3 ms·
There is a good chance (going on faith), that everything is fine: if they are running a secure HTTP proxy, then all of your data is safe. The only thing they wo
by igrigorik 14y ago
There is a good chance (going on faith), that everything is fine: if they are running a secure HTTP proxy, then all of your data is safe. The only thing they would know is the IP / hostname of the site you're connecting to. Unfortunately, can't tell from that writeup if that's the case - and it's not an easy thing to test. Would be nice for Nokia to confirm, or deny...
AFAIK, Chrome is the only desktop browser that supports HTTPS proxies: http://www.igvita.com/2011/12/01/web-vpn-secure-proxies-with-spdy-chrome/ http://www.igvita.com/2011/12/01/web-vpn-secure-proxies-with...
It would be nice to get wider adoption for this.. Perhaps Nokia has it! :)
---
[Update] It is MITM, but for S40 browser only, which does server-side rendering:
- http://browser.nokia.com/s40-browser.html http://browser.nokia.com/s40-browser.html
- http://www.developer.nokia.com/Community/Wiki/Series_40_web_apps_-_FAQ http://www.developer.nokia.com/Community/Wiki/Series_40_web_... (look under architecture)
Same story as Opera Mini.
- mqzaidi 14y agoIf you put a https proxy in between, you can capture all credit card data and other sensitive information. Use something like Charles on Mac and proxy your phone traffic through it to see this for yourself. No reason to be believe anything is safe if ssl certs are being forged.
- igrigorik 14y agoNo, you missed my point. Read the article I linked. With a proper HTTP/HTTPS proxy + CONNECT handshake, you still have the full end-to-end integrity of the connection. The proxy acts as a simple TCP relay.
- RyanZAG 14y agoA simple TCP relay that can log any and all traffic passing through it at any time with no prior warning. eg. an employee with sufficient access to the server (CTO? newly hired intern? who knows) can turn on logging of your traffic and read your private communication. This includes full access to any source code you may upload to github or any transactions you may make on your bank's website. The employee may delete the logs after he is done, and nobody would ever know that he has accessed them. Government agencies may legally prevent anybody speaking of their wiretapping through numerous laws. Basically, the fact that it acts as a simple TCP relay (obviously it does not, it is parsing the data) is seriously in doubt.
- VMG 14y agoThe point of SSL is that a TCP relay doesn't impact the security. Same is true for for a proxy and HTTP CONNECT. (The question remains if the Nokia browser does HTTP CONNECT)
- adrianmsmith 14y agoBut this isn't what Opera Mini does or wants to do. It wants to compress and otherwise alter the data flowing through it, so that you get a faster experience when browsing on the mobile. To do this it needs to see the HTML, JS etc going through it. A TCP relay wouldn't be able to do that.
- mappu 14y agoI don't use S40 any more, but when i did (on a 2010 C3-00, predecessor to the mentioned Asha 302), the stock S40 browser was straight webkit. Opera Mini was of course much faster than webkit if you could handle not having javascript. Nokia were pushing Ovi Browser at the time as a separate j2me app via the Ovi Store, which i guess has been rebranded to Nokia Xpress Browser and presumably bundled in current versions of S40.