Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. F-Droid 2.0 (f-droid.org)
    235comments
  2. Show HN: Koi.rest – watch some fish and regain your balance (koi.rest)
    12comments
  3. Show HN: Make cursed fonts like Times New Bastard (mitpit.com)
    54comments
  4. California is chasing wealth that has feet (landeconomics.org)
    168comments
  5. Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design (github.com/devdotfast)
    68comments
  6. Why is the liver so weirdly regenerative? (dynomight.substack.com)
    126comments
  7. Fearless SIMD v1.0 (linebender.org)
    26comments
  8. Rails World 2026 Opening Keynote [video] (youtube.com)
    207comments
  9. My weird new hobby: Wandering around Tokyo on Google Maps (ahmedhossamdev.com)
    71comments
  10. 2DWillNeverDie (2dwillneverdie.com)
    4comments
  11. Using LLMs to trace alchemical knowledge and decode 17th century letters (resobscura.substack.com)
    8comments
  12. International observers to investigate Swedish election fraud (tv4.se)
    2comments
  13. Sourcehut account takeover via build logs (XSS in ansi2html) (blog.arusekk.pl)
    4comments
  14. The Board Game of the Alpha Nerds (2014) (grantland.com)
    16comments
  15. Stable (YC W20) Is Hiring Product Engineers (usestable.com)
    —discuss
  16. Google’s Project Suncatcher to put ML infrastructure in space (blog.google)
    137comments
  17. Toyota is taking the Corolla electric (electrek.co)
    216comments
  18. Book review: Is parallel programming hard, and, if so, what can you do about it? (ahelwer.ca)
    20comments
  19. Security auditing in the age of (good enough) AI (trailofbits.com)
    2comments
  20. Two-tier encryption in the UK (macanorak.com)
    365comments
  21. Forging 1024-bit RSA signatures in nearly SNFS time [pdf] (iacr.org)
    6comments
  22. The forgotten battle of East Lansing (eastlansinginfo.news)
    12comments
  23. Geothermal heat map of US hot springs (soakingsprings.com)
    29comments
  24. Opus 5.5 is good at explainer videos (launchvideo.io)
    71comments
  25. Early rogue AI agent activity and attempts to hack found on urlquery.net (transluce.org)
    212comments
  26. Tutoring company tells parents to save their money and 'use AI instead' (afr.com)
    102comments
  27. WaveDigger: Dig into wireless signals to discover their physical locations (github.com/christianrowlands)
    13comments
  28. Show HN: Critic – Review code with the agent that wrote it (critic.run)
    1comments
  29. Show HN: AgentRun: DSL to turn agents into workflows (github.com/parcha-ai)
    5comments
  30. Nokia Design Archive (2025) (aalto.fi)
    114comments

August 27 TCRF DDoS Attack Postmortem

17 pointsby 3h agoblog.xkeeper.net
7 comments
1h agoHN ↗

This is why no one likes AI. It ruins wonderful passion project sites like this.

1h agoHN ↗

I recently added a new feature to The Cutting Room Floor: If you visit the site with a “Claude-code” user agent… it adds you to a Claude user ban list. Then, if you try and visit the site later, without Claude — maybe because you wanted to investigate the “prompt injection” page it received — you’re greeted with a special error page telling you to get out

This guy sounds like he has spent way too much time online getting angry at imaginary enemies, and really needs to get outside and talk to some real people outside of his filter bubble.

I actually enjoy reading TCRF, so it’s unfortunate that the owner is apparently a terminally online insane person.

1h agoHN ↗

It's a pretty funny solution to slop bots, and it's clearly effective enough to upset the exact type of loser it's designed to reject.

The insane part is launching a DDoS attack because some guy online insulted your favorite toy.

1h agoHN ↗

I’d argue both sides are acting insane; there are no good guys in this story, only people who got way too worked up about software choices and started lashing out in inappropriate ways.

48m agoHN ↗

Hi, TCRF operator here! (*she)

This story has been escalating for over a year at this point. Originally, identified bots were given a generic "access denied" message. Then a special generic "LLM poison"-type page (some joke misinformation). Once I noticed that Claude-Code bots, specifically, were evading those blocks -- making one request, then changing their user-agent and trying again -- I started adding the persistent ban for bot misbehavior.

That you didn't know any of this until now suggests, I think, that there isn't really much of a problem. After all, this only affects agents reporting as Claude-Code.

The primary goal my side of this has been to interrupt and annoy LLM/AI users, and to that it has been working incredibly well.

My previous blog post, written before this DDoS attack, went into some of the challenges of being an independent website that avoided using third-party services (outside of Linode, our host). Cloudflare was always my "last resort" — I actually signed up for an account there a bit over a year ago, during an earlier attack — and it finally became time to use that last resort.

As for "terminally online", I guess you could say guilty as charged. I've been running communities for over 20 years and TCRF specifically for nearly 17, longer than a lot of our users have been alive. It certainly gets results.

1h agoHN ↗

It's a shame that so many niche websites have no other choice than moving to Cloudflare.

"In the process of mitigating, migrating, and updating things, we’ve made a lot of upgrades and improvements to the wiki and infrastructure: Automatic blocking of many bots and other nuisances, including Tor exit nodes"

Is this supposed to be a good thing? What's the point of blocking Tor here?

8m agoHN ↗

Tor is one of those things that is nice in theory but, in my experience, tends to consist of about 20% legitimate users, 30% garbage traffic, and (most importantly) 50% specific, persistent, ban-dodging personas non grata.

There are only so many days one wants to wake up and click "delete user" 20 times for the latest batch of slur-filled trash from tor-exit-48012480.r0ck3t.ballz.