The Inside Story of How Facebook Responded to Tunisian Hacks
theatlantic.com
theatlantic.com
I think this is unnecessary dumbing down.
For most readers who already knows what a keylogger is, it should be fairly obvious to them that this is not what they were doing.
For any reader who does not know what a keylogger is, describing the hack as being like a keylogger is not going to help them understand.
Furthermore, if you are in the demographic that know what a keylogger is, but can't see how that it is obvious that is not what was going on here, it just obscures what was really at play here: authenticating over (unencrypted) HTTP.
The writer probably did not want to make this a story about authenticating over HTTP, but misdescribing a central feature of the story is misleading.
They were injecting a Javascript keylogger, not doing packet sniffing or the like. Not the same as a keylogger actually running on your OS, but I would say still the correct term.
Facebook sends login credentials over HTTPS, they aren't so dumb as to authenticate over HTTP. But they serve their login page over HTTP which is what allowed the Javascript keylogger to be 'installed'.
(edit)
PS Here's a link to the purported exploit: http://www.hackerzvoice.net/node/105
There's a quite successful startup, much beloved by HN, that has exactly this problem with one version of their sign on page. I won't say which one, because I don't want to make targeting too easy. I've been having a back and forth on a support ticket with them, after noticing the problem. They did say they followed up and looked into my concern. But they compared their design to Facebook et al. and said they were following "best practices".
An aside: Once you start using the term "best practices", you need to take a serious look at your design and engineering perspective. Especially in security, your thinking should always be challenging the established model. You may not find a better way, and you should be very skeptical of yourself when you think you have. But you need to be a bit... paranoid, always challenging the "established truths".
EDIT: To that company, if you happen to read this. I posted this after emailing you. And before the coffee fully kicked in. It wasn't my intention to create so blatant a cross reference for you to follow between me here and me in email. (I.e. not some twisted version of karma; just trying to make the point.)
Although admittedly I guess The Atlantic are not targeting the HN crowd.
However, the problem would have been (mostly) avoided by serving the login form over HTTPS. As most people who have used a browser have some notion of HTTPS vs HTTP, couldn't the Atlantic have credited their users with some intelligence, and mentioned the significance of that in the exploit?
Back to Facebook, it had played a very important role and was key to the protests success. In the past, information is spread through word of mouth. There isn't trust, when it's spread that way and also no images or videos. The information that arrives isn't quite adequate.
Emails and forums are good, but due to Video websites censoring, they can't play an important role, since only a few fraction of the Web users in Tunisia can run a proxy.
Facebook changed everything, anti-gov. pages have from 200K to 600K fans. That's more than the half of the connected Tunisian population. In the last days, activity on Facebook was terrible, I would estimate that I post 50 to 100 videos, status and images; same for my friends.
Information spread essentially from these few pages with huge popularity. In a discussion, Admins seems to be using proxies and VPN to make secure connections and they have an anonymous Facebook account to communicate with the protesters (receive videos, photos, and information).
The urgent news would take only 30 minutes at most to spread through the network. Most of my friends, spend all the night (and dawn?) until late 4 and 5 A.M.
You are shown two pictures of the same friend, with the tag of him/her showing (i.e. a square around them, like what you get when you hover over their name in a tagged photo). You are then asked to say which friend of yours it is, choosing from a list of around 7 names.
You can skip as many of these questions as you like, in case you've got pictures where the tag isn't very good (e.g. someone tagged a comic or something instead of an actual photo). But every question you answer has to be correct.
I could see myself getting the answer wrong in this instance even though I know who the person is.
1)how sure can we be that switching to SSL really got rid of the sniffing going on? I'm asking because I assume that it's totally within the capabilities of the government to sneak-install a CA certificate on clients.
Or they don't bother and trust people to just click through the security warning.
2) is that "identify your friends" check maybe a bit pointless as the needed answers can probably be determined using data from already hacked accounts.
3) playing devil's advocate here: if the laws of Tunesia allow for the government to do such things, is it Facebooks place to violate those laws? And: could they be pressed into giving away that data anyways due to political pressure from wherever?
I wouldn't use Facebook to post anything that I would not want a third party to see - unless I encrypted it beforehand.
Of course requiring SSL won't save people from widely-trusted rogue CAs, ignoring all security warnings, or even very active man-in-the-middle attacks which hide from users that SSL was ever being required. But each of those attacks requires a larger investment than tampering with a plain HTTP page.
Same with the social verifier: if the agents had already studied a specific person's network of friends, and need to break that one account, with effort they can. But their previous automatic dragnet was broken.
Facebook may have been in a stickier position if the Tunisian government had attempted a superficially 'legal' demand for user information. But the government didn't. And even if it had, unless Facebook has Tunisian offices/hosting, the government's pull over what Facebook does on its US-based servers would be very limited. To even try ordering Facebook around would have worsened the domestic discontent. (The article reports that it was rumored at one point Facebook would be blocked nationwide.)
Tunisian IPS's were injecting some javascript code on Facebook's login page that was watching the keystrokes in the login/password fields. When someone clicked LOGIN, the script would send those credentials to a URL, but also Facebook's HTTPS login page, so everything proceeded as normal.
Interesting vector for an attack, seems like the solution, of serving the login page itself in HTTPS as well is simple (and cheap) enough that everybody should adopt it.
Right, for all those pre-21st century sites that still don't enforce SSL for authorization. It should be a standard, not a counter-measure.
In short, there were indications that the government was swiping passwords on each new Facebook login. Within days, Facebook switched all Tunisian sessions to HTTPS, and required people whose passwords had likely been compromised to go through a password-reset based on identifying pictures of friends.
(Also, the article suggests that Facebook is a more important news and organizing outlet in Tunisia than Twitter.)
As for the anonymous activism - the power with Facebook is the real identities attached. People believe it because they know and trust the people sharing the news and images. Twitter tends to degenerate into a retweeting mess of platitudes around any major news event, and the anonymous nature of most tweets makes exaggerations and rumors spread like wildfire.
It doesn't sound like a directed attack on facebook, though perhaps it was a session replay attack.
The real question for me, is why didn't facebook already require SSL login.
Nope, Facebook's login page, if requested over http, was manipulated on the fly to inject a javascript code that is triggered when the login button is clicked. It retrieves the login/password values from the form and sends them to another url, besides Facebook's login url.
This is not to take away from the truthfulness of the story or the awesomeness of Facebook's response. In fact, given how prominently Twitter has featured in stories about the Iranian revolution et al, this is to be expected.
It is not simply a case of sniffing traffic. They log what users input into the login form, via Javascript injection.
The issue seems to be that code is injected in pages that merely contained a login form: http://blog.rootshell.be/2011/01/13/tunisia-tracks-users-wit...