> “The fairly technical sounding ‘install our Root Certificate’ step is appalling,” Strafach tells us. “This hands Facebook continuous access to the most sensitive data about you, and most users are going to be unable to reasonably consent to this regardless of any agreement they sign, because there is no good way to articulate just how much power is handed to Facebook when you do this.”
So for the reported use case, "hey, tiktok looks good, let's find out how many people use it before we buy it out," it would seem that non-MITM would be plenty (and technically easier/lower resource to do, VPN could be kept on device and the pre-anonymized data sent up to the cloud, saving them server costs and bandwidth.
Compensating people for information on their behaviour is nothing new. If you participate in a program to report daily purchases you probably give away as many information and yet it's not viewed as controversial. The fact that Facebook doesn't have a great track record is problematic but generally, I don't see a big issue.
However, I _would_ contend with the assertion that "there is no good way to articulate just how much power is handed to Facebook when you do this." Sure there is—just not one that would look good for Facebook.
This is bad juju.