911 Proxy Service Implodes After Disclosing Breach
krebsonsecurity.com
krebsonsecurity.com
Check us out at https://spur.us
You say it yourself:
> Residential proxies can be impossible to detect.
The appeal of residential proxies is that the traffic comes from legitimate user networks. So how do you detect malicious usage there?
Moreover, it must be a game of whack-a-mole to keep your lists updated, as these services pop up all the time.
Very interesting service, but sadly I cannot sign up for a trial, due to not possessing a US telephone number, which for some reason is required. That said I am a researcher at an Internet measurement and security group. Any chances for a cooperation?
Honestly, for assessing risk of individual users, my worry is that the only good option right now is to use tools that require lots of data on the user, like recaptcha v3. You could set up a honeypot that tries to catch as many IP addresses implicated in proxy activity as possible. Maybe that second one would be a good company idea.
1. SEON: https://seon.io/
2.IPQS: https://www.ipqualityscore.com/
As I explained to my colleagues, I wouldn't be able to determine, with confidence, which of the services were 100% legit, and which weren't. We didn't want to accidentally get involved with questionably-obtained residential IPs, etc. That would've been antithetical to our business, and also just not how we operate in general.
(The startup provided solutions in the supply chain integrity space. Part of the technology included bespoke Web scraping, to monitor certain venues for naughtiness scale and patterns over time. Because venues were around the world, and because venues had complicating incentives regarding some of the questionable third-party activity in the venue... I wanted the delicate scraping to look similar to normal consumer users who were in the geopolitical region served by the venue. Instead of a residential IP service, I used an (undisclosed) different, impeccable approach, which won't work for all use cases, but did for ours.)
3G/LTE because all mobile providers use CG-NAT?
(I also discovered that my old DSL ISP accepted its dialup provider's credentials for PPPoE). Best part about PPPoE is that you can run multiple sessions over the same line/modem.
I don’t know that’s what happened here, but it sounds like some of the installs were PPI, so I wouldn’t be surprised. That basically means anyone who can figure out how to bundle the software with an artifact can distribute it. A long time ago, and probably today too, people used to crack popular programs, bundle some adware into them, and then seed the torrent. The user is already committed to circumventing security checks and entering strange commands, so I can imagine how they might end up installing some bonus executables in the process.
And that is IMHO a good thing. The alternative is a world where no one has any freedom.
There was a time I had a very Stallman view on software. Now I think my views are that having closed source devices, where security is managed by 'trusted' third parties, is absolutely fine for people who don't care. However, there should always be a choice for those who do want to exercise their freedom, and typically those who care about their digital freedoms will be technical enough to manage their devices responsibly. Clearly though in the mobile market in particular we're very far away from realising this.
But to use that car analogy, in my country it is a legal requirement to have your car undergo a safety check every year for cars older than a certain age. That is very analogous to installing software updates in my opinion, and yet we don't enforce legal requirements to install updates on personal devices.
They're different things.
I would love to see someone start a Windows app store that's based on domain validated code signing. Domains are better trust indicators than business names IMO.
> What's the current status?
> We’re working hard to release v1.0 in July.
Hopefully they are close to release.
Did a teardown on their crazy economics recently https://scrapeops.io/web-scraping-playbook/residential-mobil...
The profit margins are insane, easily over 99% profit on millions in revenue.
Are they reselling that bandwidth, mining my data, monitoring my traffic, or all of the above?
When the service is free, you are the product.
Scraping is legal.
Attempting to block it is a grey area.
Among their reasons they list that it's a "huge challenge" to manually vet traffic to detect malicious usage. They've been online for two years and only now determined that this would be a challenge?
And then blame a hacker of manipulating user balances and data loss. Please.
This sounds like incompetence on their side to keep their shady business under wraps, and now that it's been made public, they're shutting down to re-brand and launch a "new" service with the same backend. Any one of their "competitors" could actually just be them.