Hacker News new | ask | show | jobs
by jacobgold 6 days ago
There's no spying required. The NSA and ISPs can find open proxies through infiltration and report them to (e.g. abuse@comcast.com), then Comcast simply has to act on it robustly.

ISPs already deal with abuse reports like this, the system just isn't being operated comptently.

2 comments

What is Comcast going to do about it? Shut off a paying customer? Not likely.
Voluntarily, maybe not, but we can make it a legal requirement.
Because that worked out so well with file sharing
Because this is exactly like file sharing...
The ways you are asking the government to mutilate the internet are quite similar to the ways the media industries asked the government to mutilate the internet.
Was requiring telephony providers to clamp down on spam or get blocked "mutilating the phone network?"
What I'm calling for is exactly how things are already supposed to work.

The US government should already be infiltrating hacker groups and identifying infected American computers. Internet providers should be informing customers that hackers have compromised their devices.

Characterizing this as "mutilating the internet" is ridiculous.

What are you talking about? These are not open proxies.

You actually think the actors that went to the trouble to surreptitiously set this infrastructure up are going to share it with everyone for free?

They are intentionally made hard to detect and access is sold to the highest bidder.

Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.

> These are not open proxies.

Okay, I was being imprecise. These residential proxies aren't "open proxies" in the traditional sense, but they're usually "open" to anyone willing to pay a small amount of money to use them.

> Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.

This is where regulation might play a role, or at least a change in attitude. Companies shouldn't be allowed to pollute the internet in this way when they can easily prevent it.

Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?

Unless you are doing GFW China-level traffic analysis against a blacklist, which again how do you prove?

> Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?

Why do you think that? These are proxies, so they're making huge numbers of outbound connections to websites on behalf of the people operating them. They are the "exit nodes" in this setup.

You could probably just count the number of unique destination IPs they connect to each day. If the average residential user connects to 5,000, an infected machine is probably connecting to 50,000+.

But the simplest approach is to buy access to these illicit proxy services and use them to make requests to web servers you control. If you see your own unique request arrive from a residential IP, you've proven that connection is being used as a proxy.

So your plan is for the government to shut off the internet of anyone who connects to 50000 different IP addresses in a day?