5 ms·
Residential Proxies Are a National Security Threat
- kansm 2mo ago[dead]
- jayturley 2mo agoFirst heard about this through this podcast. https://darknetdiaries.com/transcript/172/ https://darknetdiaries.com/transcript/172/
- macintux 2mo agoThat’s a scary read.
- Shank 2mo agoCitation needed? I'm not a fan of residential proxies but these are pretty wild claims that aren't substantiated. Calling them a "national security threat" implies it is a threat to e.g., the continued existence of the United States. Is it really that? All of the activities described are already violations of the Computer Fraud and Abuse Act. > At the very least, major American ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. What are we saying? Really, what are we saying? We should turn domestic ISPs into domestic surveillance apparatuses to "detect clearly suspicious activity"? What is "clearly suspicious activity"? Section 230 is still law.
- cute_boi 2mo agoThe router could also be a good place to display live TCP usage and last 30 days usage and other network activity. There should also be a service that can identify whether specific IP addresses belong to botnets or other malicious infrastructure. If there are any abnormal activity mobile app can notify the user. Governments could even purchase residential proxies themselves and check whether they're being used for malicious activity. It isn't that difficult, but I guess governments just aren't that interested.
- saghm 2mo ago> The router could also be a good place to display live TCP usage and last 30 days usage and other network activity. There should also be a service that can identify whether specific IP addresses belong to botnets or other malicious infrastructure. > It isn't that difficult, but I guess governments just aren't that interested. I recently switched from my previous ISP because they randomly broke my ability to use my own router, and during the time when I had to default to using their own modem/router hardware before I could get the new ISP to come and set things up, I could barely even get a signal in my office upstairs (which had previously been connected via a mesh endpoint) because their router didn't expose any way for me to split 5 GHz and 2.4 GHz, and the router absolutely refused to let my devices connect via 2.4 GHz despite them having more than 90% packet loss due to the weak 5 GHz signal. Regardless of how "easy" it is, I don't trust ISPs not to screw it up somehow and probably cause a lot more concrete damage (even if the individual issues they cause are smaller in magnitude) than the theoretical concerns of "national security" that, as far as I can tell from reading this thread, have caused a total of like a few hours of downtime one day in a couple decades.
- advisedwang 2mo agoRelevant Darknet Diaries episode: https://darknetdiaries.com/episode/172/ https://darknetdiaries.com/episode/172/ The interviewee seems pretty inept yet still managed to uncover something really interesting and nefarious.
- yellow_lead 2mo agoNo they aren't. > Actual data and identity loss of American citizens. > Malware that can record video and audio from infected devices. > Infrastructure for foreign covert influence campaigns. > Botnets used in hacking and DoS attacks These things have existed for 20+ years. Bad but not exactly a national security threat.
- cute_boi 2mo agoYea, but with AI we also have seen unprecedented amount of hackings etc.. using these residential proxies. Now even normal plebs can do so much harm.
- himata4113 2mo agoSo it's okay for organized crime to do it, but not normal plebs? The former is obviously a lot more harmful and in reality this is just a wakeup call to get their shit together. People were dismissive of security far too long. I think it's actually good that AI instills some fear into people causing it to take a lot more seriously than they have previously done so.
- squigz 2mo agoCitation needed
- basilikum 2mo agoMirai took out the internet in large parts of the US. The situation hasn't exactly improved since then.
- anabis 2mo agoIt's an anti-consumer evil practice, but if it is a national threat that's on the nation's security infra.
- brikym 2mo agoThey have their problems but how else am I supposed to scrape data from companies that want to hide it?
- BLKNSLVR 2mo agoI'm a bit on the fence about this, but leaning towards the "bad luck". I'm sure there's a large swathe of nuance that I'm missing, but my simplistic view is: If they don't want to be scraped then they don't get included in "the thing" which, at minimum, is a data point for consumers to make consumer decisions about. It strongly depends on how scraped data is being used. If your 'cat' hasn't been able to catch their 'mouse' then the cat needs to get smarter, or look for alternative sources of mice, or the cat should be considered 'unviable'. Have you approached them to get access to their data? Have you explained to them how your service can benefit their business? (I generally come from a position of suspicion as to why someone wants to scrape data that the owner goes to certain lengths to protect, but then I'm also an 'information wants to be free' kinda person, but the Internet is increasingly an untrustworthy place, so security is overruling narrative).
- harimau777 2mo agoI know there've been efforts to scrape information that MAGA is trying to purge from government websites.
- BLKNSLVR 2mo agoGovernment website data should be openly available one way or another (at least within the country, and with reasonable security provision against obvious maliciousness). If it has to be scraped then there may be other problems (which include lack of resources to make the data API accessible).
- alightsoul 2mo agoTake reddit for example. If you're not big tech they ignore you.
- abofh 2mo agoAnonymous packets are a national security threat!
- bharatsuthar 2mo agoIf anonymous currencies can be considered a national security threat despite making up less than 0.001% of the world's total value, then why not anonymous packets?
- BLKNSLVR 2mo agoOnce the establishment has understood how to profit from anonymous currencies, then they'll be taken off the 'bad' list (no matter how many scams continue to be foisted upon the unwashed masses).
- mindslight 2mo agoThey're also a wholly necessary endeavor until the surveillance industry stops discriminating against IP ranges with endless captcha nagwalls. That, including its likely next development of remote attestation, is a much deeper problem for individual liberty. Individual liberty is itself more important than "national security" (which is more about protecting the government rather than the People) and thus needs to be addressed first.
- ietcd 2mo agointernet is a security threat, tell other...
- deleted 2mo ago[deleted]
- bofadeez 2mo agoSounds like fear mongering to justify some kind of otherwise unpopular surveillance laws
- GolfPopper 2mo agoHow would Uncle Sam like his police state wrapped today: "national security" or "think of the children"?
- alexspring 2mo agoGoogle propaganda. Botnet proxies, agreed. All residential proxies, dumb. Educate yourself: https://layer3intel.com/blog/measuring-the-netnut-takedown https://layer3intel.com/blog/measuring-the-netnut-takedown
- imadierich 2mo ago[dead]
- iammrpayments 2mo agoMaybe IOT is the actual national security threat?
- GolfPopper 2mo agoWhy not go all the way and call the Internet a national security threat?
- bharatsuthar 2mo agoThe optimum amount of residential proxies is non-zero.
- faangguyindia 2mo agoAd networks like meta ads, google ads use residential IPs + small LLM to check landing page of your advertisers for malware and scams. They are already paying millions for this service. Sometimes their system malfunctions (cough cough) and you get charged for those clicks but you fail to report them as fraudulent as you've no proof as the IPs and useragent all appear normal to ad agencies and advertisers.
- armchairhacker 2mo agoResidential proxies are necessary to access services that try to ban VPNs without compromising anonymity. If they’re banned, it’s easier for websites to require information that can be used to track you (IP address), since most people don’t use VPNs they won’t care. More importantly, a residential proxy can be mutual. If a group of people agree to forward traffic to each others’ IP, how is it not their business? It obfuscates their identities, but this is the Internet, not e.g. a government office or test center where you obviously can’t walk in with someone else’s ID. Banning non-consensual proxies makes sense since those are effectively malware, even though they make anonymity harder, so does banning theft and here you’re stealing someone’s internet. I’m sure we can convince enough laymen to knowingly install proxies by paying them.
- BLKNSLVR 2mo agoI think the fact that they're laymen means that there's still a pocket of non-consensuality. Taking advantage of someone's ignorance of potential consequences is as bad as malware in my opinion. If you're outlining all the potential bad outcomes before signing up a 'mark', then that's slightly more OK. Myself being "not a layman" would definitely not allow anonymous usage of Internet that's tied to my home/residence/identity to be used by some internet rando just because they pay me money. I would support, however, small family/friends groups who know and trust each other well enough to not do anything that'll cause a police raid on each others homes (having endured a police raid and the ensuing 8 months of not being told anything about the progress of whatever they're doing, it's not something I'd wish on a stranger, never mind a friend/family member).
- armchairhacker 2mo ago> Taking advantage of someone's ignorance of potential consequences is as bad as malware in my opinion. If you're outlining all the potential bad outcomes before signing up a 'mark', then that's slightly more OK. Sure, the service should be upfront, although most laymen probably won't read. But if people had to really understand consequences before they accepted anything, most would miss out on most overall mutual offers. Importantly, the expected consequences are low (as long as the service isn't greedy), and the ratio of tech people agreeing would suggest that if most laymen did understand they would still.
- charcircuit 2mo agoIf so many sites and services didn't go out of there way to block or flag VPN users as suspicious then I would have no need to use residential / mobile proxies.
- LastTrain 2mo agoThat’s a weird way to justify fucking over an uninvolved third party.
- charcircuit 2mo ago>fucking over an uninvolved third party No one is being hurt by someone sharing their internet with me a few times a week.
- LastTrain 2mo agoThe article is about surreptitious proxies.
- BLKNSLVR 2mo agoWhat about using your home/personal connection? Separately, would you let your home/personal connection be used as a residential proxy? Personally, I would not, except if it was for a friend / family member, but I would still ask them, pointedly, why my internet connection is required rather than their own.
- charcircuit 2mo agoI would if there was an easy way to make a cut of the revenue of its usage or if I got to use other people's home connections.
- BLKNSLVR 2mo agoFair enough. Maybe I just have trust issues. Well earned trust issues.
- zdc1 2mo agoOh please. An IP address is an IP address. The whole idea that some IPs are more special than others flies in the face of net neutrality.
- BLKNSLVR 2mo agoDisagree fairly strongly. IP addresses known to be malicious are unequal and should be treated as such. Just because the idea of net neutrality exists doesn't mean it's true. I'm sure there's a specific context for it, and 'security' is not that context. It was about data/packet prioritisation wasn't it? Unrelated to security.
- bharatsuthar 2mo agoYeah, mail server IP reputation is a good example. I wouldn't want to be flooded by emails from spammy mailservers IPs and I'm glad that my provider de-priortizes them.
- AnthonyMouse 2mo agoThe reason that works for mail servers is that they first require the IP address to have a valid reverse DNS entry, which is not just compromising a random machine with a random IP address but having administrative control over that IP block, which basically limits you to data centers and business internet providers, and then blocks IP addresses that send spam, i.e. that are owned by providers who give reverse DNS entries to spammers. The premise is that most people aren't trying to run a mail server so you require something that takes unusual bureaucratic interaction in order to get. Trying to restrict things to end-users is the total opposite of that. The common addresses everybody gets automatically are the thing you're trying to allow. Address reputation is pointless because residential customers get dynamic IPs and the reputation you're trying to record for some IP address can get swapped with a different customer at any time.
- BLKNSLVR 2mo agoSounds like a good reason that residential proxies are a bad thing, or at least require better regulation, so as to minimise damage to unwitting end-users. It also feels like a description of the perfect camouflage to facilitate doing bad things: "don't block them because you might block an innocent bystander". Putting innocent bystanders in harms way sounds like someone else is the bad guy, not the person doing the blocking.
- indianmouse 2mo agoAnything connected to network can become a national security threat. IoT devices, internet connected smart appliances and all. Computers that run some OS is least of the worry because of the various layers of protection that can be added to them. But it is not the case with the IoT devices or SMART(!) devices where, if the firmware or any app ecosystem gets hacked / cracked / modified or sideloaded without any user intervention, could turn into a large zombie C2C botnet that can cause havoc. Proxying is least of the worries! When manufacturers bring out the smart features that require constant data collection, monitoring (obviously in the name of service quality, troubleshooting, firmware / app updates and subscription of services (!!)), it is oblivious to the fact that security and privacy at a personal / state / national level is never considered (for various reasons such as the design, profit interests and overheads / compliance perspectives and what not!) to be part of the ecosystem. Bad actors with sufficient knowledge and tools could exploit and profit from it. It has become more of a planned obsolescence / profit / greed based industrial / corporate culture in rolling out unwanted stuff / monitoring and controlling as a feature that gets exploited to the core. Honesntly, I don't have an answer for that, but have some thoughts that I wanted to share. I do not want a cleaning robot or a water purifier or a printer or a TV or a refrigerator or an oven or a smart light bulb or a smart lock or even my car to have undisclosed, unwarranted connectivity to internet for whatever reasons. I do not care if it is the manufacture or the service provider or whomsoever it may be! I want all of the network connectivity options to be explained with all the controlling options and boundaries and data collection that happens on any of the connected medium to be as much transparent with the option of preventing or restricting what one does not want to go out of the device. Will anyone do that? It ill never happen! Sadly! This problem will balloon further without adequate controls and killing the networking at a ground level would only be the only solution! But, in the case of a connected device having an inbuilt connectivity option (like the m2m based options) in a smart vehicle, even that is not possible!
- userbinator 2mo agoNo, your paranoia-outage is the true "national security threat" - a threat to freedom. Stop fanning the flames and calling for more government intervention.
- DocTomoe 2mo agoAfter decades of watching people use these three words, I've come to the conclusion that 'national security threat' is a right-wing dog-whistle for 'we have no actual proof, but we dislike it, so let's ban it'. They are basically 'won't someone please think of the children?', but with higher stakes.
- aaron695 2mo ago[dead]
- rf15 2mo agoit's a general politician dogwhistle, don't underestimate "the left" (especially in countries like the US, where the democrats are really not that left compared to other left parties in e.g. europe; leaving you with a pointless right-wing vs right-wing fight where nobody wins)
- snapplebobapple 2mo agoIts worse than that. Its "think of the children" but with slightly more truth to the statement than " think of the children". Because it is definitely a national security threatwhile primarily actually being said to |imit freedoms and increase market power abuse possibilities for big tech and/or media.
- deleted 2mo ago[deleted]
- nephihaha 2mo agoIt's neither right nor left, but authoritarian and there are plenty of those around.
- BLKNSLVR 2mo agoFrom a previous HN discussion, these are known DNS addresses to block in regards to Smart TVs being used a residential proxies: https://news.ycombinator.com/item?id=48422993 https://news.ycombinator.com/item?id=48422993 Specific Domains: proxyjs.brdtnet.com proxyjs.luminatinet.com proxyjs.bright-sdk.com clientsdk.bright-sdk.com clientsdk.brdtnet.com Wildcard domains: *.brdtnet.com *.luminatinet.com *.luminati.io Source: https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/ https://blog.includesecurity.com/2026/06/the-smart-tv-in-you...
- bharatsuthar 2mo agoThis is just the largest residential proxy provider BrightData(previously Luminati that used a free VPN to source residential bandwidth) The overall residential proxy market is too large and often undetected by intelligence tools. BrightData is actually much more compliant and malicious actors wouldn't be allowed access. They have an extensive KYC and use-case vetting process.
- chhxdjsj 2mo agoHaha no they dont, ive used brightdata and all you need is a credit card and you’re good to go It is shady AF.
- bharatsuthar 2mo agoActually they have several different products based on IP type and quality. The credit-card only access you're talking about is for shared and flagged residential proxies. ISPs legally sell them to businesses and they can work for some use cases, but you need a video call and KYC to get access to a high quality IP pool, such as real mobile IPs they source from p2p services like VPNs.
- chhxdjsj 2mo ago[dead]
- Terr_ 2mo agoIf someone with informed consent wants to run a residential proxy, that's their right and unlikely to be a national-security problem. When it comes to involunary proxies, those are really just one of many possible symptoms stemming from a real problem: Shitty security. (Edit: And shitty contract/privacy laws.) Shitty security is tolerated by our markets, is is protected from fixes due to copyright law, and it is even encouraged by parts of our government that want to exploit the flaws. We will gain far more from fundamental quality-improvements than we will from whack-a-mole-ing on this symptom.
- BLKNSLVR 2mo agoI'd be interested in the stats showing what percentage of residential proxies have 'informed consent', and the scale of what 'informed' means beyond "included in terms and conditions". > We will gain far more from fundamental quality-improvements than we will from whack-a-mole-ing on this symptom. 100%, but I feel like that's both true and rarely executed upon in most governments for most topics.
- euroderf 2mo agoWhere is my home router that is Lean-validated ?
- quotemstr 2mo agoIf I own a computer, I should be able to run whatever damn software I want on it, including software that provides a network proxy to others. (N.B. a smart TV is a computer I own.) Yes, yes, we should fight deceptive software that doesn't disclose it has a proxy function. Fine. But there's no way to square 1) fighting all residential proxies, including ones run with informed consent and 2) preserving the public's access to general-purpose compute at home. I'd rather live with the proxies than for someone to tell me that if I run squid, I'm damaging national security.
- ButlerianJihad 2mo agoVery well: your ISPs, telecomm providers, and cloud services also own computers, and they should be able to run whatever they want on the devices they own, and they choose to block all your traffic, block all traffic destined for your premises, and flag your hardware IDs in certain databases, which is software they choose to run because they own the servers.
- quotemstr 2mo agoHow do their servers know I'm running a proxy, exactly?
- bsder 2mo agoThe "solution" is to shoot CGNAT and to finally force the ISPs to adopt IPv6 so everybody can drop the addresses of a detected residential proxy into a ban list. Continuing to allow CGNAT is what allows the residential proxies to hide because it tumbles the IP identity of bad actors with normal people.
- AnthonyMouse 2mo agoYour premise seems to be that you expect IPv6 addresses to be scarce.
- ButlerianJihad 2mo agoTell us that you don't know how residential proxies work, without telling us that you don't know how residential proxies work.
- Chu4eeno 2mo agoNo, they are correct, residential proxies behind a big ISP's CGNAT is much more valuable for miscreants because you can't block the individual who installed a free android flashlight with a residential proxy SDK embedded.
- torginus 2mo agoMy personal opinion is they're not hard to detect at all. Latency is a huge giveaway, If the client can't respond in a time you'd expect a client to be able to based on its geographic location, that's a pretty big tell they're using proxies. In fact, if you did latency sensitive stuff, you'd likely find out whether you wanted to or not.
- AnthonyMouse 2mo agoThat's assuming they're tunneling the entire connection and not terminating it locally and then forwarding the data after it's downloaded. And also assuming that the only reason for higher latency is physical distance rather than crappy WiFi or corporate nanny filters or the client device swapping because the user can't afford more RAM.
- simoneree 2mo agoThis is not always the case, although plausible, as residential proxies exit on a real residential IP geographically near the victim/target, so RTT looks normal most times and latency won't reveal them. The actual tells are elsewhere: ASN/IP reputation, TLS (JA3/JA4) fingerprint vs. claimed client, and session-behavior inconsistencies.
- Chu4eeno 2mo agoBut the overall latency will be longer than expected because you add the latency from the proxy connection as well. If you're able to ping back to the connecting IP in combination with some clientside js to help measure total latency I think you should be able to reliably detect proxy users in general?
- arbol 2mo agoIt's not enough to use latency alone as the other commentor said. You need to look for repeat behaviour at scale. It's ML model time once these basic signals fail you.
- j027 2mo agoI don’t understand this being a “national security” threat. Besides, mobile proxies exist which work differently. All you need is a mobile data plan that you run a proxy server on. It allows for easy IP rotation and since it’s a pool shared with other customers you cannot easily block it. This is because of things like CGNAT. IP rotation is easy because reconnecting to the network gives you a new IP address. Static residential proxies also are a thing, even if they are less effective sometimes.
- cloudie78 2mo agoIf anyone is curious where this leads to, I will happily point to China, Kazakhstan and Russia as prime examples. Can’t wait to have our very own Roskomnadzor MITMing everything and national security laws mandating Kazakhstan style TLS interception on every single device. Just a small over the air update via your friendly neighbourhood corporations Microsoft, Apple and Google. You know. To keep you safe.
- grigio 2mo agoThese posts are a National Security Threat for freedom
- blini-kot 2mo agovery well, its great tp have something else threatening the nation state lets just hope some day there will be enough threats for nations to crumble
- 4d4m 2mo agoFeels disingenuous to call out proxies when the true issue is a lack of security on the devices running them. Barking at the wrong tree imo. Bad and good actors alike rely on proxies, inclusive of those actors that OP says should be cracking down on these.
- mcfdoesdev 2mo ago[flagged]