Hacker News new | ask | show | jobs
by ferngodfather 11 hours ago
It's not "security theatre", it's blocking the absolute worst, most painfully obvious bots that. These bots also happen to account for a good 85% of bot traffic, so it makes sense to block them.

Yes, of course, if a real threat actor is doing things properly they'll be using residential proxies and legitimate user agents, but we're talking here about blocking "some of the bots" - mainly the script kiddies.