Programa de referidos →
InicioGlosarioProxy HTTPS
Glosario

Proxy HTTPS

Un proxy HTTP que admite el método CONNECT para tunelizar tráfico HTTPS cifrado entre el cliente y el destino.

Un proxy HTTPS es un proxy HTTP capaz de transportar tráfico HTTPS cifrado. Usa el método HTTP CONNECT para abrir un túnel: el cliente pide al proxy que se conecte al destino en el puerto 443, el proxy establece la conexión TCP y luego los datos cifrados fluyen a través de él de extremo a extremo. El proxy solo retransmite los bytes cifrados sin descifrarlos.

Esto difiere de un proxy HTTP simple que maneja tráfico sin cifrar, donde el proxy puede leer y modificar las solicitudes. Con HTTPS vía CONNECT, el handshake TLS ocurre directamente entre tu cliente y el destino, por lo que el proxy solo ve que existe una conexión, no su contenido. Tus datos permanecen confidenciales frente al operador del proxy.

En la práctica, casi todos los sitios modernos usan HTTPS, así que "proxy HTTP" de un proveedor comercial significa uno que admite CONNECT y maneja HTTPS. Cuando configuras un scraper con un proxy HTTP, este usa automáticamente CONNECT para las URL https://. El mismo endpoint transporta tráfico http:// y https://.

Los proxies HTTPS son la opción por defecto para el web scraping porque funcionan con cualquier proveedor y cualquier destino. SOCKS5 es la alternativa cuando necesitas enrutar protocolos que no son HTTP. Para la recopilación estándar de datos web por HTTPS, un proxy HTTP/HTTPS es todo lo que necesitas.

Two different things called HTTPS proxy

The phrase is used for two arrangements that people constantly confuse. The first is a normal HTTP proxy carrying HTTPS traffic through a CONNECT tunnel, which is what almost everyone means and what almost every provider sells.

The second is a proxy you reach over TLS: the connection between your client and the proxy is itself encrypted. This protects your credentials and your destination list from anyone watching your local network, and it is rare because it requires the proxy to present a certificate.

In the first arrangement, your HTTPS traffic is encrypted end to end between your client and the destination. The proxy sees the hostname in the CONNECT line, the timing and the byte counts, and nothing else.

How ours works

Our endpoints speak HTTP for the proxy connection and tunnel HTTPS end to end:

The scheme confusion, resolved

curl -x http://login:password@proxy.sotaproxy.com:10000 https://example.com
     ^^^^ how you talk to us          ^^^^^ how we talk to the target

# Writing http:// as the proxy scheme while fetching an https:// page
# is correct and trips up almost everyone once.
  • Your HTTPS content is not readable by us or anyone in between. CONNECT builds a tunnel and the TLS session runs inside it.
  • The hostname is visible to us in the CONNECT request, which is unavoidable in this design and true of every provider.
  • If you need the local hop encrypted as well, use SOCKS5 over an SSH tunnel or a VPN to reach the proxy.
  • Certificate errors through a proxy usually mean interception somewhere on your network, not a fault at our end.

HTTPS proxy confusions

The proxy scheme is not the target scheme

http:// as the proxy and https:// as the target is the normal, correct combination.

A proxy does not decrypt your HTTPS

That requires a certificate your client trusts, which is a corporate arrangement rather than a public product.

SOCKS5 is not encrypted either

Neither protocol adds encryption. Your security comes from TLS at the application layer.

verify=False does not fix proxy errors

It hides them. A 407 disguised as a certificate problem is still a 407.

¿Listo para usar proxy https?

SotaProxy te da acceso a proxies residenciales rotativos, móviles, de centro de datos e ISP. Sin compromiso mínimo.

Empezar