Sure enough all the API requests for data were coming through, but whenever a request for image happened - nothing would hit the servers.
What the heck I thought to myself?
I said to the client 'that can't be, that's almost impossible....the only way that's possible is if the SSL traffic is decrypted, inspected, and images blocked from being requested, which, is a MITM attack".
He redirected me to his IT provider. I phoned them up, and explained the situation.
"Ahh so they're _____"
Me: "So what does that have to do with the price of fish?"
Them : "Content filtering..., you need to talk to ____"
Sure as the day is long, the content filter was a VPN all members of ____ had to have on their mobile devices (I don't know how widespread this is, whether it was just this business, or the entire ____ )
I applied to have our system approved, it was, and just like magic the next day photos started coming through.
I'm guessing basically it detected any .jpg/.mp4 etc URL's in https requests and flagged it up and blocked them from being requested. You can be sure on those devices the VPN would have been somehow locked in with device management, and there's no way on gods green earth they were getting at Facebook/insta etc.
So, it's not just meta. That really hammered home how seamless it can be to end users that they really can't trust what's actually happening on their devices.
It also sounds like their issue was at the ISP provider level, as well, which takes the business out of the loop of being the data controller/owner (of the collected data) at that point.
Note: I'm not saying that your comment doesn't have merit, I just don't think that the points that you made apply - specifically - in this case?
So, member of the church? you get this VPN on your phone, (not sure whether phone was supplied by the church, but certainly this VPN was on it) VPN is effectively content filtering and blocking content.
I had our app whitelisted by that central company (literally raised a ticket with them, next day magically fixed).
It certainly seemed for all intents and purposes if you were a member of _____ group (wider than the company) you had the vpn on your device, and it was filtering content. I've found other reports in other countries of that happening with the same group.
So it's not corporate content filtering, it's personal content filtering and our app got caught up in it (and approved).
It certainly made my skin crawl for anyone in that religion. That means the central filtering service could be reading messages. Not sure if they're that sophisticated but certainly they didn't want people to see random images/videos.
You could imagine a standard for a network to signal to a client that it does not allow certain privacy features like ECH, and then clients can accept that or not. Instead I expect browsers will eventually mandate ECH, so people will have to MITM instead.
Sorry I meant the optimize the content for their peers and shield them from harmful content for the better of humanity // irony
Onavo provided a compression + VPN service for people traveling; they let users use little or no data while roaming, and still get internet access. I do not know what their original business plan was, but Facebook bought them for the ability to spy on users.
Their MITM was, in fact, the raison d’etre of Onavo. And then, they were bought by Facebook. And then there was just some more analytics added. At no point, as I understand it, was it built explicitly for evil - and I suspect very few employees were in on the real reasons.
Plausible deniability works for many things.
We seem to be able to manage this with bridges, planes, electrical & hydro installations etc. No reason it shouldn't be the same for critical software infrastructure.
Why do you think Meta's work is critical software infrastructure?
I am happy to answer any questions you have about questioning or ethics at the time. Assuming that people's reaction to this was wrong, while not knowing what that reaction was, or having less than 5% of the context, isn’t going to help much.
Short answer: No, there were strong arguments for it. I reached out for institutional support to answer some questions, groups that I expected to be a lot more supportive than the ACM, but I found the reaction seriously lacking. Your intuition that groups like the ACM should offer assistance is sensible but completely overlooks many problems: geopolitics, different types of security, and individual capacities, among others. Each institution has its priorities; those are not always compatible, and it’s unclear who should have precedence. The ACM won’t help you if the argument is the kind of compromise with the devil that spy agencies often make or if problematic tools are used in efforts to dismantle large criminal groups.
I don't think you understand how Onavo works.
Why do you trust it ? Do you think that others (Google, Microsoft, Apple) are not doing/would not do such a thing ? SSL is as secure as its certificates.
In Microsoft, Google, and Apple's cases, they all have substantial enterprise business that would shit a brick if they were caught doing this.
Ergo, it's not in their best interest to do it.
Safer to rely on a company's desire to make money than any sense of "good".
1. Nobody will care in 10 days. 2. They will get a slap on the wrist at best.
Reminds me of Google driving around in StreetView cars, hacking and capturing all wifi traffic they could get their hands on. Did anything happen? Of course not!
https://www.theguardian.com/technology/2010/may/15/google-ad... https://www.wired.com/2012/05/google-wifi-fcc-investigation/
The guardian says "open" networks, apart from the fact that in 2010 networks were not secured by default in many cases. I think WEP 1 was a thing and easily hacked, and I would not be surprised if they were actually Wardriving, on the largest scale ever.
Remind me when anything more than a slap in the wrist happens. And my definition of slap on the wrist is adjusted to how big Meta actually is, they make more than some countries!
You just hate facts, just like the idiots on Reddit, I am supposed to praise big tech criminals and just make positive stuff up, then I get all the upvotes.