• jagged_circle@feddit.nl
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    2
    ·
    edit-2
    23 hours ago

    Sad there’s no mention of running an Onion Service. That has built-in PoW for DoS protection. So you dont have to be an asshole and block all if Brazil or China or Edge users.

    Just use Tor, silly sysadmins

    • Max-P@lemmy.max-p.me
      link
      fedilink
      arrow-up
      12
      ·
      23 hours ago

      Proof of work is what those modern captchas tend to do I believe. Not useful to stop creating accounts and such, but very effective to stop crawlers.

      Have the same problem at work, and Cloudflare does jack shit about it. Half that traffic uses user agents that have no chance to even support TLS1.3, I see some IE5, IE6, Opera with their old Presto engine, I’ve even seen Netscape. Complete and utter bullshit. At this point if you’re not on an allow list of known common user agents or logged in, you get a PoW captcha.

      • lightnegative@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        8 hours ago

        If I was a bot author intent on causing misery I’d just use the user agent from the latest version of Firefox/Chrome/Edge that legitimate users would use.

        It’s just a string controlled by the client at the end of the day and I’m surprised the GPT and OpenAI bots announce themselves in it. Associating meaning on the server side is always going to be problematic if the client can control the value

      • jagged_circle@feddit.nl
        link
        fedilink
        English
        arrow-up
        2
        ·
        17 hours ago

        Yeah but Tor’s doesn’t require JavaScript, so you dont have to block at-risk users and opress them further