How can I stop ticket-sale bots before they consume waiting-room slots?

0
4
Asked By MellowPine47 On

During popular event sales, our site can receive tens of millions of requests. The current waiting room controls crowds but does not stop scalpers from taking queue positions, so legitimate customers end up waiting much longer. Turnstile has been unreliable for some real users, while reCAPTCHA, hCaptcha, and Friendly Captcha are too expensive at this scale. I also tried Altcha proof-of-work; it helps somewhat, but automated requests still reach the infrastructure and consume resources. Running Altcha in an edge Worker does not seem to help because the waiting room processes requests first. Is there a practical way to pre-qualify or filter traffic before it enters the waiting room?

4 Answers

Answered By AmberKite31 On

There is no reliable way to distinguish every sophisticated scalper from a real customer. Advanced bots can use residential proxies, normal browsers, and realistic interaction patterns, so any aggressive challenge will eventually create false positives. Robots.txt and crawler controls may remove ordinary crawlers, but they will not meaningfully stop bots built specifically for event sales.

Answered By CedarFox8 On

The cleanest design is a pre-qualification step before the queue. Send visitors through a lightweight proof-of-work or risk check, then issue a short-lived, cryptographically signed token or HMAC cookie after they pass. Configure an edge firewall rule or the queue endpoint to reject requests without a valid token. That keeps scripts from filling queue slots, although the token system needs replay protection and careful rate limits.

Answered By NovaHarbor22 On

The ordering of the waiting room and Worker is the main limitation. Test whether edge WAF rules run early enough in the request pipeline to rate-limit or challenge suspicious traffic before it receives a queue position. If they do not, put a reverse proxy or edge function from another provider in front of the waiting room, or move the queue logic there entirely. Combining that layer with IP, ASN, TLS-fingerprint, and request-rate signals will reduce abuse, but none of those signals is perfect.

Answered By QuietMaple6 On

Datacenter and hosting-network traffic can be a useful first filter during the sale window. Challenge or heavily rate-limit requests from known cloud-provider ASNs while allowing ordinary residential traffic through. It will not stop residential proxies, and it can affect legitimate users, so treat it as a temporary mitigation rather than a complete solution.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.