Show HN: I learnt how to use WebSockets, made something beautiful/terrible
walloftext.art
walloftext.art
The intention was to make the most minimal project that tested the bidirectional communication of WebSockets. The end product is a scrollable grid that allows users to type anonymous comments. Of course this is already getting abused, but that's part of the fun! Anyway, I'd appreciate your feedback on the code, and if there are any ideas of how to make the end product any better/more fun/less crude.
I was also proud of my accomplishment and shared it with my nearest tech community. It was, if I recall, less than an hour before someone had exploited the obvious XSS vulnerability. At the time I was aghast and felt like it was a cruel thing to do. And while I know better than that now…
Here’s the thing: that tech community, even the whole internet, was a lot smaller then. The person who exploited my naive first program accepting user input claimed responsibility and explained why. The other people around were both knowledgeable enough and kind enough to help me understand that that person was a friendly who meant no harm.
Folks trying to learn new things now won’t be in a community like that by default, and probably won’t know to look for it. And the people who take advantage of that are clearly more malicious and not friendlies.
I don’t know what the takeaway from my “here’s the thing” is, for HN, but I do think we’d all be better off if we pay close attention to being welcoming/supportive for noobs, and also strive to make learning tech less of a risk when inevitably first steps go wrong.
[1] When the Whois DB worked, and people thought about sending letters.
I've posted many show HNs over the past 7 years and many provided some ways for people to do computation on the server (by design) but not some form of limiting that (by my inexperience).
I know everyone's experience can be different, and I know that sometimes, and for me personally, other things that people do on ShowHNs are particularly hurtful--Like being cruel or dismissive...I mean you're bearing your soul right? Your work; a little embryonic thing you're contributing to the world... And some people seem like they just want to try to kill that--but for me, that's been different to the security "hazing" my posts received. I've been personally grateful for those security hazings, because it gave me opportunities to test and improve those projects. Seriously the best free security audit you could get.
Sometimes it felt annoying .. because I thought I'd patch something but then I checked the server I found people found a way through or found a way to circumvent that.
But I saw it as a challenge and I imagined it was like a way to redteam and anticipate and prevent things that would end up happening in the real world anyway so it was incredibly valuable actually in hardening the products I made. Good learning experience too. :)
My favorite event to solve was people using my remote browser product to run cryptocurrency mining javascript. And overcoming that challenge was quite tricky at first, because cpulimit is more of a suggestion than a hard limit. And also because the cloud where I originally ran this (and most clouds have this rule too), disallowed using the compute resources for mining crypto so I almost got a strike on my account because other people were using this thing I had opened up to mine with. After discussing with the contact window everything was cool, but I still needed a way to block this. While there are CPU throttling apis I could use on a per tab basis via Chrome remote debugging protocol (and I may look into that more in future), there's also a chance that under high CPU load the debugging protocol becomes unresponsive and so you can't intervene via that route anyway.
What I went with was just operating system process monitoring and cgroups (now v2 in the latest kernels which are unfortunately for now more limited) plus killing processes that violated too many monitoring intervals. A cool thing about Google Chrome is it's pretty robust to killing some of its processes off so you can kill off the processes of a couple of tabs that are involved in cryptocurrency mining but it doesn't kill the entire browser.
The whole thing was a great way to learn more operating system internals as well as to discover the plethora of tools available for resource control in linux. Particularly impressive are the networking and bandwidth control options like iptables. So instead of dockerizing my apps I basically created these custom sandboxes by using operating system apis that's been incredibly effective at preventing abuse.
DDoS the WebSocket server? Write Very Bad URLs? Worse? :(
I wanted to see. Not fair, takers away of nice things. >:/
what could possibly go wrong.
absolutely second the recommendation of watching it!
it's optimistic in that it's not yet a realized future and we still have the opportunity to change course.
i agree, and i hope we make strong moves together as a society to curb climate disaster. admittedly i'm not holding my breath.
HN content is "fresh," mirrored on dozens of sites within minutes of showing up on the front page. 4chan and reddit get the links within about 20 minutes of it showing up here. Slashdot, dailydot, and other aggregators lag about an hour. Within 3 hours, most links here have probably hit the eyeballs of at least a few hundred million people, and there's probably a good 50k legitimately insane people in that crowd.
I found HN when I started looking for where the aggregators and forums were sourcing stuff I was interested in. I'd love to see Google's rankings and see what other sites are similar to HN in this regard.
We used socket.io to sync between the client and a NodeJS backend. (The whole thing was really an experiment to get to grips with the then-nascent Node v0.4)
Of course it was horribly abused, and we took it down after only a few days.
What'd you write it in?
Edit: I see from the OP's link to the github project that persisting the chats to a DB was included with this.
[0] https://github.com/gorilla/websocket/tree/master/examples/ch...
wss://www.walloftext.art/ws.php
Doesn't seem to be accepting connections when I try.
Out of curiosity, were you actually handling each WebSocket connection using an independent PHP-FPM instance? If so (wow), how many concurrent connections did you manage to sustain at peak?
The only experience I've had using WebSockets with PHP is with using stream_socket_server() et al, and then multiplexing everything. (Then you just get handed the problem of restarting the server(s) to keep runaway GC in check...)
Edit: Have realized you aren't OP - but that's fine, I'm interested to hear war stories from multiple sources!
I should've just gone and looked at the code before piping up... and I'm really glad I finally did, because I honestly have to say I'm learning a lot from how succinct this is (while still incorporating PHP 8.x type boilerplate, which I can't deny is an excellent habit to get into!) - I still have How Do I Even Structure This syndrome despite tinkering around for a good decade sadly.
Looking forward to seeing this back online.
If you put it behind a simple account system, only a limited subset of people would be able to access it, and you could tinker and iterate with a real-world user base.
I'm still curious what led to you shutting it down. Something overstepped a boundary, I'm presuming; depending on what that was I might not want to know exact specifics :<
> I've had to take this project offline!
> I was expecting it to be abused and violated, but was completely naive to what the internet people were capable of.
> Wow. That's all I can say. It was fun while it lasted, and it'll be back... some time.
I guess it became a test that, as expected, part of the human race failed.
But this is why it's somewhat dangerous to infer tone from text without knowing more about the context.
like comment threading, timeouts, mental map like comment grouping.
like evernote and visual programming, but for short lived comments,