Skip to content
Support

How private is my connection?

The short answer: assume LiteNet can read almost everything you do over dial-up, and keep secrets off it. The long answer is below, because you deserve to know exactly why and exactly what you can change.

The one rule

Do not send passwords, card numbers, private messages, medical information or anything else that must stay secret over a LiteNet dial-up connection.

A padlock drawn by a 1996 browser does not change this. If you have a modern machine on an ordinary internet connection, use that for those things, including for your LiteNet account pages, which are a normal encrypted website.

Who can read what

What you are doingCan LiteNet read it?Can somebody on the phone line?
An ordinary web page, reached by clicking a link Yes Yes
An encrypted site, reached by clicking a link Yes, see below Yes
An address you type yourself beginning https No No
Reading mail from your LiteNet mailbox Yes: it is our mail server Yes
Your dial-up password, as your modem sends it Yes: it is how we know it is you Yes
Your account pages, from a modern browser Yes: it is our website No

Why encrypted sites are not private here

This is the part people are most often surprised by, so it is worth being exact.

A browser from the dial-up era cannot complete a handshake with a modern encrypted website. The encryption those sites use did not exist yet. If LiteNet simply passed the connection through, almost nothing on today's web would open at all.

So LiteNet does the encrypted part for you. Every link on a repackaged page is handed to your browser as a plain http address, even when the real site is encrypted. When you follow one, your machine asks LiteNet in plain text, LiteNet makes the encrypted connection to the site, and sends the result back down the telephone line unencrypted.

The encryption is real. It just ends at our server rather than at your machine. Between us and the site, nobody else can read it; between us and you, we can, and so can anything on the telephone path.

An address you type yourself starting https is different: that goes straight from your machine to the site and never touches our proxy. In practice a period browser usually cannot finish that handshake, so it fails rather than protecting you, which is why we do not tell you to “just use https”.

What you can change, and what it costs you

Turn off repackaging

In your account, or at http://litenet/web once you are dialled in.

What it changes: pages arrive as the site sent them, not rewritten for an old browser.

What it does not change: the request still goes through LiteNet, and nothing becomes encrypted. It is a rendering choice, not a privacy one.

The trade-off: on a period machine most modern pages will be unreadable or will not load. Useful if you are dialling in from something newer.

Use a newer machine

Anything that can speak modern TLS can reach encrypted sites straight through us, exactly as on any other internet connection.

What it changes: real end-to-end encryption. We carry the packets and cannot read them.

The trade-off: a modern encrypted page over a 14.4k modem is slow, and the whole point of the repackaging is that it is not. This is the right choice for signing in somewhere, not for browsing.

Keep secrets off the line

The simplest and the one we actually recommend. Browse, read, download, use email. Do your banking somewhere else.

The trade-off: none, except the inconvenience of having two ways to get online.

What LiteNet does with what it can see

We keep what an ISP has to keep to run the service: which account connected, when, for how long, how much data crossed the modem, and the telephone number that called. We do not keep the contents of the pages you read, and we do not sell anything about you to anybody.

That is a promise about conduct, not a technical guarantee. The technical position is the table above, and it is the one to plan around.

See also the acceptable use statement, and support if any of this needs explaining properly.