6 ms·
Aisuru botnet shifts from DDoS to residential proxies
- iamacyborg 11mo agoSo not only are AI companies stealing content, they’re actively funding criminal organisations too. Wonderful
- miki123211 11mo agoThey're funding criminal organizations in the same way you're funding one if you get your hair cut at a hair salon which works as a front for money laundering. That is, mostly unknowingly, perhaps suspecting what's going on, but politely trying to ignore it for their own convenience.
- hofrogs 11mo agoA hair salon is a legitimate business. "Residential proxies" have very little legitimate use, and are sourced by unethical means, so it's not a fair comparison.
- Dylan16807 11mo agoWatching netflix is plenty legitimate in my book.
- hofrogs 11mo agoNetflix execs trying to restrict account sharing and implementing region locks wouldn't agree with that ;) I think it is a valid reason to use residential proxies as an individual (because I think that these region locks and other restrictions are bs), but if a company does that to bypass crawling restrictions - it is wrong.
- walletdrainer 11mo ago>"Residential proxies" have very little legitimate use You have to be joking. Having seen a list of biggest Luminati contracts, legitimate use makes up probably well over 90% of traffic via these services. It’s companies like Expedia and OpenAI, not Nigerian princes. Yeah sure, fraud happens. Those customers aren’t even lucrative because posting scam ads on Craigslist or wherever does not use much bandwidth. Criminals also use Google search.
- ImPostingOnHN 11mo agoHow would OpenAI routing requests through an Aisuru-compromised IoT botnet member be "legitimate"? Besides the small matter of the victim in the arrangement, the entire reason OpenAI does it is ban evasion, which is not legitimate.
- hofrogs 11mo agoAnd why is OpenAI using residential proxies instead of their own or some datacenter address space? Are they not using the proxies to steal data from unwilling website operators? I would count that as an illegitimate use. If they can't operate openly and have to bypass restrictions, they are doing something shady.
- sieep 11mo agoVery fascinating. I saw multiple people predict that these ddos attacks were just advertisement for the Aisuru services. How can regular users of Android, smart TV's, etc. identify these IoT devices that have been compromised?
- deleted 11mo ago[deleted]
- hombre_fatal 11mo agoI guess the increased bandwidth should at least show up on the ISP bill since that's the only place anyone would notice. But we're pretty far from having a system that isn't perfect for botnets and malicious proxies hiding on your network. Kinda crazy how my ISP doesn't even show me my usage on the bill. But then again every time I call them for something, they try to convince me I need something more than the minimum plan, and they're BS depends on me not knowing which tier I need.
- SkiFire13 11mo ago> I guess the increased bandwidth should at least show up on the ISP bill since that's the only place anyone would notice. Not sure about other places, but where I live ISPs don't have bandwidth limits over which they make you pay an extra. In extreme cases they might suspend service if your usage is deemed abusive though, but I never heard of this happening to people I know IRL.
- hombre_fatal 11mo agoSure. And that's yet another enabler of the status quo where malicious actors have infinite resources: every compromised computer or internet of shit product has unmetered high quality residential bandwidth.
- zokier 11mo agorealistically? not much regular joe can do. advanced users can segregate all their iot crap into separate network which allows keeping an eye on what goes on in there. but you need to know what your normal safe baseline looks like to be able to identify something weird happening. of course there is lot of fancy tools built around this topic too, stuff like zeek and suricata almost certainly could be used to identify possible compromises. especially in a separate iot network, which should have otherwise fairly regular traffic patterns. but realistically, idk if anyone has been very successful in implementing such detection.
- aPoCoMiLogin 11mo agorecently had to research "residential proxy", and the number of websites that claim that they have millions of IPs on hand was very strange. then the fact that a lot of them work in the exact same way, and a lot of them accepted payment mostly in crypto was very strange. so now connecting the dots, makes sense now why these "residential proxy" websites looked and worked the same way
- baobabKoodaa 11mo agoalso note that all of them claim that their residential proxies are "ethically sourced" (unlikely their competitors, I guess?) there's no such thing as an ethically sourced residential proxy.
- deleted 11mo ago[deleted]
- Retr0id 11mo agoI've been thinking about building an actually-ethical residential proxy system, for censorship-evasion purposes. The internet in a growing number of countries is censored, but different content categories are censored in each jurisdiction. Many sites and services also block known VPNs (i.e. non-residential IPs), so that doesn't work as a bypass in all cases. I have trusted friends in other countries, so by mutual agreement we could set up wireguard links for each other to use (subject to agreed terms). It just needs some way to intelligently route traffic depending on which jurisdictions will allow which requests (i.e. "which is the lowest-latency link that will allow this request").
- kruffalon 11mo agoAnd the concept of web of trust and signing parties just gets more and more valuable for each day!
- tuhgdetzhh 11mo ago> I've been thinking about building an actually-ethical residential proxy system, for censorship-evasion purposes. That thing already exist and is called Tor Snowflake.
- somehnguy 11mo agoIn the last few months I've seen many advertisements for a device they call the "Super Box" - it's essentially an (Android based?) IPTV device with every channel imaginable. The people I know with them paid around $300 and there isn't a monthly fee. I have a hunch they're trading free TV for becoming a residential proxy unknowingly. Would love to capture network traffic from one and see what's really going on. The fact that people are willing to buy these super sketchy devices and plug them into their networks without a second thought is kinda scary.
- lesuorac 11mo agoWell didn't lookup Super Box but I assume it's less sketchy than you image. It probably just pulls from something like https://github.com/iptv-org/iptv https://github.com/iptv-org/iptv and so the provider of Super Box doesn't have to maintain pretty much anything or use any of their own bandwidth. So the $300 minus the cost of the hardware is the profit and they don't have real reoccurring costs.
- 11mo ago
- zerof1l 11mo ago> ... renting hundreds of thousands of infected Internet of Things (IoT) devices to proxy services... And that's why I will never buy any IoT devices that require an internet connection to work. Only IoT devices in my house are those that connect to my own server and never see the light of the internet.
- ainiriand 11mo agoYour IoT is an Intranet of Things then, checks out!
- codedokode 11mo agoWhy there is no protocol that would allow a network to request blocking traffic from a subnet or network? For example, AS X doesn't want any traffic from Y, and all operators between X and Y block traffic from Y to X. To motivate lazy network operators, this protocol should be linked with financial conditions: an operator who doesn't honor the request, gets significantly reduced payment for this month's traffic. I see weak people whining about attacks for like 10 years, and nobody changes anything. It's easier to blame evil hackers than fix their own broken poorly designed systems. To give specific example, imagine a business which has 95% customers in developed country A, but receives 99% web requests from developing countries (DDoS attacks mainly come from there). It makes financial sense to cut off those countries first and after than figure out what happened.
- anonym29 11mo agoThe capabilities offered by the protocol you're envisioning already exist in the form of firewall rules and BGP peering agreements. Most websites and networks would suffer more from blocking residential ISP traffic than they do from misuse of residential ISP traffic, though...
- codedokode 11mo agoNo. If you have majority of customers in country A, but the attack comes from country B, it is better to cut off B to keep the web services working. BGP doesn't allow to stop attacks this way as I understand.
- nemomarx 11mo agowhat if the attack comes from country A too? my understanding is they try to get botnets and residential proxies in large Western countries to avoid being filtered by IP range already.
- madsushi 11mo agoThe finances work the other way around: you can often pay your transit/upstream providers an additional fee for their DDOS protection/filtering service, where you can signal (via BGP or otherwise) that there's traffic you don't want to receive. BGP Flowspec (or similar) is one of the technologies used here.
- deleted 11mo ago[deleted]
- waterproof 11mo agoAbout the ethics of residential proxies: Brightdata, which sells a residential proxy, blocks their own proxy when you point it to brightdata.com. The fact that they don't allow you to use their service to scrape their own domain, tells you something about their ethics...