Live data from Hacker News

1M People Use Facebook Over Tor

facebook.com

41–50 of 168 posts

Re: 1M People Use Facebook Over Tor

#42
post #17

Alec Muffet has done a lot of work to get Facebook running on TOR and he's a true believer. I really enjoyed working with him when I was at Facebook. He also did a lot of work to get .onion domains to be recognized by registrars as a special purpose domain name. This let us issue certificates on .onion. I don't know if the story behind the facebookcorewwwi.onion domain name itself has been talked about much, but we w…

I don't understand quite, why so much brute force?

Because it happened in the past with a hashing algorithm that isn't resistant to getting faster as time progresses.

Re: 1M People Use Facebook Over Tor

#46
post #24
post #17

Earlier quoted context omitted.

I don't understand quite, why so much brute force?

The name of .onion address is the hash of a public key, so you can't choose it, or rather the only way is to generate random public and private key pairs and to keep the one that interest you. Facebook must have generated an awful lot of key pairs to get "facebookcorewwwi". By the way, I hope they deleted the other generated pairs…

I have good faith that they didn't, or certainly not all of them. When Alex described the entire process they went through, he also smirked that should that primary key ever get compromised they have several others, almost as good, ready as drop-in replacements.

I do think he also mentioned that they only cared about keys that had their required prefix; all others were destroyed without anyone ever having access to them.

Re: 1M People Use Facebook Over Tor

#48

It's funny that they say people use Tor "for a variety of reasons related to privacy, security and safety". They left out "firewall circumvention", which I have to believe is the #1 reason, at least in China.

Unfortunately, it's been a very, very long time since Tor was last usable in China.

Re: 1M People Use Facebook Over Tor

#49
post #46
post #24

Earlier quoted context omitted.

The name of .onion address is the hash of a public key, so you can't choose it, or rather the only way is to generate random public and private key pairs and to keep the one that interest you. Facebook must have generated an awful lot of key pairs to get "facebookcorewwwi". By the way, I hope they deleted the other generated pairs…

I have good faith that they didn't, or certainly not all of them. When Alex described the entire process they went through, he also smirked that should that primary key ever get compromised they have several others, almost as good, ready as drop-in replacements. I do think he also mentioned that they only cared about keys that had their required prefix; all others were destroyed without anyone ever having access to t…

> I do think he also mentioned that they only cared about keys that had their required prefix; all others were destroyed without anyone ever having access to them.

Okay, that is what I was implying would be terrible otherwise. But actually it is quite obvious that they would not spend the disk space necessary the keep every single generated key pairs now that I think about it.

Re: 1M People Use Facebook Over Tor

#50
post #39

I've recently tried using FB via TOR (Browser) for the first time, but was unable. After entering the onion address and my FB credentials, I was informed that the account is temporarily blocked (presumably because of first access via TOR). I was presented with an option of unblocking it by recognizing a few photos of friends and matching them to names - but unfortunately, all those photos showed as blank, white squar…

That's a standard challenge if you try to log into your FB account from a new machine / IP address that geolocates somewhere you don't typically seem to be. Of course, that's pretty ironic since your Tor exit could be anywhere, but it's not specific to Tor anyhow. I have seen the same behavior using VPN, too.
Post reply on HN