Of course they have bots... That's how you index the web.
If we took Google offline I bet there would also be a reduction in bot traffic from them too!
Indexing is also probably a low priority task, so if half their datacenter capacity is taken offline, their bot traffic probably reduces by more than 50%.
Logic says google bots do not come disguised, but as google agents.
Or is there other information?
Now there is probably also AI agent spam from google, but not at this level I believe. Also I am not fully clear what they count as spam, I doubt they would include google in this list, so do they include yandex bots here, if they come officially?
I am unsure what you're trying to say. But it seems like you don't understand what Bot means in general and how is it specifically defined for the metric provided in that page.
From that pages point of view, a Google bot, Yandex bot, or your uncle Tom's AI agent spam is the same, a bot.
If official yandex bots ain't included in this data here - then it means spam/scam bots come indeed from yandex servers. As they stopped working, when the yandex data center was hit.
It's a nice reminder that HN is just filled with the same primitive tribal normies and is always getting oneshotted by the same transparent xenophobic hysteria that plagues the rest of the internet.
I keep thinking about them often, what a definition of cancer on modern humanity that country is. Not all people inside, far from it, but that country - absolutely, definitely and consistently.
And most of those inside allowed this to happen over decades since even harsh dictatorships represent underlying population in many ways, many even cheered / still cheer on direction their country has taken, and non-trivial amount also like raiding neighbors for the kill, loot and money in general.
A stark warning to US if you keep letting things slide to evil direction, this is roughly how you end up over time.
Yandex has cloud offering, their servers are used for actual bot traffic, not just crawlers. Yandex hasn’t been only a search company for a very long time.
I've reported high-volume exploit scanners multiple times, and when expiring blocks a week later, they typically would show up & resumt with the same IP at some point.
Maybe they'd care if the account was using a stolen credit card and there was a chance they wouldn't get their money, but they definitely do not care otherwise for normal people like me. I'm sure that'd be different if it's a multinational or a country-level government body is reporting something, but I can't get those to do my bidding.
Right, because I've had such outstanding results getting in touch with actual humans from Google when reporting abusive traffic directed towards my IP ranges. Top tier attention from people who really care.
I like to study rhetoric, and appreciate folks asking for specifics. There's a lot of generalities thrown around on this forum that are highly questionable, and the only antidote I have is to request details. It's surprising how often folks resist.
A sibling comment replying to you is using a familiar tactic, which is to try to shame you for asking for specifics, while simultaneously providing none and telling you that it's obvious.
Occasionally people do provide details and I learn something, but that's not the common case, sadly.
> Can you point to a few comments that you consider examples?
Just search for “Russia” on HN and follow threads. You’ll find lots of “what about West/Jews”, “Russia is fighting against NATO”, etc. Then open any western news outlet on YouTube and follow comments too.
Having multiple genuinely different viewpoints in a discussion isn’t evidence of “bots”, it’s the default in any community that isn’t heavily censored to silence dissent. And individuals voicing their different viewpoints isn’t “propaganda”, it’s the definition of discourse.
The russian bots are better.. usually its conspiracy fog, attached to a valid russia opposing point that reveals them. Chinese bots are just this months CCP talking points, so can be quite easily visible if they cram some topic only china cares about into every reply.
The downvotes are because you're resisting easily-observed reality with the seemingly-rational response "Where is this 'air'? If I'm breathing it, it should be easy to point to, no?"
No. If you can't see it, and don't understand it's there, you cannot be explained to. You're someone with no palate asking how anyone else can know if a wine tastes good.
I think you're saying that it's hard to articulate why some particular comment should be judged as having come from a bot. I.e., similar to the SCOTUS opinion regarding pornography: "I know it if I see it".
Is that correct?
If so, wouldn't that still admit someone providing a specific example? The whole point of my original comment was that I knew I wasn't judging these things the same as others were.
The HTTP traffic from Yandex is down to ~ 0 % after the third strike, after the first two strikes already degraded it. I wonder how this looks like at the network level because their search page still serves, but presumably their crawler is inactive now
Edit: Here is some more info, they do have availability issues as is to be expected
> Because three of its primary facilities were knocked offline within four days, Yandex’s failover mechanisms broke down[1][8].
> Outages have cascaded across Yandex Go (taxis), Yandex Pay, food delivery, smart home platforms, internal logistics, and third-party corporate services hosted on Yandex Cloud[2][7]. Problems have spilled into neighboring countries using these systems (Belarus, Kazakhstan, Armenia, Serbia)[2][7].
Edit 2: Here is the Yandex Cloud status page, their GCP/AWS equivalent. The entire compute core is offline, and even worse, Cloud Backup
I don't know how useful it will be as a case study since an HA/Ops person in (let's say, the US, Canada, AU, western european countries) has access to do things like buy hypervisor capacity or colocation in just about any location. I could go buy colo in Brussels or Panama City or San Diego or Edmonton or Melbourne tomorrow by contacting the right people.
The Russians are much more restricted from doing anything geographically outside of their own borders (for very well justified sanctions reasons), so their limitations are not the same as an HA person in almost any other country. Maybe some Iranian HA/Ops people will be comparing notes with them.
Sometimes there exist data or processing residence requirements that bind you to a specific region (e.g. EU-only). Also, „all AZs in this region no longer exist“ is not on everyone‘s bingo card, this is a good reminder why multi-AZ deployment in the same region may be not enough.
For data center guys this is definitely a case study, because drone attacks are probably on the threat list for everyone now, for various reasons, including domestic terrorism and hybrid warfare. If you want to defend your investment, time to think what covers you from the air.
It's an open question at what point we'll start seeing small fiesty startups that want to sell you a privately owned air defense system for your datacenter roof. The tech to do it is probably far ahead of the regulatory regime to own and operate autonomous small radar+SAM batteries.
It will require some involvement of state, but it is plausible, that critical infrastructure will be required to have this covered and certain big, licensed private contractors may be able to operate air defense systems on such sites (do you smell the money and lobbying effort?).
Also this may influence the design of such data centers. A drone that a paramilitary group can build is not very sophisticated and won’t carry big payloads. Put an outer concrete shell or some better passive defense, and maybe that will be enough.
As a result of some of my work only slightly related to telecom/internet infrastructure, I happened to get on the marketing lists for about six different Chinese companies that will gladly sell you a full size Shahed-136 clone complete with 2 stroke petrol motor. I wouldn't say that small paramilitaries being only able to fly a 5-10kg max size quadcopter with a munition on it into a datacenter is the limit of possible future capabilities. These things are cheaply made in fiberglass molds and look to be dead simple. They're already showing demo videos of them flying around with very low cost ardupilot capable flight controllers.
They even advertise the airframe and motor packages on Instagram....
It was clearly meant as an example of the ease of a non-russian company buying geographically-distributed services in the global marketplace, not "I could go buy this with a few docusign signatures and SWIFT wire transfers tomorrow". I am not in the market for colo in Panama City or Melbourne. I don't think it's a bad thing that the russians are hampered by many limitations but whatever lessons their HA people are learning these days are probably very specific to a sanctioned Russia.
Unironically yes, if you're just a typical B2B SaaS who doesn't have "datacenter getting hit by a literal missile" in your threat model, this coupled with offsite backups is probably the logical DR plan for that scenario.
I don't think there is much you can do about being targeted by a military, simply because of how unique the attack vector is.
Hacking is smart but happens through software, so if you have hardware (i.e. physical) barriers, that stops the hacking.
Natural disasters happen physically but they are dumb, so if you have software redundancy (i.e. by copying the data to multiple locations), that stops them from destroying everything.
A military is both physical AND smart. They can target multiple locations at once and destroy whole buildings.
You can learn to quickly diversify availability (or at least data safety) beyond the region of conflict when a kinetic war breaks out. The moment “kinetic sanctions” became the strategy, the risk to data centres should have been self-evident. And if it wasn’t immediately obvious, it should have been blindingly so when targeting expanded from oil refineries to Wildberries warehouses.
I don‘t think you can build a new data center in such a short time frame that passed since attacks on WB, definitely not when you can source hardware only from the black market.
I’m not describing what Yandex should do, but rather what their customers should do. Whether that means diversifying to eastern Russia, or China, or Belarus, I don’t know what options exist.
I feel like this isn't even a particularly new thing. I worked at a medium-sized SaaS company and we did disaster recovery drills for moving our stack from eu-west-1 to eu-central-1 in case something catastrophic happened in Ireland. If you want HA, you kinda have to assume that any single country in the world can have some kind of a crippling disaster. Unfortunately for Yandex's clients, Yandex only has regions in two countries, and not that many regions either.
I predict a great many more videos coming out of Russia of Firepoint UAVs flying into refineries and such, punctuated by background audio commentary that can be summed up as "cyka blyat"
I can’t believe there are so many dumb comments in this thread.
All it shows is that crawling from Yandex search engine stopped from one Yandex data center ASN.
No one runs opinion/malicious bots from data center IPs that people mention here.
You are replying to a war propaganda post with a heavily editorialized title. Of course it's swimming in bad faith engagement, that's how these things work.
I'd expect nothing less than a comment such as this, from an account that hasn't posted even once for the last 7 months and has in its post history a claim of being located in Moscow. But hey, thanks for showing up to remind us of how terrible the imperialist war-mongering west is. Very refreshing.
Not to get sidetracked, and not to argue against anything you've said, but how do you figure that out? For people you disagree with, do you open their profile's comments and start keyword-searching "russia" "china" "moscow" etc in hopes of finding a hit? They mentioned that city once in Jan 2024, halfway down the page and in passing. I'm just curious about how others use this site.
Different people read at different speeds, it took me about 5 seconds when skimming it. If you engage in enough discussion related to Russia online you will quickly learn to identify when inauthentic commenters suddenly show up from a previously idle account to add their 2 cents.
The person in question doesn't exhibit much of it, but one will also learn when skimming to identify certain grammar and sentence structure characteristics that can point to what is the first language of a person, even if they're writing in fluent English.
All that expertise (which requires some proper experience in the topic) even before you plug a llm to it, even few years ago they were good enough to identify unique writing styles of people across different accounts on HN.
On the other hand there are plenty of datacenter located command/control systems that puppeteer vast fleets of residential proxies (and Russia is by no means the only one doing so), so it will be very telling to see what social media accounts go silent over the coming days and weeks.
> from one Yandex data center ASN
This is only one of two extant Yandex ASN, not an ASN specific to one geographic region/datacenter.
*Sudden drop in Cloudflare bot traffic from AS13238 YANDEX — Yandex LLC
UPD Definition of bot traffic from Cloudflare's glossary:
>Bot vs. human traffic
>The percentage of HTTP requests classified as bot versus human, based on bot scores. Requests with a bot score between 1 and 29 are classified as likely automated (bot), while requests with a score of 30 or above are classified as likely human. For more information, refer to Bot classes.
>By default, Radar shows bot vs. human traffic for requests to HTML content. This filter is meant to represent traditional web traffic by excluding API calls, asset requests (images, scripts, fonts), and other machine-to-machine requests.
Everyone is mentioning crawlers, but wouldn't most traffic from a datacenter's ASN usually be bots just in general given that there's not many humans there to generate human traffic?
Here's an example French hosting company which has something like 14.8% "human" traffic, (the Yandex is under 5% human) though how much of that is actual humans and not advanced things puppeteering headless browsers is another question.
Apart from the correct argument that a search engine like Yandex will have crawlers, I would not be surprised if Western AI companies also used Yandex to scrape covertly.
Nvidia tried to pay off the Russian Anna's Archive for stolen data:
It's interesting (but not surprising) that so much traffic comes from the Netherlands and Singapore despite their sizes compared to the countries at the top of this list.
While not necessarily related to bot traffic, but I was thinking that in the age of AI perhaps we'll be comparing technological development of countries based on their usage of AI per capita (similar to what we have with electricity usage per capita).
An eye for an eye for the Russians.
I love western imperial propaganda though, and how HN so eagerly amplifies it. There’s something self-fulfilling about willingly becoming a foot soldier of the Empire.
Here's to a world where the West is monolithic, and may Iran, Iraq, Yugoslavia, Syria, Libya, Lebanon, Palestine be only be the beginning. And may every new crusade for freedom and democracy leave behind another Gaza, in pursuit of upholding human rights and civilizing the world.
Low-IQ Americans will think these bots are X accounts posting memes against Democrats, which is why the media is astroturfing this news to target American liberals. In reality, most of these bots are just scripts performing normal enterprise jobs, but most people know nothing about how the world works.
I'm going to be really interested how much this cleans up the internet, I mean the damage is done if you read comment sections on youtube etc, but let's see how long the BS persists.
I was thinking, we should all contribute to a Yandex fund for the Ukrainian mil to help keep the level of bot activity on the rest of the internet under control!
Modern day Russia is about the furthest possible thing from "commies". Kleptocracy? Fascism? Dictatorship? Oligarchy? Sure, some bizarro world combination of all of those. But if you want people to take your opinion seriously, try not to sound like somebody's demented grandpa by tossing around "commie" like it's 1959.
I am pretty damn sure that whatever Putin is doing these days is in no way motivated by an adherence to the Marxist-Leninist way of life.
According to orthodox Marxism, the Russian empire had not fully industrialised or created a widespread bourgeoisie. It was still largely feudal and rural, and a monarchy. Some Marxists have tried to say retroactively that the Russian Revolution was a bourgeois not a proletarian revolution as a result.
Lenin tried to paint kulaks as bourgeois en lieu of actual target, and had to modify Marxism heavily to make things fit. Stalin certainly managed to industrialise much of the USSR, so fulfilled that end. Yeltsin-Putin Russia has created an actual bourgeois state, maybe allowing a workers' revolution to take place for real next time.
Or sort of. In reality, Marx was not an infallible prophet. He did not anticipate artificial intelligence or its consequences, genetic engineering, broadcast media or a host of other things. History has not followed all of the paths he suggested.
Of course they have bots... That's how you index the web.
If we took Google offline I bet there would also be a reduction in bot traffic from them too!
Indexing is also probably a low priority task, so if half their datacenter capacity is taken offline, their bot traffic probably reduces by more than 50%.
EDIT: I was wrong, they're just generic bot vs human traffic numbers and you're right.
Or is there other information?
Now there is probably also AI agent spam from google, but not at this level I believe. Also I am not fully clear what they count as spam, I doubt they would include google in this list, so do they include yandex bots here, if they come officially?
From that pages point of view, a Google bot, Yandex bot, or your uncle Tom's AI agent spam is the same, a bot.
So yandex bots are included and this metric says nothing about malicious yandex intent here.
Yes, but it's mostly the opposite tribe of the one you're complaining about.
And most of those inside allowed this to happen over decades since even harsh dictatorships represent underlying population in many ways, many even cheered / still cheer on direction their country has taken, and non-trivial amount also like raiding neighbors for the kill, loot and money in general.
A stark warning to US if you keep letting things slide to evil direction, this is roughly how you end up over time.
Touch grass.
https://radar.cloudflare.com/bots/as200350?dateRange=7d
https://www.peeringdb.com/net/20950
Maybe they'd care if the account was using a stolen credit card and there was a chance they wouldn't get their money, but they definitely do not care otherwise for normal people like me. I'm sure that'd be different if it's a multinational or a country-level government body is reporting something, but I can't get those to do my bidding.
/s
I've never noticed occurrences of such stuff, so I'm curious what I'm failing to key in on.
Edit: and would someone mind explaining the downvotes? If they're meant to communicate something to me, I'm genuinely not understanding.
A sibling comment replying to you is using a familiar tactic, which is to try to shame you for asking for specifics, while simultaneously providing none and telling you that it's obvious.
Occasionally people do provide details and I learn something, but that's not the common case, sadly.
Just search for “Russia” on HN and follow threads. You’ll find lots of “what about West/Jews”, “Russia is fighting against NATO”, etc. Then open any western news outlet on YouTube and follow comments too.
No. If you can't see it, and don't understand it's there, you cannot be explained to. You're someone with no palate asking how anyone else can know if a wine tastes good.
Regardless, wouldn't it be easy to point me to even one example if it's as prevalent as (I think) you're saying?
Or am I missing your main point, i.e. that what's being described can't be demonstrated via example?
Read and think about my wine analogy, if you care.
Is that correct?
If so, wouldn't that still admit someone providing a specific example? The whole point of my original comment was that I knew I wasn't judging these things the same as others were.
Only then, I'll believe you that wine can taste good or bad.
Is my mind open? Is this not a waste of your time?
That is a drop in traffic specifically from Yandex bots (which includes their crawlers and other apps hosted in their DC)
Now compare it with Bot Traffic in:
* Russia: https://radar.cloudflare.com/bots/ru?dateRange=7d
* Europe: https://radar.cloudflare.com/bots/europe?dateRange=7d
* Worldwide: https://radar.cloudflare.com/bots?dateRange=7d
Dip is barely noticeable even in Russia.
Its like saying, "API requests are completely down" (and small disclaimer: only from your server, because your server is down)
If so, it isn't particularly surprising that the line would go down.
EDIT: yes, it is. Looking at the same graph for all of Russia, and there's no discernible pattern:
https://radar.cloudflare.com/bots/ru?dateRange=7d
same for the 48h view:
https://radar.cloudflare.com/bots/ru?dateRange=2d
Edit: Here is some more info, they do have availability issues as is to be expected
> Because three of its primary facilities were knocked offline within four days, Yandex’s failover mechanisms broke down[1][8].
> Outages have cascaded across Yandex Go (taxis), Yandex Pay, food delivery, smart home platforms, internal logistics, and third-party corporate services hosted on Yandex Cloud[2][7]. Problems have spilled into neighboring countries using these systems (Belarus, Kazakhstan, Armenia, Serbia)[2][7].
Edit 2: Here is the Yandex Cloud status page, their GCP/AWS equivalent. The entire compute core is offline, and even worse, Cloud Backup
https://status.yandex.cloud/ru/dashboard
> ru Compute Cloud, ru Kubernetes, ru PostgreSQL, ru ClickHouse, ru MySQL, ru YDB, ru Kafka, ru Application Load Balancer
Interestingly, Yandex tells its users on the status page to switch to competitors Selectel, K2Cloud, and VK Cloud. Which will probably be hit next
The Russians are much more restricted from doing anything geographically outside of their own borders (for very well justified sanctions reasons), so their limitations are not the same as an HA person in almost any other country. Maybe some Iranian HA/Ops people will be comparing notes with them.
For data center guys this is definitely a case study, because drone attacks are probably on the threat list for everyone now, for various reasons, including domestic terrorism and hybrid warfare. If you want to defend your investment, time to think what covers you from the air.
Also this may influence the design of such data centers. A drone that a paramilitary group can build is not very sophisticated and won’t carry big payloads. Put an outer concrete shell or some better passive defense, and maybe that will be enough.
They even advertise the airframe and motor packages on Instagram....
Hacking is smart but happens through software, so if you have hardware (i.e. physical) barriers, that stops the hacking.
Natural disasters happen physically but they are dumb, so if you have software redundancy (i.e. by copying the data to multiple locations), that stops them from destroying everything.
A military is both physical AND smart. They can target multiple locations at once and destroy whole buildings.
You could choose not to invade other countries.
No, you can choose to collaborate or you can shut it down.
Collaborators don't get to point back in time and say 'oh we had no choice', even if the choice was a painful one. Sorry it does not work that way.
Their Kazakh regions are available according to the dashboard, so it isn't as catastrophic.
Their managed DBs and data processing services are heavily affected though with no Kazakh redundancies from the looks of it.
("Ept" and "suka" are two other swearwords, that are also used much like punctuation.)
No one runs opinion/malicious bots from data center IPs that people mention here.
Did people actually stop thinking?
The person in question doesn't exhibit much of it, but one will also learn when skimming to identify certain grammar and sentence structure characteristics that can point to what is the first language of a person, even if they're writing in fluent English.
Anonymity is gone from internet for some time.
> from one Yandex data center ASN
This is only one of two extant Yandex ASN, not an ASN specific to one geographic region/datacenter.
https://www.peeringdb.com/net/1751
The other one is this: https://www.peeringdb.com/net/20950
And the 200350 also shows a near complete drop off in bot activity:
https://radar.cloudflare.com/bots/as200350?dateRange=7d
There is Hetzner for that.
UPD Definition of bot traffic from Cloudflare's glossary:
>Bot vs. human traffic
>The percentage of HTTP requests classified as bot versus human, based on bot scores. Requests with a bot score between 1 and 29 are classified as likely automated (bot), while requests with a score of 30 or above are classified as likely human. For more information, refer to Bot classes.
>By default, Radar shows bot vs. human traffic for requests to HTML content. This filter is meant to represent traditional web traffic by excluding API calls, asset requests (images, scripts, fonts), and other machine-to-machine requests.
https://developers.cloudflare.com/radar/glossary/#bot-vs-hum...
https://developers.cloudflare.com/bots/concepts/bot-score/
https://radar.cloudflare.com/traffic/as12876
Nvidia tried to pay off the Russian Anna's Archive for stolen data:
https://www.tomshardware.com/tech-industry/artificial-intell...
It would not be a surprise if similar deals have been reached with Yandex.
But this is a nice demonstration by Ukraine that all our internet problems are caused by large data centers, wherever they may be located.
Pretty benign AS as far as actual exploit or malicious crawling is concerned.
https://radar.cloudflare.com/bots
While not necessarily related to bot traffic, but I was thinking that in the age of AI perhaps we'll be comparing technological development of countries based on their usage of AI per capita (similar to what we have with electricity usage per capita).
Here's to a world where the West is monolithic, and may Iran, Iraq, Yugoslavia, Syria, Libya, Lebanon, Palestine be only be the beginning. And may every new crusade for freedom and democracy leave behind another Gaza, in pursuit of upholding human rights and civilizing the world.
https://cofense.com/blog/how-cloudflare-services-are-abused-...
https://www.heise.de/en/news/Report-Cybercriminals-use-Cloud...
Or maybe they would just want to get rid of the competition.
https://www.peeringdb.com/net/1751
(I’d welcome a data center and oil infrastructure targeting specific fund)
I am pretty damn sure that whatever Putin is doing these days is in no way motivated by an adherence to the Marxist-Leninist way of life.
Lenin tried to paint kulaks as bourgeois en lieu of actual target, and had to modify Marxism heavily to make things fit. Stalin certainly managed to industrialise much of the USSR, so fulfilled that end. Yeltsin-Putin Russia has created an actual bourgeois state, maybe allowing a workers' revolution to take place for real next time.
Or sort of. In reality, Marx was not an infallible prophet. He did not anticipate artificial intelligence or its consequences, genetic engineering, broadcast media or a host of other things. History has not followed all of the paths he suggested.