Facebook Onavo Protect doesn't protect against Facebook

VPN app collects all sorts of details

By Thomas Claburn in San Francisco

Posted in Security, 7th March 2018 20:35 GMT

Facebook's mobile VPN app, Onavo Protect, has been pushed as a way to protect personal information over public networks. But the app, which the social media giant acquired in 2013, sends users' data back to Facebook, even when the app is turned off.

In a blog post on Monday, Will Strafach, CEO of the Sudo Security Group, published his findings about the data collected by Onavo Protect for iOS.

The app, says Strafach, uses a Packet Tunnel Provider app extension – part of Apple's iOS SDK – to handle the VPN's network traffic routing. He claims the following data is being sent to Facebook:

So while the VPN may be protecting against eavesdropping on traffic traveling over an untrusted wireless network, it's simultaneously reporting details about its user to Facebook.

Strafach, in an email to The Register, said it's not clear what Facebook is doing.

"I cannot figure out why they collect the information that I am seeing," he said. "The screen thing does not seem relevant to VPN usage, it just tells them (I guess) how long you are actively on your phone during the day if I understand correctly."

Strafach said data usage tracking could make sense if Facebook were looking to identify those using too much data on its VPN.

"But the weird part is that the APIs called would tell them total usage even when not connected to the VPN, and additionally they could account for VPN usage on the server side if they wanted to," he said.

The Onavo privacy policy – more accurately described as a data use policy –explains that by using the app, "you choose to route all of your mobile data traffic through, or to, Onavo’s servers." And the app says it may use collected data to "provide, analyze, improve, and develop new and innovative services for users."

So on some level, anyone using the app, much less Facebook's other services, should be aware that they've surrendered their data, despite Facebook's assertion that Onavo "helps keep you and your data safe when you go online, by blocking potentially harmful websites and securing your personal information."

Facebook did not immediately respond to a request for comment.

Strafach argues that Facebook should be clearer about what it's doing with the data.

"They can easily clear things up by explaining more precisely why they collect certain data and what they do with it, so I don’t understand why they are so vague about it," he said. "I do hope they are being respectful of user privacy and it would be very nice if they clarified that I think." ®

Sign up to our NewsletterGet IT in your inbox daily

19 Comments

More from The Register

Facebook back in court fighting claims it nicked British data centre IP

UK-based BladeRoom's founder airs grievances

Commonwealth Games are just the ticket for Facebook

Free Wi-Fi will be lousy without a Social Network™ login, which in this of all weeks is just dumb

Facebook recruits Nokia to trial and standardise Terragraph wireless tech

Fibre to the pole, then Facebook's well-behaved wireless brings signal to the great unwired

After repeated warnings Facebook bans Britain First for 'inciting hatred'

Party leaders would protest but they're currently in prison

Facebook smartmobe app's pre-ticked privacy settings violate German data protection law

Court favours consumer group in long-running dispute

Facebook confesses: Facebook is bad for you

Grazing FB is ruining your life, admits social network after probing its army of addicts

Fed up with Facebook data slurping? Firefox has a cunning plan

The Facebook Container add-on quarantines the social network to limit data harvesting

Hey, we've toned down the 'destroying society' shtick, Facebook insists

The Social Network rises to criticism from former exec

Facebook want us to believe banning Putin's troll army safeguards Russian democracy

Stop laughing, this is serious: Zuck’s also decided only Europeans deserve GDPR-grade data protection

You'll like this: Facebook probed by US watchdog amid privacy storm

'Non-public' FTC investigation a new headache for Zuckerberg