Web Images Videos Maps News Shopping Gmail more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Public Wireless Access
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  18 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
glawson  
View profile  
 More options Nov 3, 9:42 am
From: glawson <glaw...@rhcl.org>
Date: Tue, 3 Nov 2009 08:42:16 -0600 (CST)
Local: Tues, Nov 3 2009 9:42 am
Subject: Public Wireless Access

OK, I've been thinking about wireless security when traveling. Many hotels, businesses and convention centers offer wireless connections, but I've been wondering why you can't/how to configure a small router/firewall (like the following links) to work in reverse, i.e. to use the wireless connection of the router to connect to the public wireless, and then serve wired clients (laptops). This would result in an additional layer of security (a second NAT layer, for example).

Is this logical? Possible?

I've setup a number of homebrew firewalls using IPCop and Smoothwall, and with those you can choose the NIC (interface) you want to use for inside and outside, so I think that part could be done (especially using a WRT54G or similar). I guess the trick would be in passing login authentication to the public wireless controller for initial login. Suppose that could be passed through to a client browser?

Greg Lawson
Rolling Hills Consolidated Library
1912 N. Belt Highway
St. Joseph, MO 64506

http://gadget-geek.net/wp-content/uploads/linksys-wrtgs-wireless-rout...
http://www.bestwirelesssecurity.net/images/FUL1_F5D8233-4.jpg


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rudy, Jared  
View profile  
 More options Nov 3, 9:46 am
From: "Rudy, Jared" <Jared.R...@sftks.net>
Date: Tue, 3 Nov 2009 08:46:25 -0600
Local: Tues, Nov 3 2009 9:46 am
Subject: RE: [KULUA] Public Wireless Access

If it's for personal use I would recommend setting up a Linux server at
home with SSH installed and use dynamic port forwarding for your entire
web browsing when using public access points.  Your web traffic is
encrypted and much more secure this way not to mention its dirt easy to
set up.  I've used this technique for a couple years now.

Jared Rudy
UNIX Administrator
St. Francis Health Center
1700 SW 7th
Topeka, KS 66606
785-295-7942

________________________________

From: kulua-l@googlegroups.com [mailto:kulua-l@googlegroups.com] On
Behalf Of glawson
Sent: Tuesday, November 03, 2009 8:42 AM
To: kulua-l@googlegroups.com
Subject: [KULUA] Public Wireless Access

OK, I've been thinking about wireless security when traveling. Many
hotels, businesses and convention centers offer wireless connections,
but I've been wondering why you can't/how to configure a small
router/firewall (like the following links) to work in reverse, i.e. to
use the wireless connection of the router to connect to the public
wireless, and then serve wired clients (laptops). This would result in
an additional layer of security (a second NAT layer, for example).

Is this logical? Possible?

I've setup a number of homebrew firewalls using IPCop and Smoothwall,
and with those you can choose the NIC (interface) you want to use for
inside and outside, so I think that part could be done (especially using
a WRT54G or similar). I guess the trick would be in passing login
authentication to the public wireless controller for initial login.
Suppose that could be passed through to a client browser?

Greg Lawson
Rolling Hills Consolidated Library
1912 N. Belt Highway
St. Joseph, MO 64506

http://gadget-geek.net/wp-content/uploads/linksys-wrtgs-wireless-router-
0.jpg
<http://gadget-geek.net/wp-content/uploads/linksys-wrtgs-wireless-router
-0.jpg>
http://www.bestwirelesssecurity.net/images/FUL1_F5D8233-4.jpg
<http://www.bestwirelesssecurity.net/images/FUL1_F5D8233-4.jpg>


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rudy, Jared  
View profile  
 More options Nov 3, 9:52 am
From: "Rudy, Jared" <Jared.R...@sftks.net>
Date: Tue, 3 Nov 2009 08:52:55 -0600
Local: Tues, Nov 3 2009 9:52 am
Subject: RE: [KULUA] Re: Public Wireless Access

Here's a good link on how to do it.

http://thinkhole.org/wp/2006/05/10/howto-secure-firefox-and-im-with-putt
y/

Cheers,

Jared Rudy
UNIX Administrator
St. Francis Health Center
1700 SW 7th
Topeka, KS 66606
785-295-7942

________________________________

From: kulua-l@googlegroups.com [mailto:kulua-l@googlegroups.com] On
Behalf Of Rudy, Jared
Sent: Tuesday, November 03, 2009 8:46 AM
To: kulua-l@googlegroups.com
Subject: [KULUA] Re: Public Wireless Access

If it's for personal use I would recommend setting up a Linux server at
home with SSH installed and use dynamic port forwarding for your entire
web browsing when using public access points.  Your web traffic is
encrypted and much more secure this way not to mention its dirt easy to
set up.  I've used this technique for a couple years now.

Jared Rudy
UNIX Administrator
St. Francis Health Center
1700 SW 7th
Topeka, KS 66606
785-295-7942

________________________________

From: kulua-l@googlegroups.com [mailto:kulua-l@googlegroups.com] On
Behalf Of glawson
Sent: Tuesday, November 03, 2009 8:42 AM
To: kulua-l@googlegroups.com
Subject: [KULUA] Public Wireless Access

OK, I've been thinking about wireless security when traveling. Many
hotels, businesses and convention centers offer wireless connections,
but I've been wondering why you can't/how to configure a small
router/firewall (like the following links) to work in reverse, i.e. to
use the wireless connection of the router to connect to the public
wireless, and then serve wired clients (laptops). This would result in
an additional layer of security (a second NAT layer, for example).

Is this logical? Possible?

I've setup a number of homebrew firewalls using IPCop and Smoothwall,
and with those you can choose the NIC (interface) you want to use for
inside and outside, so I think that part could be done (especially using
a WRT54G or similar). I guess the trick would be in passing login
authentication to the public wireless controller for initial login.
Suppose that could be passed through to a client browser?

Greg Lawson
Rolling Hills Consolidated Library
1912 N. Belt Highway
St. Joseph, MO 64506

http://gadget-geek.net/wp-content/uploads/linksys-wrtgs-wireless-router-
0.jpg
<http://gadget-geek.net/wp-content/uploads/linksys-wrtgs-wireless-router
-0.jpg>
http://www.bestwirelesssecurity.net/images/FUL1_F5D8233-4.jpg
<http://www.bestwirelesssecurity.net/images/FUL1_F5D8233-4.jpg>


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Marshal Graham  
View profile  
 More options Nov 3, 9:54 am
From: Marshal Graham <marshal.gra...@gmail.com>
Date: Tue, 3 Nov 2009 08:54:10 -0600
Local: Tues, Nov 3 2009 9:54 am
Subject: Re: [KULUA] Public Wireless Access
This sounds like a lot of trouble, wouldn't it be simpler to set up an
openvpn server at home or work and just tunnel your traffic through
that? That's what I typically do when I travel. Is there a reason you
want to do it this way?


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rudy, Jared  
View profile  
 More options Nov 3, 9:58 am
From: "Rudy, Jared" <Jared.R...@sftks.net>
Date: Tue, 3 Nov 2009 08:58:58 -0600
Local: Tues, Nov 3 2009 9:58 am
Subject: RE: [KULUA] Re: Public Wireless Access
I've also done the openvpn tunnel server.  The openvpn setup is much
more technical then setting up a ssh tunnel and not nearly as fast.  Not
to mention with ssh you can use compression which can actually further
speed up browsing when using a wireless network with poor connection.

Jared Rudy
UNIX Administrator
St. Francis Health Center
1700 SW 7th
Topeka, KS 66606
785-295-7942


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
djgoku  
View profile  
 More options Nov 3, 10:49 am
From: djgoku <djg...@gmail.com>
Date: Tue, 3 Nov 2009 09:49:20 -0600
Local: Tues, Nov 3 2009 10:49 am
Subject: Re: [KULUA] Re: Public Wireless Access
I second the SOCKS proxy setup. I would also suggest that you change
your SSH Server port to listen on 443 (some places block anything
outbound except 80/443).

Jonathan


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rudy, Jared  
View profile  
 More options Nov 3, 10:51 am
From: "Rudy, Jared" <Jared.R...@sftks.net>
Date: Tue, 3 Nov 2009 09:51:50 -0600
Local: Tues, Nov 3 2009 10:51 am
Subject: RE: [KULUA] Re: Public Wireless Access
Oh yea I forgot to mention that.  You can also just set your home router to listen on port 443 and then forward to the correct computer on port 22. That way you can keep your internal computer default ssh setup.

Jared Rudy
UNIX Administrator
St. Francis Health Center
1700 SW 7th
Topeka, KS 66606
785-295-7942


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Marshal Graham  
View profile  
 More options Nov 3, 10:53 am
From: Marshal Graham <marshal.gra...@gmail.com>
Date: Tue, 3 Nov 2009 09:53:23 -0600
Local: Tues, Nov 3 2009 10:53 am
Subject: Re: [KULUA] Re: Public Wireless Access
Yes I agree, openvpn does give you a performance hit.  One of the big
benefits of openvpn is cross-platform support. You can also get the
server on most of the opensource router projects like DD-WRT.  If it's
just for personal use, then you are right, ssh is probably the better
way to go. If you are going to have your employees or family use it,
you might want to look at openvpn.


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Dario Landazuri  
View profile  
 More options Nov 3, 10:57 am
From: Dario Landazuri <da...@landazuri.net>
Date: Tue, 03 Nov 2009 09:57:04 -0600
Local: Tues, Nov 3 2009 10:57 am
Subject: Re: [KULUA] Re: Public Wireless Access
You know, if you guys are *that* worried about people sniffing your
traffic, don't surf for bestiality pr0n in public.

Noone's really going to care about what you're surfing on.  Encrypt the
stuff that's important (use IMAPS, HTTPS when you're sending your cc #,
etc), and other than that, remember they're *NOT* out to get you...

Cheers,
Dario

--
************************************************************
Dario Landazuri                 Triangle Fraternity Minn97Ok
da...@landazuri.net
http://www.landazuri.net
************************************************************
"When you pull a guy's helmet off and hit him with it, you
don't call him for a face mask.  That's incidental."
                                             -Brett Gilland


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
glawson  
View profile  
 More options Nov 3, 11:11 am
From: glawson <glaw...@rhcl.org>
Date: Tue, 3 Nov 2009 10:11:41 -0600 (CST)
Local: Tues, Nov 3 2009 11:11 am
Subject: Re: [KULUA] Public Wireless Access

http://www.dd-wrt.com/wiki/index.php/Client_Mode_Wireless

This was from another list.

Greg
------------------------------


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Adam J. Thompson  
View profile  
 More options Nov 3, 1:19 pm
From: "Adam J. Thompson" <theadamjthomp...@gmail.com>
Date: Tue, 3 Nov 2009 12:19:18 -0600
Local: Tues, Nov 3 2009 1:19 pm
Subject: Re: [KULUA] Re: Public Wireless Access

Possible and logical -- it would work, but forget the security benefits.
Using a wired access point to serve non-wireless clients would work just
fine.  The security benefits from that don't have much weight in the setting
you have described.  It is my opinion that the kind of person who would want
and know how to target your hosts over the local network would be more
likely to just sniff your wireless traffic to get what they want.  That is
why everyone is recommending the use encrypted tunneling on each host.
Also, it would be cool to have a capable router that would take care of the
tunneling without any client configuration.


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
gladiatr72@gmail.com  
View profile  
 More options Nov 9, 11:42 am
From: "gladiat...@gmail.com" <gladiat...@gmail.com>
Date: Mon, 9 Nov 2009 08:42:18 -0800 (PST)
Local: Mon, Nov 9 2009 11:42 am
Subject: Re: Public Wireless Access

On Nov 3, 9:53 am, Marshal Graham <marshal.gra...@gmail.com> wrote:

> Yes I agree, openvpn does give you a performance hit.  One of the big
> benefits of openvpn is cross-platform support. You can also get the
> server on most of the opensource router projects like DD-WRT.  If it's
> just for personal use, then you are right, ssh is probably the better
> way to go. If you are going to have your employees or family use it,
> you might want to look at openvpn.
> [ ... ]

Not to derail the topic here, but what is the basis for the comments
on openvpn's performance?  I've worked with OpenVPN and OpenSSH for
years.  There have been times where I've used OpenSSH's tunnel mode
because it's there and I need a temporary solution.  Unless something
has changed in the last version or two of OpenSSH, I generally found
it to actually be a slower tunnel.  OpenVPN will do compression if you
want it to.  /shrug

I like the OpenVPN solution because of the things that it takes care
of on the routing (and access/firewall stuff if you want to put in the
scriptage.  Once you get past the TLS management hump (really: check
out the easy-rsa scripts that are part of the OpenVPN source), I've
found it to be a fabulous solution for when one finds oneself roaming
about.

What neither option is good for is forwarding your entire connection
through (making your VPN end-point your default gateway) unless you've
got some serious up-stream bandwidth on the server side.  If you're
using a typical cable or even low-end DSL connection, you're neutering
your connection down to little-better than dialup anyway, so you might
as well just sign up for a Net-Zero account and have done.

Blah blah blah.

Anyway, in answer to the OPs actual question, what you are asking is
indeed possible.  What I would suggest you do is check out the
wireless router models that are supported by DD-WRT or some other
OpenWRT derived linux distribution.  They are all but legion and
extremely cheap.  There were some politics going on in the DD-WRT
community in regards to someone trying to "adjust" its licensing to
make it slightly less open source or slightly more friendly to the
authors selling it in some context or something (dunno... ask Google,
it knows everything, right?) but it is (or was at the time) a pretty
neat replacement firmware for the WRT54 routers (and compatibles) with
a well-written interface and some pretty cool features.

The OpenWRT distro literally just gives you linux and hooks into the
router's hardware.  You can probably pick up a WRT54 compatible device
for under $80, so if you were so inclined, buy 2.  It's always fun to
have yet-another-device that has a bare-bones Linux distro
installed :)

-S


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
gladiatr72@gmail.com  
View profile  
 More options Nov 9, 11:43 am
From: "gladiat...@gmail.com" <gladiat...@gmail.com>
Date: Mon, 9 Nov 2009 08:43:45 -0800 (PST)
Local: Mon, Nov 9 2009 11:43 am
Subject: Re: Public Wireless Access
Dario,

I didn't get the idea from the original question that the concern was
line security--more along the lines of being able to drop multiple
systems on the ethernet of the wireless router and having a black-box
firewall/nat type thing where you wouldn't have to worry about the old
Windows 95 laptop exploding in your face when it touches a public
network :)

-S

On Nov 3, 9:57 am, Dario Landazuri <da...@landazuri.net> wrote:


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
glawson  
View profile  
 More options Nov 9, 12:21 pm
From: glawson <glaw...@rhcl.org>
Date: Mon, 9 Nov 2009 11:21:48 -0600 (CST)
Local: Mon, Nov 9 2009 12:21 pm
Subject: Re: [KULUA] Re: Public Wireless Access
Actually my original question was more for security than multiple access.

Greg
--------------------------


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Karl Schmidt  
View profile  
 More options Nov 9, 1:26 pm
From: Karl Schmidt <k...@xtronics.com>
Date: Mon, 09 Nov 2009 12:26:56 -0600
Local: Mon, Nov 9 2009 1:26 pm
Subject: Re: [KULUA] Re: Public Wireless Access

gladiat...@gmail.com wrote:
> What neither option is good for is forwarding your entire connection
> through (making your VPN end-point your default gateway) unless you've
> got some serious up-stream bandwidth on the server side.  

Have you ever gotten this to work? There is one situation where I need to access a web-page from the
server IP address.  Never could get openVPN to quite do that.  (I never could get it to get it to
use the servers DNS either.)  I have gotten openvpn to work with IMAP quite nicely.

> You can probably pick up a WRT54 compatible device
> for under $80, so if you were so inclined, buy 2.  It's always fun to
> have yet-another-device that has a bare-bones Linux distro
> installed :)

I don't think WRT54 supports the 'n' mode...

There are the the WRT3xxN units  - but I'm not sure they work with openwrt.

What would be very cool is if one could use Debian and have access to the kernel updates..

What every you do - don't get the WRT610N (unless you want to buy mine?) ..  it overheats, barely
works - tech support had me turn off most of its features.. still a dog...

--------------------------------------------------------------------------- -----
Karl Schmidt                                  EMail K...@xtronics.com
Transtronics, Inc.                              WEB http://xtronics.com
3209 West 9th Street                             Ph (785) 841-3089
Lawrence, KS 66049                              FAX (785) 841-0434

When your friends begin to flatter you on how young you look, it's a sure sign you're getting old.
-- Mark Twain

--------------------------------------------------------------------------- -----


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rudy, Jared  
View profile  
 More options Nov 9, 2:43 pm
From: "Rudy, Jared" <Jared.R...@sftks.net>
Date: Mon, 9 Nov 2009 13:43:57 -0600
Local: Mon, Nov 9 2009 2:43 pm
Subject: RE: [KULUA] Re: Public Wireless Access
I was able to configure openvpn to forward all network traffic including
DNS but I felt the performance hit.  In fact my only experience with
openvpn was using it in this way so it would explain while I'm a little
biased against it.  I would still recommend ssh tunneling in 95% of the
cases.  Only when an application won't work through a ssh proxy should
openvpn be used imo.  If you like I can try and find the link I used
that showed how to configure openvpn in this manner.

Cheers,

Jared Rudy
UNIX Administrator
St. Francis Health Center
1700 SW 7th
Topeka, KS 66606
785-295-7942


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
gladiatr72@gmail.com  
View profile  
 More options Nov 11, 8:20 am
From: "gladiat...@gmail.com" <gladiat...@gmail.com>
Date: Wed, 11 Nov 2009 05:20:29 -0800 (PST)
Local: Wed, Nov 11 2009 8:20 am
Subject: Re: Public Wireless Access
On Nov 9, 1:43 pm, "Rudy, Jared" <Jared.R...@sftks.net> wrote:

> I was able to configure openvpn to forward all network traffic including [...]

Oh.  I gotcha.  I didn't realize you were talking about an ssh proxy.
I thought you were talking about SSH's VPN mode (SSH-BASED VIRTUAL
PRIVATE NETWORKS is the heading for the VPN mode in ssh(1)).

Indeed if you were only concerned about http/s traffic, that would be
the way to go.

Karl:

The key to forwarding your entire connection is to make sure you're
not stomping on your ethernet device's route to the openvpn server.
This happens when you're relying on a default route to get the server.
The developers may have programatically addressed this by now, but the
last time I configured this sort of link with openvpn, it required
scriptage to read the default route, drop the default route, set a
static (host) route to the IP address of the vpn server, then execute
openvpn.  With the redirect-gateway option, it then sets the remote
end-point as the default route--with the static host route in place,
the actual vpn connection doesn't get interrupted.

Basically, regardless of what sort of vpn software you're using, you
have to do something like that if you want all your traffic to move
over a tunnel.  The only real application I've found for doing this
with either openvpn or ssh is when I had a broadcom chip on a laptop
that worked with the ndis-wrapper driver, but wpa was not supported in
any way.  I setup a port on my BSD box for the wireless router and
locked it down except for DHCP and an openvpn port.  I configured the
AP to bridge its wireless device to the switch ports connected to the
router and made sure to firewall the wireless client device (AP
operating in open mode, ya know) :)

Greg:

You probably are in a bit of a bind with that device if it's causing
trouble even in its default mode!  That doth suck.  Check out the
Buffalo Wireless devices.  Personally, I still have an old WRT54G
version 4 (I think), but I've known some people that have given
glowing reports of both the Buffalo hardware as well as their
customizability.

-Stephen


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Karl Schmidt  
View profile  
 More options Nov 11, 10:30 pm
From: Karl Schmidt <k...@xtronics.com>
Date: Wed, 11 Nov 2009 21:30:03 -0600
Local: Wed, Nov 11 2009 10:30 pm
Subject: Re: [KULUA] Re: Public Wireless Access

gladiat...@gmail.com wrote:

> Karl:

> The key to forwarding your entire connection is to make sure you're
> not stomping on your ethernet device's route to the openvpn server.
> This happens when you're relying on a default route to get the server.
> The developers may have programatically addressed this by now, but the
> last time I configured this sort of link with openvpn, it required
> scriptage to read the default route, drop the default route, set a
> static (host) route to the IP address of the vpn server, then execute
> openvpn.  With the redirect-gateway option, it then sets the remote
> end-point as the default route--with the static host route in place,
> the actual vpn connection doesn't get interrupted.

You've confirmed what I was looking at.  I saw some config variables, but they didn't appear to
work. I can almost do what I need via lynx.  I'm thinking it might be easier to set up something
that just lets me proxy surf on 80 and 443. so the request comes from the allowed IP address.

--------------------------------------------------------------------------- -----
Karl Schmidt                                  EMail K...@xtronics.com
Transtronics, Inc.                              WEB http://xtronics.com
3209 West 9th Street                             Ph (785) 841-3089
Lawrence, KS 66049                              FAX (785) 841-0434

I wonder why I wonder why; I wonder why I wonder.

--------------------------------------------------------------------------- -----


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google