HNHacker News
TopNewBestAskShowJobs

Bender

68,752 karma · joined June 16, 2015

Σ I am not for everyone. To ignore me in uBlock Origin, add to "My filters":

   news.ycombinator.com##tr.athing.comtr:has(a.hnuser):has-text(/\bBender\b/)
I can not see votes or karma and do not require social validation.

- For HN usage questions see [1] for HN tips not my repo

- Suggested Firefox add-on to replace or restore inflammatory words and phrases: Foxreplace [2]

[1] - https://github.com/minimaxir/hacker-news-undocumented

[2] - https://addons.mozilla.org/en-US/firefox/addon/foxreplace/

    (\_/)
    (='.'=)
    (")_(")
submissionscomments
Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
Not the person you are asking but site operators can not tell intent. It could be something nasty on the network or a botter feigning ignorance.

I'd say its probably an acceptable casualty in the battleground that is the internet especially for little one-off sites hosting blogs, forums, chat servers, etc... For a bigger site I would expect that person may have to open a ticket with the platform such as Amazon accepting that some CDN's and firewalls may be harder to get the block removed. This is why we can't have nice things.

Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
The ISP's do not have a financial incentive to shut them down. To them that's a paying customer. The feds will go after the big botnets if they are touching financial networks or siphoning enough money from people because there is usually a few big bank accounts and virtual currency exchange accounts they can seize once big enough to look good in the media. That's why it's on us and a few big CDN's to block some of them.
Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
Cool site. I was curious and dropped your 100k list into a reverse DNS lookup site [1]. They may still have some of the records cached. I recognized quite a few of the scanner nodes and some other usual suspects.

[1] - https://adver.tools/reverse-dns-lookup/

Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
I've noticed they strip away a header [1] in private browsing mode but I don't know why they do it since it does not disclose anything about the person. I think that may be the same thing that causes some people grief on Cloudflare as well.

[1] - https://caniuse.com/?search=sec-fetch

Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
By default they use 2.0 [1] unless someone or an addon disables it or unless the person is on a really old version. OperaMini however will use 1.1. No idea if anyone here uses OperaMini.

There are some reader apps that act as a proxy that only support http/1.1. Be careful, some of those are not just readers and do not trust what they claim to be the source code. Some of them are created by cute and fuzzy bunnies.

There are a number of botters on HN, some that control residential and phone browser-hijacked systems. One was sending me playful messages the other day. I enjoyed the bot block-jousting with them.

[1] - https://caniuse.com/http2

Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
The complaints in the thread. I am aware the lurkers would not have said anything.
Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
I second this. When I have tested blocking VPS/data-centers to my silly blog there were about a dozen people on HN [1] that could not view my site out of the roughly ~17,000 (not counting bots) that could. It's not a big number but those are real people and they count.

I am going to move full blocking to a test node that people can play with but I have to finish working with Claude to revise someones repo is is no longer maintained because one does not simply put an anonymous chan board on the great wide open internets without some critical thinking.

[1] - https://news.ycombinator.com/item?id=49060945

Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
There are several methods. [1] The most aggressive method-02 and method-03 on my document will block VPS and some data-centers but that also means it will block some legit users that are on a VPN. Most VPNs transit a data-center. If experimenting with these methods use a test server that you do not care about and set up a dummy site and ask people in your circle of friends to test it. I have to step away for a bit but if you have questions I will try to answer.

[1] - https://nochan.net/b/Internet-Crap/20260606-How-To-Block-Som...

Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
There are many possibilities but one of them could be some new vuln was released and they are looking for it. That would require looking at the URL's they are requesting. Botters run their own purpose built campaigns. Do you also have a summary of URL's requested by unique counts?
Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
Many of those user-agents listed are often faked. Look up which ASN owns their IP. If I block most VPS providers most of the faked bots vanish. There are still some running from residential and phones using hijacked code (readers that are not really just readers but really multipurpose proxies). On that note, do not trust the linked source code but rather decompile the live code your phone is running and have AI analyze it.
Bender··on Ask HN: Has HN considered adding dark mode?
It comes up from time to time. It is unlikely the site would change. One could add it locally however if they have uBlock Origin in their browser then one way to add a dark mode would be going into the uBlock Origin settings -> My Filters and adding

    # HN dark Mode:
    news.ycombinator.com##body:style(background: black)
    news.ycombinator.com##td:style(color: #fafafa !important)
    news.ycombinator.com##table:style(background-color: #24273a)
    news.ycombinator.com##div.toptext:style(color: #fafafa)
    news.ycombinator.com##div.c00:style(color: #fafafa !important)
    news.ycombinator.com##a:style(color: #ffa000 !important)
    news.ycombinator.com##span#karma:style(color: #faa000 !important)
    news.ycombinator.com##span.pagetop:style(color: #fafafa !important)
    news.ycombinator.com##textarea:style(color: #696969 !important; background: inherit; )
    news.ycombinator.com###hnmain:style(background: #24273a !important)
    
Adjust color hex codes as desired. There are a few elements missing in this one, I would have to look for the other version but this should be a start.
Bender··on We're in the Most Dangerous Period – With Doomberg [video]
I can't pass up Doomberg. It makes sense he is on Canadian Prepper as Doomberg is also a prepper and listens to Nate's channel. Nate has gotten a bit dramatic and click-baity in recent years and is way out of his depth talking about oil trade but I still find little interesting tidbits from time to time as some of his members are in the trenches so to speak. I just speed up the audio a bit and play a video game whilst listening.

Another recent Doomberg interview: [1] Doomberg: Energy, AI, and the Calls Nobody Else Made

[1] - https://www.youtube.com/watch?v=CxWZxbwQ_rI

Bender··on CFTC declares market emergency, orders Kalshi to continue to operate in New York
The cert I am seeing:

    Testing via IPv4:
    IPv4 (2 address(es)):
    104.18.25.94
    104.18.24.94
      subject   : C=US, ST=District of Columbia, O=Commodity Futures Trading Commission, CN=www.cftc.gov
      issuer    : C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36
      SAN       : DNS:www.cftc.gov, DNS:accountcreation.cftc.gov, DNS:cftc.gov, DNS:smartcheck.gov, DNS:whistleblower.gov, DNS:www.smartcheck.gov, DNS:www.whistleblower.gov
      sha1      : 42:AC:E2:34:10:93:10:9B:0E:45:6E:BC:A9:D5:B8:7D:C4:8B:BE:A5
      sha256    : E5:C9:F2:9F:4E:6C:30:51:AA:6B:63:AD:AD:F9:58:A4:E0:3E:7A:32:E9:2C:AB:8D:ED:4F:24:4D:D6:F0:DE:E8
      validity  : Oct 23 00:00:00 2025 GMT -> Nov  1 23:59:59 2026 GMT (81 days left)
      tls       : TLSv1.3 / 
      Verify return code: 0 (ok)
Are you seeing that too? This [1] is the function I am using. Claude's Improved version over my old chicken scratch.

Qualys Results [2] for www.cftc.gov Cloudflare in front of Drupal 11

[1] - https://nochan.net/b/Text-Crap/function_fingerprint2.sh

[2] - https://www.ssllabs.com/ssltest/analyze.html?d=www.cftc.gov&...

Bender··on Zuckerberg's superyacht ignored emergency channel, failed to aid stranded boat
A boat like that with a VIP on board is also likely to have heavy security as well. May as well get letters of marque [1][2] and "assist" some pirates and cartel for fun and profit. One EO could enable this.

[1] - https://www.lee.senate.gov/2025/12/patriots-of-the-caribbean...

[2] - https://en.wikipedia.org/wiki/Letter_of_marque#21st-century_...

Bender··on Ask HN: What email provider do you recommend for personal email?
I have sent emails back and forth between Fastmail and my self hosted servers to increase their trust. Sometimes I talk to myself...
Bender··on What if we got rid of cars?
It would be about $5 Trillion dollars to connect all the small communities and rural areas of the USA and that would not actually get people from their homes to the store but it would be close enough people could carry a folding bicycle assuming their shopping demands are light. That estimate is just for initial construction, not ongoing maintenance costs vs the existing roughly $500bn to maintain the existing highway system.

Cost aside this is of course problematic as many of the vehicles in my rural area are hauling horses, cattle, other livestock and vegetable produce. They won't let people take a herd of cattle on the tram and there are only a handful of open access paths that people can move cattle the original way. This gets even more complicated with things that can not walk on their own like assorted crops. People are not permitted to take 25,000 pounds of grains, fruits and vegetables on the tram. A full sized train could do it but there would not be a full sized train going into every small community (though it would be quite a sight to see). In every practical sense full sized trucks and large tractor-trailer trucks are required to move produce to the full sized trains and then tractor-trailer trucks from the train to distribution centers or your grocery stores will no longer have produce.

Even without the cars the roads would still have to be maintained and very few people would voluntarily give up their cars. Most would put up a significant fight and/or people would just buy big trucks and stick a ranch decal on the door. I would just drive my street legal UTV (a.k.a. side-by-side) into town.

Bender··on New surveillance tech links your phone to your license plate
When this data inevitably leaks I think it might be fun and curious to see what officials are taking what escorts to what private location for how long. AI could probably do a good job of teasing apart the leaks. Curious what it could also tease out from the data.
Bender··on The UK's war on anonymity has come to America
Ensure system does not have this information:

    loginctl show-user $USER 2>/dev/null
    userdbctl user $USER --json=pretty 2>/dev/null | grep -i birth
Confirm field is not set

    homectl inspect $USER | grep -i birth
If it is set, unset it

    sudo homectl update $USER --birthday=""
Tell your favorite AI what OS, kernel version (matters if using a locked down kernel) and browser is being used. Ask for a systemd service that uses bubblewrap to prevent access to systemd, set whatever other limits like memory and CPU usage.

If in the future the browser gets passive / aggressive updates if they mimic Microsoft and refuses to run if there is no age set or if they can not call systemd commands or libraries then script a random age or age range on each login so that it is not used for tracking. pseudo super-cookie

Bender··on The US hired 2k gamers to fix the air traffic control crisis
Fans of games like Fortnite

Wrong gamers. For ATC one would need the ultra-hard-mode "try-hard" gamers that know there is no such thing as "game over". The players that get one life and will pushing the gaming engine to it's limits to survive.

Fortnite assumes non-stop failure and retry. Non-stop failure and retry is not an option when directing air traffic.

Bender··on In Arizona, it may be easier to steal a home than a TV as deed fraud grows
That's an issue in every state AFAIK. Too bad there isn't a simple concept like Super-Locking a deed so that either the owner of the deed or the person inheriting it has to show up in person and show their state ID to the county clerk to transfer the title.
Bender··on The UK's war on anonymity has come to America
The problem with a self declared approach is that puts a signalling mechanism in place. Once in place the laws can easily scope creep year over year to add more information or require putting in ID information or some future nation-wide digital ID and Trump coin digital wallet which could easily be the plan all along. All they need is the API that will interface with websites using some agreed upon standard and then it can easily be extended line by line. Give them an inch, they will take a mile.

With proper parental controls there is no signalling.

Bender··on The UK's war on anonymity has come to America
Of course that is not parental controls. That's 3rd party controls. Parental controls means you create a child account for children and when a site is detected as being adult ideally using RTA headers [1] then a password prompt asks for the parents approval. That is parental controls.

[1] - https://nochan.net/b/Internet-Crap/20230829-Think-Of-The-Chi...

Bender··on Illinois just passed a law that puts Linux on the hook for age verification
These laws still do not sit well with me. This is just going to create endless lawsuits. In my opinion the safer choice would be to avoid doing anything with current teens, that's just a non starter. Instead think of sliding windows of time and sandbox small children on a child account that if all goes well will one day be a teen and then an adult. They will thank you when they are an adult for looking out for them when they were too young to consent to the data leaked by these laws.

Why not just signal age ranges? Simple, the way the legal system works is one puts in a benign sounding law, then tweak it every year since the mechanism exists. (scope creep) "Now add city, state", "Now add DOB and address", "Now add your federal wallet ID."

- For small children set an RTA header (previous discussions) [1] for any URL that may potentially contain content not appropriate for small children. Give site operators 1 year to implement this. Not counting QA and change control this takes minutes.

- Require app and device vendors to create a properly sand-boxed child account. Pen test it but it does not have to be perfect. This is for small children and default installed applications. If the child visits a URL that contains the RTA header then trigger parental controls. It is entirely up to the parent when that child is ready for mature content. It must be impossible for the child to install any applications, addons, etc... There are a myriad of ways to accomplish this.

- How is this enforced? Same way as any other parenting issue. If there is an incident that involves law enforcement, then social services can investigate and determine if negligence was occurring. When the child is mentally mature enough to deal with all the crap that is the internet their account is converted to an adult account. If the parent is giving the child an adult account before they are ready then the parent(s) go to mandatory parental training. If the child was being bullied or groomed, redirect law enforcement to go after the bullies or groomers.

- Set the laws to be active for any small child that would be under 13 as of the year 2034. Presto! One need not try to confine teens. When these small children are teens they will either be used to the sandbox account or the parent may have converted the account to adult.

As a side note all public and private schools should be legislated to have classes on dealing with all the crap the internet has to offer. Bullies, Cry-bullies, Trolls, Groomers, Scammers, Devious companies, Astroturfers, Gas Lighters, Propagandists, NGO's and so on. Also teach and help them build friend networks so there is protection in numbers. No child should be friendless.

[1] - https://nochan.net/b/Internet-Crap/20230829-Think-Of-The-Chi...

Bender··on Ask HN: Why are websites and apps still running legacy code?
I do not really have anything more to add. It sounds like this topic is something you are passionate about and maybe you will find a company that is looking to update or replace some old crusty code. I wish you the best of luck in this endeavor.
Bender··on Ask HN: Why are websites and apps still running legacy code?
Everything you are saying makes perfect sense, but that just isn't how big businesses work. Nobody wants their head on that chopping block so the only way that happens is if all the external parties are demanding it because of some regulatory changes that require the application be replaced and even then there will be meetings upon meetings upon meetings and even then they will stall to see if someone can find a clever work around that meets the new requirements. If all the external parties agree to the risks (they won't) and agree to the potential downtime(s) then the new code may move forward. These are incredibly rare events. I've seen a few of these in my lifetime and I am currently retired. Just to get SSLv2 deprecated in most of the customers took a very long time and very delicate hand holding every step of the way. Some customers just couldn't upgrade so they were assigned a special load balancer IP and strict firewall rules just for their companies. Most old crusty applications die with the company assuming it is not taken over in bankruptcy in which case some new people get to deal with it.
Bender··on Ask HN: Why are websites and apps still running legacy code?
What's keeping businesses from rebuilding & fixing their apps?

I can only speak from my past experiences with B2B. We had many B2B customers running ancient applications that would connect to us and transfer incredibly sensitive data. Getting them to update even a single application was not an option. The application may have been running for decades. The people that wrote it may be deceased or retired. Nobody knows what to do if it breaks so they dare not touch it, stare at it, taunt it or talk about it. It just works and nobody wants to create the crap-storm of creating something new that does not cover all the edge cases as a day of down-time could be millions or billions of dollars lost. Nobody want to be the one that caused that history making moment. Adding to this the application may be reaching out to dozens or hundreds of companies, government agencies, etc... and each organization expects it to work a specific way, yet there is no detailed architectural documents that would allow someone to flawlessly make a new application. Flawless is the key word. If a new thing is not flawless it will be immediately backed out and never spoken of again.

Bender··on Ask HN: What would convince you that a closed source messaging app is secure?
I've seriously considered the Librem. At the moment I have an ulefone armor with a really big battery and a very big bright LED flashlight for being in the wilderness though carrying a phone in the hills is not very practical. It's rugged but runs a carrier maintained version of Android. To have physical switches for wireless, mic and camera would be great. I am curious if you have run into any issues with RCS using a different OS and also curious if the Librem line will ever have a very rugged phone for extreme weather and with a really big battery for weirdo's like me.
Bender··on Ask HN: What would convince you that a closed source messaging app is secure?
I would not. If the modem was ever open source hardware it would never be permitted to attach to the major networks. There's always a catch. There is just too much collusion between wireless carriers and governments, having built out one of the first GSM network in the US in the 90's. The capabilities were wild back then and I can only imagine all the undocumented capabilities now. I only learned about the capabilities having worked around a lot of drunk Swedish telco switch mainframe developers.

Having said that, I would love to have a truly open source phone that I could load any bog standard Linux distro and all the drivers have been reviewed by Linus without him ever once feeling the urge to lift the middle finger. I would only be using it for non sensitive voice and text.

Bender··on Ask HN: What would convince you that a closed source messaging app is secure?
Nothing. I barely trust open source after it's been in use for decades, reviewed by a myriad of pen-testers and battle hardened in the most hostile regions of the internet. I don't trust anything on a cell phone at all. That's just my take. Others may be more trusting.
Bender··on As AI guzzles water and energy, we are facing a choice: datacentres or homes?
A bit of evaporative cooling for a data center is going right back into the cycle of things, it isnt lost water.

Agreed on everything you said, just adding that most data-centers are closed loop cooling and I have been in countless data-centers, some of the biggest in the US. I agree that data-center water usage pales in comparison to soft drinks which by themselves are a net negative to human health.

← PreviousPage 2 of 34Next →