with rage bait articles that they push against policies in their own interest. But if anyone dare suggest enforcing some minimum level of journalistic ethics they'll get attacked because somehow journalists have painted themselves as some sort of unassailable paragon of righteousness.
- quitit 3y agoBingo. It's easy to pay for influence, especially if one can spin a story for clicks. I see a lot of cheerleading and parroted talking points against the interests of developers, particularly small and independent developers. A lot of the changes lobbied for by large developers give them an insurmountable pricing and competitive advantage over small developers and startups, yet I don't see much consideration here for that, nor the wishes of bona fide consumers. Epic is particularly barefaced here, since they claim they are fighting for developers, when their proposals are not altruistic. Each clearly puts them at an advantage over smaller developers and consumers. Do we have such a short memory that we forget that this is the same Epic that settled with the FTC for using dark patterns and violating childrens' privacy for the purpose of tricking kids into accidental Fortnite purchases.(1) That was only 15 months ago. While I'd expect reddit to be less informed, I'm not so charitable with HN: it's a forum where the bulk of participants claim to be developers. (1) https://www.ftc.gov/news-events/news/press-releases/2022/12/fortnite-video-game-maker-epic-games-pay-more-half-billion-dollars-over-ftc-allegations https://www.ftc.gov/news-events/news/press-releases/2022/12/...
- ramshanker 3y agoThis seems to be a valid reason to implement certificate pinning in the application's network layer. At least 3rd party VPN providers don't get to intercept without replacing the pin.
- chiefalchemist 3y agoDid the bury the lede? Sure this a blow against "competitors" but that is ultimately a competition for the collection of data, user data. In doing this FB has expanded its ability to hoover up more data at the individual user level, correct? Yeah, crap move but my concern isn't those other scoundrels, it's me / us.
- neglesaks 3y ago"Meta" is The Evil Online Empire at this point, it's company history is a litany is decidedly immoral if not outright evil actions.
- staplers 3y agoMeta is a known state-actor. They likely have federal immunity to most wrong-doings. (Source: https://www.vice.com/en/article/v7gd9b/facebook-helped-fbi-hack-child-predator-buster-hernandez https://www.vice.com/en/article/v7gd9b/facebook-helped-fbi-h...)
- hereme888 3y agoThat article does not back up the claim that Meta is a state-actor. I hate FB, but all big platforms these days will cooperate with federal agencies in cases like the one described. Doesn't make them "state actors".
- staplers 3y ago"Facebook hired a cybersecurity consulting firm to develop a hacking tool, which cost six figures. Our sources described the tool as a zero-day exploit, which refers to a vulnerability in software that is unknown to the software developers. The firm worked with a Facebook engineer and wrote a program that would attach an exploit taking advantage of a flaw in Tails’ video player to reveal the real IP address of the person viewing the video." They literally hired a team based on an FBI request to create a zero-day exploit. This wasn't just a "give us information" request. They actively R&D'd a tool for the government.
- agaull100 3y agoNice diversion in comments away from Meta...
- typeofhuman 3y agoThe engineers should be criminally charged.
- shnkr 3y agoWhatever may be the end goal, MITM is called an 'attack', not 'research'. I'd not last a single day at such a company who would ask me to do such things. I had worked for a national political party in IT and left the job once I found about it corrupt practices and scams. If we, as engineers collectively upheld ethics as part of work culture, Meta wouldn't have attempted it.
- fagrobot 3y ago[flagged]
- barfbagginus 3y agoAs an ethical engineer, there is a further duty to also sabotage the organization once we uncover dirt on it. Never for profit. Sometimes for ego. And always because if every engineer took a stand against BS, then the world would be a much better place.
- gloryjulio 3y ago> as engineers collectively upheld ethics as part of work culture Just saying, it's really hard when your job or even your future green card is on the line. When the grunt engineers are 1 mistake away from being sent away from the US and lose all their potential futures in the US, they are much more likely to bury their heads carry out what they are told from the managers. We need to go for the higher ups more.
- shnkr 3y agosomeone committing fraud for money is same as committing fraud to keep a visa.
- baby 3y ago> MITM is called an 'attack', not 'research' Sorry but what?
- bawolff 3y agoWas this before google started certificate pinning their apps or did they get around that somehow?
- deleted 3y ago[deleted]
- nimbius 3y agoPedantic, but its TLS not SSL. And if youre stripping it without mentioning it in your ToS then you should be charged under the CFAA.
- temporary0331 3y agoI used to work for a startup that did very similar kind of thing. We paid people to install our app and our root cert. We had our own VPN server through which all traffic of the panelists (people who participate in a panel) went and we were able to decrypt all traffic that used the PKI that the operating system provided. Some apps used some other kind of encryption (banking apps eg.) so that could not be decrypted. Then we also collected additional data, for example we took screenshots of whatever was currently on the screen and tried to map those to applications for which we recorded screenshots. This was done to know what app the user was running at what time. I didn't work with the data collection, so my info is a bit limited. Facebook was our customer even though they had already bought Onavo. I can answer some questions if you have any. The company did go bankrupt and the technology was sold.
- Rosemary1499 3y ago[dead]
- Rosemary1499 3y ago[dead]
- gabriella4151 3y ago[dead]