It wouldn't stop them seeing what domains the user is going to (as it's sent in plaintext because of SNI, and ECH was still a few years away).
Reminds me of TV users willingly plugging a box into their TV that sends usage data to a statistics institute
I don’t think users knew what they were consenting to. Only a small percentage of the population know what a Certificate Authority is. And also “monitoring traffic” doesn’t carry the weight of “we are going to listen to your private conversations”.
In the same way a patient might willingly consent to some highly specific chemical treatment being replaced with another highly specific chemical - they have no idea, they rely on the doctor not to purposefully mislead them. You could put anything in those forms and most people would trust the professional is at least not allowed to defraud them.
Or maybe it's a weak, uninteresting form of social engineering, but even that's a stretch IMO
If Onavo did install a certificate and MITM the connections and send private user data to Meta... that's beyond the pale. That's far more worthy of a cover story than Bloomberg's debunked secretive tiny chips story from a few years ago. It's equally as bad if not worse.
Hopefully the technical details will come out.
> In 2016, Facebook launched a secret project designed to intercept and decrypt the network traffic between people using Snapchat’s app and its servers.
I read the rest of the article as well, and saw only confirmation:
> Given that Snapchat encrypted the traffic between the app and its servers, this network analysis technique was not going to be effective. This is why Facebook engineers proposed using Onavo, which when activated had the advantage of reading all of the device’s network traffic before it got encrypted and sent over the internet.
Where do you see the ambiguity? Other than the weasel words about proposing these programs (versus actually running them), it seems clear that they were decrypting the traffic (or reading it before it was encrypted). Did I miss a piece?
This doesn't make sense, they wouldn't see the traffic before it was encrypted. They would see it encrypted, but using the MITM certificate instead of Snapchat's. Given the inaccuracies in the article, it makes me wonder what else they got wrong.
Using a VPN client to monitor how much, when, and where traffic is going is bad, but MITM'ing a user's connection is much, much worse. I'm really skeptical that's what happened, especially given TC's inability to articulate accurately what Facebook did.
That's the former type of collection I was talking about. There's no evidence I can find that they installed a root CA certificate and were MITM'ing connections. That's a major accusation and one that is not accurate as far as I can tell.
Apple banned the app because it was inspecting underlying traffic not installing a fake root certificate: https://techcrunch.com/2019/01/30/apple-bans-facebook-vpn/
The language in the lawsuit complaint is explicit that FB installed a root cert to MITM and decrypt traffic:
Seems pretty clear that they could decrypt the traffic they were interested in, they also talk about 5 years of retention of all traffic that they can decrypt at anytime. Sound familiar?
Looks like they used a squid feature: https://wiki.squid-cache.org/Features/SslBump