TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Arxiv.org is experiencing a DDoS attack

123 pointsby smcfover 1 year ago

6 comments

elashriover 1 year ago
&gt; We will shortly be reaching out to the abuse desk of the affected ISP for assistance.<p>Does anyone here have experience working with an ISP in abuse cases like this one, specially a Chinese ISP?
评论 #37479365 未加载
评论 #37478983 未加载
评论 #37481157 未加载
Abecidover 1 year ago
Who would have the incentive to bring arxiv down?
评论 #37479367 未加载
评论 #37478494 未加载
评论 #37482493 未加载
评论 #37478385 未加载
评论 #37479308 未加载
评论 #37479659 未加载
评论 #37478261 未加载
paulpauperover 1 year ago
<i>These requests originated from over 200 IP addresses – almost all owned by an ISP for a particular province in China. The confirmation emails for this volume of requests overwhelmed our email service. As a result, many arXiv users may not have received their daily emails. And other users may not have received their confirmation emails for registering accounts, or legitimate email change requests.</i><p>this should be easy to block, no? just 200 out of millions
评论 #37478337 未加载
评论 #37477938 未加载
KirillPanovover 1 year ago
Look, arxiv.org is awesome and I love them, but they really can&#x27;t expect the ITU or abuse-reporting groups to bail them out here.<p>If you have some web service that sends emails, it&#x27;s on you to pick a sensible rate limit for it (<i>not</i> 1,000,000 messages per day unless you&#x27;re Fastmail) and to hierarchically bucket that ratelimit by the routable prefix (first 24 bits) of the requester&#x27;s IP address. As the bucket empties, respond more and more slowly. This way the worst a DDoSer can do is mildly annoy people who happen to use the same ISP that they do -- but eventually even those people will still get through.<p>I&#x27;m sorry, but this is just the sort of thing everybody has to do in order to preserve a decentralized Internet. Because if we don&#x27;t all do this sort of stuff, pretty soon it won&#x27;t be the Internet anymore, it&#x27;ll be the CloudflareNet.<p>Alright go ahead, downvote me to negative-billion. I can handle it.
评论 #37479090 未加载
评论 #37480051 未加载
KRAKRISMOTTover 1 year ago
A million password resets is shockingly low for a DDOS, could this have been an university assignment gone wrong? I can imagine some clueless dean ordering all their engineering grads to submit research to arXiv. If they have 100-200K students, a single poorly written script to link the institution&#x27;s SSO with automatically created arXiv accounts could easily overwhelm the system.
评论 #37478022 未加载
评论 #37478493 未加载
jbottomsover 1 year ago
Does the State Dept get involved in these cases? Surely China has responsibility over this ISP.