Live data from Hacker News

Disrupting the largest residential proxy network

cloud.google.com

201–210 of 230 posts

Re: Disrupting the largest residential proxy network

#201
Since I was also tracking this proxy network as part of my side project, I wrote a short blog post + give access to 16m+ proxy IPs IoCs that belong to this proxy network: https://deviceandbrowserinfo.com/learning_zone/articles/insi...

Note that even after the disruption, I'm still able to route millions of requests/day through IP IDEA's network

Re: Disrupting the largest residential proxy network

#202

Earlier quoted context omitted.

One thing about Google is that many anti-scraping services explicitly allow access to Google and maybe couple of other search engines. Everybody else gets to enjoy CloudFlare captcha, even when doing crawling at reasonable speeds. Rules For Thee but Not for Me

Why are you scraping sites in the first place? What legitimate reason is there for you doing that?

Just today I wanted to get a list of locations of various art events around the city which are all located on the same website, but which does not provide a page with all events happening this month on a map. I need a single map to figure out what I want to visit based on distance I have to travel, unfortunately that's not an option - only option is to go through hundreds of items and hope whatever I picked is near me.

Do you think this is such a horrible thing to scrape? I can't do it manually since there are few hundred locations. I could write some python script which uses playwrite to scrape things using my desktop browser in order to avoid CloudFlare. Or, which I am much more familiar with, I could write a python script that uses BeautifulSoup to extract all the relevant locations once for me. I would have been perfectly happy fetching 1 page/sec or even 1 page/2 seconds and would still be done within 20 minutes if only there was no anti-scraping protection.

Scraping is a perfectly legal activity, after all. Except thanks to overly-eager scraping bots and clueless/malicious people who run them there's very little chance for anyone trying to compete with Google or even do small scale scraping to make their life and life of local art enthusiasts easier. Google owns search. Google IS search and no competition is allowed, it seems.

Re: Disrupting the largest residential proxy network

#203

Earlier quoted context omitted.

First of: Google has not once crashed one of our sites with GoogleBot. They have never tried to by-pass our caching and they are open and honest about their IP ranges, allowing us to rate-limit if needed. The residential proxies are not needed, if you behave. My take is that you want to scrape stuff that site owners do not want to give you and you don't want to be told no or perhaps pay a license. That is the only ca…

You can’t get much crawling done from published cloud IPs. Residential proxies are the only way to do most crawls today. That said, I support Google working to shut these networks down, since they are almost universally bad. It’s just a shame that there’s no where to go for legitimate crawling activities.

> You can’t get much crawling done from published cloud IPs.

Think about why that might be. I'm sorry, if you legitimately need to crawl the net, and do so from a cloud provide, your industry screwed you over with bad behaviour. Go get hosting with a company that cares about who their customers are, you're hanging out with a bad crowd.

Re: Disrupting the largest residential proxy network

#204

Earlier quoted context omitted.

You can’t get much crawling done from published cloud IPs. Residential proxies are the only way to do most crawls today. That said, I support Google working to shut these networks down, since they are almost universally bad. It’s just a shame that there’s no where to go for legitimate crawling activities.

> You can’t get much crawling done from published cloud IPs. Think about why that might be. I'm sorry, if you legitimately need to crawl the net, and do so from a cloud provide, your industry screwed you over with bad behaviour. Go get hosting with a company that cares about who their customers are, you're hanging out with a bad crowd.

what industry is that? Every industry is on the cloud.

Re: Disrupting the largest residential proxy network

#205
post #6

My understanding is that routing through residential IPs is a part of the business of some VPN providers. I don't know how above board they are on this (as in notifying customers that this may happen, however buried in the usage agreement, or even allowing them to opt out). But, my main point, is that the whole business is "on the up and up" vs some dark botnet.

> I don't know how above board they are on this

Saying you don't know something in the comments of an article that explains that thing is a bold strategy

Re: Disrupting the largest residential proxy network

#206
post #163

Earlier quoted context omitted.

I'd still like the ability to just block a crawler by its IP range, but these days nope. 1 Hz is 86400 hits per day, or 600k hits per week. That's just one crawler. Just checked my access log... 958k hits in a week from 622k unique addresses. 95% is fetching random links from u-boot repository that I host, which is completely random. I blocked all of the GCP/AWS/Alibaba and of course Azure cloud IP ranges. It's almos…

I’ve been enduring that exact same traffic pattern. I used Anubis and a cookie redirect to cut the load on my Forgejo server by around 3 orders of magnitude: https://honeypot.net/2025/12/22/i-read-yann-espositos-blog.h...

Aha, that's where the anime girl is from. What sort of traffic was getting past that but still thwarted by the cookie tactic?

I guess the bots are all spoofing consumer browser UAs and just the slightest friction outside of well-known tooling will deter them completely.

Re: Disrupting the largest residential proxy network

#207

Earlier quoted context omitted.

> You can’t get much crawling done from published cloud IPs. Think about why that might be. I'm sorry, if you legitimately need to crawl the net, and do so from a cloud provide, your industry screwed you over with bad behaviour. Go get hosting with a company that cares about who their customers are, you're hanging out with a bad crowd.

what industry is that? Every industry is on the cloud.

No, no they really aren't, but I was thinking the "scraping industry" in the sense that that's a thing. Getting hosting in smaller datacenters is simple enough, but you may need to manage your own hardware, or VMs. Many will help you get your own IP ranges and ASN, that's going to go a long way, if you don't want to get bundled in with the bad bots.

This differs obviously, but having an ASN in our case means that we can deal you, contact you and assume that you're better than random bot number 817.

Re: Disrupting the largest residential proxy network

#208
post #6

My understanding is that routing through residential IPs is a part of the business of some VPN providers. I don't know how above board they are on this (as in notifying customers that this may happen, however buried in the usage agreement, or even allowing them to opt out). But, my main point, is that the whole business is "on the up and up" vs some dark botnet.

Mullvad seems to be one of those VPN providers. [1] Though I very much doubt they would sneakily make end-users devices exit nodes. Though, as a historical side note, let's not forget Skype used to make users computers act as a relay as well during its more decentralized days.

[1] Using the website mentioned by user Rasbora https://news.ycombinator.com/item?id=46837806

Re: Disrupting the largest residential proxy network

#209

I'm surprised by the negative takes... Yes, proxies are good. Ones which you pay for and which are running legitimately, with the knowledge (and compensation) of those who run them. Malware in random apps running on your device without your knowledge is bad.

> Ones which you pay for and which are running legitimately, with the knowledge (and compensation) of those who run them.

The problem is, it is by default unethical to have residential users be exit nodes for VPNs - unless these users are lawyers or technical experts.

No matter what you do as a "residential proxy" company - you cannot prevent your service being used by CSAM peddlers, and thus you cannot prevent that your exit nodes aren't the ones whose IP addresses show up when the FBI comes knocking.

Post reply on HN