×
Inside Rivian’s big bet on AI-powered self-driving | TechCrunch

Inside Rivian’s big bet on AI-powered self-driving | TechCrunch

The robot swerved through the cafeteria of Rivian’s Palo Alto office, shelves adorned with chilled canned coffees — until it didn’t. Five minutes later, a man carefully pushed it out of everyone’s way, the words “I’m stuck” flashing yellow on the poor droid’s screen.

It was an inauspicious start to Rivian’s “Autonomy & AI Day,” a showcase for the company’s plans to make its vehicles capable of driving themselves. Rivian doesn’t make the cafeteria robot and isn’t responsible for its abilities, but there was a familiar message in its foibles: this stuff is hard.

Hours later, as I rode in a 2025 R1S SUV during my 15-minute demo of Rivian’s new self-described “Large Driving Model,” I was reminded of that message.

The EV equipped with the automated-driving software drove myself and two Rivian employees on a switchback route near the company’s campus. As we glided past Tesla’s engineering office, I noticed a Model S in front of us slow to turn into the rival company’s lot. The R1S eventually noticed this, too, braking hard just before the Rivian employee nearly intervened.

During my demo drive, there was one actual disengagement. The employee in the driver’s seat took over as we passed through a one-lane section of road due to some tree-trimming. Minor stuff overall. But it wasn’t exactly rare either; I spotted multiple other demo rides that had disengagements, too.

The rest of the drive went well enough for software that is not ready to be shipped, especially when you consider that Rivian threw out its old rules-based driver assistance system and adopted an end-to-end approach — which is how Tesla developed Full Self-Driving (Supervised). It stopped at stoplights, it handled turns, it slowed for speed bumps, all without programmed rules telling it to do these things.

A quiet pivot in 2021

Image Credits:Rivian

Rivian’s old system “was all very deterministic, and it was all very structured,” CEO RJ Scaringe said in an interview Thursday. “Everything that the vehicle did was the result of a prescribed control strategy written by humans.”

Techcrunch event

San Francisco
|
October 13-15, 2026

Scaringe said that when Rivian saw transformer-based artificial intelligence taking off in 2021, he quietly “reconstituted the team and started with a clean sheet and said, let’s design our self-driving platform for an AI-centric world.”

After spending “a lot of time in the basement,” Rivian launched the new ground-up driving software in 2024 on its second-generation R1 vehicles, which use Nvidia’s Orin processors.

Scaringe said it was only recently that his company started to see dramatic progress “once the data started really pouring in.”

Rivian is betting it can train its Large Driving Model (LDM) on fleet data so quickly that it will allow the company to roll out what it calls “Universal Hands-Free” later this month. That means Rivian owners will be able to take their hands off the wheel on 3.5 million miles of roads in the U.S. and Canada (so long as there are visible painted lines). In the back half of 2026, Rivian will allow “point-to-point” driving, or the consumer version of the demo we received Thursday.

The ‘eyes off’ to ‘hands off’ challenge

By the end of 2026, after Rivian has started shipping its smaller, more affordable R2 SUVs, it will ditch the Nvidia chips and outfit those vehicles with a new custom autonomy computer unveiled Thursday. That computer, plus a lidar sensor, will eventually allow drivers to take their hands and eyes off the road. True autonomy — where a driver doesn’t have to worry about re-taking control of the vehicle — lies well beyond that and will largely depend on how fast Rivian can train its LDM.

This rollout introduces a near-term challenge for Rivian. The new autonomy computer and lidar won’t be ready until months after the R2 goes on sale. If customers want a vehicle that can handle eyes-off driving (or more), they’ll have to wait. But the R2 is a crucial product for Rivian, and the company needs it to sell well — especially in the wake of declining sales of its first-generation vehicles.

“When tech is moving as fast as it is, there’s always going to be some level of obsolescence, and so what we want to do here is to be really direct” about what’s coming, Scaringe said. The early R2s will still get Rivian’s promised “point-to-point” driving, which will be based on the new software and will be hands-off but not eyes-off.

“So [if] you’re buying an R2 and you buy it in the first nine months, it’s just going to be more constrained,” he said. “I think what will happen is some customers will say ‘that matters a lot to me, and I’m going to wait.’ And some will say ‘I want the newest, best things now, and I’m going to get the R2 now, and maybe I’ll trade it in a year or two, and I’ll get the next version later. Fortunately, there’s so much demand backlog for R2 that we think, by being upfront with this, customers can make the decision themselves.”

“In a perfect world, everything times at the same time, but the timeline of the vehicle and the timeline of the autonomy platform are just not perfectly aligned,” he said.

When I first interviewed Scaringe in 2018, before Rivian even showed what its vehicles looked like, he shared a goal that still rattles around my head. He wanted to make Rivian’s vehicles so capable of driving themselves that: “if you go for a hike, and you start at one point and you finish at another point, you have the vehicle meet you at the end of the trail.”

It was the kind of pie-in-the-sky promise about self-driving cars that was all the rage seven years ago, but it stuck with me at least because it was something that felt true to Rivian’s whole brand of aspirational adventure.

Scaringe told me Thursday he still thinks it’s possible for Rivian to enable a use case like that in the next few years. It certainly won’t happen until the company tests and builds its more-capable R2 vehicles, which is at least a year away in a best-case scenario.

“We could [do that]. It’s not been a huge focus,” he said. That could change as the company gets closer to level 4 autonomy, though, since by then the company will have its LDM trained on trickier roads without guiding features like lane lines.

“Then, it becomes a bit of a like, what’s the ODD [operational design domain]? Dirt roads, off road? Easy,” he said. Just don’t expect a Rivian driving itself up Hell’s Gate in Moab.

“We’re not putting any resources into rock crawling autonomously,” he said. “But in terms of getting to the trail head? For sure.”

This story has been updated to reflect that Rivian’s Universal Hands-Free update is coming later this month.

Source link
#Riviansbig #bet #AIpowered #selfdriving #TechCrunch

Microsoft’s remote meeting software will lose major functionality on mobile soon if you don’t update your app.

In a support note on its website (via TechRadar), Microsoft said that people who use the iOS or Android apps for Microsoft Teams need to update to the latest version of the app by the beginning of October. Users who fail to do that will lose access to the app’s Calendar functionality, which would obviously be a big hindrance to anyone trying to keep track of when their meetings are supposed to happen.

We asked you to predict what Apple will do next. See the results and find out how to get a shot at winning an Apple Watch!

It should be stated that nothing is changing in the browser or desktop versions of Teams. This only applies to the mobile app.

“This change helps maintain a reliable calendar experience on iOS and Android devices and ensures compatibility with ongoing Teams service updates,” the note said.

No reason was given for why this feature would be shut off for those who fail to update, but TechRadar speculated that it had to do with the upcoming end-of-life for Microsoft’s Exchange Web Services system. Updating the mobile Teams app will presumably get around that, allowing for continued use of the Calendar feature.

Don’t miss any meetings, folks.

#Microsoft #Teams #users #lose #Calendar #access #weeks #update">Microsoft Teams users will lose Calendar access in weeks unless they update
                                                            Microsoft’s remote meeting software will lose major functionality on mobile soon if you don’t update your app.In a support note on its website (via TechRadar), Microsoft said that people who use the iOS or Android apps for Microsoft Teams need to update to the latest version of the app by the beginning of October. Users who fail to do that will lose access to the app’s Calendar functionality, which would obviously be a big hindrance to anyone trying to keep track of when their meetings are supposed to happen. We asked you to predict what Apple will do next. See the results and find out how to get a shot at winning an Apple Watch!
        
            Mashable Light Speed
        
        
    

It should be stated that nothing is changing in the browser or desktop versions of Teams. This only applies to the mobile app.“This change helps maintain a reliable calendar experience on iOS and Android devices and ensures compatibility with ongoing Teams service updates,” the note said.
        SEE ALSO:
        
            Microsoft will straight up give you a free pair of Sony XM6 headphones right now
            
        
    
No reason was given for why this feature would be shut off for those who fail to update, but TechRadar speculated that it had to do with the upcoming end-of-life for Microsoft’s Exchange Web Services system. Updating the mobile Teams app will presumably get around that, allowing for continued use of the Calendar feature. Don’t miss any meetings, folks.

                    
                                            
                            
    
        Topics
                    Apps & Software
                    Microsoft
            

                        
                                    #Microsoft #Teams #users #lose #Calendar #access #weeks #update

Microsoft’s remote meeting software will lose major functionality on mobile soon if you don’t update your app.

In a support note on its website (via TechRadar), Microsoft said that people who use the iOS or Android apps for Microsoft Teams need to update to the latest version of the app by the beginning of October. Users who fail to do that will lose access to the app’s Calendar functionality, which would obviously be a big hindrance to anyone trying to keep track of when their meetings are supposed to happen.

We asked you to predict what Apple will do next. See the results and find out how to get a shot at winning an Apple Watch!

It should be stated that nothing is changing in the browser or desktop versions of Teams. This only applies to the mobile app.

“This change helps maintain a reliable calendar experience on iOS and Android devices and ensures compatibility with ongoing Teams service updates,” the note said.

No reason was given for why this feature would be shut off for those who fail to update, but TechRadar speculated that it had to do with the upcoming end-of-life for Microsoft’s Exchange Web Services system. Updating the mobile Teams app will presumably get around that, allowing for continued use of the Calendar feature.

Don’t miss any meetings, folks.

#Microsoft #Teams #users #lose #Calendar #access #weeks #update">Microsoft Teams users will lose Calendar access in weeks unless they update

Microsoft’s remote meeting software will lose major functionality on mobile soon if you don’t update your app.

In a support note on its website (via TechRadar), Microsoft said that people who use the iOS or Android apps for Microsoft Teams need to update to the latest version of the app by the beginning of October. Users who fail to do that will lose access to the app’s Calendar functionality, which would obviously be a big hindrance to anyone trying to keep track of when their meetings are supposed to happen.

We asked you to predict what Apple will do next. See the results and find out how to get a shot at winning an Apple Watch!

It should be stated that nothing is changing in the browser or desktop versions of Teams. This only applies to the mobile app.

“This change helps maintain a reliable calendar experience on iOS and Android devices and ensures compatibility with ongoing Teams service updates,” the note said.

No reason was given for why this feature would be shut off for those who fail to update, but TechRadar speculated that it had to do with the upcoming end-of-life for Microsoft’s Exchange Web Services system. Updating the mobile Teams app will presumably get around that, allowing for continued use of the Calendar feature.

Don’t miss any meetings, folks.

#Microsoft #Teams #users #lose #Calendar #access #weeks #update
Several popular Samsung smart TV apps contain code that share the owner’s internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. 

Some of these apps claim to have been installed on hundreds of millions of smart TVs in people’s homes, per the app developers.

At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its “Editor’s Choice” section on customers’ TV screens.

These apps contain software that funnels outsiders’ web traffic through ordinary home and office internet connections, known as residential proxy networks (or “resproxies”), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node — even when the app is no longer open. 

The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung’s app store, containing code that puts users at risk of having their internet connections tapped by a rogue app. 

Many of these apps are barebone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself.

“What was reviewed is not necessarily what is running,” wrote Harrison Sand, an offensive security consultant at Mnemonic. 

After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users’ internet connections, and will remove apps that contain the functionality.

“We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform,” said a Samsung spokesperson. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.”

The move comes after LG said last month that it would ban apps that contain resproxy software after recent reporting found that around 42% of apps on the company’s app store enlisted a smart TV into a proxy network.

Inside a residential proxy network

The research also offers a rare look inside a residential proxy network.

Resproxy code can also be found in regular consumer phone apps, as well as other consumer electronics, like digital frames and Android streaming boxes, which then share that device’s internet connection. 

Any time a resproxy app or device connects to the internet, an outsider can also pay to use it. 

Resproxies are not inherently illegal. Some are used for evading censorship by routing internet traffic through ordinary looking residential homes. AI companies, for example, increasingly rely on resproxies to scrape data from multiple places on the internet in one go to train their AI models.

But cybersecurity companies say resproxies have gained a reputation for allowing hackers and spies to carry out cyberattacks and data breaches while hiding their malicious activity. 

Cybersecurity companies find resproxies challenging to tackle because the network traffic looks like it’s coming from an ordinary household, rather than a malicious hacker located overseas, as they might expect. 

Moreover, the network traffic that flows through a user’s device over resproxies is generally encrypted, which is generally impossible to unscramble and inspect.

By rooting a Samsung smart TV’s software, Mnemonic’s Sand gained deep access to the television’s internals and analyzed all of the network traffic that flowed in and out of the TV. This included any app that was sharing the smart TV’s internet connection with someone else. 

He found the Pac-Man game contained resproxy code from Bright Data, an Israel-based company that provides proxy networks touting access to millions of residential networks around the world. The company also has a marketplace for selling access to scraped data sets. These datasets are derived from a network of enlisted smart TVs as exit nodes, which are used to download large amounts of public data from the web from multiple sources at once, often to circumvent systems designed to prevent scraping.

Sand found that Bright Data’s resproxy code loaded when opening the Pac-Man game, but noted that this did not automatically turn the Samsung smart TV into an exit node. Sand said the resproxy code is dormant until the user accepts a consent screen, which immediately activates the resproxy code to run in the background until the user deletes the app.

Aside from the user themselves consenting to enlisting their device into a resproxy, Sand warned that a “simple code change on a web server” could instantly activate hundreds of millions of smart TVs into a potentially malicious botnet.

With access to the network data flowing through his smart TV, Sand could see that much of it appeared to suggest the resproxy network was used for large-scale scraping of LinkedIn profiles, and for collecting AI training data. Sand said he only saw a tiny percentage of what was routed over Bright Data’s network. 

Bright Data did not respond to a request for comment.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Samsung #bans #smart #apps #share #users #internet #connections #strangers #TechCrunchcyberattacks,cybersecurity,Exclusive,privacy,residential proxy networks,Samsung">Samsung bans smart TV apps that share users’ internet connections with strangers | TechCrunch
Several popular Samsung smart TV apps contain code that share the owner’s internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. 

Some of these apps claim to have been installed on hundreds of millions of smart TVs in people’s homes, per the app developers.







At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its “Editor’s Choice” section on customers’ TV screens.

These apps contain software that funnels outsiders’ web traffic through ordinary home and office internet connections, known as residential proxy networks (or “resproxies”), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node — even when the app is no longer open. 

The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung’s app store, containing code that puts users at risk of having their internet connections tapped by a rogue app. 

Many of these apps are barebone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself.

“What was reviewed is not necessarily what is running,” wrote Harrison Sand, an offensive security consultant at Mnemonic. 

After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users’ internet connections, and will remove apps that contain the functionality.

“We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform,” said a Samsung spokesperson. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.”

The move comes after LG said last month that it would ban apps that contain resproxy software after recent reporting found that around 42% of apps on the company’s app store enlisted a smart TV into a proxy network.

Inside a residential proxy network

The research also offers a rare look inside a residential proxy network.







Resproxy code can also be found in regular consumer phone apps, as well as other consumer electronics, like digital frames and Android streaming boxes, which then share that device’s internet connection. 

Any time a resproxy app or device connects to the internet, an outsider can also pay to use it. 

Resproxies are not inherently illegal. Some are used for evading censorship by routing internet traffic through ordinary looking residential homes. AI companies, for example, increasingly rely on resproxies to scrape data from multiple places on the internet in one go to train their AI models. 

But cybersecurity companies say resproxies have gained a reputation for allowing hackers and spies to carry out cyberattacks and data breaches while hiding their malicious activity. 

Cybersecurity companies find resproxies challenging to tackle because the network traffic looks like it’s coming from an ordinary household, rather than a malicious hacker located overseas, as they might expect. 

Moreover, the network traffic that flows through a user’s device over resproxies is generally encrypted, which is generally impossible to unscramble and inspect.

By rooting a Samsung smart TV’s software, Mnemonic’s Sand gained deep access to the television’s internals and analyzed all of the network traffic that flowed in and out of the TV. This included any app that was sharing the smart TV’s internet connection with someone else. 

He found the Pac-Man game contained resproxy code from Bright Data, an Israel-based company that provides proxy networks touting access to millions of residential networks around the world. The company also has a marketplace for selling access to scraped data sets. These datasets are derived from a network of enlisted smart TVs as exit nodes, which are used to download large amounts of public data from the web from multiple sources at once, often to circumvent systems designed to prevent scraping.







Sand found that Bright Data’s resproxy code loaded when opening the Pac-Man game, but noted that this did not automatically turn the Samsung smart TV into an exit node. Sand said the resproxy code is dormant until the user accepts a consent screen, which immediately activates the resproxy code to run in the background until the user deletes the app.

Aside from the user themselves consenting to enlisting their device into a resproxy, Sand warned that a “simple code change on a web server” could instantly activate hundreds of millions of smart TVs into a potentially malicious botnet.

With access to the network data flowing through his smart TV, Sand could see that much of it appeared to suggest the resproxy network was used for large-scale scraping of LinkedIn profiles, and for collecting AI training data. Sand said he only saw a tiny percentage of what was routed over Bright Data’s network. 

Bright Data did not respond to a request for comment.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.#Samsung #bans #smart #apps #share #users #internet #connections #strangers #TechCrunchcyberattacks,cybersecurity,Exclusive,privacy,residential proxy networks,Samsung

security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung’s app store, containing code that puts users at risk of having their internet connections tapped by a rogue app. 

Many of these apps are barebone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself.

“What was reviewed is not necessarily what is running,” wrote Harrison Sand, an offensive security consultant at Mnemonic. 

After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users’ internet connections, and will remove apps that contain the functionality.

“We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform,” said a Samsung spokesperson. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.”

The move comes after LG said last month that it would ban apps that contain resproxy software after recent reporting found that around 42% of apps on the company’s app store enlisted a smart TV into a proxy network.

Inside a residential proxy network

The research also offers a rare look inside a residential proxy network.

Resproxy code can also be found in regular consumer phone apps, as well as other consumer electronics, like digital frames and Android streaming boxes, which then share that device’s internet connection. 

Any time a resproxy app or device connects to the internet, an outsider can also pay to use it. 

Resproxies are not inherently illegal. Some are used for evading censorship by routing internet traffic through ordinary looking residential homes. AI companies, for example, increasingly rely on resproxies to scrape data from multiple places on the internet in one go to train their AI models.

But cybersecurity companies say resproxies have gained a reputation for allowing hackers and spies to carry out cyberattacks and data breaches while hiding their malicious activity. 

Cybersecurity companies find resproxies challenging to tackle because the network traffic looks like it’s coming from an ordinary household, rather than a malicious hacker located overseas, as they might expect. 

Moreover, the network traffic that flows through a user’s device over resproxies is generally encrypted, which is generally impossible to unscramble and inspect.

By rooting a Samsung smart TV’s software, Mnemonic’s Sand gained deep access to the television’s internals and analyzed all of the network traffic that flowed in and out of the TV. This included any app that was sharing the smart TV’s internet connection with someone else. 

He found the Pac-Man game contained resproxy code from Bright Data, an Israel-based company that provides proxy networks touting access to millions of residential networks around the world. The company also has a marketplace for selling access to scraped data sets. These datasets are derived from a network of enlisted smart TVs as exit nodes, which are used to download large amounts of public data from the web from multiple sources at once, often to circumvent systems designed to prevent scraping.

Sand found that Bright Data’s resproxy code loaded when opening the Pac-Man game, but noted that this did not automatically turn the Samsung smart TV into an exit node. Sand said the resproxy code is dormant until the user accepts a consent screen, which immediately activates the resproxy code to run in the background until the user deletes the app.

Aside from the user themselves consenting to enlisting their device into a resproxy, Sand warned that a “simple code change on a web server” could instantly activate hundreds of millions of smart TVs into a potentially malicious botnet.

With access to the network data flowing through his smart TV, Sand could see that much of it appeared to suggest the resproxy network was used for large-scale scraping of LinkedIn profiles, and for collecting AI training data. Sand said he only saw a tiny percentage of what was routed over Bright Data’s network. 

Bright Data did not respond to a request for comment.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Samsung #bans #smart #apps #share #users #internet #connections #strangers #TechCrunchcyberattacks,cybersecurity,Exclusive,privacy,residential proxy networks,Samsung">Samsung bans smart TV apps that share users’ internet connections with strangers | TechCrunch

Several popular Samsung smart TV apps contain code that share the owner’s internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. 

Some of these apps claim to have been installed on hundreds of millions of smart TVs in people’s homes, per the app developers.

At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its “Editor’s Choice” section on customers’ TV screens.

These apps contain software that funnels outsiders’ web traffic through ordinary home and office internet connections, known as residential proxy networks (or “resproxies”), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node — even when the app is no longer open. 

The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung’s app store, containing code that puts users at risk of having their internet connections tapped by a rogue app. 

Many of these apps are barebone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself.

“What was reviewed is not necessarily what is running,” wrote Harrison Sand, an offensive security consultant at Mnemonic. 

After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users’ internet connections, and will remove apps that contain the functionality.

“We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform,” said a Samsung spokesperson. “We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components.”

The move comes after LG said last month that it would ban apps that contain resproxy software after recent reporting found that around 42% of apps on the company’s app store enlisted a smart TV into a proxy network.

Inside a residential proxy network

The research also offers a rare look inside a residential proxy network.

Resproxy code can also be found in regular consumer phone apps, as well as other consumer electronics, like digital frames and Android streaming boxes, which then share that device’s internet connection. 

Any time a resproxy app or device connects to the internet, an outsider can also pay to use it. 

Resproxies are not inherently illegal. Some are used for evading censorship by routing internet traffic through ordinary looking residential homes. AI companies, for example, increasingly rely on resproxies to scrape data from multiple places on the internet in one go to train their AI models.

But cybersecurity companies say resproxies have gained a reputation for allowing hackers and spies to carry out cyberattacks and data breaches while hiding their malicious activity. 

Cybersecurity companies find resproxies challenging to tackle because the network traffic looks like it’s coming from an ordinary household, rather than a malicious hacker located overseas, as they might expect. 

Moreover, the network traffic that flows through a user’s device over resproxies is generally encrypted, which is generally impossible to unscramble and inspect.

By rooting a Samsung smart TV’s software, Mnemonic’s Sand gained deep access to the television’s internals and analyzed all of the network traffic that flowed in and out of the TV. This included any app that was sharing the smart TV’s internet connection with someone else. 

He found the Pac-Man game contained resproxy code from Bright Data, an Israel-based company that provides proxy networks touting access to millions of residential networks around the world. The company also has a marketplace for selling access to scraped data sets. These datasets are derived from a network of enlisted smart TVs as exit nodes, which are used to download large amounts of public data from the web from multiple sources at once, often to circumvent systems designed to prevent scraping.

Sand found that Bright Data’s resproxy code loaded when opening the Pac-Man game, but noted that this did not automatically turn the Samsung smart TV into an exit node. Sand said the resproxy code is dormant until the user accepts a consent screen, which immediately activates the resproxy code to run in the background until the user deletes the app.

Aside from the user themselves consenting to enlisting their device into a resproxy, Sand warned that a “simple code change on a web server” could instantly activate hundreds of millions of smart TVs into a potentially malicious botnet.

With access to the network data flowing through his smart TV, Sand could see that much of it appeared to suggest the resproxy network was used for large-scale scraping of LinkedIn profiles, and for collecting AI training data. Sand said he only saw a tiny percentage of what was routed over Bright Data’s network. 

Bright Data did not respond to a request for comment.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Samsung #bans #smart #apps #share #users #internet #connections #strangers #TechCrunchcyberattacks,cybersecurity,Exclusive,privacy,residential proxy networks,Samsung

Post Comment