Cloudflare reports almost 7% of internet traffic is malicious
zdnet.com
zdnet.com
Even later on in the report, they say:
> 31.2% of all application traffic processed by Cloudflare is bot traffic. [...] 93% of bots we identified were unverified bots, and potentially malicious.
So I guess there's a wide range there, from 7% verified at the low end, up to maybe 30% at the higher, hypothetical end?
- people with older browsers who fail it automatically due to unsupported features
- whoever gets stuck in captcha loops and gives up eventually
- whoever has a slow internet connection and gives up during the verification process
This happens to be a lot of people, especially the less technical ones with less access to good technology, which is why we rarely hear complaints on HN.
This way, the Cloudflare people can tell you some completely made up numbers, like "This month we blocked one gazillion malicious bots and saved you 30 yottabytes of data", which makes it look like they're doing something of value instead of making the internet a more closed, restricted, corporate and centralized place.
The other 'spam' of the time was ICMP traffic. Nets were so flaky in those days everyone who could write a script was running pings to what remote servers they had. Many were idiots that didn't even realize you can send small pings with no padded payloads. And of course there were ICMP reflection attacks from bad actors with incredible payloads and address spoofing. So one number I remember is that combined spam-email and ICMP demanded 50% of bandwidth at times. But remember, at the time the principal use of the net was to move ASCII and ASCII-compressed content.
While the botspam of today probably exceeds any historical levels, the percentage is low because bots do not watch or serve video. The botspam is spoofing humans on websites and port probing for automated exploit.
It's very common for reputable hosting company's to KYC/KYB.
It's good for them & also good for their legit customers.
Where government identified categories like smoking, alcohol, pornography - are defined by governments to be potentially harmful to its citizens. So as a hosting company, you're in a weird spot because it's not clear if you can/cannot do business with those types of companies.
Ha, I wonder if an LLM can be told to "code an exploit from this proof-of-concept, find hosts where this app is running and give me admin access"...