Block Facebook Servers
github.com
github.com
Facebook Container
https://addons.mozilla.org/en-US/firefox/addon/facebook-cont...
That doesn't mean it is everything... but it at least makes that a little more likely? Some light optimism for you, I guess.
Edit: seems even this isn't necessarily true.. damn.
lol
I guess I though it would be something like https://www.facebook.com/shadow_profile_activity
How this is legal under GDPR, given I'm a UK citizen, I'm really not sure.
Also, I'm not sure about this "immediately enforceable" part - I recall some cases where member states delayed implementing EU laws for years, sometimes ending up being sued to European Court of Justice.
AFAIK it works pretty much the same in all countries and only depends on whether it's an EU regulation[0] or an EU directive[1].
[0]: https://en.wikipedia.org/wiki/Regulation_(European_Union)
[1]: https://en.wikipedia.org/wiki/Directive_(European_Union)
As the GDPR is a regulation, it directly applied to member states.
When the UK left the EU they made a paralled law
> The GDPR has been incorporated into UK data protection law as the UK GDPR see: https://ico.org.uk/for-organisations/dp-at-the-end-of-the-tr...
"You have the right to find out if an organisation is using or storing your personal data. This is called the right of access. You exercise this right by asking for a copy of the data, which is commonly known as making a 'subject access request"
[1] https://en.wikipedia.org/wiki/Data_Protection_Act_2018
[2] https://ico.org.uk/your-data-matters/your-right-to-get-copie...
https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
...which includes the downtown Palo Alto address, hah. It’s linked from facebook.com/peering/
Here’s a list of the IP prefixes:
whois -h whois.radb.net -- '-i origin AS32934' | grep ^route
Source: https://developers.facebook.com/docs/sharing/webmasters/craw...https://github.com/smigniot/smigniot.github.io/blob/master/i...
For the google part I had to recurse through the AS list first, and perform cidr merging
However I can't seem to find the --match-set option for my Android's iptables version. I Will test.
https://whois.arin.net/rest/net/NET-63-150-141-224-1.html
is Facebook's range not included above.
$ sudo nmap -sn 63.150.141.224-231
[sudo] password for alice:
Starting Nmap 7.40 ( https://nmap.org ) at 2021-02-11 06:41 CET
Nmap done: 8 IP addresses (0 hosts up) scanned in 9.15 secondsThe links contain the IP ranges (4 and 6). Testing all those should be sufficient.
There are some small ranges in RIPE too: https://apps.db.ripe.net/db-web-ui/query?searchtext=facebook
Those RADb responses include this line:
mnt-by: MAINT-AS32934
AS32934 is the account maintaining Facebook's public presence(s)? How'd you figure that out?Using routing table mainteners to DNS entries seems like a terrific why to create those ad-blocking lists. Is this how it's done? I always assumed those lists are manually collated and curated.
In the 80s these would be bunched up by org in nice ways just like how phone numbers that were all in the same place would share an area code. MIT would be 1.1.x.y and you’d route their data to Cambridge MA. IBM would be 2.x.y.z and you’d route to them and let them deal with it internally. Some small outfit in France might’ve gotten 173.4.5.q: you’d send their data into the Atlantic fibre because “173.something” meant “Europe” and let the other end figure it out.
In the 90s it all got messy because 32bits wasn’t enough to keep things in a clean hierarchy that reflected how data was routed around the net. Orgs ended up accumulating fragments of IP address space from all over the place for the hosts at their physical site. The hierarchy of the address couldn’t tell you how to route traffic and the rules for routing became highly extensive and dynamic.
Enter Autonomous Systems Numbers and BGP. It’s a layer on top of IP addressing that only matters to internet core routers with many choices as to how to your traffic (“multi homed” sites). It helps map IP addresses to actual places — internet peers, aka fellow ISPs — so they can agree with each other how traffic should be routed. BGP lets peers keep these routes updated and let’s you know who owns what.
None of this matters if you have a single internet connection. Routing is easy: it’s either “local” or you send it to your ISP. But if you’re an ISP in the centre how do you know who gets what? You use The [Internet] Routing Table as maintained by the BGP system.
Some companies have so much traffic they have their own ASN. Because the internet is open, you get to see all the IP addresses which are bundled up inside that ASN, which is what I was linking to. It only works because FB is its own self-serving ISP with its own ASN.
(With IPv6 this should all have gone away not because of the number of addresses, but because the address space was 128-bits wide. You could hierarchically route 256 towns in 256 counties in 256 states in 256 countries and still only have used half the hierarchy. ISPs usually get a /32 of this but Facebook announce a bunch of /48s which I don’t understand.)
Use both methods instead of just one. They differ in nature, and can be implemented at different perimeters of your network. Maybe there exists certain chokeholds in the network where multiple devices can be protected in one go?
Personally, I would have pure IP blackhole routing performed in the router providing WAN access to internal networks. A blanket protection for all desktops and 802.11 devices inside.
Many devices today are locked-down and editing hosts records can be untrivial. Instead of relying on 0.0.0.0 routing through hosts, the same effect can be obtained by setting up a personal DNS server e.g. bind9 with RPZ's listing the targeted domains[1].
Why all that hassle? Because an unrooted smartphone with a Wireguard link to the DNS server (or full-on VPN using that DNS server), can have lookups made through the server you control. And that DNS service is available to use on any local network/Wi-Fi one has to use. IIRC 3G/4G/5G WAN routes were harder to get right, but I think it was possible. One could always route all traffic through a purposeful VPN.
Defense in depth.
---
[1]: fb.rpz.zone:
;RPZ $TTL 10 @ IN SOA rpz.zone. rpz.zone. ( 37; 3600; 300; 86400; 60 ) IN NS localhost.
.facebook.com IN A 0.0.0.0 .facebook.net IN A 0.0.0.0 .fbcdn.com IN A 0.0.0.0 .fbsbx.com IN A 0.0.0.0 .fbcdn.net IN A 0.0.0.0 .edgesuite.net IN A 0.0.0.0
The first rule of running a megacorp is... oh, wait.
This is also why companies like Tealium and Segment are now worth billions of dollars. They provide a single integration point that funnels events to dozens of marketing companies' server-side APIs.
Sounds like they make the blocklist-curators' job easier.
If "the sites you visit" are the ones talking to Tealiums and Segments, it is trivial for "the sites you visit" to lie about the browser IP address and make it look like requests are coming from all over the world instead of just one box sitting under $FRAUDSTER's desk running a script.
For logged in users, it's trivial to match users across sites with an email address or a phone number.
If you're clicking between sites, there may be a unique ID appended to the outbound URL (on Google there's a gclid URL parameter). This ID will be logged on the destination site and can be continuously passed around to identify the same user on multiple sites.
If they don't need perfect matching, they'll use IP addresses, user agents, and other fingerprinting techniques for fuzzy matches.
Disabling Javascript and using a forward proxy, it is easy to not send User Agents and other points needed for fingerprinting.
Tracking IP address is expected and will always be acceptable. All the rest is stuff users are voluntarily transmitting even when it is not necessary, making tracking much easier and more productive for the marketers.
There are many tactics to make tracking much more difficult and more expensive. However, few are using them.
Is this the reason why so many websites log you out on their own? Like, you go to do something on a website that requires an account but you see a login form instead. No one wants that. Everyone hates that. IMO if you're using the concept of time in your session management code, you're doing it wrong.
Do bank websites let you "stay logged in" for hours, days, weeks, or longer because you have some cookie you received when you logged in some time in the past. Are they "doing it wrong".
Facebook and Google are recognized as processors in this situation. The websites that send them the data are the controllers and are subject to the vast majority of the regulation, while the processors can assume that the controller has obtained user consent until informed otherwise.
It's legally important to recognize that Facebook and Google are not blindly sucking up data from around the internet. Websites/apps are actively transmitting this data to them and other adtech platforms for their own benefits.
This can do a lot more than a normal VPN or DNS blocker because it's actually intercepting and decrypting HTTPS traffic (rather than just passing it through).
However, Facebook has been very good at making ads that are hard to block, even if you have access to everything. They've been pretty aggressive about getting around things like uBlock Origin even on desktop browsers.
DNS-based blocking also likely wouldn't have much impact on a company that could serve ad content and regular content off the same domain names - or that could just rotate domain names too much.
Also, AdGuard's local-VPN/HTTPS-intercepting feature is a pay-for feature (I believe $5/year or a $10 one-time charge).
I use this app which, among other things, lets you hook up remote sources as block lists: https://apps.apple.com/us/app/adblock/id691121579
This means you can for example hook it up directly to this repository (which I've done) and automatically get updated lists
Go to your rules window, in the bottom left there is plus and by clicking you reveal the option to add "rule group subscriptions" https://help.obdev.at/littlesnitch4/lsc-rule-group-subscript...
The same can be done in a hosts file.
E.g.
address=/facebook.com/0.0.0.0 address=/fbcdn.net/0.0.0.0
Also block DoT ports, all known DoH resolvers (real pain in the ass), VPN services and proxy sites for the best results.
Yes, the whole point of DoH is to make it harder for us to keep control over our equipment
Search by organization for Facebook, then click each organization and then, Related Networks