HTTPS-проксі
HTTP-проксі з підтримкою методу CONNECT для тунелювання зашифрованого HTTPS-трафіку між клієнтом і ціллю.
HTTPS-проксі - це HTTP-проксі, що вміє нести зашифрований HTTPS-трафік. Він використовує HTTP-метод CONNECT, щоб відкрити тунель: клієнт просить проксі під’єднатися до цілі на порту 443, проксі встановлює TCP-з’єднання, і через нього з кінця в кінець ідуть зашифровані дані. Проксі лише передає зашифровані байти, не розшифровуючи їх.
Це відрізняється від звичайного HTTP-проксі, що обробляє незашифрований трафік, де проксі може читати й змінювати запити. При HTTPS через CONNECT TLS-рукостискання відбувається напряму між вашим клієнтом і ціллю, тому проксі бачить лише факт з’єднання - але не його вміст. Ваші дані залишаються конфіденційними від оператора проксі.
На практиці майже кожен сучасний сайт використовує HTTPS, тому «HTTP-проксі» від комерційного провайдера означає проксі з підтримкою CONNECT та обробкою HTTPS. Коли ви налаштовуєте скрапер з HTTP-проксі, він автоматично використовує CONNECT для https://-URL. Один ендпоінт несе і http://, і https://-трафік.
HTTPS-проксі - вибір за замовчуванням для скрапінгу, бо працюють із будь-яким провайдером і будь-якою ціллю. SOCKS5 - альтернатива, коли потрібно проксувати не-HTTP протоколи. Для стандартного збору вебданих по HTTPS достатньо HTTP/HTTPS-проксі.
Two different things called HTTPS proxy
The phrase is used for two arrangements that people constantly confuse. The first is a normal HTTP proxy carrying HTTPS traffic through a CONNECT tunnel, which is what almost everyone means and what almost every provider sells.
The second is a proxy you reach over TLS: the connection between your client and the proxy is itself encrypted. This protects your credentials and your destination list from anyone watching your local network, and it is rare because it requires the proxy to present a certificate.
In the first arrangement, your HTTPS traffic is encrypted end to end between your client and the destination. The proxy sees the hostname in the CONNECT line, the timing and the byte counts, and nothing else.
How ours works
Our endpoints speak HTTP for the proxy connection and tunnel HTTPS end to end:
The scheme confusion, resolved
curl -x http://login:password@proxy.sotaproxy.com:10000 https://example.com
^^^^ how you talk to us ^^^^^ how we talk to the target
# Writing http:// as the proxy scheme while fetching an https:// page
# is correct and trips up almost everyone once.- Your HTTPS content is not readable by us or anyone in between. CONNECT builds a tunnel and the TLS session runs inside it.
- The hostname is visible to us in the CONNECT request, which is unavoidable in this design and true of every provider.
- If you need the local hop encrypted as well, use SOCKS5 over an SSH tunnel or a VPN to reach the proxy.
- Certificate errors through a proxy usually mean interception somewhere on your network, not a fault at our end.
HTTPS proxy confusions
The proxy scheme is not the target scheme
http:// as the proxy and https:// as the target is the normal, correct combination.
A proxy does not decrypt your HTTPS
That requires a certificate your client trusts, which is a corporate arrangement rather than a public product.
SOCKS5 is not encrypted either
Neither protocol adds encryption. Your security comes from TLS at the application layer.
verify=False does not fix proxy errors
It hides them. A 407 disguised as a certificate problem is still a 407.
Пов'язані терміни
Дивись на практиці
Готовий використовувати https-проксі?
SotaProxy надає доступ до ротуючих резидентських, мобільних, дата-центр та ISP проксі. Без мінімальних платежів.
Почати