Live data from Hacker News

Ban me at the IP level if you don't like me

boston.conman.org

501–510 of 516 posts

Re: Ban me at the IP level if you don't like me

#501

Earlier quoted context omitted.

> If you read back in the thread, we're talking about the claim that adding geoblocking will result in chargebacks, which outside the US, it won't. As a response to someone talking about customers traveling and needing support. But yeah geoblocks can occur in different situations with different appropriate resolutions. > In our case it was friendly fraud when users tried to use a service which we could not provide in…

> If you provided zero service at all, they should get their money back. And calling a chargeback in that situation "friendly fraud" is ridiculous. No, if a company upholds their side of a contract, the customer must too, within the bounds of the law. A chargeback in that situation is the _definition_ of "friendly fraud" and is actual criminal fraud. > If they weren't even asking for a refund and using a chargeback o…

> You can email or write to us.

How do I find your email or postal address if you're blocking every request from a given region? My original point was about companies that do that.

If you're not, I agree that there's much less of a problem (some jurisdictions require online cancellation methods, though).

Re: Ban me at the IP level if you don't like me

#502

I think a lot of really smart people are letting themselves get taken for a ride by the web scraping thing. Unless the bot activity is legitimately hammering your site and causing issues (not saying this isn't happening in some cases), then this mostly amounts to an ideological game of capture the flag. The difference being that you'll never find their flag. The only thing you win by playing is lost time. The best wa…

> The best way to mitigate the load from diffuse, unidentifiable, grey area participants is to have a fast and well engineered web product. I wonder what all those people are doing that their server can't handle the traffic. Wouldn't a simple IP-based rate limit be sufficient? I only pay $1 per month for my VPS, and even that piece of trash can handle 1000s of requests per second.

We have some bots that use residential IP blocks (including TMobile, AT&T, Verizon, etc)... When they hit, it's 1 request per IP, but they use 1000 IPs easily. Then we don't see that IP again for a week or more.

Re: Ban me at the IP level if you don't like me

#503

Earlier quoted context omitted.

Unfortunately, well-behaved bots often have more stable IPs, while bad actors are happy to use residential proxies. If you ban a residential proxy IP you're likely to impact real users while the bad actor simply switches. Personally I don't think IP level network information will ever be effective without combining with other factors. Source: stopping attacks that involve thousands of IPs at my work.

> If you ban a residential proxy IP you're likely to impact real users while the bad actor simply switches. Are you really? How likely do you think is a legit customer/user to be on the same IP as a residential proxy? Sure residential IPS get reused, but you can handle that by making the block last 6-8 hours, or a day or two.

We blocked AT&T Mobile once... You get lots of complaints that way and we only blocked them for an hour.

Re: Ban me at the IP level if you don't like me

#504

Earlier quoted context omitted.

I don't think so. The payload size of the bytes on the wire is small. This premise is all dependent on the .zip being crawled synchronously by the same thread/job making the request.

What if bots catch on to zip bombs, and just download them really slowly? https://en.wikipedia.org/wiki/Zeno%27s_paradoxes#Dichotomy_p...

Their objective is not to DDOS websites, if they catch on, they will download it fast and then discard it.

Re: Ban me at the IP level if you don't like me

#505

Earlier quoted context omitted.

I've heard this point raised elsewhere, and I think it's underplaying the magnitude of the issue. Background scanner noise on the internet is incredibly common, but the AI scraping is not at the same level. Wikipedia has published that their infrastructure costs have notably shot up since LLMs started scraping them. I've seen similar idiotic behavior on a small wiki I run; a single AI company took the data usage from…

From your example (and many others), AI companies are engaging in DDoS too, so why wouldn't law enforcement target them too ?

As a first and very pessimistic guess, the pages getting DoSed are maintained by people or groups with pretty minimal resources. That means time or money available for lawyers isn't there, and the monetary impact per website is small enough that LE may not care.

Also, they might share the common viewpoint of "it's the internet; suck it up."

Re: Ban me at the IP level if you don't like me

#506
post #320

Earlier quoted context omitted.

I've heard this point raised elsewhere, and I think it's underplaying the magnitude of the issue. Background scanner noise on the internet is incredibly common, but the AI scraping is not at the same level. Wikipedia has published that their infrastructure costs have notably shot up since LLMs started scraping them. I've seen similar idiotic behavior on a small wiki I run; a single AI company took the data usage from…

this is a completely fair point, it may be the case that AI scraper bots have recently made the magnitude and/or details of unwanted bot traffic to public IP addresses much worse but yeah the issue is that as long as you have something accessible to the public, it's ultimately your responsibility to deal with malicious/aggressive traffic > At some point impacting my services with your business behavior goes from "it'…

> I think maybe the current AI scraper traffic patterns are actually what "the internet being the internet" is from here forward

Kinda my point was that it's only the internet being the internet if we tolerate it. If enough people give a crap, the corporations doing it will have to knock it off.

Re: Ban me at the IP level if you don't like me

#507

Earlier quoted context omitted.

> If you read back in the thread, we're talking about the claim that adding geoblocking will result in chargebacks, which outside the US, it won't. As a response to someone talking about customers traveling and needing support. But yeah geoblocks can occur in different situations with different appropriate resolutions. > In our case it was friendly fraud when users tried to use a service which we could not provide in…

> If you provided zero service at all, they should get their money back. And calling a chargeback in that situation "friendly fraud" is ridiculous. No, if a company upholds their side of a contract, the customer must too, within the bounds of the law. A chargeback in that situation is the _definition_ of "friendly fraud" and is actual criminal fraud. > If they weren't even asking for a refund and using a chargeback o…

> No, if a company upholds their side of a contract, the customer must too, within the bounds of the law.

The company upholding their side by... doing nothing? Just give a refund if you're not providing service. And what is this about upholding your side if you're legally unable to provide the service in the first place?

> A chargeback in that situation is the _definition_ of "friendly fraud" and is actual criminal fraud.

They have to get the thing and then chargeback. Your definition is nonsense if it doesn't include them getting the thing.

> That's also criminal fraud.

It might be if they lie about something. But this isn't worth going on a tangent.

> It doesn't matter. If our terms prohibited VPN use to avoid geoblocking (which they did), it's irrelevant whether your VPN can or cannot access the cancellation page on a given day. You can email or write to us. All perfectly legal, lawful, and backed by merchant account providers.

Do they know who to email while the site is blocked? At least that's something.

But I'm not even asking about things fluctuating from day to day, I'm worried about a situation where a VPN can sign up but the same VPN at the same time can't be used to cancel.

Re: Ban me at the IP level if you don't like me

#509

Earlier quoted context omitted.

I understand your point, but my argument is in the more generic aspect. Consider how whoever complains about blacklist/whitelist would eventually complain about about allow/deny and say they are non-inclusive. Where would this stop? I would say that as long as the term in unequivocal (and not meant to be offensive) in the context, then there's no need to self-censor

> would eventually That's an empirical premise in a slippery slope style argument. Any evidence to back it up? Who is opposing the terms allow/deny and why? I don't see it. > no need to self-censor The terms allow/deny are more directly descriptive and less contested which I see as a clear win-win change, so I've shifted to use those terms. No biggie and I don't feel self-censored by doing so.

>Who is opposing the terms allow/deny and why?

I am. As a BIPOC, we've been denied rights since the founding of the US. When I read "denylist," I can see my ancestors there, on a list to be denied the right to vote. It's not inclusive to use words like "deny" in the capacity of denying access to things.

Re: Ban me at the IP level if you don't like me

#510

I've been working on a web crawler and have been trying to make it as friendly as possible. Strictly checking robots.txt, crawling slowly, clear identification in the User Agent string, single IP source address. But I've noticed some anti-bot tricks getting applied to the robot.txt file itself. The latest was a slow loris approach where it takes forever for robots.txt to download. I accidentally treated this as a 404…

would you be interested in writing an article about it ? sounds really interesting

Yeah, seems like a good fit. It will end up here, if I get to it.

https://alexsci.com/blog/

Post reply on HN