11 ms·
How did Facebook intercept their competitor's encrypted mobile app traffic?
- egberts1 2y agoOoooooooh, SSLbump. There has to be a court precedent that criminalized sniffing network traffic on the customer’s side. Should be one of those many cases involving wiretapping for banking info.
- paradox460 2y agoDoesn't the computer fraud and abuse act cover this?
- egberts1 2y agoNot ... really ... It is about intent versus capability set that CFAA does poorly with differentiation in court.
- walrus01 2y agotl;dr: If you install and fully trust a root CA on your client device, of course your TLS traffic can be MITMed. edit: the problem, obviously, is that this app tricked the non-technical people into installing/trusting the root CA for malicious purposes. Clearly this was malware.
- walterbell 2y agoUnless the TLS traffic uses certificate pinning.
- dylan604 2y agoThat's great for someone reading this forum to be aware of, but moms have no idea what any of the words you just wrote means. So if they were told they get a coupon for installing or some other bit of ridiculous things malware devs use, and yes I'm calling FB software malware. All of if it. Messenger, FB.app, everything. If it's from Meta, it's malicious.
- walrus01 2y agoThat's a very good point. I have within recent memory installed my own internal CA that I run on Android devices that I own and trust, and the process on android 11+ is sufficiently daunting that 99.5% of peoples' moms could not do it in one or two clicks. You have to go deep into system settings and manually import the CA. This requires first file-transferring the CA file somewhere onto local /sdcard storage and possibly having a file system explorer app installed to be able to view its location on "disk" and pick it. As is pointed out in the article, I would presume that Google saw the threat from allowing an app to install and trust a root CA as well, and removed the ability for a "one click" install of a root CA: "KeyChain.createInstallIntent() stopped working in Android 7 (Nougat). A user would have to manually install the certificate. It would no longer be possible to have Facebook's CA cert installed directly in the app."
- sadboi31 2y agoI would argue that everyone over the age of 8 can do it with sufficient motivation and quality documentation. $10-20 and the promise of more money doing some low-effort "consumer survey" or providing "extra analytics" is pretty enticing to a massive number of people really struggling in this country. Despite being hard-up I don't think the vast majority of these low-income individuals would agree to being so egregiously wiretapped and data mined for future political ads on youtube or bundled into some other product without better compensation.
- ahazred8ta 2y agoTry comparing P2P OTR E2EE vs Non-CA TOFU SSH
- dylan604 2y agohell, even I don't know what the "words" you just used mean!
- iam-TJ 2y agoThat got me too for a few seconds whilst my brain cogs whirred... but the latter sounds tastier than the former for some reason! For those wondering: P2P OTR E2EE == Peer to Peer, Off The Record, End to End Encryption Non-CA TOFU SSH == Non-Certificate Authority, Trust On First Use, Secure SHell
- safety1st 2y agoSo I mean, just taking a quick look at the contents of /etc/ssl/certs and what Firefox shows me when I hit its View Certificates button, I see among dozens of other actors, Amazon, Microsoft, GoDaddy, and the Beijing Certificate Authority. No software has ever asked me if I want to trust any of these guys, they've been silently trusted during a software install I suppose. Does this mean they can all MITM my TLS traffic if they so choose?
- jerbear4328 2y agoTheoretically, yes, they could, I think. However, with Certificate Transparency, the fraudulent certificates these Certificate Authorities could create would have to be published in CT logs to be valid, where they would be quickly noticed, and the CA would (hopefully) lose credibility and be removed from device's trusted CA list.
- theptip 2y agoNot in 2020, no. HSTS causes your browser to pin the first cert that it sees (from sites opting in to this scheme), so nobody (even the legitimate operator) can swap it out before it expires. https://en.m.wikipedia.org/wiki/HTTP_Strict_Transport_Security https://en.m.wikipedia.org/wiki/HTTP_Strict_Transport_Securi... And specifically to the scenario in OP, app clients these days do not use the OS cert store, they will ship a single well-known server cert and only accept that one. This doesn’t help with your Firefox usecase though.
- Uvix 2y agoWhen HSTS is enabled, browsers don't pin the specific cert, just that HTTPS is required. Pinning the cert would mean users would experience outages (because you can't swap the cert early), which would be a terrible experience.
- toast0 2y agoHSTS is https required and it needs to be a validated cert; issued by a trusted CA and not expired (maybe also not before the not before date). And the usual ignore it and move on button is gone. Doesn't help if you're worried about a trusted CA issuing a cert for your domain without your approval though. Certificate transparency helps a bit with that; Chrome requires certs issued with a not before after april 30, 2018 to be in CT logs[1], so at least you'll be able to know a certificate was issued for your domain. If that happens, you can ask the CA/Browser forum to investigate and there's a good chance the CA will get kicked out if there's not a good explaination of what happened. That's not perfect but it's better than without CT when you could only know about an unauthorized cert if you managed to see it. [1] I think max validity was two years back then, so all current certs need logs
- dilyevsky 2y agoThat’s not sufficient - you also need to intercept traffic somehow which they successfully accomplished by buying this vpn company and using them to proxy victims traffic through their infra
- eightysixfour 2y agoVictims that were being paid to participate? Edit: Not excusing Facebook here, but feel like this whole thing is in a weird grey area. It is like getting paid to have a Nielsen box monitoring your TV and then complaining when you find out it also knew what you watched on your DVD player.
- haxrob 2y ago> Victims that were being paid to participate I believe you might be referring to what happened in 2019? [1] This is a separate issue. [2] I do clarify this in the blog post, although it might be better to move the relevant text near the introduction rather then in the middle of the post. EDIT: I have also added a remark to the post that it is not clear if all users were MITM'd or just a subset [1] https://techcrunch.com/2019/01/29/facebook-project-atlas/ https://techcrunch.com/2019/01/29/facebook-project-atlas/ [2] https://techcrunch.com/2024/03/26/facebook-secret-project-snooped-snapchat-user-traffic/ https://techcrunch.com/2024/03/26/facebook-secret-project-sn...
- deleted 2y ago[deleted]
- eightysixfour 2y agoI think what is missing is a timeline and clarity about the actual steps users had to take. 1) Onavo was a (free?) VPN app acquired by FB in 2014. Facebook used it to collect “market research data.” People chose to download this, but thought it was a security product. 2) At some point (it looks like 2016?) they launched an iOS app called Research, using the same tech, which required users to install a certificate meant for internal Facebook employees. They paid these users to monitor their traffic. Are you saying that the MITM was happening for users of (1) or (2) or both?
- dylan604 2y agoThe email snippets are impressive on multiple levels, mainly how fucking stupid/arrogant people at FB must be. Openly talking about MITM, and then getting multiple other companies to include this kit in their products as well is just beyond stupid for putting in writing. "Hey Zuck, I have an idea on your proposal. We should get together to discuss in person" would be suspect, but at least it's not incriminating. It's like these people have never seen a movie, or read a news article on other companies getting caught.
- cen4 2y agoBillionaire bosses are all surrounded by opportunists and flatterers. Over time like the Great Pacific Garbage Patch the size of this group grows to unmanageable dimensions, cause anyone acting moderately sane will be treated as an existential threat to their lives of fantasy, domination, manipulation, luxury, leisure etc and pushed out.
- talldayo 2y agoThankfully our fearless American regulators would never shy away from hanging these scoundrels out to dr- hey wait, where are the lawyers going off to?
- walrus01 2y agoThe lawyers are off in the Hamptons this summer with the same people who are the root cause of the 2008 financial crisis.
- walrus01 2y agoTo paraphrase Clarke's three laws, a sufficiently advanced quantity of yes-men and tech industry bro "move fast and break things" types is indistinguishable from a hostile malware actor.
- Terr_ 2y ago> acting moderately sane will be treated as an existential threat [...] and pushed out. Or converted, by making them take actions so that "if we go down you're going down with us." Organized crime works that way too, come to think of it. They may call it "loyalty", but it really means "give us a way to coerce you into compliance."
- lowermidmgmt 2y agoIf there is a god we'll be compensated through a class action settlement for a $5 meta ad voucher.
- Scoundreller 2y agoGotta hire Illinois lawyers. They got their residents $435 per user: https://www.chicagotribune.com/2023/10/20/illinois-facebook-users-to-get-third-and-final-check-from-record-650-million-biometric-privacy-settlement/ https://www.chicagotribune.com/2023/10/20/illinois-facebook-...
- nilamo 2y agoLet's not pretend that's a good number, either.
- cryptica 2y ago[flagged]
- techbrovanguard 2y ago[flagged]
- cmeacham98 2y agoCan you give me a step by step explanation of how blockchain-based DNS would have helped here?
- cryptica 2y agoBlockchain-based DNS would allow people to actually own their domain names instead of just renting them for an annual fee. Domain transfers could be effected on-chain for a fee. Spam prevention is built-in because any action recorded on the blockchain incurs a fee. The fee is determined by the free markets and nobody holds a monopoly over the market. People who trade domains would end up subsidizing those who hold domains; allowing them to hold domains for free, permanently (once the domain is bought and initial transfer is made). It removes the need for an authority like ICANN who decide who gets to control what. You don't have to limit yourself to one blockchain, new blockchains could launch and be treated as distinct gTLDs. You don't need Certificate Authorities and the complex, trust-based infrastructure to implement certificate verification. It can all be done on-chain, anyone can sync their own nodes to verify who owns what domains. Blockchain is naturally good for high-read scenarios. It can scale in terms of number of reads without limit; just add more nodes. The writes are limited, however, transaction fees serve as a natural regulating factor; it can always meet the demand, for the right price; which is determined entirely by the markets and based on usage of computational resources, not based on monopoly pricing. Bitcoin, with a measly maximum of 4 transaction per second, has already proven that transaction fees can stay reasonable, even with extreme levels of hype on a global scale. BTW, if you managed to read my comment, you can consider yourself lucky because this perspective I'm sharing is consistently suppressed and heavily down-voted... You can be sure that there are financial interests behind the current DNS system which do not want to leave room for any tech which might liberate the internet from the clutches of the incumbents and which might force them to compete on a free market.
- ARandomerDude 2y agoIf you or I did this, we would already be in jail for phishing plus whatever add-on charges the Feds could file. Meta has Washington in their pocket so this will never leave civil court. The penalty will be less than the money made, meaning somebody gets a bonus for being creative.
- dylan604 2y agoseriously, how does this not violate wire tapping laws? does agreeing to ToS mean you also agree to being spied on in a way that protects them? you are deliberately circumventing encryption for malicious purposes. if people got in trouble for DeCSS for circumventing encryption, how is this okay? pithy "because they have all the monies" replies not wanted.
- deleted 2y ago[deleted]
- hypeatei 2y agoBig tech and telecommunications companies are effectively miniature arms of the U.S. government at this point. As seen by the "Protect America Act" of 2007[0], the government will retroactively cover their own ass and your companies' ass if deemed important enough to the intelligence apparatus. There isn't a chance in hell that Meta would be brought criminal charges for wiretapping. 0: https://en.wikipedia.org/wiki/Protect_America_Act_of_2007 https://en.wikipedia.org/wiki/Protect_America_Act_of_2007
- Scoundreller 2y agoI think The Onion nailed it in 2011: https://www.theonion.com/cias-facebook-program-dramatically-cut-agencys-costs-1819594988 https://www.theonion.com/cias-facebook-program-dramatically-...
- dylan604 2y agoWhich is clearly a red flag operation so that whenever someone serious tries to tout this, they'll be rebuffed as it's an article in the Onion. Those clever bastards!
- Crazyontap 2y agoWhy didn't a big company like Snapchat not have certificate pinning? Something is amiss here!?
- liuliu 2y agoSnapchat do certificate pinning for it's main API domain. I am not exactly sure why analytics domain are different and why not have certificate pinning. (I thought analytics go through the same API domain, but it must be wrong then).
- haxrob 2y agoThe analytics domain was "sc-analytics.appspot.com" in which the lack of pinning is described at the tail end of the blog post.
- theptip 2y agoFrom the OP, Snapchat started pinning not long after this program launched.
- RockRobotRock 2y ago"Stay safer when you're using public Wi-Fi. Turn Protection On" prompt to install a VPN config Fuck yourself, Facebook.
- iamthejuan 2y ago[flagged]
- theptip 2y agoSo just to be clear on what is being alleged, because the write-ups are omitting this detail: from what I can tell FB paid SC users to participate in “market research” and install the proxy. The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. (I’d love to get more detail on exactly what the participants were told they were getting paid for, but I’d be surprised if they did not know their actions were being monitored.) The accusation that it’s wiretapping if one party in the communication channel is actively breaking the encryption (even with a tool provided by a third party) seems tenuous to me, but IANAL. If this is wiretapping, is it also wiretapping for me to use a local SSL proxy to decrypt and analyze traffic to a service’s API?
- haxrob 2y ago> from what I can tell FB paid SC users to participate in “market research” and install the proxy. The app was available on both the Google Play and Apple App stores for anyone to download. > The way most of the writeups make it sound is that it’s some sort of hack, but this doesn’t seem to be the case. It could be that you are confused with a previous case. From the blog post: > The wiretapping claim is new and perhaps not to be confused with the prior controversy and litigation: In 2023, two subsidiaries of Facebook was ordered to pay a total of $20M by the Australian Federal Court for "engaging in conduct liable to mislead in breach of the Australian Consumer Law", according to the ACCC ... Facebook had shutdown Onavo in 2019 after an investigation revealed they had been paying teenagers to use the app to track them. Also that year, Apple went as far as to revoke Facebook's developer program certificates, sending a clear message. > If this is wiretapping, is it also wiretapping for me to use a local SSL proxy to decrypt and analyze traffic to a service’s API If by "local" on your own network/machine with your own traffic then obviously no.
- ec109685 2y agoNeilson does something similar with TV where they install capture boxes in people’s houses to determine what they’re watching for their panels: https://www.nytimes.com/athletic/3194414/2022/03/22/the-ultimate-nielsen-faq-how-we-and-they-know-how-many-of-you-are-watching-sports-on-tv/?source=user_shared_article https://www.nytimes.com/athletic/3194414/2022/03/22/the-ulti... I hope they were upfront about what they were collecting. The article didn’t show what the consent screen was before installing the proxy.
- musha68k 2y agoUnfortunately this is unsurprising; with bad actors like Meta there are likely many potential "dark patterns" put in place. I can imagine e.g. security risks involving sensor data exfiltration where accelerometers and gyroscopes etc are monitored to infer audio information. By covertly relaying and processing the collected data externally it would be possible to reconstruct sensitive information without direct access to the device's microphone. It's not unlikely that they pull off something like that. Meta and other pernicious companies and government bodies are probably employing many more, even worse and much simpler eavesdropping techniques in the wild.
- giancarlostoro 2y agoReading this article I'm just thinking that Facebook has wing that's just an NSA front at this point.
- KennyBlanken 2y agoPeople seem to forget that the research that turned into Google was initially funded by the NSA and CIA: https://qz.com/1145669/googles-true-origin-partly-lies-in-cia-and-nsa-research-grants-for-mass-surveillance https://qz.com/1145669/googles-true-origin-partly-lies-in-ci... Cars now come with Google services / Android baked into the damn infotainment system, with no possible way to pull it out. What could possibly go wrong with an advertising company seeing everywhere you go, and everyone who rides in your car?
- serial_dev 2y agoYeah... They are all connected to the "three letter agencies", in Google's case it was very early, but I believe nobody can stay popular and not have all of these agencies infiltrate then take control of them. Apple, Google, Facebook, Twitter, Alexa, they are a gold mine for agencies, but even news sites, movie studios, and YouTubers. This is why they've been after Tik Tok for so long, they know how useful that app / network is.
- b112 2y agoThis is true, but so far there are ways to disable much of this. For example on a Ford, you can literally pull the fuse for the GSM modem. On a GM, you can pull the antenna from OnStar, and put a resister there in replacement... thus rendering it unable to communicate to home base. This doesn't solve everything, but it at least stops the immediate phone home.
- kjkjadksj 2y agoYou can also buy cars that don’t need an immediate debugging
- 2y ago
- sanex 2y ago[flagged]
- exmicrosoldier 2y agoThey do this on my work laptop. Zscaler
- ozim 2y agoBig companies do MITM and deep packet inspection on company laptops that is normal - not normal is doing that on private devices.
- rkagerer 2y agoWhy would anyone use a VPN service provided by Facebook?
- dddw 2y agoMoney, If I recall correctly they paid teens to install and use the app
- egberts1 2y agoThis is why we should be doing dual-server-client TLS certificate exchange before stuffing damaging info over Internet. But, alas, nooooooooo.
- Andrex 2y agoAny more post-relevant insights we should congratulate you for, or is it just this one?
- ozim 2y agoYou can do certificate pinning.
- HL33tibCe7 2y agoHow would mutual TLS have helped here?
- egberts1 2y agoMutual TLS dutifully breaks if there is a transparent HTTPS proxy like SSLbump or Squid.
- xbmcuser 2y agoI don't know why but Facebook is the one tech company that I just can't have a good opinion about. I like and dislike Google, Microsoft, Apple, NvidiA, AMD, Intel and the rest for different things but I just hate Facebook. I closed my facebook account about 10-11 years back put a filter to keep facebook out of my search results. And I have to say it works I rarely see anything about Facebook on my Google news feeds etc. I still use WhatsApp though as that is the biggest communication app outside China in Asia
- dagmx 2y agoProbably a combination of - they’ve had a long history of trying to undermine privacy to extend profits. From stuff like in the article, to tracking pixels, alleged ghost accounts, and fighting anything that hampers tracking. Of the companies you listed, only Google has any crossover, but doesn’t come anywhere near as close. - they’re irresponsible with the effects of their algorithm to amplify hate speech. None of your other companies have anything like that. - they are dishonest in their marketing. Almost all their Quest ads and feature reveals use concept visualization to deceive users for example on what is possible. Mark often speaks in double speak when addressing issues. Double speak isn’t unique to them but they definitely take dishonest advertising to the limit versus the other companies on your list. I know Meta are having a popularity renaissance with their open weight (not open source) models in this AI cycle, as is Mark with his his recent PR blitz to reinvent his image. However I think they’re culturally the only one of your companies listed who lack a moral core to their work. I think culture is top down, and both Zuckerberg and Thiel have instilled a culture of “success at all costs” for the way Meta operates. The other companies on your list are definitely capitalist too, but have some sense of responsibility with their output.
- mschuster91 2y ago> - they’re irresponsible with the effects of their algorithm to amplify hate speech. None of your other companies have anything like that. Twitter is arguably worse - especially after Musk's takeover.
- 2y ago
- afavour 2y agoNot to downplay it but at least this requires users to download the Onavo app, which isn’t so common. The one that I wonder about a lot is this: there are two (non-deprecated) types of webview you can use in iOS: WKWebview and SFSafariViewController. They’re intended for very different uses. When you tap on a link in the Facebook app they should use SFSafariViewController. It’s private (app code has no visibility into it), it shares cookies with Safari, it’s literally intended for “load some external web content within the context of this app” Instead, FB still uses WKWebView. With that you can inject arbitrary JS into any page you want. Track navigations, resources loaded, the works. Given the revelations we’ve seen in this article and many others I shudder to imagine what FB is doing with those capabilities. They’re probably tracking user behavior on external sites down to every tap on every pixel. It seems insane to think they might be tracking every username and password entered in their in-app webviews but they have the technical capability to. And do we really trust that they wouldn’t?
- windmark 2y agoI wasn’t aware that WKWebView granted the app such power. Is there a way for me as a user to figure out if WKWebView or SFSafariViewController is being used if I have a web page open? Although I don’t use FB, I do use the web view of other apps and don’t want them to be able to do this either.
- can16358p 2y agoSFSafariViewController is less customizable visually so the standard "sheet coming up within the app" that looks always the same regardless of the app (at least in most apps and of course not Meta's apps) is that one. Having said that, since WKWebView is just a view that can be customized visually, nothing can stop someone to create a WKWebView-wrapping view controller that looks exactly like the "safe" Safari one anyway.
- saagarjha 2y agoCertain features are not available to WKWebView.
- temp0728 2y agoI used to work for a startup that collected data by using MITM attack with a VPN server, and other means. The users got paid a small sum of money to participate.
- 1vuio0pswjnm7 2y ago"There is a current class action lawsuit against Meta in which court documents include claims that the company had breached the Wiretap Act." This is not a wiretapping case. The claims are all for violations of the Sherman Act. Plaintiffs' attorneys _incidentally_ found evidence during discovery that Facebook may have breached the Wiretap Act. There are no wiretapping claims. It is an antitrust case.
- haxrob 2y agoThanks, I have modified the wording and also quoted you and linked this HN post on the blog page.
- Andrex 2y agoDoesn't this violate the DMCA too? This is circumventing an encrypted system. Does the DMCA not have enough teeth for something on this scale? Maybe an issue of standing or provable-damages? Did the plaintiffs forget about it? Curious and confused.
- bschne 2y agoI think a relative of mine once almost signed up for another market research thing that would have done essentially this, redirecting all their phone's internet traffic through a VPN & proxy controlled by the market research company, including installing their Cert. They would have received some small compensation for it, and of course consented to having it installed. I don't recall the company being misleading about anything, exactly. That being said, while I generally am not in favor of overly paternalistic policies, I wonder how meaningful the consent of someone with relatively little technical knowledge for something like this really is. They were not misleading about things, but also didn't fully spell things in a way that would really drive home what was going on for someone unaware.
- smcin 2y agoJust because some market research companies do informed disclosure, says nothing at all about how Onavo did this (and Onavo didn't advertise themselves to users as "market research company", just as some free neat app that would categorize your internet data usage).
- 29athrowaway 2y agotl;dr: They acquired an app called Onavo, with 10 million customers, and used it to install a CA certiticate thus allowing them to act as a MITM proxy.
- Ethicalhackers 2y agoYes, it can be possible. I stormbound a with a friend who recommend hire a professional team who provide me access her phone through spy app i install on my phone it work like a magic. I advice you use this team know as hireprohackers20@Gmail.com for your won job to be handle
- FragrantRiver 2y agoThis wouldn't have happened if Android used Javascript.
- sandraciara 2y ago[dead]
- webninja 2y agoIsn’t this what the broad CFAA was created for and what Aaron Schwartz was martyred over?