RustyCrab,
@RustyCrab@clubcyberia.co avatar

Serious question: if you're running a website should you just block India by default?

binkle,
@binkle@clubcyberia.co avatar
dj,
@dj@parcero.bond avatar

@RustyCrab
I recommend blocking the entire continent of Asia.

RustyCrab,
@RustyCrab@clubcyberia.co avatar

@dj would that include Russia though because I definitely want them :blobcatmoustache:

dj,
@dj@parcero.bond avatar

@RustyCrab
You can make exceptions, but there's lots of hackers and scammers in Russia. Most have to use VPN to access western services anyway. I've got all of Asia minus Japan blocked in cloudflare firewall. I can't read Jap script so I might block them anyway, too many pedos.

syzygy,
@syzygy@gh0st.live avatar

@dj @RustyCrab
>cloudflare firewall
BOAT CLICKERS GET THE FUCKING ROPE.

RustyCrab,
@RustyCrab@clubcyberia.co avatar

@dj you definitely get interesting users from Japan when they do speak english, but yes, that is a serious problem. I'm wondering if that's just a fediverse thing or a national plague

pwm,
@pwm@crlf.ninja avatar

@RustyCrab drop the entirety of apnic
Non English speakers get to use a vpn

sepples,
@sepples@pone.social avatar

@RustyCrab
The Jap boomer method. It's a tempting but really lazy and ineffective solution that won't protect you from more serious threats. It will work to block most jeets, but is trivially easy to get around with VPNs or proxies.

Really you should be set up with rate-limiting, fail2ban, and other gatekeeping systems to protect you from attacks generically. If your website is tight-knit enough, it's best to go invite-only.

RustyCrab,
@RustyCrab@clubcyberia.co avatar

@sepples yeah there's obviously ways around that. Most of the time from what I have seen though they just don't even bother. You just block IPs and that's usually the end of it.

Much of the time they're not targeting you in particular but they are doing mass scraping of half the internet and if you fall off the results list they don't even notice.

sepples,
@sepples@pone.social avatar

@RustyCrab Ok, just don't say you weren't warned when you start getting hammered from AWS us-east-1 and Hetzner Nuremberg.

deprecated_ii,
@deprecated_ii@poa.st avatar

@RustyCrab reasonable

syzygy,
@syzygy@gh0st.live avatar

@RustyCrab
Best to block India, SEA, and south America.

RustyCrab,
@RustyCrab@clubcyberia.co avatar

@syzygy idk there's some pretty funny south american users. Indians are just living spambots most of the time

syzygy,
@syzygy@gh0st.live avatar

@RustyCrab
Yeah but you might get a Brazilian.

phnt,
@phnt@fluffytail.org avatar

@RustyCrab Probably yes, especially when self hosting a forge with open registrations.

RustyCrab,
@RustyCrab@clubcyberia.co avatar

@phnt I don't think I've ever seen a user from India that did anything besides spam

mischievoustomato,
@mischievoustomato@rebased.taihou.website avatar

djsumdog and tiskaan aren't spammers...

RustyCrab,
@RustyCrab@clubcyberia.co avatar

@mischievoustomato @phnt are they IN India though? I'm not taking about race in this case but actual nationality

mischievoustomato,
@mischievoustomato@rebased.taihou.website avatar

oh, neither are from what i c

phnt,
@phnt@fluffytail.org avatar

@RustyCrab And advertising FAANG.

mischievoustomato,
@mischievoustomato@rebased.taihou.website avatar

depends, but a friend's company blocked europe once gdpr rolled out and that was less annoying

phnt,
@phnt@fluffytail.org avatar

@mischievoustomato @RustyCrab Imagine not wanting to enable cookie selection and instead block Europe. GDPR is so easy to bypass and people don't even bother.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • Hentai
  • doujinshi
  • announcements
  • general
  • All magazines