skip to content

Why does a residential IP address rent by the hour for more than a datacentre one?

level: middleimportance: should knowfreq 46%

answer

  1. not bandwidth, and not really anonymity
  2. who the address is allocated to
  3. a score inside someone else's model
  4. value decays with every use
  5. priced per gigabyte for a reason

basics

~10 s

The product is reputation, not bandwidth. Risk models score a consumer ISP address as ordinary and a hosting range as suspect, so the same request is accepted from one and refused from the other.

solid answer

~50 s

A residential exit is sold because of where it appears to come from. Sites that score incoming requests weigh the address's owner: a consumer ISP allocation in a plausible city looks like a customer, while a hosting or cloud range looks like automation and gets challenged or blocked outright. The buyer, typically a scraper, a ticket or inventory bot, an ad-fraud operator or someone abusing accounts at scale, is paying for their traffic to arrive looking domestic and ordinary. Supply comes from malware on home routers and PCs, and from bandwidth-sharing code bundled into free software. Pricing is usually per gigabyte, because the address's value decays as it is used: once it has been seen misbehaving it is scored down and burned, so the vendor's real product is continuous churn across a large pool of victims.

go deeper

for a junior

Know that a proxy exit sells the victim's address, not their files or their machine. Be able to say that traffic from a home broadband address is treated differently from traffic out of a cloud provider.

for a middle

Explain reputation as the product: allocation type, geography and history feeding a third party's scoring, and why per-gigabyte pricing follows from the address burning as it is used. Name both supply pipelines, compromised devices and bundled sharing code.

for a senior

Show the three-party structure and where the harm lands, including a corporate egress address being spent on someone else's fraud. Argue why address-based blocking is the wrong lever and what is left when it fails.

for a principal

Own the conversation with the business about an estate whose outbound address is a shared reputational asset, including who is accountable when partners begin refusing that traffic and what it costs to change it.

## The address is the product When a victim's machine is turned into a proxy exit, nothing about the machine matters except the network address it holds and the fact that it can forward traffic. The bandwidth is modest, the latency is bad, the host may vanish when someone reboots a router. None of that is the point. The buyer is paying for a property the victim did not know they owned: the reputation their address carries inside somebody else's risk model. Almost every consumer-facing site scores incoming requests, and one of the strongest signals available is what kind of network the address belongs to. Public registration data tells you whether a range is allocated to a consumer ISP, a mobile carrier, a hosting provider or a cloud platform. A request from a cloud range that claims to be a shopper browsing trainers is, statistically, automation. A request from a broadband allocation in a city where that account has logged in before is, statistically, a customer. So the same automated request is refused from one address and served from the other, and the difference in outcome is what the hourly or per-gigabyte fee buys. This is why the vocabulary of the market is "residential", "mobile" and "ISP" proxies, and why a specific country, city or carrier commands a premium. Geography that matches the account being abused is worth paying for. ## Where the supply comes from Two pipelines feed the same pool, and at the exit they are indistinguishable: - **Compromised devices.** Home routers with default or reused credentials, set-top boxes, cameras and other consumer equipment that is never updated, plus ordinary PCs infected with a small forwarding component. The owner is never told. - **Consented bandwidth sharing.** Software development kits paid into free applications, browser extensions and "earn money from your unused bandwidth" clients. Somebody clicked accept. Both produce an exit node on a consumer allocation. The vendor aggregates them into a pool of millions of addresses, and sells access with controls for country, city, carrier and session stickiness. ## Why the fee is metered by traffic An address is a wasting asset. The moment it is used against a target that scores it, the address accumulates history: challenges, blocks, abuse reports, appearances on public lists. After enough use it is worth nothing for the purpose it was rented for. That is why pricing is typically per gigabyte rather than per address, and why the vendors compete on pool size and rotation rather than on speed. The business is churn: burning victims' reputations at a controlled rate and replacing them. ## Who pays, and who never finds out The economics are unusual because there are three parties and only one of them understands the arrangement. The **victim** pays in bandwidth and data allowance, but mostly in reputation. Their address collects the consequences of the buyer's behaviour: constant challenges when they browse, services that refuse them, an abuse notice from their ISP. Where the victim is a company, the address being spent may be a corporate egress address, and the partners and services that start refusing that traffic are the company's own. The **buyer** rents an exit and often has no interest in where it comes from; some vendors advertise consented supply and the buyer takes that at face value. The **third party being defrauded** never learns a victim was involved at all. From their side, an ordinary household made a request. That is the entire product. ## The classification mistake Candidates often describe this as "hiding the attacker's IP", as if the value were anonymity. Anonymity is cheap and any hosting provider or public relay supplies it. What is not cheap is *legitimacy*: an address that a stranger's risk model has no reason to distrust. Framing it as reputation rather than concealment is what makes the countermeasure obvious, since blocking hosting ranges does nothing to a pool built out of consumer broadband, and the remaining leverage is on behaviour and on the account rather than on the address.

  • What does the victim of the proxy node actually lose?
    Bandwidth and data allowance, but mainly their address's standing. They start getting challenged or refused by services they had no trouble with, and their provider may pass on abuse complaints. If the address is a company's egress, the partners and platforms refusing that traffic are the company's, and the abuse report lands on the company.
  • Why can you not just block hosting and cloud ranges?
    Because that is exactly the block the pool exists to defeat. The exits sit in consumer broadband and mobile carrier allocations shared with real customers, so range-level blocking either misses them entirely or takes genuine users with it. Leverage moves to behaviour and to the account rather than to the address.
  • Why does the buyer pay a premium for a particular city or carrier?
    Because consistency is part of the disguise. An account that always signs in from one metro area looks wrong arriving from another country, so an exit that matches the expected location and network type survives scrutiny that a random address would not. Precision of placement is the thing being sold.

You are not renting the car. You are renting its clean number plate, and every trip through a speed camera makes that plate worth a little less.

saying these in an interview costs you the question

  • Says residential proxies are bought for speed or bandwidth
  • Describes the value as anonymity rather than legitimacy
  • Assumes every exit node comes from a compromised device
  • Thinks blocking hosting ranges removes the problem
  • Ignores that the victim's own address is what gets spent

context