how can a website block the vast majority of common bots and still be usable without Javascript/CSS/images/frames/media. I already block DCH IPs and employ strict rate limiting combined with mecriless honeypots. I already block many residential ASNs and IP ranges. How can I improve? I can blocks all common proxies by TCP RTT/HTTP 301 time mismatch, but Lynx does not redirect that fast. They spoof user agent they spoof SSL. 70% of real users use HTTP/1.1 or lower. No commerical CDN due to company policy. These honeypots are so strict they blacklist IPs of fast clickers, cellular tethering users were reporiting issues. That is fine. reverse DNS can be bypassed by ordinary VPS. 60% of bots and 40% of real users don't use TLS. My website is already 100% scraped, i dont care. I care about form spam and fake offers. All non-ascii characters are thrown away, lowercase only, special characters are restricted heavily. The captcha questions are so bizzare that we have to allow 20% mistakes. Bots usually make around 5% mistakes. The problem is that they use a literal AI agent to fill out legitimately looking offers resulting in fraud. We validate all input using in-house ML. Update: They even started using real people to fill out the forms. They give burner phones to a number of well paid workers and they CANNOT BE distinguished without KYC. KYC equals Kill Your Customer (we tried it and our stock price crashed) We can't stop them, neither can the law enforcement. WE ARE COOKED