Comment by mmarian

2 days ago

> block IP addresses based on rules triggered by specific behavior

Problem is, bots can easily can resort to resi proxies, at which point you'll end up blocking legitimate traffic.

Again, it depends. Residential proxies are much more expensive, and most vulnerability scanners will never shift to them.

I believe that there is a low chance that a real customer behind this residential IP will come to your resource. If you do an EU service, there is no pain to block Asian IPs and vice-versa.

What is really important here is that most people block IPs on autopilot without seeing the distribution of their actions, and this really matters.