|
|
Log in / Subscribe / Register

Preventing this at the app store level is hard

Preventing this at the app store level is hard

Posted Jul 10, 2026 20:42 UTC (Fri) by roc (subscriber, #30627)
Parent article: An update on the scraper situation

> all of the major vendors are silent on the topic of why it is so easy to put apps with residential-proxy functionality into their app stores.

Google's rules already forbid non-user-authorized "residential proxies": https://support.google.com/googleplay/android-developer/a...
But if the user gives genuine consent to it, should they still be banned? That's a tough call.

Of course developers can and do violate those rules. Then the problem is that it's not really possible in general to detect that code is going to break those rules just by inspecting it. So how do you detect violations other than by people reporting them and then shutting them down after the fact? That's roughly what happens now and it's better than nothing, but still whack-a-mole.


to post comments

Preventing this at the app store level is hard

Posted Jul 10, 2026 22:29 UTC (Fri) by rgmoore (✭ supporter ✭, #75) [Link] (19 responses)

Google's rules already forbid non-user-authorized "residential proxies" But if the user gives genuine consent to it, should they still be banned? That's a tough call.

No, they shouldn't be allowed. Banning them is at least as much about protecting the whole internet from their pernicious effects as it is about protecting the individual user, so it shouldn't be up to the individual user any more than emissions controls should be up to the individual driver.

I would also argue that for any user to give "genuine consent", they would need to be given the option to have the same app without the proxy. If you let the author condition use of their app on accepting the proxy, consent is at least somewhat coerced.

Preventing this at the app store level is hard

Posted Jul 10, 2026 23:11 UTC (Fri) by Wol (subscriber, #4433) [Link]

> I would also argue that for any user to give "genuine consent", they would need to be given the option to have the same app without the proxy. If you let the author condition use of their app on accepting the proxy, consent is at least somewhat coerced.

And do they ask the VICTIM for consent? Of course not, they know consent would be refused.

Let's say I run a web server. The whole point of this scheme is bypass/dodge my attempts to prevent my site being DoS'd by scrapers. Whether it's criminal or not (in Europe it probably is), the whole point of this is to attack my server in a manner to which "you knew or should have known" I would have refused to consent to.

I find it hard to think of any use to which such a network would be put, that is not in violation of England's Computer Fraud And Abuse Act. Whether said act could be enforced is another matter :-( , but consenting to your computer being used for such things could also be criminal under the "going equipped to ..." rules ...

Cheers,
Wol

Preventing this at the app store level is hard

Posted Jul 11, 2026 5:28 UTC (Sat) by roc (subscriber, #30627) [Link] (14 responses)

The "I should be able to run whatever code I want on my device" people would surely object.

Preventing this at the app store level is hard

Posted Jul 12, 2026 10:29 UTC (Sun) by tux3 (subscriber, #101245) [Link] (6 responses)

I'm one of those people, but in the sense of supporting third-party package managers (à la F-Droid).

But then people will also "consent" to being scammed over the phone, because we often don't really understand what we're consenting to when the person asking for consent is also the attacker.
There's a parallel with Public Health as a medical field. If you allow that the general public of non-experts sometimes make bad choices for themselves and others, there's a balance in intervening without creating a system where people are stripped of all autonomy.
Sham doctors can't officially practice medicine or advertise snake-oil as a panacea. I'm sure you can still find them if you really look, they just can't be near anything official that could trick the average person into "consenting" with a scam.

So I'd let people install arbitrary things if they really go look for them, but I wouldn't let botnets advertise on the official app store.

Preventing this at the app store level is hard

Posted Jul 12, 2026 11:45 UTC (Sun) by mb (subscriber, #50428) [Link] (5 responses)

> there's a balance in intervening without creating a system where people are stripped of all autonomy.

Absolutely not.

Google has *no* business "intervening" with my actions whatsoever.
I am an adult and I can do decisions on my own.
I do not need Google to "take care of me" and install a 24 hour barrier so that I "won't hurt myself".

If I fall for a scam, then it is my own fault. I am an adult. I don't need mommy Google to take care of that.

This is obviously not about user's security.
Google has obviously been locking down their platform, step by step, over the last couple of years.
And they won't stop here.

Give me *one* button to opt out of this nonsense.
No nagging, no scare questions, no 24h delays, no nothing. Just a button "I'm grown up already, no need for mommy Google to protect me".

Preventing this at the app store level is hard

Posted Jul 12, 2026 12:06 UTC (Sun) by pizza (subscriber, #46) [Link] (4 responses)

> Google has *no* business "intervening" with my actions whatsoever.

You get to say that only *after* you've built (and maintain) your own smartphone platform from does not rely on any ongoing Google services or resources.

Preventing this at the app store level is hard

Posted Jul 12, 2026 12:21 UTC (Sun) by mb (subscriber, #50428) [Link] (3 responses)

>You get to say that only *after* ...

Obvious nonsense. Here's what gives me the right to do that at any time: https://www.gesetze-im-internet.de/gg/art_5.html

Android is not a free market product that I can choose to use or not to use.
Android (or iOS) use is mandatory for an increasing amount of daily tasks.

I *wish* I *could* drop Android and use something I built on my own or any other alternative product of my choice.
This is not possible in the real world we live in, though.
And that is why regulatory actions against Google are necessary to keep user's freedoms.

Preventing this at the app store level is hard

Posted Jul 12, 2026 13:26 UTC (Sun) by pizza (subscriber, #46) [Link] (2 responses)

> Obvious nonsense. Here's what gives me the right to do that at any time: https://www.gesetze-im-internet.de/gg/art_5.html

Uh, that appears to be solely about freedom of expression and learning [1]; which as far as I can tell you're fully exercising?

It says nothing about third parties being obligated to enable you to express yourself, much less require said third parties to build, maintain, and support systems that do what *you* want. Nor does it appear to have any bearing on markets or commerce in general.

Meanwhile, Google's device-restricting actions are backstopped by EU laws that make it expressly illegal to break DRM. Repealing that would achieve far more freedom (to both individuals and markets) than piling volumes of status-quo-entrenching regulations on top.

[1] while also making it clear that said freedoms are not absolute ("The freedom of doctrine does not absolve off from fidelity to the Constitution" according to Firefox's translation)

Preventing this at the app store level is hard

Posted Jul 12, 2026 13:43 UTC (Sun) by mb (subscriber, #50428) [Link] (1 responses)

>much less require said third parties to

Google is not a random third party in the market anymore.
Google is infrastructure at this point.

And as such Google must be criticized for their actions and regulated if they exploit their market position.

And yes, I can say this and you can do nothing about it. "You get to say that only *after*..." is completely false.
If you say that I can't criticize Google for their actions unless I build a system on my own you are completely wrong.
You are trying to move the goal posts.

>EU laws

Yes, there are many more things to criticize, beyond Google.

>Repealing that would achieve far more freedom

You know, I can be against multiple things at the same time.
There is no need to select and prioritize.

Preventing this at the app store level is hard

Posted Jul 13, 2026 11:29 UTC (Mon) by pizza (subscriber, #46) [Link]

> Google is infrastructure at this point.

....Then Google should be able to collect taxes to pay for said infrastructure.

You don't get to have it both ways.

> If you say that I can't criticize Google for their actions unless I build a system on my own you are completely wrong.

No, I'm saying that it is highly naive to expect Google to cater to *your* wants (not even "needs") while you freeload off of their services and rely on what their enormous engineering staff produces.

> There is no need to select and prioritize.

When you have (very) limited resources at your disposal, most folks want to put those to where they will be the most effective. But hey, you do you.

Preventing this at the app store level is hard

Posted Jul 13, 2026 16:56 UTC (Mon) by rgmoore (✭ supporter ✭, #75) [Link] (6 responses)

The "I should be able to run whatever code I want on my device" people are wrong. It's the same old saw about your right to swing your fist ending at my nose. Your right to run what you want on your device ends when it starts causing damage to other people's devices. If you want to run a proxy on your device, you are responsible for making sure it isn't DDOSing someone's web site. If you aren't willing or able to take that responsibility, don't run a proxy.

Preventing this at the app store level is hard

Posted Jul 13, 2026 18:24 UTC (Mon) by mb (subscriber, #50428) [Link] (3 responses)

Google has to stop playing Police and State.

If I punch you in the nose or if I DoS your server there already are more than enough processes in place to make me not do that and punish me if I do it anyway.
There is absolutely no need for restricting what I can run on my device. Except for Google establishing a locked down eco system, of course.

Preventing this at the app store level is hard

Posted Jul 14, 2026 7:56 UTC (Tue) by paulj (subscriber, #341) [Link]

+100 to this. Having vast technocratic-corporates act as police, judge and jury, with 0 transparency and (unless you complain on social media and somehow manage to go viral) 0 means of effective appeal is dystopian. Bollocks to that.

Preventing this at the app store level is hard

Posted Jul 20, 2026 1:54 UTC (Mon) by ssmith32 (subscriber, #72404) [Link] (1 responses)

Google, also, per your logic, can run whatever code they like on their servers, including code that rejects your code from their app store, which runs on their servers.

Google does not police or prevent you from running residential proxies on your phone. They prevent you from placing that code for download _on their servers_ .

Even the most ardent free software folks do not argue that you have a right to be platformed by any platform of your choice.. only to build your own platform.

Sideload your proxy onto your phone to your hearts content - google won't stop you.

Heck, run a whole other OS on the phone - google won't stop you there either.

You are, in fact, arguing that google be forced to run code on their servers at your whim.

Preventing this at the app store level is hard

Posted Jul 20, 2026 5:17 UTC (Mon) by mb (subscriber, #50428) [Link]

>Google, also, per your logic, can run whatever code they like on their servers

True

> Sideload [...] google won't stop you.

Except they do?

https://keepandroidopen.org/

Over the last couple of years they have been installing a massive amount of anti features to make sideloading harder and harder.
We are at the point where I cannot buy a phone and install what I want right away.
There is absolutely no sign that they will stop here.

Preventing this at the app store level is hard

Posted Jul 19, 2026 13:51 UTC (Sun) by Segora (subscriber, #8209) [Link] (1 responses)

The analogy is flawed in multiple ways:

1. Conflating capability with action: Just like most people would balk at the notion of restraining every human just because they _could_ hit somebody on the nose, it seems vastly imbalanced to constrain all their devices because they could be used to cause harm to others.

2. Locus of control: The brain controls whether the fist gets to travel towards someone else's nose. In the implied restriction system, a third party would determine the limits of capability of a device.

3. Misattributing the Source of Harm: Putting the blame on the tool rather than on how it's used discounts legitimate uses like development, security auditing and self-sovereignty.

As already covered in other comments, a more balanced approach would be to sanction the use of devices to cause harm, rather than their existence.

Preventing this at the app store level is hard

Posted Jul 20, 2026 12:01 UTC (Mon) by Wol (subscriber, #4433) [Link]

> 1. Conflating capability with action: Just like most people would balk at the notion of restraining every human just because they _could_ hit somebody on the nose, it seems vastly imbalanced to constrain all their devices because they could be used to cause harm to others.

What you are missing in this particular case, is that pretty much the SOLE use of these botnets is to cause harm to other people.

It is illegal in ?all? European jurisdictions to access a computer system in a manner that is not sanctioned by the owner of said system. Pretty much the only use of these botnets is to get round the attempts of said owners to block unwanted access.

In other words, I cannot think of any use of these botnets that is not illegal. Can you come up with any? Tools that have a high potential for mis-use often need to be licenced. These botnets should be licenced, and I strongly suspect there will be no use-cases that warrant the issuance of said licence.

Cheers,
Wol

Preventing this at the app store level is hard

Posted Jul 11, 2026 14:49 UTC (Sat) by ibukanov (subscriber, #3942) [Link] (2 responses)

What about offering a cheaper version in return for the user consent to allow to use their network?

I also wonder why does not BrightData not offer users just to run their software for money on devices? Maybe it will be the next step.

Preventing this at the app store level is hard

Posted Jul 11, 2026 20:12 UTC (Sat) by josh (subscriber, #17465) [Link]

> What about offering a cheaper version in return for the user consent to allow to use their network?

Nuke it from orbit. If app stores are doing any good at all, this is the kind of thing they should block.

Preventing this at the app store level is hard

Posted Jul 13, 2026 16:57 UTC (Mon) by rgmoore (✭ supporter ✭, #75) [Link]

I would say that allowing a cheaper version that includes the proxy could count as informed consent as long as the vendor was completely honest about what they were asking of customers running the proxy. But that still only counts the customer consent aspect; it doesn't deal with the pernicious uses of residential proxies. I still believe there are valid reasons for blocking any service, like these residential proxies, that causes massive damage to third parties who weren't give a say.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds