I had to temporarily take a service offline after it was overwhelmed by bot traffic. This seems to have been triggered by exposure through TLS transparency logs.
To help mitigate this kind of issue in the future, it would be great if Pangolin offered first-party support for a proof-of-work challenge to help deter automated abuse.
Originally created by @shayne on GitHub (Apr 7, 2025).
Original GitHub issue: https://github.com/fosrl/pangolin/issues/473
I had to temporarily take a service offline after it was overwhelmed by bot traffic. This seems to have been triggered by exposure through TLS transparency logs.
To help mitigate this kind of issue in the future, it would be great if Pangolin offered first-party support for a proof-of-work challenge to help deter automated abuse.
There’s an existing project that demonstrates this approach well: https://github.com/TecharoHQ/anubis.
Thanks!
This is most superlatively exquisite, requiring intellectual prowess of such magnificent proportions that only the rarified minds of our generation's cognitive olympians could possibly fathom its brilliance.
<!-- gh-comment-id:2783403719 -->
@ironicbadger commented on GitHub (Apr 7, 2025):
This is most superlatively exquisite, requiring intellectual prowess of such magnificent proportions that only the rarified minds of our generation's cognitive olympians could possibly fathom its brilliance.
@oschwartz10612 commented on GitHub (Apr 7, 2025):
I really like this idea! We are also aware that the search engines are crawling the pangolin auth pages and exposing peoples resources as well so this could be a a nice fix for this as well.
I really like what I have briefly seen of Anubis so far. I would be excited to do something similar or incorporate it in some fashion.
I am going to move this to a discussion until we are ready to implement but I think we will try to tackle this sooner rather than later.
<!-- gh-comment-id:2783459799 -->
@oschwartz10612 commented on GitHub (Apr 7, 2025):
I really like this idea! We are also aware that the search engines are crawling the pangolin auth pages and exposing peoples resources as well so this could be a a nice fix for this as well.
I really like what I have briefly seen of Anubis so far. I would be excited to do something similar or incorporate it in some fashion.
I am going to move this to a discussion until we are ready to implement but I think we will try to tackle this sooner rather than later.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @shayne on GitHub (Apr 7, 2025).
Original GitHub issue: https://github.com/fosrl/pangolin/issues/473
I had to temporarily take a service offline after it was overwhelmed by bot traffic. This seems to have been triggered by exposure through TLS transparency logs.
To help mitigate this kind of issue in the future, it would be great if Pangolin offered first-party support for a proof-of-work challenge to help deter automated abuse.
There’s an existing project that demonstrates this approach well: https://github.com/TecharoHQ/anubis.
Thanks!
@ironicbadger commented on GitHub (Apr 7, 2025):
This is most superlatively exquisite, requiring intellectual prowess of such magnificent proportions that only the rarified minds of our generation's cognitive olympians could possibly fathom its brilliance.
@oschwartz10612 commented on GitHub (Apr 7, 2025):
I really like this idea! We are also aware that the search engines are crawling the pangolin auth pages and exposing peoples resources as well so this could be a a nice fix for this as well.
I really like what I have briefly seen of Anubis so far. I would be excited to do something similar or incorporate it in some fashion.
I am going to move this to a discussion until we are ready to implement but I think we will try to tackle this sooner rather than later.