Hacker News new | ask | show | jobs
by CqtGLRGcukpy 4 days ago
If you are unable to read this, there is an archived copy at https://archive.ph/d3236
3 comments

Thanks. Regretful implementation*, being a normie on iOS Safari:

https://i.ibb.co/vCDH79d0/IMG-0303.png

…and not a bot… hoping not to turn off iCloud Private Relay to read, well, anything. (Maybe Google Scholar if I really needed it, the most mainstream thing I know of with a complete and effective iCloud relay ban.)

*edit: per author’s reply elsewhere, as a test site, rather a good implementation! But other webadmins, please don’t adopt all methods if you can avoid it :)

That makes sense. I block most data-centers and that would include much of Apple's data-centers. What I am doing is of course unorthodox for a blog. This is more of a test site to show what could be done. People can pick and choose which features they like for their particular use cases.

I could some day split it out into a blog and a demo site.

No access from residential IP in Singapore. Why bother to get all sophisticated about blocking, just power down your server.
It's crazier than that. I block two entire continents. Don't worry you are not missing anything. There is a link to archive.is that mirrors the page if you are curious.
I’ll tell you why this isn’t a great experience for me. I try to actively participate on HN, and based on a title I click on posts that promise to be educational or thought-provoking. The topic of combatting bots is very much on my mind.

Instead of learning something I get a blank screen, for the crime of being interested and living somewhere you deem block worthy. Cool.

Oh I came around myself. We got a blank screen and then the author was awesome and explained themselves and I'm satisfied having this one link as an extreme blocking test. Especially because they were thoughtful enough to archive the site themselves.

Our situations to be fair aren’t equivalent. If my block were due to my region instead of an optional paid service, that would feel worse. Maybe it wouldn’t have been the first time either. Whole continents written off!

Let’s certainly loudly complain if someone implements all these methods and inadvertently blocks us when they should’ve known better or don’t care about collateral damage. (If they’re apologetic, between a rock and a hard place with receipts, would require further discussion. e.g. is their choice really between serving us and closing shop)

Edit: but title could add “(but don’t)” at the end

Try to force a refresh it may work now.
I couldn't. Amusing that archive.ph's own crawler, evidently, went through just fine.
I disabled blocking for a few hours then crawled several of my pages with their site.
Oh, I assumed Archive had an automated* tool in their arsenal to overcome the blocks that would’ve affected them. Didja happen to confirm they were blocked initially?

*I think they do something manually sometimes, like logging into a The Information Pro account and mirroring popular articles. (Unless they can use a visitor’s account somehow, like with some browser extension…) And suspected without evidence maybe The Information did some watermarking to ensure they could quickly ban accounts used like that.

And thank you!

Didja happen to confirm they were blocked initially

They were the reason I started blocking data-centers. I wanted to see if I could block all of their addresses which turned into quite an exercise. Initially I was able to block them by blocking TCP SYN packets with an MSS of 1380 and 1300 but talking about it here was a mistake as their admin is on HN. They fixed that and made their MSS 1460 like a nominal home internet connection.

The next thing I had to block was the Russian Federation. That seems to be where the controlling nodes are, I think. That made me even more curious who they were so I just kept iterating through the blocking process. I ended up blocking a number of ASN's and all of Russia. They are all in the linked archive file in the article but I don't specifically call out the ones that are archive.is.

Most on HN think they operate on a shoe-string budget but I have my doubts. I suspect an asset of a technical arm of an intelligence agency but to what purpose and what end I have no clue. They are very clever whoever they are and certainly earned my respect. Either way I think their site is useful, I just wanted to see if I could block it.

> Initially I was able to block them by blocking TCP SYN packets with an MSS of 1380 and 1300 but talking about it here was a mistake as their admin is on HN. They fixed that and made their MSS 1460 like a nominal home internet connection.

For some reason I find this very amusing.

Blocking anyone who uses a VPN. Ouch.
same applies. if its blocked just use a bot API XD. it can't see the bot traffic, it just looks like users
you can use an ai crawler API to download it if you can't get through on your personal device
I wonder why you'd be unable to read it? :-)
Because of shitty over-zealous blocking, probably.