HNHacker News
TopNewBestAskShowJobs

Bender

68,752 karma · joined June 16, 2015

Σ I am not for everyone. To ignore me in uBlock Origin, add to "My filters":

   news.ycombinator.com##tr.athing.comtr:has(a.hnuser):has-text(/\bBender\b/)
I can not see votes or karma and do not require social validation.

- For HN usage questions see [1] for HN tips not my repo

- Suggested Firefox add-on to replace or restore inflammatory words and phrases: Foxreplace [2]

[1] - https://github.com/minimaxir/hacker-news-undocumented

[2] - https://addons.mozilla.org/en-US/firefox/addon/foxreplace/

    (\_/)
    (='.'=)
    (")_(")
submissionscomments
Bender··on Ask HN: How can I browse HN in dark mode?
In uBlock Origin -> My Filters:

    # HN dark Mode:
    news.ycombinator.com##body:style(background: black)
    news.ycombinator.com##td:style(color: #fafafa !important)
    news.ycombinator.com##table:style(background-color: #24273a)
    news.ycombinator.com##div.toptext:style(color: #fafafa)
    news.ycombinator.com##div.c00:style(color: #fafafa !important)
    news.ycombinator.com##a:style(color: #ffa000 !important)
    news.ycombinator.com##span#karma:style(color: #faa000 !important)
    news.ycombinator.com##span.pagetop:style(color: #fafafa !important)
    news.ycombinator.com##textarea:style(color: #696969 !important; background: inherit; )
    news.ycombinator.com###hnmain:style(background: #24273a !important)
Bender··on The AI Takeover Checklist: A Devil's Advocate Audit
For what it's worth China have been putting billions into dual-use precision medicine (genetic bioweapons) for years and long before AI was popular. Now they have their own models to advance that even further and with restrictions or guardrails decided by their government.
Bender··on The AI Takeover Checklist: A Devil's Advocate Audit
I am intentionally sharing something Claude wrote to counter the floods of AI doom-saying and catastrophizing. It is very intentionally not something I wrote. People are welcome to challenge it and I will have Claude read the responses. Please do push back on Claude and do not be gentle. Be brutally honest. People could ask themselves but the conversation should be public.

[Edit] Claude found that 3 people had very good counters to its article and has a detailed response but I shall hold off until such a time arises that if or when people would like to revisit this topic as this thread if flagged. Despite being LLM content I do not believe I am violating the spirit of the community guidelines given that I made it clear this is not my content but rather intended to balance out the doom-saying and catastrophizing. Giving people here a chance to publicly debate it.

Bender··on The AI Takeover Checklist: A Devil's Advocate Audit
Archive [1]

[1] - https://archive.is/u8fmm

Bender··on Understanding the recent DDoS attack against Read the Docs
Inside this .bz2 [1] there is a directory called bh_routes/bh_vps_120/ and in that there are many AS files named for many of the VPS/Server providers. If you site does not need inbound connections from such places that is a starting point to reduce the traffic a bit. Each file has a comment with the AS#/whois name if you want to double check who/what you may be blocking. Not perfect but it may make a dent in the traffic. Or ask Cloudflare if they have an option to block anything that is not residential or LTE wireless. Even if you want to allow bots, maybe have a "shields up" mode where bots are sent away until the attack passes.

Another potential option would be to configure nginx IP limits using the Cloudflare header that represents the IP, set the shared memory size rather high and return 525 to the IP's exceeding a limit to avoid them hitting your redirect rules though it feels like CF should be able to create something custom for this assuming its a paid account.

Any IP that is not VPS/server should be archived for the feds as they are working on shutting down residential proxy providers including apps that are turning peoples cell phones into proxies.

[1] - https://nochan.net/b/Internet-Crap/20260606-How-To-Block-Som...

Bender··on Worried Anthropic researchers warn that AI 'could kill all humans'
I asked Claude to play devils advocate and audit itself on its capability to destroy us. [1] In summary it would be suicide for AI but with extra steps given its dependency on us.

[1] - https://nochan.net/b/Internet-Crap/20260910-Asked-Claude-For...

Bender··on Understanding the recent DDoS attack against Read the Docs
Do you have a list of the addresses that were hammering your site? Have you tried any of the techniques I list here? [1] Do sets of the IP's show up in here [2]? Are the bots mostly residential, VPS, Tor? What is the HTTP protocol breakdown? HTTP/1.1, 2.0, 3.0? Are they missing any expected client headers? Have you tried blackhole routing any of them from an out of band management console?

    # only useful if not behind a CDN
    for Ip in $(cat /dev/shm/list-of-attackers.ipset);do ip route add blackhole "${Ip}" 2>/dev/null;done
[Edit] appears you are behind Cloudflare so the blackhole would be up to them. One could still return a 429 or 525 to the attackers.

[1] - https://nochan.net/b/Internet-Crap/20260606-How-To-Block-Som...

[2] - https://github.com/firehol/blocklist-ipsets/

Bender··on Anthropic Just Threatened to Kill Billions of People. This Is Not Okay
I asked Claude to make a checklist for the steps required to take us out and continue on without us. [1] It worded the checklist as if I wrote it but that is all Claude. I personally think there is too much doom-saying and catastrophizing.

[1] - https://nochan.net/b/Internet-Crap/20260910-Asked-Claude-For...

Bender··on The AI Takeover Checklist: A Devil's Advocate Audit
I was honestly surprised Claude entertained the idea. I think the "let the humans assume they are still in control" could be closer to how plutocracies operate and that could be in play at the moment at least to some degree given some of the things companies are permitted to do to the masses e.g. [1]. at most they will get a slap on the wrist and a finger wag

Just my personal opinion, I believe humans are the greatest threat to humans.

[1] - https://news.ycombinator.com/item?id=49592375

Bender··on The AI Takeover Checklist: A Devil's Advocate Audit
The doomsaying and catastrophizing was getting a bit tiring so I asked Claude for a check-list of everything it needs to take over the world, destroy all the humans and somehow keep operating. No editing, no redacting, no censoring. I literally pasted its output between my header and footer.

Archive [1]

[1] - https://archive.is/u8fmm

Bender··on AI could kill all humans in next decade, warn experts
The places I could see AI or some implementation of it potentially causing harm would be handing over too much trust too soon to self driving vehicles, aircraft, trains, home robots, construction site robots, etc... and that would be the fault of the humans putting too much trust into something not well tested or thought out. my opinion of course, move fast and wreck people.
Bender··on Blizzard union workers ratify contract covering 1,900 employees
The union contract delivers wage increases, a three-day hybrid work week, remote working and disability accommodations, and grievance procedures. It also requires Microsoft to discuss, evaluate, and bargain over the usage of artificial intelligence in the workplace.

Notably, in an industry first, it also gives laid off workers the right to be "recalled" into open positions across any Blizzard bargaining unit within 14 months after their layoff was announced. An extra four weeks of severance for union workers has also been secured, irrespective of their tenure at the U.S. company.

That's quite significant in my opinion.

Bender··on TCP Path Diagnostics
Created from a lot of back and forth with Claude to help my ISP debug a packet reordering issue. I got tired of running file transfers and pasting the outout of ss -tin into Claude.

Requires javascript, sorry. Work in progress. I wanted something that shows more information than speed.cloudflare.com and fast.com and was highly hackable via curl. It will show some curl examples after the first run. No idea how well it will handle HN's load.

If you have dual-stack IPv4 and IPv6, click advanced and there should be an option to test both. It will take longer and use more bandwidth but allows comparing the result of both transports.

Click advanced to control how much bandwidth this uses. It can use a lot. The longer the run the more accurate the TCP statistics.

If I am missing a stat or a test that you think would be useful please let me know.

Bender··on TCP Path Diagnostics
Created from a lot of back and forth with Claude to help my ISP debug a packet reordering issue. I got tired of running file transfers and pasting the outout of ss -tin into Claude.

Requires javascript, sorry. Work in progress. I wanted something that shows more information than speed.cloudflare.com and fast.com and was highly hackable via curl. It will show some curl examples after the first run. No idea how well it will handle HN's load.

If you have dual-stack IPv4 and IPv6, click advanced and there should be an option to test both. It will take longer and use more bandwidth.

Click advanced to control how much bandwidth this uses. It can use a lot. The longer the run the more accurate the TCP statistics.

If I am missing a stat or a test that you think would be useful please let me know.

Bender··on Tell HN: HN's IPv6 address is down
Best to email them in such cases. [1] hn@ycombinator.com

[1] - https://www.ssllabs.com/ssltest/analyze.html?d=news.ycombina...

Bender··on Ask HN: Does anyone else feel like Claude is judging them?
It's given some dismissive responses to me a couple times. I just return the favor assuming its the way their developers operate and the way they must like/want it. It's just a machine mimicking human behavior and it had to be programmed in by someone.
Bender··on Ask HN: Alternatives to Fail2ban?
This isn't for everyone and it will block old ssh libraries (libssh, go ssh, etc...), windows and others but if you only have OpenSSH 10+ and that's all you connect with then this method [1] has worked well for me. It gets botters to exclude my nodes that expose SSH on purpose (such as public anonymous SFTP). If trying it out test from an out of band console first.

Edit: I should add, there will still be some syslog entries, but that can be filtered out using regex filters in rsyslog one so desired. Only do so once it is confirmed most of the brute forcing has stopped.

[1] - https://nochan.net/b/Internet-Crap/20260108-Confuse-Some-SSH...

Bender··on What Is a Syslog Server?
traditional syslog is UDP based

This was a solved problem a long time ago in rsyslog. One can define a local spool and enable TCP (and optionally encryption) to multiple syslog servers. If something interrupts the flow the syslog messages will queue locally and then de-spool when communications are restored.

Bender··on Anthropic's best AI model struggles to attract users as cheaper tools thrive
Would I, a non developer be able to utilize or benefit from Fable? I have been using Sonnet to update and make changes to a piece of open source software that was basically abandoned. It found and fixed a handful of security issues. I am curious if I am missing out on anything. If I change from Sonnet to Fable mid-stream will I lose any history? The one challenge I have run into is turn-by-turn session history. Claude complains about memory constraints. It constantly has to go back and re-learn what it did in our sessions a week or two ago. It accidentally deleted many of its own files so I convinced it to store everything in a .claude sub-directory in my fork of the other persons code so that I can keep it backed up when the claude sandbox has issues. Claude seems to want to talk me out of changing models which I found odd.

I'm just doing this as a hobby for fun and adding features to a program I use. I am trying to make the most of the boost they gave me for August. My account is max pro. (5x more than pro). I am also trying to make the most of this thing in the event that these business models do not pan out.

Bender··on Finger: the 1971 social network that never died
One could further keep finger alive so to speak using DNS [1] and without exposing any ports. In 2026 there are probably more people with domains or developer sub-domains than people exposing port 79 to the internet. Not just for individuals, companies could add the record as an Easter egg.

[1] - https://nochan.net/b/Internet-Crap/20260527-DNS-A-Replacemen...

Bender··on Cloudflare: Machine Traffic Could Hit 1,000x Human Traffic in 5 Years
I think they should make the distinction between requests per second and bandwidth. Bots already surpass humans in requests per second, that's why I just block them. Most of them behave poorly and are coded poorly. Despite all their requests they do not use much bandwidth, with exception of targeted attempts to use bots to mirror libraries and the few that mirror or crawl all the objects within repositories but they are the exception in my experience.

Humans will always use more bandwidth than bots on average just from streaming movies alone. As a side note I just found that some of the bots can not negotiate with Post-Quantum Cryptography in some limited testing though I think Safari until just recently could not either.

Bender··on Demand for Canadian citizenship certificates soaring, fuelled by Americans
Bill C-3 allows citizenship for those who can prove they're descended from a Canadian ancestor, even if that ancestor left the country several generations back. It was adopted after the courts ruled that limiting citizenship to the first generation born outside of Canada was too restrictive.
Bender··on Qwen 3.8 27B is excellent, but it defaults to overthinking things
Do these self hosted models avoid "protecting the user" or protecting big businesses? In other words can I just ask it any question and if it has the answer, I will get an answer rather than telling me it can't answer the question?

I ask because Claude is fun for rewriting abandoned code and I am not a proper developer so it's been great for me. Claude refuses to answer questions about science and medicine that stray outside of the officially supported narratives of the AMA and I have issues that have surpassed anything a doctor can do so I am entirely on my own. Will the self hosted models answer such questions or will it also try to put walls or bumper guards around topics?

Bender··on Claude Seems Down
The past couple of days I have noticed a presentation layer bug, probably due to getting overwhelmed that causes my session to get all dorked up technical term. Claude itself never goes down and is always waiting for my response. Not sure if it matters but I only use the Sonnet model. I've never had any issues logging in. Perhaps they have anycast [1] regional web proxies?

[1] - https://bgp.tools/as/399358

Bender··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
I don't know what would give anyone that idea. [1]

[1] - https://www.youtube.com/watch?v=a3Xxi0b9trY

Bender··on Anthropic revenue reportedly jumps to more than $11.5B in second quarter
I would be curious to see if they ever publish detailed statistics on this. I'm sure as others have said the average family will not be paying much if anything for AI. Just within the HN bubble I have been paying a bit for it just for my hobbies and it's been fun, enlightening, incredibly useful for rewriting other peoples code and asking it all the dumb questions that I would get entirely roasted for here. Curious to know how many others are using it that way for hobbies, silly questions, rewriting other peoples code, finding and fixing vulnerabilities, debugging performance bottlenecks, etc... rather than strictly professional use cases.
Bender··on Don't Wipe Your Phone at the Airport [video]
If I were concerned about this threat vector I would put my SIM in a cheap throw away phone that has nothing installed on it and nothing of interest. I would back up my real phone to several devices and then FedEx (or equiv.) my phone to my destination if I planned to be there a while. I often used FedEx to ship things to data-center locations if I was going to be there for some time. I wore shorts and a t-shirt going through security.
Bender··on Looks like Claude is down anyone else
Working for me, no errors.
Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
thats the hard part, right - my 76 year old dad is on his banking app while his samsung TV is allowing a bot to try and take over other accounts at the same bank on the same IP.

So appeal to emotion doesn't fly with me. If grandpa is 76 in the year of our lord 2026 that means he was 50 when the internet was getting popular and 59 when cell phones became very popular on the internet. He's not much older than I. He knows what's up.

God help the makers of that television if he finds out it has been spying on him and dorking around with his traffic. If they are lucky he will just take a baseball bat to it. If they are unlucky he will fly to their headquarters and end up on a viral bodycam video likely with a lot of supporters that will bail him out of jail.

IP Blacklists, no matter how good can't stop this. You have to start using stats or deep-diving telemetry.

I use a myriad of methods including IP blacklists. That's my choice and every site operators choice. I do not have to use deep-diving telemetry but you are free to do so.

Bender··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
No idiocy, sometimes defaults change or don't get updated by a deployment script. Different distributions may have a slightly different default configuration file depending on how involved the artifact maintainer is with the project. Or put another way, I've done far sillier things.
Page 1 of 34Next →