Live data from Hacker News

Aggressive bots ruined my weekend

herman.bearblog.dev

101–109 of 109 posts

Re: Aggressive bots ruined my weekend

#101
post #37

Maybe moving the blog service to completely static and letting cloudfare pages handle it, could help?

Cloudflare is not a solution. Only leading to a further centralized internet.

There is no better solution. DoS is fundamentally not preventable, whether in the digital realm or the physical. The only thing you can do is out-brute force the DoS. Hence Cloudflare. Hence why everything naturally centralizes to some extent (we need some word like carcinization for centralization).

Re: Aggressive bots ruined my weekend

#103
post #68
post #27

Earlier quoted context omitted.

You can get paid a few dollars (not many) to let them use your connection. I would like Cloudflare's business model (blocking datacenter IPs) to be worthless, so I do it. Haven't tried a withdrawal yet so it could well be a scam. This is not illegal (unless it's a scam).

> This is not illegal Depends on what they're doing from your connection.

Strict liability by IP address is not the norm, not even in Germany any more. It's not illegal to have a botnet infect your computer either. Since they promise not to use your connection for illegal things, it's their fault if they break that.

Re: Aggressive bots ruined my weekend

#104

Earlier quoted context omitted.

I worked for an Amazon scraping business and they used Luminati (Now Brightdata) for a few months until I figured out a way to avoid the ban hammer and got rid of their proxy. They indeed provided "high quality" residential and cellular ips and "normal quality" data center ips. You had to keep cycling the ip pool every 2-3 days which cost extra. It felt super shady. It isn't their bots, they lease connections to whoe…

> ... until I figured out a way to avoid the ban hammer ... You had my curiosity ... but now you have my attention.

Without bothering to check on Amazon, I successfully scraped meta stuff for years at rates exceeding 20gbit/s without any proxies but just rotating IPv6 addresses on the same couple of blocks for every request

There are usually silly bypasses like this that easily work even with bigco stuff

Re: Aggressive bots ruined my weekend

#105
post #3

> What's wild is that these scrapers rotate through thousands of IP addresses during their scrapes, which leads me to suspect that the requests are being tunnelled through apps on mobile devices, since the ASNs tend to be cellular networks. I'm still speculating here, but I think app developers have found another way to monetise their apps by offering them for free, and selling tunnel access to scrapers. Wild indeed,…

I wrote about this back in July when this "gang" first started hitting some sites I host: https://wxp.io/blog/the-bots-that-keep-on-giving

they use a mixture of colo (M247, Datacamp, HostRoyale, Oxylabs, etc) and international residential. I suspect the latter are where those residential app proxies come into play (bright SDK, etc). Oxylabs is also a well known proxy provider, which makes me think they're the gateway into all of these IPs.

Definitely interesting times to try and host a web server!

Re: Aggressive bots ruined my weekend

#106

Earlier quoted context omitted.

His persistent efforts are the reason I pay for Bear Blog. I think he should fight for the chance to come out on the other side of whatever future we’re heading towards.

I pay for Bear Blog, too. But this year has been problem after problem for its sole proprietor, and I don’t think it’s going to get better.

Even AWS, GCP, and Azure have had major outages in the past few months. Seems to be growing pains of the new era of the web, nowhere is truly safe.

Re: Aggressive bots ruined my weekend

#107

Why don't we sue the abusive scrapers? Scraping is legal but DDoSing is not!

Not sure if that's satire or not but how would you even identify the party to sue? What do you do if they're based in a country where you can't sue them ofer relatively trivial matters as this?

You could start by subpoenaing the registered holder of the IP address.

In general, you can ask a lawyer for your options. Chances are good there are more than zero. But only if you can afford a lawyer.

If you're getting scraped from a country where you don't do business, you can block the country. It's not good to block a country, but it works as a temporary measure. If they really want your data, they will move to a country where you do business, which means a country where you can get a lawyer. Assuming you can afford a lawyer. If they're using rotating IPs, likely some of them are from your country. You might show a judge: "Hey, look, we're getting so much traffic, from a wide variety of IP addresses but it all seems to be the same person on the other end, which would make it illegal DDoS. Can we trace back some of these?" and if you're lucky, the judge might say yes.

DDoS is not a relatively trivial matter.

Re: Aggressive bots ruined my weekend

#108
post #37

Earlier quoted context omitted.

Cloudflare is not a solution. Only leading to a further centralized internet.

There is no better solution. DoS is fundamentally not preventable, whether in the digital realm or the physical. The only thing you can do is out-brute force the DoS. Hence Cloudflare. Hence why everything naturally centralizes to some extent (we need some word like carcinization for centralization).

> DoS is fundamentally not preventable,

Murder is fundamentally not preventable. So what do we do? We regulate some of the more likely avenues of committing murder (e.g. knives and guns) to discourage, and track down and punish cases of murder to dissuade.

Re: Aggressive bots ruined my weekend

#109
post #18

Earlier quoted context omitted.

The "compliance officer" at Bright Data, instead, offered me a special deal to protect my site from their bots ... they run a protection racket along with all the rest of their nastiness.

I worked for an Amazon scraping business and they used Luminati (Now Brightdata) for a few months until I figured out a way to avoid the ban hammer and got rid of their proxy. They indeed provided "high quality" residential and cellular ips and "normal quality" data center ips. You had to keep cycling the ip pool every 2-3 days which cost extra. It felt super shady. It isn't their bots, they lease connections to whoe…

[dead]
Post reply on HN