Facebook to Remove Onavo App from Apple Store
wsj.com
wsj.com
Once Facebook has all the packets, they can do various analyses and machine learning to even learn which features are most popular within a competitor's app. It is quite sophisticated.
Edit: it was worth the downvotes, would do again.
This is just not true at all. Where are you getting this information?
They do not do any sort of analysis on the device side as that is not possible. They connect your device to a VPN server (All analysis is conducted there). The APIs you describe can not be accessed from within the App Store sandbox, I believe as of iOS 8 that became no longer possible.
Here are technical details on the local functions of the app:
https://medium.com/@chronic_9612/notes-on-analytics-and-trac...
Apps don’t even get a list of all apps you have installed, much less information on how much data another app is using. The system collects that data though, you can see it in the settings app.
I'm sure if it was a smaller company doing a similar thing they wouldn't have been given such leeway as Facebook was for so long.
Until Apple starts banning all of these types of apps and libraries (which their recently updated policies indicate they just might [2]), I view this as more of a strategic play against Facebook as opposed to in the best interest of users.
[1] https://itunes.apple.com/us/app/my-data-manager-track-your/i...
[2] http://www.integrity-research.com/new-apple-policies-threate...
VPN-based data collection apps could just as easily be cleaned up if there was the will to do so.
It's hardly malware. Users should have the right to trade access to their data for free data compression, whether you personally think that's a good idea or not.
Even if it is clear in the app description that it is collecting data from users, I don't believe that the extent or consequences of such data collection would be considered or understood by the majority of its users.
It's a spyware product, wrapped up as a VPN, relying upon lack of attention from users to succeed.
Merriam-Webster says "software designed to interfere with a computer's normal functioning". Wiktionary: "Software which has been designed to operate in a malicious, undesirable manner". Etymologically, it means software that is malevolent.
This app collects data in a malevolent/undesirable way. It clearly tries to interfere with the personal data of the user and hence the intended functioning of the computer. Hence a malware.
This is utter nonsense. How many users are making an informed decision here? How many understand what their data may be used for or how it may affect their insurance, employment, or housing prospects in the future?
There's a reason some contracts are not legal/enforceable (slavery for example).
> 2.5.14 Apps must request explicit user consent and provide a clear visual indication when recording, logging, or otherwise making a record of user activity. This includes any use of the device camera, microphone, or other user inputs.
So did Onavo "provide a clear visual indication" whenever collecting data? Somehow I doubt that, because it would have been a constant warning.
Do you have any proof of this?
You can narrowly define malware by a quick dictionary definition[1]:
> software that is intended to damage or disable computers and computer systems.
However, malware also has a much looser definition[2] if we don't restrict ourselves to a one sentence Google result:
> Programs officially supplied by companies can be considered malware if they secretly act against the interests of the computer user. For example, Sony sold the Sony rootkit, which contained a Trojan horse embedded into CDs that silently installed and concealed itself on purchasers' computers with the intention of preventing illicit copying. It also reported on users' listening habits, and unintentionally created vulnerabilities that were then exploited by unrelated malware.
Now people defend almost the same practices (in a nicer package) on Hacker News.
We are truly fucked.
Google collects a lot of data [3], including app and website usage [2] too. They have full access all the analytics a phone OS can provide, after all.
I'm not saying this is ok, but if we claim this is malware then Android is malware too. I rather reserve the malware label to software that is directly designed to harm.
PS: Apple collects app usage too [1], but IMO they're at least more clear about it.
[1] https://support.apple.com/en-us/HT202100
[2] https://myaccount.google.com/activitycontrols
[3] https://privacy.google.com/your-data.html
EDIT: Why the downvote? Rather than downvoting, some constructive discussion on spyware and business practices would be IMO more welcome.
Sure, it is. Or spyware, at least. So is Windows.
> I rather reserve the malware label to software that is directly designed to harm.
Stealing data is harmful. I mean, consider the OpenSSH user enumeration vulnerability.
It is? Android is completely ridden with dark patterns[1].
Onavo didn't have to make money because it was owned by Facebook and it was known to collect data for its parent company's market research. Much less is known about how other VPN apps remain sustainable-- I wouldn't doubt some might be running on sketchy business models.
Calling this a ‘data security app’ is like calling a Snickers bar a diet meal replacement.
This app literally gives facebook the ability to track every app you runs and every website you visit, for how long, when, and what network you do it from.
It is literally the kind of data collection that people use VPNs to avoid!
I have a feeling that a majority of VPN app users use them with the intent of preventing a specific party from collecting that data (e.g. an employer or a government).
On the one hand, there's a clear value proposition here: instead of paying a few bucks a month for a VPN, you can instead pay by giving a giant megacompany your private data.
The problem is we as a culture don't have a good consent model for educating people about what this actually means. In a world where everyone who used Onavo knew exactly what data Facebook was getting from them, and what that meant, what number of users would willingly use it?
Calling it "malware" or "spyware" doesn't feel accurate, since they're not outright lying about what the value prop is, but they're still being deceitful by omission and are preying on people's ignorance.
I suppose my point being that just because users "agreed" to something doesn't necessarily mean they knew what they were agreeing to at the time.
What happened? You've requested a page on a website (archive.is) that is on the Cloudflare network. Cloudflare is currently unable to resolve your requested domain (archive.is)."
Domain blocked?
Edit: No idea why, just sharing context I have.
Do you have a list of them or source for this claim? (not that I'm disagreeing with you, but just want to see the full extent of the problem)
"Verizon and AT&T will stop selling your phone’s location to data brokers" <https://arstechnica.com/tech-policy/2018/06/verizon-and-att-...
"Verizon and others call a conditional halt on sharing location with data brokers" <https://techcrunch.com/2018/06/19/verizon-stops-selling-cust...
It's well known now that ISPs can monetize and sell customer data. For example, see https://www.usatoday.com/story/tech/news/2017/04/04/isps-can...
EDIT: This was an honest question. If anyone has any insights to share, I would really appreciate it. Over the years, I have dealt with some truly questionable third-party VPN software from the usual big name networking equipment vendors and plenty of other so called “security” vendors.
You're paying third parties for the service, and those third parties use the money to maintain the infrastructure powerful enough for each user to have high speed VPN service (nobody's gonna use a VPN that throttles the speed by 90%) across different geographical regions.
If Microsoft and Apple wanted to offer a VPN as a first-party service out of the box, they would be forced to maintain a pretty complex infrastructure across multiple regions and somehow be able to support way more traffic than any third party VPN provider (because of their name). So, where's the money for the infrastructure going to come from?
In Facebook's case, form mining the data. I would argue that Apple isn't stupid enough to attempt something like that, and as for Google, they already do have a first-party VPN integrated into Android[0].
I would argue that the reason that third-party VPNs are shady is because they need a large infrastructure in place before they can offer the service. Once they do have the infrastructure in place, they're not making profit, but covering their losses, while at the same time being forced to scale even further.
[0] On Nexus/Pixel devices from certain regions that activates automatically when connected to an insecure WiFi: https://www.howtogeek.com/275474/how-to-use-androids-wi-fi-a...
I'll give Apple the benefit of the doubt but I'm not sure I'd be keen on this kind of setup in the case of Google or Microsoft. Then again, they have access to all of your browsing data anyway via the OS so what's to lose?
"Onavo, which began as an Israeli analytics startup focused on helping users monitor their data usage, was acquired by Facebook in 2013. Its VPN provider then became a data collection tool for Facebook to monitor smartphone users’ behavior outside its core apps, helping inform Facebook’s live video strategy, competition from other social apps, and its decision to acquire companies including WhatsApp."
Geez, man. That is evil. Especially since most users don't know the difference between "security" and "privacy", and probably assume that it would have the exact opposite effect.
Edit: Just how is this distinguishable from the Sony or HB Gary hacks? Not as much data was taken, it's true. But there were far more victims. And I doubt that there was adequate disclosure.
Edit: OK, spyware. And people have been prosecuted over spyware.
"As part of providing these features, Onavo may collect your mobile data traffic. This helps us improve and operate the Onavo service by analyzing your use of websites, apps and data. Because we're part of Facebook, we also use this info to improve Facebook products and services, gain insights into the products and services people value, and build better experiences."
Running a VPN isn't particularly cheap. I'd assume that any free VPN is one of:
1. criminals collecting and monetizing your information
2. state actors collecting and ?????????? your information
3. companies collecting and monetizing your information
4. too small to need to do one of (1)-(3)https://developer.apple.com/documentation/storekit/skadnetwo...
For this article that means go to
https://www.fullwsj.com/articles/facebook-to-remove-data-sec...
(I just copied and pasted our post link then added "full" before wsj.com)
This is in the FAQ at https://news.ycombinator.com/newsfaq.html and there's more explanation here:
https://news.ycombinator.com/item?id=10178989
https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...