Login
You're viewing the mastodon.coffee public feed.
  • Aug 8, 2026, 12:37 PM

    @dalias @stuartl @thesamesam @mgorny In the end it's abuse coming from their IP range ... they are better adapted to sort that out, so making it their problem seems fine.

    Though I agree that if the error page is as expensive than real content, that might not be a workable solution in the short term.

    💬 2🔄 0⭐ 0

Replies

  • Aug 8, 2026, 1:39 PM

    @soc @stuartl @thesamesam @mgorny There's no way they can do anything about it. The traffic looks just like normal customer use. No single IP hammers anyone. They all make only a small number of connections to any given site, spreading the abuse of the same site across millions of source addresses.

    If residential ISPs *tried* to stop this, it would fail, but they would fuck us over even more in the process. Doing things like resetting our connections, spying on SNI and having "AI" models process our browsing habits trying to classify them as normal or abnormal, etc. You do NOT want to be advocating for this.

    💬 1🔄 0⭐ 0
  • Aug 8, 2026, 5:32 PM
    @dalias @soc @stuartl @thesamesam @mgorny I do think there's few things ISPs could do without involving deep-packet inspection (illegal in quite few places for them to do). For example having some honeypots for both the residential side and hoster side, specially as most home ISPs also tend to have a hoster venture.

    And then actions taken can be things like having the controlling IPs go into a list of IPs that can be used in say an opt-in list used by their users' firewalls.
    💬 0🔄 0⭐ 0
  • Aug 8, 2026, 4:14 PM

    @soc @dalias @stuartl @mgorny I'm trying to report it, if out of principle if nothing else, but the scale is huge. When it comes to residential IPs, it feels like there's not much point because if you succeed, they're wiping out one address, not even someone who has rented out a few servers with who-knows-how-many IPs.

    💬 0🔄 0⭐ 0
  • Aug 8, 2026, 4:29 PM

    @thesamesam @soc @stuartl @mgorny Reporting residential IPs is not useful and is actively harmful. You will not hinder the attacker but you will pressure residential ISPs to become even more draconian towards their legitimate customers who have little if any choice.

    Reporting cloud shit should be useful. But it's not because the bulk of their profits come from abuse. Pretty much anything done at scale that needs orchestrators is abusive.

    💬 0🔄 0⭐ 0