1M People Use Facebook Over Tor
facebook.com
facebook.com
I don't know if the story behind the facebookcorewwwi.onion domain name itself has been talked about much, but we wanted a memorable name for the domain so we took a new cluster that hadn't been put in production yet and threw something like 500k cores at brute forcing onion names till we had a memorable domain name. Alec had a script that looked for hashes that started with facebook and then he picked the one that seemed to fit the most. And that's how we have facebookcorewwwi.onion now.
Facebook must have generated an awful lot of key pairs to get "facebookcorewwwi". By the way, I hope they deleted the other generated pairs…
I do think he also mentioned that they only cared about keys that had their required prefix; all others were destroyed without anyone ever having access to them.
Okay, that is what I was implying would be terrible otherwise. But actually it is quite obvious that they would not spend the disk space necessary the keep every single generated key pairs now that I think about it.
Finding that same one again? Not likely.
Since onion addresses are essentially random strings of a certain length, the only way to get a "vanity" onion address is to brute force it.
Edit: probably wrong, see below
So they might have just set it to filter for facebook[dictionaryword]+ and this was the best match.
* Actually any address, it's not limited to brute forcing vanity addresses.
But for the non-hash-aware among us, it would take on average 2,147,483,647 as long to brute force the last 8 with the same computing power and 4,294,967,295 as long to hash every combination of the last 8. This all assumes no vulnerabilities in the algorithm, of course.
According to this person's math [1]: "It would take ~6.7e40 times longer than the age of the universe to exhaust half of the keyspace of a AES-256 key"
I don't know if Tor uses AES-256, but I'm sure any reasonable encryption algorithm would be similar.
[1] https://www.reddit.com/r/theydidthemath/comments/1x50xl/time...
The time calculation assumes our current computers and disregards Moore's law.
> It would take 10^38 Tianhe-2 Supercomputers running for the entirety of the existence of everything to exhaust half of the keyspace of a AES-256 key.
Let's assume that Moore's law is true for forever. In 300 years we will have a super computer capable of cracking a single AES-256 key in 37 millennium. However claiming that Moore's law will stay the same for 300 years when many think it won't last 30 is foolhardy.
What? Why is brute force impossible to code? I don't understand what you're claiming.
I agree that adding in Moore's law doesn't change the numbers by much. Moore's law plus weakening of cryptographic assumptions might do it, though. Plenty of previously-believed-to-be-strong crypto algorithms have been cracked, it's reasonable to think that we just don't have the tools to create unbreakable codes yet. (E.g. RSA is known to be breakable with quantum computers with Shor's algorithm.)
You claim that a reversible algorithm takes zero time. I said that requires a reversible algorithm that applies to an arbitrary AES-256 key which is currently thought to be impossible.
Brute forcing is not breaking but instead simply enumerating the key space and is subject to the slow downs we are talking about here.
> I agree that adding in Moore's law doesn't change the numbers by much. Moore's law plus weakening of cryptographic assumptions might do it, though. Plenty of previously-believed-to-be-strong crypto algorithms have been cracked, it's reasonable to think that we just don't have the tools to create unbreakable codes yet. (E.g. RSA is known to be breakable with quantum computers with Shor's algorithm.)
But you are missing the point of cryptographic systems, the goal typically isn't to be forever uncrackable, it is to be effectively forever uncrackable which includes upgrading the strength of your cryptography over time.
If we were talking about cracking crypto within 100 years then maybe we could talk about reasonable fear, but all of these things involve timelines that are longer than that (including quantum computer work).
No, you misread my comment. Reversible computing can take almost no energy.
[1] https://news.ycombinator.com/item?id=11388997 [2] https://blog.cloudflare.com/the-trouble-with-tor/
Check out mapgrep's comment on another thread below for a more in depth answer, too.
I don't remember how long we ran it for, but IIRC we had enough candidates to stop after a week or two. I'm guessing something like 100-200M cpu hours?
[1] https://en.wikipedia.org/wiki/List_of_most_expensive_domain_...
That each of those cores are billions of times faster than my first PC just puts the icing on the cake.
Isn't TOR encrypted up to a hidden service anyway? Why would you HTTPS over TOR? Honest Question.
Edit: the original comment I replied to stated that exit nodes could sniff traffic.
Reply to new comment:
The connection is encrypted to the service's public key, what are you talking about? Stop spreading nonsense and go read documentation.
blockchainbdgpzk.onion
I'm pretty sure it's the second most trafficked site after FB
If anyone is looking at setting up a hidden service and wants a memorable name I still have the cluster setup.
Matching 10 characters isn't much of a challenge - it's why hidden service addressed on their own don't provide identity authentication and why we both went with SSL cents for Tor hidden services (provided by Digicert - who have been great advocates for the cause)
I do not trust your company, and I think you are bound to act unethically in the future. But I do not ask you to become a trustworthy ethical company. Mess with the accounts of my friends all you want. I just want to be invited to the next BBQ. People have stopped using e-mail for announcing these social events, and _all_ use Facebook. Could it be possible for me to not be on Facebook, yet still stay up-to-date on what my friends, or hell, even my parents now, are doing? A more advanced social graph API that hooks into email, RSS, Twitter, whatever... ?
I'm sure you also have my email-address from the address books of my contacts, so you could verify me.
As one of your longest non-users (I remember when TheFacebook required a Harvard-email for invite), please let me become a semi-user. It won't pay you a dime, but it will make the world a better place.
But for viewing what your friends and parents are doing on Facebook? Well, they could change their privacy settings to be public, but that would hurt their privacy. You want to be in their social graph, but not have a Facebook account. What does that even mean? Do you just not want to have a password? There's no rule you have to post any content, if you just want to view other's.
This stops after a while. Even when you stay a pleasant person, you'll always be "that guy" requiring an extra action to contact. The social ripple/ping of an event stays inside Facebook.
> You want to be in their social graph, but not have a Facebook account.
In the ideal form this would be a totally open protocol (with backing of Facebook, Google, ... and W3C).
In the current form, I do not know enough about Facebook to suggest a good system. Yes. I want to be in their social graph, but not have a Facebook account or be under Facebook TOS. If that is meaningless at the moment, maybe we should make it mean something.
They can, but they generally don't.
They'll still get -some- data off you, but frankly it's a lot of the same data they would get even if you didn't have an account.
You won't convince your social group to delete their Facebook account. You may, however, convince them that you are not cool.
I'll probably take the other advice, open a new account, use a week for invites, turn on email-updates, and bite the bullet.
So, I wasn't able to login via TOR via the purposefully created .onion address. Also, sent an issue report via non-TOR login about this, but never got any response.
Note also that this seems to mean to me, that there may be people who are cut off from FB via TOR same as me, but who don't even have a way to notify FB about the fact. And thus not having any chance of having the bug fixed.
It sounds like the test was just broken.
Start enforcing it heavily and the people that DO use those services may start protesting or moving into activist roles.
Cracking down on college students seems like a really dumb idea.
https://en.wikipedia.org/wiki/Tiananmen_Square_protests_of_1...
The process is described in "Part three" here: https://blog.torproject.org/blog/facebook-hidden-services-an...
"The short answer is that for the first half of it ('facebook'), which is only 40 bits, they generated keys over and over until they got some keys whose first 40 bits of the hash matched the string they wanted."
"Then they had some keys whose name started with 'facebook', and they looked at the second half of each of them to pick out the ones with pronouncable and thus memorable syllables. The 'corewwwi' one looked best to them — meaning they could come up with a story about why that's a reasonable name for Facebook to use — so they went with it."
(Corrected: Hash of public key not private key per itsbenweeks below)
..."a base32 encoding of a 10-octet hash of Bob's service's public key" https://gitweb.torproject.org/torspec.git/tree/rend-spec.txt...
1. race condition?
2. waste of key space?
2. You can't "register" key. If some person manage to generate key with same vanity he can use same address as facebook, but practically this is nearly impossible. And if that happen this can be easily detected by facebook so they can just change official key.
To make this more clear, most tor hidden service sites that don't have loads of computing power to bruteforce a vanity domain have uris that look like http://3g2upl4pq6kufc4m.onion
If you are in a country or organization that would prefer you not visit Facebook, this can be useful.
If you would prefer that Facebook not know your location and IP address, this can be useful.
Obviously if you log into a Facebook account with your real-world identity then all actions performed on the site will be linked with it, but that is expected.
It doesn't make sense to not allow the user to access certain sites, but allow Tor that can easily bypass that protection.
talk from the 23c3 about tor and china: https://www.youtube.com/watch?v=P6A7jLpL3Rs
Now, for some of the reasons why you'd want to use Facebook via Tor, it might not matter much - using Facebook might be bad enough (eg: it could be considered subverting state censorship) -- so if Facebook is already colluding with your adversary, just having a Facebook account might be enough to give you problems.
It might be enough for a legal veneer of plausible deny-ability, although I doubt it: Eg, perhaps you're a drone pilot and you login to Facebook via Tor, and paste in a gpg-encrypted, ascii-armored text-message to a journalist on Facebook. You could claim someone must've hacked your account. Or you could collude with someone else, and "borrow" their account. I don't think it'd keep you out prison though.
The ingenuiety of the hidden service is that FB basically inverted Tor's idea. Tor is really good at bypassing restrictive net filters, while at the same time it hides your browsing destination. So in effect FB turned a Tor address into their own highly resilient web proxy. Where a proxy normally provides a guarded way out of a network, the hidden service provides an otherwise untraceable way in.
Now, technically it is ~possible to identify FB-Tor traffic from regular Tor traffic. At least in some sense. Because the address is inside the .onion network, there are only half as many routing hops between the client and the server. So if you, as a well funded governmental adversary, first identify nearly all Tor traffic, you can then see which clients receive their responses notably faster than the rest.
These faster roundtrips are very likely using hidden services. If you then drill down even further, I am sure you should be able to identify a reasonably large fraction of your own subjects who are clearly accessing FB and thus stepping around the nationally imposed censure.
For the record, Alec didn't consider the above traffic analysis attack particularly feasible. And we both agreed that the straightforward solution is to get a lot more traffic for hidden services in general. Once FB is not the sole huge site with a hidden service, their traffic cannot stand out.
This came up in a discussion we had. FB is proposing (and funding) development that would make hidden services faster. One of the measures would be to make [some?] hidden services reachable over 3 hops only.
A quick search does not bring anything on the topic up, but it can easily be that I try to search for wrong key words.
But anyway, why would a hidden service with 3 hops look different than a clearnet site visited over tor and 3 hops?
So under the faster onion routing, when accessing FB.onion your roundtrip is total of 6 hops. Hops 3 and 4 will be made to an edge node network, so the "last hop in" and "first hop out" will be, on average, faster. Even if the circuit was reconfigured midway through the session, the fast innermost hop would still exist.[~]
It's just another timing attack, with passive traffic analysis. I wonder how much one could do with active attacks.
~: I have no knowledge how FB has configured their Tor network connectivity, but I do know that the private key is not held on a single termination point. (The traffic volume is too much for a standalone node.) Hence I am making an educated guess that their onion address is advertised from multiple edge systems.
(I suppose that different protocols are being used that have different times, but that seems negligible; wouldn't bet on that though.)
When using a public site over Tor, the connection looks like this:
1. User connects to a relatively nearby entry node (guard) [hop #1]
2. Guard node routes the packet via a relay [hop #2]
3. Relay routes the packet to an exit node [hop #3]
4. Exit node routes the packet out of the Tor network, and has responsibility for finding the actual destination. Even for a globally available high-traffic site the route from exit node to the nearest edge node has to travel across a couple of networks.
Now, under the proposed 3-hop hidden service protocol - when user accesses a hidden service, I had understood that the "exit node" is replaced by the hidden service itself. So the connection would look like this:
1. User connects to a nearby guard node [hop #1]
2. Guard node routes the packet to a relay [hop #2]
3. Relay node routes the packet to the hidden service [hop #3]
4. There is no step four. The packet has been delivered to its destination network.
For a random hidden service this probably wouldn't matter much, but if/when the third hop is provided by a globally accessible edge network, the latency between relay and final destination should be quite good.
With the elimination of post-Tor routing steps, and with the constantly better latency from relay to the hidden service, I expect the overall latency for this particular Tor circuit to be measurably lower. After all, there are no public hops beyond the circuit termination nodes. So from traffic analysis point of view, Tor/FB traffic should stand out from other Tor traffic.
And I think I found some references, at last. Search for "Direct Onion Services: Fast-but-not-hidden services" draft discussion on tor-dev archives.
Anyway, skipping the third hop would decrease user anonymity, because you'd only need two relays to cooperate to identify the user and who they're connecting to. Regular tor requires all three to cooperate.
The proposal uses a rendezvous point instead of an exit node, but that shouldn't affect speed as far as I see.
They make money from knowing who people are, and selling that. This cleaves the driving tor concept by deanonymizing users.
For anybody as large as Facebook, if enough people go for it, the remaining slice of the pie will be really small (because not all have tor, but many of those that have, have Fb).
Derive conclusions accordingly.
There are a few attempts designed to make TOR look more like standard web traffic, which are really interesting.
It's definitely a cat-and-mouse-style game. Some have more success than others.
You don't get mobile notifications this way, so I just get my notifications via email instead. And I uploaded my public PGP key to Facebook, so the emails they send me are encrypted. Getting notifications via email also means that Facebook doesn't even know if or when I've read a particular notification.
To read those encrypted emails on my phone I use K-9 Mail with OpenKeyChain. My Yubikey Neo acts like a smart card reader to my phone over NFC so I don't need to give my phone direct access to my secret PGP key.
This setup works for me because I try to limit my Facebook usage, keep my number of "friends" on there to a minimum, and lie to Facebook whenever they want me to explicitly supply information.
in theory the only thing you're leaking over a plain https is, "Hey this guy has friends." (this connection is visiting facebook).
meanwhile in theory I'd expect facebook to leak everything else on their end, because come on. I have next to zero expectation of privacy on facebook.
by that I mean you think people are planning terrorist plots over facebook? come on.
so I find the mashup of tor with facebook to be kind of bizarre.
So what I've written:
>so I find the mashup of tor with facebook to be kind of bizarre.
is even more so if anyone's reason is "I really, really, don't want facebook to know where I am!" I mean I just don't get it. Especially to the tune of 1 million people.
Your real profile and location can be inferred from your browsing habbits and friend's data.
Unfortunately, with the current size of Facebook, even "not having an active Facebook account" shares data, especially when you are in an age category where all your peers do have profiles. It's a negative signal to recruiters and employers ("must have something to hide...").
Fuck them. Is this the line of thinking you want to align your live to?
We need to work together to stop that from happening. In the end the best fake profile win's and it's a competition in hiding your sins. Medieval ages called and complained that you used them to compare to this mess.
Every second/third? totally fine, everything perfect guy has some unhealthy addiction but the guy who uses Tor for playing around or ordering drugs is suspicious? It's laughable. You only get some collections of narcissists and psychopaths as employees that still do occasionally harm to your company and use drugs like everyone else.
What the fuck is going on. It's 2016 and I'm feeling like 1516.
Also Iran (likely others) did try to inject tracking JS in plain HTTP and they got the ability for a while to have valid certs so HTTPS is not really helping if you are not really paranoid with certs and hashes that is really difficult to archive.
Once you got Tor running and connect to an onion you have quite a few guarantees that are hard to circumvent/spy on for a government.
> by that I mean you think people are planning terrorist plots over facebook? come on.
It sure has likely happened. Due to Facebook only access (internet.org) for a lot of the world using mobile and Facebook is the only access to internet that is affordable. Online shopping is also handled over Facebook in these countries.
While Facebook shares your data with courts it has no way of knowing who you are if you are using Tor. At least it can't forward your location to the local secret service to beat you up. A somewhat qualified court request from a western country is also something different than arbitrary repression from dictatorships.
No capchas.
There are search engine(s) specialized for TOR. As per Wikipedia[1]: 'Ahmia is a clearnet search engine for Tor's hidden services'. It was part of Google summer of code in 2014[2].
[1] https://en.wikipedia.org/wiki/Ahmia [2] https://blog.torproject.org/category/tags/gsoc-2014
[0] https://www.facebook.com/notes/protect-the-graph/making-conn...
Traffic directed to hidden services never "leaves" the TOR network, so it doesn't hand over any control to exit nodes and the (possibly malicious) people running them.