Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. If you write about the messy reality behind "free" internet services: we're seeing #OpenStreetMap hammered by scrapers hiding behind residential proxy/embedded-SDK networks.

If you write about the messy reality behind "free" internet services: we're seeing #OpenStreetMap hammered by scrapers hiding behind residential proxy/embedded-SDK networks.

Geplant Angeheftet Gesperrt Verschoben Uncategorized
openstreetmapbotsabuse
114 Beiträge 92 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • utf_7@mastodon.socialU utf_7@mastodon.social

    @osm_tech what is a embedded-Sdk network?

    osm_tech@en.osm.townO This user is from outside of this forum
    osm_tech@en.osm.townO This user is from outside of this forum
    osm_tech@en.osm.town
    schrieb zuletzt editiert von
    #47

    @utf_7 See https://www.youtube.com/watch?v=qhie14YKa-w&t=790s

    1 Antwort Letzte Antwort
    0
    • claireh@blahaj.zoneC claireh@blahaj.zone

      @osm_tech@en.osm.town 404 media might be interested in this - they've been doing a lot of pieces about the impact of AI

      fluffykittycat@furry.engineerF This user is from outside of this forum
      fluffykittycat@furry.engineerF This user is from outside of this forum
      fluffykittycat@furry.engineer
      schrieb zuletzt editiert von
      #48

      @ClaireH @osm_tech @404mediaco here's a good story idea, OSM is having issues with AI scrapers

      1 Antwort Letzte Antwort
      0
      • osm_tech@en.osm.townO osm_tech@en.osm.town

        If you write about the messy reality behind "free" internet services: we're seeing #OpenStreetMap hammered by scrapers hiding behind residential proxy/embedded-SDK networks. We're a volunteer-run service and the costs are real. We'd love to talk to a journalist about what we're seeing + how we're responding. #AI #Bots #Abuse

        J This user is from outside of this forum
        J This user is from outside of this forum
        jakobthomsen@urbanists.social
        schrieb zuletzt editiert von
        #49

        @osm_tech perhaps people at the Chaos Computer Club would be interested to look into that:
        https://www.ccc.de/en/
        Or maybe someone at Netzpolitik:
        https://netzpolitik.org/

        1 Antwort Letzte Antwort
        0
        • fuzzle@chaos.socialF fuzzle@chaos.social

          @osm_tech @evawolfangel #hint , vielleicht was für dich.

          gunchleoc@mastodon.scotG This user is from outside of this forum
          gunchleoc@mastodon.scotG This user is from outside of this forum
          gunchleoc@mastodon.scot
          schrieb zuletzt editiert von
          #50

          @fuzzle @osm_tech Oder @heiseonline oder @netzpolitik_feed

          1 Antwort Letzte Antwort
          0
          • L lmieldazis@mastodon.social

            @osm_tech @geerlingguy I would 100% watch a video about that. Just throwing it out there 🙂

            osm_tech@en.osm.townO This user is from outside of this forum
            osm_tech@en.osm.townO This user is from outside of this forum
            osm_tech@en.osm.town
            schrieb zuletzt editiert von
            #51

            @LMieldazis @geerlingguy oooh do we get to show him our out-of-band (remote access) Raspberry Pi with dual power feeds, 4G modem and loads of serial connections? Saved our skin a good few times.

            geerlingguy@mastodon.socialG 1 Antwort Letzte Antwort
            0
            • baloouriza@social.tulsa.ok.usB baloouriza@social.tulsa.ok.us

              @osm_tech I wonder if there's a way to fail2ban requests coming in faster than typically found in human requests.

              osm_tech@en.osm.townO This user is from outside of this forum
              osm_tech@en.osm.townO This user is from outside of this forum
              osm_tech@en.osm.town
              schrieb zuletzt editiert von
              #52

              @BalooUriza We use fail2ban to handle some of this with custom rules, but eventually fail2ban becomes a bottleneck after 100,000 IP addresses.

              dalias@hachyderm.ioD mnalis@mastodon.onlineM 2 Antworten Letzte Antwort
              0
              • E eigen@mattstodon.panar.ooo

                @osm_tech anything I can volunteer to help?

                osm_tech@en.osm.townO This user is from outside of this forum
                osm_tech@en.osm.townO This user is from outside of this forum
                osm_tech@en.osm.town
                schrieb zuletzt editiert von
                #53

                @eigen we're always looking for more volunteers to join our team. ♥️

                1 Antwort Letzte Antwort
                0
                • joeress@mastodon.socialJ joeress@mastodon.social

                  @osm_tech if you have anyone with a good microphone/audio setup, who's willing to speak on a podcast, I'd be happy to record something for one of the @latenightlinux shows.

                  osm_tech@en.osm.townO This user is from outside of this forum
                  osm_tech@en.osm.townO This user is from outside of this forum
                  osm_tech@en.osm.town
                  schrieb zuletzt editiert von
                  #54

                  @joeress @latenightlinux Sounds interesting. We'll follow up by email.

                  1 Antwort Letzte Antwort
                  0
                  • osm_tech@en.osm.townO osm_tech@en.osm.town

                    If you write about the messy reality behind "free" internet services: we're seeing #OpenStreetMap hammered by scrapers hiding behind residential proxy/embedded-SDK networks. We're a volunteer-run service and the costs are real. We'd love to talk to a journalist about what we're seeing + how we're responding. #AI #Bots #Abuse

                    sjvn@mastodon.socialS This user is from outside of this forum
                    sjvn@mastodon.socialS This user is from outside of this forum
                    sjvn@mastodon.social
                    schrieb zuletzt editiert von
                    #55

                    @osm_tech Tell me more. You can reach me at sjvn01 <at> gmail.com

                    davidgerard@circumstances.runD 1 Antwort Letzte Antwort
                    0
                    • osm_tech@en.osm.townO osm_tech@en.osm.town

                      @BalooUriza We use fail2ban to handle some of this with custom rules, but eventually fail2ban becomes a bottleneck after 100,000 IP addresses.

                      dalias@hachyderm.ioD This user is from outside of this forum
                      dalias@hachyderm.ioD This user is from outside of this forum
                      dalias@hachyderm.io
                      schrieb zuletzt editiert von
                      #56

                      @osm_tech @BalooUriza For IPv4, a bitmask of the entire address space is a viable "efficient" implementation of blocking. I wonder if there are tools that can do it that way rather than needing a gigantic list.

                      dalias@hachyderm.ioD slink@fosstodon.orgS magezwitscher@det.socialM 3 Antworten Letzte Antwort
                      0
                      • alivedevil@tauri.earthA alivedevil@tauri.earth

                        @utf_7 @osm_tech

                        This gets ugly really fast, if you want to see the full extent: <https://alternativeto.net/software/netnut-proxy-network/> for a list of _known_ residential proxy-providers.

                        dalias@hachyderm.ioD This user is from outside of this forum
                        dalias@hachyderm.ioD This user is from outside of this forum
                        dalias@hachyderm.io
                        schrieb zuletzt editiert von
                        #57

                        @AliveDevil @utf_7 @osm_tech So ridiculous that Google and Apple won't just permaban any developer embedding one of these "SDKs".

                        alivedevil@tauri.earthA 1 Antwort Letzte Antwort
                        0
                        • insertuser@en.osm.townI insertuser@en.osm.town

                          @osm_tech The proxy SDK providers need to be treated like the DDOS providers they are and prosecuted.

                          azonenberg@ioc.exchangeA This user is from outside of this forum
                          azonenberg@ioc.exchangeA This user is from outside of this forum
                          azonenberg@ioc.exchange
                          schrieb zuletzt editiert von
                          #58

                          @InsertUser @osm_tech Pulling them from app stores and banning developers of the SDKs would be a good start. Save the criminal charges for after the damage control is done.

                          1 Antwort Letzte Antwort
                          0
                          • insertuser@en.osm.townI insertuser@en.osm.town

                            @pietervdvn Because that would involve a human using their brains or having a shred of conscience and those both go against the basic principles of the companies doing this.

                            @osm_tech

                            dalias@hachyderm.ioD This user is from outside of this forum
                            dalias@hachyderm.ioD This user is from outside of this forum
                            dalias@hachyderm.io
                            schrieb zuletzt editiert von
                            #59

                            @InsertUser @pietervdvn @osm_tech It goes against their whole ideology. The ideology says trust the machine to do what it copied from scraped Stack Overflow posts. If you try to intervene to make it do better, you're not trusting it.

                            1 Antwort Letzte Antwort
                            0
                            • dalias@hachyderm.ioD dalias@hachyderm.io

                              @osm_tech @BalooUriza For IPv4, a bitmask of the entire address space is a viable "efficient" implementation of blocking. I wonder if there are tools that can do it that way rather than needing a gigantic list.

                              dalias@hachyderm.ioD This user is from outside of this forum
                              dalias@hachyderm.ioD This user is from outside of this forum
                              dalias@hachyderm.io
                              schrieb zuletzt editiert von
                              #60

                              @osm_tech @BalooUriza Like, a bitmask of IPv4 space is several times smaller than a Chrome instance. 🙃 🤡

                              1 Antwort Letzte Antwort
                              0
                              • dalias@hachyderm.ioD dalias@hachyderm.io

                                @AliveDevil @utf_7 @osm_tech So ridiculous that Google and Apple won't just permaban any developer embedding one of these "SDKs".

                                alivedevil@tauri.earthA This user is from outside of this forum
                                alivedevil@tauri.earthA This user is from outside of this forum
                                alivedevil@tauri.earth
                                schrieb zuletzt editiert von
                                #61

                                @dalias I'd wish for them to enforce policies, but they get Ad- and IAP-revenue, so why bother.

                                Also, these "Sdks" probably have kill-switches (or rather, delayed activation) built-in, to not immediately contact their C&C servers.

                                dalias@hachyderm.ioD 1 Antwort Letzte Antwort
                                0
                                • alivedevil@tauri.earthA alivedevil@tauri.earth

                                  @dalias I'd wish for them to enforce policies, but they get Ad- and IAP-revenue, so why bother.

                                  Also, these "Sdks" probably have kill-switches (or rather, delayed activation) built-in, to not immediately contact their C&C servers.

                                  dalias@hachyderm.ioD This user is from outside of this forum
                                  dalias@hachyderm.ioD This user is from outside of this forum
                                  dalias@hachyderm.io
                                  schrieb zuletzt editiert von
                                  #62

                                  @AliveDevil Yes but they could still be banned when caught. A few devs getting banned would be a big deterrent for others to ship this malware.

                                  The right *technical* defense, however, is not to allow apps arbitrary network access unless they're declared in the manifest as a "browser" or other "client software" that the user can use with any service they want (like IRC clients, mail clients, Mastodon clients, etc.).

                                  Instead, the manifest should declare a single domain the app can contact, or multiple if the developer is willing to pay for more intensive vetting of them, and only allow network access to the declared domain(s).

                                  utf_7@mastodon.socialU 1 Antwort Letzte Antwort
                                  0
                                  • osm_tech@en.osm.townO osm_tech@en.osm.town

                                    If you write about the messy reality behind "free" internet services: we're seeing #OpenStreetMap hammered by scrapers hiding behind residential proxy/embedded-SDK networks. We're a volunteer-run service and the costs are real. We'd love to talk to a journalist about what we're seeing + how we're responding. #AI #Bots #Abuse

                                    gfkdsgn@burma.socialG This user is from outside of this forum
                                    gfkdsgn@burma.socialG This user is from outside of this forum
                                    gfkdsgn@burma.social
                                    schrieb zuletzt editiert von
                                    #63

                                    That's something for you @404mediaco, isn't it?

                                    1 Antwort Letzte Antwort
                                    0
                                    • osm_tech@en.osm.townO osm_tech@en.osm.town

                                      If you write about the messy reality behind "free" internet services: we're seeing #OpenStreetMap hammered by scrapers hiding behind residential proxy/embedded-SDK networks. We're a volunteer-run service and the costs are real. We'd love to talk to a journalist about what we're seeing + how we're responding. #AI #Bots #Abuse

                                      dangoodin@infosec.exchangeD This user is from outside of this forum
                                      dangoodin@infosec.exchangeD This user is from outside of this forum
                                      dangoodin@infosec.exchange
                                      schrieb zuletzt editiert von
                                      #64

                                      @osm_tech

                                      Please contact me on Signal: DanArs.82

                                      1 Antwort Letzte Antwort
                                      0
                                      • osm_tech@en.osm.townO osm_tech@en.osm.town

                                        @LMieldazis @geerlingguy oooh do we get to show him our out-of-band (remote access) Raspberry Pi with dual power feeds, 4G modem and loads of serial connections? Saved our skin a good few times.

                                        geerlingguy@mastodon.socialG This user is from outside of this forum
                                        geerlingguy@mastodon.socialG This user is from outside of this forum
                                        geerlingguy@mastodon.social
                                        schrieb zuletzt editiert von
                                        #65

                                        @osm_tech @LMieldazis would love to talk maps ops! I've seen many projects wrapping in map data and adding scripts to dl entire regions

                                        1 Antwort Letzte Antwort
                                        0
                                        • osm_tech@en.osm.townO osm_tech@en.osm.town

                                          If you write about the messy reality behind "free" internet services: we're seeing #OpenStreetMap hammered by scrapers hiding behind residential proxy/embedded-SDK networks. We're a volunteer-run service and the costs are real. We'd love to talk to a journalist about what we're seeing + how we're responding. #AI #Bots #Abuse

                                          ryanvade@mas.toR This user is from outside of this forum
                                          ryanvade@mas.toR This user is from outside of this forum
                                          ryanvade@mas.to
                                          schrieb zuletzt editiert von
                                          #66

                                          @osm_tech @404mediaco

                                          naturemc@mastodon.onlineN 1 Antwort Letzte Antwort
                                          0
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen



                                          Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                          Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                          Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                          • Anmelden

                                          • Du hast noch kein Konto? Registrieren

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Home
                                          • Aktuell
                                          • Tags
                                          • Über dieses Forum