Hacker News new | ask | show | jobs
by ferngodfather 6 days ago
That's fair enough.

I think it's a great article to be fair. We need more of this cheap and quick bot blocking. The fact the solution to unwanted traffic is often "use Cloudflare" is _not_ great for the internet, and nobody really actually likes deploying or managing ModSecurity. Its a nice middleground.

1 comments

Cheap and quick bot-blocking is provided by go-away, less cheap and quick by Anubis.
Sadly, go-away https://git.gammaspectra.live/git/go-away doesn't seem to be maintained anymore.
both of these are easily bypassed by bots.

security theater at its finest. not to mention wasteful.

It's not "security theatre", it's blocking the absolute worst, most painfully obvious bots that. These bots also happen to account for a good 85% of bot traffic, so it makes sense to block them.

Yes, of course, if a real threat actor is doing things properly they'll be using residential proxies and legitimate user agents, but we're talking here about blocking "some of the bots" - mainly the script kiddies.