Of course they have bots... That's how you index the web.
If we took Google offline I bet there would also be a reduction in bot traffic from them too!
Indexing is also probably a low priority task, so if half their datacenter capacity is taken offline, their bot traffic probably reduces by more than 50%.
Eh. I would call several of the Middle-East countries that got their data centers smushed as "politically stable." They just got into bed with the wrong ally, I guess?
They are not politically stable, quite the opposite: weak states held together by single sector revenues.
Right after Ukraine war started, I started maintaining a map of next flashpoints: got a hit on Arabian peninsula + Iran, Venezuela, India/ Pakistan.
Israel and Gaza were a surprise.
Eastern flank (Finland/ Baltics/ Poland/ Romania is in a slow burn.
Still waiting for Taiwan, south china sea and Singapore/Malaysia+ Indonesia - but that will be the big one, and actually the conflict for the straits (Malaca and Sunday) may have gotten invalidated by the Iran mess.
> I would call several of the Middle-East countries that got their data centers smushed as "politically stable."
That's the lie that the US and most other Western countries have told themselves ever since the discovery of oil turned what used to be nomads herding camels and catching fish into the thriving petrostates they are today.
Most of MENA is only stable on paper, that stability being heavily dependent on oil and gas production providing giant slush funds to citizens and a horde of exploited migrant and seasonal workers providing for daily needs. That's why they all went into tourism so hard over the last two-ish decades, they know that the fossil fuel reserves are eventually going to deplete and worldwide demand collapsing with them, and that's why everyone but Iran eventually made their peace with the existence of Israel despite sometimes heavy opposition of the population, and that's why there's still barely any opposition to the US and Israel waging war against Iran, and that's why most of MENA militaries but Iran and Israel's are utterly useless as well - a capable military would be able of coup'ing away the ruling kleptocracy.
And now the MENA countries are in for a wild ride. The Mullahs are sadly far from gone, the Western world is busy weaning itself off of oil and gas following the Russian aggression against Ukraine and the price shocks related to that plus the Iran war, tourists won't come back in meaningful numbers likely for a decade if not longer.
>data centers are dual use technologies now and valid military targets
proclaimed by who? Even the "international order" would disagree, as Yandex Cloud wasn't providing their services to any military companies per my knowledge.
Yandex Cloud was bombed symmetrically. Ukraine made no attempt in targeting MSK-IX, which could be a real military target.
> a quick fyi: in a total war everything is a valid military target
this is not true, war crimes exist and have legal definitions, even in WW2 people pushed back on some things their government decided to do, like firebombing large civilian centers
hospitals and water facilities are easy examples, which Israel is very guilty of violating in recent years
I would just like to point out that the court that prosecutes war crimes was just hit with even more sanctions from the US, with the justification that "nobody will hurt American citizens", buy the guy who indirectly ordered the bombing of the school.
Legal definitions are pretty worthless if nobody gets prosecutesd.
> this is not true, war crimes exist and have legal definitions
That is why total wars are distinguished from a normal war. The concept that "all civilian infrastructure supports the war effort" is used in a total war to justify firebombing civilians.
Dresden and Hamburg, by the UK and Americans, public outcry saw this tactic end
WW2 is arguably bad example because everyone was committing crimes against humanity, worst thing humans ever did do, and today we're doing a lot of the same things that got us there
Logic says google bots do not come disguised, but as google agents.
Or is there other information?
Now there is probably also AI agent spam from google, but not at this level I believe. Also I am not fully clear what they count as spam, I doubt they would include google in this list, so do they include yandex bots here, if they come officially?
There's also the very well known inverse phenomenon of absolutely non-google people trying to disguise their crawler as a googlebot useragent, which has been a thing since at least... 15 years now?
I am unsure what you're trying to say. But it seems like you don't understand what Bot means in general and how is it specifically defined for the metric provided in that page.
From that pages point of view, a Google bot, Yandex bot, or your uncle Tom's AI agent spam is the same, a bot.
If official yandex bots ain't included in this data here - then it means spam/scam bots come indeed from yandex servers. As they stopped working, when the yandex data center was hit.
Yandex has cloud offering, their servers are used for actual bot traffic, not just crawlers. Yandex hasn’t been only a search company for a very long time.
I've reported high-volume exploit scanners multiple times, and when expiring blocks a week later, they typically would show up & resumt with the same IP at some point.
Maybe they'd care if the account was using a stolen credit card and there was a chance they wouldn't get their money, but they definitely do not care otherwise for normal people like me. I'm sure that'd be different if it's a multinational or a country-level government body is reporting something, but I can't get those to do my bidding.
Right, because I've had such outstanding results getting in touch with actual humans from Google when reporting abusive traffic directed towards my IP ranges. Top tier attention from people who really care.
Absence of bot traffic is secondary to the absence of nearly all Yandex traffic in general, bot or not, as a result of the datacenter being down. Which is certainly newsworthy.
Your initial submission title sounded as if Yandex DC was used as a bot attack and because they were down, bot traffic in the whole internet was substantially down.
Don't worry, now that Trump started protecting the refineries, the other data centers will be hit sooner rather than later.
All those fresh fp2 drones can't go to waste.
The only question is whats next - power plants? Water treatments? Heating somewhere up north?
The HTTP traffic from Yandex is down to ~ 0 % after the third strike, after the first two strikes already degraded it. I wonder how this looks like at the network level because their search page still serves, but presumably their crawler is inactive now
Edit: Here is some more info, they do have availability issues as is to be expected
> Because three of its primary facilities were knocked offline within four days, Yandex’s failover mechanisms broke down[1][8].
> Outages have cascaded across Yandex Go (taxis), Yandex Pay, food delivery, smart home platforms, internal logistics, and third-party corporate services hosted on Yandex Cloud[2][7]. Problems have spilled into neighboring countries using these systems (Belarus, Kazakhstan, Armenia, Serbia)[2][7].
Edit 2: Here is the Yandex Cloud status page, their GCP/AWS equivalent. The entire compute core is offline, and even worse, Cloud Backup
I don't know how useful it will be as a case study since an HA/Ops person in (let's say, the US, Canada, AU, western european countries) has access to do things like buy hypervisor capacity or colocation in just about any location. I could go buy colo in Brussels or Panama City or San Diego or Edmonton or Melbourne tomorrow by contacting the right people.
The Russians are much more restricted from doing anything geographically outside of their own borders (for very well justified sanctions reasons), so their limitations are not the same as an HA person in almost any other country. Maybe some Iranian HA/Ops people will be comparing notes with them.
Sometimes there exist data or processing residence requirements that bind you to a specific region (e.g. EU-only). Also, „all AZs in this region no longer exist“ is not on everyone‘s bingo card, this is a good reminder why multi-AZ deployment in the same region may be not enough.
For data center guys this is definitely a case study, because drone attacks are probably on the threat list for everyone now, for various reasons, including domestic terrorism and hybrid warfare. If you want to defend your investment, time to think what covers you from the air.
It heavily depends on "what kind of DC". A lot of current DCs are not really well protected against a lot of known threats - and that's just a design tradeoff.
High value data is already protected a bit better (or at least should be - the usual trend, management gets lazy when nothing blows up). I'm old enough to have sat in the meetings for "so, apparently a plane crashing into one or more of our locations is a viable risk now" - and a DC hardened for "somebody tries to land a 747 on that thing" should also survive a small drone with a bit of explosives.
While for the younger ones the "we lose several availability zones within days" is a new thing now - it really isn't. We were planning for that back then as well, just that we didn't call it "availability zone" or "cloud" yet.
It's an open question at what point we'll start seeing small fiesty startups that want to sell you a privately owned air defense system for your datacenter roof. The tech to do it is probably far ahead of the regulatory regime to own and operate autonomous small radar+SAM batteries.
It will require some involvement of state, but it is plausible, that critical infrastructure will be required to have this covered and certain big, licensed private contractors may be able to operate air defense systems on such sites (do you smell the money and lobbying effort?).
Also this may influence the design of such data centers. A drone that a paramilitary group can build is not very sophisticated and won’t carry big payloads. Put an outer concrete shell or some better passive defense, and maybe that will be enough.
As a result of some of my work only slightly related to telecom/internet infrastructure, I happened to get on the marketing lists for about six different Chinese companies that will gladly sell you a full size Shahed-136 clone complete with 2 stroke petrol motor. I wouldn't say that small paramilitaries being only able to fly a 5-10kg max size quadcopter with a munition on it into a datacenter is the limit of possible future capabilities. These things are cheaply made in fiberglass molds and look to be dead simple. They're already showing demo videos of them flying around with very low cost ardupilot capable flight controllers.
They even advertise the airframe and motor packages on Instagram....
It was clearly meant as an example of the ease of a non-russian company buying geographically-distributed services in the global marketplace, not "I could go buy this with a few docusign signatures and SWIFT wire transfers tomorrow". I am not in the market for colo in Panama City or Melbourne. I don't think it's a bad thing that the russians are hampered by many limitations but whatever lessons their HA people are learning these days are probably very specific to a sanctioned Russia.
Unironically yes, if you're just a typical B2B SaaS who doesn't have "datacenter getting hit by a literal missile" in your threat model, this coupled with offsite backups is probably the logical DR plan for that scenario.
I don't think there is much you can do about being targeted by a military, simply because of how unique the attack vector is.
Hacking is smart but happens through software, so if you have hardware (i.e. physical) barriers, that stops the hacking.
Natural disasters happen physically but they are dumb, so if you have software redundancy (i.e. by copying the data to multiple locations), that stops them from destroying everything.
A military is both physical AND smart. They can target multiple locations at once and destroy whole buildings.
Yandex is a part of Russia's military. Just the same as Google, MS, Amazon etc. provide services for the US military. Google et al. are probably in the critical path of defence for most European countries as well, insane though that is.
Not defending Yandex here, but I think their military involvement might be as accidental as of an American farmer whose beef landed in the cantina of aircraft carrier. Government and military procurement in Russia is its own universe, with strong players having specific IT expertise and capable of building DCs and tech. Assuming that everywhere in the world it’s the same as in America is wrong. Consumer tech companies aren’t operating this way usually, it is the scale of American Big Tech that allows them to compete with traditional contractors.
In general it’s the price of working with government, also see AWS Bahrain. I wonder if their insurance actually pays out because those are not officially wars there so hopefully they could recover some what from the insurance.
A very naive take from someone who clearly lives in a place where people have real choices, economic freedom, freedom of movement, and a government that protects them. "Just shut it down, bro" risks destroying your livelihood and leaving your family financially stranded, and yourself incarcerated or sent to the war zone. And it's not like Yandex develops weapons of mass destruction, you probably assume it's a collaboration even if Yandex simply hosts the Defense Ministry's websites. No sane parent will put their family at risk for this kind of stuff. "I'm going against the government for abstract ethical reasons" is something very few people/countries can afford.
And you can't shut it down anyway. The government will just nationalize it and keep it running. As long as you're the one in charge, you can at least throw a few hidden obstacles in the way, like dragging out legal processes.
No, a pretty informed take from someone who had family members that once upon a time made some very tough choices because they thought it was the right thing to do.
You can pretend at being ethical and moral as long as there is no price to pay, but when the time comes that it matters there will always be a price tag. Whether you are prepared to pay or not is what defines whether you are ethical or just pretending.
Company execs make decisions, employees make decisions, everybody carries a part.
Is it just me, or didn't we just see a single company cause a bit of a dustup when they refused to provide certain services to a military that wanted to bomb another country?
If it doesn't sound like something in the control of a single individual company, perhaps you have something distorting your hearing.
The pattern is quite interesting. I think I have seen this account in another thread today. They post pro-Russia comments, get downvoted and then delete their comment again.
There must be at least 10 or 20 of these, I point them out to the mods but some of them - for instance our good friend 'drysine' - are alive and well even after months of spouting their junk. It is really annoying.
You can learn to quickly diversify availability (or at least data safety) beyond the region of conflict when a kinetic war breaks out. The moment “kinetic sanctions” became the strategy, the risk to data centres should have been self-evident. And if it wasn’t immediately obvious, it should have been blindingly so when targeting expanded from oil refineries to Wildberries warehouses.
I don‘t think you can build a new data center in such a short time frame that passed since attacks on WB, definitely not when you can source hardware only from the black market.
I’m not describing what Yandex should do, but rather what their customers should do. Whether that means diversifying to eastern Russia, or China, or Belarus, I don’t know what options exist.
I feel like this isn't even a particularly new thing. I worked at a medium-sized SaaS company and we did disaster recovery drills for moving our stack from eu-west-1 to eu-central-1 in case something catastrophic happened in Ireland. If you want HA, you kinda have to assume that any single country in the world can have some kind of a crippling disaster. Unfortunately for Yandex's clients, Yandex only has regions in two countries, and not that many regions either.
The KZ region wasn't intended for Russia's entire workload, that's a secondary region with better Central Asian access.
If what you deduct were correct, Yandex would not be telling its customers to switch to competitora like VK Cloud. They even have a "priority onboarding code" called "CloudBro" for three competitors.
I predict a great many more videos coming out of Russia of Firepoint UAVs flying into refineries and such, punctuated by background audio commentary that can be summed up as "cyka blyat"
So cloudflare https://radar.cloudflare.com/bots?dateRange=7d shows 40% of worldwide bot traffic is from the us and <1% is from Russia. So what is this chart of traffic from russias search engine supposed to show?
Yandex is a search engine like Google is a search engine. Both are also cloud vendors. The chart of traffic from Yandex is showing that the majority of traffic was considered bot traffic, and after Ukraine's attack on its datacenter(s), that traffic has reduced substantially.
It looks like the majority of online bot traffic is coming from cloud vendor networks, which isn't surprising to me. But it makes me think that the "bot share by location" chart is more useful as a "which cloud vendor has bad bot control" chart vs. a "where is bot traffic coming from" chart.
I can’t believe there are so many dumb comments in this thread.
All it shows is that crawling from Yandex search engine stopped from one Yandex data center ASN.
No one runs opinion/malicious bots from data center IPs that people mention here.
You are replying to a war propaganda post with a heavily editorialized title. Of course it's swimming in bad faith engagement, that's how these things work.
I'd expect nothing less than a comment such as this, from an account that hasn't posted even once for the last 7 months and has in its post history a claim of being located in Moscow. But hey, thanks for showing up to remind us of how terrible the imperialist war-mongering west is. Very refreshing.
Not to get sidetracked, and not to argue against anything you've said, but how do you figure that out? For people you disagree with, do you open their profile's comments and start keyword-searching "russia" "china" "moscow" etc in hopes of finding a hit? They mentioned that city once in Jan 2024, halfway down the page and in passing. I'm just curious about how others use this site.
Different people read at different speeds, it took me about 5 seconds when skimming it. If you engage in enough discussion related to Russia online you will quickly learn to identify when inauthentic commenters suddenly show up from a previously idle account to add their 2 cents.
The person in question doesn't exhibit much of it, but one will also learn when skimming to identify certain grammar and sentence structure characteristics that can point to what is the first language of a person, even if they're writing in fluent English.
All that expertise (which requires some proper experience in the topic) even before you plug a llm to it, even few years ago they were good enough to identify unique writing styles of people across different accounts on HN.
I have seen document-analysis guides with info on how to identify the regional location of anonymous Internet commenters specifically within the US 48 states if you have a sufficiently large corpus of their text, as it relates to how they use certain regional slang, metaphors, colloquialisms, and words to describe things. Think of it as similar to how linguists have made maps showing regional variations in whether people call it "soda" or "coke" or "pop", but extended to all other common forms of North American dialect.
On the other hand there are plenty of datacenter located command/control systems that puppeteer vast fleets of residential proxies (and Russia is by no means the only one doing so), so it will be very telling to see what social media accounts go silent over the coming days and weeks.
> from one Yandex data center ASN
This is only one of two extant Yandex ASN, not an ASN specific to one geographic region/datacenter.
*Sudden drop in Cloudflare bot traffic from AS13238 YANDEX — Yandex LLC
UPD Definition of bot traffic from Cloudflare's glossary:
>Bot vs. human traffic
>The percentage of HTTP requests classified as bot versus human, based on bot scores. Requests with a bot score between 1 and 29 are classified as likely automated (bot), while requests with a score of 30 or above are classified as likely human. For more information, refer to Bot classes.
>By default, Radar shows bot vs. human traffic for requests to HTML content. This filter is meant to represent traditional web traffic by excluding API calls, asset requests (images, scripts, fonts), and other machine-to-machine requests.
Their latest consumer plan includes "Super Duper Bot Fight Mode", which lets you drone strike one data center in a sanctioned country of your choosing.
For additional strikes or to upgrade to ICBM-based payloads, you'll have to contact them to set up an enterprise plan.
Everyone is mentioning crawlers, but wouldn't most traffic from a datacenter's ASN usually be bots just in general given that there's not many humans there to generate human traffic?
Here's an example French hosting company which has something like 14.8% "human" traffic, (the Yandex is under 5% human) though how much of that is actual humans and not advanced things puppeteering headless browsers is another question.
It's interesting (but not surprising) that so much traffic comes from the Netherlands and Singapore despite their sizes compared to the countries at the top of this list.
While not necessarily related to bot traffic, but I was thinking that in the age of AI perhaps we'll be comparing technological development of countries based on their usage of AI per capita (similar to what we have with electricity usage per capita).
Apart from the correct argument that a search engine like Yandex will have crawlers, I would not be surprised if Western AI companies also used Yandex to scrape covertly.
Nvidia tried to pay off the Russian Anna's Archive for stolen data:
I think this really highlights the changing face of war.
It's hard to go to war now when your enemy can just use a few small drones to take out everything your citizens care about in a single day (social media, online deliveries etc).
And these things are practically irreplaceable in a war when you're sanctioned up the wazoo. Where are you buying racks of Xeons and DDR5 RAM and Nvidia GPUs?
I'm going to be really interested how much this cleans up the internet, I mean the damage is done if you read comment sections on youtube etc, but let's see how long the BS persists.
I was thinking, we should all contribute to a Yandex fund for the Ukrainian mil to help keep the level of bot activity on the rest of the internet under control!
Yandex is Russian Google.
Of course they have bots... That's how you index the web.
If we took Google offline I bet there would also be a reduction in bot traffic from them too!
Indexing is also probably a low priority task, so if half their datacenter capacity is taken offline, their bot traffic probably reduces by more than 50%.
I don't think these are the boys they refer to?
EDIT: I was wrong, they're just generic bot vs human traffic numbers and you're right.
This is devastating for Yandex. What does the SRE recovery plan even look like? “Raise shields”?
Issue recommendation for management: exit the Ukrainian market to reduce physical cybersecurity risks.
Activate the failover datacenters in orbit :)
Put 90 percent energy into the shields!
Don't invade another country. Easy.
That would be devastating for the US datacenter industry.
No it wouldn't.
Build data centers in politically stable countries.
Sure you cannot bribe anyone, actually have to pay taxes and can't install gas turbines but... they don't get blown up.
Eh. I would call several of the Middle-East countries that got their data centers smushed as "politically stable." They just got into bed with the wrong ally, I guess?
They are not politically stable, quite the opposite: weak states held together by single sector revenues. Right after Ukraine war started, I started maintaining a map of next flashpoints: got a hit on Arabian peninsula + Iran, Venezuela, India/ Pakistan. Israel and Gaza were a surprise. Eastern flank (Finland/ Baltics/ Poland/ Romania is in a slow burn. Still waiting for Taiwan, south china sea and Singapore/Malaysia+ Indonesia - but that will be the big one, and actually the conflict for the straits (Malaca and Sunday) may have gotten invalidated by the Iran mess.
When the USA loses it's economic dominance, Alaska looks to be another warzone to me.
Lotsa oil, small population, hard to defend.
Visit Iran, then visit UAE or Bahrain, then tell me again if they got in bed with the wrong ally.
> I would call several of the Middle-East countries that got their data centers smushed as "politically stable."
That's the lie that the US and most other Western countries have told themselves ever since the discovery of oil turned what used to be nomads herding camels and catching fish into the thriving petrostates they are today.
Most of MENA is only stable on paper, that stability being heavily dependent on oil and gas production providing giant slush funds to citizens and a horde of exploited migrant and seasonal workers providing for daily needs. That's why they all went into tourism so hard over the last two-ish decades, they know that the fossil fuel reserves are eventually going to deplete and worldwide demand collapsing with them, and that's why everyone but Iran eventually made their peace with the existence of Israel despite sometimes heavy opposition of the population, and that's why there's still barely any opposition to the US and Israel waging war against Iran, and that's why most of MENA militaries but Iran and Israel's are utterly useless as well - a capable military would be able of coup'ing away the ruling kleptocracy.
And now the MENA countries are in for a wild ride. The Mullahs are sadly far from gone, the Western world is busy weaning itself off of oil and gas following the Russian aggression against Ukraine and the price shocks related to that plus the Iran war, tourists won't come back in meaningful numbers likely for a decade if not longer.
> barely any opposition to the US and Israel waging war against Iran
It is in the interest of everyone in the region and the world to be rid of that brutal Islamist regime. The U.S. and Israel are doing God's work.
> actually have to pay taxes
Interested in recommendations of politically stable countries where companies can't practice tax avoidance.
</s>
Same for AWS Bahrain, data centers are dual use technologies now and valid military targets.
https://health.aws.amazon.com/health/status
>data centers are dual use technologies now and valid military targets
proclaimed by who? Even the "international order" would disagree, as Yandex Cloud wasn't providing their services to any military companies per my knowledge.
Yandex Cloud was bombed symmetrically. Ukraine made no attempt in targeting MSK-IX, which could be a real military target.
Iranian girls school was allegedly bombed with direct AI assistance. This fact alone makes any datacenter a valid target for Iran.
a quick fyi: in a total war everything is a valid military target, because economy backs up the military, and everything is economy.
> a quick fyi: in a total war everything is a valid military target
this is not true, war crimes exist and have legal definitions, even in WW2 people pushed back on some things their government decided to do, like firebombing large civilian centers
hospitals and water facilities are easy examples, which Israel is very guilty of violating in recent years
I would just like to point out that the court that prosecutes war crimes was just hit with even more sanctions from the US, with the justification that "nobody will hurt American citizens", buy the guy who indirectly ordered the bombing of the school. Legal definitions are pretty worthless if nobody gets prosecutesd.
> this is not true, war crimes exist and have legal definitions
That is why total wars are distinguished from a normal war. The concept that "all civilian infrastructure supports the war effort" is used in a total war to justify firebombing civilians.
> pushed back on some things their government decided to do, like firebombing large civilian centers
unless we're talking about, say, japan, where the firebombing campaigns killed more civilians than the two atomic bombs :P
Dresden and Hamburg, by the UK and Americans, public outcry saw this tactic end
WW2 is arguably bad example because everyone was committing crimes against humanity, worst thing humans ever did do, and today we're doing a lot of the same things that got us there
I'd like to see their business continuity plan lmao
I used to say "What happens if Hurricane Sandy 2 hits?" e.g. a whole region goes down.
Now I can add "AWS Bahrain" and "Yandex" to that list.
The other Yandex AS which is their hosting/hypervisor platform, broadly similar to AWS, Azure, whatever also shows a major drop in bot traffic:
https://radar.cloudflare.com/bots/as200350?dateRange=7d
https://www.peeringdb.com/net/20950
Don't let logic get in the way of a good propaganda.
Logic says google bots do not come disguised, but as google agents.
Or is there other information?
Now there is probably also AI agent spam from google, but not at this level I believe. Also I am not fully clear what they count as spam, I doubt they would include google in this list, so do they include yandex bots here, if they come officially?
Google bots definitely come disguised, to check whether the web site serves different content to non-Google user agents.
There's also the very well known inverse phenomenon of absolutely non-google people trying to disguise their crawler as a googlebot useragent, which has been a thing since at least... 15 years now?
Yeah I see a lot of what looks like non google bots pretending to be google bots, and then the next time some other bot and so on.
I am unsure what you're trying to say. But it seems like you don't understand what Bot means in general and how is it specifically defined for the metric provided in that page.
From that pages point of view, a Google bot, Yandex bot, or your uncle Tom's AI agent spam is the same, a bot.
I know what it means in general, but like I said indeed not "how is it specifically defined for the metric provided in that page."
Neither do Yandex bots. What's your point?
If official yandex bots ain't included in this data here - then it means spam/scam bots come indeed from yandex servers. As they stopped working, when the yandex data center was hit.
But what do you mean by "if"? It is a well defined metric and there is no "if".
I'll just link this comment if I may: https://news.ycombinator.com/item?id=50042416
Thank you, I missed that one (or it was not there when I started writing).
So yandex bots are included and this metric says nothing about malicious yandex intent here.
"If we took Google offline I bet there would also be a reduction in bot traffic from them too!"
That would be awesome.
I wonder how bot traffic on propaganda platforms like Twitter changed, but they probably won't give out any information anyway.
Yandex has cloud offering, their servers are used for actual bot traffic, not just crawlers. Yandex hasn’t been only a search company for a very long time.
Google hosts a significant number of bots. About half of my fail2ban list is google cloud IPs.
Of course they do, but they are quick with account bans when notified because of the liability issue unlike Yandex.
I've reported high-volume exploit scanners multiple times, and when expiring blocks a week later, they typically would show up & resumt with the same IP at some point.
Maybe they'd care if the account was using a stolen credit card and there was a chance they wouldn't get their money, but they definitely do not care otherwise for normal people like me. I'm sure that'd be different if it's a multinational or a country-level government body is reporting something, but I can't get those to do my bidding.
That must be why Google has such a stelly reputation for the quality of their support operations
> liability issue
Continue drinking the Google kool-aid
Right, because I've had such outstanding results getting in touch with actual humans from Google when reporting abusive traffic directed towards my IP ranges. Top tier attention from people who really care.
/s
I wonder how this will affect the Yandex search engine. I think I've read they split the Russian one and .com, but I'm not sure.
Someone needs to learn how to read the Bot Traffic page.
That is a drop in traffic specifically from Yandex bots (which includes their crawlers and other apps hosted in their DC)
Now compare it with Bot Traffic in:
* Russia: https://radar.cloudflare.com/bots/ru?dateRange=7d
* Europe: https://radar.cloudflare.com/bots/europe?dateRange=7d
* Worldwide: https://radar.cloudflare.com/bots?dateRange=7d
Dip is barely noticeable even in Russia.
Its like saying, "API requests are completely down" (and small disclaimer: only from your server, because your server is down)
Absence of bot traffic is secondary to the absence of nearly all Yandex traffic in general, bot or not, as a result of the datacenter being down. Which is certainly newsworthy.
Your initial submission title sounded as if Yandex DC was used as a bot attack and because they were down, bot traffic in the whole internet was substantially down.
Don't worry, now that Trump started protecting the refineries, the other data centers will be hit sooner rather than later. All those fresh fp2 drones can't go to waste. The only question is whats next - power plants? Water treatments? Heating somewhere up north?
Isn't this showing the percentage of bot traffic from the Yandex IP range?
If so, it isn't particularly surprising that the line would go down.
EDIT: yes, it is. Looking at the same graph for all of Russia, and there's no discernible pattern:
https://radar.cloudflare.com/bots/ru?dateRange=7d
same for the 48h view:
https://radar.cloudflare.com/bots/ru?dateRange=2d
The HTTP traffic from Yandex is down to ~ 0 % after the third strike, after the first two strikes already degraded it. I wonder how this looks like at the network level because their search page still serves, but presumably their crawler is inactive now
Edit: Here is some more info, they do have availability issues as is to be expected
> Because three of its primary facilities were knocked offline within four days, Yandex’s failover mechanisms broke down[1][8].
> Outages have cascaded across Yandex Go (taxis), Yandex Pay, food delivery, smart home platforms, internal logistics, and third-party corporate services hosted on Yandex Cloud[2][7]. Problems have spilled into neighboring countries using these systems (Belarus, Kazakhstan, Armenia, Serbia)[2][7].
Edit 2: Here is the Yandex Cloud status page, their GCP/AWS equivalent. The entire compute core is offline, and even worse, Cloud Backup
https://status.yandex.cloud/ru/dashboard
> ru Compute Cloud, ru Kubernetes, ru PostgreSQL, ru ClickHouse, ru MySQL, ru YDB, ru Kafka, ru Application Load Balancer
Interestingly, Yandex tells its users on the status page to switch to competitors Selectel, K2Cloud, and VK Cloud. Which will probably be hit next
This will be a case study in catastrophic events for HA and Ops folks.-
I don't know how useful it will be as a case study since an HA/Ops person in (let's say, the US, Canada, AU, western european countries) has access to do things like buy hypervisor capacity or colocation in just about any location. I could go buy colo in Brussels or Panama City or San Diego or Edmonton or Melbourne tomorrow by contacting the right people.
The Russians are much more restricted from doing anything geographically outside of their own borders (for very well justified sanctions reasons), so their limitations are not the same as an HA person in almost any other country. Maybe some Iranian HA/Ops people will be comparing notes with them.
Sometimes there exist data or processing residence requirements that bind you to a specific region (e.g. EU-only). Also, „all AZs in this region no longer exist“ is not on everyone‘s bingo card, this is a good reminder why multi-AZ deployment in the same region may be not enough.
For data center guys this is definitely a case study, because drone attacks are probably on the threat list for everyone now, for various reasons, including domestic terrorism and hybrid warfare. If you want to defend your investment, time to think what covers you from the air.
It heavily depends on "what kind of DC". A lot of current DCs are not really well protected against a lot of known threats - and that's just a design tradeoff.
High value data is already protected a bit better (or at least should be - the usual trend, management gets lazy when nothing blows up). I'm old enough to have sat in the meetings for "so, apparently a plane crashing into one or more of our locations is a viable risk now" - and a DC hardened for "somebody tries to land a 747 on that thing" should also survive a small drone with a bit of explosives.
While for the younger ones the "we lose several availability zones within days" is a new thing now - it really isn't. We were planning for that back then as well, just that we didn't call it "availability zone" or "cloud" yet.
It's an open question at what point we'll start seeing small fiesty startups that want to sell you a privately owned air defense system for your datacenter roof. The tech to do it is probably far ahead of the regulatory regime to own and operate autonomous small radar+SAM batteries.
It will require some involvement of state, but it is plausible, that critical infrastructure will be required to have this covered and certain big, licensed private contractors may be able to operate air defense systems on such sites (do you smell the money and lobbying effort?).
Also this may influence the design of such data centers. A drone that a paramilitary group can build is not very sophisticated and won’t carry big payloads. Put an outer concrete shell or some better passive defense, and maybe that will be enough.
As a result of some of my work only slightly related to telecom/internet infrastructure, I happened to get on the marketing lists for about six different Chinese companies that will gladly sell you a full size Shahed-136 clone complete with 2 stroke petrol motor. I wouldn't say that small paramilitaries being only able to fly a 5-10kg max size quadcopter with a munition on it into a datacenter is the limit of possible future capabilities. These things are cheaply made in fiberglass molds and look to be dead simple. They're already showing demo videos of them flying around with very low cost ardupilot capable flight controllers.
They even advertise the airframe and motor packages on Instagram....
Well, what an interesting time we are living in…
In a scenario were data centres in China, the US or France are getting blown up you're in WW3 and your food delivery service no longer matters.
The DR plan for pros, "I could go buy colo tomorrow by contacting the right people"
It was clearly meant as an example of the ease of a non-russian company buying geographically-distributed services in the global marketplace, not "I could go buy this with a few docusign signatures and SWIFT wire transfers tomorrow". I am not in the market for colo in Panama City or Melbourne. I don't think it's a bad thing that the russians are hampered by many limitations but whatever lessons their HA people are learning these days are probably very specific to a sanctioned Russia.
Unironically yes, if you're just a typical B2B SaaS who doesn't have "datacenter getting hit by a literal missile" in your threat model, this coupled with offsite backups is probably the logical DR plan for that scenario.
I think the complete destruction of the AWS Bahrain region got there first.
I don't think there is much you can do about being targeted by a military, simply because of how unique the attack vector is.
Hacking is smart but happens through software, so if you have hardware (i.e. physical) barriers, that stops the hacking.
Natural disasters happen physically but they are dumb, so if you have software redundancy (i.e. by copying the data to multiple locations), that stops them from destroying everything.
A military is both physical AND smart. They can target multiple locations at once and destroy whole buildings.
> I don't think there is much you can do about being targeted by a military, simply because of how unique the attack vector is.
You could choose not to invade other countries.
This (as with defense) is kind of outside Google or Yandex's purview.
Yandex is a part of Russia's military. Just the same as Google, MS, Amazon etc. provide services for the US military. Google et al. are probably in the critical path of defence for most European countries as well, insane though that is.
Not defending Yandex here, but I think their military involvement might be as accidental as of an American farmer whose beef landed in the cantina of aircraft carrier. Government and military procurement in Russia is its own universe, with strong players having specific IT expertise and capable of building DCs and tech. Assuming that everywhere in the world it’s the same as in America is wrong. Consumer tech companies aren’t operating this way usually, it is the scale of American Big Tech that allows them to compete with traditional contractors.
In general it’s the price of working with government, also see AWS Bahrain. I wonder if their insurance actually pays out because those are not officially wars there so hopefully they could recover some what from the insurance.
Said every company serving fascists ever.
No, you can choose to collaborate or you can shut it down.
Collaborators don't get to point back in time and say 'oh we had no choice', even if the choice was a painful one. Sorry it does not work that way.
A very naive take from someone who clearly lives in a place where people have real choices, economic freedom, freedom of movement, and a government that protects them. "Just shut it down, bro" risks destroying your livelihood and leaving your family financially stranded, and yourself incarcerated or sent to the war zone. And it's not like Yandex develops weapons of mass destruction, you probably assume it's a collaboration even if Yandex simply hosts the Defense Ministry's websites. No sane parent will put their family at risk for this kind of stuff. "I'm going against the government for abstract ethical reasons" is something very few people/countries can afford.
And you can't shut it down anyway. The government will just nationalize it and keep it running. As long as you're the one in charge, you can at least throw a few hidden obstacles in the way, like dragging out legal processes.
No, a pretty informed take from someone who had family members that once upon a time made some very tough choices because they thought it was the right thing to do.
You can pretend at being ethical and moral as long as there is no price to pay, but when the time comes that it matters there will always be a price tag. Whether you are prepared to pay or not is what defines whether you are ethical or just pretending.
Company execs make decisions, employees make decisions, everybody carries a part.
I guess, but that doesn't sound like something in the control of a single individual company.
Is it just me, or didn't we just see a single company cause a bit of a dustup when they refused to provide certain services to a military that wanted to bomb another country?
If it doesn't sound like something in the control of a single individual company, perhaps you have something distorting your hearing.
They control their own individual contribution.
But apparently this does not apply to you.
At least one russian shill that isn't affected by the Yandex strikes. Let's see how the rest of them fares, HN has its fair share of these characters.
The pattern is quite interesting. I think I have seen this account in another thread today. They post pro-Russia comments, get downvoted and then delete their comment again.
There must be at least 10 or 20 of these, I point them out to the mods but some of them - for instance our good friend 'drysine' - are alive and well even after months of spouting their junk. It is really annoying.
You can learn to quickly diversify availability (or at least data safety) beyond the region of conflict when a kinetic war breaks out. The moment “kinetic sanctions” became the strategy, the risk to data centres should have been self-evident. And if it wasn’t immediately obvious, it should have been blindingly so when targeting expanded from oil refineries to Wildberries warehouses.
I don‘t think you can build a new data center in such a short time frame that passed since attacks on WB, definitely not when you can source hardware only from the black market.
I’m not describing what Yandex should do, but rather what their customers should do. Whether that means diversifying to eastern Russia, or China, or Belarus, I don’t know what options exist.
... and in the middle of the RAM-pocalypse, no less.-
I feel like this isn't even a particularly new thing. I worked at a medium-sized SaaS company and we did disaster recovery drills for moving our stack from eu-west-1 to eu-central-1 in case something catastrophic happened in Ireland. If you want HA, you kinda have to assume that any single country in the world can have some kind of a crippling disaster. Unfortunately for Yandex's clients, Yandex only has regions in two countries, and not that many regions either.
> The entire compute core is offline, and even worse, Cloud Backup
Their Kazakh regions are available according to the dashboard, so it isn't as catastrophic.
Their managed DBs and data processing services are heavily affected though with no Kazakh redundancies from the looks of it.
The KZ region wasn't intended for Russia's entire workload, that's a secondary region with better Central Asian access.
If what you deduct were correct, Yandex would not be telling its customers to switch to competitora like VK Cloud. They even have a "priority onboarding code" called "CloudBro" for three competitors.
I just searched "blyat" and it worked, so?
Given that blyad is just punctuation at this point, I am not surprised.
I predict a great many more videos coming out of Russia of Firepoint UAVs flying into refineries and such, punctuated by background audio commentary that can be summed up as "cyka blyat"
The username checks out!
("Ept" and "suka" are two other swearwords, that are also used much like punctuation.)
So cloudflare https://radar.cloudflare.com/bots?dateRange=7d shows 40% of worldwide bot traffic is from the us and <1% is from Russia. So what is this chart of traffic from russias search engine supposed to show?
Yandex is a search engine like Google is a search engine. Both are also cloud vendors. The chart of traffic from Yandex is showing that the majority of traffic was considered bot traffic, and after Ukraine's attack on its datacenter(s), that traffic has reduced substantially.
It looks like the majority of online bot traffic is coming from cloud vendor networks, which isn't surprising to me. But it makes me think that the "bot share by location" chart is more useful as a "which cloud vendor has bad bot control" chart vs. a "where is bot traffic coming from" chart.
I can’t believe there are so many dumb comments in this thread. All it shows is that crawling from Yandex search engine stopped from one Yandex data center ASN.
No one runs opinion/malicious bots from data center IPs that people mention here.
Did people actually stop thinking?
You are replying to a war propaganda post with a heavily editorialized title. Of course it's swimming in bad faith engagement, that's how these things work.
I'd expect nothing less than a comment such as this, from an account that hasn't posted even once for the last 7 months and has in its post history a claim of being located in Moscow. But hey, thanks for showing up to remind us of how terrible the imperialist war-mongering west is. Very refreshing.
Both comments, his and especially yours, are terrible interpretations. That's how any discussion is turned into a mud flinging party.
Not to get sidetracked, and not to argue against anything you've said, but how do you figure that out? For people you disagree with, do you open their profile's comments and start keyword-searching "russia" "china" "moscow" etc in hopes of finding a hit? They mentioned that city once in Jan 2024, halfway down the page and in passing. I'm just curious about how others use this site.
Different people read at different speeds, it took me about 5 seconds when skimming it. If you engage in enough discussion related to Russia online you will quickly learn to identify when inauthentic commenters suddenly show up from a previously idle account to add their 2 cents.
The person in question doesn't exhibit much of it, but one will also learn when skimming to identify certain grammar and sentence structure characteristics that can point to what is the first language of a person, even if they're writing in fluent English.
All that expertise (which requires some proper experience in the topic) even before you plug a llm to it, even few years ago they were good enough to identify unique writing styles of people across different accounts on HN.
Anonymity is gone from internet for some time.
I have seen document-analysis guides with info on how to identify the regional location of anonymous Internet commenters specifically within the US 48 states if you have a sufficiently large corpus of their text, as it relates to how they use certain regional slang, metaphors, colloquialisms, and words to describe things. Think of it as similar to how linguists have made maps showing regional variations in whether people call it "soda" or "coke" or "pop", but extended to all other common forms of North American dialect.
https://www.businessinsider.com/soda-vs-pop-map-2012-7
On the other hand there are plenty of datacenter located command/control systems that puppeteer vast fleets of residential proxies (and Russia is by no means the only one doing so), so it will be very telling to see what social media accounts go silent over the coming days and weeks.
> from one Yandex data center ASN
This is only one of two extant Yandex ASN, not an ASN specific to one geographic region/datacenter.
https://www.peeringdb.com/net/1751
The other one is this: https://www.peeringdb.com/net/20950
And the 200350 also shows a near complete drop off in bot activity:
https://radar.cloudflare.com/bots/as200350?dateRange=7d
> command/control systems
There is Hetzner for that.
The funny thing is that apparently I'm the only one that flagged it... I don't know why people comment instead of using the tools?
The bots might be run in the datacenter and proxied through residential IPs as the exit point.
If they are, then that wouldn't be YANDEX AS13238. So the linked graph wouldn't show these changes.
You won't see this kind of stats on the CF page.
All it shows is direct traffic against CF infrastructure.
*Sudden drop in Cloudflare bot traffic from AS13238 YANDEX — Yandex LLC
UPD Definition of bot traffic from Cloudflare's glossary:
>Bot vs. human traffic
>The percentage of HTTP requests classified as bot versus human, based on bot scores. Requests with a bot score between 1 and 29 are classified as likely automated (bot), while requests with a score of 30 or above are classified as likely human. For more information, refer to Bot classes.
>By default, Radar shows bot vs. human traffic for requests to HTML content. This filter is meant to represent traditional web traffic by excluding API calls, asset requests (images, scripts, fonts), and other machine-to-machine requests.
https://developers.cloudflare.com/radar/glossary/#bot-vs-hum...
https://developers.cloudflare.com/bots/concepts/bot-score/
Correct, I probably didn't didn't write that in the clearest possible way, I meant "detected bot traffic hitting cloudflare originating from Yandex".
That's some intense mitigation from Cloudflare
Their latest consumer plan includes "Super Duper Bot Fight Mode", which lets you drone strike one data center in a sanctioned country of your choosing.
For additional strikes or to upgrade to ICBM-based payloads, you'll have to contact them to set up an enterprise plan.
You gave me a good laugh, cheers!
Everyone is mentioning crawlers, but wouldn't most traffic from a datacenter's ASN usually be bots just in general given that there's not many humans there to generate human traffic?
Here's an example French hosting company which has something like 14.8% "human" traffic, (the Yandex is under 5% human) though how much of that is actual humans and not advanced things puppeteering headless browsers is another question.
https://radar.cloudflare.com/traffic/as12876
The US is still responsible for almost 50% of traffic of which the top are Amazon, Google, Microsoft, Cloudlare.
https://radar.cloudflare.com/bots
Indeed, most of my server's 'Chinese' and 'Russian' bot traffic is originating from US IP addresses.
It's interesting (but not surprising) that so much traffic comes from the Netherlands and Singapore despite their sizes compared to the countries at the top of this list.
While not necessarily related to bot traffic, but I was thinking that in the age of AI perhaps we'll be comparing technological development of countries based on their usage of AI per capita (similar to what we have with electricity usage per capita).
100%. It will roughly translate to GDP. It is no different than industrialization/mechanization/computerization transitions.
Interestingly most traffic coming out of this AS was actually UDP: https://dashboard.terracenetworks.com/sources/asns/13238
Pretty benign AS as far as actual exploit or malicious crawling is concerned.
Probably QUIC if true, but you should also ask how these people get their data, because this isn't something you can just see or look up.
It's actually almost entirely DNS. Also rest assured that I have definitely asked how these people get their data [1].
[1] https://news.ycombinator.com/user?id=ericpauley
so much love for russia in the comments, maybe bot operators get some spare time to comment here
Yandex is reporting an outage for some services. https://dzen.ru/news/story/75e4b917-952d-5304-a9b4-70e5dc1fb...
Apart from the correct argument that a search engine like Yandex will have crawlers, I would not be surprised if Western AI companies also used Yandex to scrape covertly.
Nvidia tried to pay off the Russian Anna's Archive for stolen data:
https://www.tomshardware.com/tech-industry/artificial-intell...
It would not be a surprise if similar deals have been reached with Yandex.
But this is a nice demonstration by Ukraine that all our internet problems are caused by large data centers, wherever they may be located.
I have to wonder what will happen when the remaining 6 data centers get hit as well. It's bound to happen.
I think this really highlights the changing face of war.
It's hard to go to war now when your enemy can just use a few small drones to take out everything your citizens care about in a single day (social media, online deliveries etc).
And these things are practically irreplaceable in a war when you're sanctioned up the wazoo. Where are you buying racks of Xeons and DDR5 RAM and Nvidia GPUs?
If there will be an world-wide war, sure. But at that point, the Internet as we know it will probably collapse anyway.
There is one, but it's taking place mostly by information means, not physical.
https://postimg.cc/YjjDtrT2
Are there even six remaining?
It’s not really surprising that bot traffic originating from a network went away when _all_ traffic originating from that network stopped.
Could be just crawlers
Does that include the disinformation infrastructure? If so, they should keep it on.
When Brazil and Afrinet? :P
I'm going to be really interested how much this cleans up the internet, I mean the damage is done if you read comment sections on youtube etc, but let's see how long the BS persists.
It's only counting Yandex search crawler traffic, not any actually bad bots.
Cloudflare should consider donating to the Ukrainian military for the public service they are performing.
I was thinking, we should all contribute to a Yandex fund for the Ukrainian mil to help keep the level of bot activity on the rest of the internet under control!
https://war.ukraine.ua/donate/
(I’d welcome a data center and oil infrastructure targeting specific fund)
Now check how many open models search Yandex when asked for something.
surprisedpikatchu.jpeg
isn't this only counting russian origin already?
The URL is CF's public metrics for bot traffic from a single specific Russian ASN, Yandex.
https://www.peeringdb.com/net/1751
oh well of course if you blow up Yandex then Yandex stops sending you traffic, because they got blown up.
And nothing of value was lost.
Yandex is the best search engine that doesn't follow American censorship norms. For this reason Kagi uses them as one source of several.
So, is sending hot hate towards a bot farm going to be a paid service on Cloudflare now?
Would be ironic, since they provide services to criminals who commit DDoS-attacks, spread malware and conduct phishing campaigns:
https://cofense.com/blog/how-cloudflare-services-are-abused-...
https://www.heise.de/en/news/Report-Cybercriminals-use-Cloud...
Or maybe they would just want to get rid of the competition.
propaganda
“AI agents” is just a fancy rebranding of “bots” with some “intelligence”.