frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Preventing quantum downgrade attacks against IPsec

https://blog.cloudflare.com/ipsec-downgrade-protection/
1•bbg2401•1m ago•0 comments

"All Wars Are Bankers' Wars "

https://whatreallyhappened.com/WRHARTICLES/allwarsarebankerwars.php
1•axiologist•2m ago•1 comments

Most powerful obesity drug yet: People lost up to 25% of weight in trial

https://arstechnica.com/health/2026/09/most-powerful-obesity-drug-yet-people-lost-up-to-25-of-wei...
1•jnord•3m ago•0 comments

Recast WOOF: High Resolution GPU powered numerical weather simulations

https://sf.recastsystems.com
2•roastedpillows•6m ago•0 comments

Historical Burdens on Physics (2022) [pdf]

https://www.karlsruher-physikkurs.de/download/historical_burdens-2022.pdf
1•vitalnodo•6m ago•0 comments

AI does, and does not, change the way I do math

https://terrytao.wordpress.com/2026/09/29/how-ai-does-and-does-not-change-the-way-i-do-math/
1•smilelamp•6m ago•0 comments

California Virtual Power Plant

https://www.tesla.com/vpp/california
1•andsoitis•9m ago•0 comments

Build Freely: Non-AI Shed Plan Generator

https://buildfreely.com/
1•darkstar999•15m ago•0 comments

They're trying to build a digital God and then enslave it

https://www.reddit.com/r/stocks/comments/1wtdg4w/comment/pct6bsp/
1•remywang•15m ago•0 comments

I Redesigned My Courses Around Notebooks

https://jillianhess.substack.com/p/why-i-redesigned-my-courses-around
1•herbertl•17m ago•0 comments

Firefox's chief on why he hopes a redesign will help win users from Chrome

https://arstechnica.com/gadgets/2026/09/mozillas-head-of-firefox-talks-product-priorities-ai-skep...
2•walrus01•18m ago•4 comments

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional

https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targe...
1•sbulaev•20m ago•0 comments

Olomni (Olomni Agent)

https://www.olomni.com/
1•FaustoDario33•20m ago•0 comments

Mathematicians Harness Randomness to Crack a 55-Year-Old Conjecture

https://www.quantamagazine.org/mathematicians-harness-randomness-to-crack-a-55-year-old-conjectur...
1•tzury•22m ago•0 comments

Show HN: Social news aggregator, RSS feed tracker, and publishing platform

https://rsscal.com/
2•Dotnaught•22m ago•0 comments

CISA scraps 6 free cybersecurity assessments for infrastructure operators

https://www.cybersecuritydive.com/news/cisa-cybersecurity-assessments-ending/829371/
1•geox•22m ago•0 comments

Reality Only Takes Yes for an Answer

https://www.raptitude.com/2026/09/reality-only-takes-yes-for-an-answer/
1•inatreecrown2•23m ago•0 comments

Show HN: ApexHierarchy – one power scale for people, companies and institutions

https://apexhierarchy.com
1•ParamJaisinghan•26m ago•0 comments

Apple pressured to explain Trump role in ICE-tracking app removals

https://arstechnica.com/tech-policy/2026/09/apple-worked-with-trump-admin-to-remove-ice-tracking-...
2•tony101•27m ago•0 comments

Marketing That Makes Sense to Engineers

https://www.quivergtm.dev/blog/finally-marketing-that-makes-sense-to-engineers
1•builtfordevs•30m ago•0 comments

Show HN: Free token compression CLI, saves codex bills by 30%

https://github.com/spenmcke/compress
1•srmckee•37m ago•1 comments

The Anatomy of a $2 VPS: Where Does Your Money Go?

https://lowendbox.com/blog/the-anatomy-of-a-2-vps-where-does-your-money-actually-go/
1•shaunpud•40m ago•0 comments

Agents and Chatbots Don't Have to Be Mutually Exclusive

https://app.flexreportfinapi.com/blog/agents-and-chatbots-dont-have-to-be-mutually-exclusive
1•frfc12•40m ago•0 comments

While the Country Rejects ALPR Mass Surveillance, SF Settles for Weak Safeguards

https://www.eff.org/deeplinks/2026/09/while-country-rejects-alpr-mass-surveillance-sf-settles-wea...
1•hn_acker•44m ago•0 comments

Show HN: Ledge.sh – Runnable Markdown Notes

https://ledge.sh
2•dancablam•45m ago•0 comments

Inspect: An open-source framework for large language model evaluations

https://inspect.aisi.org.uk/
2•pkilgore•47m ago•0 comments

Councilmember, residents push back on AI 'blight scores' given to homes

https://www.nbcdfw.com/investigations/dallas-councilmember-residents-push-back-on-ai-blight-score...
6•hn_acker•48m ago•2 comments

WSL2 Disk Keeps Growing?

https://sweepdevv.netlify.app/blog-wsl2-shrink.html
1•asad504•50m ago•0 comments

Halo: Combat Evolved on Apple Silicon

https://github.com/pkyanam/halo-ce-apple-silicon
1•pkyanam•50m ago•1 comments

TeXmacs Vue – GNU TeXmacs in the Browser

https://mgubi.github.io/texmacs/
1•amichail•51m ago•0 comments
Open in hackernews

No as a Service

https://github.com/hotheadhacker/no-as-a-service
64•radeeyate•1y ago

Comments

Haeuserschlucht•1y ago
:)
artogahr•1y ago
:)
blahaj•1y ago
> Rate Limit: 10 requests per minute per IP

I understand that one wants some rate limiting so that others don't just use this as a backend for their own service causing every single request for their service to also create an API request. But this is as simple and resource unintensive as it gets for an HTTP server. 10 requests per minute is just silly.

Also could it be that the limit isn't enforced against the origin IP address but against the whole Cloudflare reverse proxy?

jaywcarman•1y ago
10 requests per minute per IP is plenty enough to play around with and have a little fun. For anything more than that you could (should!) host it yourself.
blahaj•1y ago
So it is just purposefully made to be less useful? Is that part of the joke?

The rate limit still pretty surely isn't applied per IP.

arp242•1y ago
Mate, it's a joke, not a serous service. The only silly thing here is going off on a tangent about the rate limit.
mindtricks•1y ago
If it helps you, think of the rate limiter as the "no" final boss.
choult•1y ago
Well this is something... someone creating a service off the back of a meme that's been flying around my networks for the past two days...
ziddoap•1y ago
Fun idea. I wonder why the rejection messages are repeated so often in the "reasons" file.

"I truly value our connection, and I hope my no doesn't change that." shows up 45 times.

Seems like most of the rejections appear between 30 and 50 times.

khanan•1y ago
Was wondering the same thing.. Probably cruft so it looks impressive at a glance.
Retr0id•1y ago
If you ask LLMs for a long enough list of things, they often repeat entries.
MalbertKerman•1y ago
There are 25 unique responses in that 1000-line file.
justin_oaks•1y ago
Once you remove the duplicates that are different only because of the typos in them, yes, that's correct.
mikepurvis•1y ago
A single large file is also sadness for incorporating suggestions from collaborators as you're always dealing with merge conflicts. Better might be a folder of plain text files, where each can have multiple lines in it, and they're grouped by theme or contributor or something.
varun_ch•1y ago
> {"error":"Too many requests, please try again later."}

I guess it still works.

lgl•1y ago
Bug report: when the server is overloaded, the No's are no longer random :)
kenrick95•1y ago
Classic Hacker News hug of death
xnorswap•1y ago
It looks like it's limited to 10 requests per minute, it's less of a hug and more of a gentle brush past.

It's documented as "Per IP", but I'm willing to bet either that documentation is wrong, or it's picking up the IP address of the reverse proxy or whatever else is in-front of the application server, rather than the originator IP.

Why do I think that? Well these headers:

    x-powered-by Express

    x-ratelimit-limit 10

    x-ratelimit-remaining 0

Which means it's not being rate-limited by cloudflare, it's express doing the rate limiting.

And I haven't yet made 10 requests, so unless it's very bad at picking up my IP, it's picking up the cloudflare IP instead.

egberts1•1y ago
Probably all those cookies tipped and triggered the connection rate limiter.
xnorswap•1y ago
Retr0id•1y ago
It could be genuinely useful for testing HTTP clients if it had a wider array of failure modes.

Some ideas:

- All the different HTTP status codes

- expired/invalid TLS cert

- no TLS cipher overlap

- invalid syntax at the TLS and/or HTTP level

- hang/timeout

- endless slowloris-style response

- compression-bomb

- DNS failure (and/or round-robin DNS where some IPs are bad)

- infinite redirect loop

- ipv6-only

- ipv4-only

- Invalid JSON or XML syntax

zikani_03•1y ago
Not exactly what you are asking for, but reminded me that Toxiproxy[0] exists if you want to test your applications or even HTTP clients against various kinds of failures:

[0]: https://github.com/Shopify/toxiproxy

deanputney•1y ago
Not sure why, but reasons.json is mostly duplicates (as many as 50!) of the same 25 responses: https://gist.github.com/deanputney/4143ca30f7823ce53d894d3ed...

It'd be easier to add new ones if they were in there a single time each. Maybe the duplication is meant to handle distribution?

finnh•1y ago
ah, yes, the "memory is no object" way of obtaining a weighted distribution. If you need that sweet sweet O(1) selection time, maybe check out the Alias Method :)
justin_oaks•1y ago
Knowing that there are only 25 responses, it makes it all the more funny that rate limiting is mentioned.

And you can host the service yourself! Hard pass. I'll read the 25 responses from your gist. Thanks!

thih9•1y ago
Example responses:

https://raw.githubusercontent.com/hotheadhacker/no-as-a-serv...

anonymousiam•1y ago
Looks impressive, but out of the 1000 possible responses, only 26 are unique.
qrush•1y ago
Oh great, it's Balatro's Wheel of Fortune card as a Service (WoFaaS)
hombre_fatal•1y ago
I made a lot of things like this as a noob and threw them up on github.

As you gain experience, these projects become a testament to how far you've come.

"An http endpoint that returns a random array element" becomes so incredibly trivial that you can't believe you even made a repo for it, and one day you sheepishly delete it.

blahaj•1y ago
I don't think things have to be impressive to be shown. A funny little idea is all you need, no matter how simple the code. Actually I find exactly that quite neat.
TehCorwiz•1y ago
I think you'll enjoy this better: https://github.com/EnterpriseQualityCoding/FizzBuzzEnterpris...
seabass•1y ago
{"error":"Too many requests, please try again later."}

a missed opportunity for some humor

richrichardsson•1y ago
{"error":"Computer says no."}
readthenotes1•1y ago
Beats "I have a headache"
n8m8•1y ago
inb4 someone genuinely doesn't understand why you wouldn't do this with an LLM
macleginn•1y ago
A worthy spiritual disciple of the Journal of Universal Rejection (https://www.universalrejection.org/)
svilen_dobrev•1y ago
nice. Reminds me of BOFH (Bastard operator from Hell) . And those box-like calendars with page-per-day with some excuse^w^w tip on each :)

https://bofh.bjash.com/bofh/bofh1.html

hotheadhacker•1y ago
The API rate limiting has been removed.
spiffyk•1y ago
A folder of plain text files will be sadness for performance. It's a file with basically line-wise entries, merge conflicts in that will be dead easy to resolve with Git locally. It won't be single-click in GitHub, but not too much of a hassle.
Retr0id•1y ago
It's ~fine for performance if you load them once at service startup. But I agree, merging is also no big deal.
mikepurvis•1y ago
In fairness, I doubt most of these kinds of meme projects have a maintainer active enough to be willing to conduct local merges, even if it's "dead easy" to do so.

Maybe then this is really a request for Github to get better/smarter merge tools in the Web UI, particularly syntax-aware ones for structured files like JSON and YAML, where it would be much easier to guess, or even just preset AB and BA as the two concrete options available when both changes inserted new content at the same point. It could even read your .gitattributes file for supported mergers that would be able to telegraph "I don't care about the order" or "Order new list entries alphabetically" or whatever.

cf. https://github.com/jonatanpedersen/git-json-merge

KTibow•1y ago
It might be a weighted random.
ziddoap•1y ago
Might be!

Not the way I'd approach it, but as a joke service, if it works it works.

I'm not following you at all?
NotMichaelBay•1y ago
It's so elegant. Even in failure, it's still operational.
riquito•1y ago
Love it, it's brilliant, but I think the rate limiting logic is not doing what the author really wants, it actually costs more cpu to detect and produce the error than returning the regular response (then my mind goes on how to actually over optimize this thing, but that's another story :-D )
hotheadhacker•1y ago
Rate limiting has been removed