This is the problem with using VPN services in general, you have to have complete trust in the service provider.

  • the post of tom joad@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    So (and im asking for technical clarification as a layman) Facebook didn’t put this data miner on unknowing user’s phones but did pay teenagers to install one (onavo) on their phones that worked to decrypt traffic for everyone those users interacted with… Right?

  • AutoTL;DR@lemmings.worldB
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    This is the best summary I could come up with:


    In 2016, Facebook launched a secret project designed to intercept and decrypt the network traffic between people using Snapchat’s app and its servers.

    On Tuesday, a federal court in California released new documents discovered as part of the class action lawsuit between consumers and Meta, Facebook’s parent company.

    “Whenever someone asks a question about Snapchat, the answer is usually that because their traffic is encrypted we have no analytics about them,” Meta chief executive Mark Zuckerberg wrote in an email dated June 9, 2016, which was published as part of the lawsuit.

    When the network traffic is unencrypted, this type of attack allows the hackers to read the data inside, such as usernames, passwords, and other in-app activity.

    This is why Facebook engineers proposed using Onavo, which when activated had the advantage of reading all of the device’s network traffic before it got encrypted and sent over the internet.

    “We now have the capability to measure detailed in-app activity” from “parsing snapchat [sic] analytics collected from incentivized participants in Onavo’s research program,” read another email.


    The original article contains 687 words, the summary contains 175 words. Saved 75%. I’m a bot and I’m open source!

  • tobogganablaze@lemmus.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    you have to have complete trust in the service provider.

    Not completley, there is 3rd party audit companies that can verify claims made by the VPN providers, like confirming no-log policy and such.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      How do you trust the third parties? And even if the third parties think it is ok that doesn’t mean that they aren’t hiding something.

      VPNs weren’t designed to be private.

      • tobogganablaze@lemmus.org
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        7 months ago

        How do you trust the third parties?

        How do you trust anyone? At some point you either do or don’t, because it’s just not possible to verify everything in your life.

        The alternative would be not using an VPN and for me personally I trust my VPN provider a lot more than my luck of not getting chaught by chance.

        • ☆ Yσɠƚԋσʂ ☆@lemmy.mlOP
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          Another option, if you have technical skills, is to just run your own VPN which tends to be pretty easy to setup on a VPS nowadays. You can find a VPS provider in a jurisdiction you want, and you control what gets logged.

          • circuscritic@lemmy.ca
            link
            fedilink
            arrow-up
            0
            ·
            edit-2
            7 months ago

            …so, trust the hosting provider to not log…and that you won’t screw up any config or update, and make sure to use anonymous payments, and…and…etc.

            • ☆ Yσɠƚԋσʂ ☆@lemmy.mlOP
              link
              fedilink
              arrow-up
              0
              ·
              7 months ago

              The only thing that actually matters is the jurisdiction. If your hosting provider is in a place that the country you live in can’t legally force to hand the data over then you’re much better off than using a service that may be sharing data with your government.

              • circuscritic@lemmy.ca
                link
                fedilink
                arrow-up
                0
                ·
                edit-2
                7 months ago

                The topic in question here is not about government abuse of data, but corporate abuses, but okay, let’s set that aside.

                You’ve said that it’s safer to roll your own VPN using a VPS service precisely because you can’t trust any VPN providers, or auditing organizations.

                But you’re now saying that you can trust a hosting provider based solely on which jurisdiction they reside in.

                You’re just arbitrarily picking which companies to trust with your connection traffic, but with added complexity, and significantly reduced egress locations for your traffic, which itself dramatically impacts any privacy benefits you were looking to achieve.

                • ☆ Yσɠƚԋσʂ ☆@lemmy.mlOP
                  link
                  fedilink
                  arrow-up
                  0
                  ·
                  7 months ago

                  First of all, nowhere did I say anything about trusting any hosting provider. The point once again was about jurisdiction of the provider. Meanwhile, there’s nothing more arbitrary about picking a hosting provider than a VPN.

      • delirious_owl@discuss.online
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        The p stands for private. They were designed to connect someone to a remote intranet…privately.

        Yes, VPNs were quite literally designed to be private

  • Elley Smith :vote:@kzoo.to
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    @yogthos Is anyone surprised by this anymore? Facebook is evil- full stop. We don’t need any more reasons to obstain from using their products but “mArKeTplAcE” and “mY cOuSiNs WoNt SwiTcH.”

    • Cyborganism@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      I’m trying really hard to get my family to use something else for communication but they won’t. It’s a fucking drag.

      • ian@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        Marketplace is pretty useful. I hope a solid open-source alternative comes along.

        • mox@lemmy.sdf.org
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          What’s important here is not the source code, but simply that the service doesn’t collect unnecessary information.

          Craigslist does a pretty good job of respecting privacy.

          • strawberry@kbin.run
            link
            fedilink
            arrow-up
            0
            ·
            7 months ago

            Craigslist also doesn’t have shit on it. try and buy a car on there. if you’re looking for a beater, sure. but a halfway decent sports car, fb marketplace is the only place

            its still OK for other stuff, I’ve bought tools and whatnot off Craigslist, but for vehicles fb is unfortunately still king

            • mox@lemmy.sdf.org
              link
              fedilink
              arrow-up
              0
              ·
              7 months ago

              What you’re describing is the network effect in action, not a flaw in Craigslist.

              (It will be the same with every alternative you find, except perhaps one that’s well funded with outside money, which will be awful on the privacy front, of course.)

              The way we overcome a network effect is piece by piece:

              • First we switch to the privacy-friendly thing for everything we can. That immediately reduces our exposure, reduces the power of the incumbent, and makes the alternative more useful by giving more users a reason to switch.
              • Then, over time, we switch for the remaining things as we find suitable replacements.

              If I felt I had to buy a sports car, and some awful invasive site like Facebook was somehow the only viable venue, I would buy just the car there. I wouldn’t make them the middle man for every other transaction in my life.

              • strawberry@kbin.run
                link
                fedilink
                arrow-up
                0
                ·
                7 months ago

                well yea its not Craigslist itself that’s the issue, its the fact that its a smaller platform. and yea I use eBay or Craigslist for everything but vehicles.its sad that Craigslist has been forgotten though.

          • ian@lemmy.ml
            link
            fedilink
            arrow-up
            0
            ·
            7 months ago

            I agree. However, I think that most people won’t use Craigslist simply because it doesn’t have a lot of the modern niceties, specifically modern messaging solutions. The email system they have is pretty painful to use.

            • mox@lemmy.sdf.org
              link
              fedilink
              arrow-up
              0
              ·
              7 months ago

              It’s easy enough to do messaging via text, or whatever other contact info you choose to give out. I like that I can use Craigslist without giving them much info about myself.

              If you’re suggesting that a messaging system built into the venue is critical for success, then I suppose all of us wanting privacy are out of luck for now… but perhaps Craigslist (or some other privacy-friendly venue) could make it happen by integrating Matrix.

              • ian@lemmy.ml
                link
                fedilink
                arrow-up
                0
                ·
                7 months ago

                I agree that most messaging services are problematic, but Facebook having Messenger is part of the moat that’s keeping FB users on Marketplace. I think offering any non-email messaging solution would be hugely beneficial. I like the Matrix idea quite a bit.

                • mox@lemmy.sdf.org
                  link
                  fedilink
                  arrow-up
                  0
                  ·
                  7 months ago

                  Europe’s new Digital Markets Act might help in this department, too, through legally mandated interoperable messaging. Let’s hope it works out in our favor.

      • gradyp@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        7 months ago

        I feel you. I’ve spent the last couple years building up self hosted replacements for these enshittified services as they flop. But despite all the work I’ve put in, I can’t even get them to log off facebook to look at what I’ve got.

          • gradyp@awful.systems
            link
            fedilink
            English
            arrow-up
            0
            ·
            edit-2
            7 months ago

            You make an excellent point, without use it’s mostly just there for nothing… but, specifically I build shit that they complain about. I have my personal photo site up with all my digital photos from the last 25 years catalogued and available from anywhere, I did this because they complained about not having them accessible. Hasn’t been logged into by anyone but me…

            But I don’t really blame them, I get it. The easy button is right there.

    • octopus_ink@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Maybe the idea is to show the folks who keep complaining about defederating from Threads that they either don’t know or have forgotten just exactly what kind of company Meta is.

  • MagneticFusion@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    People always say don’t use a VPN because you hsve to completely trust the VPN provider. Firstly, there are various trustworthy abd reputable VPN providers. Secondly, if you do end up using a shady VPN, you are really just back at square one because it’s not like your ISP isn’t siphoning all of your data anyways.

    • ☆ Yσɠƚԋσʂ ☆@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      There is no way to know whom the trustworthy VPN provider shares data with. That’s just the reality. And sure you’re back to square one if you don’t use a VPN, but the point here is that people think that using a VPN is much safer than it actually is. Furthermore, another option is always to just run your own VPN that you can host in whatever jurisdiction you want.

      • MagneticFusion@lemm.ee
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        If Mullvad got raided by the Swedish police and was not able to provide them with a single bit of data, then I think it is very safe to assume they are not providing the data to ANYONE

        • Lemmy@lemm.ee
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          7 months ago

          The creators of MullvadVPN or their identities are not prominently disclosed, which means you have to trust them. For all we know they could be working with Swedish law enforcement or other nations and you’d never know.

          • MagneticFusion@lemm.ee
            link
            fedilink
            arrow-up
            0
            ·
            edit-2
            7 months ago

            Again, worst case scenario and you are just back to square one. If you are trying to do illegal activities or hide from the feds in general, no amount of VPN (even self hosted) would prevent that. You would need to start using TOR and breaking into a whole different level of OPSEC than the average Joe trying to get some more privacy in his day to day life

        • ☆ Yσɠƚԋσʂ ☆@lemmy.mlOP
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          It’s safe to assume they were not providing data to anyone at the time, and perhaps they are not now. Thing is that you don’t know that, and it’s a relationship fundamentally based on trust. There’s nothing wrong with trusting a company like Mullvad, but it is just trust in the end.

  • delirious_owl@discuss.online
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    “I can’t think of a good argument for why this is okay. No security person is ever comfortable with this

    I agree, buy wait till you hear what network appliances are doing and what processor manufacturers are doing…

  • TheAnonymouseJoker@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    There is a lot of confusion amongst plenty people here, in how they are perceiving VPNs.

    It is correct that VPNs are not designed for complete anonymity, security or privacy. However, they absolutely are designed for privacy and anonymity against certain actors, ISPs and regular script kiddies being one of them.

    It is also correct that VPNs are not easy to trust, but that is the case with most, NOT all VPNs. Mullvad, IVPN are solid paid options, and Windscribe, AirVPN, ProtonVPN and Cryptostorm are slightly below but good to use as free/paid options. Most other VPNs either have poor technical management, poor uptime or poor track record (affiliate ads, user data leaks) or may be shady.

  • LWD@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    7 months ago

    “No security person is ever comfortable with this, no matter what consent we get from the general public. The general public just doesn’t know how this stuff works”

    Apparently there was some debate among the Facebook leadership about whether getting clueless people to sign a consent form was good enough for them.

    Cool.

    PC principal collecting consent forms

    • ArcaneSlime@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      Because “adversary” is clearly gender neutral and “man” is not, so “man” isn’t able to continue it’s double meaning as being short for “mankind” which itself is short for “humankind,” for fears that it’s exclusionary.