614 karma · joined April 6, 2014
Of course, if you get hit with something slightly more targeted, this defense is worthless.
I spent a week in Helsinki, and was blown away by how quiet it was despite being far more dense than my city.
And congratulations on the achievement!
To fight them, I use OpenResty (which doesn't seem to get much attention on HN). OpenResty is basically Nginx with Lua scripting capabilities. Before any HTTP request hits my (slow) backend, it goes through a set of hand written Lua rules where I check very basic things about the client and HTTP request like how many requests/second (or minute) the client is generating, does it have any authentication cookies set, what is the client's ASN, how many times has it hit this particular route, etc. If there is a red flag, I quickly render a page (in OpenResty/Lua -- which can easily handle thousands of requests per second) with a captcha on it. The client then submits the captcha, and the server side Lua code sets a signed cookie authenticating their session (so it is not blocked for future requests).
One gotcha I remember was having to take special care to handle POST parameters from the initial request but otherwise, it was fairly simple.
My "web application firewall" has some fancy things like hot-reloading rules, fetching ASN numbers from the IP, and checking for legit bots (with reverse DNS lookups). I like to imagine it as an early form of Cloudflare.
I should note that my "captcha" is actually just a static image (with the alt/title attribute as the correct response). The people who attack my sites never bother to customize their attack. If it becomes an issue, I'll have to use a real captcha, but for now, it works.
I feel like these people just hit random websites to test their DDoS capabilities.
I had the exact same idea as you, and shelled out a few hundred dollars for a domain from a squatter. My prototype basically reinvents fault tolerant resumable uploads (like tus.io). On the backend, it streams the file to Wasabi and Backblaze. That's as far as I got. Video/audio scares me, but I'll get to it eventually.
I really like the content moderation as a service (via AI, or humans) idea that others have mentioned.
""" The preceding report appears to have been sent to you in error. Please accept our apologies for the mix-up and the false positive alert.
Please let us also assure you that we do value our long-term partnership with you and value you as our loyal customer. The situation experienced is no more acceptable to us than it was to you.
Such a time frame was specified in our initial email as phishing is considered to be a time-sensitive issue. However, we try to extend the time frame provided to our loyal customers to the maximum possible extent. Hence, the 24-hour time frame would have been extended in case of no-response from your side and we would tried to reach you again. """
I CC'd the CEO, but haven't heard anything direct. I can't have my domains with a company that has their trigger finger glue to the "suspend" button. I just don't know who else to register with. It's all a race to the bottom in terms of service and pricing. There doesn't seem to be a middle ground between MarkMonitor and Namecheap.
If OVH is totally down, and the fail over IP doesn't work, I have a fairly low TTL on the DNS.
I backup the database state to S3 every day.
Since I'm truly paranoid, I have an Intel NUC at my house that also replicates the DB. I like knowing that I have a complete backup of my entire business within arm's reach.
They could make it a charity, and the $5-10 million would be tax deductible on top of it.
At that point, maybe Intuit wouldn't have the motivation to keep the tax code complicated. Then we could move to a simplified system at the speed of congress.
Indeed. I get these security "wall of questions" for my $10/lifetime SaaS product (it's a dumb little puzzle maker). I can't fathom why anyone thinks a vendor would spend the time answering their questions for that kind of money.
In their defense, it's probably a standard part of the procurement process and they don't even look at the app before sending the questionnaire.
Aside from that, I have no complaints about their service.
The developer also produced an incredibly useful SVG test suite comparing various libraries https://razrfalcon.github.io/resvg-test-suite/svg-support-ta...
Ouch. So anyone who wants to support older devices 3 months from now needs to add `--preferred-chain "DST Root CA X3"` to their certbot command. When that chain is completely retired in September next year, certbot appears to fallback on the default (even with that argument present).
I'm a solo dev now. I don't keep track of my time religiously but RescueTime reports I'm coding 3-4 hours a day plus 1-2 hours of email.
I use uwsgi in emperor mode. I have a Makefile that runs a few SSH commands on production to clone my git repo at a specific commit, builds a virtual environment from requirements.txt, and atomically swaps a symlink to a uwsgi socket. Nginx in front of it all. It's pretty much the Python equivalent of FTPing HTML files to a web server.
Uwsgi is terrifying because it has so many options (and I wonder how secure it is), but it has never failed me. Packaging and containerizing things sounds cool, but I just can't justify spending time on it when my setup works fine (I'm a solo dev).
I was very confused because I had implemented a bad word filter which I knew worked (it was the most interesting part of building a word search). And obviously, I didn't hard code that string in my program!
I asked to see the offending puzzle. Upon inspection, I found that the word search contained the word "ORIGINAL". When reversed for the word search it is "LANIGIRO" (which contains the substring "NIGIRO"). The start of another word - "LAW" - was placed next to "LANIGIRO" (by random chance) creating the string "LLANIGIRO". The two preceding randomly chosen letters were "K" and "I", forming the string "KILLANIGIRO".
I explained it to the superintendent, and all was well again.
http://thefrenchexit.blogspot.com/2012/02/why-does-coffee-sm...
The downside is, if you find his arguments convincing, it will leave you feeling even more angry about the current role of government in society.
We need a term for when a company purposefully makes their website worse. It's kinda like the digital equivalent of planned obsolescence.
The trick is to find a good niche, so you can build a bunch of semi-related SaaS apps and cross market them. I've found developer related SaaS (web browser testing, PDF generation, log analysis, cron notifications, etc) are highly saturated.
To be fair, none of my products qualify as "startups". But building a lifestyle business has a lot of perks (no stress).