Collateral damage
Collateral damage
Posted Aug 31, 2026 22:40 UTC (Mon) by MarcB (subscriber, #101804)In reply to: Collateral damage by pizza
Parent article: Ryabitsev: Creepy crawlies
Since I work for a company that offers cloud, VPS as well as shared hosting, I know both sides.
On the scraper side:
While the outgoing traffic of those systems is higher then usual, it is still far below anything that would allow you to suspend them. Even if you do get a complaint: Any action performed by any individual VPS against any individual target is legally speaking fine. Even the (stricter) ToS rarely apply.
To add insult to injury: They always use the lowest-margin servers and turn the margin negative because of their increased bandwidth (keep in mind: the hoster gets this double, because the scraped data has to go somewhere).
We eventually resolved this by dropping those offers. Now the smallest VPS costs three times as much and is significantly stronger in CPU and memory, which scrapers do not need.
On the scrapee side:
The initial waves of crawlers were worse than any DDoS attack we faced before (and we had some big ones...), mostly because they hit the application layer instead of just the network, but also because of the highly distributed targets and sources. This invalidated decades of experience in running a large, shared hosting platform. The load patterns and resource usage was unlike anything before. We had whole server rooms exceeding their power quotas and had to do frantic redistributions between data centres - even temporary shutdowns of non-essential systems - until we had things back under control.
