Live data from Hacker News

Residential Proxies Are a National Security Threat

jacob.gold

71–80 of 100 posts

Re: Residential Proxies Are a National Security Threat

#71

Earlier quoted context omitted.

> I generally come from a position of suspicion as to why someone wants to scrape data that the owner goes to certain lengths to protect Let's try this for example. Suppose you want to create a price comparison site. A lot of the major retailers don't want these, because they want the customer going to their site when they want to buy something, not to the price comparison site that tells the customer which retailer…

Suppose someone wants to create a price comparison site, but is unable to access all the data that would serve their customers in finding the lowest price. The I guess the site is either useless, or can be used in combination with customer's own research that includes sites not included in the comparison. The site is still useful, it's just not exhaustive. There's nothing much in the world that's exhaustive, it's all…

> The I guess the site is either useless, or can be used in combination with customer's own research that includes sites not included in the comparison. The site is still useful, it's just not exhaustive.

There is a significant difference between having the prices for 85% of retailers because you haven't figured out how to get pricing from 15% of them and having the prices for 5% of retailers because the biggest ones block you from getting their prices. The amount of work you can save the consumer, and thereby the usefulness of the service to them, changes by a dramatic amount.

> Also, maybe the source that isn't scrape-able becomes less popular as a result of not being included in the price comparison list. If they're always more expensive, then neither you nor they have any advantage in listing on your site. If they're always cheaper, then your site may have no purpose to serve.

Now consider the possibility that they sometimes have the best price and sometimes don't.

> The lack of a certain set of data may itself be a data point, and should be used as marketing material for or against the company resisting the scraping.

Suppose you go to the price comparison site to look for the best price, the best price in its data set is $22, then you go to Amazon and they have it for $19 because it doesn't have their prices. The customer then starts checking Amazon in addition to the price comparison site. Their price is only actually lower 15% of the time, but another 75% of the time it's exactly the same, so the customers who don't want to keep checking two sites start checking only Amazon instead of only the price comparison site, at which point Amazon gets to charge them a higher price on 10% of stuff, or a higher price on more than 10% once people have been trained not to check. And prevent them from patronizing a random competitor when their price is exactly the same

Causing that to happen is the reason they don't want their prices in the comparison site. If not being listed there hurt them then they wouldn't be trying to prevent scraping.

> I'm a consumer who happily does significant research before a buying decision, going to various sites and checking prices, warranties, model numbers, reviews, availability, delivery times, and all the shit. And prefer doing the research myself than trusting a price comparison site, so I'm not the target market, thus my bias in my commentary and opinion on that topic

Consider also that you may be able to justify doing this when buying electronics, or choosing which brand of something to buy on a recurring basis, but if you just want the best price on the product you already know you want, it's crazy to spend hours to save cents. But completely sensible to switch to a search box that would save you 10 cents on every $2 purchase by giving you price-sorted results from multiple retailers who all sell the same products, if it's allowed to exist.

Re: Residential Proxies Are a National Security Threat

#72
post #66

Earlier quoted context omitted.

After decades of watching people use these three words, I've come to the conclusion that 'national security threat' is a right-wing dog-whistle for 'we have no actual proof, but we dislike it, so let's ban it'. They are basically 'won't someone please think of the children?', but with higher stakes.

it's a general politician dogwhistle, don't underestimate "the left" (especially in countries like the US, where the democrats are really not that left compared to other left parties in e.g. europe; leaving you with a pointless right-wing vs right-wing fight where nobody wins)

Its worse than that. Its "think of the children" but with slightly more truth to the statement than " think of the children". Because it is definitely a national security threatwhile primarily actually being said to |imit freedoms and increase market power abuse possibilities for big tech and/or media.

Re: Residential Proxies Are a National Security Threat

#73

Earlier quoted context omitted.

This is just the largest residential proxy provider BrightData(previously Luminati that used a free VPN to source residential bandwidth) The overall residential proxy market is too large and often undetected by intelligence tools. BrightData is actually much more compliant and malicious actors wouldn't be allowed access. They have an extensive KYC and use-case vetting process.

Haha no they dont, ive used brightdata and all you need is a credit card and you’re good to go It is shady AF.

Actually they have several different products based on IP type and quality. The credit-card only access you're talking about is for shared and flagged residential proxies. ISPs legally sell them to businesses and they can work for some use cases, but you need a video call and KYC to get access to a high quality IP pool, such as real mobile IPs they source from p2p services like VPNs.

Re: Residential Proxies Are a National Security Threat

#75

If so many sites and services didn't go out of there way to block or flag VPN users as suspicious then I would have no need to use residential / mobile proxies.

What about using your home/personal connection? Separately, would you let your home/personal connection be used as a residential proxy? Personally, I would not, except if it was for a friend / family member, but I would still ask them, pointedly, why my internet connection is required rather than their own.

I would if there was an easy way to make a cut of the revenue of its usage or if I got to use other people's home connections.

Re: Residential Proxies Are a National Security Threat

#76

Earlier quoted context omitted.

I think the fact that they're laymen means that there's still a pocket of non-consensuality. Taking advantage of someone's ignorance of potential consequences is as bad as malware in my opinion. If you're outlining all the potential bad outcomes before signing up a 'mark', then that's slightly more OK. Myself being "not a layman" would definitely not allow anonymous usage of Internet that's tied to my home/residence/…

> Taking advantage of someone's ignorance of potential consequences is as bad as malware in my opinion. If you're outlining all the potential bad outcomes before signing up a 'mark', then that's slightly more OK. Sure, the service should be upfront, although most laymen probably won't read. But if people had to really understand consequences before they accepted anything, most would miss out on most overall mutual of…

> the ratio of tech people agreeing

Do we have solid numbers for that?

Re: Residential Proxies Are a National Security Threat

#77

From a previous HN discussion, these are known DNS addresses to block in regards to Smart TVs being used a residential proxies: https://news.ycombinator.com/item?id=48422993 Specific Domains: proxyjs.brdtnet.com proxyjs.luminatinet.com proxyjs.bright-sdk.com clientsdk.bright-sdk.com clientsdk.brdtnet.com Wildcard domains: *.brdtnet.com *.luminatinet.com *.luminati.io Source: https://blog.includesecurity.com/2026/06/t…

This is just the largest residential proxy provider BrightData(previously Luminati that used a free VPN to source residential bandwidth) The overall residential proxy market is too large and often undetected by intelligence tools. BrightData is actually much more compliant and malicious actors wouldn't be allowed access. They have an extensive KYC and use-case vetting process.

> just the largest residential proxy provider

So a pretty good first step in blocking then.

Re: Residential Proxies Are a National Security Threat

#78

Earlier quoted context omitted.

What about using your home/personal connection? Separately, would you let your home/personal connection be used as a residential proxy? Personally, I would not, except if it was for a friend / family member, but I would still ask them, pointedly, why my internet connection is required rather than their own.

I would if there was an easy way to make a cut of the revenue of its usage or if I got to use other people's home connections.

Fair enough. Maybe I just have trust issues. Well earned trust issues.

Re: Residential Proxies Are a National Security Threat

#79

Earlier quoted context omitted.

Haha no they dont, ive used brightdata and all you need is a credit card and you’re good to go It is shady AF.

Actually they have several different products based on IP type and quality. The credit-card only access you're talking about is for shared and flagged residential proxies. ISPs legally sell them to businesses and they can work for some use cases, but you need a video call and KYC to get access to a high quality IP pool, such as real mobile IPs they source from p2p services like VPNs.

Shitty scammy israeli company

Re: Residential Proxies Are a National Security Threat

#80

My personal opinion is they're not hard to detect at all. Latency is a huge giveaway, If the client can't respond in a time you'd expect a client to be able to based on its geographic location, that's a pretty big tell they're using proxies. In fact, if you did latency sensitive stuff, you'd likely find out whether you wanted to or not.

That's assuming they're tunneling the entire connection and not terminating it locally and then forwarding the data after it's downloaded.

And also assuming that the only reason for higher latency is physical distance rather than crappy WiFi or corporate nanny filters or the client device swapping because the user can't afford more RAM.

Post reply on HN