3 ms·
Interestingly, since Onion addresses are derived from the public key of the host server, Facebook had to basically brute force this address. The process is des
by mapgrep 10y ago
Interestingly, since Onion addresses are derived from the public key of the host server, Facebook had to basically brute force this address.
The process is described in "Part three" here: https://blog.torproject.org/blog/facebook-hidden-services-and-https-certs https://blog.torproject.org/blog/facebook-hidden-services-an...
"The short answer is that for the first half of it ('facebook'), which is only 40 bits, they generated keys over and over until they got some keys whose first 40 bits of the hash matched the string they wanted."
"Then they had some keys whose name started with 'facebook', and they looked at the second half of each of them to pick out the ones with pronouncable and thus memorable syllables. The 'corewwwi' one looked best to them — meaning they could come up with a story about why that's a reasonable name for Facebook to use — so they went with it."
(Corrected: Hash of public key not private key per itsbenweeks below)
- itsbenweeks 10y agoI thought Onion addresses were a hash of the public key, not the private key.
- mapgrep 10y agoAh, you are correct, thank you: ..."a base32 encoding of a 10-octet hash of Bob's service's public key" https://gitweb.torproject.org/torspec.git/tree/rend-spec.txt#n526 https://gitweb.torproject.org/torspec.git/tree/rend-spec.txt...
- cm3 10y agoBut how did they allocate the carefully selected key and avoid others generating the same one in the meantime?
- c22 10y agoThey "allocated" the key by using it. Others are not more likely to generate the key they found than any other specific key. This is statistically unlikely due to the extremely huge number of possible keys.
- cm3 10y agoWell, did they generate keys they liked and then tried to use them immediately, hoping nobody had generated the same key in the meantime, or did they generate only keys they would like and "registered" them all but kept just one? If so, what happens to allocated but unused keys? What I'm trying to figure out is: 1. race condition? 2. waste of key space?
- SXX 10y ago1. You can't generate vanity you like, but you can generate billions of keys and choose one you like the most. 2. You can't "register" key. If some person manage to generate key with same vanity he can use same address as facebook, but practically this is nearly impossible. And if that happen this can be easily detected by facebook so they can just change official key.
- c22 10y agoThere's nowhere to register the key, tor is decentralized. They simply start conducting their business using the key they found. There's no waste of key space for the unused keys, merely a minuscule chance of collision with other random users. I guess you could think of attempting to find hash collisions as a race condition of sorts, but it is a very long race for the attacker.
- cm3 10y agoSo do we know the hash? I guess we don't or it would be easy for someone to pretend to be Facebook.
- c22 10y agoYes, the hash is "facebookcorewwwi", this is the hash of the public key of one of the keypairs facebook generated. We can't pretend to be facebook without knowledge of the corresponding private key, however. To make this more clear, most tor hidden service sites that don't have loads of computing power to bruteforce a vanity domain have uris that look like http://3g2upl4pq6kufc4m.onion http://3g2upl4pq6kufc4m.onion
- deleted 10y ago[deleted]