HN is penalizing Tor users
I am human. Thanks.
I am human. Thanks.
(1) Rate-limiting: My regular account (this is a throwaway) has thousands in karma, but after around 4 comments I still get the 'you're posting too fast' rate limiter. Perhaps HN could disable rate-limiting after the Tor user has a certain amount of karma.
(2) Comments seem penalized, starting in the middle of threads instead of at the top. This issue has come and gone a couple of times (it's happening now on my regular account). It seems to stop when I have had an interaction with the mods; I wonder if they notice and disable it. It seems to restart after I get several downvotes in a short period; perhaps that triggers some algorithm which decides that comments over Tor are shady.
(3) Registering accounts requires a captcha and is frustrating, though something I rarely have to deal with. To register this throwaway account I got a captcha, completed it, approved. HN said the username as taken, and when I entered another username the process started over - another captcha. Then the username was too long, so I started over again.
I am currently rate-limited, I have been on rate-limiting before, and I've had my rate-limiting disappear. This has more to do with how happy (or unhappy, as the case is) the mods are with your commenting habits than what browser you are using. I do not know if your rate limit penalty has an expiration date or if they manually remove you, HN mods rarely if ever discuss rate limiting, but it is almost surely to curb what HN mods consider poor quality comments and ensure they don't overwhelm a discussion.
Being rate limited is annoying, so I appreciate the even-handedness in what you wrote.
Sorry. I'll copy it to its own thread. HN can blame itself for the spam (unless they block me from posting it anew, too.)
My preferred app is https://f-droid.org/wiki/page/com.manuelmaly.hn but that stopped working today around the same time chromium captchaed me.
94% of the requests Cloudflare saw over Tor were malicious[1], but rather than block Tor, they implemented a couple of ways to prove you are part of the 6%, including a browser extension[2] that can get you out of the CAPTCHAs.
[1] https://blog.cloudflare.com/the-trouble-with-tor/
[2] https://blog.cloudflare.com/cloudflare-supports-privacy-pass...
Most clearly malicious traffic to my servers is not Tor, but most Tor traffic is malicious. This is what I see to my servers, you may see different traffic on your servers.
There are other ways to solve these problems. As just one example you could support protocols like U2F or FIDO2 that take brute forcing off the table, and the brute forcers go away.
As another example I offer free unix shell services to the general public. Lots of people were using Tor to create accounts for cryptocurrency mining. Instead of banning Tor I blocked all outgoing traffic to all major mining pools. The mining abuse stopped.
Try to find ways to remove the incentive for bad behaviour, rather than throwing out the good with the bad.