5 ms·
It’s pretty obvious what infatica is doing and while I agree it’s shady, I wouldn’t call it a scam. Peer-to-peer proxy doesn’t mean a botnet, at least not how
by bransonf 6y ago
It’s pretty obvious what infatica is doing and while I agree it’s shady, I wouldn’t call it a scam.
Peer-to-peer proxy doesn’t mean a botnet, at least not how I think most people think that to mean. Rather they are routing traffic through residential IPs for a number of customers. $25-45/1000 users sounds exactly within the margins of a VPN provider (they even mention hola.org in the 3rd email, which is $2.99/m per ‘premium’ user or free if you become a node in the network) and residential proxies are also commonly used for scraping and other IP-sensitive work, again within those margins.
I didn’t find the code sample to be obfuscated, it was actually quite clear. It establishes a web socket with a server and simply passes requests through an endpoint, I.e. literally just a proxy.
All that said, it’s definitely shady to put this in your extension without users knowing. But, if you need to monetize something free, and make at least a good effort to inform users or allow them to opt out, and we trust infatica doesn’t allow illegal use of its proxy network, then I don’t really see the problem.
There’s a real need for residential IPs, no market to give each user $.025 and I can’t really fault someone for making a business out of this.
Edit: I also find irony that the author labels datos.live a “scammer” when in fact they are a very legitimate business engaged in similar data collection to what Google already does. ...The same author who published an extension (in the Chrome Store) for YouTube
- walrus01 6y agoThe further you dig into the "residential proxy" market, the more shady it gets. Google "residential proxies for sale" and follow the rabbit hole down...
- bransonf 6y agoI certainly am not going to defend the whole market. I’m aware of many issues. But, there is a strict business need for these proxies. If you plan to fight giants, the first thing you need is their data. And you can’t get it without proxies. Sure, that’s another subject for debate; whether scraping/crawling is ethical itself.
- walrus01 6y agoUnfortunately it's not just scraping, they're also often used for outright fraud. Various online payment payment processors' fraud detection systems can be circumvented partially by appearing as a legit residential end user on a comcast cable connection, for instance. Or lots of other fraudulent activities where you have a click worker in a cube farm in a low labor cost location, using the proxy, pretending to be an end user in the usa.
- ajayyy 6y agoAbout Datos, I'll reply and see if I can get more info about them. I still do not understand how it would be "gdpr friendly", as the data for sure would not be required for the service
- Nextgrid 6y agoThey call it GDPR-friendly because there is no serious enforcement of the GDPR and so they know they will fly under the (non-existent) radar. This is the same reason how websites claim to “comply” with the GDPR with a cookie consent prompt that only allows you to accept (and declining is hard/impossible).
- sashagim 6y agoWhat you’re saying is that they are not indeed GDPR-friendly? That would make their claim a false one.
- Nextgrid 6y agoAbsolutely. I’m not sure why you’re surprised when 90% of websites out there with a cookie banner also lie (maybe even to themselves) about their GDPR “compliance”.
- tinus_hn 6y agoAs long as Google can get away with ‘accept our cookies or you can’t use YouTube’ GDPR is a toothless tiger.
- yuliyp 6y agoWhat "legitimate" need is there for residential IPs? These are internet connections that are generally less reliable than commercial connections. The biggest usage for them is for fooling web sites into the nature of the traffic they are serving.
- arpa 6y agoScraping (serp/e-commerce/other).
- bransonf 6y agoThat’s pretty much exactly the point. On the consumer facing side there is the VPN market, which people use to access content in remote locations or obfuscate their traffic to prevent surveillance/fingerprinting. On the business side, there’s a real need to be able to scrape say LinkedIn or Amazon, which necessitates rotating IPs to avoid getting blocked. The legal precedent currently incentivizes this sort of behavior between both parties. Mentioned also, however, is that criminals can use the technology to advance fraud.
- cbsks 6y agoSo instead of the scraper’s IP being banned, it’s mine? That’s not good.
- shmoogy 6y agoThe idea is usually to use hundreds or thousands of IPs, avoiding (ideally) detection, and not having any banned. Obviously if hundreds of people are using the same blocks, it doesn't quite work like that. The real user/owner would get a captcha and be fine for most big sites. *not sticking up for any of these companies, but I have required residential proxies in the past to scrape Google PLAs.
- deleted 6y ago[deleted]
- tiagod 6y agoWeb scraping is perfectly legal in many jurisdictions, as well as getting around the countermeasures. A datacenter IP is a huge red flag for those.
- sashagim 6y agoI don’t believe the users are made aware of this kind of usage of their network. In fact, I’m pretty confident that most extension burry this purposefully In such small letters it’s impossible to understand. Which, for me, qualifies them as malware.
- stefan_ 6y agoYeah, who doesn't want their house raided because some auto-updated browser extension has turned into a trojan and is serving as a proxy? You are very far off the mark.
- cutemonster 6y ago> house raided Because the ones who used one's residential IP as a proxy, accessed a very illegal website? And the the police visit the IP address?
- FDSGSG 6y agoDo you have any examples of this actually happening?
- buzer 6y agoNot specifically due to extension, but there are plenty of cases where people hosting tor exit nodes get raided. https://nakedsecurity.sophos.com/2018/07/05/tor-linked-nonprofit-raided-by-police/ https://nakedsecurity.sophos.com/2018/07/05/tor-linked-nonpr... https://www.techdirt.com/articles/20160406/08211234116/law-enforcement-raids-another-tor-exit-node-because-it-still-believes-ip-address-is-person.shtml https://www.techdirt.com/articles/20160406/08211234116/law-e... https://www.itnews.com.au/news/tor-exit-node-operator-raided-by-police-324804 https://www.itnews.com.au/news/tor-exit-node-operator-raided... https://www.lowendtalk.com/discussion/6283/raided-for-running-a-tor-exit-accepting-donations-for-legal-expenses https://www.lowendtalk.com/discussion/6283/raided-for-runnin... https://community.torproject.org/relay/community-resources/eff-tor-legal-faq/ https://community.torproject.org/relay/community-resources/e... Nothing really prevents same thing happening when it's VPN service's exit node (except maybe the fact that people doing illegal things would usually choose tor over VPN provider (though more technical ones are likely using both)).
- FDSGSG 6y agoThe traffic coming over Tor is completely different than the traffic coming over Hola & co. You can't seriously compare the two. Try signing up for a luminati account, they do pretty good KYC. Besides, the prices are probably going to keep most criminals far away.
- shpx 6y ago> it’s definitely shady to put this in your extension without users knowing I don't think it would be an exaggeration to say that the number of "users" of extensions running these service that know that their computer is being used to make web requests on behalf of the highest bidder is 0. The number of Hoola users that know how it works is also probably below 10%.
- ricardo81 6y agoWhatever you want to call it, it's certainly lucrative as they typically charge the bandwidth buyers around $10 per GB.
- tinus_hn 6y agoYeah all you are doing is trusting a scammer. What are they going to do, scam you?