Live data from Hacker News

Ban me at the IP level if you don't like me

boston.conman.org

331–340 of 516 posts

Re: Ban me at the IP level if you don't like me

#331

Earlier quoted context omitted.

Allow/deny list is more descriptive. That's one good reason for using those terms. Do you agree? In reply to your argument, the deny list (the actual list, apart from what term we use for it) is necessarily something negatively laden, since the items denied are denied due to the real risks/costs they otherwise impose. So using and embracing the less direct phrase 'black' rather than 'deny' in this case seems unlikely…

> Allow/deny list is more descriptive It really isn’t. It’s a novel term, which implies a functional difference from the common term. Like, I can run around insisting on calling soup food drink because it’s technically more descriptive, that doesn’t mean I’m communicating better. To the extent we have a bug in our language, it’s probably in describing dark brown skin tones as black. Not a problem with the word black…

> It really isn’t.

What do the lists do? They allow or deny access, right? Seems allow/deny are fitting descriptive terms for them then. White/black are much more ambiguous prefix terms and and also come with much more semantic baggage. All in all an easy, clarifying change.

Re: Ban me at the IP level if you don't like me

#332
post #246

Earlier quoted context omitted.

Tell that to the "web3 is doing great" crowd. I've met and worked with many people who never shilled a coin in their whole life and were treated as criminals for merely proposing any type of application on Ethereum. I got tired of having people yelling online about how "we are burning the planet" and who refused to understand that proof of stake made energy consumption negligible. To this day, I have my Mastodon inst…

> and who refused to understand that proof of stake made energy consumption negligible. Proof of stake brought with it its own set of flaws and failed to solve many of the ones which already existed. > To this day, I have my Mastodon instance on some extreme blocklist because (…) Maybe. Or maybe you misinterpreted the reason? I don’t know, I only have your side of the story, so won’t comment either way. > The goalpos…

> Curious that what is probably the most corrupt administration in the history of the USA, the one actively taking away their citizens’ freedoms as we speak, is the one embracing cryptocurrency to the max.

Your memory is quite selective. El Salvador has been pushing for Bitcoin way before that, so we already have our share of Banana Republic (which is the US is becoming) promoting cryptocurrencies.

Second, the US is "embracing" Bitcoin by backing it up and enabling the creation of off-chain financial instruments. It is a complete corruption and the complete opposite of "trustless systems".

Third, the corruption of the government and their interest in cryptocurrency are orthogonal: the UK is passing bizarre laws to control social media, the EU is pushing for backdoors in messaging systems every other year. None of these institutions are acting with the interests of their citizens at heart, and the more explicit this become the more we will need to have systems that can let us operate trustlessly.

> For another, they didn’t invent the concept of trustless systems and cryptography.

But they are the ones who are actually working and developing practical applications. They are the ones doing actual engineering and dealing with real challenges and solving the problems that people are now facing, such as "how the hell do we deny access to bad actors on the open global internet who have endless resources and have nothing to lose by breaking social norms"?

Re: Ban me at the IP level if you don't like me

#333
post #33

Earlier quoted context omitted.

Many US companies do it already. It should be illegal, at least for companies that still charge me while I’m abroad and don’t offer me any other way of canceling service or getting support.

This! Dealing with European services from China is also terrible. As is the other way around. Welcome to the intranet!

In addition, my tencent and alicloud instances are also hammered to death by their own bots. Just to add a bit of perspective.

Re: Ban me at the IP level if you don't like me

#334
post #319
post #180

Earlier quoted context omitted.

Serving file content/diff requests from gitea/forgejo is quite expensive computationally. And these bots tend to tarpit themselves when they come across eg. a Linux repo mirror. https://social.hackerspace.pl/@q3k/114358881508370524

> Serving file content/diff requests from gitea/forgejo is quite expensive computationally One time, sure. But unauthenticated requests would surely be cached, authenticated ones skip the cache (just like HN works :) ), as most internet-facing websites end up using this pattern.

You can't feasibly cache large reposotories' diffs/content-at-version without reimplementing a significant part of git - this stuff is extremely high cardinality and you'd just constantly thrash the cache the moment someone does a BFS/DFS through available links (as these bots tend to do).

Re: Ban me at the IP level if you don't like me

#335
post #267

Earlier quoted context omitted.

[flagged]

Ignore the trolls. Also, if they are upset with you they should focus their vitriol on me. I block nearly all of BRICS especially Brazil as most are hard wired to not follow even the simplest of rules , most data-centers, some VPN's based on MSS, posting from cell phones and much more. I am always happy to give people the satisfaction of down-voting me since I use uBlock to hide karma. In ublock -> my filters # HN Bl…

[deleted]

Re: Ban me at the IP level if you don't like me

#336
post #246

Earlier quoted context omitted.

> and who refused to understand that proof of stake made energy consumption negligible. Proof of stake brought with it its own set of flaws and failed to solve many of the ones which already existed. > To this day, I have my Mastodon instance on some extreme blocklist because (…) Maybe. Or maybe you misinterpreted the reason? I don’t know, I only have your side of the story, so won’t comment either way. > The goalpos…

> Curious that what is probably the most corrupt administration in the history of the USA, the one actively taking away their citizens’ freedoms as we speak, is the one embracing cryptocurrency to the max. Your memory is quite selective. El Salvador has been pushing for Bitcoin way before that, so we already have our share of Banana Republic (which is the US is becoming) promoting cryptocurrencies. Second, the US is…

That read like a bizarre tangent, because it didn’t at all address the argument. To make it clear I’ll repeat the crux of my point, the conclusion that the other arguments lead up to, which you skipped entirely in your reply:

> They’re far from impervious to corruption.

That’s it. That’s the point. You brought up corruption, and I pointed out blockchains don’t actually prevent that. Which you seem to agree with, so I don’t get your response at all.

> But they are the ones who are actually working and developing practical applications.

No, they are not. If no one wants to use them because of all the things they do wrong, they are not practical.

> They are the ones doing actual engineering and dealing with real challenges and solving the problems that people are now facing

No, they are not. They aren’t solving real problems and that is exactly the problem. They are being used almost exclusively for grifts, scams, and hoarding.

> such as "how the hell do we deny access to bad actors on the open global internet who have endless resources and have nothing to lose by breaking social norms"?

That is not a problem blockchains solve. At all.

Re: Ban me at the IP level if you don't like me

#337
post #97

"I'm seriously thinking that the CCP encourage this with maybe the hope of externalizing the cost of the Great Firewall to the rest of the world. If China scrapes content, that's fine as far as the CCP goes; If it's blocked, that's fine by the CCP too (I say, as I adjust my tin foil hat)." Then turn the tables on them and make the Great Firewall do your job! Just choose a random snippet about illegal Chinese occupati…

I just tried this, i took some strings about Falun Gong and the Tianmen thing from the chinese wikipedia and put them into my SSH server banner. The connection attempts from the Tencent AS ceased completely, but now they come from Russia, Lithuania and Iran instead.

Whoa, that's fascinating. So their botnet runs in multiple regions and will auto-switch if one has problems. Makes sense. Seems a bit strange to use China as the primary, though. Unless of course the attacker is based in China? Of the countries you mentioned Lithuania seems a much better choice. They have excellent pipes to EU and North America, and there's no firewall to deal with

Re: Ban me at the IP level if you don't like me

#338

Earlier quoted context omitted.

What's worse is when you get bots blasting HTTP traffic at every open port, even well known services like SMTP. Seriously, it's a mail server. It identified itself as soon as the connection was opened, if they waited 100ms-300ms before spamming, they'd know that it wasn't HTTP because the other side wouldn't send anything at all if it was. There's literally no need to bombard a mail server on a well known port by con…

It's even funnier when you realize it is a request for a known exploit in WordPress. Does someone really run that on port 22?

I HAVE heard of someone that runs SSH on port 443 and HTTPS on 22.

It blocks a lot of bots, but I feel like just running on a high port number (10,000+) would likely do better.

Re: Ban me at the IP level if you don't like me

#339

This is a problem. There's a recent phishing campaign with sites hosted by Cloudflare and spam sent through either "noobtech.in" (103.173.40.0/24) or through "worldhost.group" (many, many networks). "noobtech.in" has no web site, can't accept abuse complaints (their email has spam filters), and they don't respond at all to email asking them for better communication methods. The phishing domains have "mail.(phishing d…

[deleted]

Re: Ban me at the IP level if you don't like me

#340
post #134

Earlier quoted context omitted.

My friend has a small public gitea instance, only use by him a a few friends. He's getting thousounds of requests an hour from bots. I'm sorry but even if it does not impact his service, at the very least it feels like harassment

Thousands of requests per hour? So, something like 1-3 per second? If this is actually impacting perceived QoS then I think a gitea bug report would be justified. Clearly there's been some kind of a performance regression. Just looking at the logs seems to be an infohazard for many people. I don't see why you'd want to inspect the septic tanks of the internet unless absolutely necessary.

i usually get 10 a second hitting the same content pages 10 times an hour, is that not what you guys are getting from google bot?
Post reply on HN