Facebook has started to encrypt links to counter privacy-improving URL Stripping
ghacks.net
ghacks.net
I have no idea if it's doable in this FB context, but usually when links can't be anonymized, the next move is to make them produce irrelevant data by adding noise.
But quite doable for a content provider like Ghacks. Users should be able to share links to web content in a way that does not create privacy risks, and this whole URI encryption business makes that quite a bit harder.
Except if you look at the documentation for AdNauseam, their fake click technique seems trivially filterable. The fake clicks are made as XHR requests, so all you have to do is look at the appropriate headers to filter them out. At best the only adtech companies that are getting fooled by this are upstarts that haven't added fraud detection yet.
https://github.com/dhowe/adnauseam/wiki/FAQ#how-does-adnause...
(And to be clear - I could be missing something. Does the browser allow replacing e.g Sec-* headers on XHR requests?)
Probably not, according to this snippet from MDN
> With this information a server can implement a resource isolation policy, allowing external sites to request only those resources that are intended for sharing, and that are used appropriately. This approach can help mitigate common cross-site web vulnerabilities such as CSRF, Cross-site Script Inclusion('XSSI'), timing attacks, and cross-origin information leaks.
https://developer.mozilla.org/en-US/docs/Glossary/Fetch_meta...
being able to override it kills the whole point of the headers.
I can't understand the people saying there is a free market choice here, this can only be solved with simple regulation that targest large platforms.
If the SEC can use its judgement on what constitutes a security, than we can have a social media comission to oversee Facebook.
The mental health benefits of leaving Facebook are worth it.
If you have a friend of a friend who you add on socials, and then you see their updates, and then you see them at a mutual party, despite not being well acquainted you are reasonably up to date with their lives. This can make the conversation flow better and you may form a meaningful connection.
But at times it's impossible in practice: my friends will create Whatsapp groups for instance to plan vacations/batchelor parties/random events, and I need to use that if I want any meaningful involvment in the event.
I've sometimes been passive and just showed up, but I'm losing a part of the shared experience.
Turns out a lot of people had this problem, so I made it into a company.
I don't want to blatantly advertise but let me know if you'd like me to link the website.
stretch that out a bit and it will fit - facebook controls your browser by infiltrating commands packed into an encrypted string.
that looks alot like what C&C servers do, the next step would be dropping a bot into users systems
There could be other reasons for this, but evading firefox rewriting links seems most likely - some gateways strip too-long query strings for example, but will leave the rest of the URL alone.
Uhm. What?
$ echo "0RjTS7KpBAGt9FHp5vCNmRJsnmBudyqRsPC7ovp8sh2EWFxve1Mk2HaGTKoRSuVKpl" | base64 -D | xxd
00000000: d118 d34b b2a9 0401 adf4 51e9 e6f0 8d99 ...K......Q.....
00000010: 126c 9e60 6e77 2a91 b0f0 bba2 fa7c b21d .l.`nw*......|..
00000020: 8458 5c6f 7b53 24d8 7686 4caa 114a e54a .X\o{S$.v.L..J.J
$ echo "AZXT7WeYMEs7icO80N5ynjE2WpFuQK61pIv4kMN-dnAz27-UrYqrkv52_hQlS_TuPd8dGUNLawATILFs55sMUJvH7SFRqb_WcD6CCOX_zYdsebOW0TWyJ9gT2vxBJPZiAaEaac_zQBShE-UEJfatT-JMQT5-bvmrLz7NlgwSeL6fGKH9oY9uepTio0BHyCmoY1A" | base64 -D | xxd
00000000: 0195 d3ed 6798 304b 3b89 c3bc d0de 729e ....g.0K;.....r.
00000010: 3136 5a91 6e40 aeb5 a48b f890 c37e 7670 16Z.n@.......~vp
00000020: 33db bf94 ad8a ab92 fe76 fe14 254b f4ee 3........v..%K..
00000030: 3ddf 1d19 434b 6b00 1320 b16c e79b 0c50 =...CKk.. .l...P
00000040: 9bc7 ed21 51a9 bfd6 703e 8208 e5ff cd87 ...!Q...p>......
00000050: 6c79 b396 d135 b227 d813 dafc 4124 f662 ly...5.'....A$.b
00000060: 01a1 1a69 cff3 4014 a113 e504 25f6 ad4f ...i..@.....%..O
00000070: e24c 413e 7e6e f9ab 2f3e cd96 0c12 78be .LA>~n../>....x.
00000080: 9f18 a1fd a18f 6e7a 94e2 a340 47c8 29a8 ......nz...@G.).
This doesn't look to me like unencrypted serialized data. Serialization would usually have some visible structure to it and possibly visible ASCII strings. Also notice that the lengths of both strings are aligned to 16 bytes — this might mean AES block encryption.Ask HN: What is with the new URLs on facebook.com? - https://news.ycombinator.com/item?id=32117489 - July 2022 (249 comments)
Modifying URLs and filtering page content should be the responsibility of extensions and the like. I personally use a filtering proxy.
This is like the argument that the Do Not Track flag was illegitimate if the browser defaulted it to 'on'. An argument that is never applied to tracking or the countless "by visiting this webpage you consent to.."
If the reader follows the "People who reacted" URL, then the reader can see the story_fbid= and (author) id= paramaters, without obfuscation.
If the reader follows the "Comment" URL, then the reader can see the story_fbid= and (author) id= paramaters, without obfuscation.
If the reader follows the "React" URL, then the reader can see the story_fbid= and (author) id= paramters, without obfuscation.
Those are just four ways to discover the unobfuscated story_fbid number. There are probably others.
Tested with mbasic.facebook.com.
I have always stripped everything but the story_fbid and (author) id parameters when sharing URLs pointing to posts on Facebook. Anything else in the URL is unnecessary. On the desktop/laptop/RPi, this stripping can be automated using a localhost forward proxy.
Another issue that seems to fly under the radar with Facebook users is the prefixing and proxying of external URLs with https://lm.facebook.com/l.php?u=.
Pretty much any practical measures I've thought of, I think of (usually obvious) ways they can be countered, and assume it's only a matter of when that measure is on the adversary's radar and worth their time.
https://youtu.be/KLEH8RJsYg => https://www.youtube.com/watch?v=KLEH8RJsYg&feature=youtu.be
The only data in that short url is the unencrypted YouTube video ID
onion_address = base32(PUBKEY | CHECKSUM | VERSION) + ".onion"
CHECKSUM = H(".onion checksum" | PUBKEY | VERSION)[:2]
[0]: https://gitweb.torproject.org/torspec.git/tree/rend-spec-v3.... (section 6)Check out line 540 of the link above (section 1.7):
Master (hidden service) identity key -- A master signing keypair
used as the identity for a hidden service. This key is long
term and not used on its own to sign anything; it is only used
to generate blinded signing keys as described in [KEYBLIND]
and [SUBCRED]. The public key is encoded in the ".onion"
address according to [NAMING].
You can then follow that to line 2292 (Appendix 2) which describes the aforementioned generation process. It's a bit too long to be pasted here, but it turns out to be elliptic curve multiplication and hashing. This is not encryption for any common definition thereof.In fact, you generally do not use public keys to do encryption at all. What often happens is that you use a key exchange algorithm like Diffie-Hellman to derive a shared secret, which you then use to do bulk encryption using your favorite cipher (some asymmetric cryptosystems permit encryption, but they're much slower than symmetric ciphers, which also benefit from strong hardware acceleration).
You can also use keypairs for signing, key exchange (e.g., DH), key derivation (as used by Tor hidden services), and creating verifiable random functions. They definitely do not imply encryption.
You're pointing out this key is used differently, to generate the more direct keys. But I don't think that matters. I would say that using elliptic curves to transform one key into another while keeping the original key data secret is a good bit closer to the platonic ideal of encryption than 15 units. So that process shouldn't be a disqualifying factor.
The game of cat and mouse continues.
I’m actually kinda surprised this hasn’t happened earlier.
I will go through this effort until browsers integrate it, or until there is a secondary service that's easily runnable. This would just be pi-hole but for the internet instead of your local network.
So maybe privacy protecting browsers will start to do double loads: 1. First to get the real URL 2. Next to do the browsing with the association information stripped from the URL/cookies/etc
i feel the majority of fb audience probably don't care about this enough to change their habits.
They can post photos, statuses, chat with friends, reply to other friends' posts ... what can replace FB for them?
Nothing. So I'm forced to stay on FB.
Vile platform, no alternative.
It's like saying I need alcohol to stay in touch with my alcoholic friend. No you don't.
What you realy mean is that you value more the convenience it offers that the price to pay for using it.
People should be more charitable.
They said that they must stay in touch with these people and that these people can’t seem to use other things. Often times you have to stay in contact with family members because they aren’t able to properly care for themselves. Those same people may not have the ability to easily change how they interact with the digital world due to mental health issues and you have no choice but to meet them where they are.
I have friends that are not on Facebook. It requires more effort to stay in touch with them (for example, calling them on the phone) but it's doable. I don't see how a thing that was invented 10 years ago is now the sole method of communication with loved ones.
That said, I agree it's not without cost to delete Facebook.
So privacy is not important enough to justify those costs.
These people are family in their 90s, for whom well-meaning children and grand-children have set up on FB. They don't use email, they can't write letters because of arthritis (and time delays ... international post can be very slow), and effectively the only async comms they use at all is FB.
I'd ask that you not try to tell me what I really mean.
For the rest, see my comment here: https://news.ycombinator.com/item?id=32131180
Reading your post, it seems Facebook is a bit of a recreational activity to keep them sharp and social, which is good. What I was thinking is whether you need to participate in it, since the people this age I know is more than willing to keeping me up to date on all interesting stuff by talking. But of course each family is different so I'll just assume you know what you're doing!
But they like using FB, and it's the only effective way I know to stay in touch and remain a part of their lives.
They didn't have internet.
We managed to get in touch.
> I'd ask that you not try to tell me what I really mean.
Manner of speaking.
The important is again that it is a matter of cost vs convenience.
I understand the cost can get pretty high.
Yet still, people kept in touch for decades with old distant relatives before the internet.
Using facebook is convenience, that's the point. It is very convenient.
It's the whole argument of this thread: the convenience eventually makes most people discard the cost of not using FB as too high, and the privacy things as not important enough compared to that.
There's even graceful degradation in your set of solutions:
1. You drop FB. Now you just look on your spouse's Facebook when necessary, and your family learns to tell your spouse to show you stuff on FB. Annoying? Yes. Unworkable? No.
2. Your entire immediate family drops Facebook. At least one (if not all of you) can still communicate with the rest over text. And the rest of your family knows how to send a photo over text on an Iphone. Annoying to extended fam? Maybe. Unworkable? Definitely not. (In fact, I'd be willing to bet that it cuts out extended family spam and makes those moments of connection more meaningful.)
3. You attempt a quixotic adventure to switching your entire extended family over to some half-baked decentralized alternative to Facebook that will be usable in forever minus a day. Impossible? Yes. So choose #1 or #2 above.
Using the tech is already hard for them. Some are partially sighted, some have mobility issues, some have arthritis, all can easily use FB to stay in touch.
And they don't use anything else.
It's just not an option to try to get them to change, it really isn't. Please, please do me the courtesy of accepting that I've done the analysis. Many times. It's simply not a reasonable objective.
And no, I won't squat on someone else's FB account so I can stay in touch.
Sure, it's a completely different kind of platform, but it serves well. People post their travel pictures there, people ask random stuff and the group can discuss, we can have private discussions by clicking one name.
Sure, it's still Meta, and there's still a lot of bullshit groups, but at least I don't have to be exposed by it, nor do baby/kid pictures are exposed to the world, nor do I give money to Meta.
Of course, maybe by "Facebook" you mean "Messenger", which is more popular than it should in the US. Replacing FB with WhatsApp or Signal is possible because my family and friends are around Latin America, Europe and Asia, where nobody uses Messenger anyways.
It’s a chore for people to forward to my preferred communication method and easy to occasionally forget. Which snowballs into only hearing about events afterwards.
Eventually you basically become a weirdo with no mates.
I’m not prepared to make that sacrifice any more. I honestly gave it my best shot and still don’t use FB and Insta but have to use WhatsApp.
The ideal solution is to hit them with the hammer until morale improves. Regulators need to wake up and just start fining them absurd amounts of money and keep it vague until Facebook et al. are scared enough to comply and then some.
If you think it's necessary to caveat that if you rely on facebook.com as your "communication infrastructure" (not that many countries would fit that bill) then you shouldn't delete it, I'm happy to do so.
"delete it" isn't a solution at all. You may as well say "turn the electricity off". People deserve privacy when services are provided to them by private companies, that's not a bonus, it ought to be a fundamental right. It's not the job of individuals to take on trillion dollar multinationals.
For some reason people here seem to think I'm precluding regulatory action against Facebook. I'm not. I just also think it's better not to use it.
Heaven forbid that we seek a political/regulatory solution.
Every HN thread about social media has one sub-thread like this, and it never produces anything of value because the premise is trite.
God I wonder what people with large extended families did before Facebook was invented! Surely they were all isolated and out of touch, how sad.
This comment was not directed at people running Facebook business accounts or political campaigns. The reason this thread produces nothing of value is because of pedantic comments such as yours bringing up irrelevant edge cases.
Your sarcasm is misplaced; once people adapt to a benefit, many understandably don't wish to forgo it, and leveraging such network effects is the core business model of social media.
As for who the comment was directed at, it was so broad as to be inclusive of all users, because it didn't qualify its suggestion at all; that's why it's trite. You're just making a 'not true Scotsmen' argument.
And (crucially) then go back to drinking.
Human attachment patterns are a primary factor in dependency problems. Addicts get into groups who mutually support each other's habit. Leaving the drug means leaving the only group who "understand" you. It's the same for cults. There's a chapter on this in Digital Vegan. Social media companies shamelessly and aggressively leverage that psychology.
It's a thought experiment to look at specific categories. Maybe it's not worth making something illegal, but it's useful to answer the question to get a good perspective.
In this case I would say it's definitely not something I specifically want to be legal.