Some info on methodology would be necessary for a paid plan for two purposes, one to audit that the quality of the methodology and the signal is good (it's not hallucinated or checking few sources).
But also to make sure it doesn't clash with other signals if used in conjunction with other sources of tool (if I have another signal, I want to know whether they are redundant or complementary, to avoid interpreting two positives as independently verified.
I assume that eventually the flag will just become meaningless and there will be other methods of verification in use by then... because cutting off a huge chunk of your customers just isn't good business.
But for now I'm already cut off from half the internet due to endless crimeflare captcha loops... I just don't visit those sites anymore because I literally can't.
If people who have a smart TV have their smart TV participate in a residential proxy, then it's billions of IP getting "flagged".
There's a non-trivial quantity error here that makes the argument of a majority qualitatively incorrect.
It's not billions of IPs that are being used in residential proxies, it's not all smart TVs.
There needs to be a vulnerability and hacked devices OR there needs to be a very low quality and shady vendor that is offering products at too cheap prices and needs to make ends meet in order to compete at that price. Probably chinese.
This would be in the range of 1 to 100 million smart TVs. sorry for the wide range, but definitely not 1Billion or every TV.
So to the extent that the ratio of infected to non infected IPs is low, then providers can block the infected ones to a great effect.
But whether your IP address is being used as a residential proxy is already important information. It answers the question (is this IP address low quality?)
Although I'll grant that it would be interesting to know if your devices are running the proxy, but you'll need an exeuctable tool for that, not a per-ip network tool.
It says I was observed on a couple areas, but not sure what to do with that information. It would be great if thi tool provided links to guides to discover more.
In my testing, Synthient's tool[0] and offerings have performed very well for this kind of service. Synthient have also achieved impressive proven success against malicious botnets[1].
Keep in mind these databases can be wildly inaccurate and basically impossible to prove them wrong (you can't prove a negative).
I've seen this (and verified with others) with other sites like iknowwhatyoudownload.com where they allege your connection downloaded something very illegal (like CSAM) even though you know for certain it never happened and you haven't been hacked.
There really isn't any proof that they can show, since iknowwhatyoudownload legally aren't allowed to download anything that you're seeding (since that would be considered piracy).
IIRC, they only show the filename, last-seen timestamp and user agent. I can't verify it though since their website seems to be down?
Would be great if it told me how recently it was detected. I have a dynamic IP from my ISP and it could very well be someone else's device 3 days or 3 months ago.
this company Spur recently got millions in funding and their pricing seems to be directed at large companies. Who's buying these absolutely non-actionable IP databases? Do corporate buyers not understand you can't just block someone because they share the IP with someone else who downloaded a dodgy app?
Spur's residential proxy data is not intended to be used as a blacklist. We recommend using it as enrichment alongside other signals, not blocking an IP just because it was associated with proxy activity.
wow my comment with a blog post about a better approach to detect residential proxies got... removed! Not sure about HN internals, do moderators do that or is this OP using several accounts to downvote contrarian comments?
Needs an API to query other IPs beyond one's own.
Try https://spur.us/context/<ip> where <ip> is the IP you want to query :)
Thanks! Do you plan on a paid plan? Would you be able to provide methodology under NDA if needed?
(cyber consultant, have people who might use this for enrichment in security stacks)
+1
Some info on methodology would be necessary for a paid plan for two purposes, one to audit that the quality of the methodology and the signal is good (it's not hallucinated or checking few sources).
But also to make sure it doesn't clash with other signals if used in conjunction with other sources of tool (if I have another signal, I want to know whether they are redundant or complementary, to avoid interpreting two positives as independently verified.
I am on mobile network and it fails to consider this as a factor that other people who might receive this IP could be having a proxy.
If the IP address you're using has been detected as a residential proxy, it doesn't matter. It's going to be flagged on lists for a long time.
Being able to check is helpful.
Flagged and then... What exactly?
If people who have a smart TV have their smart TV participate in a residential proxy, then it's billions of IP getting "flagged".
What's the use of flagging those?
When every IP is flagged, none is.
I assume that eventually the flag will just become meaningless and there will be other methods of verification in use by then... because cutting off a huge chunk of your customers just isn't good business.
But for now I'm already cut off from half the internet due to endless crimeflare captcha loops... I just don't visit those sites anymore because I literally can't.
There's a non-trivial quantity error here that makes the argument of a majority qualitatively incorrect.
It's not billions of IPs that are being used in residential proxies, it's not all smart TVs.
There needs to be a vulnerability and hacked devices OR there needs to be a very low quality and shady vendor that is offering products at too cheap prices and needs to make ends meet in order to compete at that price. Probably chinese.
This would be in the range of 1 to 100 million smart TVs. sorry for the wide range, but definitely not 1Billion or every TV.
So to the extent that the ratio of infected to non infected IPs is low, then providers can block the infected ones to a great effect.
Bright Data claim to have 400 million IPs.
https://brightdata.com/proxy-types/residential-proxies
Mine isn't flagged. Not gonna set up a smart TV.
Yeah, clicked from my mobile network without thinking and nearly jumped out my skin.
I added a warning that should help with this now.
But whether your IP address is being used as a residential proxy is already important information. It answers the question (is this IP address low quality?)
Although I'll grant that it would be interesting to know if your devices are running the proxy, but you'll need an exeuctable tool for that, not a per-ip network tool.
It says I was observed on a couple areas, but not sure what to do with that information. It would be great if thi tool provided links to guides to discover more.
Which proxy network(s) did you get tagged in?
In my testing, Synthient's tool[0] and offerings have performed very well for this kind of service. Synthient have also achieved impressive proven success against malicious botnets[1].
0: https://synthient.com/context/ip/
1: https://www.wsj.com/tech/kimwolf-hack-residential-proxy-netw... / https://archive.ph/SpKVn
Seems it only detects ipv4. Any plan to support scanning ipv6 /56 range?
Keep in mind these databases can be wildly inaccurate and basically impossible to prove them wrong (you can't prove a negative).
I've seen this (and verified with others) with other sites like iknowwhatyoudownload.com where they allege your connection downloaded something very illegal (like CSAM) even though you know for certain it never happened and you haven't been hacked.
Do they show proof of the positive if you show up in there?
There really isn't any proof that they can show, since iknowwhatyoudownload legally aren't allowed to download anything that you're seeding (since that would be considered piracy).
IIRC, they only show the filename, last-seen timestamp and user agent. I can't verify it though since their website seems to be down?
very nice.
Can we use it in other IPs? (without having to issue the request from that IP)
Yes. You can use https://spur.us/context/<ip> where the IP is the one you want to lookup.
This would probably false positive every CGNAT IP, or am I misunderstanding something?
I think CGNAT is a type of residential proxy.
Hidden from the user and provided by the ISP
CGNAT isn't a residential proxy
Yes, it did and it does.
Would be great if it told me how recently it was detected. I have a dynamic IP from my ISP and it could very well be someone else's device 3 days or 3 months ago.
My public IP is shared with some 150 people in a student dorm, and the result is negative which I find very unlikely.
this company Spur recently got millions in funding and their pricing seems to be directed at large companies. Who's buying these absolutely non-actionable IP databases? Do corporate buyers not understand you can't just block someone because they share the IP with someone else who downloaded a dodgy app?
Spur's residential proxy data is not intended to be used as a blacklist. We recommend using it as enrichment alongside other signals, not blocking an IP just because it was associated with proxy activity.
More on why here: https://spur.us/blog/i-dont-like-big-gateways-and-i-cannot-l...
thanks, that was exactly my point. Residential proxy signal's value is almost 0 but this product moves in the "I solve it all for you" price range.
wow my comment with a blog post about a better approach to detect residential proxies got... removed! Not sure about HN internals, do moderators do that or is this OP using several accounts to downvote contrarian comments?