Facebook has been paying people to install a “Research” VPN
techcrunch.com
techcrunch.com
#1 "they didn't even bother to change the function names, the selector names, or even the "ONV" class prefix. it's literally all just Onavo code with a different UI."
#2 "the Root Certificate they have users install so that they can access any TLS-encrypted traffic they'd like."
My editorializing - I have been suspicious of Facebook getting the "submarine" treatment (1) but the insane scuminess of #1 above, which essentially is a big fuck you to Apple, pretty well supports the recent view that FB will essentially break any rule that serves to further their own ends.
Edit: on 2nd thought even if Facebook can't decrypt a particular app's traffic, just knowing how many requests it makes, how large they are, and how often, could still provide some useful insights into an app's usage.
> Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. “Data loss prevention” appliances, firewalls, content filters, and malware can use this feature to defeat the protections of key pinning.
http://www.chromium.org/Home/chromium-security/security-faq#...
EDIT: Spaced on the fact this is a phone app. While Chrome on Windows ignores certificate pins, I'm unsure if this also applies to Android / iOS root stores as well.
Source: https://bugs.chromium.org/p/chromium/issues/detail?id=779166
> OK, we're looking at removing dynamic PKP in M69. Static PKP will remain until further notice (we have no active plans to remove it right now).
Jailbreak required, of course.
Many apps do not do pinning currently.
Point out a few? This needs to be common knowledge.
- installing root certificate to access encrypted data (potentially of websites? including banking websites?)
- means bypassing security mechanism put in place to prevent people to access data send to a server (from a browser/app)
- means potentially bypassing DRM, too
=> isn't that illegal even if the user agrees to it? (at last in the US where some especially DRM related laws are strange)
(However, upthread comments indicate that using certificates to see HTTPS traffic is a fairly common practice in enterprise setups)
If somehow, the practice were found to be a key part of circumventing some large industry's means of controlling something, it could realistically end up becoming illegal once subject to legal scrutiny.
By using a VPN they forced all traffic to go through their servers, and with the root certificate, they are able to monitor and gather data from every single app and website users visit/use. Which would include medical apps, chat apps, Maps/gps apps and even core operating system apps. So for users using Facebook's VPN they are effectively able to mine data which actually belongs to other apps/websites.
They could drain your bank account, hiding the transactions and adjusting the balance whenever you viewed the mobile banking website or used your mobile banking app and adjusting any emailed statements.
They could send messages to your friends and family from your account asking them to send money to you in a certain way or donate money to a "charity", hiding the entire conversation from your view.
They could make some services you use slower or less reliable in subtle ways, to steer you towards the ones they want you to use— the ones that are easier for them to manipulate the traffic to/from.
They could make you think you're going insane, in any one of a variety of ways.
They could gather all of your private information, and then lock you out of your entire digital life all at once. Two-factor authentication wouldn't protect you; they could present you with a fake "re-confirm your settings" process to collect the information necessary to disable or replace the settings. (If you pay your rent using your phone, they could lock you out of your physical life too; they could prevent the payment from going through, show you a confirmation, and suppress notifications of unpaid rent and e-mails from your landlord.)
They could control which news you see, slowly shifting your views on things like privacy and security.
If you get suspicious about any of this, they could plant false information in your search results.
But if they were operating in the UK, I'm somewhat doubtful their disclosures as reported in the article could be classed as informed consent under GDPR given the "specific protection" children are provided [1].
[0] http://www.steinfeldlaw.co.uk/uploads/Are%20you%20contractin...
[1] https://ico.org.uk/for-organisations/guide-to-data-protectio...
This is, perhaps, the most apt question to take away from this. If an individual did this, even with an EULA, that would be a fast-tracked way for them to see the inside of a penitentiary in almost any country, yeah?
And, $20 per month is pretty substantial compensation.
The way that Facebook is bypassing Apple's rules feels shady, but I've always felt those rules were user-hostile to begin with. I firmly believe that users should have control over their own devices, and that means letting users give information to companies if they so choose—especially if they're being financially compensated.
Children, specifically.
> Perhaps they don't know the full extent of what Facebook is tracking
…is this not bad?
> sideloading apps on iOS is not a one-top process—anyone who used this had some sense of what they were doing
This is not sideloading; this is enterprise app distribution. Users are not self-signing this app.
> And, $20 per month is pretty substantial compensation.
For a child who doesn't know any better, maybe…
So many of the comments in this thread are literally "Think of the children!"
Which brings us back to you falsely claiming anyone but you uttered that phrase, and your implied assertion that there is something wrong or odd with looking out for others, including children.
Just to be clear, that's the process I was referring to. I consider it a form of side loading, because the app is coming from an unofficial, non-Apple source.
Enterprise apps won't run until you manually go into settings and certify that you trust the developer. Far from the most onerous of tasks, to be sure, but significantly more involved than tapping a download button. I don't see how someone could be "duped" into running an enterprise app.
I'm just not convinced on this point. I think it's likely a lot of people did understand that Facebook could see all their internet traffic, and thought for $20 it was a fair trade. There's a HN user down thread (anonymous5133) who says he used the app and quite liked the exchange.
Now, it's possible these users did not think through all the consequences that sending this data to Facebook could have—but just how much responsibility does Facebook have here? Does Facebook need to say in big red type, "This data could be given to health insurance companies some day and used to deny coverage?" (I'm not even clear if that would be legal, but I bring it up as an oft-cited nightmare scenario.)
You could say the people who bought his kidney for an iPhone did nothing wrong. The kid had control over his own body and they made a deal the kid thought was good.
I think, though, that he wasn't properly educated of the risks that doing such a trade would leave him with, and that the people who offered him the deal very well knew them, but targeted him for being a naive child who wouldn't take them seriously.
I think this is the same case. People just don't understand or don't take the risks of this seriously enough, and companies like Facebook take advantage of that.
I don't think personal information is so valuable that we need to outlaw its sale.
Furthermore a short term windfall from selling organs will not provide the skills or assets required to prevent long term starvation and homelessness; so now the horror has been compounded: homeless, starving, and prone to debilitating illness.
Also, how you mention as fact that money from selling organs won't prevent long term starvation and homelessness is surprising; you don't know that's the case one way or another but you're trying to pass off an opinion as fact. I can't argue either that it would help with a clear and definite metric, but the correlation of living conditions and money is clear. How real-life application of such legalization or organ selling, with quality of surgery and post-surgery care, legal predatory practices, and other factors are dealt with are potential problems, but those are issues that exist in all commercial domains.
I also never argued organ selling as a solution to a problem; as others mentioned, it is a potential band-aid to a problem that lies in wealth inequalities, but which I find interesting as a societal flashpoint that show how knee-jerk emotional responses can cause logical paradoxes.
How much is a Jew's life worth vs a Christian's life vs a Muslim's life? Or would it make you squeamish to try and adjudicate that? Or are some things not worth putting a price on because of principles, because breaking those principles would have worse second and third order effects?
I tend to agree with them.
Come to think of it, is there anyone making a strong case for weaker privacy protection? I’m prepared to put aside my existing assumptions long enough to read an article or two.
Europeans seem to disagree. Maybe your "reason" is just cultural bias?
Under GDPR, it should be perfectly legal to compensate a user for agreeing to share personal data with marketing companies.
Also under GDPR the consent can be revoked at any point and the data has to be deleted. Plus the owner has to be given exhaustive information about what data was gathered, what basis it was gathered on and who it was passed on to (recursively).
You make it sound like they're just obtaining a list of URLs, but that's not it. For $20, they get to impersonate you while you're in the VPN and after you leave (they have all your passwords and session cookies). They can also impersonate anyone you deal with. They have all decrypted information going between you and the rest of the internet. Not even your ISP gets that amount.
Even further problematic is the scale at which they can do this. This isn't just a concern we should see as individuals but also as a group. They can control a grand portion of information flow and authentication in the whole web.
Very likely the kid didn't understand exactly all the risks and wasn't informed when selling his kidney. And I would guess it's the same thing for a lot of kids signing up for this facebook thingy thinking "free $20 a month? Let's fucking goooooooo!"
But I honestly feel just as creeped out by apple dictating what people can install on their phones and what they can't.
Informed consent is _impossible_ here because there is no way a person can know what future use the data will be put, and Facebook sure as shit ain't gonna tell, and they're even less likely to limit their future use of the data through an agreement made in the present.
One which needs to be opened and we need to sift through to find an acceptable answer. It is difficult to find something that allows freedom of choice and doesn't require a huge amount of knowledge. Plus, who decides what the facts are? The required minimum knowledge? How do you measure understanding? Are we going to have a ministry of truth? If so, who watches the watchmen?
If Facebook is willing to break an agreement with one of the largest corporations on the planet, what reason is there to think that they will keep any promises they make to individual users?
To me, the problem seems to be (a) lack of informed consent, compounded by (b) the targeting of a vulnerable population.
[1] https://en.wikipedia.org/wiki/Belmont_Report [2] https://en.wikipedia.org/wiki/Respect_for_persons [3] https://en.wikipedia.org/wiki/Informed_consent
The biggest question I have is why they needed the root to analyze popularity of future competitors. Surely doing domain requested (visible even with TLS) and number/time of requests would be sufficient, and that would have greatly reduced the amount of private data gathered.
But Facebook's competitors did not consent to their traffic being spied on and had a reasonable expectation that their traffic would remain safe from this type of intervention on iOS devices. Ignoring the ethics of paying users for data and so on, this seems like a straight up case of industrial espionage. The article says that this is how FB spotted the rise of WhatsApp, and presumably informed the offer. They would have known exact usage information, this is espionage via surveillance.
On top of that they would have had access to message formats, headers, encryption protocols and so on, things that are potentially trade secrets. This isn't user-visible data and app owners shouldn't expect that competitors can access it directly from a user's phone.
Combining legally-obtained data to come to a conclusion is not illegal or immoral.
https://www.theguardian.com/technology/2019/jan/20/shoshana-...
A hypothetical experiment Facebook might be interested in conducting: Do people use Facebook more if Twitter is slow and/or unreliable?
Of course the implications are outlined in the fine print / data protection agreement when signing up, but I doubt most of the participants are aware of just how far the data collection they enable with this goes...
[1] https://swissmediapanel.ch/ (Link in German)
They are clearly informed that the app will track information regarding their online activities, device usage behavior and applications they use.
I think the main issue is that users without a tech background are just not aware of the full implications of allowing a third party to collect this kind of data, even decrypting their HTTPS traffic and tracking everything they do online.
The statement by Strafach in the original article sums it up quite nicely:
“The fairly technical sounding ‘install our Root Certificate’ step is appalling,” Strafach tells us. “This hands Facebook continuous access to the most sensitive data about you, and most users are going to be unable to reasonably consent to this regardless of any agreement they sign, because there is no good way to articulate just how much power is handed to Facebook when you do this.”
Which makes this fraud, right?
In the same way automotive manufacturers are held accountable even if their was no intention to cause harm, the software industry needs to be held accountable.
We need to have professional organisations, and government regulators, working to ensure some kind of general industry best practice, where software developers can initially start getting tapped on the shoulder, then given a series of rapidly increasing penalties until the industry gets the point that it can’t keep making out it’s the wild wild west.
And this is why I don’t believe software development is a proper serious profession. The proper professions, here in Australia at least, are granted the authority to witness statutory declarations. I can go to a qualified vet, doctor, engineer, chiropractor(!), police officer, school teacher, postal worker, the list goes on[1], because these professions have a chain of trust.
And yet we trust(?) software developers and their employees with our most sensitive data!
1. https://www.ag.gov.au/Publications/Statutory-declarations/Pa...
Do we really think computer illiterate people know that Google can infer a huge about of sensitive information about their end-users without them ever ticking "i accept" or signing up for an account?
At least with this they have to take explicit actions like accepting the terms and installing the tracker before they're tracked. They even get compensated for it.
In Google's case you don't get anything.
Reading their FAQ they nicely pack what's going on in flowery language e.g. "Is the Swiss Media Software a Virus or Spyware?"
The Swiss Media Software is not a Virus and also not Spyware; it is not malicious and does not do harm to your computer, phone or tablet. The Swiss Media Software only observes the behaviour of Internet users that they have approved (this last sentence could be a bad translation by me).
That said the companies behind it; Net-Metrix and Intervista, are basically harmless - they produce consumer studies and are something like the "Nielsen" of Switzerland. The bigger risk here IMO is they themselves get hacked - knowing a little about Net-Metrix for example, I doubt they have the resources to properly protect their infrastructure.
Security and also how far they actually go in separating the tracked data from your demographic & potentially personally identifiable data is definitely a concern, next to the obvious issue of how informed one can consider the consent they get from their users...
> “The fairly technical sounding ‘install our Root Certificate’ step is appalling,” Strafach tells us. “This hands Facebook continuous access to the most sensitive data about you, and most users are going to be unable to reasonably consent to this regardless of any agreement they sign, because there is no good way to articulate just how much power is handed to Facebook when you do this.”
So for the reported use case, "hey, tiktok looks good, let's find out how many people use it before we buy it out," it would seem that non-MITM would be plenty (and technically easier/lower resource to do, VPN could be kept on device and the pre-anonymized data sent up to the cloud, saving them server costs and bandwidth.
Compensating people for information on their behaviour is nothing new. If you participate in a program to report daily purchases you probably give away as many information and yet it's not viewed as controversial. The fact that Facebook doesn't have a great track record is problematic but generally, I don't see a big issue.
However, I _would_ contend with the assertion that "there is no good way to articulate just how much power is handed to Facebook when you do this." Sure there is—just not one that would look good for Facebook.
This is bad juju.
Using intermediaries also allowed Facebook to technically not violate Apple's enterprise certificate contract (because the intermediaries were in violation instead).
I actually though they would have done that, but it used the regular "iPhone Distribution: Facebook, Inc. (In-House)" cert, they didn't even create a shell entity and get a new one. Reports say Apple has revoked this cert, breaking all internal (legitimate) apps and possibly creating quite a bit of chaos for internal ops.{1} Their separate Apple Developer Program organization account, used to deploy TestFlight public and private betas and App Store apps, as well as local deployment to a small number of devices without Apple involvement for development testing, is not affected.
The intermediaries may or may not face consequences if they have separate agreements with Apple, but they did not use any Apple products to do their part and have not violated anything with Apple.
{1} https://www.theverge.com/2019/1/30/18203551/apple-facebook-b...
Big opt-ins require big explaining because people can only truly make free decisions if there is an actual effort to inform them about what is happening.
Edit: so maybe this is a bit extreme because I realize that this might similarly apply to (for example) phone manufacturers. I still think that actually analysing the traffic is a bigger risk than simply providing the phone/browser to generate the traffic because of the centralized target that is Facebook.
* selected user's age;
* proper disclosure.
The fact that they're targeting kids makes it that much more unethical.
Plus, the deliberate targeting of children that won't know better. And asking people to upload their Amazon order history! Pretty scummy.
Surely there's something to be said about age. There's a reason 14-year-olds can't enter into a legally binding contract.
Besides this, there's also the issue of how clear it is that the app is collecting private data. The article says:
"Facebook first got into the data-sniffing business when it acquired Onavo for around $120 million in 2014. The VPN app helped users track and minimize their mobile data plan usage, but also gave Facebook deep analytics about what other apps they were using."
which seems a lot like Facebook luring users into giving them their data without the users' knowledge.
1. Those who understand what they are signing away and need $20/mo more than they need privacy
2. Those who don't understand or don't understand fully what they are signing away and see it as free money
Preying on either group is disgusting and wrong. I'm really interested to see what Apple does here, they have taken a hard line on privacy and I don't doubt they will kill this app but if FB wants to play wack-a-mole they WILL win (see iOS sideloading scene), for me the big question is will Apple take down the FB apps?
We've seen Netflix, Uber, FB, Amazon, and more skirt the rules of the App Store in the past, they've barely gotten a slack on the wrist (in public at least). At what point does Apple take a real stand and say no? Cause so far $$$$$ has ALWAYS stopped them, I really do believe they care about privacy, I don't know know if the shareholders do.
Edit: Typo
Or maybe privacy isn't something we should care about or at least value as much as we do as a society. Maybe I'm wrong. I think I see the dangers down the road but maybe it's just a mirage and privacy will die and it won't be used against use by people in power or with money.
This is not the question that's being asked here. The fact is, there are people like that, and for them, these things are great.
They're not solutions, they're band-aids. But if you're not ok with the situation existing, removing band-aids isn't particularly productive.
No questions, this is creepy. But nobody was talking about a ban. The post I replied to asked whether we should be okay with people who need $20 that badly.
The answer is no, we shouldn't be ok with it. But you're not solving the situation by banning this, you're making it worse if anything.
"We shouldn't be ok with people being homeless." "Okay, let's make 'being homeless' illegal. Problem solved!" "???"
And yes, this logic has been used before. It hasn't solved homelessness, btw.
it's provably affordable to give everyone the average rent of the world which covers housing (rent of buildings), food (rent of farmland), energy (rent of space used for solar panels, windmills, ...), natural resources (rent of mines).
If you guys are so concerned about it then create something that puts cash in my pocket. I'll gladly run whatever app you want on my phone if you pay me.
Edit: and now they shut it down. You can thank us privacy advocates later.
Resulting in thousands of deaths due to organ shortages, and sex workers being abused by pimps and corrupt cops.
That illustrates fairly well why having an underclass who provides healthy organs to the rich is a utterly barbaric idea.
I don't have a strong opinion either way, but my understanding is that it's very very far from proven that legalizing prostitution improves the lot of sex workers -- I am led to believe that trafficking becomes _more_ of a problem in localities where sex work is legal.
Further, and again no strong personal opinion on the matter, but I suspect you'd see a huge rise in coerced organ selling if it became legalized.
These are questions societies need to answer for themselves, and my central point was that there's already precedent for societies deciding that they don't benefit when some things are available for sale, even if an individual in the moment says they want to sell it.
When a person is paid to strip you, nor the house, get to read everything they do on their smartphones.
> For some people this money could be incredibly important.
So I took this to mean "desperate enough" as in there are scales/levels of "desperate"-ness. Maybe desperate is the wrong word and the "enough" modifier wasn't obvious in my meaning.
Maybe a better way to put it:
Are we, as a society, ok with people needing $20 more than their privacy?
I was trying to convey that I imagine I would have to be pretty desperate to give up my privacy for $20/mo.
What if you have five kids. That’s $100 a month.
That's exactly the problem. In Human Subjects Research this might be considered a violation of Informed Consent in the form of undue influence. From the Belmont Report [1]:
An agreement to participate in research constitutes a valid consent only if voluntarily given. This element of informed consent requires conditions free of coercion and undue influence. Coercion occurs when an overt threat of harm is intentionally presented by one person to another in order to obtain compliance. Undue influence, by contrast, occurs through an offer of an excessive, unwarranted, inappropriate or improper reward or other overture in order to obtain compliance. Also, inducements that would ordinarily be acceptable may become undue influences if the subject is especially vulnerable.
Note the "especially vulnerable" part at the end there.
[1] https://www.hhs.gov/ohrp/regulations-and-policy/belmont-repo...
> That's exactly the problem.
I thoroughly disagree, and I feel like speaking up about this particular philosophy of consent.
If I buy a used iPhone for $100 from someone who would die if they didn't get the $100, have I acted unethically? Whereas if I bought it from someone who didn't really need the $100, I wouldn't be acting unethically?
This sounds not only wrong, but highly counter-productive to me, since the consequence of not entering into this trade, just because the seller really needs the money, is that the seller dies. How does that make any of us better off?
As a society, we should encourage trading with people who really need the money, not label it as unethical. Whether a trade is unethical or not can be determined solely from the trade itself, not how much either (or both of the parties) needs the proceeds from the trade.
Example illustrating the absurdity: imagine two people who both really need the proceeds trading with each other. Ouch! According to your philosophy, they are both acting unethically (when in fact they are doing the only reasonable thing).
In some cases, you have clearly acted unethically. For instance, if the iPhone is worth $800 and you have more money, but you're getting the $100 price because the man is dying now and there's nobody else around to offer him more than $100.
Yes, it would be unethical to both parties.
In the first case, it is unethical because you are taking advantage of someone's dire need to get a better price on an iPhone.
In the second case you are denying yourself a clear cut opportunity to really help someone in need.
To be in a position to help someone in such a state is a privilege that does not come around often.
In an ideal world, I would just pay the person $100 and not take their phone—but, c'mon, this isn't the world we're living in. People die every day in the US—never mind the rest of the world—because they couldn't afford medicine/shelter/food/etc
In this case you could make it that kind of world, for that person, just for $100.
To be placed in a position where it's so easy to help someone is a privilege.
I agree you can contrive a situation where the best ethical option is to pay the seller $100 for the phone but you really have to work on it (and the situation is pretty contrived to begin with)
It's even more unethical to encourage people to do so, like FB did.
As far as I know, when Apple discovered Uber doing some shady, but way less messed up things, they were flat out threatened to be kicked out. Problem is, this isn't Facebook's first rodeo, their previous app that did this was kicked off.
I think it's fine for group #1. If the $20 is that important to them then I'd rather not deny them the opportunity.
What if you simply don't care if some researchers have access to your data?
I'd honestly consider doing this myself, even though I am a highly paid software engineer, because it really does sound like "free money".
Although I probably won't, because I don't want to go through the hassle of sideloading an app on my phone (but if it was a 1 click thing, I'd seriously consider it).
This makes a lot more sense now. At that time the tech sphere was surprised at the price tag which is expected as people outside Fb perhaps didn't have these metrics.
How they heck is this fair?
I suspect there's been enough revelations about FB practices that many users would support Apple if they blocked the main apps. For a temporary block anyway.
Most of the general population probably neither understands nor cares that much if someone is watching what sites they visit or other basic privacy items and if you make them choose between privacy (especially privacy of others) and being able to post a picture of their lunch, many will choose the latter.
“My phone is listening to my conversations” is how it goes - people know this tracking is happening, they hate it and find it intensely creepy, they just don’t know the mechanism being used.
Disabling an app would be very noticeable and would anger many people.
Ummm, then those people don't have to side load an app that sells your data for money.
It would be an interesting twist of irony if they did take them down and there was a massive backlash against Apple. I have a sneaking suspicion that the media and Twitterati are more up in arms about all this than the users themselves.
On top of this you can add the fact that they basically shipped renamed onavo code, which was already banned from the app store, so this is de facto a violation of Apple's rules.
It's in the long term interest of Apple to not be soft on this stuff, it's not symbiotic.
And you'd be wrong.
> How can they claim to take privacy seriously if it’s clearly possible for bad actors to get around the rules multiple times!
That's BS. You might as well say: "how can they claim to take security seriously, if it's clearly possible for bad actors to find exploitable bugs in their products multiple times!"
Apple has a tough job, and it won't do it perfectly because no one can. It's bizarre to claim that it's excellent but not perfect performance somehow makes it guilty of the things it's trying to stop.
The device belongs to the user. It is fully within the user's legal right to install apps on their phone, even if Apple disgrees with those apps.
It is instead how the law works.
Apple tried, and failed, to sue people for doing things with the phones that were legally purchased by the individual.
If you install something Apple doesn't like, it is your full legal right to do so. The courts proved this.
If someone ones the phone, it is within their full legal right to do whatever they want with it. No extra fee necessary.
Block 3rd party cookies, install an adblocker and delete the cookies when you are done with FB/Instagram.
I can bet this is the LAST thing they want to see in the headlines. It forces them to address it, maybe they have a plan ready to go for this eventuality, a whole PR push and I kind of hope they do. If they don't they either look weak on privacy or have to roll out some half-baked plan/proposal/nebulous idea on how to protect users privacy better in iOS 13 or something like that.
Right now Apple is doing a whole hell of a lot of taking out of both sides of it's mouth and I understand it's a hard line to walk, I'm not saying I could do it better. FB's practices in general are probably an affront to Apple in general but skirting Apple's limitations to piss all over privacy and essentially turn an iPhone into an Android-level of data collection, I can imagine Apple is PISSED. I just really hope they had something planned for this day.
Enterprise developer accounts (the ones that can issue apps signed such that they can be sideloaded on any device) aren't something just anyone can go online and sign up for-- they require manual approval with proof of a business's identity before they're created.
So, unless Facebook starts opening well-disguised shell companies or something along those lines to circumvent any restrictions Apple might put on them, this will be over as soon as Apple revokes Facebook's enterprise distribution account. (Or, more likely, threatens Facebook into dropping the VPN app, because FB probably doesn't want to lose the ability to distribute legitimate internal-use apps to their employees.)
It's my understanding that faking these business identities is the entire business model of iOS sideloaded services (see the subreddit for examples [0]) so I don't think it's that difficult to do. That said, I'd be shocked if Apple let them go that far as to keep spinning out fake businesses but then again if FB thinks it can get away with it what's stopping them?
Good call.
https://seekingalpha.com/news/3427520-apple-banning-facebook...
> Apple says. "Any developer using their enterprise certificates to distribute apps to consumers will have their certificates revoked, which is what we did in this case to protect our users and their data.”
Apple could block all updates to Facebook's apps until Facebook complies with their policies. That would get Facebook's attention in a way that wouldn't alienate Apple's users.
Facebook needs mobile, which means they need Apple more than Apple needs them.
1. Ban all accounts that were publishing this "VPN" (I assume FB didn't use it's main account for any of this, if they did leave that account alone and ban the others)
2. Block updates to FB for some period of time if they try to open new accounts and get caught
3. Delete FB Apps from App Store
4. Delete FB Apps from iOS devices
Is that actually true? Last time I checked iPhone only had a 20% market share. People buy phones, including iPhones, to do stuff with them. What Facebook provides is the stuff a huge part of the users want to do with their phone.
Imagine iPhone users can no longer WhatsApp/FB-messanger with their Android using friends. How many people will think twice before buying an iPhone again? Facebook screws with privacy the users don't care about (yes, the average user doesn't give a shit, especially if he gets paid), while Apple would screw with the users apps, which they care about a lot! Apple is in the disadvantage here. Especially since their whole business model is a better user experience for overpriced hardware.
> Is that actually true? Last time I checked iPhone only had a 20% market share.
But it's a relatively premium market segment that Facebook can't afford to lose. If they cede it, they're taking a serious risk that a serious competitor could emerge on the platform that turns them into the next MySpace. That 20% could pull the rest of the market its way, since whatever they migrate to would likely be available on all platforms.
This isn't a far-fetched idea. It's basically what Facebook did with it's initial rollout exclusively to the Ivy League schools.
> Imagine iPhone users can no longer WhatsApp/FB-messanger with their Android using friends. How many people will think twice before buying an iPhone again?
That might have been true five years ago, but Facebook's products are much less compelling now, for a whole host of reasons. Cross-platform replacements would quickly emerge to fill the niches Facebook was driven out of. Many people would get mad about not having Facebook on their phone, but most of them would get over it. But others are already primed to abandon Facebook, they're just waiting for a push.
> Apple is in the disadvantage here.
No, Facebook is, since their dominance of social netoworking is so tenuous that they need to convince people to use spy-VPNs to stay on top of emerging competitors.
For messaging, one could argue that it already exists: Signal (which has already benefited from FB’s announcement that they collect WhatsApp)
It might actually get ordinary users interested in making it so Apple doesn't have total control of what can be installed on the phones they purchased. They won't see all the philosophy behind it that people in the free software community do, but it would point them in the right direction.
Say, FB wants to get your location, even though FB has location permissions a pop up says "Facebook is attempting to find your location. Do you consent to sending your location to Facbook?" "Facebook is attempting to read the Names, Telephone Numbers and Addresses of everybody in your contact list. Do you consent to this?" every time facebook app makes the request?
I'd be a bad user experience, but Apple could say it cares about privacy and blame facebook.
They could slow walk updates as they do unusually thorough privacy audits, and perhaps even apply extra access restrictions (e.g. skewing location, forbid use of certain permissions, etc).
No iPhone user could use any Facebook apps, anywhere in the world, which would make this story front page on every newspaper. Business could no longer manage their ads spots or use iOS devices for social media. They will likely be shocked at the unwarranted disruption, rightly blame Facebook for it, and cut their spend on ads. Both PR departments would be working full steam on a war of worlds, disrupting all other work. Numerous suits would be filed. Meanwhile, Facebook stock would crash, leading to numerous investor lawsuits, especially since Facebook clearly risked this by blatantly violating contracts. Institutional investors will cut losses and pull out, further driving the price down.
I'd love to see it happen. But Apple doesn't want to, and honestly can't be expected to, pull the nuclear option just as a punishment for this. They would incur massive PR and legal expenses in response.
Why is Josh Constine still covering Facebook at TechCrunch? Is there no accountability for journalists who totally failed us?
For context, he's the guy who was supposed to be covering Facebook over the last 10 years, but instead of hard hitting journalism, we got nothing more than press releases and pro-FB articles.
See for yourself:
https://www.google.com/search?q=Josh+constine+facebook+site:...
If people at this point doubt that traditional media is waging war against Facebook as a means of survival and masquerading as a bastion of privacy as a means to an ends they are willfully delusional. These organizations show much more intrusive ads to me than Facebook. Also they treat Twitter with kid gloves because Twitter is useful for them to gain a following and disseminate their posts. Twitter has also shown me much more politically motivated ads recently than Facebook has.
Why do I do this? Because I enjoy making side hustle money with my phones. This research app in particular is very useful to me because it is 100% passive. If you are concerned with privacy you can always just use a crap side phone to run the app.
(There's a thread about informed consent elsewhere in this discussion. I'd like to understand how informed you are about the risks associated with the app and certificate.)
Can you explain what you mean by this? I wouldn’t like it because I would consider it to be watching me, and I don’t think that’s passive.
I'm merely in the US; I'm not sure what agency would even protect my own friends and family from clear abuse.
In that sense, it shall be treated as if there hasn't been a contract at all. The process is purposefully designed to get a signed contract as fast as possible. The technology to make proper ID (Age) verification is available, but my understanding is, that it is not used by facebook and its partners.
I mixed two points here. Contracts that contradict the law and my wish for better regulations.
Which is complicated both legally and ethically when it's deliberately targeting teens.
If I offered you 10% of my bakery's profits but told you explicitly that you'd have no voice in how I run it, it could be a good deal for both of us and we'd both know what we're getting into.
Seems like a risky game to play, likely staking their appstore developer account at the same time. High stakes.
They seem to have broken the cardinal rule though. Namely the somewhat ambiguous "Don't use your Enterprise account to bypass the App Store."
But I agree, add this to the "unforgivable" pile.
If you mind this, you should be honest with yourself and compare it to all the other deals you're striking with many services.
Now imagine if people were being offered the chance to get some gift cards in exchange for strapping a microphone to their face 24/7, regardless of location. That's analogous to what's happening here.
Anything you do, visit, etc, can be collected. Your bank app traffic, your location data that any app requests, the contents of your data voice calls over non-FB apps, etc.
But I don't see a fundamental difference between strapping a microphone over someone's mouth 24/7, and only strapping the mic on (or, more practically, turning it on) when the user uses certain applications. In both cases you're compensated and in the former we feel violated, and in the latter it's all fair game and business.
I only got paid $31 for a month. Even as a kid, it wasn't worth the effort required due to their constant updates.
The real hidden gems were NetZero and K-Mart's BlueLight. Both were completely free dial-up internet providers, paid for by a banner ad program that was easy to hide with window killers.
Netzero went on to acquire BlueLight and many other free internet providers, and eventually turned into a paid internet service: https://www.mybluelight.com/
My exp exactly.
>The real hidden gems were NetZero and K-Mart's BlueLight.
Yes and Yes! Used both, both were a giant pain but fun to mess around with. Now that I'm thinking about it, I'm not sure why I bothered as our family had dialup (I was probably just bored)
EDIT: I ultimately went with MeWe because it's more user-friendly to non-tech people i.e. most of my relatives.
Don't delete your account. Just delete all your posts and change your profile pic to something that tells everyone you've ditched Facebook. It'll continually remind everyone you've left and make Facebook seem more like a dying community to those who are still on it.
Then finally delete your account once it's as dead as MySpace.
[1] https://theintercept.com/2018/11/29/google-china-censored-se...
Human beings, body parts, privacy, those kind of things.
Obviously it's not the same thing, that was a list, a category of things which are in some way similar. If I include a dog, hippo and human in a list of creatures, would you complain that a human is not a dog?
The issue is, they are selling something which they can never get back for a pittance, and that something can come back and harm them at any point for the rest of their lives.
There is a reason privacy is a human right, its loss can deeply affect the lives of those that forfeit it or have it abused.
Find me five people off the street who can explain the implications of tapping yes to install that root cert.
Privacy is also a human right, as declared in the universal declaration of human rights.
I'll let you put 1 and 1 together.
What is Facebook thinking?? Shouldn’t a company which is already getting bad PR for its handling of private data be extra careful about how much personal data it gathers and what it does with it?
Further, their only major competitor in the ads space is Google, which has access to this information via Android and its control over the Play Store.
Plus, what are the teenagers going to do about it? Facebook also owns Instagram. I guess they could use Snapchat...
Eventually they'll encounter a hero, someone important enough who says "fuck it"
Its just speculation, that they're blackmailing anyone to make things happen, but anyone can see the incentive is there. Hard to imagine blackmail isn't just waiting to happen with that kinda data.
What will get them to stop is likely regulatory oversight.
I mean Facebook does deserve the negative PR it's receiving, don't get me wrong. I finally deleted my account, too, since it's become too much. It does seem to me like it's very much in their interest of the media to keep attacking Facebook now that it's socially acceptable (Cambridge Analytica stuff and all), since Facebook's one of the companies that greatly influenced and interfered with their possibility to generate an income.
As an organization they don't have another way to operate / seem incapable of doing anything else other than this scummy stuff.
They can't stop being what they are or they'd die so they just double down and double down.
This story is full of people making apologias for facebook's shady behaviour.
I just don't get the urge in some people to defend the rich and powerful.
They don't need you to defend them, they are probably 100000x richer than all of us discussing this here put together.
This is an honest question because I can't understand the motivation behind it. If you are one of those people defending facebook, why are you doing it?
How informed should the user be? What qualifies as an informed user?
This is getting into some dangerous territory because it because implies so some sort of contract literacy.
We already have laws forbidding certain types of deceptive contracts.
The average user can't be expected to understand the consequences of installing facebooks 'trusted' root certificate.
Of course, while connected to the VPN you can't connect to anything on the LAN, and I'm not sure how regular users would be able to disable the thing.
And, of course, the problem of Google sniffing everything you do.
The "secure" VPN dialog only comes up for certain WiFi connections that Google has some knowledge about. For example, when I'm in Chick-fil-A I get the "Secure this connection?" dialog, but I never get it at home or work. I've never had a need to disable it to reach local resources, but I'm guessing you could turn off WiFi and turn it back on to rejoin the network and not accept the VPN connection. I've never had the need to do that so I don't know if it would work or not. :/
If a person were to adopt this behavior, we would call them a criminal. Facebook, on similar lines, is a criminal enterprise that hasn't been punished appropriately so far!
But how? I didn't knew this is possible to do on iPhones except really old models. If it is I'd love to know how.
For example, we use them to distribute frictionless test builds internally.
I just wanted it to be clear to others that this is NOT the intended purpose of the Enterprise program.
Similar to SuperUDID, they installed a profile onto their device that provided special privileges for Facebook.
Edit: HN title has changed to remove this part completely.
How was this data stored? Who at Facebook had access to the SSNs and nude photos and the like that was certainly collected with a program like this of any scale? Were the procedures to delete it? How were the systems secured? And while I doubt even FB would do this, a truly lawless bad actor could use those logins without tripping security alerts because you would have used one of their IPs to sign in before. Or an external actor, having access the data dumps, could sign up as a user and then make use of the VPN to easily pawn everyone's account.
The more I think about this, the more outrageous it is. They may as well put cameras in your house and photocopy all your papers.
Elsewhere in the article it mentions people were paid to screenshot their Amazon order history. Why would they do that if they could read all app traffic? My guess, Amazon is smart enough to use certificate pinning and/or not trust root certs
Do they though? Do they really understand what it means? Do they understand that that nude they sent to their GF/BF is now on a FB server and FB has FULL rights to have and use that (obviously not publish it but still)? Do they just not care?
I really don't know, the last question kind of terrifies me TBH. My hope is they don't fully understand what they are giving up and "$20 is $20".
Sounds like AllAdvantage.com (I had to look that up again) all over again. They tracked your internet usage and paid you money for it. My friends and I thought it was a good deal and had no compunctions about gaming it. I’m sure these kids are thinking the same thing, and our moral outrage is self-inflicted.
If you use Facebook they already know more about you than you do.
Might as well take $20 a month.
I’m still waiting for my kickback from the in-message advertising I get in Instagram.
I am very aware of data I share with Facebook. I take measures to prevent them from getting data about me elsewhere.
Giving up close 100% of privacy just because you are currently giving up, say, 20% of privacy seems insane.
It's like saying "let's throw all our plastic in the countryside because some people are littering already".
What about the massive information asymmetry?
How about the power imbalance?
Is it possible for Facebook to have good intentions that lead to positive outcomes, or is everything they touch toxic?
I think maybe we can have more than one opinion simultaneously. I really like some of Facebook’s features, and Apple has some good things going for it. And it’s definitely fair to criticise both for their shortcomings.
Yeah, obviously, kids are very good at understanding the consequences of their actions. I mean, imagine if they didn't! We would need special rules in criminal law for dealing with young offenders or something!
> glitchc: there’s no law broken here. So, how should I feel about this?
But you can interpret it whatever you wish.
Let's not forget that until mid-20th century, adultery was illegal in most states...
He's pointing out that morally repugnant things can be legally compliant.
Yes, and?
Kids (and some adults) frequently send demeaning nude videos of themselves to public web forums (and promptly get harassed IRL). Are they being defrauded? Or just act that way, because they are naive and can't read emotions and body language across the computer monitor? Either way, the incident described in article is a clear children rights violation. Whether parents properly understood and condoned it or were defrauded by Facebook, — does not really matter (I suspect, that if any of them faced a trial, they all would claim the later).
1) Regarding distribution channels, I have only once had the program advertised, via an Instagram ad. I have my real age on Insta (I know, I know...) so targeting younger users may have played a role. I first saw the ad in June 2018, and decided to click through to see how bad it was from a security standpoint. IIRC I never installed it, but I got an email to my throwaway account a few weeks ago asking to reinstall, so I decided to give it a run-through for research. They refer to is as "Research Application," and avoid mentioning FB, their email the first time was facebookresearch@applause.com and it is now sent through a mailer with no mention of FB in email address. The contractor was Applause/uTest, they offered $10/month via PayPal (which <18 technically aren't allowed to have). Since uninstalling, they sent an email saying it hadn't heard from the app in 24-hours and you must participate 23/days month to be paid.
2) The install link is at https://m.facebook.com/facebook-study/f8854f1fb9f4f57bf0d861..., and the IP used by the VPN is vpn-sjc1.v.facebook-program.com / 185.89.216.194. On iOS, the "Connect on Demand" feature is used to render the normal VPN off switch useless, one must uninstall the app or turn off COD on the VPN info page. Outgoing traffic goes through a regular FB IP (I wonder if any IP-based authentication on their systems might be weakened by doing this?).
3) I definitely agree with TechCrunch that this is an Apple ToS issue, however, they are wrong to say that FB "avoided TestFlight." TestFlight is for closed betas only, and this app is not a beta of anything, so it is patently ineligible. Interestingly, if Apple revokes their cert in response (as they due to shell company certs used for sideloading marketplaces), it would result in an immediate shutdown of all Facebook's legit internal apps, because Apple only (afaik) issues one cert to each DUNS number. Notably, the cert says "Facebook, Inc. (In-House)" not just "Facebook Research, Inc." so it looks like the main cert. I've sent a complaint to Apple Privacy about this, will report back if they reply.
3b) Apple's Enterprise Dev Program ToS[1] excludes from allowed internal apps those that are, "used, distributed, or otherwise made available to other companies, contractors (except for contractors who are developing the Internal Use Application for You on a custom basis and therefore need to use or have access to such Application), distributors, vendors, resellers, end-users or members of the general public." It does allow the use of written, binding agreements to enable contractors to use the app, but it seems doubtful that this would extend to those ostensibly participating in social research for a nominal compensation.
4) Most users need to be clearly told that installing a "trusted root" cert is the keys to the kingdom. Providing a normal VPN honestly wouldn't be that bad, as TLS protects everything but the domain name. So they could see "morpheuskafka made 200 requests to reddit.com in an hour," but not the content, much less my login and password. Most people who know what a VPN is are familiar with the idea of their network traffic being rerouted and monitored at the ISP level, but they could easily think they were installing the VPNs server certificate or a client certificate to access it. It's staggering to think that . Also remember that Facebook owns the certs for its own platforms, so they could (ethically) monitor your use of their own services w/out this. Remember "don't even give the IT people your password?" Fill out any login in form and FB has your password (and can use the same IP to sign in without raising suspicion). Job or college app? SSN, tax info, etc. Only e2e is safe. Notable, Caddy's MITM detector cannot detect this "research app."
I hope they do revoke the signing cert, and will enjoy seeing all their internal apps stop working in the chaos. And I hope that Google and other large companies send password change warning to anyone who has logged in from these IPs.
[1] https://download.developer.apple.com/Documentation/License_A... [can sign in with any Apple ID to view]
Sorry for the long post, but this is truly outrageous.
I’m sorry but...it’s not as if they’re using this data to do evil things. They’re trying to target advertisements. Whooptie doo. So evil.
I don't recall the app having any mechanism to filter EU/EEA nationals, so the GDPR shitshow is about to explode in Facebook's face as well.
There are all sorts of things you do with your smartphone and this VPN tracks all of them.
I guess my point is that the concept of being directly paid to give up elements of privacy is a well established concept.
I also think it's extremely patronising to the poor to assume that they don't understand what trade off they are making.
and that should make you uncomfortable too! how on earth can you justify this with an equally insane analogue?
I agree with the previous user that it isn't that different than what Nielsen does to collect TV ratings.
Maybe Facebook's execution here wasn't the best, i.e., I agree that a better device would have some limitations as to what kind of data it could access.
Why is, "I don't really care" not enough of a justification for you that I don't mind putting a GPS tracker on my car?
Car insurance. Scope limited to car's location tracking.
This is Facebook, getting access to all of one's online (PKI-based TLS) traffic. Not just mail, banking, etc. All.
Calling this wide scope "elements of privacy" is a bit disingenuous in this day and age.
You can play with them using mitmproxy to generate a Cert and intercept SSL traffic.
Fortunately, the title has been edited now to remove "root access".
I fail to see how this is supposed to make it in any way worse.
This isn’t a bunch of adults deciding to sell their privacy. It’s children who have no hope of understanding what they’re doing.
Adults might have fully developed brains from a biology perspective, and I recognise this is what you meant, but I believe there is a strong argument to be made that many adults, myself included, are heavily lacking in the development of mind department. Mark Zuckerberg surely is, either that or he’s actually Satan.
I definitely have an undeveloped appreciation of the consequences of my actions, and I’m easily manipulated. I’m rapidly approaching 40 laps around the sun!
My greater point here is that I don’t find your argument for why it’s worse because children particularly compelling. Or, perhaps, insufficient. So I’ll replace with my own:
Society at large has a long history of, and a cultural and biological evolutionary adaptation, to protect children more strongly than adults, because we are born vulnerable and take a long time to reach sexual reproductive age. We’ve only made it this far because we’re not descended from parents who let their kids stumble in to sabretooth tiger territory. (As an aside, I appreciate that the greatest threat to children’s health and development is their immediate family. But here we are).
The worrying thing is, now the sabretooth tiger is a guy who’s surname translates from the mother tongue, German, to English as candy mountain, Google translate actually says “pile of sugar”, and comes with a family friendly large blue thumbs up symbol. So the threat is difficult to discern.
I’d actually be more worried if I didn’t have a seizure like laughing fit every time I think about the whole scenario. It’s a coping mechanism I guess.
I mean, is this really happening? I wish Bill Hicks was still alive! Aaah, he lives on through those who carry the flame!
But on a more serious note, children don't necessarily understand the consequence of their actions, especially at a technical level. Mind you, plenty of adults don't either, but their acceptance of the terms of conditions of something or other is contingent on their being responsible enough to accept any negative consequences that may come; children are not in that position.
That's why they aren't allowed to gamble among a multitude of other things that their developing brains can't handle.
A culture that doesn’t have a strong child-protective drive, and a strong drive toward kindness and treading lightly, is likely to disintegrate and eventually destroy the each other and the world.
As evidence I present: the current state of affairs!