this post was submitted on 09 Jan 2025
30 points (96.9% liked)

Selfhosted

40956 readers
1240 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Now that we know AI bots will ignore robots.txt and churn residential IP addresses to scrape websites, does anyone know of a method to block them that doesn't entail handing over your website to Cloudflare?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 6 points 14 hours ago (5 children)

If I'm reading your link right, they are using user agents. Granted there's a lot. Maybe you could whitelist user agents you approve of? Or one of the commenters had a list that you could block. Nginx would be able to handle that.

[–] [email protected] 1 points 14 hours ago (3 children)

Thank you for the reply, but at least one commenter claims they'll impersonate Chrome UAs.

[–] [email protected] 10 points 13 hours ago* (last edited 13 hours ago) (1 children)

You can read more Here

If you try to rate-limit them, they'll just switch to other IPs all the time. If you try to block them by User Agent string, they'll just switch to a non-bot UA string (no, really). This is literally a DDoS on the entire internet.

https://pod.geraspora.de/posts/17342163

[–] [email protected] 2 points 11 hours ago (1 children)

Except it's not denying service, so it's just a D.

[–] [email protected] 6 points 7 hours ago

In the hackernews comments for that geraspora link people discussed websites shutting down due to hosting costs, which may be attributed in part to the overly aggressive crawling. So maybe it's just a different form of DDOS than we're used to.

load more comments (1 replies)
load more comments (2 replies)