posted on Aug, 2 2008 @ 03:09 AM
reply to post by Shaker
Just looked at wiki about proxies and it says this, so sounds like you have to be careful with these also.
In using a proxy server (for example, anonymizing HTTP proxy), all data sent to the service being used (for example, HTTP server in a website) must
pass through the proxy server before being sent to the service, mostly in unencrypted form. It is therefore possible, as has been demonstrated, for a
malicious proxy server to record everything sent to the proxy: including unencrypted logins and passwords.
By chaining proxies which do not reveal data about the original requester, it is possible to obfuscate activities from the eyes of the user's
destination. However, more traces will be left on the intermediate hops, which could be used or offered up to trace the user's activities. If the
policies and administrators of these other proxies are unknown, the user may fall victim to a false sense of security just because those details are
out of sight and mind.
The bottom line of this is to be wary when using proxy servers, and only use proxy servers of known integrity (e.g., the owner is known and trusted,
has a clear privacy policy, etc.), and never use proxy servers of unknown integrity. If there is no choice but to use unknown proxy servers, do not
pass any private information (unless it is properly encrypted) through the proxy.
In what is more of an inconvenience than a risk, proxy users may find themselves being blocked from certain Web sites, as numerous forums and Web
sites block IP addresses from proxies known to have spammed or trolled the site.