Take all regular papers and change their words or keywords to something outrageous and watch it feed it to users.
https://www.brainonfire.net/blog/2024/09/19/poisoning-ai-scr...
It really sucks that this is the way things are, but what I did was
10 requests for pages in a minute, you get captchad (with a little apology and the option to bypass it by logging in). asset loads don’t count
After a captcha pass, 100 requests in an hour gets you auth walled
It’s really shitty but my industry is used to content scraping.
This allows legit users to get what they need. Although my users maybe don’t need prolonged access ahem.
[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/...
Bad actors don’t care and annoying actors would make fun of you for it on twitter
There’s some stuff you can do, like creating risk scores (if a user changes ip and uses the same captcha token, increase score). Many vendors do that, as does my captcha provider.
Of course they could have just used the site directly.
It sucks!