{"id":123,"date":"2006-12-07T23:40:43","date_gmt":"2006-12-08T07:40:43","guid":{"rendered":"http:\/\/outflux.net\/blog\/archives\/2006\/12\/07\/paranoid-browsing-with-squid\/"},"modified":"2016-07-27T19:58:06","modified_gmt":"2016-07-28T03:58:06","slug":"paranoid-browsing-with-squid","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2006\/12\/07\/paranoid-browsing-with-squid\/","title":{"rendered":"paranoid browsing with squid"},"content":{"rendered":"<p>As <a href=\"http:\/\/ubuntu.wordpress.com\/2006\/12\/08\/ssh-tunnel-socks-proxy-forwarding-secure-browsing\/\">Carthik<\/a> says, the SSH SOCKS option is a great way to quickly tunnel your web traffic.  A word of caution for the deeply paranoid: all your DNS traffic is still in the clear.  While the web traffic and URLs aren&#8217;t sniffable any more, curious people can still get a sense for what kinds of stuff you&#8217;re browsing, based on domain names.  (And for the really really paranoid: if you&#8217;re on open wireless, your DNS lookups could get hijacked, causing you to browse to look-alike sites ready to phish your login credentials.)<\/p>\n<p>Luckily, with SOCKS5 Firefox can control which side of the proxy handles DNS lookups.  By default, it does the lookups locally resulting in the scenario above.  To change this, set <strong>network.proxy.socks_remote_dns = true<\/strong> in <a href=\"about:config\">about:config<\/a>.  This makes the SOCKS proxy more like a regular proxy, where DNS is handled by the remote end of the tunnel.<\/p>\n<p><strong>Update:<\/strong> Oops, as the title hints, I was going to talk about Squid.  But then I didn&#8217;t.  It&#8217;s pretty cool too.  Carry on&#8230;<\/p>\n<p style='text-align:left'>&copy; 2006 &#8211; 2016, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>As Carthik says, the SSH SOCKS option is a great way to quickly tunnel your web traffic. A word of caution for the deeply paranoid: all your DNS traffic is still in the clear. While the web traffic and URLs aren&#8217;t sniffable any more, curious people can still get a sense for what kinds of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,14],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/123"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=123"}],"version-history":[{"count":1,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/123\/revisions"}],"predecessor-version":[{"id":889,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/123\/revisions\/889"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}