Simple, secure SOCKS proxies using spiped
1.7K
Recently, I've been getting more concerned with security. As an American living in a Middle Eastern monarchy, multiple government agencies are likely monitoring my internet traffic—not to mention that I frequently connect to servers from sketchy internet cafes while traveling in the developing world. To mitigate these risks, I proxy all my traffic through a secure server—but with the recent heartbleed bug, I decided to step my security up a notch.
Now, all traffic is routed through spiped, a simple and secure utility. Using Docker, I've automated most of the setup for this system, so you can easily route your traffic securely as well.
Setting up the server for this is quite simple, assuming you have Docker installed.
Clone my Dockerfile, which handles setting up a Socks proxy (with SSH) and the spiped server.
git clone https://github.com/morgante/spiped-docker /home/spiped
Enter the spiped directory, where the magic happens:
cd /home/spiped
Generate a secure key for the spiped socket to use for communication across the internet.
dd if=/dev/urandom bs=32 count=1 of=spiped.key
Build the Docker image (it will automatically load the key you just generated)
docker build -t spiped .
Start the spiped server with Docker:
docker run -d -p 49168:8089 -t spiped
You now have a fully functional SOCKS proxy listening on port 49168 and secured using a private key.
On the client, all you need to do is installed spiped and connect to the server. These instructions are for OS X, but the process should be similar for other operating systems.
Install spiped (with Homebrew).
brew install spiped
Copy the private key from your server.
scp [email protected]:/home/spiped/spiped.key ~/spiped.key
Start the spiped client:
spiped -e -s '[0.0.0.0]:8089' -t '[107.170.94.89]:49168' -k ~/spiped.key
In System Preferences, configure your network to connect to a SOCKS proxy at localhost:8089.
Now all your internet activity is securely routed through your server. If you want to automate this slightly more, I have written a very simple start script.
In my experience, the spiped tunnel is highly reliable and recovers more gracefully than a standard SSH tunnel.
Leave any questions in the comments and I'll do my best to answer.
Content type
Image
Digest
Size
160.2 MB
Last updated
almost 10 years ago
docker pull 2devnull/spiped-docker