Hacker News new | ask | show | jobs
by jacobgold 10 days ago
US residential proxies are the bane of the internet. They're the major source of social media manipulation and spam.

Services can dramatically reduce abuse by blocking entire IP ranges based on country of origin, organization, or type (hosting providers). But a company can't block US residential IPs if it would also cut off many of their real customers.

The US government (probably the NSA) should be cracking down hard on US residential proxy networks. They're a genuine national security threat, actual data/identity loss of American citizens, act as infra for foreign covert influence campaigns, botnets used in hacking/DoS attacks, etc.

Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)

9 comments

Counterpoint: IP range blocking is the bane of the internet, and I'm glad I can get around it by buying residential proxies. They cause very little problem to anyone except for the companies that think they can be the tzar of who gets to view certain information. The most unethical component is that the user often didn't consent to installing the proxy (which causes no problems for him) but this can be resolved and some people voluntarily install proxies for money.
how's it avoid causing problems for the user? it's using their Internet. imagine if they had data caps or so on and you're downloading through that proxy - that's basically taking his money, right?
Is Windows Update basically taking my money? Residential proxy costs per GB are quite high, so traffic isn't.
if windows update was downloading things without my knowledge or consent, kind of? this is why people resent some forced Microsoft software after all.

anyway if the costs are high surely they can pay the end users. at least then there's awareness and agreement. the ones bundled in apps or software seem less ethical to me than offering them some money per month to host it.

I'm glad someone else is saying this. Entire companies exist (that do a great job at it) that primarily surface this information in the form of "threat intelligence" for companies to make risk decisions based off of.
> Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)

Is there incentive for them to? If anything, you might be paying extra for the data use and not even know it, right? They would lose money

frmr ISP call center nerd here that took calls for hundreds of rural ISPs in North America, ranging from little rural fiber coops to as large as the former Hargray of South Carolina:

The support costs of malware remediation fucking suck. The moment you try to implement some kind of blocker in place like this is the moment you flood your call center(s) with thousands of ignorant consumers that have zero clue what you're trying to tell them, can't comprehend that they have "a virus problem", and are not going to calmly listen to a support rep try to suddenly train them on what the issue is and how to fix it.

(Bonus points for liability on what we direct a customer to do or not do.)

all Jimbob knows is that "comcast has blocked me from getting to my pornhub" and is very angry at the rep they have on the phone.

There's a reason we used to be told to blow people off with a 'contact your local computer shop' and it's time and money and liability.

It may actually be costing them money through higher peak usage (requiring more capacity). I'm not sure but either way the government should have a role if market incentives aren't sufficient.
yeah no, this isn't a good take imo. we already have way too much of ISPs doing bad things to internet shaping and random governmental overreach (from state govts no less!) on domains and such.

if someone wants to knowingly host a proxy they should. stuffing it along with other apps is shady and if LG wants to disallow those apps from their store than w/e but like we don't need governmental stuff encroaching on this stuff. if LG wants to do moderation on those apps than whatever.

there was a lot of fighting over this stuff back in the early 2010s because the alternative was effectively a balkanized corponet.

smart TVs, by virtue of being devices you can write apps for, have morphed into more general purpose computing devices and keeping it as open as it can be is important. the backsliding from stuff like Android has been horrible for the ecosystem and that shouldn't be normalized, let alone as a legal requirement geez

A crackdown would probably be an FBI responsibility, the NSA is not a law enforcement agency and absolutely does not have the authority.
In terms of law enforcement, sure. But what we really need is competent white hat hackers doing battle with the black hats.

Even if no one goes to jail, the NSA could make residential proxies much harder to operate in the US simply by detecting them and reporting them to ISPs. It would be good for ISPs to then validate the reports properly, give warnings, etc.

A lot of residential proxy networks don't let you access financial and government websites because that would create an actual national security risk and get them shut down. So, given that, what is the actionable complaint?
- Actual data and identity loss of American citizens.

- Malware that can record video and audio from infected devices.

- Infrastructure for foreign covert influence campaigns.

- Botnets used in hacking and DoS attacks.

So that would also apply to, like, Xiaomi, right? Or basically any foreign code you run?
My major sources of spam traffic are Chinese and Indian residential and mobile IP blocks. So there's that.

Second, everybody screamed loudly when they were cracking down on file sharing traffic. You're saying spying on the citizens is ok when it's for this little reason over here, but not this one over there. It doesn't track.

Not to mention most ISP abuse mailboxes are automated these days because they are flooded with LLM-generated reports from "security" grifters.

The tech industry flooding the market with countless IoS (Internet of Shit) devices didn't help. This has moved way beyond accidentally installing spyware on your PC. People are intentionally bugging their homes with these devices.

I understand the FCC is trying to crack down on this stuff - starting with routers - but of course that gets pushback too. You can't win.

There's no spying required. The NSA and ISPs can find open proxies through infiltration and report them to (e.g. abuse@comcast.com), then Comcast simply has to act on it robustly.

ISPs already deal with abuse reports like this, the system just isn't being operated comptently.

What is Comcast going to do about it? Shut off a paying customer? Not likely.
Voluntarily, maybe not, but we can make it a legal requirement.
Because that worked out so well with file sharing
Because this is exactly like file sharing...
What are you talking about? These are not open proxies.

You actually think the actors that went to the trouble to surreptitiously set this infrastructure up are going to share it with everyone for free?

They are intentionally made hard to detect and access is sold to the highest bidder.

Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.

> These are not open proxies.

Okay, I was being imprecise. These residential proxies aren't "open proxies" in the traditional sense, but they're usually "open" to anyone willing to pay a small amount of money to use them.

> Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.

This is where regulation might play a role, or at least a change in attitude. Companies shouldn't be allowed to pollute the internet in this way when they can easily prevent it.

Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?

Unless you are doing GFW China-level traffic analysis against a blacklist, which again how do you prove?

> Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?

Why do you think that? These are proxies, so they're making huge numbers of outbound connections to websites on behalf of the people operating them. They are the "exit nodes" in this setup.

You could probably just count the number of unique destination IPs they connect to each day. If the average residential user connects to 5,000, an infected machine is probably connecting to 50,000+.

But the simplest approach is to buy access to these illicit proxy services and use them to make requests to web servers you control. If you see your own unique request arrive from a residential IP, you've proven that connection is being used as a proxy.

> Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)

Does having TLS everywhere make this much harder?

Not sure how it would? Because the bad actors are remotely instructing infected computers/devices to make HTTP/TLS requests for them, so they appear totally normal to the other side.
In a hypothetical world where using TLS was abnormal, you could monitor the content of whatever the bots are doing for suspicious activity. And if they chose to use TLS anyway, the mere presence of of TLS could be considered suspicious.

Back in the real world, you can also passively fingerprint TLS handshakes to characterise the client device. Most of these proxy networks masquerade as "normal" clients, but if the type and variety of device fingerprints for an IP suddenly changes, that's a signal too.

It's not a crime to buy a new device and log it in to your WiFi.
Of course not, but if someone buys 1000 new devices and rotates devices with each request, it might be worth sending them an email like "hey did you mean to be doing that?"
Until DoH and ECH are commonplace, DNS lookups and SNI probably leak enough for statistical analysis.
DNS and SNI are usually not encrypted.
gosh, thanks for sharing your US national security concerns. as a former Googler. straight out of San Francisco. the world's epicentre of "win-win" tech innovations

> But a company can't block US residential IPs if it would also cut off many of their real customers.

since when do companies care whether they cut off real customers? i've been paying for residential proxies for everyday internet browsing for nearly 6 months. because it's the only way to pass the captcha service of another famous company headquartered in San Francisco

In a not so far dystopian future, we might be thankful for any bit of anonymity we get. I am waiting for the day my ISP detects and blocks my tor/vpn traffic, as GP suggested. You think politicians/regulators wouldnt go so far to "protect children"?
And it is source of major scam. NSA can simply sign up residential proxy and start banning each hop. But, I guess they aren't interested.
Alternate take; deliberately broken moderation systems and perverse incentives are the biggest source of social media manipulation.

Fix social media, and leave the consumers alone.

Also the firehose of spam will continue regardless of what you do on the consumer end.