Meta Allegedly Intercepted Encrypted Traffic from Onavo Protect App
By
taubek
Pulled from the oven just right. Trustworthy, fact-dense, deeply satisfying.
Summary
A class action lawsuit against Meta alleges that the company intercepted encrypted HTTPS traffic from users of the Onavo Protect app, using a technique called "ssl bump" akin to a MITM attack. The investigation is based on court documents and reverse-engineered app packages, suggesting Facebook aimed to gain competitive insights by decrypting user data.
Key quotes
· 3 pulledFacebook intercepted user's encrypted HTTPS traffic by using what would be considered a MITM attack.
The technique, called "ssl bump," was allegedly used to decrypt specific traffic for competitive insights.
Court documents suggest Meta may have breached the Wiretap Act.
You might also wanna read
Italian court annuls €15M OpenAI GDPR fine on jurisdictional grounds under EU one-stop-shop rule
A Rome tribunal annulled Italy's €15 million GDPR fine against OpenAI, ruling that the Italian data protection authority (Garante) lacked ju
Disney faces $5M lawsuit over facial recognition technology use in parks
Disney is facing a $5 million lawsuit over its use of facial recognition technology in its amusement parks, with the lawsuit accusing the co
California Attorney General sues 23andMe successor over 2023 data breach exposing genetic data
California Attorney General Rob Bonta announced he will sue Chrome Holding (successor to 23andMe) following an investigation into a 2023 dat
Google's $135 Million Android Data Privacy Settlement: What 100 Million Eligible Users Should Know
Google has reached a $135 million settlement in a class-action lawsuit accusing the company of secretly transferring Android users' data wit
AI Note-Taking Tools Raise Attorney-Client Privilege Concerns for Lawyers
Lawyers are increasingly concerned about AI note-taking tools appearing in virtual meetings, as these tools could potentially waive attorney
Noyb files GDPR complaint against LinkedIn over paywalled profile visitor data
An article about how LinkedIn's practice of withholding profile visitor data from non-premium users may violate GDPR Article 15, which grant
