upvote
> Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)

Does having TLS everywhere make this much harder?

reply
Not sure how it would? Because the bad actors are remotely instructing infected computers/devices to make HTTP/TLS requests for them, so they appear totally normal to the other side.
reply
In a hypothetical world where using TLS was abnormal, you could monitor the content of whatever the bots are doing for suspicious activity. And if they chose to use TLS anyway, the mere presence of of TLS could be considered suspicious.

Back in the real world, you can also passively fingerprint TLS handshakes to characterise the client device. Most of these proxy networks masquerade as "normal" clients, but if the type and variety of device fingerprints for an IP suddenly changes, that's a signal too.

reply
Until DoH and ECH are commonplace, DNS lookups and SNI probably leak enough for statistical analysis.
reply
I'm glad someone else is saying this. Entire companies exist (that do a great job at it) that primarily surface this information in the form of "threat intelligence" for companies to make risk decisions based off of.
reply
> Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)

Is there incentive for them to? If anything, you might be paying extra for the data use and not even know it, right? They would lose money

reply
It may actually be costing them money through higher peak usage (requiring more capacity). I'm not sure but either way the government should have a role if market incentives aren't sufficient.
reply
A crackdown would probably be an FBI responsibility, the NSA is not a law enforcement agency and absolutely does not have the authority.
reply
In terms of law enforcement, sure. But what we really need is competent white hat hackers doing battle with the black hats.

Even if no one goes to jail, the NSA could make residential proxies much harder to operate in the US simply by detecting them and reporting them to ISPs. It would be good for ISPs to then validate the reports properly, give warnings, etc.

reply
My major sources of spam traffic are Chinese and Indian residential and mobile IP blocks. So there's that.

Second, everybody screamed loudly when they were cracking down on file sharing traffic. You're saying spying on the citizens is ok when it's for this little reason over here, but not this one over there. It doesn't track.

Not to mention most ISP abuse mailboxes are automated these days because they are flooded with LLM-generated reports from "security" grifters.

The tech industry flooding the market with countless IoS (Internet of Shit) devices didn't help. This has moved way beyond accidentally installing spyware on your PC. People are intentionally bugging their homes with these devices.

I understand the FCC is trying to crack down on this stuff - starting with routers - but of course that gets pushback too. You can't win.

reply
There's no spying required. The NSA and ISPs can find open proxies through infiltration and report them to (e.g. abuse@comcast.com), then Comcast simply has to act on it robustly.

ISPs already deal with abuse reports like this, the system just isn't being operated comptently.

reply
What is Comcast going to do about it? Shut off a paying customer? Not likely.
reply
What are you talking about? These are not open proxies.

You actually think the actors that went to the trouble to surreptitiously set this infrastructure up are going to share it with everyone for free?

They are intentionally made hard to detect and access is sold to the highest bidder.

Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.

reply
> These are not open proxies.

Okay, I was being imprecise. These residential proxies aren't "open proxies" in the traditional sense, but they're usually "open" to anyone willing to pay a small amount of money to use them.

> Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.

This is where regulation might play a role, or at least a change in attitude. Companies shouldn't be allowed to pollute the internet in this way when they can easily prevent it.

reply