12 ms·
1M People Use Facebook Over Tor
- HalcyonicStorm 10y agoPlease explain it to me if I'm wrong, but doesn't logging into Facebook on Tor defeat the purpose of Tor?
- buro9 10y agoNot if the user merely intends to get past a firewall the country has... their purpose isn't anonymity, but free communication, unfortunately they must don anonymity to achieve free communication.
- pmontra 10y agoBut if one of your friends is not really your friend, and you won't know until it's too late, they'll know you got past the firewall and that could be enough to get you into troubles. You better have to stay fully anonymous, which limits what you do on Facebook. You probably want different accounts for different groups and an empty timeline in every account.
- Joof 10y agoIt may be that it just isn't that strictly enforced for a variety of reasons. China allows a number of VPN services that bypass the firewall to function. My guess is that it isn't a huge deal because the vast majority of people don't care enough to go out of their way to bypass the firewall; the social effects of having that firewall are still in place. Start enforcing it heavily and the people that DO use those services may start protesting or moving into activist roles.
- 50CNT 10y agoWhich also tends to be the subset of people that have studied abroad, various repatriated huaqiao and college students at some of the more metropolitan colleges and I guess tech people/white collar workers. Cracking down on college students seems like a really dumb idea.
- zhemao 10y agoAnd yet, that hasn't stopped them in the past. https://en.wikipedia.org/wiki/Tiananmen_Square_protests_of_1989 https://en.wikipedia.org/wiki/Tiananmen_Square_protests_of_1...
- Joof 10y agoI think this is a good reminder of why they would want to keep people just barely satisfied. China will go that far, but it's an expensive point to make.
- zhemao 10y agoSince Tiananmen, the party has basically bargained that people will accept economic progress as a substitute for political freedom. Now that the rapid growth of the last two decades is starting to slow down, we'll have to see how the CCP and Chinese people respond.
- aplusbi 10y agoAccording to the article, facebook has a .onion domain.
- godzillabrennus 10y agoThe article says its https://www.facebookcorewwwi.onion https://www.facebookcorewwwi.onion
- mapgrep 10y agoInterestingly, since Onion addresses are derived from the public key of the host server, Facebook had to basically brute force this address. The process is described in "Part three" here: https://blog.torproject.org/blog/facebook-hidden-services-and-https-certs https://blog.torproject.org/blog/facebook-hidden-services-an... "The short answer is that for the first half of it ('facebook'), which is only 40 bits, they generated keys over and over until they got some keys whose first 40 bits of the hash matched the string they wanted." "Then they had some keys whose name started with 'facebook', and they looked at the second half of each of them to pick out the ones with pronouncable and thus memorable syllables. The 'corewwwi' one looked best to them — meaning they could come up with a story about why that's a reasonable name for Facebook to use — so they went with it." (Corrected: Hash of public key not private key per itsbenweeks below)
- itsbenweeks 10y agoI thought Onion addresses were a hash of the public key, not the private key.
- mapgrep 10y agoAh, you are correct, thank you: ..."a base32 encoding of a 10-octet hash of Bob's service's public key" https://gitweb.torproject.org/torspec.git/tree/rend-spec.txt#n526 https://gitweb.torproject.org/torspec.git/tree/rend-spec.txt...
- cm3 10y ago
- mapgrep 10y agoTor does not only allow anonymity of identity, it also can provide anonymity of location and anonymity of destination. If you are in a country or organization that would prefer you not visit Facebook, this can be useful. If you would prefer that Facebook not know your location and IP address, this can be useful.
- Titanous 10y agoNo, you retain all of the properties of Tor hidden services: censorship resistance, authenticated end-to-end encryption, onion routing that hides your source IP. Obviously if you log into a Facebook account with your real-world identity then all actions performed on the site will be linked with it, but that is expected.
- boomlinde 10y agoI think his point is that if you are using Facebook, you are still limited by the level of trust you have with them. That should be quite low for any privacy conscious internet user. That you are using a different IP and a pseudonym might be a hoop for them to jump through through to figure your identity out should be considered in the context that they are likely already collecting data about you without your consent from many different sources. When it comes to jumping through these kinds of hoops, Facebook is a circus lion.
- lbenes 10y agoWhen I was traveling in China, I would have had no access to Facebook if it weren’t for Tor. All I needed was my USB drive with a Tor + Linux and I could access the free Internet from any computer. Providing anonymity of identity is just one of the many uses of tor. [1] [1] https://www.torproject.org/about/torusers.html.en https://www.torproject.org/about/torusers.html.en
- slig 10y agoWhy doesn't China block Tor? Isn't it easy as blocking all known public IP addresses? It doesn't make sense to not allow the user to access certain sites, but allow Tor that can easily bypass that protection.
- jaeh 10y agothere are non public ip addresses and the tor team spends quite some time fighting the big firewall in various ways. talk from the 23c3 about tor and china: https://www.youtube.com/watch?v=P6A7jLpL3Rs https://www.youtube.com/watch?v=P6A7jLpL3Rs
- ggregoire 10y agogreat talk, thanks for sharing this video
- rnhmjoj 10y agoNo, not really: even if you could block all the known tor relays there are still the bridges that are exactly meant for this situation: bridges are like normal relays but their full list is not disclosed so it shouldn't be possible to block them entirely. This is probably what he has been using. https://www.torproject.org/docs/bridges https://www.torproject.org/docs/bridges
- e12e 10y agoIf you assume that Facebook will comply with whatever entity you're trying to avoid, by using Onion, it sounds like a pretty bad idea to me, yes. In theory you could probably use a separate browser and Tor session for Facebook, and for your other browsing - making it a little harder to associate your Facebook login with your Tor session (ip). Sounds like a terrible idea, though. Now, for some of the reasons why you'd want to use Facebook via Tor, it might not matter much - using Facebook might be bad enough (eg: it could be considered subverting state censorship) -- so if Facebook is already colluding with your adversary, just having a Facebook account might be enough to give you problems. It might be enough for a legal veneer of plausible deny-ability, although I doubt it: Eg, perhaps you're a drone pilot and you login to Facebook via Tor, and paste in a gpg-encrypted, ascii-armored text-message to a journalist on Facebook. You could claim someone must've hacked your account. Or you could collude with someone else, and "borrow" their account. I don't think it'd keep you out prison though.
- bostik 10y agoIf your plan was to remain anonymous on FB, it would. But that's not what their .onion service is for. The ingenuiety of the hidden service is that FB basically inverted Tor's idea. Tor is really good at bypassing restrictive net filters, while at the same time it hides your browsing destination. So in effect FB turned a Tor address into their own highly resilient web proxy. Where a proxy normally provides a guarded way out of a network, the hidden service provides an otherwise untraceable way in. Now, technically it is ~possible to identify FB-Tor traffic from regular Tor traffic. At least in some sense. Because the address is inside the .onion network, there are only half as many routing hops between the client and the server. So if you, as a well funded governmental adversary, first identify nearly all Tor traffic, you can then see which clients receive their responses notably faster than the rest. These faster roundtrips are very likely using hidden services. If you then drill down even further, I am sure you should be able to identify a reasonably large fraction of your own subjects who are clearly accessing FB and thus stepping around the nationally imposed censure. For the record, Alec didn't consider the above traffic analysis attack particularly feasible. And we both agreed that the straightforward solution is to get a lot more traffic for hidden services in general. Once FB is not the sole huge site with a hidden service, their traffic cannot stand out.
- ikeboy 10y agoWhat? Hidden services use 6 hops compared to regular traffic's three. They are slower.
- pg_is_a_butt 10y agomaking someone hop 6 times before a marathon is also slower than running a marathon without hopping 6 times first. the guy that hopped 6 times first didn't get run over by a car right out of the gate. lucky coincidence.
- bostik 10y agoOh sorry, the context was missing. This came up in a discussion we had. FB is proposing (and funding) development that would make hidden services faster. One of the measures would be to make [some?] hidden services reachable over 3 hops only. A quick search does not bring anything on the topic up, but it can easily be that I try to search for wrong key words.
- rmc 10y agoThere are several advantages of Facebook over Tor. One of them is that your ISP is unable to see who what site you are talking to, and that Facebook is unable to see your source IP address.
- quickben 10y agoYes. They make money from knowing who people are, and selling that. This cleaves the driving tor concept by deanonymizing users. For anybody as large as Facebook, if enough people go for it, the remaining slice of the pie will be really small (because not all have tor, but many of those that have, have Fb). Derive conclusions accordingly.
- randyrand 10y agoFB will know you logged in. But your ISP will not.
- walrus01 10y agoNot really, if your expected adversary is your local nation state that wants to watch your Internet traffic for domestic political dissent (Iran, Ethiopia, China, etc).
- supermatt 10y agoOr 1 person uses 1M facebook accounts over Tor...
- asimuvPR 10y agoWhich would not surprise me a bit.
- shi 10y agoExactly my thought
- mtgx 10y agoDon't give Hillary's campaign anymore ideas: http://www.thedailybeast.com/articles/2016/04/21/hillary-pac-spends-1-million-to-correct-commenters-on-reddit-and-facebook.html http://www.thedailybeast.com/articles/2016/04/21/hillary-pac...
- mvidal01 10y agoI wonder how many of these accounts are sock puppets?
- tomswartz07 10y agoProbably not a lot. I use it to bypass firewalls sometimes.
- sidcool 10y agoDoes Google allow searches from Tor network? Last I heard it didn't.
- p4bl0 10y agoIt does, but you will have to go through captchas regularly.
- ryanlol 10y agoIn my experience, unless you get lucky with your node it'll just throw an infinite captcha loop at you.
- nicelynicely 10y agoDisconnect.me wraps Google and is bundled in the for browser. No capchas.
- realkitkat 10y agoURL: https://ahmia.fi/ https://ahmia.fi/ There are search engine(s) specialized for TOR. As per Wikipedia[1]: 'Ahmia is a clearnet search engine for Tor's hidden services'. It was part of Google summer of code in 2014[2]. [1] https://en.wikipedia.org/wiki/Ahmia https://en.wikipedia.org/wiki/Ahmia [2] https://blog.torproject.org/category/tags/gsoc-2014 https://blog.torproject.org/category/tags/gsoc-2014
- yxlx 10y agoCool, been looking for something like this. However, it should be noted that this is not what parent asked about. Parent was wondering if Google was usable for regular web searches using a client that came from a Tor exit node via the Tor network.
- akerro 10y agoIt never disallowed? What do you mean?
- nocarrier 10y agoAlec Muffet has done a lot of work to get Facebook running on TOR and he's a true believer. I really enjoyed working with him when I was at Facebook. He also did a lot of work to get .onion domains to be recognized by registrars as a special purpose domain name. This let us issue certificates on .onion. I don't know if the story behind the facebookcorewwwi.onion domain name itself has been talked about much, but we wanted a memorable name for the domain so we took a new cluster that hadn't been put in production yet and threw something like 500k cores at brute forcing onion names till we had a memorable domain name. Alec had a script that looked for hashes that started with facebook and then he picked the one that seemed to fit the most. And that's how we have facebookcorewwwi.onion now.
- ludamad 10y agoI don't understand quite, why so much brute force?
- detaro 10y agoThe onion-name is a hash of the public key the service uses, so you can't just pick a name and use it. They had to try many keypairs to find some that hashed to "facebook...." (Normally you generate your key and just use whatever name that hashes to, but it's cool to have one that's easy to remember)
- p4bl0 10y agoThe name of .onion address is the hash of a public key, so you can't choose it, or rather the only way is to generate random public and private key pairs and to keep the one that interest you. Facebook must have generated an awful lot of key pairs to get "facebookcorewwwi". By the way, I hope they deleted the other generated pairs…
- bostik 10y agoI have good faith that they didn't, or certainly not all of them. When Alex described the entire process they went through, he also smirked that should that primary key ever get compromised they have several others, almost as good, ready as drop-in replacements. I do think he also mentioned that they only cared about keys that had their required prefix; all others were destroyed without anyone ever having access to them.
- agildehaus 10y agoI thought .onion addresses were for anonymous hidden services, which Facebook is not. What's the advantage of accessing a .onion versus using Tor to visit the normal facebook.com?
- loeg 10y agoTOR is also useful for routing around damage (censorship).
- dublinben 10y agoTry reading the introductory blog post[0] before asking redundant questions. [0] https://www.facebook.com/notes/protect-the-graph/making-connections-to-facebook-more-secure/1526085754298237/ https://www.facebook.com/notes/protect-the-graph/making-conn...
- chrisfosterelli 10y agoIf you are using TOR to connect to facebook.com, your connection has to leave the TOR network. This gives a lot of power and control to whoever is your exit node out of the network. Although they can't see who you are, they have full MiTM of your traffic. SSL helps a lot with this obviously, but it's still not the most ideal scenario. Traffic directed to hidden services never "leaves" the TOR network, so it doesn't hand over any control to exit nodes and the (possibly malicious) people running them.
- rhokstar 10y agoMaybe bot networks are included in that number?
- lossolo 10y agoFor sure there is a huge amount of bots in this number.
- akavel 10y agoI've recently tried using FB via TOR (Browser) for the first time, but was unable. After entering the onion address and my FB credentials, I was informed that the account is temporarily blocked (presumably because of first access via TOR). I was presented with an option of unblocking it by recognizing a few photos of friends and matching them to names - but unfortunately, all those photos showed as blank, white squares! So, I wasn't able to login via TOR via the purposefully created .onion address. Also, sent an issue report via non-TOR login about this, but never got any response. Note also that this seems to mean to me, that there may be people who are cut off from FB via TOR same as me, but who don't even have a way to notify FB about the fact. And thus not having any chance of having the bug fixed.
- blacksmith_tb 10y agoThat's a standard challenge if you try to log into your FB account from a new machine / IP address that geolocates somewhere you don't typically seem to be. Of course, that's pretty ironic since your Tor exit could be anywhere, but it's not specific to Tor anyhow. I have seen the same behavior using VPN, too.
- besselheim 10y agoThere isn't an exit when accessing an onion address - the identity of the client-chosen part of the circuit would be unknown to the hidden service operator.
- akavel 10y agoThe problem is not the existence of the challenge. The problem is it is broken in a fresh, unmodified install of the TOR Browser. Sorry, but I can't recognize a pure white square properly as a person.
- Raphmedia 10y agoThat test is a Captcha. You failed it. Are you sure you are not a robot? Sorry to announce it to you like that...
- NelsonMinar 10y agoIt's funny that they say people use Tor "for a variety of reasons related to privacy, security and safety". They left out "firewall circumvention", which I have to believe is the #1 reason, at least in China.
- HeavenFox 10y agoUnfortunately, it's been a very, very long time since Tor was last usable in China.
- cloudjacker 10y agoI heard that internally, China has a very robust internet infrastructure, and it is just connecting to things on the outside that are broken
- envy2 10y ago"Broken" would suggest that this isn't intentional. But yes, you are correct; domestic internet is fine, but traffic in/out is slowed and interfered with nearly to the point of being unusable.
- cloudjacker 10y agoI heard that internally, China has a very robust internet infrastructure, and it is just connecting to things on the outside that are broken
- alexchantavy 10y agoCan you elaborate? Someone above commented that Tor was the only way they were able to get out of the GFW.
- chrisfosterelli 10y agoChina uses fairly complex artificial intelligence to detect TOR connections. Anything that "behaves like" TOR or a VPN is quickly caught on to and blocked. There are a few attempts designed to make TOR look more like standard web traffic, which are really interesting. It's definitely a cat-and-mouse-style game. Some have more success than others.
- logicallee 10y agoGiven Facebook's real-name policy, and the fact that it's literally a social network of your best friends, then since all Facebook pages are HTTPS anyway, the idea of using it over tor is... Uh... a bizarre in theory the only thing you're leaking over a plain https is, "Hey this guy has friends." (this connection is visiting facebook). meanwhile in theory I'd expect facebook to leak everything else on their end, because come on. I have next to zero expectation of privacy on facebook. by that I mean you think people are planning terrorist plots over facebook? come on. so I find the mashup of tor with facebook to be kind of bizarre.
- c22 10y agoIf you expect facebook to leak everything they know about you then connecting through tor allows them to know one less thing about you (the location you used to visit facebook).
- logicallee 10y agosure, but people usually obscure their location by using a vpn, not going through the hassle of going through tor. So what I've written: >so I find the mashup of tor with facebook to be kind of bizarre. is even more so if anyone's reason is "I really, really, don't want facebook to know where I am!" I mean I just don't get it. Especially to the tune of 1 million people.
- c22 10y agoWhat is the hassle of using tor? You have to download, configure, and run some software, just like you'd have to to connect to a vpn, but you don't have to, yanno, set up a vpn... You also don't have to rely on the integrity of a single proxy.
- putasidemobile 10y agoActually you share one more, important, datum: This user uses Tor. Likely uses Tor for other, possible nefarious, purposes too. Likely has a high X_keyscore. Your real profile and location can be inferred from your browsing habbits and friend's data. Unfortunately, with the current size of Facebook, even "not having an active Facebook account" shares data, especially when you are in an age category where all your peers do have profiles. It's a negative signal to recruiters and employers ("must have something to hide...").
- hfourm 10y agoTerrible title. I was wondering in what use case Facebook makes sense as an alternative to Tor
- hfourm 10y agoTerrible title. I was wondering in what use case Facebook makes sense as an alternative to Tor
- torkable 10y agoDoesn't logging in to a site like facebook full of your personal data sorta defeat the purpose of tor(attempting to stay anonymous)?
- putasidemobile 10y agoRelated: Please Facebook, let me peek over your walled garden. Taking a privacy-friendly stance, with the current Facebook, hurts my social life. I do not trust your company, and I think you are bound to act unethically in the future. But I do not ask you to become a trustworthy ethical company. Mess with the accounts of my friends all you want. I just want to be invited to the next BBQ. People have stopped using e-mail for announcing these social events, and _all_ use Facebook. Could it be possible for me to not be on Facebook, yet still stay up-to-date on what my friends, or hell, even my parents now, are doing? A more advanced social graph API that hooks into email, RSS, Twitter, whatever... ? I'm sure you also have my email-address from the address books of my contacts, so you could verify me. As one of your longest non-users (I remember when TheFacebook required a Harvard-email for invite), please let me become a semi-user. It won't pay you a dime, but it will make the world a better place.
- mcpherrinm 10y agoFacebook users can invite non-Facebook users by email to events, if they want to. But for viewing what your friends and parents are doing on Facebook? Well, they could change their privacy settings to be public, but that would hurt their privacy. You want to be in their social graph, but not have a Facebook account. What does that even mean? Do you just not want to have a password? There's no rule you have to post any content, if you just want to view other's.
- putasidemobile 10y ago> Facebook users can invite non-Facebook users by email to events, if they want to. This stops after a while. Even when you stay a pleasant person, you'll always be "that guy" requiring an extra action to contact. The social ripple/ping of an event stays inside Facebook. > You want to be in their social graph, but not have a Facebook account. In the ideal form this would be a totally open protocol (with backing of Facebook, Google, ... and W3C). In the current form, I do not know enough about Facebook to suggest a good system. Yes. I want to be in their social graph, but not have a Facebook account or be under Facebook TOS. If that is meaningless at the moment, maybe we should make it mean something.
- JumpCrisscross 10y agoI wish Google and Apple would roll out .onion Gmail and iCloud services, respectively.
- cookiemonsta 10y agoand how many of those are for spam...?
- mike-cardwell 10y agoI use "Tinfoil for Facebook" on my Android phone. It's a wrapper around the mobile site with some extra features, and you can tell it to use "Orbot" (Tor client for Android), and you can tell it to use the onion address as well if you want (which I do). Which means I can use Facebook over Tor without using the official app which steals god knows what data from your phone. You don't get mobile notifications this way, so I just get my notifications via email instead. And I uploaded my public PGP key to Facebook, so the emails they send me are encrypted. Getting notifications via email also means that Facebook doesn't even know if or when I've read a particular notification. To read those encrypted emails on my phone I use K-9 Mail with OpenKeyChain. My Yubikey Neo acts like a smart card reader to my phone over NFC so I don't need to give my phone direct access to my secret PGP key. This setup works for me because I try to limit my Facebook usage, keep my number of "friends" on there to a minimum, and lie to Facebook whenever they want me to explicitly supply information.