Live data from Hacker News

Updated rate limits for unauthenticated requests

github.blog

21–30 of 187 posts

Re: Updated rate limits for unauthenticated requests

#23
I don’t think the publication date (May 8, as I type this) on the GitHub blog article is the same date this change became effective.

From a long-term, clean network I have been consistently seeing these “whoa there!” secondary rate limit errors for over a month when browsing more than 2-3 files in a repo.

My experience has been that once they’ve throttled your IP under this policy, you cannot even reach a login page to authenticate. The docs direct you to file a ticket (if you’re a paying customer, which I am) if you consistently get that error.

I was never able to file a ticket when this happened because their rate limiter also applies to one of the required backend services that the ticketing system calls from the browser. Clearly they don’t test that experience end to end.

Re: Updated rate limits for unauthenticated requests

#24
post #17

This was announced https://github.blog/changelog/2025-05-08-updated-rate-limits...

Doesn‘t make it any better. Collateral damage of AI I guess

It's even more hilarious because this time it's Microsoft/Github getting hit by it. (It's funny because MS themselves are such a bad actor when it comes to AIAIAI).

Re: Updated rate limits for unauthenticated requests

#25
It sucks that we've collectively surrendered the urls to our content to centralized services that can change their terms at any time without any control. Content can always be moved, but moving the entire audience associated with a url is much harder.

Re: Updated rate limits for unauthenticated requests

#26
post #17

Earlier quoted context omitted.

Doesn‘t make it any better. Collateral damage of AI I guess

It's even more hilarious because this time it's Microsoft/Github getting hit by it. (It's funny because MS themselves are such a bad actor when it comes to AIAIAI).

This is the same Microsoft that owns LinkedIn which got sued by HiQ which is where the ruling came from that is making sites login required.

Re: Updated rate limits for unauthenticated requests

#27

https://github.com/orgs/community/discussions/157887 This has been going on for weeks and is clearly not a simple mistake.

(We detached this subthread from https://news.ycombinator.com/item?id=43981673 so we could include it in the merged thread)

Re: Updated rate limits for unauthenticated requests

#29

Earlier quoted context omitted.

It's even more hilarious because this time it's Microsoft/Github getting hit by it. (It's funny because MS themselves are such a bad actor when it comes to AIAIAI).

This is the same Microsoft that owns LinkedIn which got sued by HiQ which is where the ruling came from that is making sites login required.

Wow! Website terms of use actually meant something in a court of law!

Re: Updated rate limits for unauthenticated requests

#30
post #5
post #4

I assume they're trying to keep ai bots from strip mining the whole place. Or maybe your IP/browser is questionable.

*other ai bots, ms will obviously mine anything on there. Personally, I like sourcehut (sr.ht)

Same way Reddit sells all its content to Google, then stops everyone else from getting it. Same way Stack Overflow sells all its content to Google, then stops everyone else from getting it.

(Joke's on Reddit, though, because Reddit content became pretty worthless since they did this, and everything before they did this was already publicly archived)

Post reply on HN