TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Supporting the Anonymous Use of Facebook via Tor

64 pointsby lambadaover 10 years ago

7 comments

voltagex_over 10 years ago
So Facebook can get a .onion cert, but normal people can&#x27;t? That&#x27;s a little annoying.<p>I wonder whether the same effect could be had by using a self-signed cert - would work especially well with a phone app which could pin whatever cert it wanted.
评论 #8571889 未加载
评论 #8571434 未加载
评论 #8571514 未加载
saurikover 10 years ago
HBO was granted an SSL certificate by Verisign for &quot;localhost&quot; that was embedded in their iOS app for a while (allowing them to have the iPhone player, which had some SSL requirement I never knew much about, to connect to localhost to stream content, but let the app apply some crazy custom DRM scheme to the traffic). It was found by jan0, when he was working on a Cydia Substrate extension to backport the bug fix for one of the SSL issues that Apple had on iOS 4, and his extension died on someone&#x27;s phone logging about localhost. He mentioned it on IRC and then left for lunch, so I decided it would be a fun challenge to try to grab it out; two hours later I had disassembled the code and figured out that it had a string that was like &quot;AHdagw%@gcgAWdsa%@fGS3&quot; that it formatted with two strings (replacing the &quot;%@&quot;, if you don&#x27;t know Objective-C), then base-64 decoded that, and used it as the password for a key file, which was something like &quot;Amst3rd4m1sC0ld&quot; (I remember what it said, but not the numbers&#x2F;caps ;P). I knew it hadn&#x27;t taken him two hours to figure this out, so I asked him how he did it, and he made fun of me for not using my own tools (in this case, Substrate) to just hook the function that you pass the password to to decrypt a key file :(.
userbinatorover 10 years ago
Seeing the words &quot;Facebook and &quot;anonymous&quot; together is a little odd, given how use of Facebook, and its policies, is often seen as being the exact opposite of anonymous.
评论 #8571700 未加载
评论 #8571748 未加载
gizmo686over 10 years ago
Site down.<p>Cached version: <a href="http://webcache.googleusercontent.com/search?q=cache%3Ablog.digicert.com%2Fanonymous-facebook-via-tor%2F&amp;oq=cache%3Ablog.digicert.com%2Fanonymous-facebook-via-tor%2F&amp;aqs=chrome..69i57j69i58.2125j0j4&amp;client=ubuntu-browser&amp;sourceid=chrome&amp;es_sm=93&amp;ie=UTF-8&amp;strip=1" rel="nofollow">http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache%3Ablog....</a>
rlpbover 10 years ago
&quot;Facebook would treat users as “hacked’ since their location would vary throughout the world. Using the .onion address prevents the lock-out from occurring.&quot;<p>So anybody wanting to &quot;hack&quot; a Facebook account should do it via Tor and use the .onion address to avoid being detected and locked out? How does that work?
评论 #8571897 未加载
darkhornover 10 years ago
Why does it matter? It doesn&#x27;t work!<p>Sorry, something went wrong<p>Please try closing and re-opening your browser window.
alimoeenyover 10 years ago
What does this even mean? How can you use facebook anonymously?
评论 #8572325 未加载
评论 #8572094 未加载