Hacker News new | ask | show | jobs
by thomzane 18 days ago
This monetization scheme benefits the botnet controller and the developer who added the SDK and not the user who likely did not realize they signed up to become an exit node.
1 comments

It allows as free versions of apps to be economically viable and compete with others. It helps users because they don't need to be spied on and shown ads to fund the development of the app.

The existence of an app brings users value, else they wouldn't use it.

Recruiting your users' systems into a botnet is not an acceptable way to make an app "economically viable" any more than, say, installing a rootkit on their systems.
Is Google Maps a botnet because all of the clients share location data to make navigation more optimized? Having multiple users connecting back to a central server does not make something a botnet. Users should be able to decide for themselves whether they want apps like this or not.
The difference of course is that Popa does not provide 1. informed consent to users and 2. actual useful app functionality. The user does not know when an application is using the Popa SDK and does not know their device has been compromised. It is bundled inside seemingly legitimate software without the user's knowledge. Therefore, the user cannot make an informed decision about whether to use the app. Also, unlike the Maps example, the botnet provides no feature that the user would want or choose.

Popa is an illegitimate and botnet[1] that no end user knowingly/willingly uses.

1: https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-...

I would not have as big of a problem with it if it was a transparent arrangement that the app is free of cost, but the Internet connection would be shared with customers of RoboVPN. The issue is that the often invisible arrangement is not obvious and likely breaks the terms of service with the Internet Service Provider. If the user was intentionally running a TOR node, I would not have a problem with it. The current reality of it is absolutely unethical and breaking the Internet as we know it.
I agree that users should be informed, but if parts of the internet are breaking due to user anonymity it is hard for me to feel bad for those sites.
the fsf has never really been concerned with commercial viability. They're the worst audience for this sort of argument.

and I doubt these apps are really Free versions - do they support user modifications and access to the code? If they did support the four freedoms maybe the fsf would have something positive to say to balance it out?

You are not wrong. The FSF often takes an absolute stance on these things where they don't properly support partial steps towards more free computing.