There's no exact definition of what constitutes a Secure anonymous proxy or indeed a place you can find one for free on the internet. But I'd like to add some general points and things to watch out for if you are searching for such a proxy server.
An important fact to remember that simply adding the tag - ninja, elite or high anonymity to the description of a proxy server does in fact have no effect whatsoever on how secure that server actually is. This might sound an obvious point but I have personally checked a huge list of supposedly 'Elite proxy servers' and to be honest my gran could have configured them more securely.
Lets for instance take one of the very basic premises of running a secure, anonymous proxy server - what context is the proxy service running in. Is this something you know about on proxy servers you have used?
Let me tell you why - the absolute worse thing you can do is run the proxy service as root, yet I see many that are configured in just this way. The problem is that any flaw, bug or vulnerability with your proxy server could lead to the compromise of the whole machine. The root account gives complete control of the server, and with it all your browsing, all your logs and any traffic you send through that proxy. This sounds pretty stupid but you will find that many 'free anonymous proxies' that appear in the net are configured exactly like this.
There is a common alternative which runs in the context of the user 'nobody', now this is much better as the account has no special privileges which could put the server at risk. But neither is it a suitable configuration for a high anonymous proxy and the reason for this is that the account will still have some read and write privileges over public areas and directories. It will also have some rights over all logs created in the context of the 'nobody' user meaning potentially all users of the proxy have potential access to all the proxy logs and files created by this user.
The most secure alternative is what I would expect to see on any highly anonymous proxy and that is that each user has a specific user ID for using the proxy server. This user account should have no other access rights whatsoever, each proxy session would run in the context of this individual user. This protects the security, anonymity of every user of the proxy and secures their files and logs from other surfers using the proxy service.
Configuring an anonymous proxy is extremely important, a badly configured and insecure proxy server puts all of it's users and their information at risk. Remember whenever you use a proxy server, you are creating a single log of all your browsing in addition to your ISP logs - if it is not secure you will be putting your security at great risk, in fact much more than not using a proxy at all. If you want a high anonymous proxy make sure you get one.
If you're serious about protecting yourself online use a proper high anonymous proxy. A well configured secure proxy which protects and encrypts your connection even has other benefits like helping you watch BBC Iplayer abroad
Jim
Click the XML Icon Above to Receive Security Articles Via RSS!