Multiple things can be true at the same time... do you think the seller doesn't want a closely surveilled world with no exits?
Besides, money keeps businesses in the economy afloat, it's an artificial good with (more or less) constant value. Money's a systematic means to an end and rarely an end goal, its purpose is the transportation of value, and not the communication of value.
It's hard to see how you wouldn't at least be okay with that outcome if you were actively making it happen. But maybe this is just explaining why I'll never have that much money.
I love this analogy. It’s hardly a crime to kick my lawnmower until it starts to come apart. Vandalism at best. If you want to entirely dehumanize these people, at least go all the way.
That was a reference to a Bryan Cantril speech, and it's more about the lawnmower's ability to gravely harm your person without having any intent or feeling beyond doing what a lawnmower does.
This is the drug-dealer justification -- "if I don't [sell drugs|provide mass surveillance at an unprecedented scale|crush these kittens] someone else will"
There are buyers who want drugs for recreational reasons, murders for emotional reasons, or spy cams on hotel rooms for business reasons. But those are simply 3 instances where existent demand doesn't mean we should be allowing any offer to exist.
I'd personally agree to put Flock-levels of civil vigilance in the same bag.
We need to climb two very difficult hills for there to be any change here: 1. We need our governments to actually start charging companies with crimes, when what they are doing would be illegal for an individual to do, and 2. We need the penalties to be something other than fines, which are ultimately treated by companies as routine costs of business.
> We need the penalties to be something other than fines, which are ultimately treated by companies as routine costs of business.
It's true that fines are nothing more than predictable costs, so maybe an option would be fines in percentage of the incoming of the company: this way it could make a real impact. I know in some north Europe countries the speed limit fines are in percentage on the personal net worth.
Bail only works while waiting for the court date. I was talking about the actual sentence if found guilty.
Going after individuals instead of fining the company is still a better deterrent. Corporate fines are paid by shareholders and customers, not by the people who made the decision.
As a side note: If we believe that well paid lawyers can win all cases, there is nothing to discuss under this thread anyway. No fine or sentence can save us.
Income is too small, how about in terms of the highest market capitalization between deciding to do the bad thing and being convicted of the bad thing? Maybe some of these penalties should result in bankruptcies for the most egregious big players, and when I say bankruptcies I don't mean restructuring but actual corporate financial death: firesale auction the assets, debt holders lose much of their value, equity holders get squat, and all employees are out on their asses having been let go. Do it to a Microsoft or Google sized company, scare the piss out of the rest! Then implement protection policies to make it impossible to move headquarters out of the country without having product prices end up 2-4x higher, so domestic competition (which could be let to run tax free) can come up and fill the void. Also tax the hectomillionaires+ more heavily on assets, income, and capital gains!
I think that the fines should be the amount per crime that is being fined, plus the total amount of all revenue from whatever the fines are related to (including indirect, but only counted once).
So step one is a constitutional amendment to ban corporate money in politics, which is going to be suuuper hard to accomplish.
But yeah similar to how humans are put in jail and it can easily ruin their life, the punishment for a severe crime needs to ruin a company’s life. It’s an absurd double standard.
Simplest thing to say is: find all the people responsible for this, from the bottom to the top, and charge them with the same crime as an individual would be. I would include everyone in the chain from the programmers that implemented it, to the VP that authorised it, and finally to the CEO because all responsibility ends with them (that's why they get paid the big bucks right?).
I'd like to say look at Volkswagen for an example but I don't know if all the necessary people were charged.
I don't blame VW because EPA's requirements were killing diesel cars in the US. There haven't been any new model diesel passenger cars in about ten years now.
Similar policy is why American trucks and SUVs are ridiculusly massive transformer-looking behemoths and there're really no 'small' trucks anymore. The Ford Ranger of today is of similar size to the Ford F-150 of 25 years ago.
Seriously. This was my first thought too, the audacity to implement a system like this and the deterioration of a society that seems to give any fucks about privacy where this will be a minor news story that gets some buzz then disappears fairly quickly... I don't know what the fuck has happened. At the very least something like this should result in devastating class action lawsuits towards LG.
Many don't though, and even if they all did, you can't hedge forever. Hedges are also rolling, so as some hedges expire the companies need to set up new hedges, which are at a worse FX rate. So the hedges lessen the impact but they aren't perfect, otherwise they would not be called 'hedges'.
Why not aggressively rate limit? Legitimate use of HTML rendered commits should be largely unaffected, and crawlers slowed to a halt. You can even jail after a number of 429's...
There is a section in the article answering your question if you read it.
> Suddenly, the crawlers were coming from millions of random residential or mobile IPs, all pretending to be random modern browsers. An IP like that would make 4-5 requests and then never show up in the logs again. There was no point in banning them, because by the time you figured out that they were bots, they were already done with you.
I’d love a service like spamcop.net where I could submit my access_log and they lookup the abuse addresses and file abuse reports in my name. Maybe if people’s Internet access gets suspended they’ll think about installing random apps that work as a proxy in the background.
That is a ridiculous way to try and deal with the problem of residential proxies.
You are, in reality, only hurting the actual owners, the subscribers of those ISPs who are behind those addresses. We call that "collateral damage".
If any of those actual residential users try to use a website, their ability to freely access the Internet may be harmed by a bad reputation that they do not deserve. They may be totally unaware and non-consenting to residential proxy use.
You are not, in fact, hurting the residential proxy-ers at all. Not one bit. They will move on to another IP and another compromised LAN, and they will continue to move on and on and on. They will not be harmed or impeded; they will simply keep turning up fresh, new, high-reputation IPv4 and IPv6 sources. This is a sheer numbers game, where the numbers are always in favor of the attackers.
Also if network admins keep blocking/filtering abusive residential proxies, they will balloon their firewall rules and cause actual performance issues at the network level. You will turn into your own DDOS without any actual benefit. You're on the losing side of the numbers game, and in the immortal words of W.O.P.R., "The Only Winning Move Is... Not to Play."
Similar to how people running an open SMTP are complicit in promoting spam, I see people running a wild public proxy as complicit in this malicious scraping activity.
And similar to how most people running mail daemons are using blackhole lists nowadays and are keen to not end up on there, maybe ISPs and web hosters can use the AbuseIPDB to sort out their customers.
Just doing nothing doesn't appear to stop the scans hammering my poor Raspberry Pi serving my few Git repositories.
Hey, from the beginning of SMTP, running an open relay was an administrative mistake. The MTA administrators were supposed to know what they were doing, because resources were allocated to them. They had privileges granted for the system and the network. It was right if they were blacklisted for misuse of those resources.
Now in 2026, running a "public proxy" doesn't take an administrator. You don't even need to be aware. Most victims are unknowing victims. They simply subscribe to an ISP and they have their own devices. They are being exploited for that innocence and ignorance. Most victims have no visibility to even detect that they're being used as a proxy. Most victims couldn't stop it, even if they wanted to.
I challenge anyone with a home router to list the processes running on that router, and list all current open connections on that router, and list all open, listening sockets on that router. I bet you can't do it. There are no consumer router OS that lend themselves to being secured, or even diagnosed. Malware can easily be planted on any of them and run, completely invisibly.
A residential proxy server could run on routers, could run on a switch, could run on your "Smart TV" or a smartphone, or a notebook computer. It could be anywhere in any form. Perhaps you consented to it, perhaps you didn't notice.
In no way is this the same as an SMTP open relay situation. If you wanna play "whack-a-mole" with a "blackhole list" you're simply going to overwhelm those lists with false positives and collateral damage. The residential proxies have long since moved on. You won't even find the culprits using those addresses you just blocked. You're just clogging up your own machines. It's a total self-own.
> You are, in reality, only hurting the actual owners
How many times do I have to hurt them before they decide to buy a different smart TV?
Seriously, that's like saying "if you try to stop your neighborhood rodent problem by getting citations sent to people with cat food on their porch, you're just hurting the innocent outdoor cat owners". They're participating, whether they know it or not. We can and should PSA and shame and regulate away residential proxies on the supplier side, but we can and should also simultaneously discourage them on the end-user side as well.
Well, nowadays the purpose of a TV is usually to watch content over the internet, so I wouldn't call it "stupid" to connect the TV to the internet.
You might say it's naive, but is it really naive to buy a TV and expect it to be a device to display audiovisual content and not a spyware/adware machine?
I feel like it's not the user's behavior that should be put into question here, but the borderline criminal behavior of the manufacturer.
Yeah... Original and clever, and a great read! But it seems mostly useful to the handful of people dealing with ELF internals, than to the vast majority of people executing ELF blissfully ignorant of its internals... Maybe if the latency and size trade-offs were the other way around it would be more appealing to the masses.
Worth the shout-out to the open source NetGuard app which allows you to block internet access for select apps without root, using Android's always-on VPN feature as a firewall. This is useful to prevent this and any other apps from talking to the network in a way external to the app itself.
Correct, but there are no better non-root alternatives as far as I know. Would love to be proved wrong. There are some workarounds to use NetGuard with a VPN based on a work profile or something, but I haven't personally tried them and cannot attest to them working.
reply