6 ms·
Alec Muffet has done a lot of work to get Facebook running on TOR and he's a true believer. I really enjoyed working with him when I was at Facebook. He also di
by nocarrier 10y ago
Alec Muffet has done a lot of work to get Facebook running on TOR and he's a true believer. I really enjoyed working with him when I was at Facebook. He also did a lot of work to get .onion domains to be recognized by registrars as a special purpose domain name. This let us issue certificates on .onion.
I don't know if the story behind the facebookcorewwwi.onion domain name itself has been talked about much, but we wanted a memorable name for the domain so we took a new cluster that hadn't been put in production yet and threw something like 500k cores at brute forcing onion names till we had a memorable domain name. Alec had a script that looked for hashes that started with facebook and then he picked the one that seemed to fit the most. And that's how we have facebookcorewwwi.onion now.
- ludamad 10y agoI don't understand quite, why so much brute force?
- detaro 10y agoThe onion-name is a hash of the public key the service uses, so you can't just pick a name and use it. They had to try many keypairs to find some that hashed to "facebook...." (Normally you generate your key and just use whatever name that hashes to, but it's cool to have one that's easy to remember)
- p4bl0 10y agoThe name of .onion address is the hash of a public key, so you can't choose it, or rather the only way is to generate random public and private key pairs and to keep the one that interest you. Facebook must have generated an awful lot of key pairs to get "facebookcorewwwi". By the way, I hope they deleted the other generated pairs…
- bostik 10y agoI have good faith that they didn't, or certainly not all of them. When Alex described the entire process they went through, he also smirked that should that primary key ever get compromised they have several others, almost as good, ready as drop-in replacements. I do think he also mentioned that they only cared about keys that had their required prefix; all others were destroyed without anyone ever having access to them.
- p4bl0 10y ago> I do think he also mentioned that they only cared about keys that had their required prefix; all others were destroyed without anyone ever having access to them. Okay, that is what I was implying would be terrible otherwise. But actually it is quite obvious that they would not spend the disk space necessary the keep every single generated key pairs now that I think about it.
- jsprogrammer 10y agoHow would that be terrible?
- deleted 10y ago[deleted]
- p4bl0 10y agoThe number of generated key pair to find "facebook" + keywords must have been gigantic, maybe even so much that it could be used as a kind of rainbow table which would allow people (or three letters agencies) who can access it to attack hidden services that use one of the .onion for which a corresponding private key is known.
- baby 10y agoThis is not vulnerable to brute-force nor rainbow tables.
- besselheim 10y agoRelative to the 2^80 (1,208,925,819,614,629,174,706,176) possible onion addresses, whatever they generated would be miniscule.
- p4bl0 10y agoIndeed. I was being stupid and didn't take the time to really think it through. Thanks to you and all the others who pointed that out :).
- danielvf 10y agoOnion names are sort of public keys. You generate a secret key, then that's transformed/hashed into the public key that is your onion address. Since onion addresses are essentially random strings of a certain length, the only way to get a "vanity" onion address is to brute force it.
- 0x0 10y agoAlso, if I'm not mistaken, this means that if YOU can brute force a vanity domain, anyone else willing to throw down the same amount of computing power can perform the same brute force and discover your private key, taking over your onion site? Edit: probably wrong, see below
- eterm 10y agoNormally you brute force vanity addresses by having a range of acceptable outcomes, whereas to brute force a specific vanity address* you are only targetting a single outcome. So they might have just set it to filter for facebook[dictionaryword]+ and this was the best match. * Actually any address, it's not limited to brute forcing vanity addresses.
- 0x0 10y agoI guess I incorrectly assumed the process would be repeatable, but now I see that getting a specific duplicate equals bruteforcing the entire key space - even if the prefix is a chosen vanity name. I confused it with the effort of getting a similar address where just the vanity prefix needs to match.
- nocarrier 10y agoIt requires substantially more compute power to match "facebookcorewwwi" vs just finding a hash with a prefix of "facebook" that looks readable. Good luck hashing the remaining eight characters!
- Russell91 10y ago
- loeg 10y agoOnion domains are just an encoding of a hash of a public key. To get a memorable name, you have to find a keypair that hashes to some letters you want. There is no correlation between any of the characters, so you have to do an exhaustive search to find nice strings.
- 0xdeadbeefbabe 10y agoBecause it happened in the past with a hashing algorithm that isn't resistant to getting faster as time progresses.
- wicket 10y agoThat's really interesting. Are you able to tell us how long those 500k cores were running for before the facebookcorewwwi.onion name was found?
- nocarrier 10y agoWe generated many candidates beginning with facebook, so I don't recall when that one was found--it just happened to be the one that looked the best. There's a number of backup memorable domains that we kept the keypairs for just in case facebookcorewwwi gets compromised somehow. I don't remember how long we ran it for, but IIRC we had enough candidates to stop after a week or two. I'm guessing something like 100-200M cpu hours?
- wicket 10y agoThanks for sharing! I'm now curious to know what the energy bill came to and whether it would make it to the list of most expensive domain names[1]. [1] https://en.wikipedia.org/wiki/List_of_most_expensive_domain_names https://en.wikipedia.org/wiki/List_of_most_expensive_domain_...
- danbruc 10y ago100M...200M core h, 10 W/core, 50 $/MWh and we get 50k...100k $.
- noir_lord 10y agoIt's awesome we live in a world where we can throw 100-200 million cpu hours at something of a whim. That each of those cores are billions of times faster than my first PC just puts the icing on the cake.
- evgen 10y agoFWIW, we ran it on and off for about a month IIRC, as the cluster was put through its paces prior to going live. I also seem to remember Matt Jones doing a minor tweak to the scallion code to speed things up as well...
- jimktrains2 10y ago> This let us issue certificates on .onion. Isn't TOR encrypted up to a hidden service anyway? Why would you HTTPS over TOR? Honest Question.
- RaleyField 10y agoProbably authentication of server, but client still remains anonymous.
- m00dy 10y agoThat's true. Exit nodes do not play a role in hidden services. But, Rendezvous point does. So, If your node somehow selected as rendezvous point for meeting, then you could possibly sniff the traffic.
- dchest 10y agoThis is incorrect, exit nodes are not involved with hidden services. Edit: the original comment I replied to stated that exit nodes could sniff traffic. Reply to new comment: The connection is encrypted to the service's public key, what are you talking about? Stop spreading nonsense and go read documentation.
- herbst 10y agoThey cant. That is the whole concept behind the word "onion" that they cant.
- dchest 10y agoIt is encrypted, but when you're going to facebookcorewwwi.onion you only know that you're connecting to server that knows the corresponding private key, of which "facebookcorewwwi" is a hash. Which is already good. However, seeing EV certificate on this domain also shows you that the corresponding private key for HTTPS connection is signed by a certificate authority: that is, if you trust this CA, you can pretty much trust that you're connecting to Facebook, Inc.
- belorn 10y ago
- kregasaurusrex 10y agoI remember this was talked about by a group at Ohio Linuxfest a couple years ago and also went into IP load balancing at scale. Really neat work being done there.
- nikcub 10y agoIt took me only 24 hours and about $200-300 in compute to hit Blockchains hidden server key which is: blockchainbdgpzk.onion I'm pretty sure it's the second most trafficked site after FB If anyone is looking at setting up a hidden service and wants a memorable name I still have the cluster setup. Matching 10 characters isn't much of a challenge - it's why hidden service addressed on their own don't provide identity authentication and why we both went with SSL cents for Tor hidden services (provided by Digicert - who have been great advocates for the cause)