Hacker News new | ask | show | jobs
by pudgywalsh 6 days ago
My major sources of spam traffic are Chinese and Indian residential and mobile IP blocks. So there's that.

Second, everybody screamed loudly when they were cracking down on file sharing traffic. You're saying spying on the citizens is ok when it's for this little reason over here, but not this one over there. It doesn't track.

Not to mention most ISP abuse mailboxes are automated these days because they are flooded with LLM-generated reports from "security" grifters.

The tech industry flooding the market with countless IoS (Internet of Shit) devices didn't help. This has moved way beyond accidentally installing spyware on your PC. People are intentionally bugging their homes with these devices.

I understand the FCC is trying to crack down on this stuff - starting with routers - but of course that gets pushback too. You can't win.

1 comments

There's no spying required. The NSA and ISPs can find open proxies through infiltration and report them to (e.g. abuse@comcast.com), then Comcast simply has to act on it robustly.

ISPs already deal with abuse reports like this, the system just isn't being operated comptently.

What is Comcast going to do about it? Shut off a paying customer? Not likely.
Voluntarily, maybe not, but we can make it a legal requirement.
Because that worked out so well with file sharing
Because this is exactly like file sharing...
The ways you are asking the government to mutilate the internet are quite similar to the ways the media industries asked the government to mutilate the internet.
What are you talking about? These are not open proxies.

You actually think the actors that went to the trouble to surreptitiously set this infrastructure up are going to share it with everyone for free?

They are intentionally made hard to detect and access is sold to the highest bidder.

Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.

> These are not open proxies.

Okay, I was being imprecise. These residential proxies aren't "open proxies" in the traditional sense, but they're usually "open" to anyone willing to pay a small amount of money to use them.

> Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.

This is where regulation might play a role, or at least a change in attitude. Companies shouldn't be allowed to pollute the internet in this way when they can easily prevent it.

Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?

Unless you are doing GFW China-level traffic analysis against a blacklist, which again how do you prove?

> Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?

Why do you think that? These are proxies, so they're making huge numbers of outbound connections to websites on behalf of the people operating them. They are the "exit nodes" in this setup.

You could probably just count the number of unique destination IPs they connect to each day. If the average residential user connects to 5,000, an infected machine is probably connecting to 50,000+.

But the simplest approach is to buy access to these illicit proxy services and use them to make requests to web servers you control. If you see your own unique request arrive from a residential IP, you've proven that connection is being used as a proxy.

So your plan is for the government to shut off the internet of anyone who connects to 50000 different IP addresses in a day?