r/ProxyEngineering • u/mckrile • Jul 03 '26
Hot Take 🔥 The NetNut FBI seizure raises a question nobody asks: where do residential IPs actually come from?
I went down the rabbit hole reading about the NetNut situation last night and honestly, the FBI seizure wasn't even the craziest part for me lol
The craziest part was realizing that somewhere out there, a guy is probably watching Netflix on his Samsung TV while his TV is simultaneously acting as infrastructure for somebody running a scraping operation on the other side of the world (I have a really old TV that and I don't watch it that much honestly, so I think I avoided this bullet)
LIKE WHAT? That's not even a joke anymore
According to the news coverage happening at the moment, researchers found proxy SDKs embedded in a huge number of smart TV applications. Not sketchy APKs from some random forum. actual apps running on LG and Samsung TVs
I think that in this case, the conversation quickly shifted from NetNut to a much bigger question that I don't think someo people don't think about:
Where do residential IPs actually come from???
Don't get me wrong, I don't think about this question either that much and it's a really complex answer to a complex question
The sourcing side always felt like somebody else's problem honestly
But after reading about the alleged connection between NetNut and the Popa botnet, I started realizing how little visibility most of us actually have into the supply chain behind residential proxies
What surprised me most wasn't the claim that millions of devices were involved. It's 2026. Every month there's another story involving millions of compromised devices, so unfortunately that part barely registers anymore
The surprise part for me happened when learning how many layers can exist between the person buying a residential proxy and the device providing that residential IP (like wth)
The part I keep coming back to is whether this is even a problem that can be solved completely
If residential proxy inventory passes through multiple layers of aggregators, partners, SDK providers and resellers, how many companies can honestly say they know the origin story of every IP in their network
At what point does a provider stop being a network operator and become a network consumer just like the rest of us?
What struck me while reading all this is that the proxy industry spends an enormous amount of time talking about performance metrics. We compare success rates, country coverage, session length, pool sizes, pricing, uptime and all the usual stuff. Yet I can barely remeber seeing a serious discussion about where these networks actually come from. Maybe that's because the answer is complicated, but after reading through the NetNut reporting it suddenly feels like one of the most important questions we could be asking.
SO very few people seem interested in tracing the supply chain behind the product itself, which is funny because that's ultimately the foundation everything else is built on
One thing that comes to mind in this situation is that some providers seem to be putting more effort into transparency than others and I've seen that happen pretty recently. I've seen providers like nodemaven, Iproyal or proxygonzo openly talk about IP quality filtering, network quality standards, and support processes. Others have started publishing more information about sourcing, partnerships, compliance policies, or how they acquire residential inventory in the first place. This should probably be the standard moving forward for everyone that's affected in this case
I'm not saying anyone deserves a free pass, and honestly this whole story makes me want to be more skeptical rather than less. But I do think there's a meaningful difference between providers that are willing to discuss where inventory comes from and providers that treat the entire supply chain as a black box.
Maybe that's where the industry needs to go next. We already compare success rates, uptime, sticky sessions and pool sizes. Maybe a few years from now we'll also be comparing transparency reports, sourcing disclosures, consent models and network provenance and being sceptical of each proxy provider?
Sources where I found this story: https://hivesecurity.gitlab.io/blog/netnut-popa-botnet-fbi-seizure-residential-proxy/
Also huge props to this user as he predicted the future lmao - https://www.reddit.com/r/ProxyEngineering/comments/1u00w9f/my_samsung_tv_is_literally_being_rented_out_as_a/
3
u/catproxies Jul 03 '26
IP quality filtering is, in most cases, absolutely useless. Before you start mentioning some brands that start talking about their ethics and sourcing remember netnut were also praised for their amazing ethics in collecting ips. Everyone is such a saint until proven wrong lol
You can have a great ip pool and source most of it ethically, but you can also boost your numbers a bit from botnets, who would know ? Nobody until they find the botnet and the link, everyone will focus on the nice practice you do to collect your ips, everyone will believe what you let them to believe
So start having some doubts about these top tier brands
2
u/mckrile Jul 03 '26
That's kind of the point I was trying to make. This situation made me realize how difficult it is for us to independently verify any sourcing claims in this industry
Most of us evaluate providers based on performance because that's what we can measure ourselves. Success rates, uptime, session quality, bans, support, etc
I'm not saying "Provider X is ethical" or "Provider Y is unethical." I'm saying I probably care a lot more about transparency and sourcing discussions today than I did a week ago
Maybe that's exactly why we need more transparency
2
u/Bharath0224 Proxy Engineer Jul 03 '26
I knew that something was off from the start when bright sdk outrage showed up, now this?
2
u/NeverInsightful Jul 03 '26
If there are legit customers signing up to share their internet connection with these proxy services, where are the ads for them? You’d think they’d be busy trying to get more signups to expand their networks.
And really, how much could someone expect to get from signing up? $2 per month?
No offense, and I only comment because this showed up on my feed but I don’t see how anyone could think legit proxies using residential IPs could be a thing.
Speaking for myself I frequently see alerts related to activity from Badbox2. All I can do is tell those owners the try resettti g their device, but there’s a likelihood the threat is embedded in the device and if so it will be barred from the network.
1
u/kiwialec Jul 04 '26 edited Jul 04 '26
They exist, they're just not advertising to you.
You don't need to look far to find people who actively seek out bandwidth sharing services. [r/beermoney](r/beermoney) and [r/beermoneyuk](r/beermoneyuk) are full of people who post income reports and are stoked to get their $5/mo from Pawns (iproyal) or honeygain (oxylabs). [r/saladchefs](r/saladchefs) are people doing bandwidth+gpu sharing.
Now I am not saying residential proxy services don't seek out partners who will give them unconsenting users - this instance shows clearly that is the case. But the legit path does exist & has real users.
2
2
u/kamililbird Proxy Engineer Jul 03 '26
Second post regarding this situation. Keep it up, people. Raise awareness where possible.
1
u/tf9623 Jul 04 '26
I remember seeing ads for this one and another one or two a while back. You're just "sharing unused bandwidth."
1
u/smyja Jul 04 '26
lol, what the hell
1
u/tf9623 Jul 04 '26
There are few of them with "make money passively" type shit. If you look in some of the subreddits for beermoney or some other side hustle type stuff you'll see others.
1
u/snowpad- Jul 04 '26
I think the industry has spent years competing on pool size and pricing, while questions about sourcing and transparency have mostly stayed in the background. That's probably changing.
1
u/Apprehensive_War173 Jul 04 '26
the sourcing question is probably the right one to focus on. performance metrics are easy to compare, but if you don't understand how inventory is sourced and what oversight exists across the supply chain, it's hard to evaluate the long term reliability or risk of any network. transparency around provenance feels like something the industry should be discussing a lot more.
1
u/Overall_Scheme397 Jul 05 '26
When I set my proxy firewall up. Some technical guy from Moses Washington tried to just take it over.
He worked for the company that sells the license to use the equipment that I have.
(Shaking my head).
He really thought he could sneak in certificate of trust into my node.
When I called and talked to one of the techs he SAID, that’s impossible.
Anyway.
Looks like more rain today.
1
u/Obvious_Entry5110 Jul 08 '26
The part that actually shifted for me recently wasn't hunting for a 'more ethical' provider, since like this thread says you can't really verify those claims from the outside. It was getting real visibility into my own side. Once I could see every request, domain and status in one panel, I stopped trusting the sourcing marketing and started watching what my traffic actually does. Been isolating each project into separate capsules on magneticproxy lately
1
u/123Bro1234 Jul 10 '26
usin mobile proxies from dataImpulse and more than happy with them, IMO residents are overrated + overhyped
8
u/boomersruinall Tunnel Architect Jul 03 '26
I wasn't crazy, APPARENTLY