Meta tried to gain a competitive advantage over its competitors, including Snapchat and later Amazon and YouTube, by analyzing the network traffic of how its users were interacting with Meta’s competitors. Given these apps’ use of encryption, Facebook needed to develop special technology to get around it.

Facebook’s engineers solution was to use Onavo, a VPN-like service that Facebook acquired in 2013. In 2019, Facebook shut down Onavo after a TechCrunch investigation revealed that Facebook had been secretly paying teenagers to use Onavo so the company could access all of their web activity.

After Zuckerberg’s email, the Onavo team took on the project and a month later proposed a solution: so-called kits that can be installed on iOS and Android that intercept traffic for specific subdomains, “allowing us to read what would otherwise be encrypted traffic so we can measure in-app usage,” read an email from July 2016. “This is a ‘man-in-the-middle’ approach.”

A man-in-the-middle attack — nowadays also called adversary-in-the-middle — is an attack where hackers intercept internet traffic flowing from one device to another over a network. When the network traffic is unencrypted, this type of attack allows the hackers to read the data inside, such as usernames, passwords, and other in-app activity.

  • @MataVatnik
    link
    English
    2112 months ago

    And people want to let these parasites integrate into the fediverse

    • @nuzzlerat
      link
      English
      72 months ago

      honest question: why does it matter? all data in any fediverse project is public anyways

      • @MataVatnik
        link
        English
        20
        edit-2
        2 months ago

        For me it’s not really about the data, it’s unforseen malicious maneuvers outside data. Sabotaging instances, manipulating feeds for their gain, or try to still centralize the fediverse undermining the whole concept. My point is, we don’t know what bad thing they could/would do, they are creative. But we sure as fuck know it’s an evil organization and they can’t be trusted.

        • @nuzzlerat
          link
          English
          22 months ago

          that’s fair. I fully believe they could pull some fuckery that would make everything worse

    • @[email protected]
      link
      fedilink
      English
      -682 months ago

      Please tell me what governing body exists for the fediverse that would let us deny them access?

      • @[email protected]
        link
        fedilink
        English
        772 months ago

        How is this a relevant question? Nobody said anything about some governing body. There have been discussions on many instances about whether to federate with them or not, and it’s accurate to say that some people think we should.

        • @[email protected]
          link
          fedilink
          English
          212 months ago

          For example, I’m personally of the opinion that instances should be allowed to federate until they prove themselves to be bad actors, but in Meta’s case there’s a lot of existing evidence that shows they shouldn’t be allowed to federate in the first instance.

          • @MataVatnik
            link
            English
            242 months ago

            Meta is the textbook definition of a bad actor. Plenty of precedent there.

            • @[email protected]
              link
              fedilink
              English
              122 months ago

              Every instance gets to decide on its own, there’s no set of rules governing the whole thing. That’s why I stated this is my opinion, not some hard and fast rule.

        • @A_Random_Idiot
          link
          English
          -11
          edit-2
          2 months ago

          its also accurate to say some people are fucking idiots and think we should federate.

          on the wax winged hope in hell that the bad actor suddenly, miraculously, becomes a good actor…for reasons no one can explain.

      • @QuandaleDingle
        link
        English
        212 months ago

        Do you know how the Fediverse works? Instance maintainers who are less than thrilled with Meta can choose to defederate from Threads.

        • @[email protected]
          link
          fedilink
          English
          32 months ago

          Exactly my point. It’d be on an instance by instance basis, there is no “singular group” that can block them from the entire fediverse.

          • @[email protected]
            link
            fedilink
            English
            122 months ago

            The whole point of federation is that you aren’t locked in the sinking ship. If everyone is defederating from your instance you can move to a better one.

            • @[email protected]
              link
              fedilink
              English
              102 months ago

              Yes, but to realistically keep Threads from federating and utilizing people’s posts, every single instance owner would have to defederate. 1) that’s not likely, and 2) that’s a unilateral decision by the instance owner. I’m looking at things from a realistic standpoint, not an idealistic one.

              • @[email protected]
                link
                fedilink
                English
                52 months ago

                The only places Threads can federate with are instances that are so poorly managed that they don’t even block Threads.

                • Cosmic Cleric
                  link
                  English
                  22 months ago

                  The only places Threads can federate with are instances that are so poorly managed that they don’t even block Threads.

                  Or are paid not to block.

      • @MataVatnik
        link
        English
        32 months ago

        Im more specifically thinking about the big ones when this debate was going on about a couple of months ago.

  • Aniki 🌱🌿
    link
    fedilink
    English
    1032 months ago

    This is blatantly circumventing encryption and a violation of the DMCA but lets see the DoJ do fuck all about it.

    Right, Biden? Facebook, Good, Tiktok, bad?

    • @[email protected]
      link
      fedilink
      English
      562 months ago

      Two things can be bad at once.

      What Meta did/is doing here is unbelievably shitty (but not that shocking).

      That in no way diminishes the incredibly serious implications of TikTok being wholly owned and operated by a PRC-based company, which comes with the implicit but very real and crucial caveat of the CCP will tell you to do just quietly things with your company sometimes, and if you don’t do it, you go to jail indefinitely.

      • @[email protected]
        link
        fedilink
        English
        192 months ago

        But then it just comes off hypocritical and disingenuous if you selectively apply pressure. Then it just looks like you’re trying to give a competitive edge to US evil social media and preventing youth from learning about the situation in Palestine.

        • Promethiel
          link
          English
          6
          edit-2
          2 months ago

          Then it just looks like you’re trying to give a competitive edge to US evil social media.

          This is not just probable but certain; the whole thing is a very long way of saying this. In a world where the US worked for its citizens, this is a national security no-brainer. But we don’t live in a world where the spirit of things is followed when you can enrich yourself skirting the letter. Shit sucks, but this not a secret conspiracy; it’s realpolitik.

          and preventing youth from learning about the situation in Palestine.

          This one is more subjective…and also still probable for the same fucking reasons and good luck sharing the fact that you can act in a so called ‘security’ driven purpose and this is the perfect time to do sneaky shit. As if all of History wasn’t rife with examples with the Patriot Act being the first USA centric coming to mind amongst fuck what, hundreds?

          That is also realpolitik, and all the players know it. Shit sucks.

        • Cethin
          link
          fedilink
          English
          1
          edit-2
          2 months ago

          It is absolutely giving an edge to “evil” (morality doesn’t matter in politics, especially international politics, and TikTok isn’t good anyway) US social media. China literally blocks all western social media. Everyone plays this game, and TikTok shouldn’t be on a pedestal just because you like using it.

          preventing youth from learning about the situation in Palestine

          OK, I really don’t think this has anything to do with it. There are many more places people’s are discussing this, like Lemmy for instance, that aren’t targeted. I’m sure you can find the same conversations happening on Reddit, Facebook, or whatever other social media. TikTok, though increasingly used for news, is not the only source of news about Palestine, nor is it the best. Short format content will never be good for detailed discussion of news and anyone thinking they’re getting thorough news in that format should reconsider.

      • @[email protected]
        link
        fedilink
        English
        32 months ago

        I’d only accept the TikTok argument when it gets applied to all social media companies in equal measure.

        We don’t need one-off bans that let the worst offenders get away with exploiting people’s personal data. We need a bill of privacy rights.

        • @[email protected]
          link
          fedilink
          English
          32 months ago

          So your argument is if the regulation isn’t perfectly applied to every possible instance of a potential violation simultaneously, then it should never be applied? How does that make any sense?

          • @Leg
            link
            English
            32 months ago

            I think it’s a reasonable request that regulations be consistently applied rather than utilized at the whims of corporate favoritism. Facebook deserved a ban well before tiktok was an entity.

          • @[email protected]
            link
            fedilink
            English
            1
            edit-2
            2 months ago

            As opposed to selective enforcement of regulation mostly informed by nationalism and insider trading?

            How is this even a question. XD

        • @[email protected]
          link
          fedilink
          English
          22 months ago

          You’re focusing on one of the two issues I brought up, and ignoring the other categorically.

          • @[email protected]
            link
            fedilink
            English
            -2
            edit-2
            2 months ago

            If you take off the nationalist filter you’ll see that they are the same issue.

            Social networks don’t need middlemen, middlemen need social networks that rely on server/client architecture they can exploit.

        • @ripcord
          link
          English
          -12 months ago

          deleted by creator

      • @xantoxis
        link
        English
        02 months ago

        deleted by creator

    • @[email protected]
      link
      fedilink
      English
      72 months ago

      While I agree Facebook is also bad, the Tiktok thing is entirely different, because the legal issue is sending Amarican citizens data out to China, which the users agreed to give to Tiktok, but the government doesn’t want to be sent to China. The Facebook crime is secretly snooping without proper user consent.

    • Aatube
      link
      fedilink
      42 months ago

      I definitely see why this would be illegal, but how would the DMCA apply?

        • Aatube
          link
          fedilink
          -22 months ago

          That would be if they downloaded the uploaded Snapchats. This takes out web traffic, aka which “locations” your device visited, which 1. isn’t protected by copyright since it’s not a work 2. hasn’t been to Snapchat’s encryption yet. That time Bethesda accidentally shipped a DRM-free version of doom along with the main version, I don’t think opening the DRM-free one would count as circumventing.

          The relevant laws here should be about privacy and hacking.

          • Aniki 🌱🌿
            link
            fedilink
            English
            6
            edit-2
            2 months ago

            Why did you ask if you already had your answer then? The DMCA has no carve outs.

            • Aatube
              link
              fedilink
              10
              edit-2
              2 months ago

              Because you may have seen some angle I didn’t anticipate.

              Not sure what you mean about carveouts.

              • @[email protected]
                link
                fedilink
                English
                32 months ago

                There’s no exceptions for fair use, if you break the encryption at all then you’re in violation of the DMCA.

                • Aatube
                  link
                  fedilink
                  -12 months ago
                  1. They technically (and legally) didn’t break it as they’re intercepting the traffic before it gets encrypted.
                  2. Not all encryption is DRM and covered by the DMCA. Hacking into and decrypting an encrypted database of passwords is violating hacking laws, not the DMCA. Same would apply to traffic data.

                  Note that IANAL.

  • @[email protected]
    link
    fedilink
    English
    822 months ago

    Let that parasite rot in prison.

    And can somebody split Meta already? Please and thank you.

    • @[email protected]
      link
      fedilink
      English
      72 months ago

      Why split Meta? The poor mom and pop shop only makes 350 million in revenue… Every day…

    • @thorbot
      link
      English
      62 months ago

      Yeah, he wont

  • @[email protected]
    link
    fedilink
    English
    362 months ago

    I was thinking of buying a Meta Quest 3, because of a lack of similar devices. I wasn’t really seriously considering it, but I sure as hell am not at all now.

  • RedFox
    link
    fedilink
    English
    222 months ago

    I’m sure corporations like this would give you free Internet if they could collect and sell all your data. I’m also sure people would still do it, regardless of how much they are being monetized as a product.

    Since companies like Facebook own legislators, our only real choice is to stop using it. Unpopular opinion, but If you really want fuck Zuck, delete your account, and get all your friends and family to as well. Maybe there’s some alternatives for the people who truly use the service to connect with friends/family?

    • @rtxn
      link
      English
      252 months ago

      corporations like this would give you free Internet if they could collect and sell all your data

      Facebook Zero is more or less what you described.

    • @[email protected]
      link
      fedilink
      English
      82 months ago

      The free Internet if you give use your data is already a thing. I saw an ad in germany where you get unlimited free internet access (can’t remember if it was a data plan for phones or cable / fibre service) if you use their “payment partner” for your usual payments like rent, loans and salary. So they basically can see your daily payments and will use and sell this data im exchange for “free” Internet access.

      The company and its investors and corporation lead to a weird network of people and a corp in dubai. It’s all quite shady really.

      • RedFox
        link
        fedilink
        English
        32 months ago

        Wow, that is weird. I honestly just made that up in my head when I wrote it.

        The saying is true, if it’s free, you’re the product.

        I don’t actually know why I care about that level of privacy. Some of us are quite fine with companies or their government having any information about them. Some are very opposed.

        Maybe I dislike the idea that information could be used against me somehow or they’re making even more money than I’m already paying in some hypothetical case. Not sure.

        • @[email protected]
          link
          fedilink
          English
          32 months ago

          I work in IT so you might think I might be more into the topic and thus more careful with my data. There are a lot of colleagues of mine that don’t care one bit. Some even jokingly call me paranoid.

          Sure, I use GrapheneOS, a de-googled Android OS, made the switch from Gmail to Tuta (formerly tutanota), a privacy ans security focused mail provider and use my own domain for mailing.

          Then there are some other measurements in place like AdGuard and Pihole to block ads and trackers. I think that’s the bare minimum, especially if you’re working in IT. It doesn’t cost much, the setup is straight forward and the benefits are huge. I haven’t had any ads in my network for years.

          I’m currently switching from windows to Linux as daily driver. There are some issues with getting some games to run, but as soon as they do I’m switching for good.

          There are some easy thing one can do, even without any expertise in IT. There are even things you can do that aren’t finicky (like linux troubleshooting). People are just way to comfortable.

          Maybe they should watch the documentary about Edward Snowden, Citizenfour. That might change their mind.

          • RedFox
            link
            fedilink
            English
            12 months ago

            I watched that. Didn’t surprise me one bit.

            The overreaching government apparatus doesn’t inherently bother me, but we’re really placing a lot of power and trust in those people, and that does concern me.

    • @[email protected]
      link
      fedilink
      English
      32 months ago

      I’m sure corporations like this would give you free Internet if they could collect and sell all your data.

      Already a thing. I see them advertised everywhere for prepaid plans and people go ‘omg Facebook/Whatsapp/Instagram/TikTok for free!!1!’.

    • @[email protected]
      link
      fedilink
      English
      12 months ago

      I dunno, seem like the goal is to get you to buy a subscription to collect your data hostage in their cloud.

      And somehow for enough gullible customers its actually working.

  • @LEDZeppelin
    link
    English
    222 months ago

    Delete this shit from your phones asap

    Zuck Fuckerberg

    • @thorbot
      link
      English
      112 months ago

      Can’t delete something that was never there in the first place

    • @[email protected]
      link
      fedilink
      English
      12 months ago

      Yeah, they’re making it a system app now. Can’t be installed without adb, and most people don’t know how.

  • @rtxn
    link
    English
    212 months ago

    Every 60 seconds in Africa, a minute passes.

  • @[email protected]
    link
    fedilink
    English
    18
    edit-2
    2 months ago

    I must be way out of the loop, cuz I had no idea this was possible. So does this mean the Facebook app on my phone has permission to view all of my network traffic? Why do Android and iOS allow this? Shouldn’t that be a special permission that can only be granted explicitly?

    • @diffusive
      link
      English
      142 months ago

      Nope, because Facebook app is not a VPN service so it cannot intercept traffic.

      What it is unclear from the article is how they circumvented the certificate check on the app side. Probably (given this was many years ago, maybe these apps weren’t setupping certificate pinning/HPKP)

      • @[email protected]
        link
        fedilink
        English
        12 months ago

        In theory, yes. In practice of they found some sort of exploit that allowed this I’d 100% not be surprised if Meta took advantage of it. Facebook app is malware

  • @xantoxis
    link
    English
    162 months ago

    The world would be a better place if Mark Zuckerberg accidentally got sucked into a jetski engine somehow

  • @[email protected]
    link
    fedilink
    English
    142 months ago

    Learning: VPN services are tracking instruments, not some magic tool.

    And its not even new…

  • @TORFdot0
    link
    English
    132 months ago

    Certainly they weren’t planning on actually planning on finding a way to get people to install a VPN to decrypt their traffic just to use Facebook, right?

    That’s why they paid teenagers to use the VPN so they could get some “guerrilla market research”.

    Even in 2013 apps didn’t have the permission access to install a device level VPN without some unspecified exploit. 0 chance Facebook would literally hack people’s phones, right?

    Right?

  • @Nonononoki
    link
    English
    102 months ago

    Wait, how does a VPN break TLS encryption?

    • @[email protected]
      link
      fedilink
      English
      162 months ago

      The VPN adds its own root certs to the device, and just terminates TLS at the gateway, then establishes a second TLS tunnel to the device.

      • @[email protected]
        link
        fedilink
        English
        52 months ago

        It can’t do that silently, the user has to approve installation of root certs. This only works silently with apps which have broken (insecure) cert validation

        • @[email protected]
          link
          fedilink
          English
          12 months ago

          Can’t do it silently, but it’s not uncommon for root certs to come along with a VPN. I wouldn’t be surprised to see that it’s built into the VPN profile API on Andriod and Apple devices.

    • @waitmarks
      link
      English
      52 months ago

      it doesn’t, what this is suggesting is the vpn was routing traffic through it so they could analyze snapchat traffic. not the contents of it but essentially meta analysis of the traffic. how often it was sending data, how much data, where it was going etc.