How many of those wordpress, joomla, drupal blogs, web2.0 products of various sort and other websites do you go to that are encrypted using SSL(https)? How many times a day to you enter your credentials, or use cookie based (the ‘remember me’ checkbox type) authentication on websites a day? Do you find yourself in coffee shops, or other public wifi frequently and sometimes wonder who is watching your traffic?
I know I do. Up until now I’ve been using SSH tunnels to get my traffic back home where I know nobody is running a packetsniffer. The trouble with SSH tunnels though is that they’re fickle, and often drop. I wanted a better solution – so I made one.
Right now its pretty much just a VPN. My goals are pretty straight forward
- Obtain subscribers, and offer excellent service
- Grow the product, then upgrade the hardware and bandwidth
- Value-Adds, like in-line antivirus, antispam, malware etc – make the product SAFER
- Bolt on business-class solutions like traffic shaping, packet prioritization and SLA guarantees.
My inital product pricing will be something like this:
- $15/mo or $150 a year for the base package (You save 2 months worth by buying a year in advance)
- $25/mo or $250 a year for higher packet priority
- Business class services – still working this one out.
I’m totally open to collaboration. I built this for myself, and my friends – so that we could feel secure using sites, and applications that were built insecurely on public wireless networks without fear of someone capturing our credentials, or snooping in on our traffic (e.g. airpwn, ettercap, goatseAP and the others)
Ideas? Comments? Hatemail? Drop me a note!
Tags: aten, atenlabs, in, information, infosec, labs, man, middle, MITM, packet, prevention, product, security, sniff, sniffing, the, vpn
An IPsec service that’s probably cloud hosted, would suspect it uses PSKs and dumps all data onto a shared “secure” server? Yeah — right.
No – this is a product designed to serve a purpose, not capture data.
Right now its just a single Cisco asa 5505 connected to a business network. As it grows, It will be moved to a network with more available bandwidth.
Sorry – I think you may be confusing Aten Labs with Google or Facebook – those monsters have a reason to log traffic and record data – Aten Labs does not.