Earlier quoted context omitted.
When I was traveling in China, I would have had no access to Facebook if it weren’t for Tor. All I needed was my USB drive with a Tor + Linux and I could access the free Internet from any computer. Providing anonymity of identity is just one of the many uses of tor. [1] [1] https://www.torproject.org/about/torusers.html.en
Why doesn't China block Tor? Isn't it easy as blocking all known public IP addresses? It doesn't make sense to not allow the user to access certain sites, but allow Tor that can easily bypass that protection.
1M People Use Facebook Over Tor
101–110 of 168 posts
Re: 1M People Use Facebook Over Tor
#102Earlier quoted context omitted.
They "allocated" the key by using it. Others are not more likely to generate the key they found than any other specific key. This is statistically unlikely due to the extremely huge number of possible keys.
Well, did they generate keys they liked and then tried to use them immediately, hoping nobody had generated the same key in the meantime, or did they generate only keys they would like and "registered" them all but kept just one? If so, what happens to allocated but unused keys? What I'm trying to figure out is: 1. race condition? 2. waste of key space?
2. You can't "register" key. If some person manage to generate key with same vanity he can use same address as facebook, but practically this is nearly impossible. And if that happen this can be easily detected by facebook so they can just change official key.
Re: 1M People Use Facebook Over Tor
#103Alec Muffet has done a lot of work to get Facebook running on TOR and he's a true believer. I really enjoyed working with him when I was at Facebook. He also did a lot of work to get .onion domains to be recognized by registrars as a special purpose domain name. This let us issue certificates on .onion. I don't know if the story behind the facebookcorewwwi.onion domain name itself has been talked about much, but we w…
> This let us issue certificates on .onion. Isn't TOR encrypted up to a hidden service anyway? Why would you HTTPS over TOR? Honest Question.
Re: 1M People Use Facebook Over Tor
#104Alec Muffet has done a lot of work to get Facebook running on TOR and he's a true believer. I really enjoyed working with him when I was at Facebook. He also did a lot of work to get .onion domains to be recognized by registrars as a special purpose domain name. This let us issue certificates on .onion. I don't know if the story behind the facebookcorewwwi.onion domain name itself has been talked about much, but we w…
> This let us issue certificates on .onion. Isn't TOR encrypted up to a hidden service anyway? Why would you HTTPS over TOR? Honest Question.
Re: 1M People Use Facebook Over Tor
#105Earlier quoted context omitted.
> This let us issue certificates on .onion. Isn't TOR encrypted up to a hidden service anyway? Why would you HTTPS over TOR? Honest Question.
That's true. Exit nodes do not play a role in hidden services. But, Rendezvous point does. So, If your node somehow selected as rendezvous point for meeting, then you could possibly sniff the traffic.
Edit: the original comment I replied to stated that exit nodes could sniff traffic.
Reply to new comment:
The connection is encrypted to the service's public key, what are you talking about? Stop spreading nonsense and go read documentation.
Re: 1M People Use Facebook Over Tor
#106It's funny that they say people use Tor "for a variety of reasons related to privacy, security and safety". They left out "firewall circumvention", which I have to believe is the #1 reason, at least in China.
Unfortunately, it's been a very, very long time since Tor was last usable in China.
Re: 1M People Use Facebook Over Tor
#107Earlier quoted context omitted.
> This let us issue certificates on .onion. Isn't TOR encrypted up to a hidden service anyway? Why would you HTTPS over TOR? Honest Question.
That's true. Exit nodes do not play a role in hidden services. But, Rendezvous point does. So, If your node somehow selected as rendezvous point for meeting, then you could possibly sniff the traffic.
Re: 1M People Use Facebook Over Tor
#108Earlier quoted context omitted.
How would that be terrible?
The number of generated key pair to find "facebook" + keywords must have been gigantic, maybe even so much that it could be used as a kind of rainbow table which would allow people (or three letters agencies) who can access it to attack hidden services that use one of the .onion for which a corresponding private key is known.
Re: 1M People Use Facebook Over Tor
#109Earlier quoted context omitted.
How would that be terrible?
The number of generated key pair to find "facebook" + keywords must have been gigantic, maybe even so much that it could be used as a kind of rainbow table which would allow people (or three letters agencies) who can access it to attack hidden services that use one of the .onion for which a corresponding private key is known.
Re: 1M People Use Facebook Over Tor
#110Earlier quoted context omitted.
Which also tends to be the subset of people that have studied abroad, various repatriated huaqiao and college students at some of the more metropolitan colleges and I guess tech people/white collar workers. Cracking down on college students seems like a really dumb idea.
And yet, that hasn't stopped them in the past. https://en.wikipedia.org/wiki/Tiananmen_Square_protests_of_1...