Privoxy – a non-caching web proxy with advanced filtering capabilities
privoxy.org
privoxy.org
I wonder if Privoxy would compile / install on the Ubiquiti EdgeRouter Lite (it should, since it just runs an ARM build of Debian, but firmware updates would possibly wipe away all your set-up). I'm also not sure if the little ERLite has enough horsepower to efficiently handle running a filtering proxy with tons of rules.
I was using it for a while in place of AdBlock because of the memory issues associated with the Chrome AdBlock extension (Gmail would regularly and quickly balloon to 1-1.5GB of memory usage).
I recently moved over to µBlock to give it a shot, and pages seem to load faster than through Privoxy (plus I can use QUIC on Google services since there's no proxy), but I haven't had an opportunity yet to test the memory implications.
[1] https://github.com/gorhill/uBlock/wiki/%C2%B5Block-vs.-ABP:-... [2] https://github.com/gorhill/uMatrix
I use Proxomitron ( http://en.wikipedia.org/wiki/Proxomitron ), which is quite similar in basic operation but also allows filtering HTTPS using OpenSSL. You do need to create and install your own certificates, which fortunately isn't all that difficult. I suppose you could call it a "benevolent MITM". The author has unfortunately long passed away, and it's not open-source, but there's still a small and active community working on patches to improve its functionality.
Just wanted to comment that setting up your own CA is the solution I chose to go with to continue filtering HTTPS sites. Certificate pinning can prevent this, but apps or devices that employ that can simply be uninstalled or resold.
The move to HTTPS is intended to benefit consumers, it doesn't have to be an obstacle to viewing sites the way you want to.
I believe in being able to verify that a device or app isn't leaking sensitive information, and I enforce that using HTTPS interception. As an app developer if you attempt to lock me out of the communications leaving my network, I the choice of potentially compromising my security and privacy or the choice of blocking the traffic, and I choose to take a hard line when it comes to security.
The frustrating thing is that HTTPS is typically seen as good guys (server operator) vs bad guys (anything who isn't the client browser). But there's a lot of gray areas.
Take any network that wants to scan HTTPS traffic for incoming viruses at the perimeter for example, which is a lot of corporate networks. Any use of certificate pinning restricts the network owner's ability to virus-scan or apply Data Leakage Prevention rules to that traffic.
We probably both agree that virus scanners are unlikely to catch emerging threats and that DLP rules are easily bypassed, but they are also layers of a much larger security onion.
Edit: HSTS headers can be stripped in transit, but certificate pinning requires significantly more effort to defeat and IMO isn't worth the effort, that's why I talked about cert pinning.
I disagree that I shouldn't try to catch the low hanging fruit because of the existence of higher hanging fruit.
Like it or not, some people have a legit need to protect the data on their network.
We understand that only the most obvious leaks will be caught this way. The existence of more sophisticated attackers shouldn't discourage you from trying to catch the less sophisticated ones.
If you really want to see the data transferred by a specific app, inspect/modify your app's source code. If you don't have the app's source code, and you are worried about what data it transmits, what are you doing using it?
Most leaks aren't terribly complicated.
If I was an ISP or network provider I would have to agree with you.
Is there an easy way to install this on Mac Os X currently so I can test it out ?
brew update && brew install privoxy
https://github.com/Homebrew/homebrew/blob/master/Library/For...I have always thought ad blocking in the browser is crazy since so many programs these days have browsers built in (mail, RSS readers etc) not to mention trying to sync the configs for multiple browsers.
My usage seems to be the opposite of yours as I use the web browser as a fallback.