Continuing the saga ...
When I list an offending (hotlinking) domain in my .htaccess files as
blocked, upon reload after updating the .htaccess file, the domain is about
95% of the time promptly denied access, though I always have to reload the
hotlinking domain's URL in order to see the effect.
Turns out that the [nonfree] domain management software on my ISP's server
lists the domains that I have explicitly blocked in my .htaccess file as
explicitly _allowed_ access, exactly the opposite to what I intend. That has
been a known bug for a long time, dating back to 2010.
Therefore, the few domains who have been successfully bypassing hotlink
protection when their domains' URLs are accessed from _only my computer_ (and
no one else's !) are accessing my domain's images through my server's domain
managment software and not through my domain's .htaccess file. When my ISP's
support team looks at the hotlinking URL's they get a 403 error, just as I
intend. When I look at the recent visitors access log for my domain, my own
router's IP address shows a 403 error for every attempt to load those
domains' URLs from whichever Trisquel installation I am running at the time.
Nevertheless, for these few hotlinking domains, mine appear to be on the only
computer that cannot see the effect of denying access from those domains to
my domain's image files. I have actually blocked _all_ access to my domain
from those hotlinking sites by listing their servers' IP addresses in the
"deny from" section of my .htaccess file.
On a first-order level, this shouldn't bother me, but if the hotlinking
domains are loading malevolent script from the webpage that contains the
hotlink to my computer when I look at my domain's hotlinked image, that could
threaten the security of my computer.
George Langford
amenex