Bot traffic from Yandex

(radar.cloudflare.com)

553 points | by walrus01 9 hours ago ago

162 comments

  • londons_explore 8 hours ago

    Yandex is Russian Google.

    Of course they have bots... That's how you index the web.

    If we took Google offline I bet there would also be a reduction in bot traffic from them too!

    Indexing is also probably a low priority task, so if half their datacenter capacity is taken offline, their bot traffic probably reduces by more than 50%.

    • cromka 8 hours ago

      I don't think these are the boys they refer to?

      EDIT: I was wrong, they're just generic bot vs human traffic numbers and you're right.

      • jquery 5 hours ago

        This is devastating for Yandex. What does the SRE recovery plan even look like? “Raise shields”?

        • londons_explore 35 minutes ago

          "We should be able to handle a long term net-split" was always part of my emergency plan for every service I worked on. (ie. Imagine all Comms between the Americas and the rest of the world cut for weeks)

          Pretty likely to happen if there is a major war or political upheaval to require the internet be cut in two. I didn't require the service had no downtime, but that it was reasonably possible to restore service within a few hours.

          Things contributing to that are you should have either live data or a backup in similar geo location to the user. Both the data and the crypto keys. Same for the code. And you should build your service simple enough that someone else who has never seen it before can deploy it and get things at least mostly working. Things like terraform are good for that - and it dramatically reduces employee training too.

        • dlkasajiewo 3 hours ago

          Issue recommendation for management: exit the Ukrainian market to reduce physical cybersecurity risks.

        • michelb 5 hours ago

          Activate the failover datacenters in orbit :)

        • theplumber 5 hours ago

          Put 90 percent energy into the shields!

        • beAbU 4 hours ago

          Don't invade another country. Easy.

          • zorked 3 hours ago

            That would be devastating for the US datacenter industry.

        • expedition32 5 hours ago

          Build data centers in politically stable countries.

          Sure you cannot bribe anyone, actually have to pay taxes and can't install gas turbines but... they don't get blown up.

          • kulahan 14 minutes ago

            Politically stable countries are more likely to let you skirt taxes because you’re bringing thousands of high paying jobs in, theoretically. It’s a really easy argument to make.

            But also, there’s basically aren’t any politically stable countries right now lol.

          • qingcharles 5 hours ago

            Eh. I would call several of the Middle-East countries that got their data centers smushed as "politically stable." They just got into bed with the wrong ally, I guess?

            • rembal an hour ago

              They are not politically stable, quite the opposite: weak states held together by single sector revenues. Right after Ukraine war started, I started maintaining a map of next flashpoints: got a hit on Arabian peninsula + Iran, Venezuela, India/ Pakistan. Israel and Gaza were a surprise. Eastern flank (Finland/ Baltics/ Poland/ Romania is in a slow burn. Still waiting for Taiwan, south china sea and Singapore/Malaysia+ Indonesia - but that will be the big one, and actually the conflict for the straits (Malaca and Sunday) may have gotten invalidated by the Iran mess.

              • londons_explore an hour ago

                When the USA loses it's economic dominance, Alaska looks to be another warzone to me.

                Lotsa oil, small population, hard to defend.

            • flyinglizard 2 hours ago

              Visit Iran, then visit UAE or Bahrain, then tell me again if they got in bed with the wrong ally.

            • mschuster91 an hour ago

              > I would call several of the Middle-East countries that got their data centers smushed as "politically stable."

              That's the lie that the US and most other Western countries have told themselves ever since the discovery of oil turned what used to be nomads herding camels and catching fish into the thriving petrostates they are today.

              Most of MENA is only stable on paper, that stability being heavily dependent on oil and gas production providing giant slush funds to citizens and a horde of exploited migrant and seasonal workers providing for daily needs. That's why they all went into tourism so hard over the last two-ish decades, they know that the fossil fuel reserves are eventually going to deplete and worldwide demand collapsing with them, and that's why everyone but Iran eventually made their peace with the existence of Israel despite sometimes heavy opposition of the population, and that's why there's still barely any opposition to the US and Israel waging war against Iran, and that's why most of MENA militaries but Iran and Israel's are utterly useless as well - a capable military would be able of coup'ing away the ruling kleptocracy.

              And now the MENA countries are in for a wild ride. The Mullahs are sadly far from gone, the Western world is busy weaning itself off of oil and gas following the Russian aggression against Ukraine and the price shocks related to that plus the Iran war, tourists won't come back in meaningful numbers likely for a decade if not longer.

              • drnick1 41 minutes ago

                > barely any opposition to the US and Israel waging war against Iran

                It is in the interest of everyone in the region and the world to be rid of that brutal Islamist regime. The U.S. and Israel are doing God's work.

                • mschuster91 2 minutes ago

                  I agree, but the way they have gone at it is about the dumbest and incompetent way to do it. A blunder of historic dimensions, I'd even say Vietnam made more sense.

          • Iolaum an hour ago

            > actually have to pay taxes

            Interested in recommendations of politically stable countries where companies can't practice tax avoidance.

            </s>

        • verdverm 5 hours ago

          Same for AWS Bahrain, data centers are dual use technologies now and valid military targets.

          https://health.aws.amazon.com/health/status

          • innocent_name 2 hours ago

            >data centers are dual use technologies now and valid military targets

            proclaimed by who? Even the "international order" would disagree, as Yandex Cloud wasn't providing their services to any military companies per my knowledge.

            Yandex Cloud was bombed symmetrically. Ukraine made no attempt in targeting MSK-IX, which could be a real military target.

            • sedan_baklazhan 2 hours ago

              Iranian girls school was allegedly bombed with direct AI assistance. This fact alone makes any datacenter a valid target for Iran.

          • notaigenerated 2 hours ago

            a quick fyi: in a total war everything is a valid military target, because economy backs up the military, and everything is economy.

            • verdverm 2 hours ago

              > a quick fyi: in a total war everything is a valid military target

              this is not true, war crimes exist and have legal definitions, even in WW2 people pushed back on some things their government decided to do, like firebombing large civilian centers

              hospitals and water facilities are easy examples, which Israel is very guilty of violating in recent years

              • rembal an hour ago

                I would just like to point out that the court that prosecutes war crimes was just hit with even more sanctions from the US, with the justification that "nobody will hurt American citizens", buy the guy who indirectly ordered the bombing of the school. Legal definitions are pretty worthless if nobody gets prosecutesd.

              • smuhakg 2 hours ago

                > this is not true, war crimes exist and have legal definitions

                That is why total wars are distinguished from a normal war. The concept that "all civilian infrastructure supports the war effort" is used in a total war to justify firebombing civilians.

              • thedrexster 2 hours ago

                > pushed back on some things their government decided to do, like firebombing large civilian centers

                unless we're talking about, say, japan, where the firebombing campaigns killed more civilians than the two atomic bombs :P

                • verdverm 2 hours ago

                  Dresden and Hamburg, by the UK and Americans, public outcry saw this tactic end

                  WW2 is arguably bad example because everyone was committing crimes against humanity, worst thing humans ever did do, and today we're doing a lot of the same things that got us there

        • ptyyy 3 hours ago

          I'd like to see their business continuity plan lmao

        • alexpotato 2 hours ago

          I used to say "What happens if Hurricane Sandy 2 hits?" e.g. a whole region goes down.

          Now I can add "AWS Bahrain" and "Yandex" to that list.

    • walrus01 7 hours ago

      The other Yandex AS which is their hosting/hypervisor platform, broadly similar to AWS, Azure, whatever also shows a major drop in bot traffic:

      https://radar.cloudflare.com/bots/as200350?dateRange=7d

      https://www.peeringdb.com/net/20950

    • asdfsa32 7 hours ago

      Don't let logic get in the way of a good propaganda.

      • lukan 7 hours ago

        Logic says google bots do not come disguised, but as google agents.

        Or is there other information?

        Now there is probably also AI agent spam from google, but not at this level I believe. Also I am not fully clear what they count as spam, I doubt they would include google in this list, so do they include yandex bots here, if they come officially?

        • selcuka 5 hours ago

          Google bots definitely come disguised, to check whether the web site serves different content to non-Google user agents.

          • walrus01 5 hours ago

            There's also the very well known inverse phenomenon of absolutely non-google people trying to disguise their crawler as a googlebot useragent, which has been a thing since at least... 15 years now?

            • duxup an hour ago

              Yeah I see a lot of what looks like non google bots pretending to be google bots, and then the next time some other bot and so on.

              • lukan 27 minutes ago

                How do you know they are not google? Their IP address or behavior?

                • duxup 15 minutes ago

                  Behavior mostly. I don’t expect Google to be trying to hit known exploits for that given server and similar behavior.

        • asdfsa32 7 hours ago

          I am unsure what you're trying to say. But it seems like you don't understand what Bot means in general and how is it specifically defined for the metric provided in that page.

          From that pages point of view, a Google bot, Yandex bot, or your uncle Tom's AI agent spam is the same, a bot.

          • lukan 7 hours ago

            I know what it means in general, but like I said indeed not "how is it specifically defined for the metric provided in that page."

        • konart 7 hours ago

          Neither do Yandex bots. What's your point?

          • lukan 7 hours ago

            If official yandex bots ain't included in this data here - then it means spam/scam bots come indeed from yandex servers. As they stopped working, when the yandex data center was hit.

            • asdfsa32 7 hours ago

              But what do you mean by "if"? It is a well defined metric and there is no "if".

            • konart 7 hours ago

              I'll just link this comment if I may: https://news.ycombinator.com/item?id=50042416

              • lukan 7 hours ago

                Thank you, I missed that one (or it was not there when I started writing).

                So yandex bots are included and this metric says nothing about malicious yandex intent here.

    • JKCalhoun 2 hours ago

      "If we took Google offline I bet there would also be a reduction in bot traffic from them too!"

      That would be awesome.

    • enopod_ 5 hours ago

      I wonder how bot traffic on propaganda platforms like Twitter changed, but they probably won't give out any information anyway.

    • dgellow 7 hours ago

      Yandex has cloud offering, their servers are used for actual bot traffic, not just crawlers. Yandex hasn’t been only a search company for a very long time.

      • nik282000 7 hours ago

        Google hosts a significant number of bots. About half of my fail2ban list is google cloud IPs.

        • alephnerd 6 hours ago

          Of course they do, but they are quick with account bans when notified because of the liability issue unlike Yandex.

          • luckylion 6 hours ago

            I've reported high-volume exploit scanners multiple times, and when expiring blocks a week later, they typically would show up & resumt with the same IP at some point.

            Maybe they'd care if the account was using a stolen credit card and there was a chance they wouldn't get their money, but they definitely do not care otherwise for normal people like me. I'm sure that'd be different if it's a multinational or a country-level government body is reporting something, but I can't get those to do my bidding.

          • saghm 6 hours ago

            That must be why Google has such a stelly reputation for the quality of their support operations

          • 876433790 5 hours ago

            > liability issue

            Continue drinking the Google kool-aid

          • walrus01 6 hours ago

            Right, because I've had such outstanding results getting in touch with actual humans from Google when reporting abusive traffic directed towards my IP ranges. Top tier attention from people who really care.

            /s

    • AlienRobot 7 hours ago

      I wonder how this will affect the Yandex search engine. I think I've read they split the Russian one and .com, but I'm not sure.

  • throwaw12 7 hours ago

    Someone needs to learn how to read the Bot Traffic page.

    That is a drop in traffic specifically from Yandex bots (which includes their crawlers and other apps hosted in their DC)

    Now compare it with Bot Traffic in:

    * Russia: https://radar.cloudflare.com/bots/ru?dateRange=7d

    * Europe: https://radar.cloudflare.com/bots/europe?dateRange=7d

    * Worldwide: https://radar.cloudflare.com/bots?dateRange=7d

    Dip is barely noticeable even in Russia.

    Its like saying, "API requests are completely down" (and small disclaimer: only from your server, because your server is down)

    • walrus01 6 hours ago

      Absence of bot traffic is secondary to the absence of nearly all Yandex traffic in general, bot or not, as a result of the datacenter being down. Which is certainly newsworthy.

      • throwaw12 3 hours ago

        Your initial submission title sounded as if Yandex DC was used as a bot attack and because they were down, bot traffic in the whole internet was substantially down.

    • rembal an hour ago

      Don't worry, now that Trump started protecting the refineries, the other data centers will be hit sooner rather than later. All those fresh fp2 drones can't go to waste. The only question is whats next - power plants? Water treatments? Heating somewhere up north?

  • timr 7 hours ago

    Isn't this showing the percentage of bot traffic from the Yandex IP range?

    If so, it isn't particularly surprising that the line would go down.

    EDIT: yes, it is. Looking at the same graph for all of Russia, and there's no discernible pattern:

    https://radar.cloudflare.com/bots/ru?dateRange=7d

    same for the 48h view:

    https://radar.cloudflare.com/bots/ru?dateRange=2d

  • schleck8 8 hours ago

    The HTTP traffic from Yandex is down to ~ 0 % after the third strike, after the first two strikes already degraded it. I wonder how this looks like at the network level because their search page still serves, but presumably their crawler is inactive now

    Edit: Here is some more info, they do have availability issues as is to be expected

    > Because three of its primary facilities were knocked offline within four days, Yandex’s failover mechanisms broke down[1][8].

    > Outages have cascaded across Yandex Go (taxis), Yandex Pay, food delivery, smart home platforms, internal logistics, and third-party corporate services hosted on Yandex Cloud[2][7]. Problems have spilled into neighboring countries using these systems (Belarus, Kazakhstan, Armenia, Serbia)[2][7].

    Edit 2: Here is the Yandex Cloud status page, their GCP/AWS equivalent. The entire compute core is offline, and even worse, Cloud Backup

    https://status.yandex.cloud/ru/dashboard

    > ru Compute Cloud, ru Kubernetes, ru PostgreSQL, ru ClickHouse, ru MySQL, ru YDB, ru Kafka, ru Application Load Balancer

    Interestingly, Yandex tells its users on the status page to switch to competitors Selectel, K2Cloud, and VK Cloud. Which will probably be hit next

    • Bluestein 8 hours ago

      This will be a case study in catastrophic events for HA and Ops folks.-

      • walrus01 7 hours ago

        I don't know how useful it will be as a case study since an HA/Ops person in (let's say, the US, Canada, AU, western european countries) has access to do things like buy hypervisor capacity or colocation in just about any location. I could go buy colo in Brussels or Panama City or San Diego or Edmonton or Melbourne tomorrow by contacting the right people.

        The Russians are much more restricted from doing anything geographically outside of their own borders (for very well justified sanctions reasons), so their limitations are not the same as an HA person in almost any other country. Maybe some Iranian HA/Ops people will be comparing notes with them.

        • ivan_gammel 7 hours ago

          Sometimes there exist data or processing residence requirements that bind you to a specific region (e.g. EU-only). Also, „all AZs in this region no longer exist“ is not on everyone‘s bingo card, this is a good reminder why multi-AZ deployment in the same region may be not enough.

          For data center guys this is definitely a case study, because drone attacks are probably on the threat list for everyone now, for various reasons, including domestic terrorism and hybrid warfare. If you want to defend your investment, time to think what covers you from the air.

          • finaard 2 hours ago

            It heavily depends on "what kind of DC". A lot of current DCs are not really well protected against a lot of known threats - and that's just a design tradeoff.

            High value data is already protected a bit better (or at least should be - the usual trend, management gets lazy when nothing blows up). I'm old enough to have sat in the meetings for "so, apparently a plane crashing into one or more of our locations is a viable risk now" - and a DC hardened for "somebody tries to land a 747 on that thing" should also survive a small drone with a bit of explosives.

            While for the younger ones the "we lose several availability zones within days" is a new thing now - it really isn't. We were planning for that back then as well, just that we didn't call it "availability zone" or "cloud" yet.

          • walrus01 6 hours ago

            It's an open question at what point we'll start seeing small fiesty startups that want to sell you a privately owned air defense system for your datacenter roof. The tech to do it is probably far ahead of the regulatory regime to own and operate autonomous small radar+SAM batteries.

            • ivan_gammel 6 hours ago

              It will require some involvement of state, but it is plausible, that critical infrastructure will be required to have this covered and certain big, licensed private contractors may be able to operate air defense systems on such sites (do you smell the money and lobbying effort?).

              Also this may influence the design of such data centers. A drone that a paramilitary group can build is not very sophisticated and won’t carry big payloads. Put an outer concrete shell or some better passive defense, and maybe that will be enough.

              • walrus01 6 hours ago

                As a result of some of my work only slightly related to telecom/internet infrastructure, I happened to get on the marketing lists for about six different Chinese companies that will gladly sell you a full size Shahed-136 clone complete with 2 stroke petrol motor. I wouldn't say that small paramilitaries being only able to fly a 5-10kg max size quadcopter with a munition on it into a datacenter is the limit of possible future capabilities. These things are cheaply made in fiberglass molds and look to be dead simple. They're already showing demo videos of them flying around with very low cost ardupilot capable flight controllers.

                They even advertise the airframe and motor packages on Instagram....

                • ivan_gammel 6 hours ago

                  Well, what an interesting time we are living in…

            • expedition32 5 hours ago

              In a scenario were data centres in China, the US or France are getting blown up you're in WW3 and your food delivery service no longer matters.

        • themgt 6 hours ago

          The DR plan for pros, "I could go buy colo tomorrow by contacting the right people"

          • walrus01 6 hours ago

            It was clearly meant as an example of the ease of a non-russian company buying geographically-distributed services in the global marketplace, not "I could go buy this with a few docusign signatures and SWIFT wire transfers tomorrow". I am not in the market for colo in Panama City or Melbourne. I don't think it's a bad thing that the russians are hampered by many limitations but whatever lessons their HA people are learning these days are probably very specific to a sanctioned Russia.

          • SOLAR_FIELDS 6 hours ago

            Unironically yes, if you're just a typical B2B SaaS who doesn't have "datacenter getting hit by a literal missile" in your threat model, this coupled with offsite backups is probably the logical DR plan for that scenario.

      • cowlevel 6 hours ago

        I think the complete destruction of the AWS Bahrain region got there first.

      • AlienRobot 7 hours ago

        I don't think there is much you can do about being targeted by a military, simply because of how unique the attack vector is.

        Hacking is smart but happens through software, so if you have hardware (i.e. physical) barriers, that stops the hacking.

        Natural disasters happen physically but they are dumb, so if you have software redundancy (i.e. by copying the data to multiple locations), that stops them from destroying everything.

        A military is both physical AND smart. They can target multiple locations at once and destroy whole buildings.

        • jacquesm 7 hours ago

          > I don't think there is much you can do about being targeted by a military, simply because of how unique the attack vector is.

          You could choose not to invade other countries.

          • loeg 7 hours ago

            This (as with defense) is kind of outside Google or Yandex's purview.

            • phatfish 6 hours ago

              Yandex is a part of Russia's military. Just the same as Google, MS, Amazon etc. provide services for the US military. Google et al. are probably in the critical path of defence for most European countries as well, insane though that is.

              • ivan_gammel 5 hours ago

                Not defending Yandex here, but I think their military involvement might be as accidental as of an American farmer whose beef landed in the cantina of aircraft carrier. Government and military procurement in Russia is its own universe, with strong players having specific IT expertise and capable of building DCs and tech. Assuming that everywhere in the world it’s the same as in America is wrong. Consumer tech companies aren’t operating this way usually, it is the scale of American Big Tech that allows them to compete with traditional contractors.

                • a012 4 hours ago

                  In general it’s the price of working with government, also see AWS Bahrain. I wonder if their insurance actually pays out because those are not officially wars there so hopefully they could recover some what from the insurance.

            • jacquesm 6 hours ago

              Said every company serving fascists ever.

              No, you can choose to collaborate or you can shut it down.

              Collaborators don't get to point back in time and say 'oh we had no choice', even if the choice was a painful one. Sorry it does not work that way.

              • kgeist 5 hours ago

                A very naive take from someone who clearly lives in a place where people have real choices, economic freedom, freedom of movement, and a government that protects them. "Just shut it down, bro" risks destroying your livelihood and leaving your family financially stranded, and yourself incarcerated or sent to the war zone. And it's not like Yandex develops weapons of mass destruction, you probably assume it's a collaboration even if Yandex simply hosts the Defense Ministry's websites. No sane parent will put their family at risk for this kind of stuff. "I'm going against the government for abstract ethical reasons" is something very few people/countries can afford.

                And you can't shut it down anyway. The government will just nationalize it and keep it running. As long as you're the one in charge, you can at least throw a few hidden obstacles in the way, like dragging out legal processes.

                • jacquesm 4 hours ago

                  No, a pretty informed take from someone who had family members that once upon a time made some very tough choices because they thought it was the right thing to do.

                  You can pretend at being ethical and moral as long as there is no price to pay, but when the time comes that it matters there will always be a price tag. Whether you are prepared to pay or not is what defines whether you are ethical or just pretending.

                  Company execs make decisions, employees make decisions, everybody carries a part.

          • AlienRobot 7 hours ago

            I guess, but that doesn't sound like something in the control of a single individual company.

            • freeopinion 4 hours ago

              Is it just me, or didn't we just see a single company cause a bit of a dustup when they refused to provide certain services to a military that wanted to bomb another country?

              If it doesn't sound like something in the control of a single individual company, perhaps you have something distorting your hearing.

            • jacquesm 6 hours ago

              They control their own individual contribution.

          • whatdouthink 7 hours ago

            But apparently this does not apply to you.

            • jacquesm 6 hours ago

              At least one russian shill that isn't affected by the Yandex strikes. Let's see how the rest of them fares, HN has its fair share of these characters.

              • microtonal 5 hours ago

                The pattern is quite interesting. I think I have seen this account in another thread today. They post pro-Russia comments, get downvoted and then delete their comment again.

                • jacquesm 4 hours ago

                  There must be at least 10 or 20 of these, I point them out to the mods but some of them - for instance our good friend 'drysine' - are alive and well even after months of spouting their junk. It is really annoying.

        • simondotau 7 hours ago

          You can learn to quickly diversify availability (or at least data safety) beyond the region of conflict when a kinetic war breaks out. The moment “kinetic sanctions” became the strategy, the risk to data centres should have been self-evident. And if it wasn’t immediately obvious, it should have been blindingly so when targeting expanded from oil refineries to Wildberries warehouses.

          • ivan_gammel 6 hours ago

            I don‘t think you can build a new data center in such a short time frame that passed since attacks on WB, definitely not when you can source hardware only from the black market.

            • simondotau 6 hours ago

              I’m not describing what Yandex should do, but rather what their customers should do. Whether that means diversifying to eastern Russia, or China, or Belarus, I don’t know what options exist.

            • Bluestein 3 hours ago

              ... and in the middle of the RAM-pocalypse, no less.-

      • Hamuko 7 hours ago

        I feel like this isn't even a particularly new thing. I worked at a medium-sized SaaS company and we did disaster recovery drills for moving our stack from eu-west-1 to eu-central-1 in case something catastrophic happened in Ireland. If you want HA, you kinda have to assume that any single country in the world can have some kind of a crippling disaster. Unfortunately for Yandex's clients, Yandex only has regions in two countries, and not that many regions either.

    • alephnerd 6 hours ago

      > The entire compute core is offline, and even worse, Cloud Backup

      Their Kazakh regions are available according to the dashboard, so it isn't as catastrophic.

      Their managed DBs and data processing services are heavily affected though with no Kazakh redundancies from the looks of it.

      • schleck8 3 hours ago

        The KZ region wasn't intended for Russia's entire workload, that's a secondary region with better Central Asian access.

        If what you deduct were correct, Yandex would not be telling its customers to switch to competitora like VK Cloud. They even have a "priority onboarding code" called "CloudBro" for three competitors.

    • bamboozled 7 hours ago

      I just searched "blyat" and it worked, so?

      • eptcyka 7 hours ago

        Given that blyad is just punctuation at this point, I am not surprised.

        • walrus01 7 hours ago

          I predict a great many more videos coming out of Russia of Firepoint UAVs flying into refineries and such, punctuated by background audio commentary that can be summed up as "cyka blyat"

        • throw-the-towel 7 hours ago

          The username checks out!

          ("Ept" and "suka" are two other swearwords, that are also used much like punctuation.)

          • bamboozled 22 minutes ago

            Get with the times, gramps

  • f311a 7 hours ago

    I can’t believe there are so many dumb comments in this thread. All it shows is that crawling from Yandex search engine stopped from one Yandex data center ASN.

    No one runs opinion/malicious bots from data center IPs that people mention here.

    Did people actually stop thinking?

    • walrus01 7 hours ago

      On the other hand there are plenty of datacenter located command/control systems that puppeteer vast fleets of residential proxies (and Russia is by no means the only one doing so), so it will be very telling to see what social media accounts go silent over the coming days and weeks.

      > from one Yandex data center ASN

      This is only one of two extant Yandex ASN, not an ASN specific to one geographic region/datacenter.

      https://www.peeringdb.com/net/1751

      The other one is this: https://www.peeringdb.com/net/20950

      And the 200350 also shows a near complete drop off in bot activity:

      https://radar.cloudflare.com/bots/as200350?dateRange=7d

      • magic_quotes 6 hours ago

        > command/control systems

        There is Hetzner for that.

    • monday_ 7 hours ago

      You are replying to a war propaganda post with a heavily editorialized title. Of course it's swimming in bad faith engagement, that's how these things work.

      • walrus01 6 hours ago

        I'd expect nothing less than a comment such as this, from an account that hasn't posted even once for the last 7 months and has in its post history a claim of being located in Moscow. But hey, thanks for showing up to remind us of how terrible the imperialist war-mongering west is. Very refreshing.

        • orbital-decay 5 hours ago

          Both comments, his and especially yours, are terrible interpretations. That's how any discussion is turned into a mud flinging party.

        • mattstir 6 hours ago

          Not to get sidetracked, and not to argue against anything you've said, but how do you figure that out? For people you disagree with, do you open their profile's comments and start keyword-searching "russia" "china" "moscow" etc in hopes of finding a hit? They mentioned that city once in Jan 2024, halfway down the page and in passing. I'm just curious about how others use this site.

          • walrus01 6 hours ago

            Different people read at different speeds, it took me about 5 seconds when skimming it. If you engage in enough discussion related to Russia online you will quickly learn to identify when inauthentic commenters suddenly show up from a previously idle account to add their 2 cents.

            The person in question doesn't exhibit much of it, but one will also learn when skimming to identify certain grammar and sentence structure characteristics that can point to what is the first language of a person, even if they're writing in fluent English.

            • kakacik 6 hours ago

              All that expertise (which requires some proper experience in the topic) even before you plug a llm to it, even few years ago they were good enough to identify unique writing styles of people across different accounts on HN.

              Anonymity is gone from internet for some time.

              • walrus01 5 hours ago

                I have seen document-analysis guides with info on how to identify the regional location of anonymous Internet commenters specifically within the US 48 states if you have a sufficiently large corpus of their text, as it relates to how they use certain regional slang, metaphors, colloquialisms, and words to describe things. Think of it as similar to how linguists have made maps showing regional variations in whether people call it "soda" or "coke" or "pop", but extended to all other common forms of North American dialect.

                https://www.businessinsider.com/soda-vs-pop-map-2012-7

    • braiamp 6 hours ago

      The funny thing is that apparently I'm the only one that flagged it... I don't know why people comment instead of using the tools?

    • treyd 5 hours ago

      The bots might be run in the datacenter and proxied through residential IPs as the exit point.

      • Sayrus 5 hours ago

        If they are, then that wouldn't be YANDEX AS13238. So the linked graph wouldn't show these changes.

      • f311a 5 hours ago

        You won't see this kind of stats on the CF page.

        All it shows is direct traffic against CF infrastructure.

  • r721 9 hours ago

    *Sudden drop in Cloudflare bot traffic from AS13238 YANDEX — Yandex LLC

    UPD Definition of bot traffic from Cloudflare's glossary:

    >Bot vs. human traffic

    >The percentage of HTTP requests classified as bot versus human, based on bot scores. Requests with a bot score between 1 and 29 are classified as likely automated (bot), while requests with a score of 30 or above are classified as likely human. For more information, refer to Bot classes.

    >By default, Radar shows bot vs. human traffic for requests to HTML content. This filter is meant to represent traditional web traffic by excluding API calls, asset requests (images, scripts, fonts), and other machine-to-machine requests.

    https://developers.cloudflare.com/radar/glossary/#bot-vs-hum...

    https://developers.cloudflare.com/bots/concepts/bot-score/

    • walrus01 9 hours ago

      Correct, I probably didn't didn't write that in the clearest possible way, I meant "detected bot traffic hitting cloudflare originating from Yandex".

  • caidan 2 hours ago

    So cloudflare https://radar.cloudflare.com/bots?dateRange=7d shows 40% of worldwide bot traffic is from the us and <1% is from Russia. So what is this chart of traffic from russias search engine supposed to show?

    • saxonww 2 hours ago

      Yandex is a search engine like Google is a search engine. Both are also cloud vendors. The chart of traffic from Yandex is showing that the majority of traffic was considered bot traffic, and after Ukraine's attack on its datacenter(s), that traffic has reduced substantially.

      It looks like the majority of online bot traffic is coming from cloud vendor networks, which isn't surprising to me. But it makes me think that the "bot share by location" chart is more useful as a "which cloud vendor has bad bot control" chart vs. a "where is bot traffic coming from" chart.

  • pluc 8 hours ago

    That's some intense mitigation from Cloudflare

    • Pikamander2 an hour ago

      Their latest consumer plan includes "Super Duper Bot Fight Mode", which lets you drone strike one data center in a sanctioned country of your choosing.

      For additional strikes or to upgrade to ICBM-based payloads, you'll have to contact them to set up an enterprise plan.

    • Alifatisk 7 hours ago

      You gave me a good laugh, cheers!

  • LiamPowell 7 hours ago

    Everyone is mentioning crawlers, but wouldn't most traffic from a datacenter's ASN usually be bots just in general given that there's not many humans there to generate human traffic?

    • walrus01 6 hours ago

      Here's an example French hosting company which has something like 14.8% "human" traffic, (the Yandex is under 5% human) though how much of that is actual humans and not advanced things puppeteering headless browsers is another question.

      https://radar.cloudflare.com/traffic/as12876

  • bhouston 7 hours ago

    The US is still responsible for almost 50% of traffic of which the top are Amazon, Google, Microsoft, Cloudlare.

    https://radar.cloudflare.com/bots

    • rpozarickij 6 hours ago

      It's interesting (but not surprising) that so much traffic comes from the Netherlands and Singapore despite their sizes compared to the countries at the top of this list.

      While not necessarily related to bot traffic, but I was thinking that in the age of AI perhaps we'll be comparing technological development of countries based on their usage of AI per capita (similar to what we have with electricity usage per capita).

      • bhouston 3 hours ago

        100%. It will roughly translate to GDP. It is no different than industrialization/mechanization/computerization transitions.

    • michelb 2 hours ago

      Indeed, most of my server's 'Chinese' and 'Russian' bot traffic is originating from US IP addresses.

  • ericpauley 7 hours ago

    Interestingly most traffic coming out of this AS was actually UDP: https://dashboard.terracenetworks.com/sources/asns/13238

    Pretty benign AS as far as actual exploit or malicious crawling is concerned.

    • cowlevel 7 hours ago

      Probably QUIC if true, but you should also ask how these people get their data, because this isn't something you can just see or look up.

  • karol 6 hours ago

    Yandex is reporting an outage for some services. https://dzen.ru/news/story/75e4b917-952d-5304-a9b4-70e5dc1fb...

  • calin2k 2 hours ago

    so much love for russia in the comments, maybe bot operators get some spare time to comment here

  • tkrl-pskl 6 hours ago

    Apart from the correct argument that a search engine like Yandex will have crawlers, I would not be surprised if Western AI companies also used Yandex to scrape covertly.

    Nvidia tried to pay off the Russian Anna's Archive for stolen data:

    https://www.tomshardware.com/tech-industry/artificial-intell...

    It would not be a surprise if similar deals have been reached with Yandex.

    But this is a nice demonstration by Ukraine that all our internet problems are caused by large data centers, wherever they may be located.

  • speckx 7 hours ago

    I have to wonder what will happen when the remaining 6 data centers get hit as well. It's bound to happen.

    • qingcharles 5 hours ago

      I think this really highlights the changing face of war.

      It's hard to go to war now when your enemy can just use a few small drones to take out everything your citizens care about in a single day (social media, online deliveries etc).

      And these things are practically irreplaceable in a war when you're sanctioned up the wazoo. Where are you buying racks of Xeons and DDR5 RAM and Nvidia GPUs?

    • walrus01 7 hours ago
    • afdbcreid 7 hours ago

      If there will be an world-wide war, sure. But at that point, the Internet as we know it will probably collapse anyway.

      • cowlevel 7 hours ago

        There is one, but it's taking place mostly by information means, not physical.

    • Hamuko 7 hours ago

      Are there even six remaining?

  • beaker52 7 hours ago

    It’s not really surprising that bot traffic originating from a network went away when _all_ traffic originating from that network stopped.

  • pKropotkin 7 hours ago

    Could be just crawlers

  • luckystarr 3 hours ago

    Does that include the disinformation infrastructure? If so, they should keep it on.

  • accountrequired 7 hours ago

    When Brazil and Afrinet? :P

  • bamboozled 7 hours ago

    I'm going to be really interested how much this cleans up the internet, I mean the damage is done if you read comment sections on youtube etc, but let's see how long the BS persists.

    • cowlevel 7 hours ago

      It's only counting Yandex search crawler traffic, not any actually bad bots.

  • toomuchtodo 9 hours ago

    Cloudflare should consider donating to the Ukrainian military for the public service they are performing.

    • exe34 8 hours ago

      I was thinking, we should all contribute to a Yandex fund for the Ukrainian mil to help keep the level of bot activity on the rest of the internet under control!

  • dzink 6 hours ago

    Now check how many open models search Yandex when asked for something.

  • fHr 6 hours ago

    surprisedpikatchu.jpeg

  • WiSaGaN 9 hours ago

    isn't this only counting russian origin already?

    • walrus01 9 hours ago

      The URL is CF's public metrics for bot traffic from a single specific Russian ASN, Yandex.

      https://www.peeringdb.com/net/1751

      • cowlevel 8 hours ago

        oh well of course if you blow up Yandex then Yandex stops sending you traffic, because they got blown up.

        • walrus01 7 hours ago

          And nothing of value was lost.

          • cowlevel 7 hours ago

            Yandex is the best search engine that doesn't follow American censorship norms. For this reason Kagi uses them as one source of several.

  • surfingdino 7 hours ago

    So, is sending hot hate towards a bot farm going to be a paid service on Cloudflare now?

  • modzu 5 hours ago

    propaganda

  • rvz 9 hours ago

    “AI agents” is just a fancy rebranding of “bots” with some “intelligence”.