Citation needed? I'm not a fan of residential proxies but these are pretty wild claims that aren't substantiated. Calling them a "national security threat" implies it is a threat to e.g., the continued existence of the United States. Is it really that? All of the activities described are already violations of the Computer Fraud and Abuse Act.
> At the very least, major American ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy.
What are we saying? Really, what are we saying? We should turn domestic ISPs into domestic surveillance apparatuses to "detect clearly suspicious activity"? What is "clearly suspicious activity"? Section 230 is still law.
They're also a wholly necessary endeavor until the surveillance industry stops discriminating against IP ranges with endless captcha nagwalls. That, including its likely next development of remote attestation, is a much deeper problem for individual liberty. Individual liberty is itself more important than "national security" (which is more about protecting the government rather than the People) and thus needs to be addressed first.
Ad networks like meta ads, google ads use residential IPs + small LLM to check landing page of your advertisers for malware and scams. They are already paying millions for this service.
Sometimes their system malfunctions (cough cough) and you get charged for those clicks but you fail to report them as fraudulent as you've no proof as the IPs and useragent all appear normal to ad agencies and advertisers.
Residential proxies are necessary to access services that try to ban VPNs without compromising anonymity. If they’re banned, it’s easier for websites to require information that can be used to track you (IP address), since most people don’t use VPNs they won’t care.
More importantly, a residential proxy can be mutual. If a group of people agree to forward traffic to each others’ IP, how is it not their business? It obfuscates their identities, but this is the Internet, not e.g. a government office or test center where you obviously can’t walk in with someone else’s ID.
Banning non-consensual proxies makes sense since those are effectively malware, even though they make anonymity harder, so does banning theft and here you’re stealing someone’s internet. I’m sure we can convince enough laymen to knowingly install proxies by paying them.
If so many sites and services didn't go out of there way to block or flag VPN users as suspicious then I would have no need to use residential / mobile proxies.
Anything connected to network can become a national security threat. IoT devices, internet connected smart appliances and all. Computers that run some OS is least of the worry because of the various layers of protection that can be added to them. But it is not the case with the IoT devices or SMART(!) devices where, if the firmware or any app ecosystem gets hacked / cracked / modified or sideloaded without any user intervention, could turn into a large zombie C2C botnet that can cause havoc.
Proxying is least of the worries!
When manufacturers bring out the smart features that require constant data collection, monitoring (obviously in the name of service quality, troubleshooting, firmware / app updates and subscription of services (!!)), it is oblivious to the fact that security and privacy at a personal / state / national level is never considered (for various reasons such as the design, profit interests and overheads / compliance perspectives and what not!) to be part of the ecosystem. Bad actors with sufficient knowledge and tools could exploit and profit from it.
It has become more of a planned obsolescence / profit / greed based industrial / corporate culture in rolling out unwanted stuff / monitoring and controlling as a feature that gets exploited to the core.
Honesntly, I don't have an answer for that, but have some thoughts that I wanted to share.
I do not want a cleaning robot or a water purifier or a printer or a TV or a refrigerator or an oven or a smart light bulb or a smart lock or even my car to have undisclosed, unwarranted connectivity to internet for whatever reasons.
I do not care if it is the manufacture or the service provider or whomsoever it may be!
I want all of the network connectivity options to be explained with all the controlling options and boundaries and data collection that happens on any of the connected medium to be as much transparent with the option of preventing or restricting what one does not want to go out of the device.
Will anyone do that?
It ill never happen! Sadly!
This problem will balloon further without adequate controls and killing the networking at a ground level would only be the only solution!
But, in the case of a connected device having an inbuilt connectivity option (like the m2m based options) in a smart vehicle, even that is not possible!
No, your paranoia-outage is the true "national security threat" - a threat to freedom. Stop fanning the flames and calling for more government intervention.
If someone with informed consent wants to run a residential proxy, that's their right and unlikely to be a national-security problem.
When it comes to involunary proxies, those are really just one of many possible symptoms stemming from a real problem: Shitty security. (Edit: And shitty contract/privacy laws.)
Shitty security is tolerated by our markets, is is protected from fixes due to copyright law, and it is even encouraged by parts of our government that want to exploit the flaws. We will gain far more from fundamental quality-improvements than we will from whack-a-mole-ing on this symptom.
If I own a computer, I should be able to run whatever damn software I want on it, including software that provides a network proxy to others. (N.B. a smart TV is a computer I own.)
Yes, yes, we should fight deceptive software that doesn't disclose it has a proxy function. Fine. But there's no way to square 1) fighting all residential proxies, including ones run with informed consent and 2) preserving the public's access to general-purpose compute at home.
I'd rather live with the proxies than for someone to tell me that if I run squid, I'm damaging national security.
The "solution" is to shoot CGNAT and to finally force the ISPs to adopt IPv6 so everybody can drop the addresses of a detected residential proxy into a ban list.
Continuing to allow CGNAT is what allows the residential proxies to hide because it tumbles the IP identity of bad actors with normal people.
38 comments
[ 0.28 ms ] story [ 10.1 ms ] thread> At the very least, major American ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy.
What are we saying? Really, what are we saying? We should turn domestic ISPs into domestic surveillance apparatuses to "detect clearly suspicious activity"? What is "clearly suspicious activity"? Section 230 is still law.
The interviewee seems pretty inept yet still managed to uncover something really interesting and nefarious.
> Actual data and identity loss of American citizens.
> Malware that can record video and audio from infected devices.
> Infrastructure for foreign covert influence campaigns.
> Botnets used in hacking and DoS attacks
These things have existed for 20+ years. Bad but not exactly a national security threat.
Sometimes their system malfunctions (cough cough) and you get charged for those clicks but you fail to report them as fraudulent as you've no proof as the IPs and useragent all appear normal to ad agencies and advertisers.
More importantly, a residential proxy can be mutual. If a group of people agree to forward traffic to each others’ IP, how is it not their business? It obfuscates their identities, but this is the Internet, not e.g. a government office or test center where you obviously can’t walk in with someone else’s ID.
Banning non-consensual proxies makes sense since those are effectively malware, even though they make anonymity harder, so does banning theft and here you’re stealing someone’s internet. I’m sure we can convince enough laymen to knowingly install proxies by paying them.
Proxying is least of the worries!
When manufacturers bring out the smart features that require constant data collection, monitoring (obviously in the name of service quality, troubleshooting, firmware / app updates and subscription of services (!!)), it is oblivious to the fact that security and privacy at a personal / state / national level is never considered (for various reasons such as the design, profit interests and overheads / compliance perspectives and what not!) to be part of the ecosystem. Bad actors with sufficient knowledge and tools could exploit and profit from it.
It has become more of a planned obsolescence / profit / greed based industrial / corporate culture in rolling out unwanted stuff / monitoring and controlling as a feature that gets exploited to the core.
Honesntly, I don't have an answer for that, but have some thoughts that I wanted to share.
I do not want a cleaning robot or a water purifier or a printer or a TV or a refrigerator or an oven or a smart light bulb or a smart lock or even my car to have undisclosed, unwarranted connectivity to internet for whatever reasons.
I do not care if it is the manufacture or the service provider or whomsoever it may be!
I want all of the network connectivity options to be explained with all the controlling options and boundaries and data collection that happens on any of the connected medium to be as much transparent with the option of preventing or restricting what one does not want to go out of the device.
Will anyone do that?
It ill never happen! Sadly!
This problem will balloon further without adequate controls and killing the networking at a ground level would only be the only solution!
But, in the case of a connected device having an inbuilt connectivity option (like the m2m based options) in a smart vehicle, even that is not possible!
Specific Domains:
Wildcard domains: Source: https://blog.includesecurity.com/2026/06/the-smart-tv-in-you...When it comes to involunary proxies, those are really just one of many possible symptoms stemming from a real problem: Shitty security. (Edit: And shitty contract/privacy laws.)
Shitty security is tolerated by our markets, is is protected from fixes due to copyright law, and it is even encouraged by parts of our government that want to exploit the flaws. We will gain far more from fundamental quality-improvements than we will from whack-a-mole-ing on this symptom.
Yes, yes, we should fight deceptive software that doesn't disclose it has a proxy function. Fine. But there's no way to square 1) fighting all residential proxies, including ones run with informed consent and 2) preserving the public's access to general-purpose compute at home.
I'd rather live with the proxies than for someone to tell me that if I run squid, I'm damaging national security.
Continuing to allow CGNAT is what allows the residential proxies to hide because it tumbles the IP identity of bad actors with normal people.