A researcher has discovered that an SDK embedded in free mobile and smart TV apps by Bright Data allows the company to use consumer devices as residential proxies. These devices relay web-scraping traffic, which is highly valued by the AI industry because it bypasses anti-bot defenses designed to block datacenter IPs. The research highlights how these connections can persist in the background, sometimes even bypassing VPNs on iOS devices.
Key points:
- Bright Data SDK turns consumer electronics into web-scraping exit nodes.
- Residential IP addresses are preferred by AI companies for data harvesting.
- Technical findings show a lack of authentication and potential bypasses of standard security tools/VPNs.
- Opt-in screens may underrepresent the actual bandwidth usage (up to 200GB per month).
- Mitigation involves blocking specific Bright Data domains at the router level using Pi-hole or NextDNS.
Jason Donenfeld, the creator of the popular open-source WireGuard VPN software, has been locked out of his Microsoft developer account. This unexpected suspension prevents him from signing drivers and shipping critical software updates to Windows users. The issue stems from a mandatory account verification process within Microsoft's Windows Hardware Program, which has suspended accounts that failed to complete verification by a specific deadline, often without prior notification to the developers. This situation mirrors recent troubles faced by other prominent open-source projects like VeraCrypt and Windscribe, highlighting a growing tension between Microsoft's security verification requirements and the operational needs of independent software maintainers.
This article details how to set up and configure a Wireguard VPN server on OpenBSD, Amazon Linux, and Debian, along with instructions for configuring a GL.iNet travel router to connect to it.