Meta tried to gain a competitive advantage over its competitors, including Snapchat and later Amazon and YouTube, by analyzing the network traffic of how its users were interacting with Meta’s competitors. Given these apps’ use of encryption, Facebook needed to develop special technology to get around it.

Facebook’s engineers solution was to use Onavo, a VPN-like service that Facebook acquired in 2013. In 2019, Facebook shut down Onavo after a TechCrunch investigation revealed that Facebook had been secretly paying teenagers to use Onavo so the company could access all of their web activity.

After Zuckerberg’s email, the Onavo team took on the project and a month later proposed a solution: so-called kits that can be installed on iOS and Android that intercept traffic for specific subdomains, “allowing us to read what would otherwise be encrypted traffic so we can measure in-app usage,” read an email from July 2016. “This is a ‘man-in-the-middle’ approach.”

A man-in-the-middle attack — nowadays also called adversary-in-the-middle — is an attack where hackers intercept internet traffic flowing from one device to another over a network. When the network traffic is unencrypted, this type of attack allows the hackers to read the data inside, such as usernames, passwords, and other in-app activity.

  • @BurningnnTree
    link
    English
    18
    edit-2
    3 months ago

    I must be way out of the loop, cuz I had no idea this was possible. So does this mean the Facebook app on my phone has permission to view all of my network traffic? Why do Android and iOS allow this? Shouldn’t that be a special permission that can only be granted explicitly?

    • @diffusive@lemmy.world
      link
      fedilink
      English
      153 months ago

      Nope, because Facebook app is not a VPN service so it cannot intercept traffic.

      What it is unclear from the article is how they circumvented the certificate check on the app side. Probably (given this was many years ago, maybe these apps weren’t setupping certificate pinning/HPKP)

      • @phx@lemmy.ca
        link
        fedilink
        English
        13 months ago

        In theory, yes. In practice of they found some sort of exploit that allowed this I’d 100% not be surprised if Meta took advantage of it. Facebook app is malware