FYI a significant chunk of Chinese IP space has been banned
Good morning everyone. Just a quick heads up that I've banned a good chunk of IP space in China due to abusive traffic.
I've tried to restrict this where possible to datacenter blocks from Huawei, Tencent, and Alibaba, but China Telecom / Mobile were also heavy sources of suspicious traffic. I doubt we have many (if any) users in China, but if you are affected please let me know.
This has been ongoing for a while and I ignored it initially since the traffic levels were low, but it wasn't anymore.
Hmm, I don't think my China blocks did, but I did also turn on Cloudflare's AI bot protection which looks like it did. I've turned that back off now. Sorry about that, thanks for pointing it out!
It's not about the load. It's about not letting the bots know they've been blocked and making them switch to residential proxies and thus making them harder to block.
Haven't done ops in a while, is there any good automated system that can block IPs on individual basis based on activity patterns? E.g. trying to login with the wrong SSH password too many times, but relevant to our use case?
Cloudflare tries, but bots do a pretty good job looking like regular users these days. There's some more advanced "AI" solutions that learn based on existing traffic patterns, but I've been out of that space for a while so not sure what the latest tech is.
Not terribly, but it would be a little more surprising if they talked from a Canadian perspective yet seemed more interested in Chinese interests than they were in Canadian interests. That also ignores the large Asian population in Canada who may still have ties with or fondness for China.