• Randomgal@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    12 days ago

    I’m glad we’re burning the forests even faster in the name of identity politics.

  • x0x7@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    Jokes on them. I’m going to use AI to estimate the value of content, and now I’ll get the kind of content I want, though fake, that they will have to generate.

    • Slaxis@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      The problem is, how? I can set it up on my own computer using open source models and some of my own code. It’s really rough to regulate that.

  • XeroxCool@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Will this further fuck up the inaccurate nature of AI results? While I’m rooting against shitty AI usage, the general population is still trusting it and making results worse will, most likely, make people believe even more wrong stuff.

  • weremacaque@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    12 days ago

    You have Thirteen hours in which to solve this labyrinth before your baby AI becomes one of us, forever.

  • RelativeArea1@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    this is some fucking stupid situation, we somewhat got a faster internet and these bots messing each other are hugging the bandwidth.

    • IninewCrow@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      13 days ago

      It’s what I’ve been saying about technology for the past decade or two … we’ve hit an upper limit to our technological development … that limit is on individual human greed where small groups of people or massively wealthy people hinder or delay any further development because they’re always trying to find ways to make money off it, prevent others from making money off it, monopolize an area or section of society … capitalism is literally our world’s bottleneck and it’s being choked off by an oddly shaped gold bar at this point.

    • dual_sport_dork 🐧🗡️@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      13 days ago

      Especially since the solution I cooked up for my site works just fine and took a lot less work. This is simply to identify the incoming requests from these damn bots – which is not difficult, since they ignore all directives and sanity and try to slam your site with like 200+ requests per second, that makes 'em easy to spot – and simply IP ban them. This is considerably simpler, and doesn’t require an entire nuclear plant powered AI to combat the opposition’s nuclear plant powered AI.

      In fact, anybody who doesn’t exhibit a sane crawl rate gets blocked from my site automatically. For a while, most of them were coming from Russian IP address zones for some reason. These days Amazon is the worst offender, I guess their Rufus AI or whatever the fuck it is tries to pester other retail sites to “learn” about products rather than sticking to its own domain.

      Fuck 'em. Route those motherfuckers right to /dev/null.

      • desktop_user@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        0
        ·
        13 days ago

        the only problem with that solution being applied to generic websites is schools and institutions can have many legitimate users from one IP address and many sites don’t want a chance to accidentally block one.

      • Buelldozer@lemmy.today
        link
        fedilink
        English
        arrow-up
        0
        ·
        13 days ago

        and try to slam your site with like 200+ requests per second

        Your solution would do nothing to stop the crawlers that are operating 10ish rps. There’s ones out there operating at a mere 2rps but when multiple companies are doing it at the same time 24x7x365 it adds up.

        Some incredibly talented people have been battling this since last year and your solution has been tried multiple times. It’s not effective in all instances and can require a LOT of manual intervention and SysAdmin time.

        https://thelibre.news/foss-infrastructure-is-under-attack-by-ai-companies/

        • confusedbytheBasics@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          13 days ago

          Yep. After you ban all the easy to spot ones you’re still left with far too many hard to ID bots. At least if your site is popular and large.

        • dual_sport_dork 🐧🗡️@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          13 days ago

          It’s worked alright for me. Your mileage may vary.

          If someone is scraping my site at a low crawl rate I honestly don’t care so long as it doesn’t impact my performance for everyone else. If I hosted anything that was not just public knowledge or copy regurgitated verbatim from the bumf provided by the vendors of the brands I sell, I might oppose to it ideologically. But I don’t. So I don’t.

          If parallel crawling from multiple organizations legitimately becomes a concern for us I will have to get more creative. But thus far it hasn’t, and honestly just wholesale blocking Amazon from our shit instantly solved 90% of the problem.

      • QuarterSwede@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        12 days ago

        The problem you aren’t recognizing is that, until humans are no longer driven by self preservation, there will always be oppression in any system. They all have and will continue to breakdown. It’s easy to blame capitalism but even socialist systems eventually cave under the weight of greed and power. We are the problem mon frère.

            • Val@lemm.ee
              link
              fedilink
              English
              arrow-up
              0
              ·
              13 days ago

              So here’s a little bit of lemmy lore for you. You’re instance lemmy.ml is considered to be a tankie instance by some users. lemmy.dbzer0.com is an anarchist instance. The user you responded to probably made a generalisation based on this and assumed you were familiar with anarchist/communist/socialist/leftist discourse. From this comment I assume they were wrong.

              So on behalf of no-one but myself: Hello! Welcome to Anarchism! The belief that authority should not exist. This belief comes from a lot of different places and wears a lot of different faces. Most short explanations aren’t sufficient and long explanation bore most. If you don’t mind a little learning here is a link: https://anarchistfaq.org/afaq/sectionA.html#seca1 and another one https://crimethinc.com/2016/09/28/feature-the-secret-is-to-begin-getting-started-further-resources-frequently-asked-questions#faq or if you like videos: https://youtu.be/lrTzjaXskUU.

              Also a little bit about authority: people use authority to mean many things (this is even bought up in the video I linked above). But as far as anarchists are concerned (in general (no specific statement can be made about a group so vast)) authority is the act of coercing people to follow orders or commit involuntary acts. You’re boss can coerce you to neglect your health by threatening to fire you. Your government can force you to obey gender roles by threatening to jail you. A rich person can make you do whatever demeaning thing they want by dangling money in front of you (for reference see mrbeast) because otherwise your landlord will kick you out. This is authority and it is wrong. Those in authority can make mistakes, become greedy and start to think they have the power to do whatever they want (mostly because they can). This leads to suffering. My meaning of life is to minimise suffering. Anarchy is the belief that no-one should hold power over others. That all leadership should be scrutinised. It rejects blind faith in single people and encourages to think for yourself so no-one can do you wrong. And if you can’t be bothered, it encourages you to find people who genuinely care about you and let them stand up for you.

              • morrowind@lemmy.ml
                link
                fedilink
                English
                arrow-up
                0
                ·
                13 days ago

                Thanks, I don’t really care for generalizing instances and didn’t really have a choice when I made my account.

                But also your definition is impossibly broad as you well and I’m pretty sure not the general consensus. The video doesn’t define it as such either.

                For one thing, by your definition we can have absolutely no meaningful human relationships. I can explain this more later when I have time if you don’t see what I mean

                • Val@lemm.ee
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  12 days ago

                  My explanation of authority wasn’t meant as a definition but rather a brief summarisation of a complex concept, Andrew does a better job actually explaining it. Like pointing out that Authority is confused with a lot of different concepts like respect or influence. Which I’m starting to suspect is happening here. meaningful human relationships are based on mutual respect. This is not authority as it is voluntary, reciprocated and revoked as soon as the other party steps over the line. This is what I believe is the basis of society and what we need to return to in order to live a truly free life. In modern society in most interactions respect has been replaced with authority. People in positions of power even use them synonymously.

      • IrateAnteater@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        13 days ago

        That’s not really relevant here. This is more of a “genie is out of the bottle and now we have to learn how to deal with it situation”. The idea and technology of bots and AI training already exists. There’s no socioeconomic system that is going to magically make that go away.

        • limer@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          0
          ·
          13 days ago

          He is not wrong. Unless people start to take steps , the dependency of tech will be used to chain most of us. Granted, these chains will be the kindest and gentlest chains seen in a long time.

          Social revolution lives on in decentralized services, like this; the true battles will be later though. This year is a mild warm up. I can’t imagine the challenges that await many

    • Dr. Moose@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 days ago

      Lol website traffic accounts for like 1% of bandwidth budget. 1 netflix movie is like 20k web pages.

  • Deebster@infosec.pub
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    So they rewrote Nepenthes (or Iocaine, Spigot, Django-llm-poison, Quixotic, Konterfai, Caddy-defender, plus inevitably some Rust versions)

    • zovits@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      It certainly sounds like they generate the fake content once and serve it from cache every time: “Rather than creating this content on-demand (which could impact performance), we implemented a pre-generation pipeline that sanitizes the content to prevent any XSS vulnerabilities, and stores it in R2 for faster retrieval.”

  • lily33@lemm.ee
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    while allowing legitimate users and verified crawlers to browse normally.

    What is a “verified crawler” though? What I worry about is, is it only big companies like Google that are allowed to have them now?

      • lily33@lemm.ee
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        13 days ago

        Any accessibility service will also see the “hidden links”, and while a blind person with a screen reader will notice if they wonder off into generated pages, it will waste their time too. Especially if they don’t know about such “feature” they’ll be very confused.

        Also, I don’t know about you, but I absolutely have a use for crawling X, Google maps, Reddit, YouTube, and getting information from there without interacting with the service myself.

  • Dr. Moose@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    12 days ago

    Considering how many false positives Cloudflare serves i see nothing but misery coming from this.

    • Dave@lemmy.nz
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 days ago

      In terms of Lemmy instances, if your instance is behind cloudflare and you turn on AI protection, federation breaks. So their tools are not very helpful for fighting the AI scraping.

        • Dave@lemmy.nz
          link
          fedilink
          English
          arrow-up
          0
          ·
          12 days ago

          I’m not sure what can be done at the free tier. There is a switch to turn on AI not blocking, and it breaks federation.

          You can’t whitelist domains because federation could come from and domain. Maybe you could somehow whitelist /inbox for the ActivityPub communication, but I’m not sure how to do that in Cloudflare.

    • Xella@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 days ago

      Lol I work in healthcare and Cloudflare regularly blocks incoming electronic orders because the clinical notes “resemble” SQL injection. Nurses type all sorts of random stuff in their notes so there’s no managing that. Drives me insane!

  • _cryptagion [he/him]@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Now this is a AI trap worth using. Don’t waste your money and resources hosting something yourself, let Cloudflare do it for you if you don’t want AI scraping your shit.

  • DigitalDilemma@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    12 days ago

    Surprised at the level of negativity here. Having had my sites repeatedly DDOSed offline by Claudebot and others scraping the same damned thing over and over again, thousands of times a second, I welcome any measures to help.

    • dan@upvote.au
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 days ago

      thousands of times a second

      Modify your Nginx (or whatever web server you use) config to rate limit requests to dynamic pages, and cache them. For Nginx, you’d use either fastcgi_cache or proxy_cache depending on how the site is configured. Even if the pages change a lot, a cache with a short TTL (say 1 minute) can still help reduce load quite a bit while not letting them get too outdated.

      Static content (and cached content) shouldn’t cause issues even if requested thousands of times per second. Following best practices like pre-compressing content using gzip, Brotli, and zstd helps a lot, too :)

      Of course, this advice is just for “unintentional” DDoS attacks, not intentionally malicious ones. Those are often much larger and need different protection - often some protection on the network or load balancer before it even hits the server.

      • DigitalDilemma@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        11 days ago

        Already done, along with a bunch of other stuff including cloudflare WAF and rate limiting rules.

        I am still annoyed that it took me over a day’ of my life to finally (so far) restrict these things. And several other days to offload the problem to Cloudflare pages for sites that I previous self hosted but my rural link couldn’t support.

        this advice is just for “unintentional” DDoS attacks, not intentionally malicious ones.

        And I don’t think these high volume AI scrapes are unintentional DDOS attacks. I consider them entirely intentional. Not deliberrately malicious, but negligent to the point of criminality. (Especially in requesting the same pages again so frequently, and all of them ignoring robots.txt)

  • finitebanjo@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Cloudflare kind of real for this. I love it.

    It makes perfect sense for them as a business, infinite automated traffic equals infinite costs and lower server stability, but at the same time how often do giant tech companies do things that make sense these days?

  • nyan@lemmy.cafe
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Will it actually allow ordinary users to browse normally, though? Their other stuff breaks in minority browsers. Have they tested this well enough so that it won’t? (I’d bet not.)