ansuz (@ansuz@gts.cryptography.dog)

2 min read Original article ↗

I've observed a huge increase in tightly coordinated traffic that's consistent with Bright Data's behaviour.

Somebody has clearly made a list of URLs from various websites I host, and requests them in alphabetical order from a variety of IPs all around the world. Some come from data-centers or directly from ISPs, but the majority are residential.

I don't know for sure that it's Bright Data, because there could be other companies (or straight-up illegal botnet operators) running their own market of sublet IPs. Bright Data definitely seems to be the largest one, however.

I assume that most people whose IPs are involved in what is effectively a commercial botnet either have no idea that it's happening, or don't realize the implications.

As someone whose digital infrastructure has become a target of this, the most sensible thing to do is to add their IP addresses to a long-lived firewall rule to keep them from coming back. No other approach to mitigation is really viable. If that response becomes prevalent, then those people are going to find that lots of online services stop working for them.

Because IP addresses are often shared, people might find that their ability to access the web is negatively affected by something like their roommates' choice of TV brand. There are just so many negative externalities to this technology and business-model. It's quite simply making the web worse for both end-users and operators.

At least at present, the demand for this kind of tech seems to be coming almost entirely from people collecting data to train various types of "AI".