Skip to content

Comment on An Alternative to Required API Keysparent

Comments

Perhaps set limits for granularities of /32, /28, /24 and /20?

Our last case of T-Online abuse originated from 79.192.0.0/10 (e.g. 79.241.205.250, 79.241.223.141, 79.241.207.37 in rapid succession) and there's not much we could do about it (we blocked the changing IPs for 15 minutes each time and hoped we didn't lose too many legitimate users who happened to get one of the blocked IPs).

Are there really enough reliable cost-free options out there to make that a massive problem?

Apparently there are hundreds of free/open proxies out there. They don't seem to change often and there are some lists of such IP adresses circulating the web, so it's possible to keep up with those. But it's a hassle...

While you can't block them (EC2)

Actually with obvious server/VPS addresses, blocking is feasible for web sites (not APIs!) because the chances that legitimate website visitors will be affected, are slim.

IPv6

Indeed, but at least the problem of rapidly changing IPv4 addresses will probably disappear there (you block the offender's /64 and he's not likely to get another quickly).

> you block the offender's /64 and he's not likely to get another quickly

That might not always be the case. The /64 I have is from a /48 and apparently I could have other /64s from that block mapped to this line if I wish (http://aa.net.uk/kb-broadband-ipv6-tech.html).

This could be an uncommong perculiarity of course, A&A are in the habit of doing things a little differently to other ISPs (usually to their customer's convenience; like offering fully delegated rDNS, which I've not heared of other UK ISPs doing, and refusing to implement ineffectial and false-positive-ridden content filtering attempts).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.