If everyone would block it the website owners would have no choice other than to move to a different captcha system.
If everyone would block it the website owners would have no choice other than to move to a different captcha system.
DRINK VERIFICATION CAN
It shouldn't be the case, and I don't want to block people who have a legitimate reason to use Tor. Unfortunately there isn't a "block Tor traffic from assholes" option, so all I can really do to reduce the malicious traffic is block exit nodes.
> Unfortunately there isn't a "block Tor traffic from assholes" option
What exactly is "Tor traffic from assholes"? Bulk DDoS attacks? E-mail spam? SSH login attempts? Please share your valuable experience with everyone here, so that all of us could stay safe by learning from your example.
Most "asshole" traffic I see falls into one of two categories - attempts to exploit vulnerabilities (../../../etc/passwd stuff) and account takeover attacks.
The first I can forgive, I don't frankly care where that traffic comes from and the responsibility is entirely mine as website admin to prevent these types of attacks through good coding practices, WAF, etc.
The second I have less control over because customers / the general public sucks at security. They re-use passwords they've had for 10 years and won't opt-in to 2fa. And as a merchant, my company generally eats the cost of fraud that these attacks generally result in.
If no or little legitimate traffic is coming from Tor, and a significant percentage of malicious traffic is coming from Tor - at great cost to me / my company - why the hell would I allow it to continue?
There are many types of "abuse" (not just trolling) - mass downloading/scanning. (Ex: several types of port scanning can't be done via Tor since it doesn't support UDP)
The only way to make that happen is to stop using Chrome and tell others to do the same.
Google took over with shady practices, with the help of tech savvy people.
"It works in Chrome and Edge, which is based on Chrome, so what's your problem, again?"
And before I get accused of shilling, I hate chrome and despise Google with a passion.
It seems pretty clear from the fact that nonsense user agents like "TotallyNotMicrosoft" and "IE6" worked, that there is a blacklist, not a whitelist.
It seems pretty clear from the fact that nonsense user agents like "TotallyNotMicrosoft" and "IE6" worked, that there is a blacklist, not a whitelist.
Then maybe the standards process needs disruption. But if we don't build to standards then we are building roads that only certain cars can drive.
I also love sending him patches to show how easy it is to fix his stuff so it works in Firefox, Chrome, Edge... and of course Safari.