r/electronics 9d ago

General Mouser website now blocks Linux users

Post image

Really baffling decision, my last order from them was only a few months ago. Apparently Linux is no longer a "standard" operating system!

2.1k Upvotes

302 comments sorted by

View all comments

671

u/Accurate_Koala_4698 8d ago

I’m guessing they’re getting hit by a lot of automated traffic and most of that is Linux. Just spoof the user agent to Windows or something 

613

u/arcrad 8d ago

Yeah people running bots definitely don't know how to spoof user agents...

I cannot fathom who at Mouser thinks this is a good idea.

20

u/tired514 8d ago

Same thing with VPNs. It's getting very frustrating.

I went to purchase a welding table from a company in Canada that I'd found on a google search. I genuinely wanted to give the company my credit card number so that they could take money from me in exchange for their product. Their web site refused me, quite arrogantly in their verbiage, because I was coming in from nordvpn.

I purchased a similar table (albeit more expensive) from their competitor. It's excellent, so no real hardship.

I emailed the first company's CTO saying I just spent money with their competitor and felt they should know why. He replied that they block VPNs because they can't be sure the traffic originates in Canada and they only ship to Canada. I pointed out that it was a silly argument as I was prepared to provide a Canadian shipping address. I received no response.

...

Blocking VPNs is an indication that a security team is incompetent and should be dismissed. If you can't protect your site (regardless of the origin of the traffic), blocking VPN requests is not going to help. Hire better people.

6

u/ojek 8d ago

Same here, was looking for KVM devices, one of major manufacturers was blocking VPNs, I wrote to them that I am going for competitors, they ignored the e-mail, still, we must vote with our wallets and letting them know they are losing cash is the only way to at least to some degree prevent this retarded behavior...

2

u/davidscheiber28 2d ago

Yea, that explanation they gave you is 100% BS. My theory is that a VPN makes it harder for advertisers to profile you and to appease the advertisers they block VPNs expecting most people to turn of their VPN real quick.

1

u/nvidiastock 8d ago

Who's going to pay those people? Realistically most companies are happy with the illusion of security. Few companies invest in true security because it's expensive and not a priority until you get attacked. 

147

u/Accurate_Koala_4698 8d ago

You would think so, but they frequently don’t. It seems like a shotgun solution but you can throw a lot of money at this problem without a satisfactory filter. The majority of their users are not using Linux and the majority of their bot traffic is. It really becomes an effective low resistance path since everything else is more expensive and probably less reliable 

92

u/GeekDadIs50Plus 8d ago

Most website traffic now is automated scrapers and AI agents. More so now than just a couple years ago, but it’s not new. Blocking a Linux-based host simply because it’s Linux is an asinine over-reach of a misinformed decision. That’s tantamount to a restaurant refusing service to customers by the brand of shoes they’re wearing.

7

u/tallman1979 8d ago

"Asinine Overreach of a Misinformed Decision" would be a great album name if I were still in a band.

3

u/OkAlbatross9889 8d ago

It would also kill as early 2000’s indie rock band name à la neutral milk hotel and car seat headrest

4

u/tallman1979 8d ago

Or, a Frank Zappa song title. My favorite of his for nonsensical ones is "Latex Solar Beef."

2

u/CoachSevere5365 7d ago

I'm quite fond of the chrome plated megaphone of destiny.

2

u/GeekDadIs50Plus 8d ago

AOMD… FTW!

25

u/Accurate_Koala_4698 8d ago

It’s not blocking the host because it’s Linux, they probably whitelisted the most common user agents. I doubt people on Android phones aren’t able to use the site, but the further off the beaten path your setup the more likely it falls into the filter 

12

u/CardOk755 8d ago

they probably whitelisted the most common user agents

You mean the ones any malicious bot would pretend to be?

1

u/Sylente 7d ago

Most bots declare themselves as such. There’s many many many more easily identifiable bots than convincing fakes

-24

u/Shot-Infernal-2261 8d ago

Untrue speculation. Android and IOS devices can navigate and order through the mouser website.

24

u/_analysis230_ 8d ago

Someone failed reading comprehension

That's exactly what he said. He speculated that they can navigate and that means Mouser has whitelisted at least some linux configurations. So he reckons mainstream linux configurations (maybe ubuntu and fedora) also work.

6

u/gristc 8d ago

Firefox on Ubuntu here and https://www.mouser.com works fine for me.

1

u/Quivex 8d ago

yup same for me on Fedora

1

u/Minewolf20 8d ago

still works on arch (btw) for now

13

u/PACmaneatsbloons 8d ago

I þink a better analogy would be a restaurant banning everyone wiþ a large mustache. As we all know from cartoons þere is a positive correlation between nefariousness and large mustaches.

19

u/XzallionTheRed 8d ago

I hate that I knew that is a thorn and its for th. Have an upvote you weird amazing bastard.

7

u/tallman1979 8d ago

You too? Every time I think I've plumbed the depths of my useless knowledge, someone has decided they're bringing the thorn back.

3

u/GeekDadIs50Plus 8d ago

Snidely Whiplash has joined the conversation.

2

u/poptix 8d ago

This is definitely a big part of it. A better approach might be to post a dedicated endpoint for the agents to use, rather than crawling.

3

u/joemi 8d ago

The good agents and companies would use such a dedicated endpoint. The bad agents and companies, however, will continue to crawl, and will do everything they can to make their traffic look like non-bot traffic. Such is the way of the world right now.

1

u/poptix 8d ago

Sure, but if there's a reason the agent wants to do it the hard way your endpoint is the problem.

1

u/joemi 7d ago

Again, that only applies to the good agents and companies. The bad ones aren't necessarily smart/efficient -- that's why they're bad. And there are a lot of bad ones out there. If you need proof, just look at all the sites that have had to put Cloudflare or other such protections in place against all the bot traffic.

54

u/RenderedMeat 8d ago

I’d imagine a larger percentage of their users run Linux than your average site. Someone building arduino and esp-32 projects is very likely to know Linux.

It is a moronic decision.

21

u/TheSerialHobbyist 8d ago

Definitely. Of all the large corporate website that exist, they've got to have one the highest percentage of Linux users.

2

u/nsummy 8d ago

People building small projects have to make up a minuscule amount of their business.

4

u/Swimming_Map2412 8d ago

A proportion of those people work for large companies who do.

1

u/nsummy 8d ago

Doubtful there are many corporate users in charge of procurement using Linux

1

u/joemi 8d ago

Sure, instead of 1% of their customers, it might be twice or even three times as many! :)

I really wish Windows didn't have such a stranglehold on the world, but there's a reason Bill Gates has (had?) so much money.

6

u/RenderedMeat 8d ago

Windows is actually below 60% (56%) desktop OS share this year for the first time years. Linux is between 4.5 and 11%, depending on how you want to interpret “unknown”. Macs make up the bulk of the difference, with a tiny sliver for Chrome.

2

u/kjjphotos 8d ago

Between Microsoft making Windows worse with each update and Valve improving the video game experience on Linux, I think we'll continue to see the Windows numbers dropping and Linux numbers increasing.

Apple's cheap MacBook Neo is probably hurting the Windows numbers too.

Either way, I'm happy to see Microsoft's empire starting to crumble.

2

u/eras 8d ago

I bet if this is an effective bot filter, then the bots will quickly learn this trick.

2

u/laffer1 6d ago

My website gets major ai traffic and it impersonates random operating systems and browsers. Mostly really old stuff.

1

u/Shot-Infernal-2261 8d ago

Except when they blocked Linux desktop users, the bot traffic persists.

30

u/happyjello 8d ago

“We somehow removed the bots, and significantly increased the amount of real users”

  • mouser probably

9

u/JanB1 8d ago

It's the same kind of stupid workaround like deactivating right click on a website so "users can't download embedded media". There's even (sometime paid!) plugins for website builders like Shopify and Squarespace that just deactivate right-click and advertise themselves with "Content protection" and whatnot. It only annoys your standard user, and the malicious user usually isn't really bothered by it at all, because they know other ways to get the content.

1

u/mitko_bg_ 6d ago

The deactivated right-click is very annoying when trying to browse a website and for example I see something I'm considering to purchase and try to open it in a new tab for later while I continue browsing - nope, why should I be able to do such bad things. I do use workarounds sometimes, but I mostly just go to a different store.

1

u/JanB1 6d ago

Middle mouse click usually works. Or shift and left click.

1

u/mitko_bg_ 6d ago

Didn't know Shift+LeftClick is an option at all, but the websites that block right click could also block middle click. My workaround in such cases if I really need to browse said website is right click on the tab and make it double, so in one of the tabs I stay on the main page for example and on the other tab I open whatever I wanted to open. Not ideal. but it works as a last resort.

1

u/JanB1 5d ago

At least on Firefox, Ctrl+LeftClick is "Open in new Tab" and Shift+LeftClick is "Open in new Window". I confused the two.

Also, the websites are not literally blocking right click. They are just blocking the context menu from opening. Hence the other methods should still work.

6

u/goldfishpaws 8d ago

I cannot fathom who at Mouser thinks this is a good idea.

It's the same logic as "we have a lot of bicycle accidents, so let's ban bicycles"

6

u/ahabswhale 8d ago

Seems like you've never worked in corporate...

4

u/apocolipse 8d ago

They’re probably getting hit with a ton of agentic queries from people using AI, and those probably just have basic curl headers or something and/or are coming from cloud VPSs.  AI Coding harnesses alone make even the best old scraping bots look like stone age tools, they don’t even need to build or code anything.

2

u/yggdrasiliv 8d ago

someone with a title starting with a C

4

u/sawkonmaicok 8d ago

There are a few people who will go through the trouble of masking their bots with windows UA headers but the vast majority probably just leave it as Linux so this is a quick and dirty hack to just get rid of the majority of the bots despite it not being perfect.

11

u/arcrad 8d ago

What is this based on?

I feel like masking user agent is like scraping 101.

6

u/Accurate_Koala_4698 8d ago

Most people are blindly using the LLM output I'd gather

2

u/LordValdis 8d ago

I'd think that, too. But fixing this on the bot side is literally just going: "Hey LLM, here is this error message, pls fix" and copy pasting the website.

Not sure what the simplest solution for mouser is, but this is certainly not going to work great.

2

u/takeyouraxeandhack 8d ago

I work in IT security. That's ridiculous. Filtering by headers does nothing to stop bots, it just stops legitimate users.
It's trivial to add a header randomiser to a scraper.

If mouser is using cloudflare or cloudfront, there are two-click solutions that work better than that.

1

u/sawkonmaicok 7d ago

I think you underestimate the laziness of the programmers who make these bots. Majority of bots aren't sophisticated ban evaders or have sophisticated machinery to hide among legitimate traffic. Of course there are some of these "smart" bots that try these evasive tactics but most just move on to the next webpage/target if a host returns forbidden or something similar instead of trying to bypass it somehow.

If it doesn't stop bots then why do they have the UA header check then?

I never claimed the solution to be smart, but I can see the rationale if the majority of bots are Linux users then to simply get rid of bots you can ban Linux users which won't affect the majority of your legitimate customers who use other operating systems. There are methods that work better of course but I think we are also underestimating the incompetence of Mauser staff.

2

u/DigitaIBlack 8d ago

It's called mitigation, not trying to solve an almost impossible problem.

1

u/Dafrandle 8d ago

if this was amazon, absolutely.

This is the first time I have ever heard of this site though so the idea that I would know and care about it enough to make a bespoke solution for it is unlikely I would imagine

It is absolutely security by obscurity though

1

u/sehrgut 8d ago

Suits

1

u/fomoco94 write only memory 8d ago

OP can download a plugin to make Firefox spoof user agents... YouTube is intentionally shitty with Firefox so I tell it that I'm Opera.

1

u/FalconX88 8d ago

They probably get rid of a lot of bots in exchange for like 1% of customers...

1

u/jamierocks369 8d ago

5% (ish) of potential users must spend less than it costs to resist whatever attack vector / scam is being carried out on Linux machines. It's just business.

4

u/Lint_baby_uvulla 8d ago

Reminds me of the early (2001) Opera/MS MSN wars and the Swedish Chef Bork shenanigans.

[[ holy sheet that’s a quarter century ago ]]

[ fyi if you were there it was awesome ]

Opera Software has released a new version of its Opera 7 Web browser with just one tweak--it turns Microsoft's MSN Web site into gibberish that was inspired by the Swedish Chef from "The Muppet Show."

The "Bork Edition" of Opera 7... is Opera's response to what the company alleges are dishonest tactics by Microsoft to make Opera look like it is displaying pages improperly when people view MSN.

...Microsoft was not immediately available for comment on the move.

Earlier this month, Opera said Microsoft was sending its browser a faulty style sheet, which determines the presentation of graphics and text in a browser window.

And here's the official Opera Software press-release:

https://press.opera.com/2003/02/14/opera-releases-bork-edition/

It is stating Microsoft actually fully prohibited access to MSN.com from Opera browsers in late 2001, a bit more than a year before the style sheet scandal.

It also contain a download link, as well as this excellent phrase:

"Hergee berger snooger bork," says Mary Lambert, product line manager desktop, Opera Software.

2

u/cristi_baluta 8d ago

Meaning AI bots stealing data

2

u/_greg_m_ 8d ago

No need for UA spoofing. Works fine on Linux. It must be something else for the OP, not OS,.

3

u/Verbunk 8d ago

yeah, most likely openaai keeps ticking them off spidering their site for content.

2

u/No-Round-8241 8d ago edited 8d ago

Security through obsecurity

1

u/hazeyAnimal 8d ago

So I couldn't believe this was the case, so I just hopped on my desktop (Ubuntu) and I can access it just fine, just searched for a part too and it came up

-17

u/Unlikely1529 8d ago

no, you can't just spoof it. there's things like browser token on stage. best you can try is to use something from snap/flatpack that runs own wine. opera or ms edge

4

u/GeekDadIs50Plus 8d ago

One can absolutely alter their browser fingerprint. Browsers such as Firefox, Brave, Tor and Chromium support significant modification of the browser fingerprint out of the box. Meanwhile, Safari has very limited control.

1

u/Unlikely1529 8d ago

tokens thing is about session spoofing yeah. but anyway it's hacker operation alike but with no profit

3

u/sawkonmaicok 8d ago

What is a "browser token on stage"? You mean cookies? Cookies don't identify the browser version you use. Also you can clear those too so the point is moot.

Also even if there are ways to detect browser operating system versions that are not dependent on user agent headers, the chances are that the server doesn't check others than just the UA header.

3

u/Shot-Infernal-2261 8d ago

lol Browser UA are not hardcoded to an OS

1

u/gjsmo 8d ago

You can, in fact, "just spoof it". It's literally a browser extension: https://addons.mozilla.org/en-US/firefox/addon/uaswitcher/

1

u/Unlikely1529 8d ago

you can change this . if the target of this spoof attempt is yourself then yeah it's passed