Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • It's an anti-consumer evil practice, but if it is a national threat that's on the nation's security infra.
  • Does this take include, or exclude, DDOS?
  • somewhat related to @iammrpayments comment, the S in IoT stands for security.

    The nation's security infra is a reflection of the nation's security legislation and regulation.

    Aside: TheSInIoT is my DMZ's wifi password.

  • They're also a wholly necessary endeavor until the surveillance industry stops discriminating against IP ranges with endless captcha nagwalls. That, including its likely next development of remote attestation, is a much deeper problem for individual liberty. Individual liberty is itself more important than "national security" (which is more about protecting the government rather than the People) and thus needs to be addressed first.
  • The "solution" is to shoot CGNAT and to finally force the ISPs to adopt IPv6 so everybody can drop the addresses of a detected residential proxy into a ban list.

    Continuing to allow CGNAT is what allows the residential proxies to hide because it tumbles the IP identity of bad actors with normal people.

  • Your premise seems to be that you expect IPv6 addresses to be scarce.
  • Tell us that you don't know how residential proxies work, without telling us that you don't know how residential proxies work.
  • Anything connected to network can become a national security threat. IoT devices, internet connected smart appliances and all. Computers that run some OS is least of the worry because of the various layers of protection that can be added to them. But it is not the case with the IoT devices or SMART(!) devices where, if the firmware or any app ecosystem gets hacked / cracked / modified or sideloaded without any user intervention, could turn into a large zombie C2C botnet that can cause havoc.

    Proxying is least of the worries!

    When manufacturers bring out the smart features that require constant data collection, monitoring (obviously in the name of service quality, troubleshooting, firmware / app updates and subscription of services (!!)), it is oblivious to the fact that security and privacy at a personal / state / national level is never considered (for various reasons such as the design, profit interests and overheads / compliance perspectives and what not!) to be part of the ecosystem. Bad actors with sufficient knowledge and tools could exploit and profit from it.

    It has become more of a planned obsolescence / profit / greed based industrial / corporate culture in rolling out unwanted stuff / monitoring and controlling as a feature that gets exploited to the core.

    Honesntly, I don't have an answer for that, but have some thoughts that I wanted to share.

    I do not want a cleaning robot or a water purifier or a printer or a TV or a refrigerator or an oven or a smart light bulb or a smart lock or even my car to have undisclosed, unwarranted connectivity to internet for whatever reasons.

    I do not care if it is the manufacture or the service provider or whomsoever it may be!

    I want all of the network connectivity options to be explained with all the controlling options and boundaries and data collection that happens on any of the connected medium to be as much transparent with the option of preventing or restricting what one does not want to go out of the device.

    Will anyone do that?

    It ill never happen! Sadly!

    This problem will balloon further without adequate controls and killing the networking at a ground level would only be the only solution!

    But, in the case of a connected device having an inbuilt connectivity option (like the m2m based options) in a smart vehicle, even that is not possible!

  • Ad networks like meta ads, google ads use residential IPs + small LLM to check landing page of your advertisers for malware and scams. They are already paying millions for this service.

    Sometimes their system malfunctions (cough cough) and you get charged for those clicks but you fail to report them as fraudulent as you've no proof as the IPs and useragent all appear normal to ad agencies and advertisers.

  • No they aren't.

    > Actual data and identity loss of American citizens.

    > Malware that can record video and audio from infected devices.

    > Infrastructure for foreign covert influence campaigns.

    > Botnets used in hacking and DoS attacks

    These things have existed for 20+ years. Bad but not exactly a national security threat.

  • Yea, but with AI we also have seen unprecedented amount of hackings etc.. using these residential proxies. Now even normal plebs can do so much harm.
  • Mirai took out the internet in large parts of the US. The situation hasn't exactly improved since then.
  • First heard about this through this podcast. https://darknetdiaries.com/transcript/172/
  • That’s a scary read.
  • My personal opinion is they're not hard to detect at all. Latency is a huge giveaway, If the client can't respond in a time you'd expect a client to be able to based on its geographic location, that's a pretty big tell they're using proxies. In fact, if you did latency sensitive stuff, you'd likely find out whether you wanted to or not.
  • This is not always the case, although plausible, as residential proxies exit on a real residential IP geographically near the victim/target, so RTT looks normal most times and latency won't reveal them. The actual tells are elsewhere: ASN/IP reputation, TLS (JA3/JA4) fingerprint vs. claimed client, and session-behavior inconsistencies.
  • That's assuming they're tunneling the entire connection and not terminating it locally and then forwarding the data after it's downloaded.

    And also assuming that the only reason for higher latency is physical distance rather than crappy WiFi or corporate nanny filters or the client device swapping because the user can't afford more RAM.

  • From a previous HN discussion, these are known DNS addresses to block in regards to Smart TVs being used a residential proxies: https://news.ycombinator.com/item?id=48422993

    Specific Domains:

      proxyjs.brdtnet.com
      proxyjs.luminatinet.com
      proxyjs.bright-sdk.com
      clientsdk.bright-sdk.com
      clientsdk.brdtnet.com
    
    Wildcard domains:

      *.brdtnet.com
      *.luminatinet.com
      *.luminati.io
    
    Source: https://blog.includesecurity.com/2026/06/the-smart-tv-in-you...
  • This is just the largest residential proxy provider BrightData(previously Luminati that used a free VPN to source residential bandwidth)

    The overall residential proxy market is too large and often undetected by intelligence tools. BrightData is actually much more compliant and malicious actors wouldn't be allowed access. They have an extensive KYC and use-case vetting process.

  • They have their problems but how else am I supposed to scrape data from companies that want to hide it?
  • Exactly! I like the comment!
  • Apologies for the double post, but I've got an alternate perspective:

    Do you allow the data you've scraped to be scraped? Do you share it as freely as you desire the 'companies that want to hide it' would? Or do you consider the scraped data is 'hard earned reward for effort' and therefore has value that others should subscribe to your service for?

  • I'm a bit on the fence about this, but leaning towards the "bad luck". I'm sure there's a large swathe of nuance that I'm missing, but my simplistic view is: If they don't want to be scraped then they don't get included in "the thing" which, at minimum, is a data point for consumers to make consumer decisions about.

    It strongly depends on how scraped data is being used.

    If your 'cat' hasn't been able to catch their 'mouse' then the cat needs to get smarter, or look for alternative sources of mice, or the cat should be considered 'unviable'.

    Have you approached them to get access to their data? Have you explained to them how your service can benefit their business?

    (I generally come from a position of suspicion as to why someone wants to scrape data that the owner goes to certain lengths to protect, but then I'm also an 'information wants to be free' kinda person, but the Internet is increasingly an untrustworthy place, so security is overruling narrative).

  • No, your paranoia-outage is the true "national security threat" - a threat to freedom. Stop fanning the flames and calling for more government intervention.
  • After decades of watching people use these three words, I've come to the conclusion that 'national security threat' is a right-wing dog-whistle for 'we have no actual proof, but we dislike it, so let's ban it'.

    They are basically 'won't someone please think of the children?', but with higher stakes.

  • If someone with informed consent wants to run a residential proxy, that's their right and unlikely to be a national-security problem.

    When it comes to involunary proxies, those are really just one of many possible symptoms stemming from a real problem: Shitty security. (Edit: And shitty contract/privacy laws.)

    Shitty security is tolerated by our markets, is is protected from fixes due to copyright law, and it is even encouraged by parts of our government that want to exploit the flaws. We will gain far more from fundamental quality-improvements than we will from whack-a-mole-ing on this symptom.

  • Where is my home router that is Lean-validated ?
  • I'd be interested in the stats showing what percentage of residential proxies have 'informed consent', and the scale of what 'informed' means beyond "included in terms and conditions".

    > We will gain far more from fundamental quality-improvements than we will from whack-a-mole-ing on this symptom.

    100%, but I feel like that's both true and rarely executed upon in most governments for most topics.