Live data from Hacker News

Residential Proxies Are a National Security Threat

jacob.gold

81–90 of 100 posts

Re: Residential Proxies Are a National Security Threat

#81
post #54

The "solution" is to shoot CGNAT and to finally force the ISPs to adopt IPv6 so everybody can drop the addresses of a detected residential proxy into a ban list. Continuing to allow CGNAT is what allows the residential proxies to hide because it tumbles the IP identity of bad actors with normal people.

Your premise seems to be that you expect IPv6 addresses to be scarce.

Re: Residential Proxies Are a National Security Threat

#82

My personal opinion is they're not hard to detect at all. Latency is a huge giveaway, If the client can't respond in a time you'd expect a client to be able to based on its geographic location, that's a pretty big tell they're using proxies. In fact, if you did latency sensitive stuff, you'd likely find out whether you wanted to or not.

This is not always the case, although plausible, as residential proxies exit on a real residential IP geographically near the victim/target, so RTT looks normal most times and latency won't reveal them. The actual tells are elsewhere: ASN/IP reputation, TLS (JA3/JA4) fingerprint vs. claimed client, and session-behavior inconsistencies.

Re: Residential Proxies Are a National Security Threat

#83

Earlier quoted context omitted.

I would if there was an easy way to make a cut of the revenue of its usage or if I got to use other people's home connections.

Fair enough. Maybe I just have trust issues. Well earned trust issues.

But do they serve you still, or are you holding on to past trauma(s) unnecessarily.

Re: Residential Proxies Are a National Security Threat

#84

Earlier quoted context omitted.

Disagree fairly strongly. IP addresses known to be malicious are unequal and should be treated as such. Just because the idea of net neutrality exists doesn't mean it's true. I'm sure there's a specific context for it, and 'security' is not that context. It was about data/packet prioritisation wasn't it? Unrelated to security.

Yeah, mail server IP reputation is a good example. I wouldn't want to be flooded by emails from spammy mailservers IPs and I'm glad that my provider de-priortizes them.

The reason that works for mail servers is that they first require the IP address to have a valid reverse DNS entry, which is not just compromising a random machine with a random IP address but having administrative control over that IP block, which basically limits you to data centers and business internet providers, and then blocks IP addresses that send spam, i.e. that are owned by providers who give reverse DNS entries to spammers. The premise is that most people aren't trying to run a mail server so you require something that takes unusual bureaucratic interaction in order to get.

Trying to restrict things to end-users is the total opposite of that. The common addresses everybody gets automatically are the thing you're trying to allow. Address reputation is pointless because residential customers get dynamic IPs and the reputation you're trying to record for some IP address can get swapped with a different customer at any time.

Re: Residential Proxies Are a National Security Threat

#85

Earlier quoted context omitted.

Yeah, mail server IP reputation is a good example. I wouldn't want to be flooded by emails from spammy mailservers IPs and I'm glad that my provider de-priortizes them.

The reason that works for mail servers is that they first require the IP address to have a valid reverse DNS entry, which is not just compromising a random machine with a random IP address but having administrative control over that IP block, which basically limits you to data centers and business internet providers, and then blocks IP addresses that send spam, i.e. that are owned by providers who give reverse DNS en…

Sounds like a good reason that residential proxies are a bad thing, or at least require better regulation, so as to minimise damage to unwitting end-users.

It also feels like a description of the perfect camouflage to facilitate doing bad things: "don't block them because you might block an innocent bystander". Putting innocent bystanders in harms way sounds like someone else is the bad guy, not the person doing the blocking.

Re: Residential Proxies Are a National Security Threat

#86

No, your paranoia-outage is the true "national security threat" - a threat to freedom. Stop fanning the flames and calling for more government intervention.

After decades of watching people use these three words, I've come to the conclusion that 'national security threat' is a right-wing dog-whistle for 'we have no actual proof, but we dislike it, so let's ban it'. They are basically 'won't someone please think of the children?', but with higher stakes.

It's neither right nor left, but authoritarian and there are plenty of those around.

Re: Residential Proxies Are a National Security Threat

#87
post #54

The "solution" is to shoot CGNAT and to finally force the ISPs to adopt IPv6 so everybody can drop the addresses of a detected residential proxy into a ban list. Continuing to allow CGNAT is what allows the residential proxies to hide because it tumbles the IP identity of bad actors with normal people.

Tell us that you don't know how residential proxies work, without telling us that you don't know how residential proxies work.

Re: Residential Proxies Are a National Security Threat

#88

Earlier quoted context omitted.

Haha no they dont, ive used brightdata and all you need is a credit card and you’re good to go It is shady AF.

Actually they have several different products based on IP type and quality. The credit-card only access you're talking about is for shared and flagged residential proxies. ISPs legally sell them to businesses and they can work for some use cases, but you need a video call and KYC to get access to a high quality IP pool, such as real mobile IPs they source from p2p services like VPNs.

There is nothing in that explanation that makes it sound anything like an above board trustworthy business that doesn't make one feel dirty for interacting with.

> you need a video call and KYC to get access to a high quality IP pool

They need to know who to blame (cough come after cough) if their top-shelf stock gets tainted by some script kiddie.

Re: Residential Proxies Are a National Security Threat

#90

Earlier quoted context omitted.

That’s a weird way to justify fucking over an uninvolved third party.

>fucking over an uninvolved third party No one is being hurt by someone sharing their internet with me a few times a week.

The article is about surreptitious proxies.
Post reply on HN