Why are free proxies free? (2013)
blog.haschek.at
blog.haschek.at
Edit: Oddly, nobody from the schools ever called me out on it despite PII on the page and the WHOIS data (I was using personal domains at that point, .com and .info). I can't remember if Tor ever worked, but back then it was slow as hell anyway because even the school's "high-speed" connection wasn't close by today's standards.
Further edit: I was trying to learn PHP at the time, and was using some existing scripts along with dinky little modifications. It wasn't malicious, but a couple times it was fun to manually post stats for which sites were the most visited. The type of sites people used it for was not surprising. Regrettably I never took it far enough to do anything clever, instead pretty much abandoning code for following couple years.
Fun memories since I'd mostly buried that whole period as "boring, non-technical, and embarrassingly childish" stuff.
"Why wouldn't we? Our users aren't particularly tech-savvy, and we've calculated that 90% of our [user] base doesn't have an adblocker of such installed. ... [we] see 90% [of our income, combined with our VPN services] from injecting ads - sometimes, they are more relevant than what the visiting site serves."
Assuming you're injecting JS, the site isn't SSL meaning all that data is available to the proxy anyway (its part of their operation). The botnet angle is much more interesting than the loss of privacy one.
My understanding is that you should be able to set up a TLS session with a destination server while you're routing your traffic through a robot-in-the-middle. And the robot shouldn't be able to harm your content in any way, due to the encryption. (I originally said that a free proxy could still cause harm, but if HTTPS is involved, I'm pretty sure that's not true, otherwise Tor wouldn't work. It could drop the connection, but it shouldn't be able to modify anything.)
_However_, many free online proxies, e.g. HideMyAss, will simply fetch the page and send it to the client encrypted using their key. In this case, the TLS part is being done with the proxy website, not the actual website being requested. (Basically original website sends encrypted data to the proxy; proxy decrypts it and then encrypts it with its own key; proxy sends to browser.)
(Tor, however, will simply send the raw TCP packets back to the client).
HTTPS tries to perform two goals:
encryption: all the data is encrypted which means that a malicious agent can not sniff the data
authentication: since the data is signed by the website's key it can't be modified by an attacker.
The way HTTPS works is so that it's impossible to sniff the data or modify the data without having the session key (that might not be the correct name; but I don't remember). The session key is stored on the client and server. Without access to either of these machines it's impossible to break HTTPS.
However, the proxy could drop packets obviously.
Would it be true to say that HTTPS-over-proxy provides zero security for the end user, since a proxy must be able to encrypt raw HTTP requests/results on behalf of the client? In other words, the proxy can be blatantly malicious against the user, and the client won't even be able to realize that. The only security would be against any third-party eavesdroppers (someone else besides the user, proxy, or final website).
I might be wrong about that too, but I'm trying to grok it.
However, you can configure a proxy to intercept and re encrypt things. But the client (your browser) must trust the certificate that's re encrypting, which won't happen unless the proxy's CA cert is installed on your system. This most often occurs in corporate environment, where they control the endpoints.
Of course, if you're not careful, the proxy can do sslstrip and such, tricking users into not using/checking https. But if you're careful and check for HTTPS, you're OK in theory (assuming TLS works, no vulns, etc).
They say it is just for caching purposes (if the html data is encrypted they cannot serve cached images and so), but who knows what they do with your data as credit cards, etc.
If a man in the middle proxy decrypted the content and re-encrypted it, it would be using a different public key than the one that belongs to the original website, and your browser would know immediately and warn you, probably also preventing you from even loading the page.
The proxy would have to be trusted on your computer as a Certificate Authority, at which point you've given the proxy the power to say "trust me, this public key really does belong to Google". Even then, in many browsers the certificates for common websites are pinned, so if you tried to go to gmail.com for example and a proxy was intercepting it, and was also trusted as a certificate authority, chrome would still prevent the page from loading.
Even when you do, the connection to the proxy being HTTPS has nothing to do with the "https://" you see in the browser.
Bottom line: do you see a green "https://...google.com/..." ? Then you are safe. SSL stripping will NOT go undetected, without compromising your computer in some way (fake root CA).
For more info, search the net for SSL strip tools and look at their features. E.g.: homograph domain names, rewriting https:// links to http://, or using self-signed CAs (will cause SSL warning). If you find a real, clean SSL strip, make sure to post it here to HN. Guaranteed you will make the front page ;)
In Sweden a couple of years ago, the largest mobile operator Telia injected some toolbar with ads on top of all mobile web content. Within a working day literally all of the swedish media sites had collectively blocked all access to their web sites from Telia mobile IP ranges. The next day the ad toolbar was gone.
That's amazing - the market kicking back in full force and putting a giant back in its place. In other markets/regions this would just pass.
Do you have a source? I tried some googling but my English keywords seem to have no power ;)
and
https://translate.googleusercontent.com/translate_c?depth=1&...
Seems like my memory was a bit hazy. The issue was that not that they inserted their own ads on top of mobile content, but that they inadvertedly blocked some ad content in the actual sites.
One study suggested that even posting unallowed content might escape without censorship (let alone punishment) -- unless the posted content attracts discussion from others, and thus the algorithms make it look like you might actually be organizing.
One way or another, somebody is watching. Either it's the NSA or some ad agency interested in your browsing habits while you "bypass" the filters.
Then, he modified it slightly to scrape facebook username/passwords, and gave the URL to all his friends. :)
I wonder whether modern security practices (e.g. https everywhere) will make proxies less lucrative (and therefore less common).
> How children are supposed to not think of
> computers as magic boxes if they're prohibited
> from doing anything interesting on it (and that
> very much includes breaking them and fixing by
> themselves)?
The first thing every kid did in the computer lab was highlight all the icons on the desktop and try to delete them. We already knew how to use computers because we had one at home to mess with. The whole goal of the computer lab was to figure out how to create a bomb for the next user.Now pretend we aren't in the heights or mid/upper burbs anymore. There is no IT/networking staff. It's just Mr. Perkins, the English teacher that volunteered to look after the computer room. And there are kids without computers in their household. Too bad, all the computers are hosed because lol.
While their desktop proxy service is free, they also offer a premium account for their VPN services for mobile.
Nah, just use Private/Incognito windows when using "free" proxies
see my post above in this thread about setting up tinyproxy
can also use haproxy if its only one specific site you are scraping
2. Install tinyproxy (apt-get install tinyproxy)
3. Configure it to bind to the vps public ip, set a high port, limit access to your home/work ip address or range(s)
4. Set your browser proxy to vps.ip.add.res:12345
The above is simple and effective, only downside anyone else on your ip or range you specified can use that proxy too (if they find out the ip:port and if they done steps 3 and 4 above). You can switch off the vps when not using it (saving you money)
Basically having a http proxy (im not talking about web proxies but forward and reverse ones such as tinyproxy & haproxy) has its uses for example if you have a robot scraping via multiple addresses (to bypass limits for example or scrape different content dependant on location)
and well they are simpler to setup and use that vpns both on client on and server end
a vpn is fine in most cases but there are usecases where a quick and dirty http proxy helps save alot of headaches.
If you have ssh access, you can set up a proxy on the remote server, and use ssh dynamic port forwarding (-D) to forward the proxy connections on your local machine.
Using this trick you can safely use any ssh capable machine as a proxy. It works like a charm.
If are worried about privacy you should be using bitcoin (and know how to use this anonymously, which i am not going to go into), You could then buy a vps with bitcoin quite anonymously with likes of chunkhost.com or bithost.io (reselling digitalocean for btc)
https://www.linode.com/docs/networking/ssh/setting-up-an-ssh...