[blog.rayfoo] Infosec, DFIR, tech geekery, thoughts and whatnot

28Jan/100

SecureMe: starting off

Am starting off with SecureMe for the more technically inclined.

(Heh, it's pretty fun to be typing this from outside whilst using SecureMe.  But that's not the point.)

If you're ok/familiar with installing + basic configuration of software (namely an OpenVPN client) and know how to configure your browser to use proxies, you're the guys/gals I'm looking for!

Let me know if you wish to have a VPN + proxy + DNS resolver service for no minimum cost (read: donorware should you feel like it).  Am limiting this offer to the first two people for now.  (The same offer still stands for those who've responded to my earlier call for helpers, so don't worry.)

The only things I need of you:

1) you need to be savvy enough to at least know how to install stuff on your computer, and to configure your browser

2) also, it would be good if you can help me in my efforts to make his easier for the less technically inclined.  Not a requirement though :P

So...let me know if you want to try this out for free!  I promise to keep it free/donorware for these two respondents as long as I can run this service ;)

You can contact me via Twitter or Facebook (you should be able to find the links at least), or if you're paranoid enough not to use these services you could alternatively email me at secureme{@T}rayfoo[dot]info and I'll get back to ya asap.

21Nov/090

Project: SecureMe

Will start to write some posts on how to get things up and running with the project that I mentioned last week, thanks for the wait.

In order for everyone to be on the same page, let's call this project "SecureMe", hopefully this would increase the basic protection you'd get when surfing from a public hotspot.

I can't (and won't) guarantee that you will be 100% safe from all those bad guys out there, but with this it would make it a lot harder for any Tom, Dick or Harry to sit down in the same cafe/MacDonalds/BK/your-favourite-hangout-place and start looking into your Facebook account and whatnot.

If your machine has been compromised with a virus/malware/adware/botnet, all bets are off.  This would require a cleanup before you can trust what your machine does (unfortunately).

This is a simple VPN tunnel + HTTP proxy + DNS resolver, so that your traffic will not be modified, or listened to by the fellows mentioned above.  As such, no anti-virus screening/protections for now.  One thing that might help is that I'm using OpenDNS to help resolve the DNS queries, and it automatically comes with a certain amount of protection against phishing sites :)

You won't be totally anonymous with this service: I won't hesitate to turn over information if you have been found to be using this service to do nefarious deeds against other people/servers, of if you use it to access stuff that's illegal anyway.

I'll be using this project to learn, so I will need to keep some logs for my own analysis and accountability (see above).  But I will not use this to infringe on your privacy (duh!), not as if I'd want to anyway. ;)

Lastly, though this is workable, it's not perfect yet.  I'll be changing things here and there from time to time if needed to improve this service, so no promises that you won't ever have to change anything ok?  It's a free(/donor) service anyway, so no one has to be obliged, ok? :)

Hope this helps you whoever you are, and pleaseeee do give me feedback ok?  Have fun!

PS: Signups are still available for now, for those who wish to help trial this free service :)

15Nov/092

New project coming up

Going to provide a trial run of a free (/donor-ware) service for people pretty soon, which is targeted at those who have to access the internet via public wifi hotspots.

Using a combination of easily available/open-source/free tools, it would provide pretty good basic protection against network sniffers/attackers for thse folks.

Why free/donor-ware?  I'm not looking to earn big bucks (if at all) out of this, probably just enough to cover the running costs would be nice.  And this project would be more of a learning experience for me rather than a business opportunity.

More details to be released soon, thanks to those who've responded to my initial call for trial helpers!