Yes, I think captchas are the wrong solution. They annoy all clients, humans included.
IP+subnet based throttling on the other hand is a perfectly working solution, optionally with a proof-of-work or login requirement for intensive POST requests only. Why is it a problem if only a few requests per day are made per home IP? Just how bad and inefficient is the web server?
Bots are not a second class client. They were here before AI, and they, like AI, work for humans. For the most part, they're not trolling the web autonomously.
Sorry but the proposal is egregious, considering your website's access far falls short of a DDoS attack against it. You voluntarily host it on the public web. Pay-for-access proposals have existed for decades, and there is a reason they never go anywhere.
Even a $5 VM I have has an included quota of at least 1TB egress data per month, and it can handle 9,540,534 requests in a day if not less. A Rust server can handle a lot more. In practice, my egress quota is larger by virtue of having a couple of more nodes.
If you actually cared, you would use something cheaper then AWS, ideally with zstandard compression, and a CPU efficient service that doesn't buckle under a moderate load.
jmclnx · · focus · HN ↗
OutOfHere · · focus · HN ↗
IP+subnet based throttling on the other hand is a perfectly working solution, optionally with a proof-of-work or login requirement for intensive POST requests only. Why is it a problem if only a few requests per day are made per home IP? Just how bad and inefficient is the web server?
Bots are not a second class client. They were here before AI, and they, like AI, work for humans. For the most part, they're not trolling the web autonomously.
kator · · focus · HN ↗
[1] Proposed Amendment to the Telephone Consumer Protection Act of 1991 (2026-05-08) - <a href="https://www.karlbunch.com/random/website-protection-act/" rel="nofollow">https://www.karlbunch.com/random/website-protection-act/
OutOfHere · · focus · HN ↗
Even a $5 VM I have has an included quota of at least 1TB egress data per month, and it can handle 9,540,534 requests in a day if not less. A Rust server can handle a lot more. In practice, my egress quota is larger by virtue of having a couple of more nodes.
If you actually cared, you would use something cheaper then AWS, ideally with zstandard compression, and a CPU efficient service that doesn't buckle under a moderate load.
rdevilla · · focus · HN ↗
[dead]