Dan Pinto is CEO and co-founder of Fingerprint. With over a decade in tech, he is an entrepreneur behind many startups.
Detecting fraud requires monitoring all sorts of signals across behavioral biometrics, device intelligence and network data. There was a time when VPN usage was a notable signal, but nowadays, people tend to shrug off VPNs because “everyone uses VPNs.” It’s not that simple. Not only are there different types of VPNs for different scenarios, but there’s also another tool that can mask your IP address. Although it has some legitimate uses, it’s increasingly linked to fraud.
I’m talking about the residential proxy.
Residential proxies route traffic through real devices, like smart TVs or routers, to appear legitimate. Millions of users have unknowingly become proxy nodes after installing free VPNs or dubious browser extensions, allowing attackers to create fake accounts, scrape data at scale and commit promo and payment fraud. The use of residential proxies is a growing problem in the fraud prevention space, and it’s time to sound the alarm.
Your Geofencing Is Obsolete
When Google disrupted the world’s largest residential proxy network, IPIDEA, earlier this year, over 550 individual threat groups were using its exit nodes, including groups from China, North Korea, Iran and Russia. Although this was a headline-grabbing story, state actors aren’t the only attackers using this tech.
Say your company requires its users to log in with not just a username and a password but a two-factor authentication (2FA) code as well. Because the 2FA code is a hassle, it makes users less likely to log in. To reduce login abandonment, your company has likely added a rule that says if a user’s geolocation matches their historical geolocation, they don’t need the 2FA code. Skipping the 2FA code because fraudsters can’t fake their IP address seems like a reasonable solution. Unfortunately, residential proxies let fraudsters fake just that, giving them access to the same high-speed lane as legitimate users.
If somebody gets a leaked dark web username-password list that also includes IP addresses, they can do a geo lookup on the IP address and use a residential proxy to switch to the same location. This applies to every company, from your identity and access management platform to your retailer to your bank.
The FBI recently released a warning that covered a number of scenarios in which criminals use residential proxies to their benefit, including bypassing purchase restrictions and taking over accounts.
In short, the geolocation-based login rules that every IT department uses across company systems are now essentially useless.
VPNs Versus Residential Proxies
Before, an IP address showing you accessing work from Dayton, Ohio, wasn’t very helpful to an attacker trying to get into your account. When VPNs first became available, they didn’t let you specify a new location. The tools simply assigned you a random location in your country or nearby. Later, VPN releases would let you pick, but only from a list of major cities. For example, if the VPN provider doesn’t have a data center in Dayton, Ohio, they can’t route traffic through it, meaning you can’t get to the level of resolution that could bypass a 2FA rule.
Now, there are residential proxy nodes in Dayton, Ohio. They allow you to reach much lower resolution, meaning much closer geographical accuracy compared to historical providers. Although some niche VPNs may let you leverage some local data centers, VPNs generally can’t get to the same level of precise, small-city granularity as a residential proxy can. In short, if your company has a 2FA exception based on city matching, attackers can use a residential proxy service or network to set their location as Dayton, Ohio, and log into your account without triggering additional verification checks.
Residential proxies make a fraudster’s IP address look like a random household IP address anywhere in the world. Understanding how many times that residential IP was used in different services can be difficult because a single residential IP address assigned to a time zone in Des Moines, Iowa, can be used by browsers from time zones all over the globe. What looks like a clean IP address in Iowa could, in fact, be hiding plenty of fraudulent activity.
It’s not easy, but it’s possible to detect when traffic is going through a residential proxy. Companies can leverage multiple techniques: They can check whether the network time zone differs from the computer time zone, the speed-of-light timing of network requests and whether any information is leaking. For example, a WebRTC request may not go through the residential proxy, but an HTTP request could. Detecting these proxies means expanding from the IP header into signal intelligence.
If you add up all the right signals in the right combination, you can figure out with a high probability if a user’s traffic is going through a residential proxy. That’s crucial for anyone trying to verify a user’s login or to detect bots, fake accounts or other types of fraud.
Moving From Static Rules To Device-Level Signals
Every financial institution, SaaS provider and IT department creates strict rules for all the login systems they manage. Residential proxies are just one example of why this rules approach is dated and insecure.
If you want to mitigate security headaches, move away from static IP-based rules and toward a device intelligence approach that focuses on signals like suspicious browser anomalies and virtual machine detection. Device intelligence companies can adapt their signals to detect new evasion techniques far faster than you can adjust your login rules. This lets you focus on your business without wondering if you’re doing everything you can to balance security and convenience for your users.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


