Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To be fair to those ISPs, most SSH connection attempts in my logs seem to come from consumer IP addresses. Many of them in China, but also a whole bunch in South America. I think it's because of hacked IoT crapware and other malware adding unsuspecting people to a botnet. I doubt anyone is renting hundreds of internet connections just to brute force admin/admin all day.

I can't imagine those South Americans being able to access anything without clearing twenty Cloudflare CAPTCHAs (I don't think Cloudflare operates in China), but then again, I think they'll just blame Cloudflare for sabotaging their perfectly safe 100% legit web traffic.

This type of blocking wouldn't be necessary if these companies actually did something with the abuse reports they receive, but I guess blocking SSH and telnet is an easy way to stop the flood of reports coming in if you don't care about your customers.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: