GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Jan Wildeboer 😷:krulorange: (jwildeboer@social.wildeboer.net)'s status on Friday, 18-Apr-2025 23:13:17 JST Jan Wildeboer 😷:krulorange: Jan Wildeboer 😷:krulorange:

    The web is broken, IMHO

    So there is a (IMHO) shady market out there that gives app developers on iOS, Android, MacOS and Windows money for including a library that sells users network bandwidth. Infatica [1] is just one example, there are many more.

    I am 99% sure that these companies cause what effectively are DDoS attacks that many webmasters have to deal with since months. This business model should simply not exist. Apple, Microsoft and Google should act.

    1/5

    [1] https://infatica.io/sdk-monetization/

    In conversation about a month ago from social.wildeboer.net permalink

    Attachments


    1. https://cdn.masto.host/socialwildeboernet/media_attachments/files/114/358/981/878/799/686/original/cc68dc3dc8616a99.png
    2. Domain not in remote thumbnail source whitelist: infatica.io
      Infatica SDK: Monetize Extensions, Mobile and Desktop Apps & Games | Infatica
      from admin
      Monetize your mobile and desktop software and Chrome extensions without ads and complex methods. Simply join Infatica SDK to increase your income.
    • Phantasm and pistolero like this.
    • Ryan Castellucci :nonbinary_flag: repeated this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Friday, 18-Apr-2025 23:13:15 JST Rich Felker Rich Felker
      in reply to

      @jwildeboer Gonna be really fun when someone buys access to this botnet anonymously with stolen credit cards and uses it to post CSAM all over the place from the IP addresses of all the devices running this malware...

      In conversation about a month ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 21-Apr-2025 04:00:10 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      @jwildeboer I am going to build the tech to destroy this business model.

      In conversation about a month ago permalink
    • Embed this notice
      Jan Wildeboer 😷:krulorange: (jwildeboer@social.wildeboer.net)'s status on Monday, 21-Apr-2025 04:00:18 JST Jan Wildeboer 😷:krulorange: Jan Wildeboer 😷:krulorange:
      in reply to

      What these companies then sell to *their* customers is network access through the devices/PCs that have an app with this SDK installed. They are proud to tell you how you can funnel your (AI) web scraping etc through millions of rotating, residential and mobile IP addresses. Exactly the pattern we see hitting our servers.

      https://infatica.io/pricing/

      2/8

      In conversation about a month ago permalink

      Attachments


      1. https://cdn.masto.host/socialwildeboernet/media_attachments/files/114/358/990/769/474/526/original/39d61076ab83ff4c.png

      2. https://cdn.masto.host/socialwildeboernet/media_attachments/files/114/358/990/775/460/491/original/b275737a75824145.png
    • Embed this notice
      Jan Wildeboer 😷:krulorange: (jwildeboer@social.wildeboer.net)'s status on Monday, 21-Apr-2025 04:00:41 JST Jan Wildeboer 😷:krulorange: Jan Wildeboer 😷:krulorange:
      in reply to

      Addendum: Trend Micro did some research on these companies back in 2023 and it confirms my suspicions. And I guess with AI scraping this kind of business is booming. For the paranoid:

      „There are malicious actors who repacked freeware and shareware written by other people to conduct drive-by downloads of the Infatica peer-to-business (P2B) service“

      https://www.trendmicro.com/vinfo/ae/security/news/vulnerabilities-and-exploits/a-closer-exploration-of-residential-proxies-and-captcha-breaking-services

      6/8

      In conversation about a month ago permalink

      Attachments


      1. https://cdn.masto.host/socialwildeboernet/media_attachments/files/114/360/220/833/046/193/original/5310f130924d8a19.jpeg

      2. https://cdn.masto.host/socialwildeboernet/media_attachments/files/114/360/223/430/244/990/original/f72e385c2a718cf2.jpeg
      Ryan Castellucci :nonbinary_flag: repeated this.
    • Embed this notice
      Jan Wildeboer 😷:krulorange: (jwildeboer@social.wildeboer.net)'s status on Monday, 21-Apr-2025 04:00:43 JST Jan Wildeboer 😷:krulorange: Jan Wildeboer 😷:krulorange:
      in reply to

      I already blogged about this at https://jan.wildeboer.net/2025/02/Blocking-Stealthy-Botnets/

      I might rewrite that blog post to make the problem clearer. And to explain why I am now of the opinion that *every* form of web-scraping should be considered abusive. If you think your web-scraping is acceptable behaviour, you can thank these shady companies and the "AI" hype for moving you to the bad corner.

      TL;DR certain companies recruit app developers to create botnets. Botnets are malware. Period.

      The web is broken, IMHO.

      5/8

      In conversation about a month ago permalink

      Attachments



      Ryan Castellucci :nonbinary_flag: repeated this.
    • Embed this notice
      Jan Wildeboer 😷:krulorange: (jwildeboer@social.wildeboer.net)'s status on Monday, 21-Apr-2025 04:00:45 JST Jan Wildeboer 😷:krulorange: Jan Wildeboer 😷:krulorange:
      in reply to

      But this explains the explosion of bot traffic that really cripples a lot of smaller services (like my forgejo instance, that I had to make non-public).

      So if you include such an SDK in your app to make some money — you are part of the problem and I think you should be punished for that. You are delivering malware to your users, making them botnet members.

      Unfortunately it is next to impossible for normal users to detect the inclusion of such shady SDKs and the network traffic they cause.

      4/8

      In conversation about a month ago permalink
    • Embed this notice
      Jan Wildeboer 😷:krulorange: (jwildeboer@social.wildeboer.net)'s status on Monday, 21-Apr-2025 04:00:46 JST Jan Wildeboer 😷:krulorange: Jan Wildeboer 😷:krulorange:
      in reply to

      Now, again, this company is just one of many selling similar services. And they all promise that they carefully check what commands their customers send to the (IMHO) infected apps on your phone and PC. Yeah, I am sure they "do no evil". And when they do, they can claim it's not their problem because they are merely the proxy. Again, IMHO, a shady business model.

      3/8

      In conversation about a month ago permalink
    • Embed this notice
      Jan Wildeboer 😷:krulorange: (jwildeboer@social.wildeboer.net)'s status on Monday, 21-Apr-2025 04:00:50 JST Jan Wildeboer 😷:krulorange: Jan Wildeboer 😷:krulorange:
      in reply to

      Addendum 2: If you want to feel really dirty, go to https://proxyway.com/reviews?e-filter-da2a7bc-reviews_categories=proxy-providers for a collection of reviews on these services. It's a huge market and I am 100% convinced that "AI" web scraping is currently the biggest "growth" driver for these companies.

      And when I see that quite some of them rely on injecting SDKs into 3rd party apps to "extend" their "Reach", I would call these "residential proxy providers" malware/botnets. But that's just my personal opinion. I am sure they are all legit.

      7/8

      In conversation about a month ago permalink

      Attachments


      1. https://cdn.masto.host/socialwildeboernet/media_attachments/files/114/360/412/655/011/095/original/b4b1c5d8fd67cc8e.png

      2. https://cdn.masto.host/socialwildeboernet/media_attachments/files/114/360/413/245/335/026/original/8e77c6a89984f020.png

      3. https://cdn.masto.host/socialwildeboernet/media_attachments/files/114/360/432/124/287/893/original/b3dcd34be2eca241.png

    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 21-Apr-2025 17:36:31 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Xdej

      @xdej @jwildeboer real time proxy detection

      In conversation about a month ago permalink
    • Embed this notice
      Xdej (xdej@mamot.fr)'s status on Monday, 21-Apr-2025 17:36:32 JST Xdej Xdej
      in reply to
      • Ryan Castellucci :nonbinary_flag:

      @ryanc
      Fake the library to take the cash without making the requests?
      @jwildeboer

      In conversation about a month ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.