Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It heavily depends on how they implement IP bans. Often they are done at a much lower level, making verifying the user is logged in impossible. Doing them at a high level usually makes the ban not effective as they still waste a bunch of overhead.

The alternative is to have two views of the site that hit different servers, one that requires login and another that does not, but that introduces a whole slew of other problems. It would probably be the way to go if you wanted to do this however.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: