frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Ask HN: Non AI-obsessed tech forums

16•nanocat•4h ago•10 comments

Ask HN: Anyone Using a Mac Studio for Local AI/LLM?

43•UmYeahNo•1d ago•26 comments

Ask HN: Ideas for small ways to make the world a better place

8•jlmcgraw•6h ago•16 comments

Ask HN: 10 months since the Llama-4 release: what happened to Meta AI?

42•Invictus0•22h ago•11 comments

AI Regex Scientist: A self-improving regex solver

5•PranoyP•8h ago•1 comments

Ask HN: Who wants to be hired? (February 2026)

139•whoishiring•4d ago•510 comments

Ask HN: Who is hiring? (February 2026)

312•whoishiring•4d ago•511 comments

Ask HN: Any International Job Boards for International Workers?

2•15charslong•4h ago•0 comments

Ask HN: Why LLM providers sell access instead of consulting services?

4•pera•14h ago•13 comments

Tell HN: Another round of Zendesk email spam

104•Philpax•2d ago•54 comments

Ask HN: Is Connecting via SSH Risky?

19•atrevbot•1d ago•37 comments

Ask HN: What is the most complicated Algorithm you came up with yourself?

3•meffmadd•16h ago•7 comments

Ask HN: Has your whole engineering team gone big into AI coding? How's it going?

17•jchung•1d ago•12 comments

Ask HN: How does ChatGPT decide which websites to recommend?

5•nworley•1d ago•11 comments

Ask HN: Is it just me or are most businesses insane?

7•justenough•1d ago•5 comments

Ask HN: Mem0 stores memories, but doesn't learn user patterns

9•fliellerjulian•2d ago•6 comments

Ask HN: Anyone Seeing YT ads related to chats on ChatGPT?

2•guhsnamih•1d ago•4 comments

Ask HN: Does global decoupling from the USA signal comeback of the desktop app?

5•wewewedxfgdf•1d ago•2 comments

Ask HN: Is there anyone here who still uses slide rules?

123•blenderob•3d ago•122 comments

Kernighan on Programming

170•chrisjj•4d ago•61 comments

We built a serverless GPU inference platform with predictable latency

5•QubridAI•1d ago•1 comments

Ask HN: How Did You Validate?

4•haute_cuisine•1d ago•4 comments

Ask HN: Cheap laptop for Linux without GUI (for writing)

15•locusofself•3d ago•16 comments

Ask HN: Have you been fired because of AI?

17•s-stude•3d ago•15 comments

Test management tools for automation heavy teams

2•Divyakurian•1d ago•2 comments

Ask HN: Does a good "read it later" app exist?

7•buchanae•3d ago•18 comments

Ask HN: OpenClaw users, what is your token spend?

14•8cvor6j844qw_d6•4d ago•6 comments

Ask HN: Anyone have a "sovereign" solution for phone calls?

11•kldg•3d ago•1 comments

Ask HN: Has anybody moved their local community off of Facebook groups?

23•madsohm•4d ago•17 comments

How do you deal with SEO nowadays?

5•jackota•1d ago•8 comments
Open in hackernews

Ask HN: Do You Block DigitalOcean?

11•sugarpimpdorsey•6mo ago
I have at least half their subnets blacklisted at this point. They seem to host a lot of bot traffic, port scans, and other generally unsavoury characters.

Is this the wrong approach? A losing battle of whack-a-mole?

FWIW I get a not-insignificant amount of malicious traffic from AWS, Azure, and Google but I view these providers as "too big to block" - I can't blacklist large swaths of their IP space without breaking the Internet.

Comments

ecb_penguin•6mo ago
Depending on your app, yes, you can block DO. You can probably block all of AWS and GCP as well. You can take it further and block all non-residential ASNs.

You'll block some legit traffic, but the majority of normal users will not be affected.

What is the persona of your average user? Average people shopping online? None of them are connecting through weird ASNs.

Someone complaining about a VPN being blocked? It's cost-benefit, tell them tough shit.

darklake•6mo ago
I've self hosted my email on DO for over 10 years on the same IP address. I am registered with Gmail so they don't block. I sometimes get blocked by major sites from whom I receive spam. I am not a fan of group punishment which is what you advocate.
mmarian•6mo ago
IP blocking is a losing battle. Malicious actors can easily hop onto residential proxies.

Why do you care about that traffic? What exploits are you worried about? The answers will help you figure out what protection you'll need to set up.

KomoD•6mo ago
> Malicious actors can easily hop onto residential proxies.

They can, but most don't. It's a lot more expensive than spinning up a $5 droplet

mmarian•6mo ago
$4 for 1GB, which is more than enough: https://oxylabs.io/pricing/residential-proxy-pool
fennec-posix•6mo ago
The Internet is always gonna have undesirable traffic if you're facing it. The trick is to minimize your surfaces as much as possible:

- Only keep open ports/forward ports for applications you use, drop/block everything else.

- Use strict host-header checking for web services on port 80/443, drop anything to 403/404 that doesn't have a valid host-header for the website(s) you're hosting.

- Move SSH and other remote admin servers to use a non-standard port. (legit, find a random port number between 9000-65535)

- If it doesn't need to be public, allow-list it with iptables.

Unfortunately DO and other providers will never have 100% legit traffic, it's just the nature of the Internet's noise floor.

Hope this helps you or someone else!

toomuchtodo•6mo ago
We block all cloud CIDRs at a financial services firm for public customer facing infra.
PaulHoule•6mo ago
There is a lot of blocking of AWS. Blocking inbound traffic to AWS would "break the internet" but outbound traffic is mostly automated systems which people don't like today -- despite the occasional desktop virtualization users.
ksherlock•6mo ago
You should block Cloudfare as well. Cloudfare workers are little more than a bot farm for hire. Allegedly, you can file an abuse report. Maybe. It's behind a captcha that thinks I'm a bot. Fuck them.

At least it's a short list.

https://www.cloudflare.com/ips/

https://www.cloudflare.com/ips-v4/#

Bender•6mo ago
For my silly hobby sites I block most VPS providers, especially the low cost providers. For some of my special purpose hobby things I also block wireless providers and anything sending a TCP SYN packet with a TTL greater than 128 or MSS outside of the range of 1220:1460 on IPv4 and I disable IPv6. I do many other things but those quite everything down a lot. To block archive.is I had to also block about 60 ASN's.
KomoD•6mo ago
Yes, I block DO on all my servers.
firefax•6mo ago
When I worked in a SOC I can't recall seeing anything malicious from them directed at my network -- it was usually AWS or Azure instances.

I'd focus on behaviors rather than providers -- I found them to be stricter than other providers at times when I was more of a skiddie -- I got very angry emails when I accidentally used an Algo I had set up on their stuff instead of a separate one for "linux ISOs".