Supporting the Anonymous Use of Facebook via Tor
blog.digicert.com
blog.digicert.com
I wonder whether the same effect could be had by using a self-signed cert - would work especially well with a phone app which could pin whatever cert it wanted.
This should help that. You can be more confident that it's not being man in the middled.
On https://example.com/ I add:
<script src="//example.onion/x.js"></script>
x.js contains: alert(
"I notice you can access Tor hidden services. We have"
+ "a hidden service address at example.onion by the way"
);
The only way this would work when you are using SSL on example.com is if you are also using SSL on example.onion.But for a Silk Road-like marketplace? Uh, sure: why don't they incorporate, print business cards, lease an office, do an IPO and invite the FBI to the opening party while they're at it? ;-)
Of course, it will be quite superfluous, because .onion addresses are themselves truncated hashes of keys. Tor's already looking into improving all that.
Also, Facebook made a "vanity address" that is pretty memorable, facebookcorewwwi.onion [0]. So, someone else could brute-force a similar address and lure people to it, but presumably they wouldn't be able to get a trusted CA to issue a cert authenticating that they're "the same entity as the one operating facebook.com" (from the article -- I presume facebook.com is also named in the cert, which shouldn't happen unless the CA vetted it.)
[0] https://lists.torproject.org/pipermail/tor-talk/2014-October...
https://lists.torproject.org/pipermail/tor-talk/2014-October...
I didn't mention the part about how the public keys are 1024-bit RSA, but it adds to the sense that native hidden service transport encryption is using dated crypto.
And that's not even considering the fact that Tor's transport to hidden services implies authenticity... DigiCert is unable to usefully contribute to the claim "these people own facebookcorewwwi.onion" or "these people own facebookrotflbbq.onion" because Tor is already making that claim strongly, so the only claim they can help with is "these people are/aren't who you think of as Facebook".
If DigiCert were able to issue an EV cert for "Facebook, Inc. [US]", that would be another matter entirely, but the industry rules on EV certificates are tight, and in particular I think there are rules about being in the public DNS. I'd imagine one thing they're working on is being able to issue EV certs for .onion domains.
This just looks like a dirty anti-gov protest and mass publicity stunt. It offers a false and wrong sense of security to the users. We have reports of rogue TOR exit nodes that try to insert malware, and we assume that we can actually trust the owners of this infrastructure? I'm sorry, I am all for security, improvements to services that ensure people I don't want seeing my communications, can't, but this? Calling bullshit on this.
They are two separate things.
To my mind, accessing the general Internet is not what you want to do with TOR -- ideally the service you want to access will also be on .onion, allowing you to avoid exit nodes. In practice, that's not going to be possible in all cases so exit nodes are a necessary evil requiring extra care.
There, that's why you need the Facebook .onion. You can have reason to fear the initial hops of your packets but not the destination.
Cached version: http://webcache.googleusercontent.com/search?q=cache%3Ablog....
So anybody wanting to "hack" a Facebook account should do it via Tor and use the .onion address to avoid being detected and locked out? How does that work?
Sorry, something went wrong
Please try closing and re-opening your browser window.