back

by Bender·4d ago·view on hn ↗
There are several methods. [1] The most aggressive method-02 and method-03 on my document will block VPS and some data-centers but that also means it will block some legit users that are on a VPN. Most VPNs transit a data-center. If experimenting with these methods use a test server that you do not care about and set up a dummy site and ask people in your circle of friends to test it. I have to step away for a bit but if you have questions I will try to answer.

[1] - https://nochan.net/b/Internet-Crap/20260606-How-To-Block-Som...

2 comments
Your site does not currently seem to be reachable / responsive when I try to reach it from a US Comcast IPv4 address - you are not advertising IPv6.

Edit / Update: It was Apple's Private browsing mode that causes it not to respond. I can now see it when this is disabled.

I've noticed they strip away a header [1] in private browsing mode but I don't know why they do it since it does not disclose anything about the person. I think that may be the same thing that causes some people grief on Cloudflare as well.

[1] - https://caniuse.com/?search=sec-fetch

Per your link...

> block http 1.1, real users only use 2.0

Chrome on android and Firefox on linux both appear to use 1.1 still...

By default they use 2.0 [1] unless someone or an addon disables it or unless the person is on a really old version. OperaMini however will use 1.1. No idea if anyone here uses OperaMini.

There are some reader apps that act as a proxy that only support http/1.1. Be careful, some of those are not just readers and do not trust what they claim to be the source code. Some of them are created by cute and fuzzy bunnies.

There are a number of botters on HN, some that control residential and phone browser-hijacked systems. One was sending me playful messages the other day. I enjoyed the bot block-jousting with them.

[1] - https://caniuse.com/http2

Apparently nginx didn't enable it on my new server... why it's not enabled by default, I don't know... I retract my idiocy :P
No idiocy, sometimes defaults change or don't get updated by a deployment script. Different distributions may have a slightly different default configuration file depending on how involved the artifact maintainer is with the project. Or put another way, I've done far sillier things.