@monsieuricon When I reply to your email after this work task, I will include Tor hidden service suggestions for 0-hop hidden services to make that hidden service more responsive
@monsieuricon is there a reason to think the botnets wouldn't just start running tor themselves, or is this just a workaround until they do?
@monsieuricon it depends if they think of and are willing to trust one of those clearnet tor web proxies, I suppose. that would presumably be very easy for them until they overwhelm those as well.
@qyliss @monsieuricon yeah it seems reasonable to do but, what Alyssa said
@monsieuricon the eventual outcome is probably just more load on the Tor network. That potentially has upsides for Tor as well though, because it helps normalize Tor (maybe especially so in the case of these "residental proxies" which AIUI are just normal people's devices). Would be interesting to know Tor network maintainers' opinions.
@monsieuricon I suppose the actual content we're talking about here are not very big, just expensive to generate, so maybe it wouldn't be noticeable Tor traffic anyway.
@qyliss @monsieuricon You're assuming the bots are run by rational actors that are actively monitoring what they are scraping. They are not. They are headless, soulless automatons that just click every link on every link on every link over and over with the biggest queue backlog you can possibly imagine times 10,000. Any barrier to entry is probably too much, and I'd be willing to bet they're using Headless Google Chrome.
@jeroen @monsieuricon @qyliss @cadey I like the idea... Mutual TLS auth, certs require a valid email to generate, you can then block emails or even entire domains that abuse the service. 401 error links to the certificate generation service.