this post was submitted on 21 Mar 2025
124 points (98.4% liked)

Linux

6583 readers
506 users here now

A community for everything relating to the GNU/Linux operating system

Also check out:

Original icon base courtesy of [email protected] and The GIMP

founded 2 years ago
MODERATORS
 

LLM scrapers are taking down FOSS projects' infrastructure, and it's getting worse.

all 23 comments
sorted by: hot top controversial new old
[–] [email protected] 1 points 46 minutes ago

Whats confusing the hell out of me is: why are they bothering to scrape the git blame page? Just download the entire git repo and feed that into your LLM!

9/10 the best solution is to block nonresidential IPs. Residential proxies exist but they're far more expensive than cloud proxies and providers will ask questions. Residential proxies are sketch AF and basically guarded like munitions. Some rookie LLM maker isn't going to figure that out.

Anubis also sounds trivial to beat. If its just crunching numbers and not attempting to fingerprint the browser then its just a case of feeding the page into playwright and moving on.

[–] [email protected] 46 points 10 hours ago* (last edited 10 hours ago) (1 children)

Wow that was a frustrating read. I dd not know it was quite that bad. Just to highlight one quote

they don’t just crawl a page once and then move on. Oh, no, they come back every 6 hours because lol why not. They also don’t give a single flying fuck about robots.txt, because why should they. [...] If you try to rate-limit them, they’ll just switch to other IPs all the time. If you try to block them by User Agent string, they’ll just switch to a non-bot UA string (no, really). This is literally a DDoS on the entire internet.

[–] [email protected] 19 points 10 hours ago (2 children)

the solution here is to require logins. thems the breaks unfortunately. it'll eventually pass as the novelty wears off.

[–] [email protected] 5 points 7 hours ago (1 children)

Alternative: require a proof of work calculation.

[–] [email protected] 2 points 5 hours ago (1 children)

This is exactly what we need to do. You'd think that a FOSS WAF exists out there somewhere that can do this

[–] [email protected] 1 points 5 hours ago (2 children)

There is. That screenshot you see in the article is a picture of a brand new one, Anubis

[–] [email protected] 2 points 3 hours ago

Yeah I realised that after posting. I think we need a better one to deal with the cases of letting legitimate users in easier though

[–] [email protected] 1 points 3 hours ago

It kind of sucks but it is the best we have for the moment

[–] [email protected] 8 points 10 hours ago (2 children)

Next you'll have to invest in preventing automated signups

[–] [email protected] 2 points 5 hours ago

not really, just tie it with 2fa SMS style and the hurdle is large enough most companies won't bother.

[–] [email protected] 3 points 10 hours ago (1 children)

Signups in most platforms are quite hard. Straight up give your phone and do SMS verification, or at least give email and to register that email you will have to provide phone anyway. Captchas nowadays became so hard that even humans struggle with them and it often takes multiple attempts to get it right.

[–] [email protected] 1 points 1 hour ago

provide phone number to look at this foss project's website, not too sure about that

[–] [email protected] 2 points 5 hours ago (2 children)

I'm perfectly fine with Anubis but I think we need a better algorithm for PoW

[–] [email protected] 1 points 4 hours ago* (last edited 3 hours ago) (1 children)

Tor has one now

Maybe it can be reused for the clearnet.

[–] [email protected] 1 points 3 hours ago (1 children)
[–] [email protected] 1 points 3 hours ago* (last edited 3 hours ago) (1 children)

And Tor itself

It is part of the denial of service protection

[–] [email protected] 1 points 3 hours ago

That's neat

[–] [email protected] 16 points 10 hours ago

This is the most crazy read on subject in a while. Most articles just talk about hypothetical issues of tomorrow, while this one actually full of today's problems and even costs of those issues in numbers and hours of pointless extra work. Had no idea it's already this bad.

[–] [email protected] 3 points 7 hours ago (1 children)

How much you wanna bet that at least part of this traffic is Microsoft just using other companies infrastructure to mask the fact that it’s them

[–] [email protected] 2 points 3 hours ago

I doubt it since Microsoft is big enough to be a little more responsible.

What you should be worried about is the fresh college graduates with 200k of venture capital money.

[–] [email protected] 3 points 9 hours ago (1 children)

Sometimes, I hate humanity.

[–] [email protected] 9 points 8 hours ago

just hate the techbros