Jake Gold

Jake Gold

Building AI infra @ Clor in SF Bay Area. Helped launch and scale Vibecode and Bluesky. Prev: Nuro, Docker, Google, and founder.

Residential Proxies Are a National Security Threat

US residential proxies are the bane of the internet. They’re the major source of social media manipulation and spam. A residential proxy runs someone else’s traffic through a real home internet connection, so it looks like a normal person on Comcast or AT&T. Almost no one intentionally runs one on behalf of bad actors, they’ve been tricked or hacked. Usually it’s one of a few things:

  • A free VPN app reselling your bandwidth.
  • A proxy SDK buried in some free game.
  • Malware on a computer, router, or smart TV.

LG recently moved to ban proxy apps from its smart TVs after researchers found that over 42% of its apps could covertly turn your TV into a proxy.

Why they’re so hard to block

Internet services (including social media apps) can dramatically reduce abuse by blocking entire IP ranges based on country of origin, organization, or type (hosting providers). But a company can’t block US residential IPs if it would also cut off many of their real users. This is why bad actors love US residential proxies, their abuse comes from the same addresses as genuine users.

There’s a whole industry of “threat intelligence” companies that track IPs and sell this information for a lot of money. It’s readily available if you pay for it (and they could just report abuse to internet providers), but there are obviously perverse incentives here, since significantly reducing the problem would reduce their value.

A national security threat

The US government (probably the NSA) should be cracking down hard on US residential proxy networks. They’re a genuine national security threat:

  • Actual data and identity loss of American citizens.
  • Malware that can record video and audio from infected devices.
  • Infrastructure for foreign covert influence campaigns.
  • Botnets used in hacking and DoS attacks.

ISPs should warn their customers

At the very least, major American ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It’s very bad for the customers too, it slows things down and gets their IP banned.

None of this is unique to the US. Every country should be doing the same as part of running a healthy and secure internet of its own.

Discuss on Hacker News