Hacker News new | ask | show | jobs
by Ganoes47 3529 days ago
Can someone ELI5 how they actually capture all these data ?

Are they basically cracking encryption ? I thought the kind of encryption provided by VPN services (256-bit AES/CBC) was strong enough? If that's what they do, aren't they violating privacy laws ? Aren't they breaching companies such as Google, Facebook etc... T&C ? Are they installing some kinds of trojans, keyloggers and stuff on 3rd parties computers ? Isn't what they are selling black hat hacking solutions ? Or are they only capturing clear traffic ? which is not necessarily very meaningful.

It says : "extract information about people’s usage of services such as Gmail, Hotmail, WhatsApp, and Facebook"

The latest terms and conditions you had to acknowledge recently to continue using watsapp (yes, I read them!) mentionned that they don't keep a record of the content being exchanged via watsapp. So, is watsapp lying ? Or what does this Endace system records ? Watsapp T&C also say that they use a strong encryption. so, FTW?

2 comments

They can't do anything with encrypted data, except (badly) try to detect that it's encrypted in the first place.
It seems they can only guess at the contents of encrypted packets.

https://www.endace.com/deep-packet-inspection.html