8 ms·
I'm surprised by the negative takes... Yes, proxies are good. Ones which you pay for and which are running legitimately, with the knowledge (and compensation)
by progbits 8mo ago
I'm surprised by the negative takes...
Yes, proxies are good. Ones which you pay for and which are running legitimately, with the knowledge (and compensation) of those who run them.
Malware in random apps running on your device without your knowledge is bad.
- mschuster91 8mo ago> Ones which you pay for and which are running legitimately, with the knowledge (and compensation) of those who run them. The problem is, it is by default unethical to have residential users be exit nodes for VPNs - unless these users are lawyers or technical experts. No matter what you do as a "residential proxy" company - you cannot prevent your service being used by CSAM peddlers, and thus you cannot prevent that your exit nodes aren't the ones whose IP addresses show up when the FBI comes knocking.
- bettystaplesmd 8mo ago[dead]
- bdcravens 8mo agoMany are "compensated" (in the way of software they didn't pay for), so the real question is that of disclosure (in which case many software vendors check the box in the most minimal way possible by including it as fine print during the install)
- happyopossum 8mo agoNo, the question is not just disclosure. People have their bandwidth stolen, and sometimes internet access revoked due to this kind of fraud and misuse - disclosure wouldn’t solve that
- the_fall 8mo agoAlso, as a website owner, these residential proxies are a real pain. Tons and tons of abusive traffic, including people trying to exploit vulnerabilities and patently broken crawlers that send insane numbers of requests, and no real way to block it. It's just nasty stuff. Intent matters, and if you're selling a service that's used only by the bad guys, you're a bad guy too. This is not some dual-use, maybe-we-should-accept-the-risks deal that you have with Tor.
- Kodiack 8mo agoI run a really small forum and I've been absolutely inundated with a bunch of junk traffic. I had to tighten my Cloudflare WAF rules a whole bunch, and start issuing browser challenges way more aggressively. Excluding known "good" crawlers, well over 99% of the traffic trying to hit the site has been attempting to maliciously scrape. Most of this traffic looks genuine, but has random genuine-looking user agents and comes from random residential proxies in various countries, usually the US. For the traffic that does make it all the way to a browser challenge, the success rate is a measly 0.48%. Put another way, over 50% of traffic is already blocked by that point, and of the under 50% that makes it to a browser challenge, more than 99.5% fails that challenge. It's been virtually no disruption to users either, since I configured successful challenges to be remembered for a long period of time. The legitimate traffic is a gentle trickle, while the WAF is holding back garbage traffic that's orders of magnitude above and beyond normal levels. The scale of it is truly insane.
- bigfatkitten 8mo agoIf they're lucky. Sometimes people have their doors kicked in by armed police.
- CodeMage 8mo agoGetting rid of malware is good. A private for-profit company exercising its power over the Internet, not so much. We should have appropriate organizations for this.
- UqWBcuFx6NV4r 8mo agoOkay. You get right on that. In the meantime, would you rather they did nothing? What do you actually want, in concrete terms?
- vachina 8mo agoThe proxies is the reason why you get spam in your Google search result, spam in your Play store (by means of fake good reviews), basically spam in anything user generated. It directly affects Google and you, I don’t see why they should not do this.
- Nextgrid 8mo agoSpam in Google search results is due to Google happily taking money from the spammers in exchange for promoting their spam, or that the spam sites benefit Google indirectly by embedding Google Ads/Analytics. I don't see any spam in Kagi, so clearly there is a way to detect and filter it out. Google is simply not doing so because it would cut into their profits.
- miki123211 8mo agoThe reason you don't see spam in Kagi is because nobody is targeting Kagi specifically. They can probably get away with a lot of stupid rules that would backfire if anybody tried to cater to them specifically.
- Nextgrid 8mo ago"SEO spammers being more advanced than multi-billion-dollar search conglomerate" is a myth. Spam sites have an obvious objective: display ads, shill affiliate links or sell products. All these have to be visible, since an ad or product you can't see/buy is worthless. It is trivial to train a classifier to detect these. But let's play devil's advocate and say you are right and spammers are successfully outsmarting Google - well, Kagi does use Google results via SerpAPI by their own admission, meaning they too should have those spam results. Yet they somehow manage to filter them out with a fraction of the resources available to Google itself with no negative impact on search quality.
- throwoutway 8mo ago> Malware in random apps running on your device without your knowledge is bad. And ones that have all the indicators of compromise of Russia, Iran, DPRK, PRC, etc
- bigiain 8mo agoAm I the only one cynically thinking that "Russia, Iran, DPRK, PRC, etc" is the "But think of the chiiildren!!!" excuse for doing this? And when Google say "IPIDEA’s proxy infrastructure is a little-known component of the digital ecosystem leveraged by a wide array of bad actors." What they really mean is " ... leveraged by actors indiscriminately scraping the web and ignoring copyright - that are not us." I can't help but feel this is just Google trying to pull the ladder up behind then and make it more difficult for other companies to collect training data.
- Craighead 8mo agoNo, what they're saying is what they said, what you're implying reveals a strange bias. Web scraping through residential proxies? Please think through your thoughts more. There's much more effective and efficient ways to do so. Multiple bad actors, like ransomware affiliates, have been caught using residential proxy networks. But by all means, don't let facts and cyber threat intelligence get in the way.
- bomewish 8mo agoWhat are the much more effective and efficient ways — since you said it ?
- usefulposter 8mo ago>let facts and cyber threat intelligence get in the way Appeal to authority by way of invoking the megacorp-branded "threat intelligence" capability (targeted PR exercise).
- JDye 8mo agoResidential proxies aren't used for scraping? That doesn't align well with my experience...
- vlovich123 8mo ago> Some users may knowingly install this software on their devices, lured by the promise of “monetizing” their spare bandwidth. Sounds like they’re targeting networks even if the users are ok participating in, precisely what you’re saying is ok. As for malware enrolling people into the network, it depends if the operator is doing it or if the malware is 3rd parties trying to get a portion of the cash flow. In the latter case the network would be the victim that’s double victimized by Google also attacking them.
- wmf 8mo agoUsers are OK with acting as proxies because they don't understand all the shady stuff their proxy is being used for. Also consumer ISPs generally ban this.
- chii 8mo agoBut then would you make the same arguments for running a tor node (presumably, you don't know what shady stuff is there, but you know there's shady stuff)?
- wmf 8mo agoPersonally I consider Tor less shady than these residential proxy networks because Tor has some normal users but yes, the considerations are similar. (I ran one of the earliest Tor exit nodes.)
- jraph 8mo agoThat's totally something you should consider, even if you decide for running the tor node anyway in the end.
- Spooky23 8mo agoRunning a tor node is pretty stupid from a liability perspective, but at least you have more deniability and you are making an informed choice. These residential proxies are pretty much universally shady. I doubt most of the users understand what they are consenting to.
- riedel 8mo agoI learn: proxy networks run by large corps are good. True internet is bad. While I understand that often we are talking about Malware/Worms etc that enable this. However, i find it often disturbing to here often a lot of libertarian speech from the tech scene, while on the other hand are feeling themselves very comfortable to take over state power like policing efforts to save the world.