Conversation

Current status: The LVFS is getting pillaged by an AI bot that's coming from *hundreds* of different IPs with a user agent of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/91.0.4472.124".

I'm impressed the LVFS handled the load spike, but I'm also planning to add support for blocking by ASN today...

3
0
0

I'm not terribly sure how; the LF uses Terraform to deploy onto AWS. @monsieuricon is this something other LF projects have done?

1
0
0

@hughsie £10 says those IPs are coming from residential networks across the planet, so good luck blocking by ASN...

1
0
0

Interestingly, the "poison pill" firmware seems to have (accidentally?) stopped the onslaught -- as soon as the IP address gets the 429 status code it completely stops -- and very soon after that (just a few minutes) all the other IP addresses on the ASN just stopped too.

0
0
0
@hughsie other projects use either Anubis or a CloudFlare based defence, yes.
0
0
1