ยังไม่มีหน้านี้ในภาษาของคุณ คุณกำลังอ่านข้อความภาษาอังกฤษ
Blog
How to choose a proxy for a profile: four connection kinds
ทีม ARMANOS7 min
What the four words actually mean
A proxy without a login reaches the browser as it is. A proxy with a login, whatever its kind, turns into a local exit before a window opens: otherwise the password would have to sit in the launch line.
The exit address is the same in all four cases, and the platform sees that one. What changes is how much the network in between sees.
- 1
http
The most common kind in seller lists. A secure page passes through whole and is never read.
- 2
https
The same, with the leg up to the proxy encrypted. Your surrounding network cannot see where the profile goes.
- 3
socks5
A kind that does not parse the request. More than the web goes through it.
- 4
ssh
Not a purchase but a login to your own server. A tunnel comes up beside the profile.
What happens to a fifth word
A line like ftp://address:port is refused with a reason. What you do not get is a quiet exit from your home address.
Three spellings of SOCKS read the same: socks, socks5 and socks5h mean one thing. A line with no scheme counts as plain http, which is how most lists arrive.
A proxy with a password differs
Almost every paid proxy comes with a login and a password, and this kind breaks the most profiles. A password written into the launch address is refused.
So your password never reaches that launch line. The profile presents it to the proxy itself and to nobody else.
Measured on the finished engine
Your own server instead of buying
With a server of your own in the right country, buying a proxy is optional. Write it as ssh://login@address:22 and the profile leaves through it.
The browser knows nothing about ssh and does not need to. The tunnel opens a real socks5 on your machine, and the window uses that address.
On Windows an exit through your own server works with a key file: there is no safe way to hand over a password there, so the app refuses in plain words rather than silently.
The password is invisible to the machine
Not in the launch line and not in environment variables. On disk the system seals it on Windows only: on macOS the key ships inside the program, and on Linux it is written as typed.
A broken tunnel shows at once
The tunnel is polled every 15 seconds and counts as down after three silent replies.
No tunnel means no launch
Not up within 20 seconds means no window: leaving directly is not an option.
Which kind fits your task
A list handed over with no scheme needs no choosing: the line works as it is. Choice starts where the surrounding network matters.
| Your task | What to take | Why |
|---|---|---|
| A seller list with no kind given | http | Reads as plain http, so the list needs no reworking |
| From a cafe, hotel or borrowed office | https | The leg to the proxy is encrypted, so the local network sees nothing |
| Not just the browser, but tools beside it | socks5 | Any traffic goes through it, not only requests to sites |
| Your own server in the right country | ssh | Nothing to pay for, and the exit comes up on your machine |
What else to ask the seller
The kind of connection and the kind of address are different things, and they get mixed up often. An account lets you in on the second: whose address it is matters, not the scheme.
The Proxy providers screen inside the app holds eight names and four kinds of address. The kind decides more than the scheme does.
Residential
Home addresses. The safest choice for social networks, and the priciest after mobile.
Datacenter
Server addresses. Cheap and fast, but social networks recognise them.
ISP
Provider addresses in a data centre. Fast, and far sturdier than plain server ones.
Mobile
Carrier addresses. The most durable for social networks, and the most expensive.
How to paste what you bought
Sellers write the same thing five ways, and none needs reshaping. An IPv6 address goes in square brackets, and the brackets stay.
address:port
No credentials and no scheme. Reads as plain http.
address:port:login:password
A colon inside the password breaks nothing.
login:password@address:port
An at sign inside the password stays part of the password.
socks5://address:port
The scheme on the left sets the kind for the whole line.
socks5://login:password@address:port
The same thing together with the credentials.
Four kinds of address across eight sellers
The app lists eight proxy providers, and each is described by the kind of address: residential, datacenter, mobile or ISP. Four sell residential, two datacenter, one mobile and one ISP.
The kind of address and the kind of link are different things. The first tells a platform whose address this is, the second tells your browser how to reach the proxy. A seller names the first, and you pick the second from a list when entering the proxy: HTTP, HTTPS, SOCKS5 or SSH, which is an exit through your own server.
A proxy with a login goes through a local exit
A stock browser has nowhere safe to put a proxy password: in the launch line any program on the computer can read it. So a proxy with a login, whatever its kind of link, is raised as a local exit on the machine itself.
The profile window talks to that local address, and it in turn talks to the proxy and supplies the password. For the platform nothing changes: the seller's address is what goes out. The one kind without such an exit is SSH, where the password works differently.
One host, several logins
A duplicate in the library means the address together with the login, not the address alone. A host with per-session logins lands as many rows as there are logins in the file.
Those are not spare rows: at the seller each login is a separate exit, and folding them into one record would throw away half of what you paid for.
What the app does not decide about a proxy
The app does not choose a seller for you and does not vet their reputation. The list of eight is a hint about where people take addresses from, not our pick of the best.
It does not know how many other people sit on the same address at the seller, and there is nowhere to learn that. A platform sees how clean an address is; we do not.
When no proxy is needed at all
A profile without a proxy opens on your real address, and for one account from home that is an honest choice. The app does not forbid such a profile, and the list row says there is no proxy.
The danger begins with a second account on the same platform: two sign-ins from one address in a day get tied together faster than by any fingerprint.
Checking the proxy before first login
The IP change link comes with the credentials and is worth checking early. The profile takes it over http and https; the ban on private network addresses guards links arriving from the server, not the one you typed in yourself.
- 1
Ask for the address through the profile
Open a page showing the exit address. It has to name the seller's address, not your home one.
- 2
Match the country against the clock
The country of the address and the timezone of the profile have to agree. A mismatch shows to the first script.
- 3
Look at the WebRTC leak
A browser can name your real address around the proxy. Checking that is free.
What this does not claim
- It does not claim that the right kind of connection saves an account. It removes one trouble of many; behaviour and account history stay yours.
- It does not claim that every seller carries all four kinds. Some hand over http only, some socks5 only.
- A live tunnel to a real server comes up in the check only where an ssh server exists on that machine. Otherwise the part is declared skipped out loud.
- The eight providers on the Proxy providers screen are neither a ranking nor advice. None of them pays us, and we have not measured their speed.
Where you can see this yourself
Every number above comes out of something you can open and run.
- Four kinds are declared in one place, and a fifth is refused
- packages/shared/src/proxy-line.js · apps/desktop/test/proxy-library.js · apps/desktop/test/выход-по-ssh.js
- Five spellings and an IPv6 address are parsed by running them
- packages/shared/test/разбор-прокси-понимает-ipv6.js
- The proxy applies to all traffic, not only to plain pages
- apps/desktop/test/proxy-covers-https.js
- A proxy with a password opens pages in a live ARMANOS Browser
- apps/desktop/test/прокси-с-паролем-живьём.js
- An SSH exit comes up as a real tunnel
- apps/desktop/src/lib/sshTunnel.js · apps/desktop/test/выход-по-ssh.js
- The IP change link is parsed before anything follows it
- apps/desktop/test/proxy-rotation.js
- Eight providers and four kinds of address, named in human words
- packages/shared/src/index.js · apps/web/test/виды-прокси.js
Questions
- Which is faster, socks5 or http?
- No noticeable difference in ordinary work: speed comes from the seller's channel, not the scheme. The socks5 handshake is shorter, but not visibly.
- Can I put two proxies on one profile?
- No. A profile takes one address of one kind, and all traffic of that profile goes through it.
- The seller gave me http only. Is that enough?
- For sites it is enough. Secure pages pass through whole, and the platform sees the seller's address.
- What if I paste a line with an unfamiliar scheme?
- The line is not accepted and you see a refusal. There is no quiet trip out from your home address.
- Where does my proxy password end up?
- It sits in the profile on your machine. On Windows the system seals it with a key tied to your Windows account, on macOS it is sealed with a key that ships inside the program, and on Linux it is written as typed. It never reaches the browser’s launch line, which any program can read.
- Do I need a separate address for every profile?
- For accounts on one platform, yes. One address across several profiles reads to the platform as one machine.
Check the address you bought before the first login
It reads the addresses your browser hands out around the proxy and sends none of them anywhere.