Making Connections to Facebook More Secure
facebook.com
facebook.com
Looks like Tor hidden services are now broken to me...
[edit] What's to stop Facebook from brute forcing a key for any of the existing hidden services?
[edit2] If Facebook can brute force keys like this, so can the NSA and GCHQ. Tor hidden services are officially broken.
[edit3] A colleague of mine suggested that this might be simply Facebooks way of making it public knowledge that Tor hidden services can no longer be relied upon.
[edit4] Facebook are saying (on the Tor Talk list) that they generated a load of keys starting "facebook" and then just picked the one which looked most memorable, and were extremely lucky to get such a good one:
Which is why using TLS on top of the .onion address is brilliant: even if the secret key for the .onion address is compromised, the TLS certificate (which is rotated more often) will keep the connection safe. The worst that could happen would be someone hijacking the .onion address, but that would lead only to a DoS instead of the compromise that would happen without the redundant TLS layer.
And the certificate also helps validate that the .onion address is really from facebook: as someone observed elsewhere in this discussion, the certificate is also valid for the non-.onion addresses, so just examining its alternate names extension is enough to prove that the certificate owner could also get a valid certificate for www.facebook.com (meaning the certificate owner is very probably facebook itself).
Progress: https://lists.torproject.org/pipermail/tor-dev/2013-August/0...
So someone bruteforcing the .onion key could easily get their own valid SSL cert and have full access to the plaintext for anyone browsing the .onion site over SSL.
The security of facebook over onion is now only protected by the hash power required to brute force the vanity address, instead of the integrity of the SSL CA system or the power required in factoring an SSL key. Even the requirement to spoof DNS or perform actual man-in-the-middle-of-the-wire hijacks has vanished.
Did you ask NSA for a full 16-character bruteforce? :)
Meanwhile, whilst I applaud Facebook going above and beyond here, this doesn't set a good precedent.
Firstly, Onion service are very slow. There is no need to pay this cost for a service whose ownership is not actually hidden. If the Tor project made it easier to reliably identify traffic from Tor exit nodes, Facebook could apply whatever rules they wanted to Tor traffic without needing to slow things down for everyone.
Secondly, by doing this, there's now a risk that other firms who want to be on the cutting edge of privacy will try to copycat this approach, even though it makes no sense and is very complex and expensive to set up. Worse, users might think it's some kind of "gold standard".
Thirdly, it doesn't actually solve any of the reasons why Tor traffic is routinely discriminated against and harassed: Tor is effectively a "bulletproof ISP" that shields a lot of abuse and hacking. Merely making a Tor hidden service specifically for Facebook doesn't solve that, at all.
As long as you don't have to use it, I don't see why offering users a choice is a problem.
>If the Tor project made it easier to reliably identify traffic from Tor exit nodes, Facebook could apply whatever rules they wanted to Tor traffic without needing to slow things down for everyone.
ExoneraTor does this quite well in my opinion, and I don't follow how/why you think this will slow things down for everyone. Surely you're not referring to the entire Tor network?
The main value in using this, in my opinion, is reducing the potential attack surface associated with MITM attacks--including CDNs--after your traffic exits Tor. Attacks on Facebook users involving Akamai have been documented by NSA, for example; Facebook is a PRISM partner, but this would arguably still stack the deck in favor of "going through the front door" to access Facebook user data.
Tor's current support for detecting usage is patchy. You can't query a random third party website for every login for a system like Facebook, so you need a list of IPs that can be refreshed quickly. But such lists tend to be incomplete or behind e.g. the "exit" flag doesn't mean what you'd intuitively expect, so it's sometimes possible for Tor traffic to turn up from an IP that is not identified as an exit.
Re: MITM security. Even if Facebook got lucky here, we're talking about an 80 bit identifier and brute forcing these has been demonstrated before, I believe. I'm not sure this is much of an upgrade over just regular SSL CA + HSTS pinning.
(edit: last paragraph)
my take on the post was that it was presented as an option, and for users taking the time to access a site via tor, speed may not be the only (or even primary) consideration. i say that as someone who does ~95% of my browsing--both work and personal--via Tor.
> But such lists tend to be incomplete or behind e.g. the "exit" flag doesn't mean what you'd intuitively expect, so it's sometimes possible for Tor traffic to turn up from an IP that is not identified as an exit.
Doesn't the onion address solve this problem?
> I'm not sure this is much of an upgrade over just regular SSL CA + HSTS pinning.
Depends on your threat model, but I think it's a useful option and congratulate the Facebook team for offering it to users. I'd love to see Google, Twitter, and others start to compete on the extent to which they support TBB users.
Here is my worry -- Tor looks easy to use, but requires habit changes to actually be effective for anonymity. The habit changes that I am led to believe are required for any effective anonymity through Tor scream "NO NO NO NO NO!!!" at the idea of logging into javascript requiring, cookie placing, Facebook.
This seems to me like a situation where the illusion of anonymity might be worse than the reality of non-anonymity. Granted, it lets you bypass censorship. Granted, if you are very careful and, say, only use your Tor Browser to connect to Facebook and nothing else whatsoever... maybe. I just don't think I could trust myself to do it properly. And while I'm no Edward Snowden, I'm also not dumb.
How do you differentiate between this and account takeovers though? If someone constantly lives in from California, and then someone elsegets their Gmail password and logs in through Tor, can you know it's actually a compromised account and not the registrant just deciding to use Tor?
That may be the worst unexpected consequence. Once onion services become more mainstream, I fear FB's example - no matter how well intentioned - will turn into an engineering nightmare. After all, after one of the best known online brands does something clever, you can expect copycats to follow.
First, we'll get clueless PHB types demanding long vanity names.
Second, some services will happen upon neat onion addresses and ride the wave. Their very existence will act as a goal post for the others.
Third, a vocal segment of users becomes accustomed to seeing "perfect" vanity names. After all, such name means that the entity behind the name has enough resources to actually get a proper vanity name.
Amidst all that, somewhere between stages #2 and #3, we will see (horribly misguided) vanity onion service name markets. A bit like domain name squatting from the late 90's, but with far worse consequences: at least with domain names the only thing transferred was the control over the DNS entry. Because onion service names are directly mapped to the private keys, selling a $VANITY.onion address is the same as selling a copy of the private key.
Caveat emptor, indeed.
The list of "you have to" involved in making its use meaningful is pretty long, and "normal" users aren't good at caring about details like that.
Please nobody construe that as a dismissal of the needs of those users, that isn't what I'm getting at.
Right now? No. But in a near future? Possibly yes, if Firefox decides to include a built-in Tor client. [0]
Even if the article (and the slashdot thread I lifted it from) were vapourware right now, the idea clearly has been floated enough to make it an attractive option.
DuckDuckGo is being irrational? Keybase? Riseup? Sorry, but I don't see how knowing the owner of a service can immediately disqualify the service from having the privilege of a hidden service. The only thing limiting Facebook is the stress that may be placed on so many connections at once on a single onion. It should not cost too much out of actual resources to run one single gateway, especially when Facebook is a very successful business and can afford to invest in something that may expand their audience even more.
I'm not saying anything for or against Facebook's ethics in general; I am a little hesitant given their history to trust them at all, but this is admittedly a huge step in shedding light on what Tor actually is. It's not just for drugs or child pornography; it can actually be used by the everyday Joe wanting to check on his friends and see if there's a party nearby. What people seem to miss is that Tor provides IP anonymity. Yes, encouraging users to be more careful about their browsing habits is a good thing, but if people want to give out their personal information, in the end that cannot be stopped. If the website owner wants to disclose his or her identity, that cannot be stopped. Tor provides anonymity of IP addresses and nothing else.
Yes.
There just isn't any really solid technical reason to do this. The closest I saw was something like "newspaper dropbox wants to force people to use Tor and an onion address is the easiest way to do that", but again, they could just identify traffic from exit nodes and block anything that isn't coming from there, if there were better tools for it.
If you use Tor, what's the point in providing a phone number. All that does is give Google data that can be subpoena'd by the feds. :(
Bench marking Shallot on an Intel 3350P@3.10GHz:
time ./shallot ^a -> 0.09 sec user
time ./shallot ^aa -> 0.12 sec user
time ./shallot ^aaa -> 0.12 sec user
time ./shallot ^aaaa -> 0.47 sec user
time ./shallot ^aaaaa -> 5.92 sec user
time ./shallot ^aaaaaa -> 118 sec user
Unfortunately OpenCL doesn't work with the nouveau drivers so I can't test scallion.Who knows how much they spent trying to brute force that onion address.
EDIT: Ok looks like they went the backronym route
[0] https://github.com/lachesis/scallion [1] https://github.com/katmagic/Shallot
They are therefore trying to brute force the first 11 characters of the address. The author of scallion estimates one can achieve 520 MH/s with a AMD Radeon HD5770 GPU [2] which retails for $190 [3], they then give the formula for calculating the time (in seconds) to have a 50% chance of finding a matching URL: 2^(5length-1) / hashspeed Which with a length of 11 and a hashspeed of 520M, would take about a year with the one GPU [4]. The total cost of the hardware to have a 50% chance of finding the vanity address "facebookwww?.onion" within a week would therefore be around $11 000 [5].
Imho, this is well within the realms of possibility for a company as large as Facebook and does not suggest a weakness in the .onion scheme.
[1] https://github.com/lachesis/scallion
[2] https://github.com/lachesis/scallion#speed--performance
[3] https://www.amazon.com/dp/B0032F63TW
[4] http://www.wolframalpha.com/input/?i=%282^%285*11-1%29+%2F+5...
[5] http://www.wolframalpha.com/input/?i=%24190+*+%282^%285*11-1...
[edit]
Dustcore is very correct, correcting for my initial mistake, it would take 1.1 million years on a single GPU using scallion. Finding that sort of result in a month would require $2.6 billion worth of GPUs. Now I know facebook is known for spending billions on questionable purchases, but this would be a bit extreme even for them. How the hell have they managed this?
The .onion URL is created by hashing the public key (and possibly more information), and then it is stored in Tor's database of hidden service descriptors as noted by this[1]. This would indicate to me that if there's a hash conflict, such as the NSA trying to take over FB's .onion URL, the database of hidden service descriptors would reject the duplicate insertion to the database.
[1] https://security.stackexchange.com/questions/23241/how-are-t...
IIRC it's 80bit truncated SHA-1, so it's not even close to feasible unless there's a substantial preimage attack against the function (and none are known). It's clearly feasible to find something close enough to the human eye for a phishing/spoofing attack, but that's hardly a problem exclusive to Tor.
Now, the other, more important for me observation is, that reportedly the TLS certificate is actually worth close to nothing, and giving false security, as a HNer claims to have got a valid cert issued for this very same facebook's .onion address already: https://news.ycombinator.com/item?id=8539066 -- if I understand correctly, cert issuers seem to happily accept any .onion URLs in "alternative addresses" in SSL certs without any verification. Anybody else could confirm/deny?
Good thread on StackExchange about how to do that: http://security.stackexchange.com/questions/29772/how-do-you...
A more manageable 61 bits for 12 characters or so, from my recollection. Did you pile a dictionary attack on top of that?
I don't believe this does "break hidden services". That's just a truncated key fingerprint, not the key, and a collision would I suspect (but haven't checked) be a loudly visible error.
Actually, a name collision would still mean hijacking the traffic, even if they don't have the same private key. The last HS to announce "owns" the name.
Even NSA-influenced NIST recommended against using SHA1 after Dec. 2013. And when NIST recommends a deadline for change, you know you should be doing that at least 3-5 years earlier to be safe against state sponsored/NSA attacks.
[1] - https://blake2.net/
> The .onion name is computed as follows: first the SHA1 hash of the DER-encoded ASN.1 public key is calculated. Afterwards the first half of the hash is encoded to Base32 and the suffix ".onion" is added. Therefore .onion names can only contain the digits 2-7 and the letters a-z and are exactly 16 characters long.
(Source: https://trac.torproject.org/projects/tor/wiki/doc/HiddenServ...)
The move to slower hash functions is really only important when you're dealing with passwords because the input is enumerable enough to bruteforce to begin with. In general, having a fast cryptographic hash function is extremely desirable, and, for applications where the input is essentially random (nonces and randomly generated keys etc) it's fine.
[0] https://en.wikipedia.org/wiki/MD5#Preimage_vulnerability
Using this would also add to the data that one of the world's most aggressive advertisers and an NSA PRISM partner will have about you as a Facebook user.
One plus: at least the login page appears to load correctly without javascript enabled.
Edit to add: someone whose only interest is in not sharing their IP address/location with Facebook could access this URL via facebookcorewwwi.tor2web.org but the usual browser fingerprinting and potential tracking caveats apply
Why? With data encrypted end to end the only people who know you've identified yourself are you and the end service.
even just having a strong authenticator of your real identity active on tor at a given time may be concerning, depending on your threat model.
https://lists.torproject.org/pipermail/tor-talk/2014-October...
"So I'm totally anonymous if I use Tor?
No.
First, Tor protects the network communications. It separates where you are from where you are going on the Internet. What content and data you transmit over Tor is controlled by you. If you login to Google or Facebook via Tor, the local ISP or network provider doesn't know you are visiting Google or Facebook. Google and Facebook don't know where you are in the world. However, since you have logged into their sites, they know who you are. If you don't want to share information, you are in control."
They're not, they just want users on networks that block facebook.com, or try to perform MITM (by hijacking DNS or the switch from HTTP to HTTPS), to be able to reach them safely.
They've recently announced they plan to ease the real name policy http://bits.blogs.nytimes.com/2014/10/01/facebook-agrees-to-...
By creating a entry point, they can more easily track and label users that even use that entry point, to better handle abuse.
A new session can be created by restarting Tor or from the tor indicator if within TAILS.
The reason for this is that it never leaves the Tor network. Traffic from a tor client to a hidden service goes (encrypted) through relays, but never exits. Basically you are entering a validation of the public key when you type in the .onion address, so nobody can tamper with the connection.
As I currently understand it, you connect anonymously to Facebook, login and link your activities to your real life identity and Facebook turns over the information that you provide to whatever powerful government entity you are hiding from.
Why would anyone do this?
What is the value in using tor to connect anonymously to a system that ties back to your real life identity?
http://venturebeat.com/2014/05/15/how-the-nsa-fbi-made-faceb...
The only concession is that now the government you're avoiding might know you use Tor, if Facebook tells them.
----
Here's the usage case: you're a foreign national visiting a country with a restrictive firewall, like China's. Now you can continue to communicate with people back home.
Facebook already had your information, in this scenario, so nothing has changed except that they know people from China are desperate for their services. That's only good, in my book.
The attacker will not raise any flags anymore (since it could be you).
CN = *.facebook.com
O = "Facebook, Inc."
L = Menlo Park
ST = CA
C = US
with a bunch of altnames DNS Name: *.facebook.com
DNS Name: facebook.com
DNS Name: *.fb.com
DNS Name: *.fbsbx.com
DNS Name: *.fbcdn.net
DNS Name: *.xx.fbcdn.net
DNS Name: *.xy.fbcdn.net
DNS Name: fb.com
DNS Name: facebookcorewwwi.onion
DNS Name: fbcdn23dssr3jqnq.onion
DNS Name: fbsbx2q4mvcl63pw.onionedit: They've revoked the cert. :(
EDIT: Or simply redirecting myownfacebook420.onion to facebook.com, because that can VERY easily be done. Just add a HiddenServicePort 80 facebook.com:80 to the torrc.
Looks like some sort of CA structure is going to be pretty vital to Tor…
cloudflare ends up being a HUGE pain and practical barrier for the vast majority of people who use tor to exercise their right to read.
Sites that want Tor users should do well and avoid services like Cloudfare, but for sites that don't care it's a very effective way to cut out malicious actors.
It's not nice in a freedom sort of way, but for ad supported sites Tor traffic is worthless and there is little incentive to try and cater towards it.
So I can now tell Facebook my personal information and a list of associates securely, which it will then promptly share with any government interested.
I guess its the best way yet to illustrate the basic problem with Tor (no technology in the world can protect you from giving the bad guys your home address), but can't shake the feeling that this makes an utter mockery of the idea behind Tor.