3 ms·
It is generally easier to use Squid in reverse mode. It is a production quality proxy that can do reverse proxying. You can generate a CA cert, install it onto
by bitexploder 9y ago
It is generally easier to use Squid in reverse mode. It is a production quality proxy that can do reverse proxying. You can generate a CA cert, install it onto Squid chain it to privoxy and install the CA cert into your browsers.
Mitmproxy is great and we use it a lot, but it will have a pretty big hit on your performance. They have a more streamlined tool, mitmdump that is more aimed for these use cases, but it is still not written for performance first.
https://www.cyberciti.biz/tips/linux-setup-transparent-proxy-squid-howto.html https://www.cyberciti.biz/tips/linux-setup-transparent-proxy...
https://wiki.squid-cache.org/Features/DynamicSslCert https://wiki.squid-cache.org/Features/DynamicSslCert
https://wiki.squid-cache.org/Features/SslPeekAndSplice https://wiki.squid-cache.org/Features/SslPeekAndSplice
That link is an exact recipe for what I am talking about. It isn't really trivial to setup, but it does work well. Then, you can transparently privoxy ALL of your connections. You have to mix and grind several ingredients together.
Specifying proxy is always easier/better, but transparent with upstream (from squid) proxies is possible. Squid can also do much of the ad blocking as well like privoxy, just without as nice of a config look and feel.
edit: Just keeping things simple, I use squid with dynamic ssl certs, non transparently and have most of the rules I used in Privoxy working fine on Squid as the "one proxy" to run browser through. This prevents needing to monkey with proxy rules. As a bonus idea I also run this Squid on a perma-privacy-VPNd box, and always force certain site traffic through using a browser configuration like ProxySwitch Sharp. If you are really paranoid you can keep your sensitive traffic through your home / more trusted connection (whitelist style) and then route everything else through Squid/Privoxy.
Setting up a nice little Linux VM that simply can't route traffic without the VPN connection is very nice, it ensures traffic thru your little VM can't leak if something on the VPN fails.
- pmoriarty 9y agoIs there anywhere I could read more detail on this setup? I'm not exactly clear on how it works. Do you have: A: client -> squid -> privoxy -> internet or B: client -> privoxy -> squid -> internet And some more details on the exact squid & privoxy setup would be nice too. I've long wanted to get privoxy working over HTTPS, and would love to know the details of how this is done.
- bitexploder 9y agoDirect proxy, no transparent, client -> privoxy -> squid -> http(s) sites. I trust Squid at the tip a lot more. Forwarding Privoxy to another proxy is easy. Read the Forwarding section of the Privoxy manual. Setup Privoxy how you want. Forward to Squid. Follow: https://wiki.squid-cache.org/Features/DynamicSslCert https://wiki.squid-cache.org/Features/DynamicSslCert You should then have the perfect proxy centipede. For bonus fun use dnsmasq and blacklist domains via DNS too. Things get much more complex if you want to do things transparently. Now you have to monkey with iptables. The idea is similar though. Start with Privoxy getting all HTTP traffic on a router. Forward to Squid. Have Squids dynamic SSL cert on your client devices.
- pmoriarty 9y agoSo is privoxy happy handling HTTPS requests as long as it's fronted by Squid? I guess I'm still not clear on how/why that works. I thought privoxy could only handle HTTP.