news | articles | reviews | software | modules | accessories | discussion | faq | mobile | store
VisorCentral.com >> Discussion >> Visor Related >> Communications
Security of proxy web browsers

Post a New Thread | Post A Reply

  Last Thread   Next Thread
Author
Topic: Security of proxy web browsers    
dredhead
Member

Registered: Nov 2000
Location:
Posts: 85

Question

With the limited memory capacity of our PalmOS devices, those of us who access the internet have made heavy use of web browsing through a proxy. I'm getting a little concerned with the potential for abuse of personal information.

At this point, I'm really not terribly worried that Bluelark Systems knows every web site I've vistited with their browser. They're storing every cookie for me, so I don't have to clutter up my RAM with such data. Besides, any ISP could easily collect the same data if they wished.

But the next great thing that we all need to make the wireless web worthwhile is a secure link - to our Travelocity accounts, web banking, Ameritrade, etc. With a personal computer, the encrypted link is between the server and your desktop. With an SSL proxy browser, isn't the secure link between the proxy (palmscape, blazer, etc.) and the remote server? What prevents folks at Palmscape from reading every secure transaction I make?

I have similar issues with FusionOne. I do use them to sync my computers and my handheld, but I never put anything sensitive through their pipeline. Sure, logging on to their site is secured by password, but I have no idea who has access on their end.

Is there a stand-alone browser that supports SSL? Is there a fee-based, bonded service in whom one could place some trust? Is there any way (preferred) I can use my own desktop computer, with its always-connected 10Base-T net link, as my own personal proxy server, so the sensitive password info never gets further than my own sphere?

I don't think I'm being paranoid... despite the fact that you're all looking at me.

__________________
...the patron saint of the easily amused...

dredhead is offline Old Post 01-08-2001 06:07 PM
Click Here to See the Profile for dredhead Edit/Delete Message Reply w/Quote
swendor
Member

Registered: Oct 1999
Location:
Posts: 231

dredhead:

I had the same thoughts as you while logging onto E*Trade. Who is stopping them from looking at sensitive info? Sure they give us the privacy statement saying that none of our data will be shared with outside parties, but there's always a chance that ONE person could...

After reading your post, I looked in YadaBrowse preferences to see if there was a SSL option. Nope. But did find the option "Always Encrypt." I don't know if this is referring to the user name and password or to all data.

I think I'll check that box now.

swendor is offline Old Post 01-09-2001 12:54 AM
Click Here to See the Profile for swendor Edit/Delete Message Reply w/Quote
Matthew Nichols
Member

Registered: Nov 2000
Location:
Posts: 714

Whats to keep a waitress from copying down your credit card # at a resteraunt?

I was wondering this today too, after I saw Browse-It advertising its 128-bit SSL. How safe are PQAs?

__________________
Matt Nichols
[email protected]

Matthew Nichols is offline Old Post 01-09-2001 01:23 AM
Click Here to See the Profile for Matthew Nichols Edit/Delete Message Reply w/Quote
swendor
Member

Registered: Oct 1999
Location:
Posts: 231

What if the waitress copied your credit card number and used it to buy herself a pair of shoes or something? In that case you could contest the charges and say that you never used that merchant. You're only responsible for up to $50.

On the other hand passwords can open up a whole wealth of info: account balances, account numbers, portfolios, etc. If someone has the name and password to your online bank account, they could change your address, liquidate your holdings and have a check in their hands on the way to cash it! Not only would you be out of $50 but possibly everything else in you account.

I'm not paranoid. I'm just saying that it's possible.

I know all too well. I just learned this morning that my account info was hacked from Egghead's site!

swendor is offline Old Post 01-09-2001 02:04 AM
Click Here to See the Profile for swendor Edit/Delete Message Reply w/Quote
gadgetguru
Member

Registered: Oct 2000
Location: Arlington, TX
Posts: 334

Where can I get Browse-It? I have tried their website, but all I can get to is the server page. They don't have a visible link to the browser.

Rick

__________________
Rick

www.visorsolutions.com

gadgetguru is offline Old Post 01-09-2001 02:10 AM
Click Here to See the Profile for gadgetguru Edit/Delete Message Reply w/Quote
pda4you
Member

Registered: Dec 2000
Location:
Posts: 13

Lightbulb Try this link...

Try this:
http://www.intellisync.com/p2_download.shtml

If that does not work go to http://www.intellisync.com and sign up for an account. Click on my Intellisync and create and account. Then down at the lower left you will see a link to download.

I don't use Browse-it because it does not support my ISP - Juno.

pda4you is offline Old Post 01-09-2001 02:38 AM
Click Here to See the Profile for pda4you Edit/Delete Message Reply w/Quote
dredhead
Member

Registered: Nov 2000
Location:
Posts: 85

quote:
Originally posted by Matthew Nichols
Whats to keep a waitress from copying down your credit card # at a resteraunt?

I was wondering this today too, after I saw Browse-It advertising its 128-bit SSL. How safe are PQAs?



Probably not all that safe, either. The average PQA I have is about 5K in size. Not very much room to have any sophisticated security measures written in.

Is Browse-It's encryption done in the PDA or done at their server?

__________________
...the patron saint of the easily amused...

dredhead is offline Old Post 01-09-2001 03:42 PM
Click Here to See the Profile for dredhead Edit/Delete Message Reply w/Quote
wkreamer
Member

Registered: Jan 2001
Location:
Posts: 5

Hi,

I have a VDX and am able to establish a PPP connection to my employer's network via a wireline modem (Thinmodem from CardAccess) and my cellular phone (Motorola StarTAC). I have successfully used ftp and telnet programs for my handheld to access these computers, but I have not been able to get a browser to work. I have tried Blazer, YadaBrowse, and AvantGo's browser, all without success. My employer's network IS behind a firewall, so that could be part of the problem, but I think the bigger problem is that I don't understand what the browser is trying to do. For instance, why do I need to set up a Server in all of these browsers? Don't they work like IExplore and Netscape? Why can't I just request an http page without going through a "server"?

Any tips anyone?

TIA

wkreamer is offline Old Post 01-09-2001 04:17 PM
Click Here to See the Profile for wkreamer Edit/Delete Message Reply w/Quote
dredhead
Member

Registered: Nov 2000
Location:
Posts: 85

quote:
Originally posted by swendor
dredhead:

I had the same thoughts as you while logging onto E*Trade. Who is stopping them from looking at sensitive info? Sure they give us the privacy statement saying that none of our data will be shared with outside parties, but there's always a chance that ONE person could...

After reading your post, I looked in YadaBrowse preferences to see if there was a SSL option. Nope. But did find the option "Always Encrypt." I don't know if this is referring to the user name and password or to all data.

I think I'll check that box now.



But again, checking that box doesn't guarantee that someone at the proxy can't read your transmissions. It probably only secures the link between YY and E*Trade. How much do you trust Yadayada?

__________________
...the patron saint of the easily amused...

dredhead is offline Old Post 01-09-2001 04:19 PM
Click Here to See the Profile for dredhead Edit/Delete Message Reply w/Quote
All times are GMT. The time now is 09:01 PM. Post New Thread    Post A Reply
  Last Thread   Next Thread
[ Show a Printable Version | Email This Page to Someone! | Receive updates to this thread ]

Forum Jump:

Powered by: vBulletin Version 2.3.4
Copyright ©2000, 2001, Jelsoft Enterprises Limited.