hn.today

How NOT to detect residential proxies

blog.truesign.ai21 points7 comments
Screenshot of How NOT to detect residential proxies

Explains how residential proxies work and why they’re hard to block: many consumer apps, browser extensions, cheap IoT devices and SDKs turn real home, office and mobile connections into proxy pools that attackers rent for large-scale crawling, credential stuffing and card testing. Datacenter IPs are often blocked, so residential/mobile IPs - now commodified at roughly $1.25/GB - are preferred. Legacy detection vendors scrape proxy services to build IP blacklists, but those IPs belong to real people (often shared behind CGNAT), so blunt per‑IP blocking causes collateral damage. Sites already lose customers by blocking anonymizers (reported 4-7% of traffic) and risk high false positives when using static IP databases.

Presents a different approach based on real‑time network analysis: classify TCP/IP conversation, timing and formatting patterns from a single HTTP request to tell whether traffic is proxied, then embed an encrypted anonymizer score (0, 7, 9) in a token and recommend blocking only score 9 to avoid false positives. Supplements network signals with agent fingerprinting and an invisible.js for advanced bot detection. Continuous monitoring links independent suspicious requests to coordinated attacks so defenders can allow legitimate anonymized users while blocking attack flows. A free trial lets operators inspect tokens and traffic before enforcing blocks.

Read on blog.truesign.ai7 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.