milankragujevic 11 years ago

Couldn't you just use Facebook's "Fetch as FacebookBot" feature and just fetch the pages yourself? Example: https://developers.facebook.com/tools/debug/og/echo?q=https%... I was thinking about doing this since on my network Facebook access is free but Internet isn't. (2nd world country, but barely)

  • hippich 11 years ago

    It looks like it is more general purpose, than just html browser.

    • spiritplumber 11 years ago

      Potentially a problem that internet = web, at zeroth approximation.

  • h43k3r 11 years ago

    How does they rate limit this thing?

Liquix 11 years ago

To me, the worst part of this is that there are places where Facebook is free but you need to pay for an internet connection. If the average user can only access the mindless corporate money-making machines and not the real internet, we are moving in the wrong direction.

  • jsedgwick 11 years ago

    What constitutes the real internet - the rest of it ?

  • randartie 11 years ago

    They went from having no free internet to having Free facebook + other core sites like wikipedia through Facebook's internet.org, but it's moving in the wrong direction?

    >If the average user can only access the mindless corporate money-making machines and not the real internet

    They can, but it's not free, and a lot of people have no other option but to use what is free. This corporate money-making machine just provided pure value to a ton of people, there's no downside to having this additional option available.

    • nitrogen 11 years ago

      there's no downside to having this additional option available.

      Sure there's a lot of value in communicating with other Facebook users, but if you can't see the possible downside of having a large group of people's first and only connection being through a corporate-controlled view of the world, you're not using your imagination.

      • icelancer 11 years ago

        Can you actually make the argument that access to Facebook/Wikipedia/etc is worse than no Internet whatsoever?

        • foiboitoi 11 years ago

          Wouldn't it prevent people interested in creating an ISP in any area that has "free" facebooknet? Especially if the services provided by facebooknet is most of which people would want with an ISP anyway?

          So not only does it prevent competitor websites, but it stops competitive ISPs, too. It's especially bad if this coporate network is censoring information. No opportunity to even discover non-filtered information outside the info bubble. This triple whammy is the consequence for those involved or not.

          • girvo 11 years ago

            Are those competitive ISPs going to give the audience we're talking about access to the net for free as well? Because for a lot of people in this world, they will never be connected to the net unless they don't have to pay; they simply can't afford it.

            • microtonal 11 years ago

              That's why we need government or non-profit programs, giving general access to the net. Because only then it is a level playing field, and the next Facebook can be from Brasil.

              This is only an intentional effort to control and shut out competition (e.g. future Facebook competitors) and has the risk of killing local ISPs as a by-product.

              tl;dr It only serves Facebook. Wikipedia et al. are just thrown into the mix to make it look like a humanitarian effort.

            • foiboitoi 11 years ago

              Why would they need to be "free?" Not everyone needs personal internet to benefit from a free (as in freedom) internet being available in their area. Unfiltered information spreading in a community is almost guaranteed if it exists.

              How on earth are we going to get them innovative/affordable internet solutions if no one can compete to get there?

        • hueving 11 years ago

          It would be somewhat contrived, but you could argue that the shown ability of Facebook to influence the moods of a population via filtering content could be used to oppress underprivileged people.

        • andreyf 11 years ago

          Yes, absolutely, and it's not a new idea, e.g. "sending shirts destroys local textile economies by flooding the market with free goods and undercutting local t-shirt producers" [1].

          1. http://freakonomics.com/2011/02/15/what-happens-to-all-those...

          • themusicgod1 11 years ago

            This allows those communities to dedicate resources that would have gone towards shirt manufacturing into something more valueable. Textile economies are a mostly waste of human ingenuity and time, and have been since the Jacquard Loom at least.

            • andreyf 11 years ago

              Within our lifetimes, this reasoning will apply to more professions than you might think. "Dignity is more important than wealth" and all...

  • qq66 11 years ago

    Free Facebook means the ability to send and receive messages with ~1 billion people at no cost. That's hugely valuable to a lot of people without the money for a general-purpose Internet connection.

    • microtonal 11 years ago

      And it will destroy the prospects of a healthy local internet economy where everyone can publish information or compete on a level playing field.

zx2c4 11 years ago

Back in the day when Skype was a pretty cool peer-to-peer encrypted mesh network, that successfully evaded firewalls and traffic analysis, I wrote a tool to proxy Internet traffic ontop of the Skype mesh. I was quite young when I wrote it, but I managed to dust off an old demo screencast I made (and convert the swf to an mp4), which gave me a laugh. If you're curious:

http://data.zx2c4.com/skypeproxydemo.mp4

  • orangebread 11 years ago

    That is very cool. Does Skype not have a direct peer to peer connection anymore?

    • zx2c4 11 years ago

      Supposedly since the Microsoft buy-out, everything is gradually becoming centralized.

WhitneyLand 11 years ago

I've been wondering if something like this could be helpful to breach the great firewall.

Find some high traffic site in China and smuggle in content via various site features such as chat, messaging, forums, etc.

The content could be obfuscated to appear benign while embedding hidden data in text, images, or binary attachments.

fitzwatermellow 11 years ago

Wonderful proof-of-concept!

Humanity needs steganography-as-a-service. But think how difficult it is to implement in a regime where all networks are monitored and even Android phones are assumed to be backdoored. Most services will re-encode data during transmission, potentially munging whatever secret happens to be embedded. And more generally, its the metadata that often de-anonymizes, not the data itself. If all the dissidents one day begin communicating via Lutheran Insult memes, its simply becomes a matter of picking one up and applying "rubber-hose" cryptanalysis to put an end to the party.

cheesedoodles 11 years ago

This is really cool! In so many 2nd and 3rd world/poor countries internet is a luxury, as the price of bandwith is so high. Philippines for instance, a country that mainly provides connectivity through limited 3G and LTE, have a monthly price of about 30 beers from the local bar. In comparison, I pay around the price of 4-5 local beers, for 100/100 fiber.

Its sucks so hard that people cant afford to get knowledge from internet. Especially considering they would benefit greatly as schoolbooks are expensive and in some countries, censored.

  • matiasb 11 years ago

    Hack author here, in my country, Paraguay, you get 10 MBPS for ~140 U$ per month. I discovered the Internet through my father, because he is a journalist and the press had really early access to this kind of tech, 20 years later I'm still crazy about it. Thanks for the comment!

    • cheesedoodles 11 years ago

      Wow! Thats really expensive! Hard do access stuff often sparks creative ideas and solutions :) Keep on hacking!

  • hobarrera 11 years ago

    ~70USD for a symetric 3Mbps static-IPv4/6 connection in Argentina.

    I believe asymetric normal connections cost about ~40USD.

    A beer is about 4USD, IIRC, if that helps the comparison.

anticodon 11 years ago

Facebook limits number of messages you can send. After passing some secret threshold, your profile would be put in 'restricted' mode.

k__ 11 years ago

I once read a story about tunneling IP over DNS. Something about free Internet/DNS for Microsoft-Update. But I can't find it.

  • jakejake 11 years ago

    I remember possibly the same article - it was a guy who noticed that airport wifi allows DNS even if you haven't paid.

    • mariuolo 11 years ago

      Yes, they have to because of how Windows detects connectivity (NCSI).

  • chx 11 years ago
    • yhager 11 years ago

      Yeah, I've played with that a bit..it was fun. It worked in airports, as DNS was available, even though you had to pay for actual surfing. Not surprisingly, it was quite slow.

acd 11 years ago

Some mobile operators offer unlimited Facebook and whatsapp traffic doesn't count towards the monthly data transfer limit.

  • userbinator 11 years ago

    I've heard this is also true for Twitter and a few other social networking sites, so you could potentially tunnel your traffic through them too.

    However, these tunnels are going to be relatively low-bandwidth (especially if they start throttling it) and high-latency, so the "unlimited" would in reality be "how much can you transfer continuously in a month?"

JoshTriplett 11 years ago

Interesting, but wouldn't you need a server somewhere to act as the other end of the tunnel, for which you'd have to pay for hosting and/or bandwidth anyway?

  • matiasb 11 years ago

    Sure, you need that end!

  • wongarsu 11 years ago

    But hosting and bandwith for servers is extremely cheap if you don't care about reliability and trendyness. You can get a vps with 1Tb bandwidth/month for $4 (probably even less if you look around more than I did). Try getting mobile bandwidth for anything near that price.

purringmeow 11 years ago

I am pretty much a beginner dev, so can anyone briefly explain how this works? It's not really clear to me from the code.

It's mentioned in the README that packets are being sent as base64. Let's say I would like to send a GET request to google.com. How does Facebook Chat serve me with google's page?

swah 11 years ago

I was just reading about gumbo parser yesterday! h/t @nostrademons

Very nice hack... its just fun to do something like this.

Reminds me when I used to fiddle w/ "phreaking" when it was really easy. I didn't think about ethical implications - just got a really big thrill when I got a free call.

  • nostrademons 11 years ago

    Thanks! I'm glad to see it used for things...when I wrote it (and decided to open-source it), it was very much a "Well, I have one immediate need for this, but it seems like people could do a lot with a robust HTML5 parser with a simple API."

greggman 11 years ago

interesting given FB keeps chat history forever

  • szatkus 11 years ago

    I wonder if they have any flood protection...

    Also HTTPS packets should be quite safe.

    • corndoge 11 years ago

      It'd be more interesting if this was done over Google's chat, since Chrome trusts the Google Internet Authority cert...

      • modeless 11 years ago

        What makes this interesting is the fact that Facebook chat traffic is subsidized by Facebook and free of charge in some countries as part of their anti-net-neutrality "Internet.org" initiative. This project allows you to hijack the Facebook subsidy for purposes they didn't intend. Of course, if it becomes popular then Facebook will have to block it, emphasizing the self-serving commercial nature of the subsidy.

        • nl 11 years ago

          Internet.org might not be net neutral, but that doesn't make it bad. Much of the world isn't the US, and differently structured markets need to be considered differently.

          • zanny 11 years ago

            So if you are in an impoverished area your packets are different from first world packets, magically making it harder to send them to 207.241.224.2 (archive.org) than 173.252.120.6 (facebook.com)?

            No, that is not the case. Instead, Facebook will pay for you to get Internet if that is Internet that only lets you access Facebook. And that is not an Internet at all. The infrastructure, the physical reality, means that if you have any connection, you can have all connections, and in these circumstances only profit hungry greedy monsters would consider effectively blacklisting every site but their own to guarantee them revenues to show to shareholders for providing network connectivity to you - or I guess it should be more appropriately called Facebook connectivity.

            • Dylan16807 11 years ago

              They're not blacklisting anything.

              The only bad thing they do is call it "internet". It's not internet access. Free access to things like wikipedia is a good thing, as long as it's not taking money away from actual free internet initiatives.

              Price gouging actual internet access would also be bad, but that would be someone else doing it, and I don't think it's happening here.

            • sukilot 11 years ago

              Did you know that yombinator.com o ly allows you to transmit comments on HackerNews posts, subject to heavy moderstion, not free and open internet speech?

            • sukilot 11 years ago

              I didn't know that infrastructure was free to build and maintain. I wonder why WorldCom and Global crossing went bankrupt, if they had no expenses.

            • nl 11 years ago

              I think that internet access to a site like Wikipedia is incredibly valuable to those with no internet access.

              If Facebook wants to pay for that, and the cost is that they also get access to Facebook then my view is that is a net good.

        • pakled_engineer 11 years ago

          Here's one telecom's implementation of this proprietary Internet.org app showing free tier fb/messenger the photos are still displayed just obscured until you pay for a data plan (notice it uses free.facebook.com which is complicit in enforcing this. https://youtu.be/sUGZdFXs22o?t=2m16s

          Guess no embedding creative commons university pdfs in wall posts.

andrepd 11 years ago

With a built-in encryption layer (on top of eventual HTTPS) it could be a useful "hack" for the kinds of situations mentioned in the readme. I wonder how facebook and the telecos will feel about this. All in all, a cool concept but unlikely to work in practice if either facebook or the telecos do not want to.

  • vincentclair 11 years ago

    It would be cool if a company such as facebook supported this. Seeing them as an enabler for free/uncensored internet, given that the country was chosen for a internet.org campaign.

    • jakejake 11 years ago

      If Facebook wanted to support it they would probably just implement a standard proxy server that would be more efficient. If anybody can handle the traffic it would be Facebook, but I bet their chat services are not really tuned for this kind of usage.

      • vincentclair 11 years ago

        It would certainly be interesting if facebook started to provide proxy access

        • sitkack 11 years ago

          They sure as hell would love to see all of your traffic. Facebook wants to be your ISP, no actually, Facebook wants to be your internet.

        • cmdrfred 11 years ago

          The question then is, do you trust facebook more than your isp?

          • icelancer 11 years ago

            For those of us with Comcast, it's a pretty close race...

    • hobarrera 11 years ago

      They're also basically the ones responsable for restricting that same internet access.

      If they wanted you to access those other sites, they'd have given you access to them.

      But why would they? As-is, they have no competition. "when there's only one choice, there's only one vote!"

vskarine 11 years ago

I tried something like this over gchat but they throttled pretty soon so didn't work well. But it worked for me over Firebase. Here is simple project to demo how to do VNC over Firebase: https://github.com/vskarine/fireport

hartror 11 years ago

Dear Australian Government,

Please add this to your list of reasons why your wrong headed "meta"-data retention plan can not work.

Rory

nly 11 years ago

Uses Gumbo... from the README

> Gumbo was initially designed for a product that worked with trusted input files only. We're working to harden this and make sure that it behaves as expected even on malicious input, but for now, Gumbo should only be run on trusted input or within a sandbox.

  • nostrademons 11 years ago

    That's mostly historical at this point - Gumbo passed a security review as of 0.9.1, has had several rounds of fuzz testing, and is used by a bunch of other libraries now. It's been struck out of the README at HEAD, though I think it was listed in several earlier versions' READMEs.

fugyk 11 years ago

While I find this project awesome, but I don't think telecos or even facebook will allow this in long run. I think that it even breaks facebook TOS.

fallat 11 years ago

Base64 encoding is such a useful tool. I used it to transfer binary over IRC once.

  • lo96z 11 years ago

    Why not just use DCC?

    • fallat 11 years ago

      DCC relies on all parties to have a specific port open and even then if the connection drops all hell breaks loose.

r0naa 11 years ago

That's a really neat hack, love it.

0x0 11 years ago

We need screenshots here! :D

ape4 11 years ago

Nice hack

erodingvar 11 years ago

This is the kind of hacking I find to be abusive. Finding clever uses for things is fine, but not when it's misuse with potential for harm. This reminds me of when someone exploited TinyURL to make TinyDisk.

tzakrajs 11 years ago

No, please no this is terrible.

logicallee 11 years ago

I think this is kind of abusive of FB's infrastructure TBH. It must be hard to keep real-time messaging up for ... okay, I was going to say for 1 billion users, looked it up and it's 1.3 billion monthly actives - 890 million daily actives (Jan 2014 figure). So tell you what, on second thought I think they can handle your data.

however there's a good chance you'll cause some infrastructure problems since I'm sure there are assumptions baked in, regarding how often a user will send new messages, queuing, caching, etc. so I'm still not totally sure how I feel about this.

at the end of the day FB is just a php script. i wouldn't be surprised if you break it.

  • ForHackernews 11 years ago

    Maybe if it becomes popular, it'll make facebook rethink wanting to store everyone's messages until the end of time.

    • im3w1l 11 years ago

      Or limit how much data you can send over chat. Say max 10 bytes per second sustained (higher burst) allowed. Should be enough for normal chat, while limiting infrastructure problems.

    • sitkack 11 years ago

      If facebook can see this traffic, they would love it, not discourage it.

      • ForHackernews 11 years ago

        I think a good implementation of this would encrypt the traffic between the proxy server and the client.

    • kudu 11 years ago

      Hahahah nope.

  • jacquesm 11 years ago

    It's one of the more useful ways facebook infrastructure is put to work.

  • kudu 11 years ago

    I totally support this "abuse" of their infrastructure if it makes them realize that giving free access to their own social network via Internet.org isn't a charitable endeavour.