• iopq@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    6
    ·
    16 hours ago

    Ever heard of counting attempts? Log the IP, present a CAPTCHA after 100 requests in a minute.

    Besides, if I wrote a bot I would run a browser dialer from Chrome. It would request your site in a Chrome tab and appear completely legitimate to your stupid fingerprinting scripts

    • Saik0@lemmy.saik0.com
      link
      fedilink
      English
      arrow-up
      13
      ·
      13 hours ago

      Ever heard of counting attempts? Log the IP, present a CAPTCHA after 100 requests in a minute.

      Ever heard of IP rotation? This is one malicious source rotating through IPs over the course of 24 hours. They’re attempting to credential stuff my logins ( on a production service ).

    • SerotoninSwells@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      16 hours ago

      Yes, the industry is well aware of this. We do behavioral detection on both sessions and IPs. This is fairly basic.

      • iopq@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        49 minutes ago

        Yeah, it’s fine as long as you don’t block legitimate users. For example, when I use a VPN a lot of sites block me. Even when my actual IP is banned when I’m in China (4chan range bans Chinese IPs) or the website is blocked in China.