
Facebook's Onavo Protect app intercepted user's encrypted HTTPS traffic by using a technique called "ssl bump" to decrypt specific domains, including Snapchat, YouTube, and Amazon, without user consent or knowledge. The app used a custom certificate installed on the device to achieve this, which was possible due to a technical limitation in Android at the time, but is no longer possible with ...