Perhaps set limits for granularities of /32, /28, /24 and /20?
Our last case of T-Online abuse originated from 79.192.0.0/10 (e.g. 79.241.205.250, 79.241.223.141, 79.241.207.37 in rapid succession) and there's not much we could do about it (we blocked the changing IPs for 15 minutes each time and hoped we didn't lose too many legitimate users who happened to get one of the blocked IPs).
Are there really enough reliable cost-free options out there to make that a massive problem?
Apparently there are hundreds of free/open proxies out there. They don't seem to change often and there are some lists of such IP adresses circulating the web, so it's possible to keep up with those. But it's a hassle...
While you can't block them (EC2)
Actually with obvious server/VPS addresses, blocking is feasible for web sites (not APIs!) because the chances that legitimate website visitors will be affected, are slim.
IPv6
Indeed, but at least the problem of rapidly changing IPv4 addresses will probably disappear there (you block the offender's /64 and he's not likely to get another quickly).
> you block the offender's /64 and he's not likely to get another quickly
That might not always be the case. The /64 I have is from a /48 and apparently I could have other /64s from that block mapped to this line if I wish (http://aa.net.uk/kb-broadband-ipv6-tech.html).
This could be an uncommong perculiarity of course, A&A are in the habit of doing things a little differently to other ISPs (usually to their customer's convenience; like offering fully delegated rDNS, which I've not heared of other UK ISPs doing, and refusing to implement ineffectial and false-positive-ridden content filtering attempts).
Comments
Our last case of T-Online abuse originated from 79.192.0.0/10 (e.g. 79.241.205.250, 79.241.223.141, 79.241.207.37 in rapid succession) and there's not much we could do about it (we blocked the changing IPs for 15 minutes each time and hoped we didn't lose too many legitimate users who happened to get one of the blocked IPs).
Apparently there are hundreds of free/open proxies out there. They don't seem to change often and there are some lists of such IP adresses circulating the web, so it's possible to keep up with those. But it's a hassle...
Actually with obvious server/VPS addresses, blocking is feasible for web sites (not APIs!) because the chances that legitimate website visitors will be affected, are slim.
Indeed, but at least the problem of rapidly changing IPv4 addresses will probably disappear there (you block the offender's /64 and he's not likely to get another quickly).
> you block the offender's /64 and he's not likely to get another quickly
That might not always be the case. The /64 I have is from a /48 and apparently I could have other /64s from that block mapped to this line if I wish (http://aa.net.uk/kb-broadband-ipv6-tech.html).
This could be an uncommong perculiarity of course, A&A are in the habit of doing things a little differently to other ISPs (usually to their customer's convenience; like offering fully delegated rDNS, which I've not heared of other UK ISPs doing, and refusing to implement ineffectial and false-positive-ridden content filtering attempts).