11 ms·
Blocklist of all Facebook domains
- mfo 10y agoI just want to say "Privacy matters, thanks you" (even more when FB decided to leverage their like/share button for a global ad netwotk) :-) non tech saavy guys may love a simple .sh / .bat to automatically add those entries to the /etc/hosts on windows & unix
- isxek 10y agoNot sure if this list is included here, but here's something a friend has used: https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts
- rochacon 10y agocurl https://raw.githubusercontent.com/jmdugan/blocklists/master/corporations/facebook/all | sudo tee -a /etc/hosts
- pixl97 10y agoData straight from the net into a system file as root... You are a bad, bad man Mr Rochacon.
- sdfjkl 10y agoTelling "non tech saavy guys" to pipe URLs into their shell (or hosts file in this instance) is a pretty bad idea. You're training them to engage in risky behaviour and be even more gullible.
- nkrisc 10y agoAll you have to do is copy/paste that into the file using any text editor.
- elcapitan 10y agoOh wow, I didn't know it were that many, I had like 20 in my hosts file. Thanks!
- curiousgal 10y ago>On Windows 7, the default AV security scan will try to remove the # facebook.com entry Wat?
- Namidairo 10y agoI'm guessing some sort of crude malware tried to MitM Facebook logins so they started cleaning host files?
- curiousgal 10y agoInteresting thought. I wonder if it does that to email domains as well.
- walterbell 10y agoMicrosoft was an investor in Facebook, http://whoownsfacebook.com http://whoownsfacebook.com and they are planning an undersea cable between the US and Europe that will only be used by the two companies.
- curiousgal 10y agoWhat for? I can see Trading companies doing that but why would Microsoft/Facebook need that?
- jamesdwilson 10y agothey are trading data
- renaudg 10y agoThis sounds like the most likely reason, rather than the "Microsoft is a FB investor" conspiracy BS. Occam's razor, people.
- midgetjones 10y agoIt is faintly terrifying just how long the list is.
- marios 10y agoConsidering the infrastructure Facebook is running, it's really not IMHO.
- curiousgal 10y agoAny idea of an easy/quick way to toggle these edits on/off on Ubuntu?
- maxschumacher91 10y agoI've put them in my host file and created an alias that switches between naming the host-file "hosts" (which will be recognized by the OS) and hostx. from my .zshrc: #block Twitter, Facebook, reddit and Linkedin. alias on="sudo mv /etc/hostx /etc/hosts" alias off="sudo mv /etc/hosts /etc/hostx"
- curiousgal 10y agoAwesome! Thanks.
- maaaats 10y agoWould wildcard support in hosts files be too heavy for the performance needed? Most of these are subdomains that *.facebook.com would have blocked.
- Namidairo 10y agoMy first impression when I saw it was something along the lines of "this would be so much cleaner if one were writing this as a dnsmasq config"
- Borating 10y agoI agree. From this project I discover FreeContributor [1], which use dnsmasq has a DNSBL. [1] https://github.com/tbds/FreeContributor https://github.com/tbds/FreeContributor
- djKianoosh 10y agoIs it possible to apply this at the network level? I want to update my home router easily so that all devices in my home can benefit, not just my own laptop (since most of these lists are just updating /etc/hosts)
- jlgaddis 10y agoIf your router runs dnsmasq, it should be possible. It would depend upon your router, however, and how much control it allows you over the dnsmasq configuration.
- Borating 10y agoIs it possible to apply this at the network level? Yes. Please check pi-hole project [1] or flash your router with open-wrt/dd-wrt and run dnsmasq with the FreeContributor lists. [1] https://pi-hole.net/ https://pi-hole.net/
- djKianoosh 10y ago
- hallatore 10y agoIsn't Ghostery a better solution for something like this? If we are talking about browsers that is.
- curiousgal 10y agoThis uses less system resources.
- falcolas 10y agoGhostery only works with the web browser. Other apps would be free to continue to embed such links or assets from those locations (and based off my own use of a hosts file, it's more common than I'd like to admit).
- rasz_pl 10y agourlfilter.ini is even better, less resources
- marios 10y agoNot the way I'd do it, since you can easily miss on some new domain that belongs to facebook (or perhaps some server that does not look like it belongs to facebook in the first place, but it is sitting in their assigned subnets). If you really want to block all traffic from/to facebook, lookup the IP prefixes associated with their AS number(AS32934), and setup your firewall to block those. If you are using PF, tables are your friend. With netfilter, consider using ipset.
- Borating 10y agoLike this [1], More details at [2] [1] http://www.commandlinefu.com/commands/view/16096/block-all-facebook-traffic http://www.commandlinefu.com/commands/view/16096/block-all-f... [2] http://www.tcpiputils.com/browse/as/32934 http://www.tcpiputils.com/browse/as/32934
- bogomipz 10y agoWhy would you wait and drop the traffic inbound? Why would you let your browser send the SYNs at all? This rule doesn't make any sense.
- jethro_tell 10y agoBecause most people don't block outbound and certainly not in a stateful way which means it's a poor place or a blacklist. To get this to work outbound, you need to allow all other traffic out (fine that's probably what you are doing already) or have a curated whitelist of other traffic allowed out. I assume this package doesn't want to make that assumption so the safe thing to do is to make an inbound blacklist.
- hueving 10y agoThat doesn't make any sense. You can block outbound just fine by having your block rules followed by a default allow. You don't need anything to be stateful when you are blocking whole IP addresses.
- avree 10y agoIf you're blocking Instagram, shouldn't you be blocking the Oculus Rift site (and any subdomains) too?
- arcticfox 10y agoNot really, Instagram is a social network, Oculus is a device? It depends on the purpose of the list, of course, but for me they're very different.
- entheon 10y agoKnowing corporate org charts for what they tend to be, reporting and analytics initiatives, and any server statistics therein, are considered revenue generating information (leads), and thus subject to agreements for the exchange mutually beneficial data sets. Across my various jobs, I've had to write reports for departments, and open up permissions to internal people, to give read access for things they'd have no natural reason to care about. If data is being collected at all, weird people will be looking at it. If not today, maybe tomorrow. But, no matter when, it's there for the looking whenever some internal lookie-loo decides it might be interesting.
- angry-hacker 10y agoThen what's the whole point of using this blacklist at the first place?!
- stardogg 10y agoI'm wondering ... what's the best approach to automatically collect all domains of a company?
- deleted 10y ago[deleted]
- rolfn 10y agothere is no consistent way of defining the meaning of "all domains of a company". Who pays for the registration? Which email is listed as technical contact? Who has the authority to change DNS-records? Which email listed in the DNS SOA-record?
- jmdugan 10y agoas the maintainer of this resource, for now, I've found no good answer to this question, hence this group project to make the catalogs people may want
- punnerud 10y agoThis does just the same: .facebook.com .facebook.com .fbcdn.com .fbcdn.net .facebook.com.edgekey.net .facebook.com.edgesuite.net .instagram.com .instagramstatic-a.akamaihd.net .instagramstatic-a.akamaihd.net.edgesuite.net .cdninstagram.com .tfbnw.net .whatsapp.com .fbsbx.com facebook-web-clients.appspot.com .fb.me fbcdn-profile-a.akamaihd.net h-ct-m-fbx.fbsbx.com.online-metrix.net ac-h-ct-m-fbx.fbsbx.com.online-metrix.net
- lsaferite 10y agoYou can't do wildcards in a hosts file.
- dredmorbius 10y agoYou can with dnsmasq. http://www.thekelleys.org.uk/dnsmasq/doc.html http://www.thekelleys.org.uk/dnsmasq/doc.html
- cm2187 10y agoI can understand the multiplication of sub domains, to be able to use multiple connections. But what's the rationale for the multiplication of domain names? Ad blocker avoidance?
- robryk 10y agoMaybe separation of cookies?
- deleted 10y ago[deleted]
- jethro_tell 10y agoAlso literally separate domains in the sense that one team probably owns authoritative DNS for fbcdn.com and another probably owns facebook.com. with a big infrastructure, it would be negligent to allow everyone permissions to edit a domain like that. But you probably want to do permissions more like an org chart and less of a hand curated list of people who both have business reason to edit and steady hands/full understanding of DNS. Lots of big infrastructures are pretty much put together like the internet.
- mp3geek 10y agoAlternatively you can use Adblock to block it. https://secure.fanboy.co.nz/fanboy-antifacebook.txt https://secure.fanboy.co.nz/fanboy-antifacebook.txt Disclaimer, list Author.
- avree 10y agoYour list blocks fewer things, though.
- mp3geek 10y agoWhen a site adds Facebook it's using connect.facebook.* the main bulk of the list is just whitelists for Facebook users (first-party). The hosts file will break all of Facebook even if you visit it directly. The better option is to just block Facebook outside of Facebook.
- jjuhl 10y agoNo. The better option is to just block facebook everywhere, including direct access. Just my humble opinion.
- danthejam 10y agoBecause his list blocks facebook in other sites but lets you use facebook itself if you ever want to?
- justsaysmthng 10y agoI'm sorry, I've been away for a couple of hours... What happened ? Why should I (we) block all facebook domains ?
- bbcbasic 10y agoProcrastination perhaps?
- yoo1I 10y agoYou should do nothing. I can think of at least one good reason why I want to do that though: to disable their tracking of non-users on this my computer.
- Thasc 10y agoThis is probably a reaction to the news that Facebook is now officially tracking non-users to create shadow profiles and serve adverts to them off Facebook itself. I think it's the serve-adverts-off-Facebook-itself part that's the actual news; all of the moderately chilling tracking and profile construction was of course happening already. http://www.theverge.com/2016/5/27/11795248/facebook-ad-network-non-users-cookies-plug-ins http://www.theverge.com/2016/5/27/11795248/facebook-ad-netwo...
- r3bl 10y agoAnd yet, Google started going down a similar path since December 2009 when they introduced personalized searches for non-logged-in users and nobody tries to block them.
- jpkeisala 10y agoSlightly off topic: It would be nice to have some kind of extension for Chrome that blocks all Time-Wasting websites with one click. Has anyone seen something like that?
- jpkeisala 10y agoanswering my own guestion... I could have just google it instead of writing my thoughts... https://www.google.com/search?q=un-productive+sites&ie=utf-8&oe=utf-8&client=firefox-b-ab#q=Time-Wasting+websites+extension+ https://www.google.com/search?q=un-productive+sites&ie=utf-8...
- mgiannopoulos 10y agoRescueTime is your friend
- apancik 10y agoI discovered that using https://chrome.google.com/webstore/detail/waitblock/kcnjfeppclpdinikcljfjigoongebpkh https://chrome.google.com/webstore/detail/waitblock/kcnjfepp... to add a delay before opening the time-wasting website actually works better when trying to procrastinate less. Waiting 60 seconds before Fb loads gives you enough time to think about whether you want to visit it, but is also not so inconveniencing that it would make you disable it straight away when you actually want to visit the site.
- aninhumer 10y agoIt's really interesting. It kind of turns your impulsiveness against itself, so your monkey is saying "Ugh, waiting for Facebook is boring, let's do something else."
- gtirloni 10y agoThis extension is really awesome! Thanks for sharing. I usually open some time-wasting website when I'm waiting on some other tasks to finish and it's got so bad I do that even if the wait is <30sec, such is the addiction to these little useless rewards. Now with a wait time on the time-wasting websites, maybe I could use this habit against itself and instead go do something else more productive while I wait.
- zackus 10y agoHi please upvote for me..:( i cant submit
- joeblau 10y agoWill there be a point where the government will step in or is all of this tracking within fair use of non-logged in Facebook users visiting a website?
- lake99 10y agoI doubt it. Judging by history, it's more likely they'll demand access to all that data.
- benevol 10y ago> they'll demand access to all that data Snowden has made it clear that that government grants itself direct access, whatever the legal situation really is. It's also become clear that the government lets itself get away with it. And that there is no resistance from the voters who voted the politicians in and are paying not only for the politicians' salaries but also for their own total surveillance.
- elcapitan 10y agoIf they regulate it, they will probably do it like in the EU where you have to click on some super-annoying "I agree to cookies bla bla bla" thing entering any website, which just trains people to automatically agree.
- chriswarbo 10y agoThat was really frustrating. As a UK Web developer at the time, I understood the ruling as preventing the use of client-side tracking technology without an opt-in; this would have included tracking cookies, supercookies, web beacons, etc., but wouldn't include non-tracking uses required for functionality, like "remember me" tickboxes. It looked like a good first step to tackling rampant privacy violation, but at the last moment the Information Commissioner caved in to bullshit claims that the ruling would cause the collapse of all Web businesses. The enforcement was changed from "not allowed unless opted-in" into "visiting a site counts as opting in". The end result is not only completely ineffective, as it basically changes nothing; it's also resulted in the profileration of ridiculous "by using our site you agree to our use of cookies" messages, which just annoy without doing anything.
- TazeTSchnitzel 10y agoShould you not also include `::` IPv6 entries?
- hellbanner 10y agoThank you! Now I can censor, too
- deleted 10y ago[deleted]
- petrikapu 10y agoDo you how to apply this just for my user on OS X? My partner is heavy FB user and I don't want to block her...
- cheiVia0 10y agouBlock Origin can handle hosts files, so you can just add it on the bottom of the Third Party Filters tab. It will auto-update it too. https://raw.githubusercontent.com/jmdugan/blocklists/master/corporations/facebook/all https://raw.githubusercontent.com/jmdugan/blocklists/master/...
- gorhill 10y agoThough hosts files can be fed to uBlock Origin ("uBO"), it will enforce their content differently. With uBO, a "facebook.com" entry in a hosts file will also cause all subdomains of "facebook.com" to also be blocked, so there is no need to list all subdomains as is done here if the goal is to block "facebook.com" with uBO. If one wants to block Facebook via uBO, I personally advise to do it through dynamic filtering[1]. This way one can always point-and-click to create exceptions on a per-site basis. [1] https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-to-easily-reduce-privacy-exposure https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-to...
- cheiVia0 10y agoWell, if my goal is to block all of Facebook's domains, I wouldn't complain if uBO happens also to block new.sub.domain.fbcdn.net even if it's not in the hosts file :) Does uBO optimize these cases, though? E.g. if there's "apps.facebook.com", "connect.facebook.net" and plain "facebook.com", does it collapse to just 1 filter (facebook.com)? I see it says "880 used out of 881" which is the number of entries in the file.
- blowski 10y agoDoes Gas Mask let you do this?
- zxcvcxz 10y agoHonest question because I seriously don't know: Is facebook really worse than google when it comes to privacy? I kind of wonder who exactly are the people telling everyone to block facebook everywhere while everyone seems to collectively ignore google. Google and facebook seem to both purposely ignore the known implications of their data collection programs. They likely have handed over data to the NSA, and we know they sell the data.
- superuser2 10y agoNot really. We know that they sell ads which can be targeted to users with specific characteristics. If you have discovered actual user data for sale from Google or Facebook, that's news.
- renaudg 10y ago> we know they sell the data Sounds a lot like "we know global warming is fake" and "we know vaccines are evil" to me.
- hanspeter 10y ago> Is facebook really worse than google when it comes to privacy? No. In my view Google (has the potential to) collect a lot more sensitive data than Facebook. All Facebook knows is who my friends are and stuff like what things I like and where I've been - mostly things that I wouldn't mind being public anyway. Google knows everything I search for, every email I receive and every web page I visit.
- labithiotis 10y agoWho really cares?
- kazinator 10y agoIt's inefficient to specify a large number of hosts in the facebook.com domain instead of blocking the whole domain. For this, you can run dnsmasq and use the "--address" option or "address" command in dnsmasq.conf: $ man dnsmasq [...] -A, --address=/<domain>/[domain/]<ipaddr> Specify an IP address to return for any host in the given domains. Queries in the domains are never forwarded and always replied to with the specified IP address which may be IPv4 or IPv6. To give both IPv4 and IPv6 addresses for a domain, use repeated -A flags. Note that /etc/hosts and DHCP leases over‐ ride this for individual names. A common use of this is to redi‐ rect the entire doubleclick.net domain to some friendly local web server to avoid banner ads. The domain specification works in the same was as for --server, with the additional facility that /#/ matches any domain. Thus --address=/#/1.2.3.4 will always return 1.2.3.4 for any query not answered from /etc/hosts or DHCP and not sent to an upstream nameserver by a more spe‐ cific --server directive.
- yrro 10y agoIs there the concept of an 'administratively prohibited' error in the DNS? So your resolver could return an error with that code rather than an incorrect result.
- Borating 10y agoNXDOMAIN [1] ? Dnsmasq can return nxdomain responses echo 'server=/.example.tld/' >> /etc/dnsmasq.conf Check dnsgate [2] or FreeContributor [3] [1] https://www.dnsknowledge.com/whatis/nxdomain-non-existent-domain-2/ https://www.dnsknowledge.com/whatis/nxdomain-non-existent-do... [2] https://github.com/jakeogh/dnsgate https://github.com/jakeogh/dnsgate [3] https://github.com/tbds/FreeContributor https://github.com/tbds/FreeContributor
- fanf2 10y agoSadly not. The closest match is probably SERVFAIL, but that covers all sorts of problems. (SERVFAIL is what a validating recursive server will return if its upstream tries to NXDOMAIN a signed domain.)
- supergirl 10y agodramatic and useless.
- rotoole 10y agoAside from being easier to automate, getting IP's via the ASN lookup is also better for blocking HTTPS requests when you are MITM, since the HTTPS request will only contain the IP and not the FQDN. Also, many firewalls do a 1-time DNS lookup of a given FQDN to resolve a single IP address when a FQDN based rule is created. This doesn't work well if you have an FQDN that can resolve to many different IP's, which is typical for cloud services.
- toast0 10y agoTLS connections from browsers usually include the SNI extension that has the destination host name in clear text. It requires an TLS specific blocker, rather than IP firewalling, but is probably more flexible. You could also just block the names in DNS.
- ausjke 10y agoIMHO the only way to block things efficiently is via a proxy these days, IP/domain-based blocking are not reliable or efficient.
- effie 10y agoWhat can you set up on proxy that you can't set up on your machine?
- Mark_Z 10y agoLittle to late dumbfuck.
- meeper16 10y agoThis is awesome. Facebook needs to go to the graveyard with friendster, myspace and AOL.
- zhong 10y agoNo need do this, come to China prepared everything for you like this.
- personjerry 10y agoWell technically speaking, because of the way the Great Firewall works, you might still be able to get some packets if the server is fast enough.
- hartator 10y agoI would actually do it for Google. But, we all know we have became to dependent on them.
- mickrussom 10y agoIm going to start trying this out. Awesome. Also as marios said block AS32934's networks.
- hackney 10y agoSo awesome. Facebook: Server not found
- iam-TJ 10y agoWith the help of a couple of prefix aggregation tools [1] [2], the BASH shell, and the RIPE database, it is straightforward to block any Autonomous System with, e.g: $ ASN=32934; for IP in 4 6; do \ whois -h riswhois.ripe.net \!${IP/4/g}as${ASN} |\ sed -n '2 p' | tr \ \\n | aggregate${IP/4/} |\ while read NET; do echo ip${IP/4/}tables -I OUTPUT -d ${NET} -j REJECT;\ done; done (note this command uses echo to show the command it could execute) [1] aggregate http://packages.ubuntu.com/source/xenial/aggregate http://packages.ubuntu.com/source/xenial/aggregate [2] aggregate6 https://github.com/job/aggregate6 https://github.com/job/aggregate6
- chriswarbo 10y agoI've been blocking facebook for years (nowhere near as comprehensive as this list though). Many of the most unfortunate problems with these sites are social in nature rather than technical. For example, no matter how much I plead with people not to, they keep uploading information about me to these type of sites, including photographs with timestamps and GPS location metadata, which they then "tag" my face as being me. I don't have any idea how much of this information is even out there, since these sites require signing up in order to find out. Maybe I should look into my rights under data protection legislation...
- ew 10y agoWho are you that you are so worried about this?
- chriswarbo 10y agoThis question sounds a little too close to "nothing to hide, nothing to fear" to me, but in any case I think it's Facebook, attempting to build dossiers on billions of people for profit, who need to justify themselves; not me for wanting to remain undocumented. As far as concrete reasons go, I've had to deal with far too much fallout from being incorrectly flagged by braindead processes trawling private databases which I didn't even know I was in. Since lots of these databases share information, but not necessarily updated corrections, I still run into the same mis-flagging every few years, across utilities, courts, credit agencies, banks, letting agents, etc. As far as Facebook goes, being a citizen of the CCTV-riddled UK makes me acutely aware of the power, and potential abuse, that facial recognition technology can bring; having images of my face tagged and fed into a database does not sit well with me. Since I don't use Facebook, I don't even get the meagre upside of whatever services they build on top of this database (some kind of gallery, I presume).
- flavmartins 10y agoDid you add the Facebook Tor Onion address? facebookcorewwwi.onion Might as well make it a complete block. Make sure those creative types don't find that last alternate path to FB.
- ew 10y agoThis list is missing the very obvious messenger.com