frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Ask HN: Do You Block DigitalOcean?

10•sugarpimpdorsey•1d ago
I have at least half their subnets blacklisted at this point. They seem to host a lot of bot traffic, port scans, and other generally unsavoury characters.

Is this the wrong approach? A losing battle of whack-a-mole?

FWIW I get a not-insignificant amount of malicious traffic from AWS, Azure, and Google but I view these providers as "too big to block" - I can't blacklist large swaths of their IP space without breaking the Internet.

Comments

ecb_penguin•1d ago
Depending on your app, yes, you can block DO. You can probably block all of AWS and GCP as well. You can take it further and block all non-residential ASNs.

You'll block some legit traffic, but the majority of normal users will not be affected.

What is the persona of your average user? Average people shopping online? None of them are connecting through weird ASNs.

Someone complaining about a VPN being blocked? It's cost-benefit, tell them tough shit.

darklake•1d ago
I've self hosted my email on DO for over 10 years on the same IP address. I am registered with Gmail so they don't block. I sometimes get blocked by major sites from whom I receive spam. I am not a fan of group punishment which is what you advocate.
mmarian•1d ago
IP blocking is a losing battle. Malicious actors can easily hop onto residential proxies.

Why do you care about that traffic? What exploits are you worried about? The answers will help you figure out what protection you'll need to set up.

fennec-posix•1d ago
The Internet is always gonna have undesirable traffic if you're facing it. The trick is to minimize your surfaces as much as possible:

- Only keep open ports/forward ports for applications you use, drop/block everything else.

- Use strict host-header checking for web services on port 80/443, drop anything to 403/404 that doesn't have a valid host-header for the website(s) you're hosting.

- Move SSH and other remote admin servers to use a non-standard port. (legit, find a random port number between 9000-65535)

- If it doesn't need to be public, allow-list it with iptables.

Unfortunately DO and other providers will never have 100% legit traffic, it's just the nature of the Internet's noise floor.

Hope this helps you or someone else!

toomuchtodo•1d ago
We block all cloud CIDRs at a financial services firm for public customer facing infra.
PaulHoule•1d ago
There is a lot of blocking of AWS. Blocking inbound traffic to AWS would "break the internet" but outbound traffic is mostly automated systems which people don't like today -- despite the occasional desktop virtualization users.
ksherlock•22h ago
You should block Cloudfare as well. Cloudfare workers are little more than a bot farm for hire. Allegedly, you can file an abuse report. Maybe. It's behind a captcha that thinks I'm a bot. Fuck them.

At least it's a short list.

https://www.cloudflare.com/ips/

https://www.cloudflare.com/ips-v4/#

Bender•20h ago
For my silly hobby sites I block most VPS providers, especially the low cost providers. For some of my special purpose hobby things I also block wireless providers and anything sending a TCP SYN packet with a TTL greater than 128 or MSS outside of the range of 1220:1460 on IPv4 and I disable IPv6. I do many other things but those quite everything down a lot. To block archive.is I had to also block about 60 ASN's.

Ask HN: How will the OSA affect small Mastadon instances?

7•Digit-Al•57m ago•0 comments

Claude Code weekly rate limits

568•thebestmoshe•19h ago•647 comments

Ask HN: Does Claude AI run locally?

2•kvthweatt•2h ago•1 comments

Ask HN: What are you working on? (July 2025)

251•david927•1d ago•814 comments

Have We Stopped Inventing Futures Worth Predicting?

4•squarekernels•5h ago•1 comments

How do I get a paid internship as a 16yo developer?

8•uint23•12h ago•18 comments

Drafting Software Recommendation

15•morpheos137•4d ago•16 comments

Warp.dev Terminal – Overpriced, Buggy, and AI-Sabotaged My Code

53•MistermanX•1d ago•37 comments

Ask HN: How many of you are working in tech without a STEM degree?

51•zebproj•6d ago•77 comments

My Theory: Advertising is a lot like capitalism itself

8•cm2012•18h ago•10 comments

Ask HN: Has your opinion on AI changed over the past year?

4•atleastoptimal•15h ago•11 comments

Ask HN: Is there any LLM provider that is GDPR compliant?

6•pera•15h ago•1 comments

Are we building AI coding assistants wrong?

2•anaempromptu•19h ago•3 comments

Ask HN: How do you handle audit logs in your systems?

16•efeoge•1d ago•8 comments

Ask HN: Have you ever waited for a project to be launched but it never did?

3•alganet•20h ago•3 comments

How to prioritize marketing when attribution is broken and AI is changing rules?

3•ivanmarketingua•1d ago•1 comments

Ask HN: What is Lex Fridman's association with MIT?

11•chirau•9h ago•7 comments

Ask HN: Do You Block DigitalOcean?

10•sugarpimpdorsey•1d ago•8 comments

Ask HN: Will I get left behind if I don't jump on AI train?

21•LLcolD•2d ago•32 comments

Ask HN: How do you build B2B software that pays living expenses?

10•architectofsw•1d ago•7 comments

Ask HN: Why do Cursor, Windsurf and Claude Code dominate the conversation?

28•bluelightning2k•1w ago•38 comments

Ask HN: What is so good about MCP servers?

43•metadat•4d ago•38 comments

FreeToolSuite – 200 growing collection of genuinely useful free online tools

25•mviradia•2d ago•4 comments

Ask HN: Are we pretending RAG is ready, when it's barely out of demo phase?

11•TXTOS•2d ago•10 comments

Ask HN: Discrete Mathematics Preriquisites for Data Structures?

3•shivajikobardan•2d ago•1 comments

I'm Peter Roberts, immigration attorney who does work for YC and startups. AMA

164•proberts•1w ago•266 comments

Ask HN: What's your uv exit strategy?

12•ctoth•1d ago•8 comments

Ask HN: Engineers deserve better recognition. Can a protocol change that?

7•mzk_pi•1d ago•16 comments

Ask HN: Why is virtualization still not solved?

16•prmph•3d ago•30 comments

Ask HN: Who is looking for a cofounder in London?

10•warthog•2d ago•4 comments