Live data from Hacker News

Ban me at the IP level if you don't like me

boston.conman.org

461–470 of 516 posts

Re: Ban me at the IP level if you don't like me

#461
post #352

Earlier quoted context omitted.

I think you might be talking about "fraudulent transaction/cardholder does not recognize" disputes. Yes, when using 3DS (which is now much more common at least in Europe, due to often being required by regulation in the EU/EEA), these are much less likely to be won by the issuer. But "merchant does not let me cancel" isn't a fraud dispute (and in fact would probably be lost by the issuing bank if raised as such). Tho…

No, you're just wrong here. Merchant doesn't let me cancel will almost always be won by the vendor when they demonstrate that they do allow cancellations within the bounds of the law and contracts. I've won many of these in the EU, too (we actually never lost a dispute for non-compliance with card network rules, because we were _very_ compliant). I can only assume you are from the US and are assuming your experience…

You’re assuming wrong.

And have you won one of these cases in a scenario where the merchant website has a blanket IP ban? That seems very different from cardholders incapable of clicking an “unsubscribe” button they have access to.

Re: Ban me at the IP level if you don't like me

#462

I've been working on a web crawler and have been trying to make it as friendly as possible. Strictly checking robots.txt, crawling slowly, clear identification in the User Agent string, single IP source address. But I've noticed some anti-bot tricks getting applied to the robot.txt file itself. The latest was a slow loris approach where it takes forever for robots.txt to download. I accidentally treated this as a 404…

would you be interested in writing an article about it ? sounds really interesting

Re: Ban me at the IP level if you don't like me

#463

Earlier quoted context omitted.

If enough websites block the entire ISP / city in this way, *and* enough users get annoyed by being blocked and switch ISPs, then the ISPs will be motivated to stay in business and police their customers' traffic harder. Alas, the "enough users get annoyed by being blocked and switch ISPs" step will never happen. Most users only care about the big web properties, and those have the resources to absorb such crawler tr…

Indeed. This is why it was important that "net neutrality" not be the law. ISPs need the power to police their user traffic.

Incorrect. They need to be forbidden from policing traffic this way. Companies like netflix will need to either ban every ISP (and therefore go bankrupt) or cope harder.

Re: Ban me at the IP level if you don't like me

#464
this is related: https://www.pcworld.com/article/2845330/hundreds-of-chrome-e...

The TL;DR is that there are malicious browser plugins that make the browser into a web scraping bot.

I see this all the time in web server logs; it is recognizable as a GET on a deep link coming from some random IP, usually residential.

Re: Ban me at the IP level if you don't like me

#465

Earlier quoted context omitted.

> What do the lists do? They allow or deny access, right? In part. A whitelisted party is always allowed access. If you are whitelisted to enter my home, you always have access. This is different from conditionally having access, or having access for a pre-set period of time. Same for a blacklist. An IP on a blacklist clearly communicates that it should not be casually overridden in a way a ‘deny-access list’ does no…

> different from conditionally having access, or having access for a pre-set period of time. Irrelevant since the terms allowlist/denylist do not presuppose conditionallity or pre-set time limits. > If someone says to add an IP address to an allow access list, that’s longer Allowlist/denylist (9 + 8 chars) is shorter than whitelist/blacklist (9 + 9 chars). > Inventing a personal language Sounds like you think the pro…

> the terms allowlist/denylist do not presuppose conditionallity or pre-set time limits

They don't pre-suppose anything. They're neologisms. So you have to provide the context when you use them versus being able to leverage what the other person already knows.

> Allowlist/denylist (9 + 8 chars) is shorter than whitelist/blacklist (9 + 9 chars)

The point is you can't just say allow list this block of IPs and walk away in the way saying whitelist these works.

> really only about updating a technical industry term pair to a more descriptive and less semantically loaded pair

Eh, it looks more like creating jargon to signal group membership.

> There is good reason for making the change that do not involve any claim that doing so would solve racism

I guess I'm not seeing it. Black = bad and white = good are deep cultural priors across the world.

Trying to bend a global language like English to accomodate the fact that we've turned those words into racial designations strikes me as silly. (The term blacklist predates [1] the term black as a racial designator, at least in English, I believe by around 100 years [2]. If we want to go pedantic in the opposite direction, no human actually has black or white skin in natural light.)

(For what it’s worth, I’ve genuinely enjoyed this discussion.)

[1] https://en.wikipedia.org/wiki/Blacklisting#Origins_of_the_te...

[2] https://nabado.co.ke/2025/01/05/the-origins-and-evolution-of...

Re: Ban me at the IP level if you don't like me

#466
post #223

> Alex Schroeder's Butlerian Jihad That's Frank Herbert's Butlerian Jihad.

To be fair, he was referring to a post on Alex Schroeder's blog titled with the same name as the term from the Dune books. And that post correctly credits Dune/Herbert. But the post is not about Dune, it's about Spam bots so it's more related to what the original author's post is about. Speaking of the Butlerian Jihad, Frank Herbert's son (Brian) and another author named Kevin J Anderson co-wrote a few books in the D…

Those books completely misrepresent Frank Herbert's original ideas for Butlerian Jihad. It wasn't supposed to be a literal war against genocidal robots.

Re: Ban me at the IP level if you don't like me

#467
post #382

Earlier quoted context omitted.

I've heard this point raised elsewhere, and I think it's underplaying the magnitude of the issue. Background scanner noise on the internet is incredibly common, but the AI scraping is not at the same level. Wikipedia has published that their infrastructure costs have notably shot up since LLMs started scraping them. I've seen similar idiotic behavior on a small wiki I run; a single AI company took the data usage from…

So weird to scrape wikipedia when you can just download db dumb from them.

When you have a pile of funding, and you get told to do things quickly.

Re: Ban me at the IP level if you don't like me

#468

Earlier quoted context omitted.

> different from conditionally having access, or having access for a pre-set period of time. Irrelevant since the terms allowlist/denylist do not presuppose conditionallity or pre-set time limits. > If someone says to add an IP address to an allow access list, that’s longer Allowlist/denylist (9 + 8 chars) is shorter than whitelist/blacklist (9 + 9 chars). > Inventing a personal language Sounds like you think the pro…

> the terms allowlist/denylist do not presuppose conditionallity or pre-set time limits They don't pre-suppose anything. They're neologisms. So you have to provide the context when you use them versus being able to leverage what the other person already knows. > Allowlist/denylist (9 + 8 chars) is shorter than whitelist/blacklist (9 + 9 chars) The point is you can't just say allow list this block of IPs and walk away…

> They don't pre-suppose anything

Oh I think they do presuppose a link to the main everyday meaning of the terms allow and deny. To their merit! But yes they do not presuppose conditionality or time-limits.

> versus being able to leverage what the other person already knows

I'd guess over a million people start learning software dev every year without any prior knowledge of these industry terms. In addition while dev terms often have english roots many, maybe even a majority, of new devs are not native english speakers, and for them the other meanings and etymology of whitelist/blacklist might be less familiar and maybe even confusing. In that regard allowlist/denylist have a descriptive advantage, since the main everyday meaning of allow/deny are mnemonic towards their precise technical meaning and when learning lots of new terms every little mnemonic helps to not get overwhelmed.

> you can't just say allow list this block of IPs and walk away in the way saying whitelist these works.

You can once the term is adopted in a context, like a dev team's style guide. More generally there can be a transition period for any industry terminology change to permeate, but after that there'd be no difference in the number of people who already know the exact industry term meaning vs the number who don't. Allowlist/denylist can be used as drop in replacement nouns and verbs. Thereafter the benefit of saving one character per written use of 'denylist' would accumulate forever, as a bonus. I don't know about you but I'm quite used to technical terms regularly getting updated or replaced in software dev and other technical work so this additional proposed change feels like just one more at a tiny transition cost.

> it looks more like creating jargon to signal group membership

I don't think any argument I've given have that as a premise. Cite me if you think otherwise.

> The term blacklist predates

Yep, but I think gains in descriptiveness and avoiding loaded language has higher priority than etymological preservation, in general and in this case.

> Trying to bend a global language like English

You make the proposed industry term pair change sound earthshaking and iconoclastic. To me it is just a small improvement.

Thanks for the discussion!

Re: Ban me at the IP level if you don't like me

#469

Earlier quoted context omitted.

One of our customers was paying a third party to hit our website with garbage traffic a couple times a week to make sure we were rejecting malformed requests. I was forever tripping over these in Splunk while trying to look for legitimate problems. We also had a period where we generated bad URLs for a week or two, and the worst part was I think they were on links marked nofollow. Three years later there was a bot st…

> And if you 429 Google’s bots they will reduce your pagerank. That’s straight up extortion from a company that also sells cloud services. Googlebot uses different IP space from gcp

They use the same bank accounts and stock ticker. This is basically a non sequitur.

The point is they’re getting paid to run cloud servers to keep their bots happy and not dropping your website to page six.

Re: Ban me at the IP level if you don't like me

#470
post #200

Earlier quoted context omitted.

Uh, no, it's definitely not. Hero begins with a consonant, so it should be preceded by "a", not "an".

Welcome to British English. The h in hero isn’t pronounced, same as hospital, so you use an before it.

I was thinking of 'hotel'. Wrong building. Ooops.
Post reply on HN