Arxiv.org is experiencing a DDoS attack
blog.arxiv.org
blog.arxiv.org
Does anyone here have experience working with an ISP in abuse cases like this one, specially a Chinese ISP?
I think this article is misleading; there's nothing terribly "distributed" about the DoS.
Happy to help discussing mitigation techniques. Long time user of ArXiv. Email in Bio.
y
That's it. Beautiful.To reproduce
curl https://x.com/username
curl https://x.com
The second one gets a different "error message": x
That's it.How to get a "z".
Further proof that the authors tweet is not about or against open access is that she publishes open access herself:
https://jlm.ipipan.waw.pl/index.php/JLM/article/view/292
The example was actually a Gatekeeper who values peer review before publication.
Additionally, Arxiv won't kick you off their platform if you post a preprint there, and then you get published in Nature.
In other words, the reason it does not change the point is that Arxiv does not weaken the publication process for the actual journals the preprint will be submitted to. You still need peer review to get published and you are still incentivised to do just that.
You could argue 'preprints ARE publishing' but I'd need to be convinced of that point because I don't agree for the reasons stated above.
There's timeless beauty in CS, but there's also a lot more fertile ground for research in CS, given how young the field is compared to the older sciences.
and I've offered at least as much evidence as you have.
For some reason I can not access this link.
- revenge for rejected paper
- badly written scraping script
this should be easy to block, no? just 200 out of millions
The email requests already happened. So blacklisting the IP addresses wouldn't prevent the email overload.
If you have some web service that sends emails, it's on you to pick a sensible rate limit for it (not 1,000,000 messages per day unless you're Fastmail) and to hierarchically bucket that ratelimit by the routable prefix (first 24 bits) of the requester's IP address. As the bucket empties, respond more and more slowly. This way the worst a DDoSer can do is mildly annoy people who happen to use the same ISP that they do -- but eventually even those people will still get through.
I'm sorry, but this is just the sort of thing everybody has to do in order to preserve a decentralized Internet. Because if we don't all do this sort of stuff, pretty soon it won't be the Internet anymore, it'll be the CloudflareNet.
Alright go ahead, downvote me to negative-billion. I can handle it.
I tried, but HN seems to implement some kind of rate limiting. D'Oh
And 10 accounts using 100 different IP addresses, would seem unlikely for an innocent project. And creating new accounts ...
Also there may be a good reason why arXiv call it a DDoS attack - they can probably see the same emails being flipped multiple times, which would not be inline with an accidental script issue.