AnonyFacebook: Protecting Activism through Cryptographic Privacy
AnonyFacebook - Liking Facebook Posts Anonymously
AnonyFacebook is a principled privacy-preserving system that enables users to "like" social media content without revealing their identity to the platform or third parties. By leveraging Exponential ElGamal homomorphic encryption and threshold secret sharing, it maintains an accurate public tally of likes while ensuring individual actions remain mathematically obscured.
TL;DR
AnonyFacebook is a research-driven architecture that allows users to engage with social media content (specifically "liking" posts) with absolute anonymity. By combining Exponential ElGamal homomorphic encryption with Threshold Cryptosystems, the system ensures that even the Facebook administrators cannot determine which user liked which post, while still maintaining an accurate, verifiable count of total engagement.
Background: The Price of a "Like"
In the context of global social movements, such as the Arab Spring, social media engagement is more than just digital vanity—it is a tool for mobilization. However, this visibility is a double-edged sword. As noted in the paper, activists like Wael Ghonim were targeted based on their social media footprints. The fundamental flaw in current Social Network Architectures (SNAs) is that engagement is tied to identity by design.
The authors argue that for a social network to be safe for political discourse, it must support quantitative feedback without individual identification.
Methodology: The Core Mechanism
The brilliance of AnonyFacebook lies in its ability to perform arithmetic on data it cannot see. The architecture relies on three pillars:
1. Exponential ElGamal Homomorphic Encryption
Standard encryption hides data. Homomorphic encryption allows the server to compute the sum of "Likes" while they are still encrypted.
- A "Like" is represented as , and a "No-Like" as .
- The server receives these encrypted bits and multiplies the ciphertexts. Due to the properties of Exponential ElGamal, the product of the ciphertexts corresponds to the sum of the plaintexts.
2. The Decoy Strategy (Privacy vs. Deduplication)
If a user only sent an encrypted "1" for the post they liked, the server would still know which post was liked, even if it didn't know who sent it (if the connection was anonymized). To solve this, AnonyFacebook uses a "K-anonymity" style approach:
- The client sends the
post_idin cleartext to allow the server to prevent duplicates. - To hide the true intent, the client sends the real post ID alongside random decoy post IDs.
- The server sees a user interacting with several posts but doesn't know which one received the "1" and which received the "0".

3. Distributed Trust (Threshold Cryptography)
To prevent the Facebook server from eventually decrypting the data, the private key is never held by a single entity. It is split into "shadows" distributed among various Trustees (e.g., neutral NGOs). Decryption of the final "Like" count requires a majority of these trustees to participate, ensuring no single party can compromise user privacy.
Experimental Insights
The paper addresses two primary concerns: Usability and Accuracy.
- Collision Probability: Because the server rejects duplicate
post_identries to prevent double-voting, there is a risk that a user might be blocked from liking a post if it was previously used as a "decoy." The authors calculated that with Facebook's scale, a user would only encounter such a collision roughly once per year, a negligible trade-off for total anonymity. - Performance: While cryptographic operations are more taxing than standard database writes, the authors' implementation (available as an open-source replica) proves that the latency is well within the bounds of modern web expectations.
Critical Insight & Conclusion
AnonyFacebook represents a shift from "Trust us, we won't look at your data" to "We cannot look at your data."
While the current implementation relies on a specific set of Trustees—which introduces a new layer of organizational complexity—the technical foundation is sound. The move toward privacy-preserving quantitative feedback is a vital step in evolving social networks from centralized surveillance hubs into genuine platforms for free expression.
Future Directions
The authors suggest that as CPU power grows, the overhead of homomorphic encryption will vanish, making this architecture viable for larger-scale deployments. Future work could potentially integrate Zero-Knowledge Proofs (ZKPs) to prove that an encrypted "Like" is indeed a 0 or 1 without the need for decoy post IDs, further optimizing bandwidth.
Academic Identity: This review was structured by a Senior Tech Editor focusing on the intersection of Cryptography and Social Computing.
