> "In the process of mitigating, migrating, and updating things, we’ve made a lot of upgrades and improvements to the wiki and infrastructure: Automatic blocking of many bots and other nuisances, including Tor exit nodes"
Is this supposed to be a good thing? What's the point of blocking Tor here?
There are only so many days one wants to wake up and click "delete user" 20 times for the latest batch of slur-filled trash from tor-exit-48012480.r0ck3t.ballz.
Depending on the scale of the volumetric attack, you do have other options. There's plenty of low end hosts selling 'unmetered' 10G severs. I'd bet most attacks are smaller than that. It may take some tuning to drop garbage that fast, but it's doable on 10 year old hardware. My bet is most of these unmetered servers are using for outbound, and the inbound directly is underutilized... so the host probably won't mind as long as the volume isn't too big... If you consistently get DDoSed, maybe it helps your host have balanced in and out and that may qualify them to peer with networks that have a lot of botted hosts.
If you get more than 10G inbound garbage, you can try renting multiple servers and round robin DNS...
DIY options beyond that are going to be spendy. You'd need to get an ASN, an IP allocation, and BGP privileges... Start advertising your IP range from all your 10G servers and that will distribute the garbage at least a little.
This guy sounds like he has spent way too much time online getting angry at imaginary enemies, and really needs to get outside and talk to some real people outside of his filter bubble.
I actually enjoy reading TCRF, so it’s unfortunate that the owner is apparently a terminally online insane person.
This story has been escalating for over a year at this point. Originally, identified bots were given a generic "access denied" message. Then a special generic "LLM poison"-type page (some joke misinformation). Once I noticed that Claude-Code bots, specifically, were evading those blocks -- making one request, then changing their user-agent and trying again -- I started adding the persistent ban for bot misbehavior.
That you didn't know any of this until now suggests, I think, that there isn't really much of a problem. After all, this only affects agents reporting as Claude-Code.
The primary goal my side of this has been to interrupt and annoy LLM/AI users, and to that it has been working incredibly well.
My previous blog post, written before this DDoS attack, went into some of the challenges of being an independent website that avoided using third-party services (outside of Linode, our host). Cloudflare was always my "last resort" — I actually signed up for an account there a bit over a year ago, during an earlier attack — and it finally became time to use that last resort.
As for "terminally online", I guess you could say guilty as charged. I've been running communities for over 20 years and TCRF specifically for nearly 17, longer than a lot of our users have been alive. It certainly gets results.
Other tools either run off of a central cloud provider, in which case they get the standard anti-AI page, or mask as a "legitimate" user agent, in which case I leave it up to the captcha/challenge.
The insane part is launching a DDoS attack because some guy online insulted your favorite toy.