https://OpenStreetMap.org has been disrupted today. We're working to keep the site online while facing extreme load from anonymous scrapers spread across 100,000+ IP addresses. Please be patient while we mitigate and protect the service. #OpenStreetMap #DDoS #Scrapers #AI
OpenStreetMap

OpenStreetMap is a map of the world, created by people like you and free to use under an open license.

OpenStreetMap
@osm_tech thanks for the good work 
@osm_tech the scrapers don't know that you can torrent the whole OSM for free, without ddosing the webservice
@ISibboI Correct. Not an ounce of brain. It has been going on for months, but it is just getting worse. Waste of their resources/time and ours.
@ISibboI @osm_tech I think, that spreading it on 100 000+ IP addresses tells they know they are doing shady thing.
@pesasa @ISibboI @osm_tech It's a pattern I've seen others relate to the building of AI datasets.
@pesasa @ISibboI @osm_tech
If its helpful (if you want to stuff something unpleasant down their throats), I believe @jwz has been making a 'json bomb' for (AIUI) pretty much this purpose:
https://mastodon.social/@jwz/116049057703097965
@osm_tech @ISibboI Scraping the OpenStreetMap website gives of the same vibe as stealing free stuff. 
@osm_tech @ISibboI isn't there a chance that service disruption is one of the objectives?
@Notme @ISibboI We are not unique in battling these scrapers; Wikipedia, KDE, Gnome, OpenWRT, Arch Linux and many other projects have the same issue.
@ISibboI @osm_tech Is there a torrent for the tiles? Or just the world file? Are they scraping tiles?
@geospacedman @ISibboI They are scraping the website pages: /ways/, /nodes/ and /relations/. All this data is published on planet.osm.org already.
@osm_tech @ISibboI Oh that's so much worse than I'd imagined.
@osm_tech
Bloody idiots. I wonder if it's AI platforms?
@geospacedman @ISibboI
@osm_tech 🫣 thank you for your work!
New Linux botnet SSHStalker uses old-school IRC for C2 comms

A newly documented Linux botnet named SSHStalker is using the IRC (Internet Relay Chat) communication protocol for command-and-control (C2) operations.

BleepingComputer
How crawlers impact the operations of the Wikimedia projects

Since the beginning of 2024, the demand for the content created by the Wikimedia volunteer community – especially for the 144 million images, videos, and other files on Wikimedia Commons – has grow…

Diff
Oof, sorry you are dealing with that load. Beyond blocklists, caching tiles plus aggressive rate limits per ASN, and serving 429s with Retry-After can help. For bulk use, requiring API keys for heavy endpoints can also cut abuse. Thanks for keeping OSM running.

@osm_tech Ugh, I am so sorry to hear this, and thank you to everyone working on this project.

Such a nightmare, and so completely pointless. 🤬

@osm_tech Good luck, and thank you as always.
@osm_tech wonder if it is collateral damage or intended, to get rid of alternative sources of information?
Anyway, zip-bomb the hell out of them.
@Don_Clemente Just dumb scrapers. They want our data, so maybe we /should/ redirect them to the latest full history planet file, it is only 245GB ;-)
@osm_tech yes, but that's heavy on your resources and bandwidth. A zip file of 10GB Zeros is much more resource-efficient on your side ;-)
@osm_tech @Don_Clemente Replacing the actual data with Null Island data that points to planet.osm.org is not a dumb idea IMHO
@osm_tech @lehtimaeki I wonder if anyone has looked at the various AI browsers out there to see if they're used for active scraping.
@osm_tech Block all read access except from registered users? And be restrictive on whom to grant an account (captcha, verified email address)?

@martinrust

had a similar issue with a much, much smaller wiki server (😅 ) but facing the same anonymous scrapers coming from thousands of random IP's.

Couldn't find a way to keep them from crashing the server, so now access is by registration only.

Very disruptive, this "AI" race to the bottom destroyed the open internet 😟

@osm_tech

@osm_tech

Please, please, AI bubble, burst already, so we can stop seeing this kind of vandalism.
@osm_tech I went to use OpenStreetMap today to get directions but it asked me to sign up/ log in, so I used Mapquest instead which doesn't.
@Air_Quotes_Comedian Weird. We don't require login for directions.

@osm_tech Hmmm.

Perhaps I'm the only one who is required to log in for directions.

@Air_Quotes_Comedian

That looks unusual. How about sharing the original OSM URL where you requested for directions?

The only time the site will ask you to login is when you're trying to edit the map, all other operations can be used without an OSM account.

@MapAmore Initial URL:
https://www.openstreetmap.org/#map=12/37.8149/-88.5361

Second URL: https://www.openstreetmap.org/directions#map=12/37.8149/-88.5361

Tried something different this time and didn't click on the START MAPPING button (seemingly the obvious one to press).

It worked and I didn't have to offer up a buccal swab trapped between two microscope slides.

Thanks for that. 🙂

Now I never have to use crappy old Mapquest again. It might not need a sign-in but it's awful.

OpenStreetMap

OpenStreetMap is a map of the world, created by people like you and free to use under an open license.

OpenStreetMap

@Air_Quotes_Comedian
That explains why it's asking you to login (or sign-up for an account).
"Start Mapping" is the button for editing the map.

I hope you enjoyed the routing service based on OSM, and that one of these days, you'll be tempted to *start mapping.* 😁

@osm_tech I blocked user agents matching "Chrome.139.0.0.0 Safari.537.36" as this combination seems to not exist, except for millions of requests out of china.
Thank you for your service
@osm_tech you should poison their data in some way

@osm_tech have you considered getting law enforcement involved? At least in Germany running a DDOS is most likely illegal. I would really like to know what the police and prosecution will do in this case.

https://www.gesetze-im-internet.de/stgb/__303b.html

§ 303b StGB - Einzelnorm

@cccpresser
I suspect they will shrug their shoulders decisively.
@osm_tech