In a surprise announcement Friday, Facebook said it had joined with the anonymity network Tor, making it possible for users living in repressed nations around the world to use Facebook without fear of government retaliation.
Facebook published a blog post Friday announcing that it has created a new, hidden version of the website that's accessible only via the Tor anonymity software. Users will still have to log in to Facebook with their real identity, but after that their physical location, online activity and other potentially compromising information will remain encrypted. The Tor-only URL is available here: https://facebookcorewwwi.onion/
Though Tor is well known for facilitating online crimes, it was created in 2002 as a way of helping people access the Internet anonymously. People who download Tor software have their connection rerouted through hundreds of nodes around the world, with membership traditionally rising in countries where the Internet is restricted. Facebook's involvement is especially remarkable because Tor advocates have long called on the company to make it easier to access Facebook with Tor to help demonstrators and dissidents make announcements and connect with other users in their country without fear of prosecution.
It's also a big deal because it appears to be the first time that a site with Certificate Authority -- that is, a way of establishing secure connections with visitors -- has authorized a connection for Tor users. Facebook has traditionally made it difficult for Tor users to log on to the site, because when they reroute, Facebook's security safeguards respond as if hackers are trying to infiltrate the network.
“Tor challenges some assumptions of Facebook's security mechanisms – for example, its design means that from the perspective of our systems a person who appears to be connecting from Australia at one moment may next appear to be in Sweden or Canada,” Alec Muffett, a Facebook security engineer Alec Muffett, wrote in the blog post. “Considerations like there have not always been reflected in Facebook's security infrastructure, which has sometimes led to unnecessary hurdles for people who connect to Facebook using Tor.”
Still, both Facebook and members of the Tor Project have reminded users that the anonymity network doesn't mean Facebook won't know who is logging on. The same goes for any website; Tor simply protects the connection and skews the location.
“No, you're not anonymous to Facebook when you log in, but this provides a huge benefit for users who want security and privacy,” Runa Sandvik, a privacy and security research involved with Tor, said in the Facebook post. “You get around the censorhsip and local adversarial surveillance, and it adds another layer of security on top of your connection.”