Show HN: Check if your IP has appeared in a residential proxy network

haveibeenproxied.com

69 points by microcode a day ago


negura - 7 hours ago

How exactly do they obtain this data? Residential proxy providers don't publish their IP list (you connect to one of their servers which then tunnels your traffic to the residential exit point). Plus there are tons of such providers.

In any case, residential proxies are a godsend. Because most of the everyday services like web shops, govt information portals, even personal blogs sometimes are blocking access usings captchas.

EDIT: they write this on their marketing copy [0]:

> The Spur platform identifies traffic originating from residential proxy networks by analyzing service fingerprints, ASN ownership, and behavioral indicators.

Sounds like guesswork that results in a ton of false positives. And the more innocent IPs are blocked by platforms on the basis of this data, the more the demand increases for residential proxies, from users who need access to essential services. Talk of creating the problem and then selling the "solution".

[0] https://spur.us/platform/residential-proxy-detection

reincoder - 3 hours ago

I work for IPinfo. We offer a residential proxy detection service, which you can check at ipinfo.io/my.

We had a previous discussion about surfacing visitor IP address resproxy status explicitly. Should we have some sort of badge or a more explicit alert to show if a site visitor's IP address is part of a residential proxy network?

Even though it is great for demonstrating the product's value, it is kind of a low-tier value. What can a user actually do when they realize their IP address is part of a residential proxy pool?

The first issue is that residential proxy SDK infiltration is massive. If you start connecting to different IP addresses and constantly check your IP address on our website, you will often see that many of those IP addresses were, at some point, part of a residential proxy pool. We provide frequency information showing how many times an IP address was observed in a residential proxy pool, with a default observation period of 7 days.

Then there is the question of what a user can actually do about it. If it is a controlled IT environment with paranoid IT admins, sure, they can actively monitor traffic and identify why their IPs are showing up in residential proxy pools. They can attempt to do something about it. But it is not easy even then.

Residential proxy SDKs can simply be baked into almost any smartphone or smartphone-derived OS that allows app installation through marketplaces. So, many residential networks are already cooked (because of android TVs). Moderate-scale NAT connections almost always see residential proxy flags, as do public Wi-Fi hotspot IPs, which we also detect.

Identifying the apps that are generating background network traffic is quite hard. You need some level of DNS monitoring or a network sniffer. Alternatively, you need router-level firewall software.

These SDKs are not always sending high-volume, constant traffic that makes them easy to detect. If you see a 100% residential proxy flag for your IP address, then they probably are. But in many cases, the traffic is intermittent and much harder to identify.

Nobody has an answer to what I should do when I see my IP address in a residential proxy pool. It has been accepted in spirit as a "consented malware" for the last few years. It is undetectable and extremely hard to remove because the SDK has been baked into apps themselves.

rckoepke - 19 hours ago

In my testing, Synthient's tool[0] and offerings have performed very well for this kind of service. Synthient have also achieved impressive proven success against malicious botnets[1].

0: https://synthient.com/context/ip/

1: https://www.wsj.com/tech/kimwolf-hack-residential-proxy-netw... / https://archive.ph/SpKVn

koutakun - 15 hours ago

Would be great if it told me how recently it was detected. I have a dynamic IP from my ISP and it could very well be someone else's device 3 days or 3 months ago.

jasonvorhe - 18 hours ago

This would probably false positive every CGNAT IP, or am I misunderstanding something?

babooka - 14 hours ago

this company Spur recently got millions in funding and their pricing seems to be directed at large companies. Who's buying these absolutely non-actionable IP databases? Do corporate buyers not understand you can't just block someone because they share the IP with someone else who downloaded a dodgy app?

hollow-moe - 14 hours ago

My public IP is shared with some 150 people in a student dorm, and the result is negative which I find very unlikely.

imalexandru - an hour ago

what if i have an always rotating ip?

- 20 hours ago
[deleted]
varispeed - 19 hours ago

I am on mobile network and it fails to consider this as a factor that other people who might receive this IP could be having a proxy.

ranger_danger - 18 hours ago

Keep in mind these databases can be wildly inaccurate and basically impossible to prove them wrong (you can't prove a negative).

I've seen this (and verified with others) with other sites like iknowwhatyoudownload.com where they allege your connection downloaded something very illegal (like CSAM) even though you know for certain it never happened and you haven't been hacked.

xyst - 19 hours ago

Seems it only detects ipv4. Any plan to support scanning ipv6 /56 range?

stogot - 19 hours ago

It says I was observed on a couple areas, but not sure what to do with that information. It would be great if thi tool provided links to guides to discover more.

toomuchtodo - 21 hours ago

Needs an API to query other IPs beyond one's own.

hansufati - 13 hours ago

wow my comment with a blog post about a better approach to detect residential proxies got... removed! Not sure about HN internals, do moderators do that or is this OP using several accounts to downvote contrarian comments?

TZubiri - 18 hours ago

very nice.

Can we use it in other IPs? (without having to issue the request from that IP)

lpellegr - 3 hours ago

[dead]

aitoolsprimer - 16 hours ago

[flagged]

pimlottc - 12 hours ago

[dead]

hansufati - 14 hours ago

[dead]