VirtualFriendship: Shielding Social Interactions from the Prying Eyes of OSN Providers

VirtualFriendship: Hiding interactions on Online Social Networks

2014-10-01
Filipe Beato, Mauro Conti, Bart Preneel, Dario Vettore
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces VirtualFriendship (VF), a hybrid privacy-preserving architecture that enables users to hide their social network structure and browsing behavior from centralized Online Social Network (OSN) providers like Facebook. It leverages a decentralized network of "routing friends" and anonymous networks (e.g., Tor) to decouple user identities from their online interactions.

TL;DR

VirtualFriendship (VF) is a hybrid privacy framework that allows users to stay on mainstream platforms like Facebook while hiding their interaction patterns. By leveraging a decentralized channel of "routing friends" and Tor, it ensures that your social network provider cannot track whose profile you visit or who you are truly close to.

The Hidden Cost of "Connecting the World"

Online Social Networks (OSNs) are free because we are the product. While many users have adopted encryption tools to hide the content of their messages, the metadata—who you talk to, whose photos you linger on, and the structure of your friendship circle—remains an open book for the OSN provider. This behavioral data allows providers to build intimate psychological profiles or facilitate government surveillance (e.g., NSA's PRISM).

The core challenge is that current privacy-enhancing technologies are binary: you either use a centralized, feature-rich but invasive OSN, or you switch to a decentralized alternative (like Diaspora) where none of your friends are.

Methodology: Social Trust as a Routing Layer

VirtualFriendship bridges this gap with a hybrid approach. It doesn't ask you to leave Facebook; it asks you to change how you access it.

1. The Concept of Routing Friends

The key innovation is the Routing Friend (F). Unlike a standard OSN connection, a routing friend is a contact you trust socially to relay your traffic.

  • Public Connections (C): Your standard Facebook friends.
  • Private Relationships (R): A subset of that serves as your anonymous routing entries and exits.

2. The Anonymity Loop

When Alice wants to view Bob’s profile, she doesn't request it directly from Facebook. Instead:

  1. Request Generation: Alice’s local server () creates a request.
  2. The Relay: The request is sent through an anonymous network (Tor) to a Routing Friend of Bob (say, ).
  3. The Fetch: uses their own credentials to fetch Bob's profile from the OSN.
  4. The Return: encrypts the data and sends it back through the anonymous tunnel to Alice.

VirtualFriendship System Overview

From Facebook’s perspective, simply looked at Bob's profile—a perfectly normal interaction. The fact that Alice was the actual requester remains hidden.

Technical Deep Dive: Token-Based Authentication

To prevent unauthorized users from hijacking these routing channels, VF uses a Token-based Authentication system.

  • Token Unforgeability: Users exchange authorization tokens () out-of-band or via encrypted in-band messages.
  • Proof of Knowledge: When requesting content, the requester provides a MAC (Message Authentication Code) of a random nonce using the token. This proves they have permission to view the content without revealing their identity to the entry routing friend.

Information Request Process

Latency vs. Liberty: Experimental Results

The researchers implemented VF-App, a Firefox extension. The primary trade-off is latency. Routing through Tor and intermediate friends inherently slows down the browsing experience.

  • Cryptographic Overhead: Negligible (~12ms total for authentication and decryption).
  • Network Latency: As shown in the performance graph, retrieving a full profile takes significantly longer than a native Facebook request (seconds vs. milliseconds).

Performance Comparison

However, the authors argue this is a "tolerable cost" for users who prioritize privacy. The system achieves a high degree of Entropy-based Anonymity—as long as a user has a decent-sized group of routing friends, the probability of the OSN provider correctly guessing the requester's identity remains low.

Critical Analysis & Conclusion

VirtualFriendship is a pragmatic "middle-ware" solution. It acknowledges that the massive network effect of platforms like Facebook is too strong to overcome with decentralized clones. Instead, it "parasitizes" the existing infrastructure to provide privacy.

Limitations:

  1. Availability: Routing friends must be online to relay traffic.
  2. "Like" Interactions: The current model doesn't easily support public actions like "Liking" a post, which inherently links an identity to an action.
  3. Tor Blocking: As a system dependent on Tor, it is vulnerable to environments where Tor entry nodes are blacklisted.

In conclusion, VirtualFriendship proves that your social circle can be your greatest privacy asset. By formalizing social trust into a technical routing protocol, we can begin to claw back our behavioral anonymity from the central hubs of the internet.

Find Similar Papers

Try Our Examples

  • Search for recent studies that utilize social trust or "trusted execution environments" to anonymize user behavior in centralized social media platforms.
  • What are the original theoretical foundations of using the social graph as a mixing network for anonymity, and how has this lineage evolved since the "Drac" or "Pisces" architectures?
  • Explore how decentralized routing friend mechanisms can be adapted for mobile-first OSN environments where persistent peer availability and bandwidth constraints are more significant factors.
Contents
VirtualFriendship: Shielding Social Interactions from the Prying Eyes of OSN Providers
1. TL;DR
2. The Hidden Cost of "Connecting the World"
3. Methodology: Social Trust as a Routing Layer
3.1. 1. The Concept of Routing Friends
3.2. 2. The Anonymity Loop
4. Technical Deep Dive: Token-Based Authentication
5. Latency vs. Liberty: Experimental Results
6. Critical Analysis & Conclusion