logoalt Hacker News

jt2190today at 3:45 PM1 replyview on HN

I still don’t understand why a rate-limiting approach is not preferred. Why should I care if the abuse is coming from a bot or the world’s fastest human? Is there a “if you need to rate limit you’ve already lost” issue I’m not thinking of?


Replies

charlie-83today at 4:15 PM

A lot of bots will be able to make requests from a range of IP addresses. If you rate limit one, they just start sending requests from the next.