Facebook: We install a root CA on the device and MitM all SSL traffic
documentcloud.org
documentcloud.org
> ..This code, which included a client-side “kit” that installed a “root” certificate on Snapchat users’ (and later, YouTube and Amazon users’) mobile devices, see PX 414 at 6, PX 26 (PALM-011683732) (“we install a root CA on the device and MITM all SSL traffic”), also included custom server-side code based on “squid” (an open-source web proxy) through which Facebook’s servers created fake digital certificates to impersonate trusted Snapchat, YouTube, and Amazon analytics servers to redirect and decrypt secure traffic from those apps for Facebook’s strategic analysis.
Here's a link to the PDF document: https://s3.documentcloud.org/documents/24514262/discovery-br...
I mean, this is literally every big company IT department.
The best argument I could see that would lead to this succeeding is if someone at Facebook accepted the Snapchat ToS and it said "you can't use MITM to intercept our traffic". Otherwise, fair game, done billions of times a day. (Pin your certs friends.)
The arguable legal gray area is: If a user gives unlimited permission to do so, is decrypting another company's network traffic on device legal? I fall on the side of the fence that it's okay with consent because not even that other company has unlimited and exclusive ownership of a user's data or network packets preflight on their own device.
Btw at Meta/Facebook, even the data about employee devices has privacy filters on collected analytics because location, IP address, MAC address, serial number could be used maliciously by a rogue employee targeting other individual employees if there weren't protections (like Twitter was). Instead, almost all data at Meta is uniformly stored with hard privacy ACLs that, by default, prevent casual exploration. In other words, if I worked at Facebook and knew your Facebook accounts' graph FBID, I would be presented with minimal-to-no information about it and a "make a request for access for business use" dialog that is rarely granted by an appropriate manager or senior trusted person except for actual business needs. Even browsing my own Facebook account by FBID in the graph, I couldn't see all of the details, just a bunch of uninteresting housekeeping and general details. In general, they took at-rest storage of personal information seriously.
These are also the same methods that companies use to spy on their employees. There is a vast number of firewalls that do this automatically. Companies absolutely have the ability to deploy trusted certs on every device that is within their control. This includes when people link their personal device to their company's email portal and it requests all those permissions to control your phone.
I have no love for Facebook but it seems they were being more upfront about what was going on then your average corporation does with their employees.
Google runs their own app check study that you can be a part of. When part of this program you will install an app on your phone that takes screenshots of what you're looking at on your phone and send it to Google. You are paid for this. Google even sends you a pixel phone to do this on and request that you use it as your normal phone. And while it does attempt to not take screenshots of some apps that are considered private it absolutely will grab those screenshots on accident at times.
https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3...
15 years in, Zuckerberg is still a gross liability when asked to give sworn testimony under questioning by a competent professional. It is a disaster for Facebook waiting to happen.
https://ia802908.us.archive.org/29/items/gov.uscourts.cand.3...
HN comments are ignoring the elements of a wiretapping claim. No injury or damage, no "harm", is required in order to be convicted.
https://www.law.cornell.edu/uscode/text/18/2511
That someone may have paid to use an app, or otherwise voluntarily used an app, or that other companies may engage in similar practices does not provide an exception to the federal crime of wiretappping; it does not absolve Facebook of culpability. If the target of the wiretap consented to be surveilled, then one would think the plaintiffs attorneys would be aware of this fact. This document alleges there is no exception that Facebook can rely on.
When Google has been accused of wiretapping, and this has happened multiple times, it has always settled the claims rather than defend itself against them. It is being sued yet again for wiretaping at this very moment.
"239. Indeed, the amount of surveillance was jaw-dropping. Facebooks Onavo Protect app reported on users activities whether their screens were on or off; whether they used WiFi or cellular data; and even when the VPN was turned off. There was simply no rational relationship between the data collected and the purported purpose of the application. Put simply, a VPN that collected data even when the VPN was off was an obvious subterfuge for blatant spying on user behavior.
240. Undeterred, Facebook repackaged its Onavo spyware as a Facebook Research VPN app. Facebook sidestepped the App Store by rewarding teenagers and adults when they downloaded the Research app and gave it rootsuperuseraccess to network traffic on their mobile devices. Facebook has been leveraging its Onavo code in similar ways since at least 2016, administering the program under the codename Project Atlasa name suited to its goal of surveilling app usage on mobile devices in real time.
241. When the news broke in January 2019 that Facebooks Research apps were repackaged Onavo apps designed to spy on users, Facebook immediately withdrew the programs from the Apple App store."
When I was young and almost a teenager we had a different set of social diseases that we worried about. Those were the days, my friend.
It was revealed that these crashes were due to these apps loading in a JavaScript file from Facebook.
Everyone thought I was crazy when I canceled Spotify later that week and stopped using every single affected app moving forward, because I don't trust Facebook.
They have their tendril in everything
More discussion: https://news.ycombinator.com/item?id=39832952
Even if in all cases a user selected to allow Facebook/Meta to see what they were communicating, which from reading all of the attached documents I don't believe was the case, I don't see how Amazon gave consent.
If some individual had done what Facebook/Meta did, I can't see a situation where Amazon wouldn't have asked for criminal prosecution.
Mastercard and Visa? It would be surprising to see how they would just shrug this off; maybe this hasn't hit their radar yet.
See also: https://stratechery.com/2024/apple-and-the-monopoly-question...
> asking for “out of the box thinking” on a task that “is really important.”
> we are going to figure out a plan for a lockdown effort during June to bring a step change to our Snapchat visibility. This is an opportunity for our team to shine.”
Edit: they paid people to do it: https://techcrunch.com/2019/01/29/facebook-project-atlas/
http://web.archive.org/web/20240329040246/https://www.docume...
Yes, but Facebook is a trusted entity, not like Achmed. /s