Tor requests getting HTTP 429 errors
Categories
(bugzilla.mozilla.org :: Infrastructure, defect)
Tracking
()
People
(Reporter: opal, Assigned: glob)
Details
Recently (I can't pin a date because I don't access BMO frequently enough) I have been getting HTTP 429 "Too Many Requests" errors from the openresty server. I am using Tor to proxy my requests, and a standard Firefox ESR 78 user-agent without spoofing headers.
I have not had issues previously, accessing BMO via Tor, for as long as I have had my account here, and the issue has only manifested fairly recently. I am wondering if BMO has experienced increased load from various Tor exits, or if firewall / WAF configurations have been modified to be more restrictive toward Tor exits.
Comment 1•5 years ago
|
||
Could be the fact that we put iprepd in place in front of BMO not too long ago. This removes the need for BMO to do its own rate limiting.
Historically TOR has been a spam/abuse vector that we can't control, frequently tripping other anti-spam countermeasures.
As dkl mentioned we recently switched from an "in house" rate limiting feature to iprepd that provides protection for multiple Firefox assets (eg. Accounts, Sync); this likely accounts for the change in responses you're experiencing.
I'm sorry but if you're going to participate then I recommend you use a conventional route.
I'm waiting to hear back from the operators of iprepd to see if there's something we can do here; however due to the nature of the abuse cat and mouse game I'm not expecting limits to be raised.
if you're going to participate then I recommend you use a conventional route.
I understand that Mozilla's big and that the crossover between Mozilla and Tor Project is relatively small, but it was my impression that Mozilla had vested interest in Tor as well as privacy in general. I find it a bit insulting to call non-Tor use "conventional" when many people simply do not have that as an option.
I'm waiting to hear back from the operators of iprepd to see if there's something we can do here
Hopefully so; I don't know much about iprepd (first time I heard of it in fact) but if I come up with any suggestions I'll update the ticket. I operate online services that receive a lot of anonymous traffic, so this kind of abuse mitigation—where IP addresses are not a valuable source of information to combat abusive traffic—is not new to me.
Haven't run into this issue since then; actually I almost forgot I even opened this issue.
Description
•