9 ms·
Arxiv.org is experiencing a DDoS attack
- paulpauper 3y agoThese requests originated from over 200 IP addresses – almost all owned by an ISP for a particular province in China. The confirmation emails for this volume of requests overwhelmed our email service. As a result, many arXiv users may not have received their daily emails. And other users may not have received their confirmation emails for registering accounts, or legitimate email change requests. this should be easy to block, no? just 200 out of millions
- deleted 3y ago[deleted]
- smcin 3y agoThey said a million email change requests, originating from over 200 IP addresses. The email requests already happened. So blacklisting the IP addresses wouldn't prevent the email overload.
- Abecid 3y agoWho would have the incentive to bring arxiv down?
- dist-epoch 3y ago- for the lulz - revenge for rejected paper - badly written scraping script
- deleted 3y ago[deleted]
- bsder 3y agoCould be a "proof" before selling a larger DDoS on the black market.
- woadwarrior01 3y agoGatekeepers who hate open access. https://x.com/emilymbender/status/1696374958652522612 https://x.com/emilymbender/status/1696374958652522612
- tokai 3y agoThere is nothing in the tweet you are linking against open access.
- kawhah 3y agoThe tweet says "arxiv is a cancer". It's obviously reasonable evidence that some people don't like arxiv. You are splitting hairs.
- davidgerard 3y agoand the context really isn't "gatekeepers hate open access", is it.
- woadwarrior01 3y agoThe context is that the author of the tweet hates fast paced open research (which IMO is a net good for humanity) and makes up the strawman `"can't keep up" + "anything older than 6 months is irrelevant" in CS` quotes to justify that position. There's timeless beauty in CS, but there's also a lot more fertile ground for research in CS, given how young the field is compared to the older sciences.
- davidgerard 3y agocounterpoint: no she doesn't, that's weird nonsense. and I've offered at least as much evidence as you have.
- tokai 3y agoThe author of that tweet clearly has an issue with the arxiv being an open repository where everyone can upload anything. There is nothing about open access in the tweet. And arxiv is not same as the concept or movement of open access. Most articles on Arxiv doesn't even have a proper license to fulfill the definition of Open Access in the BOAI declaration. Further proof that the authors tweet is not about or against open access is that she publishes open access herself: https://jlm.ipipan.waw.pl/index.php/JLM/article/view/292 https://jlm.ipipan.waw.pl/index.php/JLM/article/view/292 https://nejlt.ep.liu.se/article/view/4017 https://nejlt.ep.liu.se/article/view/4017 https://dl.acm.org/doi/10.1145/3498366.3505816 https://dl.acm.org/doi/10.1145/3498366.3505816
- generationP 3y agoSomeone who has just plagiarized from it and wants to hide the source.
- jimhefferon 3y agoI ran an open service for more than a decade. The world is filled with people who do things that are bad and cannot be understood.
- turtles3 3y agoSome men just want to watch the world burn.
- _lvbh 3y agoI’ve hosted a few free services over the past 2 years. They are just utilities, nothing controversial, yet there are DDOS attacks ever few weeks from some Chinese IP ranges (especially Alibaba). Ended up just blocking the ASN as the JA3 fingerprints were spoofed and they were sending legitimate looking data (thus difficult to identify and block)
- elashri 3y ago> We will shortly be reaching out to the abuse desk of the affected ISP for assistance. Does anyone here have experience working with an ISP in abuse cases like this one, specially a Chinese ISP?
- KirillPanov 3y agoIf it's one ISP you don't work with them, you simply add a `drop` rule for their IP range. I think this article is misleading; there's nothing terribly "distributed" about the DoS.
- bdavbdav 3y agoYep - customers will start getting pretty shirty if websites become unavailable only on their ISP, as their ISP fails to respond to abuse reports.
- taskforcegemini 3y agowhois on the ip-address tells their range, also their asn with which you can find and block all their nets if necessary. but block via firewall, not webserver
- pera 3y agoNot from China but yes, usually they are very quick to respond, it's crucial for most ISPs to maintain a good reputation.
- cbf66 3y agoWell, no reply from the ISP so far.
- qmarchi 3y agoHave you tried blocking only endpoint for the IPs in question? Happy to help discussing mitigation techniques. Long time user of ArXiv. Email in Bio.
- 3y ago
- KRAKRISMOTT 3y agoA million password resets is shockingly low for a DDOS, could this have been an university assignment gone wrong? I can imagine some clueless dean ordering all their engineering grads to submit research to arXiv. If they have 100-200K students, a single poorly written script to link the institution's SSO with automatically created arXiv accounts could easily overwhelm the system.
- bagels 3y agoWhat school has 200k engineering students?
- regularfry 3y ago"poorly written" could easily remove the "engineering" qualifier.
- mousetree 3y agoThey would also have to be in the same class and all running their code at the same time.
- cbf66 3y agoIt was from about 10 accounts. Which we suspended. But it appears that they created new accounts overnight (daytime in China). arXiv is not well-equipped to play whack-a-mole. And 10 accounts using 100 different IP addresses, would seem unlikely for an innocent project. And creating new accounts ...
- deathlock 3y agoCan you set a restriction so that each user cannot change the email if it has already been changed during the last hour/day? In this way you won't need to ban IPs while still allowing legitimate users to change their emails or to create new accounts.
- skoocda 3y agoIndira Gandhi National Open University has over 4 million students, and in China about 40% of university students are in STEM. It's certainly not impossible that this is coming from a single institution.
- jbottoms 3y agoDoes the State Dept get involved in these cases? Surely China has responsibility over this ISP.
- KirillPanov 3y agoLook, arxiv.org is awesome and I love them, but they really can't expect the ITU or abuse-reporting groups to bail them out here. If you have some web service that sends emails, it's on you to pick a sensible rate limit for it (not 1,000,000 messages per day unless you're Fastmail) and to hierarchically bucket that ratelimit by the routable prefix (first 24 bits) of the requester's IP address. As the bucket empties, respond more and more slowly. This way the worst a DDoSer can do is mildly annoy people who happen to use the same ISP that they do -- but eventually even those people will still get through. I'm sorry, but this is just the sort of thing everybody has to do in order to preserve a decentralized Internet. Because if we don't all do this sort of stuff, pretty soon it won't be the Internet anymore, it'll be the CloudflareNet. Alright go ahead, downvote me to negative-billion. I can handle it.
- Angostura 3y ago> Alright go ahead, downvote me to negative-billion. I can handle it. I tried, but HN seems to implement some kind of rate limiting. D'Oh
- quickthrower2 3y agoIt’s an ego preservation system, it only shows downvotes to -4 :-)
- gcanyon 3y agoI upvoted you out of spite :-)