4 ms·
> Firstly, Onion service are very slow. There is no need to pay this cost for a service whose ownership is not actually hidden. As long as you don't have to us
by justcommenting 12y ago
> Firstly, Onion service are very slow. There is no need to pay this cost for a service whose ownership is not actually hidden.
As long as you don't have to use it, I don't see why offering users a choice is a problem.
>If the Tor project made it easier to reliably identify traffic from Tor exit nodes, Facebook could apply whatever rules they wanted to Tor traffic without needing to slow things down for everyone.
ExoneraTor does this quite well in my opinion, and I don't follow how/why you think this will slow things down for everyone. Surely you're not referring to the entire Tor network?
The main value in using this, in my opinion, is reducing the potential attack surface associated with MITM attacks--including CDNs--after your traffic exits Tor. Attacks on Facebook users involving Akamai have been documented by NSA, for example; Facebook is a PRISM partner, but this would arguably still stack the deck in favor of "going through the front door" to access Facebook user data.
- mike_hearn 12y agoAccessing an .onion address via Tor is slower than accessing a normal website via Tor. If this onion service is now the official way to access Facebook via Tor and direct access doesn't work well, then this is slowing things down. Tor's current support for detecting usage is patchy. You can't query a random third party website for every login for a system like Facebook, so you need a list of IPs that can be refreshed quickly. But such lists tend to be incomplete or behind e.g. the "exit" flag doesn't mean what you'd intuitively expect, so it's sometimes possible for Tor traffic to turn up from an IP that is not identified as an exit. Re: MITM security. Even if Facebook got lucky here, we're talking about an 80 bit identifier and brute forcing these has been demonstrated before, I believe. I'm not sure this is much of an upgrade over just regular SSL CA + HSTS pinning. (edit: last paragraph)
- justcommenting 12y ago> If this onion service is now the official way to access Facebook via Tor and direct access doesn't work well, then this is slowing things down. my take on the post was that it was presented as an option, and for users taking the time to access a site via tor, speed may not be the only (or even primary) consideration. i say that as someone who does ~95% of my browsing--both work and personal--via Tor. > But such lists tend to be incomplete or behind e.g. the "exit" flag doesn't mean what you'd intuitively expect, so it's sometimes possible for Tor traffic to turn up from an IP that is not identified as an exit. Doesn't the onion address solve this problem? > I'm not sure this is much of an upgrade over just regular SSL CA + HSTS pinning. Depends on your threat model, but I think it's a useful option and congratulate the Facebook team for offering it to users. I'd love to see Google, Twitter, and others start to compete on the extent to which they support TBB users.
- mike_hearn 12y agoYes, you're right, it's just an option and presumably access via the regular web address will still work. It may be that the hidden service is a way to identify Tor traffic, but it shouldn't really be necessary to do that if Tor had the right support in it. And of course you cannot assume everyone who uses Facebook via Tor will know about this service, unless TBB itself is adjusted to force usage, in which case you're now changing Tor and could as well make exit identification 100% reliable.
- neltnerb 12y agoYou effectively use Tor 95% of the time? This surprises me, actually. I think if I used it that much I would unavoidably lose my anonymity. Here is my worry -- Tor looks easy to use, but requires habit changes to actually be effective for anonymity. The habit changes that I am led to believe are required for any effective anonymity through Tor scream "NO NO NO NO NO!!!" at the idea of logging into javascript requiring, cookie placing, Facebook. This seems to me like a situation where the illusion of anonymity might be worse than the reality of non-anonymity. Granted, it lets you bypass censorship. Granted, if you are very careful and, say, only use your Tor Browser to connect to Facebook and nothing else whatsoever... maybe. I just don't think I could trust myself to do it properly. And while I'm no Edward Snowden, I'm also not dumb.