|
|
Log in / Subscribe / Register

IP blocks should be neither authentication nor authorization

IP blocks should be neither authentication nor authorization

Posted Jul 13, 2026 10:43 UTC (Mon) by paulj (subscriber, #341)
In reply to: IP blocks should be neither authentication nor authorization by quotemstr
Parent article: An update on the scraper situation

Indeed. This is fundamentally a spam / sybil attack problem. And ultimately it requires a web architecture with some protections against this. Proof of interactive humanity may not always be enough. It may stop higher-rate crawlers, but it will not allow one to stop human-bot-farms (if one wished). In some cases, someone may wish to deny lower-rate human-bot-farms too; in other cases it might not matter.

We need some kind of privacy architecture for the Internet that allows for different levels commitment by the resource accessor to the resource owner and hosters. E.g., a commitment of humanness; a commitment of a pseudonymous, longer-term, more stable identity with some reputation attached; a commitment of financial resources (i.e., some micro-payment that is paid, or some bond that is committed towards good behaviour on the network); a commitment of real identity, verified by some reputable body (either provided up-front, or revealable by the reputable body if some bad behaviour is reported).

And absolutely, we need to build this on relatively distributed and private protocols. For if we do not, we will have that de facto Cloudflare gatekeeper you mention.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds