4 ms·
Anecdote, but I once ran a blog for many years. Country breakdown for traffic was roughly 30% China, 30% Russia, and 30% US. Almost 100% of requests out of Chin
by Damorian 6y ago
Anecdote, but I once ran a blog for many years. Country breakdown for traffic was roughly 30% China, 30% Russia, and 30% US. Almost 100% of requests out of China and Russia were hacking attempts, I assume mostly by bots. They've earned a reputation and there's nothing wrong pointing it out. If you operate a website, unless China and Russia are part of your market/audience, I'd suggest blocking them altogether.
- McAtNite 6y agoJust wanted to second this. I ran several public Linux servers at a major university. China and Russia based IPs we’re constantly trying to brute force all of our servers. It got the point where we would just apply a geoblock just in case one finally managed to get through. I’m all for avoiding nationalistic dog whistles when discussing things, but both China and Russia have rightfully earned their places as bad actors on the internet.
- warent 6y agoIt adds no information or value to the discussion by giving the hackers a nationality. If there was a statistic that the majority of hackers wore hoodies, would we be calling that out and saying "Attacked by hackers in hoodies?" Obviously not because their clothing has nothing to do with the fact that they're malicious. What's happening here is profiling and it doesn't work. Add that to the fact that there are of course bad actors in countries including the US who happen to have proxies in other countries. Geolocating the IP address tells us nothing. The largest botnets came from a variety of nationalities and are rarely Chinese. Conficker was allegedly from the Ukraine, and a Swede plead guilty. Alureon came from Estonia. Mariposa from spain. Stop with the emotionally-charged flame baiting based on shallow data and anecdotal information.
- TurkishPoptart 6y agoThank you for making the world a better place through your valiant activism.
- rowanG077 6y agoIf I had a shop and everyone that robs me has a hoody I would damn well point it out and ban them. That doesn't mean every person with a hoody wil rob me but it's a very effective and filter. It's not emotionally charged it's completely logical.
- warent 6y agoEither the problem is with the analogy and you're taking it too literally, or your reasoning is severely distorted and leads into very dark, hellish places. People can decide not to wear hoodies anymore. Chinese people cannot choose to just not be Chinese anymore, nor should they have to.
- rowanG077 6y agoI don't think that we should 'ban' Chinese or Russian people if you are pointing towards that. I do think that we shouldn't pull a smokescreen over the truth by dissallowing statement of fact that most hackers are Chinese or Russian. We also shouldn't shout down people who are hit everyday by this as rascist or emotionally charged. It's completely logical for them to want to ban these groups. Instead we should educate on exactly what kind of a very dark and hellish place banning leads to.
- wolco 6y agoYou ban the ip block that is the problem. If American hackers are using ips based in China they get blocked. If anyone living in China doesn't like that they have the power through the government to regulate that traffic. People can decide in China too.
- wolco 6y agoGeolocating tells us which country the ip address belongs to. The countries policies towards companies operating those ips have a big effect. Nationities do matter.
- McAtNite 6y agoPlease note I never used a nationality in my comment, but referred to the countries themselves. Nothing I stated had any emotions behind it. I stated simple facts from personal experience. Geolocating the origination points of an exploit is extremely useful. Your point of other countries using proxies being the prime reason. The simple fact is if China and Russia wanted to limit the number of attacks originating from their IP blocks they could do so. Since they more or less allow it to continue they are a common source of malicious traffic, and geo blocking will significantly reduce the number of attempted exploits you experience.
- chrischen 6y agoChange your statement to read “black” instead of Chinese and see if you still think it’s OK. The crime is hacking, and your attempts to “expose” Chinese hackers is more like an agenda to prejudice Chinese even if statistically many Chinese-originated traffic is attempting to hack you. In the chance that the hacking is actually caused by American hackers routing their traffic through China, then what purpose does your Chinese assumption serve except to encourage others to profile and prejudice Chinese? In a more realistic example of how your comments may incite racial prejudice for no good reason is that it is actually very likely the biggest botnets have Chinese victims (because they are poor, run Windows XP still, and generally have very poor internet security practices). Oh, and also they happen to have the most people on Earth, so statistically any given thing would be mostly Chinese. So, unless you are absolutely certain that being Chinese makes you a criminal hacker I would recommend leaving race or nationality out of the discussion.
- tossmeout 6y agoThe implication isn't that being Chinese makes one likely to be a hacker. It's the other way around. It's that being a hacker makes it unusually likely that you're Chinese (or Russian). Similarly, being a Nigerian doesn't make you an email scammer, but being an email scammer makes you unusually likely to be Nigerian. Being a drug lord makes you unusually likely to be Mexican. These are archetypes, i.e. popularly associated examples of particular actions. But I'm not sure if they're full-blown stereotypes, where they get over-applied to members of that group. People don't believe that all Chinese and Russians are hackers, that all Nigerians are email scammers, that all Mexicans are drug overlords, etc. Stereotypes tend to be more insidious. Many people (in America) do believe that Blacks and Mexicans are criminals, that Chinese are great at math, etc., to the degree that it changes how they actually treat people. So I think these are much worse and shouldn't be equated. That said, despite the above analysis, I can see how being Chinese you would still cringe when you see the phrase "Chinese hacker" being used casually. I'm an ethnic minority and have felt similarly in similar situations.
- chrischen 6y agoYes but I also gave a pretty likely hypothesis as to why the hackers appear Chinese. The OP is claiming DDoS attacks which are likely from compromised machines. So if that is true then the viewpoint of blaming it on Chinese becomes nonsensical and also wrong. So given that there is reasonable doubt, is it right to attribute this "being a hacker" to having anything to do with being Chinese in any way?
- joshstrange 6y agoI'll third this. Every single IP that I have geo-located that has attempted to get into one of my home servers/routers is coming from China. I didn't go as far as blocking all of China because I was sure that some point down the line it would cause some other random issue and I would have long forgotten blocking Chinese IP's. If I remember correctly I used fail2ban or similar software to blacklist IP's after X failed attempts. That plus moving all services to non-standard ports (save for 80/443).
- blackrock 6y agoWhat if all the hacking actually originated from America? They just compromised a bunch of random computers in China and Russia, running an old copy of Windows XP, and built themselves a botnet. What further evidence do you have, other than an IP address?
- Klinky 6y agoEven if that was the case, China/Russia having a bunch of vulnerable computers being used as proxy botnets would still be alarming.
- andykx 6y agoWhy just those two countries then? Why don’t I see a thousand get requests for /wp-login from countries all around the world? Wouldn’t that be significantly more effective since you can’t simply block a range of addresses to mitigate it?