Facebook Accused of Using Your Phone to Wiretap Snapchat
gizmodo.com
gizmodo.com
When are we going to start holding CEOs (and shareholders!) accountable for this behaviour. The guy is worth $173bn and can seemingly abuse whatever laws he wants behind the corporate veil to further increase his fortune.
It seems cartoonish given the scope alone: "A team of senior executives and roughly 41 lawyers worked on Project Ghostbusters,"
Yep the CEO of one of the most top-down structured companies in the world with sole decision making power doesn't know what his senior executives and lawyers are doing. Either way even if he didn't know I also don't understand why responsibility and leadership seemingly don't go hand in hand in the corporate world. Imagine a military leader lost a battalion and went with "Well I don't know they ran off in that direction..."
Although this is incredibly shady, it’s nothing different to companies paying analytics companies which partner with VPN and adware companies to provide the same data. The only difference is Facebook owned the process end-to-end and didn’t mitigate the reputational risk associated with the collection.
Which is surprising.
Nobody in the Risk department considered this. Perhaps because it was too secretive, and didn’t ultimately go through enough hoops to get that level of review.
Understatement, to put it kindly.
Likely taking advantage of EULA-burnout, most users likely just agreed and installed on good faith.
Yes, caveat emptor and all that, but unethical (if still legal).
You can read the full complaint here. It is full of juicy details, including Mark Zuckerberg directly suggesting 'figuring out a way' to access Snapchat's encrypted traffic, and how Meta installed a root certificate onto user devices to snoop.
https://storage.courtlistener.com/recap/gov.uscourts.cand.36...
Direct quote from Meta employee based on the complaint: "we install a root CA on the device and MITM all SSL traffic"
I'm surprised it took 7 years and a lawsuit for this to be confirmed. I remember there were reports of "facebook-affiliated VPN app that might be spying on users" a few years ago, but I don't think the fact that they were MITMing user traffic was confirmed. Sure enough, I went back and skimmed the news stories[1] from back then and there were no mentions of root certificates or MITM. Given how many scary prompts you have to go through to install a root certificate, I'm surprised nobody got suspicious and posted screenshots to the public.
[1] https://gizmodo.com/do-not-i-repeat-do-not-download-onavo-fa..., https://www.extremetech.com/internet/263867-facebooks-new-on..., https://techcrunch.com/2018/02/12/facebook-starts-pushing-it...
Unfortunately, the EU attacking Apple’s ability is do things like this in the future will harm consumers.
A world of anybody being able to have their own App Store is one where a massive company like Facebook bullies their users into using their App Store, and trading their privacy for access to the largest social network on the planet.
You’d rather have a large company strictly force all users into their App Store instead of having any choice because you believe that another large company will “bully” users unless they use a different store?
Has something like this happened on android?
Still seems like choice is better here.
Yes. This happened both on on iOS and android.
From TFA:
Thus, Project Ghostbusters was born. It’s Meta’s in-house wiretapping tool to spy on data analytics from Snapchat starting in 2016, later used on YouTube and Amazon. This involved creating “kits” that can be installed on iOS and Android devices, to intercept traffic for certain apps, according to the filings.I'm not sure what to believe. I am personally going to have to do more research before coming to conclusions on this, as my ability to trust Gizmodo (especially on the subject of social media) has been compromised by that incident.
Meta may wish it was no longer newsworthy, but being reported on and being prosecuted for an issue are very different things.
"The researchers [at NYU's Ad Observatory] gathered data by creating a browser extension that was programmed to evade our detection systems and scrape data such as usernames, ads, links to user profiles and “Why am I seeing this ad?” information, some of which is not publicly-viewable on Facebook. The extension also collected data about Facebook users who did not install it or consent to the collection. The researchers had previously archived this information in a now offline, publicly-available database. "
> Thus, Project Ghostbusters was born. It’s Meta’s in-house wiretapping tool to spy on data analytics from Snapchat starting in 2016, later used on YouTube and Amazon. This involved creating “kits” that can be installed on iOS and Android devices, to intercept traffic for certain apps, according to the filings. This was described as a “man-in-the-middle” approach to get data on Facebook’s rivals, but users of Onavo were the “men in the middle.”