Oxylabs(NordVPN) Fined $7.5M by jury for residential proxy botnet
techradar.com
techradar.com
http://web.archive.org/web/20191128170008/https://medium.com...
> See the problem is, NordVPN is linked closely with a Lithuanian data mining company called Tesonet. NordVPN is said to be one of Tesonet’s projects, Oxylabs.io is another one.
> So what’s the big deal? Oxylabs.io advertises on its website “32M+ residential proxies…100% anonymous proxies from all over the globe with zero IP blocking.” Think of “residential proxies” this way: 1.) Oxylabs installs some malware on to a user’s device, unknown to the user, by bundling it with other software that the user downloads. 2.)This malware enables Oxylabs to sell off your bandwidth, your computing power, and your IP address to third parties, who will route their internet traffic through your device.
“If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.”
-Cardinal Richelieu
The problem is that residential proxies are primarily used for abusive purposes, like credit card fraud (e.g. making purchases with a proxy in the same city as the credit card holder) or web forum spam. There are very few legitimate use cases for these services; most of the ones I have heard are either poorly justified (you don't really need a residential IP to test web site performance, for example) or borderline abusive (like content scraping or sneaker botting).
But it would be interesting to know what these companies do to cut down abuse and results thereof...
The people providing the exit points for Oxylabs and Luminati do not know they are acting as exit points, nor would they actually approve of it if they knew what it meant.
Oxylabs have a public stance about doing it in above-the-board ways (https://oxylabs.io/blog/standards-for-proxy-acquisition) but I guess you're saying this is BS.
For the actual end user it's definitely not above the board.
Public notes:
https://www.reddit.com/r/androiddev/comments/ao27tu/my_app_w...
https://www.reddit.com/r/androiddev/comments/ajfc7w/question...
https://dx.doi.org/10.14722/ndss.2021.24008
I have never seen actual informed consent before in ANY of these for the final end user; most of the targeted apps are general rubbish (think flashlight app requesting location permission and contacts type of BS). At best it would be buried deep in a ToS or EULA somewhere, and even that's fairly rare. Using a very very stretched definition of rewarding users, you could argue that "allowing the use of a calculator for free" is the reward for being an open proxy.
If you find any example anywhere by the implementors ("oh, it's the sdk includer's fault they aren't saying anything, we're totally above board...") that there is anything approaching informed consent, I would love to know some examples, because I've never seen one in these. (I would dearly love to be wrong here)
There's still a remote possibility that they have changed their behaviour, since their post about end-user awareness and monetary compensation is somewhat newer than your references, but at this point I would need some independent third party vetting about that to convince me.