Delivery-Date: Wed, 17 Feb 2016 18:18:03 -0500
Return-Path: <tor-talk-bounces@lists.torproject.org>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on moria.seul.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.1 required=5.0 tests=BAYES_00,DKIM_SIGNED,
	RCVD_IN_DNSWL_MED,T_DKIM_INVALID,T_RP_MATCHES_RCVD autolearn=ham version=3.3.1
X-Original-To: archiver@seul.org
Delivered-To: archiver@seul.org
Received: from eugeni.torproject.org (eugeni.torproject.org [38.229.72.13])
	(using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by khazad-dum.seul.org (Postfix) with ESMTPS id 1D7821E0B49;
	Wed, 17 Feb 2016 18:18:02 -0500 (EST)
Received: from eugeni.torproject.org (localhost [127.0.0.1])
	by eugeni.torproject.org (Postfix) with ESMTP id EDB3A393DC;
	Wed, 17 Feb 2016 23:17:54 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
 by eugeni.torproject.org (Postfix) with ESMTP id 9210D3928C
 for <tor-talk@lists.torproject.org>; Wed, 17 Feb 2016 23:17:51 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at 
Received: from eugeni.torproject.org ([127.0.0.1])
 by localhost (eugeni.torproject.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id ohUHKEBTGHI5 for <tor-talk@lists.torproject.org>;
 Wed, 17 Feb 2016 23:17:51 +0000 (UTC)
Received: from mx0a-00082601.pphosted.com (mx0a-00082601.pphosted.com
 [67.231.145.42])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (Client did not present a certificate)
 by eugeni.torproject.org (Postfix) with ESMTPS id 64BB03925F
 for <tor-talk@lists.torproject.org>; Wed, 17 Feb 2016 23:17:48 +0000 (UTC)
Received: from pps.filterd (m0044010.ppops.net [127.0.0.1])
 by mx0a-00082601.pphosted.com (8.15.0.59/8.15.0.59) with SMTP id
 u1HNELlY004919
 for <tor-talk@lists.torproject.org>; Wed, 17 Feb 2016 15:17:45 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=fb.com;
 h=from : to : subject : date
 : message-id : references : in-reply-to : content-type :
 content-transfer-encoding : mime-version; s=facebook;
 bh=LzIxVPGApopNmi8hePi5H4sueBdiiaLPb+WkrGaAkPM=;
 b=Uoow+hAOgPaGrxiba6mCMLTWBK4Fv1ROnxOv7OFrFLMDJXNn/pK+PnWgkoGO83027lVi
 JLWjSPIiMic4G+olDj1gPJyEafEpEflhljiVTVDz405N5UChsAZuo3KpM7tCwKWO3UCI
 ZmgkZSkOXQ3M+JaDf8gW2W6ShWHlzgTrwCg= 
Received: from mail.thefacebook.com ([199.201.64.23])
 by mx0a-00082601.pphosted.com with ESMTP id 2151u3g4kd-1
 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NOT)
 for <tor-talk@lists.torproject.org>; Wed, 17 Feb 2016 15:17:45 -0800
Received: from PRN-MBX02-4.TheFacebook.com ([169.254.2.160]) by
 PRN-CHUB08.TheFacebook.com ([fe80::c9c7:30fd:ad3:b94%12]) with mapi id
 14.03.0248.002; Wed, 17 Feb 2016 15:17:45 -0800
From: Alec Muffett <alecm@fb.com>
To: "tor-talk@lists.torproject.org" <tor-talk@lists.torproject.org>
Thread-Topic: [tor-talk] Does Facebook Onion Work?
Thread-Index: AQHRacBQgLbU7HYXT02wve1vrbWLNJ8xQe8AgAABboCAAAKOAP//kBDZ
Date: Wed, 17 Feb 2016 23:17:43 +0000
Message-ID: <A806FDDFD9B20F4DA7EAC5A362E5E35277C59367@PRN-MBX02-4.TheFacebook.com>
References: <4bec438e9c32eae22790e149ec49a419@openmailbox.org>
 <D262C9CF-743B-4801-BC0B-71D9B8B2805B@sebastianhahn.net>
 <20160217211551.GA2142@raoul>,
 <A1331FB6-0A6D-490A-92DD-568D7F3D2ECD@sebastianhahn.net>
In-Reply-To: <A1331FB6-0A6D-490A-92DD-568D7F3D2ECD@sebastianhahn.net>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [192.168.52.123]
MIME-Version: 1.0
X-Proofpoint-Spam-Reason: safe
X-FB-Internal: Safe
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, ,
 definitions=2016-02-17_11:, , signatures=0
Subject: Re: [tor-talk] Does Facebook Onion Work?
X-BeenThere: tor-talk@lists.torproject.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: tor-talk@lists.torproject.org
List-Id: "all discussion about theory, design,
 and development of Onion Routing" <tor-talk.lists.torproject.org>
List-Unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=unsubscribe>
List-Archive: <http://lists.torproject.org/pipermail/tor-talk/>
List-Post: <mailto:tor-talk@lists.torproject.org>
List-Help: <mailto:tor-talk-request@lists.torproject.org?subject=help>
List-Subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: tor-talk-bounces@lists.torproject.org
Sender: "tor-talk" <tor-talk-bounces@lists.torproject.org>

Hi All!

I just wanted to confirm that facebookcorewwwi is working and is under active development; we are currently working on scaling bandwidth so that we can support more people who want to use Facebook over Tor.

The facebookcorewwwi URLs use (and need) subdomains which are respected by web browsers, albeit that they are invisible to the Tor protocol.

The URLs are as follows:

  https://www.facebookcorewwwi.onion/

  https://m.facebookcorewwwi.onion/

...the latter URL ("M-site") is a web-version of Facebook designed for mobile devices, which uses Javascript and yet can *also* be used without Javascript being available at all.

When an issue (potential bug?) is raised with us, we generally attempt to reproduce it. Our rule-of-thumb is to try reproducing the issue on a recent (ideally latest) version of TorBrowser, without extra extensions, and with the TBB "Security Level" set between Low/Medium-High (for www) or between Low/High (for m-site).

So far I have only managed to reproduce the "looping" issue once, and then only by exceeding the bounds of our "rule of thumb"; I currently suspect that this behaviour is related to manual configuration of Javascript controls in such a way that JS is only partially-enabled for the site, leading to anomalous script behaviour.

Where Javascript is considered a risk it seems wisest to disable it entirely (Security Level: High) and then use M-site; restarting Tor Browser should clear any active state that would trigger the issue. 

    - alec

--
Alec Muffett
Security Infrastructure
Facebook Engineering
London

-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

