Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

SurfEasy - Anyone Use it?

281 views
Skip to first unread message

Janet Wilder

unread,
May 20, 2013, 5:26:25 PM5/20/13
to
I came across this gizmo on the Internet today. It sounds to me like
the answer to using RV park and coffee shop open WiFi.

https://surfeasy.com/index.aspx

They sell it at Target stores. It appears to be based on Mozilla so the
browser is like Firefox.

Anyone have any comments? I'm really interested to hear what some of
you computer gurus think about it.
--
Janet Wilder
Way-the-heck-south Texas
Spelling doesn't count. Cooking does.

nothermark

unread,
May 20, 2013, 7:07:23 PM5/20/13
to
On Mon, 20 May 2013 16:26:25 -0500, Janet Wilder
<kellie...@yahoo.com> wrote:

>I came across this gizmo on the Internet today. It sounds to me like
>the answer to using RV park and coffee shop open WiFi.
>
>https://surfeasy.com/index.aspx
>
>They sell it at Target stores. It appears to be based on Mozilla so the
>browser is like Firefox.
>
>Anyone have any comments? I'm really interested to hear what some of
>you computer gurus think about it.

Hmmm. A VPN usually is an encrypted connection between two devices.
The USB plug in apparently provides a secure connetion to someplace
else that will be identified as the source of your browsing. That
gives you anonymity and maybe some more security. I do not see why I
would want it. Let's see what other folks think.

Frank Howell

unread,
May 20, 2013, 10:37:36 PM5/20/13
to
Janet Wilder wrote:
> I came across this gizmo on the Internet today. It sounds to me like
> the answer to using RV park and coffee shop open WiFi.
>
> https://surfeasy.com/index.aspx
>
> They sell it at Target stores. It appears to be based on Mozilla so
> the browser is like Firefox.
>
> Anyone have any comments? I'm really interested to hear what some of
> you computer gurus think about it.

Since all my phones are like me, dumb, I have no experience with this
software, but I did find a decent review on a respected site, CNET, they
titled "Browsing privacy for Grandma." http://tinyurl.com/3knv358

But I'm confused about this product. It appears there are two different
products here. One of them being SurfEasyt Mobile VPV for the smartphone and
tablet, which which is free, up to 500mb, at an app store. The other product
is SurfEasy Private Web Browser which targets Windows XP, 7 and 8 and Mac OS
and presumable laptops would be the top candidates for this offer and is
sold by Target. It appears that you get software and a USB flash drive and
once the software is installed on the flash drive, you then take it with you
and your laptop to resturants, library's, etc. and plug it in your
computer's USB port and the product does it's job.

So I'm thinking you want one that is an App for your smartphone, which is
free, not the one for laptop or desktop 'puter?

--
Frank Howell


nothermark

unread,
May 21, 2013, 7:36:51 AM5/21/13
to
My impression is that it is resident on the flash drive so it does not
provide connectivity but it does provide encryption. That would
require a Gateway at the other end to decrypt the data stream and then
browse the internet. In effect it does the same thing I did when I
browsed the internet with my work computer while I was connected via
VPN. That put me inside their firewall with all those ramifications.

Janet Wilder

unread,
May 21, 2013, 9:55:59 AM5/21/13
to
I want the one that is not free for the netbook. I'm not all that
concerned about the phone, though I'll probably put the free app on it
and the tablet.

I use the netbook when we travel and frequently use campground, hotel or
cruise ship WiFi, that's why I was interested in the one sold at Target.

BTW, I did read the same review. I was just curious to learn what
others thought of it.

Janet Wilder

unread,
May 21, 2013, 9:57:28 AM5/21/13
to
That's my take as well. It will only work where they have networks,
i/e. the US, Canada, UK and Singapore. Won't work in other countries, I
guess.

K Miller

unread,
May 21, 2013, 10:41:10 AM5/21/13
to
Janet Wilder wrote:
>>
>
> That's my take as well. It will only work where they have networks,
> i/e. the US, Canada, UK and Singapore. Won't work in other
> countries, I guess.

It should work anywhere that the SurfEasy host network is not actually
blocked.


Janet Wilder

unread,
May 21, 2013, 2:03:19 PM5/21/13
to
Do you think it would work on a cruise ship?

K Miller

unread,
May 21, 2013, 2:30:11 PM5/21/13
to
Janet Wilder wrote:
> On 5/21/2013 9:41 AM, K Miller wrote:
>> Janet Wilder wrote:
>>>>
>>>
>>> That's my take as well. It will only work where they have networks,
>>> i/e. the US, Canada, UK and Singapore. Won't work in other
>>> countries, I guess.
>>
>> It should work anywhere that the SurfEasy host network is not
>> actually blocked.
>>
>>
> Do you think it would work on a cruise ship?

Yes, as long as you can plug it into a computer with a working USB port, an
Internet connection, and no blocks on the SurfEasy network. My unsupported,
untested, and unsubstantiated opinion is that it would work just fine.
Personally, I would test it at home before I left to make certain I knew how
it worked and how to use it but, other than that....



nothermark

unread,
May 21, 2013, 2:43:57 PM5/21/13
to
On Tue, 21 May 2013 13:03:19 -0500, Janet Wilder
<kellie...@yahoo.com> wrote:

>On 5/21/2013 9:41 AM, K Miller wrote:
>> Janet Wilder wrote:
>>>>
>>>
>>> That's my take as well. It will only work where they have networks,
>>> i/e. the US, Canada, UK and Singapore. Won't work in other
>>> countries, I guess.
>>
>> It should work anywhere that the SurfEasy host network is not actually
>> blocked.
>>
>>
>Do you think it would work on a cruise ship?


If they provide broad band internet for their customers. The point is
what do you thiink it will do for you?

MaxD

unread,
May 21, 2013, 3:25:58 PM5/21/13
to
Keep my internet communications confidential?? I pay bills online.
I'm interested in the device but I hope someone gets one to see if it
works. ;-)

nothermark

unread,
May 21, 2013, 4:13:38 PM5/21/13
to
if you are paying bills or banking/money managing in general you
should be connected through an https:// address. That is encrypted
between you and your destination so intermediate stops cannot read it.
The only reason I can think of for using it is to prevent the ISP from
reading your browsing information.

Janet Wilder

unread,
May 21, 2013, 7:49:59 PM5/21/13
to
Thanks, Kevin. I have a Target gift card somewhere and will get one
before we leave on our next RV trip. Of course that will be in the US,
but I'll have campground WiFi to test it on. If I have free WiFi at a
campground, I'll use that instead of the Jet Pack as there is no data
use build up.

Janet Wilder

unread,
May 21, 2013, 7:50:57 PM5/21/13
to
They do provide internet access for a (hefty) price. I think it will
protect me if and when I have to access my bank while at sea. I'll be
at sea for 30 days later this summer.

K Miller

unread,
May 21, 2013, 8:02:13 PM5/21/13
to
Janet Wilder wrote:
>>
> Thanks, Kevin. I have a Target gift card somewhere and will get one
> before we leave on our next RV trip. Of course that will be in the US,
> but I'll have campground WiFi to test it on. If I have free WiFi at a
> campground, I'll use that instead of the Jet Pack as there is no data
> use build up.

Please take time to let me know how it goes. I'm usually leary of devices
such as this but this particular one looks pretty good at first blush, to
me. Please keep in mind that almost nothing is completely secure and if, for
example, the SurfEasy network is somehow compromised then any data sent over
it might also be compromised.


Janet Wilder

unread,
May 21, 2013, 9:08:59 PM5/21/13
to
I will report back.

rvfulltime

unread,
May 22, 2013, 3:48:58 PM5/22/13
to
On 5/20/2013 2:26 PM, Janet Wilder wrote:
> I came across this gizmo on the Internet today. It sounds to me like the answer
> to using RV park and coffee shop open WiFi.
>
> https://surfeasy.com/index.aspx
>
> They sell it at Target stores. It appears to be based on Mozilla so the browser
> is like Firefox.
>
> Anyone have any comments? I'm really interested to hear what some of you
> computer gurus think about it.

From what I see the big advantage is anonymous web surfing. If you need to
visit web sites that can't be tracked by your ISP, then this would work for you.
You can also do the same thing by using one of many anonymously forwarding web
sites, some free and some paid. I normally don't visit sites that I don't want
to leave a IP address fingerprint with my ISP.

With respect to using encrypted communications to perform banking operations,
the encryption already used by most common web browsers is really quite good.
One should be 100 times more concerned about someone looking over your shoulder
than someone intercepting your internet traffic to and from your bank.

Most computer breaches are done by tricking someone into giving up their
password, visiting a web site loaded with malware while using a buggy browser,
not actually hacking into someone's computer. I personally do banking
operations using my computer all the time while I'm traveling, and I'm away from
home about 1/3 of the time. I would never do it using a public computer.

While I'm no longer active in the industry, I was a computer programmer for over
25 years with an interest in computer security. By the way, my 9 year old
laptop running Windows XP, which was my primary computer for 5 years, have never
had any anti-virus software. Knowing what not to do is more important than any
anti-virus software.

K Miller

unread,
May 22, 2013, 4:03:01 PM5/22/13
to
rvfulltime wrote:
>
> With respect to using encrypted communications to perform banking
> operations, the encryption already used by most common web browsers
> is really quite good. One should be 100 times more concerned about
> someone looking over your shoulder than someone intercepting your
> internet traffic to and from your bank.

Unless you're using a wifi hotspot to connect your machine to the Internet -
in which case the SurfEasy device appears to add another level of security.
I'm speculating that it would make a man in the middle attack just that much
more difficult.

>
> Most computer breaches are done by tricking someone into giving up
> their password, visiting a web site loaded with malware while using a
> buggy browser, not actually hacking into someone's computer. I
> personally do banking operations using my computer all the time while
> I'm traveling, and I'm away from home about 1/3 of the time. I would
> never do it using a public computer.

The SurfEasy is apparently designed to let you use a public computer safely
for banking or anything else. Cookies and browsing data are stored to the
SurfEasy device instead of the public computer. All data between the device
and the SurfEasy network is encrypted on top of the encryption provided by
the particular financial institution via SSL.

At least, as I read their info, anyway....



MaxD

unread,
May 22, 2013, 6:40:13 PM5/22/13
to
I often see a warning on RV park sign-in paperwork that informs me that
information sent from my computer to a website can be seen by the
computer in the office of the campground. (as if someone might want to
"snoop")
If I'm engaged in internet bill paying is the above applicable?


K Miller

unread,
May 22, 2013, 7:16:05 PM5/22/13
to
MaxD wrote:

>>
>
> I often see a warning on RV park sign-in paperwork that informs me
> that information sent from my computer to a website can be seen by the
> computer in the office of the campground. (as if someone might want to
> "snoop")
> If I'm engaged in internet bill paying is the above applicable?

Possibly. It depends upon many things. It's always safest to assume a public
wifi connection is unsecure, if that's the connection you're talking about
and, personally, I refrain from accessing any website that requires me to
log on when I'm using a public connection.


K Miller

unread,
May 22, 2013, 7:18:26 PM5/22/13
to
Sorry - I should also note that millions of people use millions of public
connections a day without issue. Still, you assess your own level of risk
taking and you might be more comfortable connecting at 8 over than I am...


nothermark

unread,
May 22, 2013, 7:43:58 PM5/22/13
to
sort of. They can see that you have traffic and assume things if you
are pulling a lot of data. If they get really into it that can read
your packets to see where you are going or what is in the packets. If
you are using an https connection all they see is gibberish for the
data part of the packet.

I expect that the biggest reason they tell you that is to keep folks
from downloading movies and tying up the bandwidth. That is
relatively easy to monitor.

Hunter Hampton

unread,
May 22, 2013, 7:49:02 PM5/22/13
to
On 5/22/2013 4:16 PM, K Miller wrote:
> Possibly. It depends upon many things. It's always safest to assume a public
> wifi connection is unsecure, if that's the connection you're talking about
> and, personally, I refrain from accessing any website that requires me to
> log on when I'm using a public connection.

Good plan, I found out the hard way when $2,000.00 was missing from my
checking account after going on paypal at a KOA.

Paypal returned it, but I had a moment <g>

Hunter

rvfulltime

unread,
May 22, 2013, 8:28:23 PM5/22/13
to
You are correct. A packet sniffer could see and read unencrypted data, but
encrypted would be, as you say, gibberish.

rvfulltime

unread,
May 22, 2013, 8:32:47 PM5/22/13
to
If you have to use a public computer, then SurfEasy would make it safer, but not
safe enough. It would not get around a keylogger program. Keyloggers record
your keystrokes, which occurs before it gets encrypted. I have used some public
computers at hotels and they were loaded with viruses. All I did was some
general browsing, nothing that would require any identification of who I was.

rvfulltime

unread,
May 22, 2013, 8:36:44 PM5/22/13
to
On 5/22/2013 4:16 PM, K Miller wrote:
I have no concern about public connections with my computer. But one should
never use a public computer with any site that requires you to log in. Make
sure that once you log in using your computer, that the HTTPS protocol is
maintained (Yahoo Mail doesn't).

rvfulltime

unread,
May 22, 2013, 8:39:05 PM5/22/13
to
It really won't help you much if you use your own computer. If you use their
computer and they allow you to use SurfEasy, then you will have some protection,
but not enough.

MaxD

unread,
May 22, 2013, 8:50:19 PM5/22/13
to
If I use one of those "Safesurf" doodads does the same apply?
I have (whatever Verizon calls it to connect to the internet with my
laptop) on my phone.
Is that a more secure option?

Janet Wilder

unread,
May 22, 2013, 8:51:24 PM5/22/13
to
Surf Easy has a feature that allows you to create a virtual keyborad.
You use the mouse to click on the appropriate letters, numbers, etc. on
the screen, but no keyboard entries. That's a big plus to defeating
keyboard loggers.

MaxD

unread,
May 22, 2013, 8:51:33 PM5/22/13
to
Both of my banks use the https.

jerryosage

unread,
May 22, 2013, 8:58:04 PM5/22/13
to
A properly executed man-in-the-middle attack doesn't care if the
connection is https they can still decode it.

It is imperative to carefully read, and understand, any pop up windows
that opens. Usually it is something to the effect: Certificate not
verified - do you want to continue.

Jerry O.

Bob

unread,
May 22, 2013, 9:02:16 PM5/22/13
to
In article <knj7eg$1sb$1...@news.america.net>,
rvfulltim...@isp.nospaam.com says...
Don't forget about the zero-day Flash exploits. As a software developer, I
don't have Flash or Java installed on my computers. The only infection the
family PC ever got was when my wife visited the web site of a very famous
Opera singer done all in Flash. Took me over 4 hours to clean up.

Bob

Hunter Hampton

unread,
May 22, 2013, 9:42:03 PM5/22/13
to
On 5/22/2013 5:58 PM, Jerry Osage wrote:
> A properly executed man-in-the-middle attack doesn't care if the
> connection is https they can still decode it.
>
> It is imperative to carefully read, and understand, any pop up windows
> that opens. Usually it is something to the effect: Certificate not
> verified - do you want to continue.
>
> Jerry O.


Since the bad guys read keystrokes, if you have a password manager, and
don't hit any keys on wifi, wouldn't that foil keystroke readers?

Hunter

MaxD

unread,
May 22, 2013, 11:07:40 PM5/22/13
to
"SurfEasy".

Verizon calls it "Mobile Hot Spot"

K Miller

unread,
May 22, 2013, 11:29:34 PM5/22/13
to
MaxD wrote:
> On 5/22/2013 5:18 PM, K Miller wrote:
>> K Miller wrote:
>>> MaxD wrote:
>>>
>>>>>
>>>>
>>>> I often see a warning on RV park sign-in paperwork that informs me
>>>> that information sent from my computer to a website can be seen by
>>>> the computer in the office of the campground. (as if someone might
>>>> want to "snoop")
>>>> If I'm engaged in internet bill paying is the above applicable?
>>>
>>> Possibly. It depends upon many things. It's always safest to assume
>>> a public wifi connection is unsecure, if that's the connection
>>> you're talking about and, personally, I refrain from accessing any
>>> website that requires me to log on when I'm using a public
>>> connection.
>>
>> Sorry - I should also note that millions of people use millions of public
>> connections a day without issue. Still, you assess your own
>> level of risk taking and you might be more comfortable connecting at
>> 8 over than I am...
>
> If I use one of those "Safesurf" doodads does the same apply?

Possibly. It seems to me that, unless this thing uses some sort of two
factor authentication - such as a hardware key and your password, one would
still be at risk of having that first connection to the SurfEasy network
subverted by someone who really knows what they're doing. But you're trying
to make things just a bit more difficult so that Joe Scriptkiddy, who
downloaded some hack tools from the Internet but doesn't really understand
them beyond the simple instructions that he downloaded with them finds you
too time consuming and moves on to easier targets. Does this device do that?
Possibly.

Is it proof against keyloggers or other malware that might already be
installed on the computer the device is attached to? Apparently. I believe I
read that it can put an on screen keyboard up (allowing you to point and
click your entries) so that password and other entered data would not be
available to a locally installed keylogger.

Would I know if you plugged it into one of the computers that I'm
responsible for? Yes - almost immediately I'd get an email alert that a new
device had been detected on that computer and I would be checking to find
out exactly what you were doing. So (hi oz), would I recommend that someone
use it to try and browse privately on their employer's network in an attempt
to bypass the corporate policies, firewalls, and other protections? Not if
they're concerned about continued employment with that company.

> I have (whatever Verizon calls it to connect to the internet with my
> laptop) on my phone.
> Is that a more secure option?

More secure than public wifi? Definitely and without a doubt. If you're only
using that connection and are sure your Internet browsing device is clean of
malware and are careful to only enter passwords on secured sites (like
Paypal and most financial institutions) and aren't worried if your ISP knows
that you were also browsing the porn sites in between your stock
transactions, then no. You probably don't need the device...


K Miller

unread,
May 22, 2013, 11:30:23 PM5/22/13
to
MaxD wrote:
>>
>> If I use one of those "Safesurf" doodads does the same apply?
>> I have (whatever Verizon calls it to connect to the internet with my
>> laptop) on my phone.
>> Is that a more secure option?
>
> "SurfEasy".
>
> Verizon calls it "Mobile Hot Spot"

I believe those are apples and oranges, Max.


jerryosage

unread,
May 23, 2013, 3:48:00 AM5/23/13
to
Yes, however, keystroke loggers are different than the man in the
middle attacks. MITM fools you into logging on through him - then a
secure, https connection is established with him and he captures
everything. And your password manager does send the password, you
just don't type the password manager does it for you,

Now you are using his cert. keys for security and he can decode it. He
does, and logs onto the site you wanted. Using their cert he forwards
your message. It comes back and he sends it on to you using his
bogus cert which you accepted. So you are doing a https connection
and all seems OK. Everything works as expected, perhaps just a little
slower than expected

Some even fake a certificate that your machine will accept without
question, so no warnings.

And when you log off he has the complete transaction.

Then he can log back on as you and have some fun.

Public WiFi can be very dangerous. On the road I use my phone for
banking transactions after making sure WiFi is turned off.

Jerry O.

MaxD

unread,
May 23, 2013, 9:56:26 AM5/23/13
to
On 5/22/2013 9:29 PM, K Miller wrote:

Some much appreciated information for someone who just hasn't taken the
time to acquire computer savvy.
Thank you sir.

I'm going to get one of those SurfEasy thingies.

Janet Wilder

unread,
May 23, 2013, 10:18:49 AM5/23/13
to
On 5/22/2013 7:50 PM, MaxD wrote:

> If I use one of those "Safesurf" doodads does the same apply?
> I have (whatever Verizon calls it to connect to the internet with my
> laptop) on my phone.
> Is that a more secure option?

I would think that the Jet Pack or air card is safer than an open WiFi
in a campground or coffee shop.

Janet Wilder

unread,
May 23, 2013, 10:25:03 AM5/23/13
to
I downloaded the free Surf Easy app to my smartphone yesterday. It
doesn't interfere with anything. It dies set icons for itself on the
top of the phone's main screen. I also run Avast on my phone for AV.

D-R

unread,
May 23, 2013, 10:29:59 AM5/23/13
to
On 5/22/2013 3:40 PM, MaxD wrote:
> I often see a warning on RV park sign-in paperwork that informs me that
> information sent from my computer to a website can be seen by the
> computer in the office of the campground. (as if someone might want to
> "snoop")
> If I'm engaged in internet bill paying is the above applicable?
>

The short answer is if you are on an encrypted site is no. There is
always a possibility of a man in the middle attack but that exists on
ANY WiFi network not just public networks. The simplest security
solution to most perceived problems is an intelligence on the keyboard.
Malware is much more significant than packet sniffing and packet
sniffing can be done anywhere on the network between you and the website.


--

AJ - up in the Arizona mountains

Hunter Hampton

unread,
May 23, 2013, 11:50:03 AM5/23/13
to
On 5/23/2013 12:48 AM, Jerry Osage wrote:
> Public WiFi can be very dangerous. On the road I use my phone for
> banking transactions after making sure WiFi is turned off.

I do too......

I also don't click on emails from my bank, for example, to go to their
site..... I start from scratch <g>

Hunter

Janet Wilder

unread,
May 23, 2013, 5:47:49 PM5/23/13
to
I had a $50 Target gift card from my children for some holiday or
another. Went into Target and asked for the SurfEasy. Could have been
asking for a purple elephant.

I brought up Target's web site on my phone and did a search and the
fellow went in the back and came out with one. $64.95 plus tax.

The USB key is in a a holder the size of a credit card. There is a
little manual with it. I will be setting it up with my netbook.

More to come.
0 new messages