Live data from Hacker News

1M People Use Facebook Over Tor

facebook.com

31–40 of 168 posts

Re: 1M People Use Facebook Over Tor

#31
post #11

Earlier quoted context omitted.

Interestingly, since Onion addresses are derived from the public key of the host server, Facebook had to basically brute force this address. The process is described in "Part three" here: https://blog.torproject.org/blog/facebook-hidden-services-an... "The short answer is that for the first half of it ('facebook'), which is only 40 bits, they generated keys over and over until they got some keys whose first 40 bits o…

I thought Onion addresses were a hash of the public key, not the private key.

Ah, you are correct, thank you:

..."a base32 encoding of a 10-octet hash of Bob's service's public key" https://gitweb.torproject.org/torspec.git/tree/rend-spec.txt...

Re: 1M People Use Facebook Over Tor

#32
post #28

Earlier quoted context omitted.

Onion names are sort of public keys. You generate a secret key, then that's transformed/hashed into the public key that is your onion address. Since onion addresses are essentially random strings of a certain length, the only way to get a "vanity" onion address is to brute force it.

Also, if I'm not mistaken, this means that if YOU can brute force a vanity domain, anyone else willing to throw down the same amount of computing power can perform the same brute force and discover your private key, taking over your onion site? Edit: probably wrong, see below

Normally you brute force vanity addresses by having a range of acceptable outcomes, whereas to brute force a specific vanity address* you are only targetting a single outcome.

So they might have just set it to filter for facebook[dictionaryword]+ and this was the best match.

* Actually any address, it's not limited to brute forcing vanity addresses.

Re: 1M People Use Facebook Over Tor

#33
post #28

Earlier quoted context omitted.

Onion names are sort of public keys. You generate a secret key, then that's transformed/hashed into the public key that is your onion address. Since onion addresses are essentially random strings of a certain length, the only way to get a "vanity" onion address is to brute force it.

Also, if I'm not mistaken, this means that if YOU can brute force a vanity domain, anyone else willing to throw down the same amount of computing power can perform the same brute force and discover your private key, taking over your onion site? Edit: probably wrong, see below

It requires substantially more compute power to match "facebookcorewwwi" vs just finding a hash with a prefix of "facebook" that looks readable. Good luck hashing the remaining eight characters!

Re: 1M People Use Facebook Over Tor

#34
post #17

Earlier quoted context omitted.

I don't understand quite, why so much brute force?

Onion names are sort of public keys. You generate a secret key, then that's transformed/hashed into the public key that is your onion address. Since onion addresses are essentially random strings of a certain length, the only way to get a "vanity" onion address is to brute force it.

The third part on the Tor project's blog at https://blog.torproject.org/blog/facebook-hidden-services-an... describes this well.

Check out mapgrep's comment on another thread below for a more in depth answer, too.

Re: 1M People Use Facebook Over Tor

#35
post #11

Earlier quoted context omitted.

The article says its https://www.facebookcorewwwi.onion

Interestingly, since Onion addresses are derived from the public key of the host server, Facebook had to basically brute force this address. The process is described in "Part three" here: https://blog.torproject.org/blog/facebook-hidden-services-an... "The short answer is that for the first half of it ('facebook'), which is only 40 bits, they generated keys over and over until they got some keys whose first 40 bits o…

But how did they allocate the carefully selected key and avoid others generating the same one in the meantime?

Re: 1M People Use Facebook Over Tor

#36
post #28

Earlier quoted context omitted.

Onion names are sort of public keys. You generate a secret key, then that's transformed/hashed into the public key that is your onion address. Since onion addresses are essentially random strings of a certain length, the only way to get a "vanity" onion address is to brute force it.

Also, if I'm not mistaken, this means that if YOU can brute force a vanity domain, anyone else willing to throw down the same amount of computing power can perform the same brute force and discover your private key, taking over your onion site? Edit: probably wrong, see below

Sure. The same is true for anything that uses public key encryption (Bitcoin for one). But the amount of computing power needed doesn't exist.

According to this person's math [1]: "It would take ~6.7e40 times longer than the age of the universe to exhaust half of the keyspace of a AES-256 key"

I don't know if Tor uses AES-256, but I'm sure any reasonable encryption algorithm would be similar.

[1] https://www.reddit.com/r/theydidthemath/comments/1x50xl/time...

Re: 1M People Use Facebook Over Tor

#37
post #14
post #10

Earlier quoted context omitted.

But if one of your friends is not really your friend, and you won't know until it's too late, they'll know you got past the firewall and that could be enough to get you into troubles. You better have to stay fully anonymous, which limits what you do on Facebook. You probably want different accounts for different groups and an empty timeline in every account.

It may be that it just isn't that strictly enforced for a variety of reasons. China allows a number of VPN services that bypass the firewall to function. My guess is that it isn't a huge deal because the vast majority of people don't care enough to go out of their way to bypass the firewall; the social effects of having that firewall are still in place. Start enforcing it heavily and the people that DO use those serv…

Which also tends to be the subset of people that have studied abroad, various repatriated huaqiao and college students at some of the more metropolitan colleges and I guess tech people/white collar workers.

Cracking down on college students seems like a really dumb idea.

Re: 1M People Use Facebook Over Tor

#38

Please explain it to me if I'm wrong, but doesn't logging into Facebook on Tor defeat the purpose of Tor?

When I was traveling in China, I would have had no access to Facebook if it weren’t for Tor. All I needed was my USB drive with a Tor + Linux and I could access the free Internet from any computer. Providing anonymity of identity is just one of the many uses of tor. [1]

[1] https://www.torproject.org/about/torusers.html.en

Re: 1M People Use Facebook Over Tor

#39
I've recently tried using FB via TOR (Browser) for the first time, but was unable. After entering the onion address and my FB credentials, I was informed that the account is temporarily blocked (presumably because of first access via TOR). I was presented with an option of unblocking it by recognizing a few photos of friends and matching them to names - but unfortunately, all those photos showed as blank, white squares!

So, I wasn't able to login via TOR via the purposefully created .onion address. Also, sent an issue report via non-TOR login about this, but never got any response.

Note also that this seems to mean to me, that there may be people who are cut off from FB via TOR same as me, but who don't even have a way to notify FB about the fact. And thus not having any chance of having the bug fixed.

Re: 1M People Use Facebook Over Tor

#40

Please explain it to me if I'm wrong, but doesn't logging into Facebook on Tor defeat the purpose of Tor?

If you assume that Facebook will comply with whatever entity you're trying to avoid, by using Onion, it sounds like a pretty bad idea to me, yes. In theory you could probably use a separate browser and Tor session for Facebook, and for your other browsing - making it a little harder to associate your Facebook login with your Tor session (ip). Sounds like a terrible idea, though.

Now, for some of the reasons why you'd want to use Facebook via Tor, it might not matter much - using Facebook might be bad enough (eg: it could be considered subverting state censorship) -- so if Facebook is already colluding with your adversary, just having a Facebook account might be enough to give you problems.

It might be enough for a legal veneer of plausible deny-ability, although I doubt it: Eg, perhaps you're a drone pilot and you login to Facebook via Tor, and paste in a gpg-encrypted, ascii-armored text-message to a journalist on Facebook. You could claim someone must've hacked your account. Or you could collude with someone else, and "borrow" their account. I don't think it'd keep you out prison though.

Post reply on HN