{"id":1598,"date":"2024-03-19T00:19:07","date_gmt":"2024-03-19T04:19:07","guid":{"rendered":"https:\/\/www.rfdm.com\/blog\/?p=1598"},"modified":"2024-03-19T00:19:07","modified_gmt":"2024-03-19T04:19:07","slug":"big-tech-arms-race-is-out-of-control-its-time-to-bolster-defenses","status":"publish","type":"post","link":"https:\/\/www.rfdm.com\/blog\/?p=1598","title":{"rendered":"Big Tech arms race is out of control; it&#8217;s time to bolster defenses"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I recently posted about doing my annual web log perusal and adding more networks to the list which I block from accessing my web server.  Until 2021 or so, most of the networks I added were what I&#8217;d consider hostile netizens, and most of them in foreign countries (China far and away the worst offender, followed by Russia, Singapore, Hong Kong and others).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Around 2021 (maybe earlier), I started seeing more attacks coming from cloud infrastructure.  Today, after my first full pass of changes (March 17, 2024), it&#8217;s the majority.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As an aside, how do I know that many of the adversaries are foreign?  Well, after my first pass of changes, it&#8217;s pretty clear that a lot of them were far away (by network round-trip time).  Below are plots of traffic and round trip times to clients of my web server, from before my changes and right after my changes.  Note how the 95th and 75th percentile round trip times dropped dramatically.  That&#8217;s because many of the nefarious users were far away.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240318.png\"><img loading=\"lazy\" decoding=\"async\" width=\"782\" height=\"1024\" src=\"https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240318-782x1024.png\" alt=\"\" class=\"wp-image-1600\" srcset=\"https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240318-782x1024.png 782w, https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240318-229x300.png 229w, https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240318-768x1006.png 768w, https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240318-1173x1536.png 1173w, https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240318.png 1394w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s worth noting that much of my traffic is local to my home.  I have many Raspberry Pis and other hosts running my &#8216;mcrover&#8217; software, and one of the things it does it monitor my web server, including queries to my blog and the gallery software for Randy&#8217;s site since they have database backends I want to be sure are running.  This background monitoring traffic works out to about 80 kilobits\/second on average.  The round trip time for this traffic is tiny; for some hosts it&#8217;s sub-millisecond since they have 10 gigabit connections (DAC, fiber or 10GbaseT).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Back to the topic at hand&#8230;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Late last year I got a question via email from a customer at DigitalOcean as to why I had blocked their access.  I didn&#8217;t reply.  I&#8217;ve come to the conclusion that if users won&#8217;t police themselves, and their cloud provider won&#8217;t police their users (and expects us to help them do the policing!), neither deserve my time.  If you, or your customer, are getting 404&#8217;s from my website for URLs like &#8216;\/login.php&#8217; (which doesn&#8217;t exist and has never existed on my site), you&#8217;re either a criminal or an accomplice.  Neither of you deserve my time.  Your activities are hostile, period.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since 2021 or so, the more disturbing trend I see seems to be driven by the AI arms race in big tech.  Microsoft (and OpenAI), Google and Apple crawling my web site with more frequency, and pulling everything they can find.  PDFs, all images, etc.  There was a time when I considered it OK, in the sense that it was used only for search purposes, which at least gives back a bit to the web as a whole (search is a useful service, despite the mess it has become).  But today, it&#8217;s pretty clear to me that the snarfing of data by big tech is not balanced by a benefit to users of the web.  It&#8217;s also quite aggressive.  How do I benefit from Microsoft downloading every PDF and image that&#8217;s on my web site?  I don&#8217;t.  I lose (I pay for my bandwidth), they profit.  There is literally zero benefit to me, or you unless you&#8217;re Microsoft or OpenAI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;ve grown tired of this.  I&#8217;m not interested in feeding the LLMs, much less allowing cloud infrastructure to be leveraged against my web site.  So as of this week, anytime I happen to be doing some block list maintenance and see traffic from a cloud service or big tech, the network will be blocked.  And not just small chunks; the entire CIDR allocation.  And not just for a short period of time; 2 years.  If you manage to get your act together 2 years from now, great.  If not, you&#8217;ll be blocked for 2 more years.  I anticipate the latter, since that&#8217;s been the steady course for the last 7 years.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;ve already blocked large swaths of Amazon, Microsoft, Google, DigitalOcean, Linode, Hetzner, Hurricane Electric, OVH and other cloud services.  There is literally no reason I should see requests from any of these address spaces.  They&#8217;re not human beings reading my web pages.  They are nefarious automation, and not policed by the cloud providers.  We are the victims.  Ideally the cloud providers would be using deep packet inspection and proactively shut down such activities.  But if no one is going to jail for their paying customers&#8217; illicit activities&#8230; nothing gets done.  And most of us don&#8217;t have time to do the policing for them.  It&#8217;s MUCH faster for me to just block the cloud provider&#8217;s entire address space.  I&#8217;m not going to play wack-a-mole, nor serve as their unpaid reporter of nefarious activity they&#8217;re enabling.  A simple buh-bye to the cloud provider and all of their customers is my far and away best option.  This isn&#8217;t a rash decision on my part; I&#8217;ve seen nefarious traffic from the cloud providers for many years, and given that they hold gobs of address space, it&#8217;s futile to block only small parts.  The only sane course is to block all of their address space.  In particular, I&#8217;m talking to you Amazon, Google, DigitalOcean, Hetzner, Linode, Microsoft and OVH. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is highly likely that I&#8217;ll soon be blocking crawler address space belonging to Google, Apple, Microsoft and others.  Sad but true that the benefit of being indexed by search engines has finally been eclipsed by the downsides of allowing unfettered access from big tech.  robots.txt doesn&#8217;t get us there because it doesn&#8217;t have the granularity we need, and the reality is that many of the crawlers don&#8217;t even bother to look at it.  Worse, how are we as web site admins supposed to be able to determine how the data is being used?  If the request is coming from Google crawler address space, is it for search or for feeding their LLMs?  Or for sale to a third party?  Or for driving their ad revenue?  The reality is that we don&#8217;t know, and have no means of knowing.  I&#8217;d rather my web site disappear from search than have all of my web site data used against me in some manner (which includes directed advertising).  And I&#8217;m tired of the amount of bandwidth it consumes.  Google alone is responsible for over 3,000 downloads from my web site per week.  Honestly, it&#8217;s pretty disgusting.  My site is a TINY personal web site, mostly for my own use.  I can&#8217;t imagine the barrage of traffic from Google to large web sites.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you happen to be a victim of the more aggressive blocking I&#8217;m about to start and the automation that will maintain it long term, my apologies.  But I&#8217;m unlikely to be sympathetic to pleas for access.  If your neighbor attacks my site and my automation blocks the network you share with them as a result&#8230; I am truly sorry, but I don&#8217;t have time to poke tiny holes as exceptions.  I&#8217;ll likely leave the 30 day with geometric escalation policy in place for U.S. broadband users, but if you&#8217;re using a VPN through a cloud provider and someone else uses that provider to abuse my web site&#8230; you&#8217;ll be out of luck for much longer.  Again, my apologies.  If you want to do something about what&#8217;s been happening for years on this front that&#8217;s forcing some of us to block large swaths of cloud provider space and probably soon the web crawlers of Google, Microsoft, Apple and others&#8230; reach out to your legislators.  If you&#8217;re in the U.S., maybe just making them aware that cloud services on U.S. soil are being used every minute of every day to attack law abiding, tax paying citizens who just want to share knowledge with other citizens.  Good luck, godspeed, live long and prosper.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I recently posted about doing my annual web log perusal and adding more networks to the list which I block from accessing my web server. Until 2021 or so, most of the networks I added were what I&#8217;d consider hostile netizens, and most of them in foreign countries (China far and away the worst offender, &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.rfdm.com\/blog\/?p=1598\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Big Tech arms race is out of control; it&#8217;s time to bolster defenses&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[85,86,12,13],"tags":[],"class_list":["post-1598","post","type-post","status-publish","format-standard","hentry","category-network-security","category-networks","category-software-development","category-web-development"],"_links":{"self":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1598"}],"version-history":[{"count":2,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1598\/revisions"}],"predecessor-version":[{"id":1601,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1598\/revisions\/1601"}],"wp:attachment":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}