Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Rotate through several thousand to several hundred thousand noncontiguous, geographically distributed, residential IP addresses

How are they getting residential IP addresses, compromised PCs?




Other commenters have basically answered already, but to be clear Luminati is not the only provider, just the most infamous. It’s very easy to find others of greater or lesser reliability. Search “residential IPs proxy” and you’ll find many vendors.

But yes, the whole cottage industry is sketchy. Almost all providers are leasing users’ computer with outright malware or shady TOS. The savvy play is to release a free game, app or even SDK which will then opportunistically route requests from the control server through the user’s device.

Recaptcha solving APIs are frequently bundled with the more reliable and premium services of this kind. They introduce a lot of latency since there’s a real mechanical turk across the world solving it for you, but they basically work.



How the hell do they get people to open up their home computer to be used this way?


They encourage developers to include their SDK:

> Monetize your mobile app or game with our SDK, without showing intrusive ads or requiring annoying subscriptions and in app purchases.

https://luminati.io/sdk

They approached nmap of all people:

> Hi,

> My name is Lior and I'd like to offer you a new way to make money off your software. The Luminati SDK provides your users the option to use your software for free by contributing to the Luminati proxy network.

> We will pay you $3,000 USD a month for every 100K daily active users.

> No collection of users' data, no disruption of user experience.

> I'd like to schedule a 15 minute call to let you know how we can start. Are you available tomorrow at 12:30pm your local time?

> Best regards,

> Lior

https://seclists.org/nmap-dev/2018/q1/27


$3000 USD for 100k users? If you can get five pennies from each you're better off than with this crap.


The equation changes if you actually care about your users' experience. Or if you don't and include both Luminati and ads.


It's pretty hard to get five pennies from each of your users


Users of free mobile apps (mostly games) are offered the option of allowing use of their devices as proxies as an alternative to being interrupted by ads.

https://luminati.io/faq


Excellent, a new botnet to exploit. ;)


They pay developers to include the Luminati "SDK" (their euphemism for malware) in popular apps.


Sounds like the answer is to increase the response size for failed login requests. At $12.5/G, if you blow up your response to a mega byte, they'll spend about a cent per try - close to the rate they'll need to pay to have recaptchas solved by humans.


Most criminals are not using services like Luminati - they are using actual botnets made up of compromised computers. In that case, their bandwidth costs are far cheaper than yours.


Then can't they run-out-of-money DDoS you fairly easily? Since you'd pay for the outgoing bandwidth and at Google Cloud and AWS that's expensive.


I don't know how expensive it is with Google/AWS, but I'm paying about $1.50 per TB at my non-cloud-host (vs their $12500/TB), so if it comes down to it, they need to outspend me by multiple magnitudes. Sucks, but still cheaper than losing customers due to hyper-annoying Recaptchas, and I doubt that somebody is willing to stomach $12500 cost to make me suffer $1.50 ... I'm sure there would be more efficient attacks ;)




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: