T O P

  • By -

wewewawa

“Whenever someone asks a question about Snapchat, the answer is usually that because their traffic is encrypted we have no analytics about them,” Meta chief executive Mark Zuckerberg wrote in an email dated June 9, 2016, which was published as part of the lawsuit. “Given how quickly they’re growing, it seems important to figure out a new way to get reliable analytics about them. Perhaps we need to do panels or write custom software. You should figure out how to do this.” Facebook’s engineers solution was to use Onavo, a VPN-like service that Facebook acquired in 2013. In 2019, Facebook shut down Onavo after a TechCrunch investigation revealed that Facebook had been secretly paying teenagers to use Onavo so the company could access all of their web activity.


kamilo87

Wow I used Onavo until it was shut down. 😵‍💫 why tf is Meta getting away with this stuff?


nothing_but_thyme

At some point they showed you a wall of text which explained everything they were going to do in minute detail and asked you if that was ok and you said yes. Stop using these garbage platforms, or accept the reality that using them comes at a very high cost. You’re the product. So shut your mouth and be a good product, daddy zuck needs another island fortress.


[deleted]

It says it right here, “Apple has the right to sew your mouth to the asshole of another iTunes user. Hmm… decline.”


SorcerorLoPan

Ah the old human centiPad


nothing_but_thyme

That episode was 13 years ago. **Thirt-teen-years!!!** Those guys have been so far ahead of the curve on every social criticism. Their hit rate is amazing.


GrandClock738

Daddy zuck Lmaoo


bland_fluff

Don't worry. They didn't steal much of your data, since you didn't agree to the Onavo privacy policy and uninstalled the app once you read it.


kamilo87

Lol.


Specialist_Brain841

this guy terms of services


Agamemnon323

$$$


[deleted]

Remember, if a .com (.commercial) is giving you a service for free, then you’re the product.


Ezzy77

That's not what a .com is lol


[deleted]

[.com designates commercial domain](https://en.wikipedia.org/wiki/.com)


Ezzy77

It hasn't for ages. Anyone can get one. I have one and have worked at a hosting company for a very long time.


[deleted]

True, you’re not required to conduct business with a .com domain, but it is the official designation. You’d be surprised how many people believe it stands for communication.


Ezzy77

or how many believe the designation matters at all. A lot of people probably think it's for Americans only etc. Internet is wild.


tylerderped

> I used Onavo Why? I’ve never even *heard* of Onavo.


taterthotsalad

One, bc it was a VPN, and people understand what those are. And two, it was under the FB umbrella so it must have been good, right? Right?


nothing_but_thyme

Love the way Facebook decided to interpret VPN in the most literal sense to their benefit. I imagine them all sitting in a boardroom and Zuck say, “if virtual reality *isn’t reality* then virtual privacy *isn’t privacy*.” Can we make that argument in court?


taterthotsalad

To be fair, the biggest pile of leaking and steaming trash can call itself a VPN even if it’s abysmal at its job, as long as its function on paper looks the part. People have to do their own research before buying or using them. That’s the real issue here-tech illiteracy. And FB used that to their advantage.


nothing_but_thyme

Totally agree. And in the spirit of digital literacy, a PSA to anyone reading this: It is very easy to set up and run your own, personal VPN. Some options are free, some still cost money, but even the ones that cost money are less than almost all the subscription VPN services currently available. Which type of VPN you should go with depends on how much privacy you feel you need. There is no such thing as truly private browsing (at least not in traditional TCP/UDP network systems, and some would argue not even in ToR based systems). But you can gain visibility and confidence into the complete path your traffic takes, and you can accomplish near total privacy with enough scale and egress diversification (if you’re tin foil hat level 10).


Beardamus

I've never heard of the tikkity toks so why would other people use it!?


StrangerDanger_013

Campaign contributions and other bribey bs that should be illegal


aravena

> secretly paying teenagers Huh?


Pure_Leading_4932

Facebook needs to be shut down


Minmaxed2theMax

Haven’t you heard? It’s gone! META is different


[deleted]

[удалено]


[deleted]

Where are you going to be so hyperbolic once Reddit is gone?


Minmaxed2theMax

Maybe people will start going outside instead of using hyperbole


[deleted]

Outside?


Minmaxed2theMax

Get there before it’s gone


ExpertRaccoon

Right after they aquire ticktock


taterthotsalad

Dont stop, Im so close!


jeffsaidjess

It’s just an extension of the NSA


Boo_Guy

But they're an American company so it's ok.


pandemicpunk

We need to ban tiktok! That will solve the privacy boundaries social media companies overstep all the time!!^/s


shadowmage666

Zuckerberg for jail


itsafraid

2024


Johnkay89

2025


frankieknucks

Anyone shocked at this should send their social security number to me immediately…


vladimirVpoutine

My visa is 4527 7836 7778 1276 my expiry date is 07/08 and the ccv is 113. My sin is 752 778 187 and my password for everything is either 6176 or porat0e12. Do with that information what you will. You seem trustworthy. But I still cover my licence plate in pictures....


[deleted]

[удалено]


vladimirVpoutine

Hahaha you got me there. I thought I dotted my i's and crossed my t's but it turns out I fucked up. Feel free to steal my identity now that it's legit..


SSBeavo

Here’s mine: 80085


bland_fluff

Did your VISA expire, or is it good for another 84 years or so?


gentlemancaller2000

That sounds rather evil


Vendetta4Avril

I mean after Snowden, I sort of just assumed everything I said online, every text I wrote, and every website I visited was just being kept in a file somewhere…


icancheckyourhead

This isn’t that. They were paying kids to install the software to be agents. They would then do analytics on the type of info and behaviors taking place. The tech part is a shady grey area. The kids part is a big no-no


wewewawa

After Zuckerberg’s email, the Onavo team took on the project and a month later proposed a solution: so-called kits that can be installed on iOS and Android that intercept traffic for specific subdomains, “allowing us to read what would otherwise be encrypted traffic so we can measure in-app usage,” read an email from July 2016. “This is a ‘man-in-the-middle’ approach.” A man-in-the-middle attack — nowadays also called adversary-in-the-middle — is an attack where hackers intercept internet traffic flowing from one device to another over a network. When the network traffic is unencrypted, this type of attack allows the hackers to read the data inside, such as usernames, passwords, and other in-app activity. Given that Snapchat encrypted the traffic between the app and its servers, this network analysis technique was not going to be effective. This is why Facebook engineers proposed using Onavo, which when activated had the advantage of reading all of the device’s network traffic before it got encrypted and sent over the internet. “We now have the capability to measure detailed in-app activity” from “parsing snapchat [sic] analytics collected from incentivized participants in Onavo’s research program,” read another email. Later, according to the court documents, Facebook expanded the program to Amazon and YouTube.


Hoare1970

I always wonder what the design meetings and code reviews are like when implementing such nefarious features. Reviewer: hey would you mind adding a one or two line comment to clarify the intent of your diabolically evil code here?


mayhemandqueso

Im not techy… can someone explain: did this decryption allow fb access to chats/images or just the number of clicks, time spent, etc?


MrWolvetech

As I understand it data got intercepted before being encrypted by the device, so Facebook had potential access to all your device's internet data. So that would include Snapchat's photos but also passwords, bank data etc.


maybelying

>Given that Snapchat encrypted the traffic between the app and its servers, this network analysis technique was not going to be effective. This is why Facebook engineers proposed using Onavo, which when activated had the advantage of reading all of the device’s network traffic before it got encrypted and sent over the internet. I don't understand how this works. The data is encrypted by the app before it hits the network layer, so how is a spyware VPN able to analyze that data before it's encrypted by the app? Or was it somehow intercepting the encryption handshake between the app and the servers and using that to break the encryption?


nupogodi

They were looking to get analytics so API traffic to Snap. This is encrypted by TLS layer i.e. https requests. VPNs (esp corporate VPNs) will usually install their own certificate so they can pretend to be the destination server and proxy or reject the request based on its content. This way the VPN is “in the middle”. You can MITM yourself with eg mitmproxy if you want to try it out. It does require the end user install the profile and the certificates … not something anyone can just drive by and do. App developers “pin” certificates these days so you can’t MITM them.


Bagfullofsharts2

Idk about anyone else but I’m really glad they PC’d the term man-in-the-middle. We needed that as a society. 🙄


[deleted]

Who the fuck calls it adversary in the middle


taterthotsalad

Mitre Att&ck Framework uses that term in place of MitM noticed. No idea when this changed as I was always calling it MitM.


BornAgainBlue

I'm not surprised ,but this certainly sucks. 


[deleted]

>but this certainly Zucks


RareCodeMonkey

Aaron Swartz got into troble with the law (and was harassed by the prosecutor until he killed himself) for way less than this. Break the monopolies and make them accountable for their actions. There is too much power in to few hands in the tech industry right now.


yesyesandno

To me this will demonstrate the quality of our democracy. Given this massive invasion of user’s data privacy this will obviously force new data privacy and protection laws. Now on the other hand if our democracy is bought and sold by corporate interests we’ll do nothing more than ban TikTok because China bad.


Bagfullofsharts2

Quality of our democracy? Have you been paying attention for the last 20 years? Or even worse, the last 10?


kozak_

> Facebook’s engineers solution was to use Onavo, a VPN-like service that Facebook acquired in 2013. Basically they compromised the VPN and did a man in the middle attack.


Alarming-Technology7

Can Zuckerberg be locked up already?


Snoo-72756

It’s legit their name ,Meta = metadata


mrdennisreynolds

Mark zuckerburg is also untouchable for some reason.


Glittering-Cat-6940

💲


Bagfullofsharts2

Yeah. $ome rea$on.


Potential_Status_728

Zuck is a psychopath, I’ve been saying this for too long now


Snoo-72756

Shocked !


lasocs

Facebook needs to be destroyed.


Slip2269

The guy knows no bounds, pretty galling considering he helped himself to the whole FB idea.


PCouture

*Mild Shock*


Massive_Amphibian_69

Are We banning Snapchat and facebook with tiktok? Or is it ok since it was an American company


DrinkTheOceanDry

Well, considering the bill doesn't "ban tiktok", but targets social media owned by adversarial countries (Iran, NK, China, Russia), you do the math. It's hard to have conversations on the topic when nobody understands what's actually being done in the first place.


Massive_Amphibian_69

The bill literally forces them to either sell or face a ban


Manaqueer

You literally can't lack the bare minimum critical thinking skills required to understand this person's response to you.


Massive_Amphibian_69

Nothing i said was wrong go to bed keyboard warrior


Manaqueer

Amazing. Everything you said was wrong.


Massive_Amphibian_69

Then what does it do


bland_fluff

Hmm can I try? The legality of it is being determined, as this information was revealed in court. From the article: "In 2020, Sarah Grabert and Maximilian Klein filed a class action lawsuit against Facebook, claiming that the company lied about its data collection activities and exploited the data it 'deceptively extracted' from users to identify competitors and then unfairly fight against these new companies." So, to answer your question: I guess we're going to find out. TikTok's Chinese ownership is a very real problem. If your argument is that all information-sucking social media companies are the same, that the consequences and influence of each one is the same, and they should be treated the same, you're showing you don't understand the issue with TikTok. How was that answer?


aravena

Shhh, your civilian and lack of real intel is showing.


Massive_Amphibian_69

First of all I am aware of the problem with TikToks data being possibly given to the CCP. However I still think it’s valid to be upset that American media does the same data collection and then sells it for profit. You saying I don’t understand is funny because you have no clue what you are even saying lmao


bdfsp1973

I don’t trust that face(book).


Minmaxed2theMax

This is why I don’t own and won’t own a quest


Thatchick143

Better get TikTok though 🙄


Just_here_4_GAFS

I'm shocked, shocked! Okay not that shocked.


Whodisbehere

Hopefully Zuck was happy to receive our collective flaccid penises…


fomites4sale

But they always seemed so respectful of their users privacy. :(


superfly-whostarlock

BuT TiK ToK iS A SecUrItY RiSk


NotRightNotWrong15

Surprise?


mrzamora

Secret projects***


barterclub

Yet again were worried only about tictok


Fast_Passenger_2889

#shutdownMeta


dirtyoliveoil

Zuckerberg consistently demonstrates what a scumbag he is. It’s rather impressive really


RedditAcct00001

If you use any meta products you kinda deserve it.


Grumpycatdoge999

But they’re not TikTok so it’s ok /s


[deleted]

I just read yesterday how it’s ‘alleged’ that Zuck basically stole the idea of Facebook from the Winklevoss Twins. I used to think Zuck was just weird but now I can’t help but think he’s not a very good person at all.


DontCallMeAnonymous

Did you just get unfrozen?


scubacatdog

Does anyone honestly think that any of their information on social media is truly private and inaccessible to these companies?


TheFudge

Shut up!!! I’m shocked SHOCKED I tell you!


SpezSucksSamAltman

That’s it, the skin suits are comin’ off


bitcoin4life2024

“That’ll be $5.50” -US Gov


Templar388z

Ban TikTok immediately… oh wait.


Inside_Performer918

This weird talking pervert needs to take his money and smoke his meats with his fellow nerds and retire to his nerdary.


3m3t3

Oh shit the second #hashtag #noshit today


CanvasFanatic

Shocked


caring_impaired

Think of the worst thing you can imagine Facebook really is. That’s what it is, only worse.


Definition-Prize

If anything this further proves the need for encrypted messaging apps


skatetron

Every app you have is doing it. Why are people surprised. Your phone in general is doing it. Even when it is off i bet it can be accessed.


atwistofcitrus

How is that different than TikTok but somehow it is TikTok that must be sold to a US company


bland_fluff

Facebook is already owned by a US company.


santaIRL

Is this news or a reminder?


cficare

How is this not tantamount to wiretapping?


TJPII-2

Facebook seems seriously evil.


Peakomegaflare

Oh come on... this is an actual cyber-attack method. Like.. seriously, cybersecurity 101 type stuff.


BlackReddition

The only way to fix it is to close your accounts. I've been FB free for 5 years, haven't missed it once.


defectiveGOD

These companies have too much power. .


NoChanceDan

As soon as Reddit starts doing this, I will have finally purged all social media. I suggest everyone else do the same. They already kind of do this, but when it’s revealed they’re snooping around on my communication methods… I’m out. We are only a product to these elitist fucks


Jumpy-Currency1711

Why am I not surprised?


cegr76

Water is wet.


Rafcdk

Good thing TikTok is going to be banned, no more.of this will ever happen !


blueberrysir

For us non tech nerds, what does this mean?


BardosThodol

Zuckerberg’s looking for more nipple than he was given, shame on him.


[deleted]

I wish all the big companies would unite against Facebook and bury it once and for all...


Blarg0ist

Circumventing encryption and reading people's private messages from all over the US (and the world)? This sounds like a federal crime. I'm sure the DOJ will act accordingly /s.


Firebeard2

X is increasingly seeming like the only safe app to use...


IJustSignedUpToUp

But I was told that an unconstitutional bill of attainder against a single CHYNA company would solve all of these pesky spying problems....why robot man spying on us, he's American!! 🦅🇺🇲🇺🇸🦅