frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Study confirms experience beats youthful enthusiasm

https://www.theregister.com/2026/02/07/boomers_vs_zoomers_workplace/
1•Willingham•3m ago•0 comments

The Big Hunger by Walter J Miller, Jr. (1952)

https://lauriepenny.substack.com/p/the-big-hunger
1•shervinafshar•4m ago•0 comments

The Genus Amanita

https://www.mushroomexpert.com/amanita.html
1•rolph•9m ago•0 comments

We have broken SHA-1 in practice

https://shattered.io/
1•mooreds•9m ago•1 comments

Ask HN: Was my first management job bad, or is this what management is like?

1•Buttons840•10m ago•0 comments

Ask HN: How to Reduce Time Spent Crimping?

1•pinkmuffinere•12m ago•0 comments

KV Cache Transform Coding for Compact Storage in LLM Inference

https://arxiv.org/abs/2511.01815
1•walterbell•16m ago•0 comments

A quantitative, multimodal wearable bioelectronic device for stress assessment

https://www.nature.com/articles/s41467-025-67747-9
1•PaulHoule•18m ago•0 comments

Why Big Tech Is Throwing Cash into India in Quest for AI Supremacy

https://www.wsj.com/world/india/why-big-tech-is-throwing-cash-into-india-in-quest-for-ai-supremac...
1•saikatsg•18m ago•0 comments

How to shoot yourself in the foot – 2026 edition

https://github.com/aweussom/HowToShootYourselfInTheFoot
1•aweussom•19m ago•0 comments

Eight More Months of Agents

https://crawshaw.io/blog/eight-more-months-of-agents
3•archb•21m ago•0 comments

From Human Thought to Machine Coordination

https://www.psychologytoday.com/us/blog/the-digital-self/202602/from-human-thought-to-machine-coo...
1•walterbell•21m ago•0 comments

The new X API pricing must be a joke

https://developer.x.com/
1•danver0•22m ago•0 comments

Show HN: RMA Dashboard fast SAST results for monorepos (SARIF and triage)

https://rma-dashboard.bukhari-kibuka7.workers.dev/
1•bumahkib7•22m ago•0 comments

Show HN: Source code graphRAG for Java/Kotlin development based on jQAssistant

https://github.com/2015xli/jqassistant-graph-rag
1•artigent•27m ago•0 comments

Python Only Has One Real Competitor

https://mccue.dev/pages/2-6-26-python-competitor
3•dragandj•29m ago•0 comments

Tmux to Zellij (and Back)

https://www.mauriciopoppe.com/notes/tmux-to-zellij/
1•maurizzzio•29m ago•1 comments

Ask HN: How are you using specialized agents to accelerate your work?

1•otterley•31m ago•0 comments

Passing user_id through 6 services? OTel Baggage fixes this

https://signoz.io/blog/otel-baggage/
1•pranay01•32m ago•0 comments

DavMail Pop/IMAP/SMTP/Caldav/Carddav/LDAP Exchange Gateway

https://davmail.sourceforge.net/
1•todsacerdoti•32m ago•0 comments

Visual data modelling in the browser (open source)

https://github.com/sqlmodel/sqlmodel
1•Sean766•34m ago•0 comments

Show HN: Tharos – CLI to find and autofix security bugs using local LLMs

https://github.com/chinonsochikelue/tharos
1•fluantix•35m ago•0 comments

Oddly Simple GUI Programs

https://simonsafar.com/2024/win32_lights/
1•MaximilianEmel•35m ago•0 comments

The New Playbook for Leaders [pdf]

https://www.ibli.com/IBLI%20OnePagers%20The%20Plays%20Summarized.pdf
1•mooreds•36m ago•1 comments

Interactive Unboxing of J Dilla's Donuts

https://donuts20.vercel.app
1•sngahane•37m ago•0 comments

OneCourt helps blind and low-vision fans to track Super Bowl live

https://www.dezeen.com/2026/02/06/onecourt-tactile-device-super-bowl-blind-low-vision-fans/
1•gaws•39m ago•0 comments

Rudolf Vrba

https://en.wikipedia.org/wiki/Rudolf_Vrba
1•mooreds•39m ago•0 comments

Autism Incidence in Girls and Boys May Be Nearly Equal, Study Suggests

https://www.medpagetoday.com/neurology/autism/119747
1•paulpauper•40m ago•0 comments

Wellness Hotels Discovery Application

https://aurio.place/
1•cherrylinedev•41m ago•1 comments

NASA delays moon rocket launch by a month after fuel leaks during test

https://www.theguardian.com/science/2026/feb/03/nasa-delays-moon-rocket-launch-month-fuel-leaks-a...
2•mooreds•41m ago•0 comments
Open in hackernews

Ask HN: Contact form spam despite trying everything

2•pettycashstash2•8mo ago
I'm at my wit's end with contact form spam on my sites. I've tried:

CleanTalk - caught some spam but still getting through, plus the monthly cost adds up Turnstile - better UX than reCAPTCHA but bots seem to be solving it reCAPTCHA v2 - effective but users hate the image challenges reCAPTCHA v3 - invisible but I'm still getting 20-30 spam submissions daily even with strict thresholds

I've also implemented honeypots, rate limiting, basic keyword filtering, and email validation (both format checking and MX record verification). The spam is getting more sophisticated - proper English, realistic email addresses that actually exist, even passing behavioral checks. What I'm curious about: How does Hacker News handle spam so effectively? I rarely see spam comments here, and there's no visible CAPTCHA. Are you using something custom, or is there a service/approach I'm missing? For context, I get about 500 legitimate form submissions per month, so I need something that won't block real users while stopping the bot flood. What's worked best for your sites? Especially interested in hearing from anyone who's dealt with determined, human-like spam at scale.

Comments

gus_massa•8mo ago
> I rarely see spam comments here, and there's no visible CAPTCHA. Are you using something custom, or is there a service/approach I'm missing?

Go to your profile https://news.ycombinator.com/user?id=pettycashstash2 and enable "showdead". There is a lot of bad post that are [dead] and are hidden unless you really want to see them.

There is a mix of automated tools, but the details are part of the secret sause, dang never told them. Also a lot of manual moderation by the mods. And also, users can flag and downvote bad comments and with enough of them the post is marked as [dead].

A long time ago, I used Spambayes to filter email. I'm not sure if it van be adapted to filter your contact messages.

pettycashstash2•8mo ago
Thanks for the reply. Coca Cola recipe type of Secret sauce? I am now debating implementing sms code verification ( but this comes at cost).
gus_massa•8mo ago
I remember a few pages that sed some stupid captcha like "please write the word orange" or "please calculate 204+109". It was a static value, so it was trivial to program. For not very popular blogs, it was good enough (a long time ago).

Also, other blog has a hidden field, that should be empty, but bots like filling all fields.

I'd try those stupid tricks, and if they fail I'd try to put Spambayes as a filter. It was nice because it has good/bad/unusual, and you may like to take a look at unusual stuff to detect false positives. (I'm not sure if there is a better alternative to Spambayes. I used it like 20 years ago.)

pettycashstash2•8mo ago
Thanks for the suggestions! About simple custom captchas, they are easily bypassed but effective enough for smaller sites. I've got the honeypot field running now and am monitoring how well it catches bots. The email verification should be the strongest barrier of the bunch. Between those two plus the basic captcha, hopefully that covers most automated spam without being too annoying for real users. Curious to see the results over the next week or two.
sds357•8mo ago
I eliminated virtually all spam submissions on my site by using hidden fields and checking for common browser automation flags. I didn't want to use intrusive captchas if I didn't have to.
pettycashstash2•8mo ago
I am aware of hidden fields and have implemented them. Can you elaborate on browser automation flags? Very much appreciated.
sds357•8mo ago
https://developer.mozilla.org/en-US/docs/Web/API/Navigator/w...

If true, block