Facebook is facing a class action lawsuit over claims that it intercepted encrypted traffic from the Onavo Protect app to gain competitive insights. Using techniques akin to a MITM attack, Facebook allegedly decrypted specific domains' traffic by prompting users to install a CA certificate. However, improved security measures in newer Android versions prevented this from being feasible. The core controversy lies in whether the data interception was legal or ethical. The continued analysis of archived app versions and court documents sheds light on Facebook's methods and the technical challenges involved.

13m read timeFrom doubleagent.net
Post cover image
Table of contents
MotivationTechnical analysisWhat else?Wrapping upSign up for doubleagent.net
2 Comments

Sort: