3 ms·
> Rate-limit login and comment POST requests even harder. Ban IPs that exceed the amount Don't ban IPs. Or if you do, let the ban expire relatively quickly (da
by CodeSgt 4y ago
> Rate-limit login and comment POST requests even harder. Ban IPs that exceed the amount
Don't ban IPs. Or if you do, let the ban expire relatively quickly (days/weeks, not months/years).
- Avamander 4y agoIdeally you'd keep track of repeat offenders and decide the length based on that.
- annoyingnoob 4y agoI ban IPs from small data centers all the time. For my purposes there is no need to support traffic from small hosting providers that are everywhere all over the world. I do not tend to ban the IPs of commercial ISPs that provide service to end users.
- rndgermandude 4y agoYou will probably ban a lot of VPN users as collateral damage. VPN providers often use these small and relatively cheap providers for their endpoints. You may be fine with banning those VPN users, or even want that - lots of bots will try to hide behind "legitimate" VPNs - but one has to be aware of this consequence at least, especially considering that more and more people seem to use them - probably also thanks to the aggressive "sponsoring" certain providers such as ExpressVPN do on e.g. a wide variety youtube videos.
- annoyingnoob 4y agoIt depends on what you are trying to protect I suppose. Banning OVH IPs (and others) cleared up a lot of issues for me. I don't miss them, but sure you might.
- LinuxBender 4y agoOr at least rate limit session cookies. If a person does not have a session cookie, rate limit by IP. If they are authenticated as a unique person have different rate limits and different levels of authentication. HAProxy can do different rate limits by ACL conditions. Or instead of strictly rate limiting, ask them a question that can't be "looked up" in a table and that requires human thought, philosophy, emotion, ethics. Maybe GPT could eventually adapt to this and in that case fall back to IP rate limiting and grow the set of questions.