[HN Gopher] Disrupting the largest residential proxy network
       ___________________________________________________________________
        
       Disrupting the largest residential proxy network
        
       Author : cdrnsf
       Score  : 53 points
       Date   : 2026-01-28 22:46 UTC (2 days ago)
        
 (HTM) web link (cloud.google.com)
 (TXT) w3m dump (cloud.google.com)
        
       | xyzzy_plugh wrote:
       | > These efforts to help keep the broader digital ecosystem safe
       | supplement the protections we have to safeguard Android users on
       | certified devices. We ensured Google Play Protect, Android's
       | built-in security protection, automatically warns users and
       | removes applications known to incorporate IPIDEA SDKs, and blocks
       | any future install attempts.
       | 
       | Nice to see Google Play Protect actually serving a purpose for
       | once.
        
         | trollbridge wrote:
         | Yeah, it serves the purpose of blocking this kind of proxy
         | traffic that isn't in Google's personal best interests.
         | 
         | Only Google is allowed to scrape the web.
        
           | a456463 wrote:
           | Yup exactly. Google must be the only one allowed to scrape
           | the web. Google can't have any other competition. Calling it
           | in "user's best interest" is just like their other marketing
           | cons: "play integrity for user's security" etc
        
       | kotaKat wrote:
       | I'm actually a little shocked seeing that there was a _WebOS_
       | variant of the residential proxying SDK endpoint. Does that mean
       | there might be a bit more unchecked malware lurking behind the
       | scenes in the LG ecosystem?
       | 
       | Personally I'm surprised they didn't have a Samsung option.
        
         | wincy wrote:
         | I keep my brand new LG C5 totally disconnected from the
         | internet and use my Apple TV for movie watching. I'm not going
         | to trust a company like LG to secure their devices.
        
           | xnx wrote:
           | > trust a company like LG to secure their devices.
           | 
           | They have an interest in securing their devices so they can
           | sell proxy service themselves.
        
       | whartung wrote:
       | My understanding is that routing through residential IPs is a
       | part of the business of some VPN providers. I don't know how
       | above board they are on this (as in notifying customers that this
       | may happen, however buried in the usage agreement, or even
       | allowing them to opt out).
       | 
       | But, my main point, is that the whole business is "on the up and
       | up" vs some dark botnet.
        
         | nielsbot wrote:
         | FTA
         | 
         | > While operators of residential proxies often extol the
         | privacy and freedom of expression benefits of residential
         | proxies, Google Threat Intelligence Group's (GTIG) research
         | shows that these proxies are overwhelmingly misused by bad
         | actors
        
           | direwolf20 wrote:
           | Google's definition of a "bad actor" is someone who wants to
           | use Google without seeing the ads. Or Kagi. Or an AI other
           | than Gemini.
        
       | samsullivan wrote:
       | The need for proxies in any legitimate context became obsolete
       | with starlink being so widespread. Throw up a few terminals and
       | you have about 500-2k cgnat IP addresses to do whatever you like.
        
         | JDye wrote:
         | 2k IPs is not enough to do most enterprise scale scraping.
         | Starlink's entire ASN doesn't seem to have enough V4 addresses
         | to handle it even.
        
       | londons_explore wrote:
       | We need _more_ residential proxies, not less.
       | 
       | I've had enough of companies saying "you're connecting from an
       | AWS IP address, therefore you aren't allowed in, or must buy
       | enterprise licensing". Reddit is an example which totally blocks
       | all data to non-residential IP's.
       | 
       | I want exactly the same content visible no matter who you are or
       | where you are connecting from, and a robust network of
       | residential proxies is a stepping stone to achieving that.
        
         | packetslave wrote:
         | > Reddit is an example which totally blocks all data to non-
         | residential IP's.
         | 
         | No, we don't.
        
           | direwolf20 wrote:
           | Have you tried it? Every new account will be shadowbanned and
           | if it's shared you often get blank page 429. None of this was
           | true before the API shutdown.
        
             | gruez wrote:
             | >Every new account will be shadowbanned
             | 
             | That's not the same as "blocks all data to non-residential
             | IP's"?
             | 
             | >if it's shared you often get blank page 429. None of this
             | was true before the API shutdown.
             | 
             | See my other comment. I agree there's a non-zero amount of
             | VPNs that are banned from reddit, but it's also not
             | particularly hard to find a VPN that's not banned on
             | reddit.
        
               | interloxia wrote:
               | Probably not hard but my poor little innocent VPS at
               | Hetzer that I have had for years is denied and that makes
               | me sad.
        
             | 3rodents wrote:
             | That's not my experience, using various VPNs, public
             | networks, Cloudflare and Apple private relays. A captcha is
             | common when logged out but that's about it, I have not
             | encountered any shadow bans. I create a new account each
             | week.
        
           | hackeman300 wrote:
           | Try browsing from any Mullvad vpn. You will be "blocked by
           | network security"
        
             | gruez wrote:
             | That's just mullvad's IP pool being banned. The other VPN
             | providers I use aren't banned, or at least are only
             | intermittently banned that I can easily switch to another
             | server.
        
             | edoceo wrote:
             | I use mullvad regularly & visit reddit from that connection
             | - it works. But! You have to sign-in.
        
           | piskov wrote:
           | Yes you do.
           | 
           | Private VPS for personal VPN in Netherlands (digital ocean),
           | then Hungary (some small local DC) -- both are blocked from
           | day one.
           | 
           | > You've been blocked by network security. To continue, log
           | in to your Reddit account or use your developer token. If you
           | think you've been blocked by mistake, file a ticket below and
           | we'll look into it.
        
             | Imustaskforhelp wrote:
             | Proton VPN sometimes (mostly?) has this issue too. It's a
             | bit of an hit or miss in there iirc but I have definitely
             | seen the last message of your comment.
        
           | dvngnt_ wrote:
           | there are several times where I've had to disable PIA to
           | access reddit's login page
        
           | thot_experiment wrote:
           | I have never interacted with a reddit employee who wasn't
           | actively gaslighting me about the platform. Do you even use
           | the site? I talked to a PM recently who genuinely thought the
           | phone app was something people liked.
        
           | tokyobreakfast wrote:
           | If they downvote you hard enough it will become true (this
           | also works on Reddit).
        
           | a456463 wrote:
           | Have you tried using it logged out on a vpn? It is
           | impossible.
        
         | xg15 wrote:
         | Also, nevermind the tech companies building their own proxy
         | networks, such as Find My or Amazon Sidewalk.
        
           | a456463 wrote:
           | Agreed. With things people paid for and using our wifi data
           | to build their "positioning dbs" that you can't block or turn
           | off on your phone, without "rooting" your own device.
        
           | enneff wrote:
           | How is Find My a proxy network?
        
         | direwolf20 wrote:
         | You can run one, something like ByteLixir, Traffmonetizer,
         | Honeygain, Pawns, there are lots more, just google "share my
         | internet for money"
         | 
         | What will you be proxying? Nobody knows! I haven't had the
         | police at my house yet.
         | 
         | Seems a great way to say "fuck you" to companies that block IP
         | addresses.
         | 
         | You may see a few more CAPTCHAs. If you have a dynamic IP
         | address, not many.
        
           | dist-epoch wrote:
           | How much can you make if you run all of them at the same
           | time?
           | 
           | Doesn't the ISP detect them?
        
         | ndiddy wrote:
         | If you look at the article, the network they disrupted pays
         | software vendors per-download to sneakily turn their users into
         | residential proxy endpoints. I'm sure that at least _some_ of
         | the time the user is _technically_ agreeing to some wording
         | buried in the ToS saying they consent to this, but it 's
         | certainly unethical. I wouldn't want to proxy traffic from
         | random people through my home network, that's how you get legal
         | threats from media companies or the police called to your
         | house.
        
           | londons_explore wrote:
           | > that's how you get legal threats from media companies or
           | the police called to your house.
           | 
           | Or residential proxies get so widespread that almost every
           | house has a proxy in, and it becomes the new way the internet
           | works - "for privacy, your data has been routed through
           | someone else's connection at random".
        
             | Imustaskforhelp wrote:
             | > Or residential proxies get so widespread that almost
             | every house has a proxy in, and it becomes the new way the
             | internet works - "for privacy, your data has been routed
             | through someone else's connection at random".
             | 
             | Is this a re-invention of tor, maybe I2P?
        
           | dataviz1000 wrote:
           | They provide an SDK for mobile developers. Here is a video of
           | how it works. [0] They don't even hide it.
           | 
           | [0] https://www.youtube.com/watch?v=1a9HLrwvUO4&t=15s
        
         | BoredPositron wrote:
         | I still "run" a small ISP with a few thousand residential ips
         | from my scraping days. The requirements are laughable and costs
         | were negligible in the early 2000s.
        
         | Aurornis wrote:
         | > I want exactly the same content visible no matter who you are
         | or where you are connecting from
         | 
         | The reason those IP addresses get blocked is not because of
         | "who" is connecting, but "what"
         | 
         | Traffic from datacenter address ranges to sites like Reddit is
         | almost entirely bots and scrapers. They can put a tremendous
         | load on your site because many will try to run their queries as
         | fast as they can with as many IPs as they can get.
         | 
         | Blocking these IP addresses catches a few false positives, but
         | it's an easy step to make botting and scraping a little more
         | expensive. Residential proxies aren't all that expensive, but
         | now there's a little line item bill that comes with their
         | request volume that makes them think twice.
         | 
         | > We need more residential proxies, not less
         | 
         | Great, you can always volunteer your home IP address as a
         | start. There are services that will pay you a nominal amount
         | for it, even.
        
         | tokyobreakfast wrote:
         | > I've had enough of companies saying "you're connecting from
         | an AWS IP address
         | 
         | I run a honeypot and the amount of bot traffic coming from AWS
         | is insane. It's like 80% before filtering, and it's 100%
         | illegitimate.
        
         | JDye wrote:
         | I live in the UK and can't view a large portion of the internet
         | without having to submit my ID to _every_ site serving anything
         | deemed "not safe the for the children". I had a question about
         | a new piercing and couldn't get info on it from Reddit because
         | of that. I try using a VPN and they're blocked too. Luckily, I
         | work at a copmany selling proxies so I've got free proxies
         | whenever I want, but I shouldn't _need_ to use them.
         | 
         | I find it funny that companies like Reddit, who make their
         | money entirely from content produced by users for free (which
         | is also often sourced from other parts of the internet without
         | permission), are so against their site being scraped that they
         | have to objectively ruin the site for everyone using it. See
         | the API changes and killing off of third party apps.
         | 
         | Obviously, it's mostly for advertising purposes, but they love
         | to talk about the load scraping puts on their site, even suing
         | AI companies and SerpApi for it. If it's truly that bad, just
         | offer a free API for the scrapers to use - or even an API that
         | works out just slightly cheaper than using proxies...
         | 
         | My ideal internet would look something like that, all content
         | free and accessible to everyone.
        
           | Aurornis wrote:
           | > that they have to objectively ruin the site for everyone
           | using it. See the API changes and killing off of third party
           | apps.
           | 
           | Third party app users were a very small but vocal minority.
           | The API changes didn't drop their traffic at all. In fact,
           | it's only gone up since then.
           | 
           | The datacenter IP address blocks aren't just for scrapers,
           | it's an anti-bot measure across the board. I don't spend much
           | time on Reddit but even the few subreddits I visited were
           | starting to become infiltrated by obvious bot accounts doing
           | weird karma farming operations.
           | 
           | Even HN routinely gets AI posting bots. It's a common
           | technique to generate upvote rings - Make the accounts post
           | comments so they look real enough, have the bots randomly
           | upvote things to hide activity, and then when someone buys
           | upvotes you have a selection of the puppet accounts upvote
           | the targeted story. Having a lot of IP addresses and
           | generating fake activity is key to making this work, so
           | there's a lot of incentive to do it.
        
         | a456463 wrote:
         | This blog post from the company that used promise "don't be
         | evil", one that steals water for data centers from vilages and
         | towns via shady deals, whose whole premise it stealing other
         | people's stuff and claiming it as their own and locking them
         | out and selling their data.. Who made them the arbiter of the
         | internet? No one!!!
         | 
         | They just stole this and get on their high horse to tell people
         | how to use internet? You can eff right off Google.
        
       | direwolf20 wrote:
       | All of this sounds legal, so on what basis did they get them shut
       | down?
        
         | SOTGO wrote:
         | I haven't looked at any court documents, but the WSJ article
         | from Wednesday reported that "Last year, Google sued the
         | anonymous operators of a network of more than 10 million
         | internet-connected televisions, tablets and projectors, saying
         | they had secretly pre-installed residential proxy software on
         | them... an Ipidea spokeswoman acknowledged in an email that the
         | company and its partners had engaged in "relatively aggressive
         | market expansion strategies" and "conducted promotional
         | activities in inappropriate venues (e.g., hacker forums)...""
         | 
         | There was also a botnet, Kimwolf, that apparently leveraged an
         | exploit to use the residential proxy service, so it may be
         | related to Ipidea not shutting them down.
        
       | scirob wrote:
       | so that only google and anthropic are allowed to scrape the web.
       | No one else may have workarounds
        
         | a456463 wrote:
         | Exactly. This is just google building a "moat" around their
         | shady business.
        
       | htx80nerd wrote:
       | nice to see in the comments how many people didnt even do a 30
       | second scan of the article before clicking `add comment`
        
       | progbits wrote:
       | I'm surprised by the negative takes...
       | 
       | Yes, proxies are good. Ones which you pay for and which are
       | running legitimately, with the knowledge (and compensation) of
       | those who run them.
       | 
       | Malware in random apps running on your device without your
       | knowledge is bad.
        
       ___________________________________________________________________
       (page generated 2026-01-30 23:01 UTC)