frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Badak178.blog

https://blog.cloudflare.com/welcome-to-connectivity-cloud/
1•cristiannasar•1m ago•0 comments

How OCD came to haunt American life

https://harpers.org/archive/2025/07/shadow-of-a-doubt-ocd-andrew-kay/
1•pseudolus•2m ago•0 comments

CudaText – Cross-platform code editor written in Object Pascal

https://cudatext.github.io/
1•andsoitis•4m ago•0 comments

MCP is eating the world–and it's here to stay

https://www.stainless.com/blog/mcp-is-eating-the-world--and-its-here-to-stay
1•emschwartz•4m ago•0 comments

The Great Indian Family Offices Fatigue

https://www.dealflowiq.com/p/the-great-indian-family-offices-fatigue
1•koolhead17•6m ago•0 comments

Show HN: Calcy.net – A Vibe Coded Calculator Site

https://www.calcy.net/
1•alexlarch•9m ago•1 comments

Men, Where Have You Gone? Please Come Back

https://www.nytimes.com/2025/06/20/style/modern-love-men-where-have-you-gone-please-come-back.html
2•prmph•13m ago•0 comments

Pope Leo XIV on AI, ethics, and corporate governance

https://www.vatican.va/content/leo-xiv/en/messages/pont-messages/2025/documents/20250617-messaggio-ia.html
1•michaelsbradley•14m ago•0 comments

Developers are using AI Wrong

https://nmn.gl/blog/ai-amnesia
2•namanyayg•15m ago•0 comments

Introducing the Ultra Plan

https://www.cursor.com/en/blog/new-tier
1•sh_tomer•15m ago•0 comments

Research: The Transformative Power of Sabbaticals

https://hbr.org/2023/02/research-the-transformative-power-of-sabbaticals
1•bilsbie•15m ago•0 comments

•16m ago

WQ42: Grounding LLMs in Wikidata Facts via Tool Calling

https://thottingal.in/blog/2025/06/21/wq42-llm-wikidata/
1•sthottingal•19m ago•0 comments

Language Workbenches: The Killer-App for Domain Specific Languages? (2005)

https://martinfowler.com/articles/languageWorkbench.html
1•Jtsummers•20m ago•0 comments

Buy It Now, Track Me Later: Attacking User Privacy via Wi-Fi AP Online Auctions

https://arxiv.org/abs/2506.13052
1•walterbell•20m ago•0 comments

Notepad Calculator

https://notepadcalculator.com/
2•gsky•20m ago•0 comments

Smallest Self-Powered Bipedal Robot Sets New Speed Record

https://scitechdaily.com/worlds-smallest-self-powered-bipedal-robot-sets-new-speed-record/
1•Brajeshwar•24m ago•0 comments

MIT's Window-Sized Device Pulls Drinking Water from Thin Air, Even in the Desert

https://scitechdaily.com/mits-window-sized-device-pulls-drinking-water-from-thin-air-even-in-the-desert/
3•Brajeshwar•24m ago•0 comments

Earth's Largest Camera Takes 3B-Pixel Images of the Night Sky

https://www.nytimes.com/interactive/2025/06/19/science/rubin-observatory-camera.html
1•Brajeshwar•24m ago•0 comments

The Future of Stalwart: Webmail, Roadmap, and Beyond

https://old.reddit.com/r/stalwartlabs/comments/1lgaccb/the_future_of_stalwart_webmail_roadmap_and_beyond/
2•thunderbong•24m ago•0 comments

Show HN: LinkMage – Instantly analyze any URL with AI

https://link-mage.vercel.app/
1•SumitkAg•27m ago•0 comments

Case of Hype-Cycle-Itis

https://usealttab.substack.com/p/case-of-hype-cycle-itis
2•willstenzel•28m ago•0 comments

Tell HN: Beware confidentiality agreements that act as lifetime non competes

4•throwarayes•32m ago•2 comments

Writing with AI: The Power of the Smarmy First Draft

https://brevity.wordpress.com/2025/06/19/writing-with-ai/
1•dctoedt•33m ago•0 comments

Telecoms Tell Employees to Stop Looking for Evidence of Salt Typhoon Intrusion

https://www.techdirt.com/2025/06/20/salt-typhoon-hack-keeps-getting-worse-telecoms-tell-employees-to-stop-looking-for-evidence-of-intrusion/
2•hn_acker•33m ago•1 comments

AI-assisted coding for teams that can't get away with vibes

https://blog.nilenso.com/blog/2025/05/29/ai-assisted-coding/
1•codingmoh•34m ago•0 comments

Glass bottles found to contain more microplastics than plastic bottles

https://phys.org/news/2025-06-glass-bottles-microplastics-plastic.html
1•bilsbie•34m ago•1 comments

Ask HN: What is your recommendation for a wireless keyboard and mouse?

1•kirtyv•34m ago•1 comments

Alibaba Staffer's Resignation Letter

https://www.techinasia.com/news/read-alibaba-staffers-resignation-letter-got-jack-mas-reply
1•calebchiam•35m ago•1 comments

How to Become a Backyard Naturalist with Just Your Smartphone

https://gizmodo.com/how-to-become-a-backyard-naturalist-with-just-your-smartphone-2000615730
1•rntn•35m ago•0 comments
Open in hackernews

Record DDoS pummels site with once-unimaginable 7.3Tbps of junk traffic

https://arstechnica.com/security/2025/06/record-ddos-pummels-site-with-once-unimaginable-7-3tbps-of-junk-traffic/
45•Brajeshwar•3h ago

Comments

smokel•2h ago
> A total of 34,500 ports were targeted, indicating the thoroughness and well-engineered nature of the attack.

How is that more complicated than a for-loop?

ukuina•2h ago
Because it's a distributed for loop?
lolinder•48m ago
Not necessarily. It could be one for loop running on tens of thousands of compromised IoT devices, with the only thing distributed being the command that starts the loops.
blitq•2h ago
It’s not :)
monster_truck•1h ago
You can't just spray every port blindly if you are maximally trying to disrupt, there is nuance to it.
lolinder•51m ago
Right. So why does the fact that they targeted 34,500 ports show it was a well-engineered attack? By itself it's just evidence that they know how to iterate over ports. Coupled with the data size (7.3Tbps) we know they had an enormous botnet. None of this points to a well-engineered attack, it just means that lousy IoT has made botnets incredibly cheap.

A well-engineered attack would not draw headlines for its scale because it would take down its target without breaking any records.

motorest•34m ago
> A well-engineered attack would not draw headlines for its scale because it would take down its target without breaking any records.

You don't hear much about DDoS that are either comparable in size or bring down targets. How do you explain why this one made the news in spite of not having met your arbitrary and personal bar?

lolinder•26m ago
Like I said: it broke records for data throughput. It doesn't hurt that Cloudflare has an interest in publicizing the size of the DDoS attacks it fights off.

> in spite of not having met your arbitrary and personal bar?

I'm not sure what you mean by this. I didn't establish any sort of bar for what sorts of DDoS should get headlines, I'm just agreeing with OP that that line in the article doesn't make any sense. There may be other reasons to believe this attack was well-engineered but the article doesn't get into them.

rob_c•12m ago
> How do you explain why this one made the news in spite of not having met your arbitrary and personal bar?

It's that a serious question or bait?

Either way, are you so broken as to not understand what was just typed?

balanc•2h ago
Doesn’t Cloudflare have every incentive to inflate the bandwidth of the attack they have successfully mitigated?

And yes I know that there are Cloudflare employees here so spare me with your pinky swears.

x2tyfi•2h ago
Couldn’t this logic apply to basically every internal metric across every company?
udev4096•2h ago
Clownflare is more incentivized to make it look like they are the only ones who can defend against such an attack so they could gather more users for backdooring the majority of internet traffic. I wonder if it would be possible to create a peer-to-peer and decentralized DDoS mitigation service for anyone. All you gotta do is donate some of your bandwidth
eviks•2h ago
How does it counter the incentives of all other companies to make it look like they're not the only one???
mlyle•1h ago
Cloudflare has the biggest scale and is arguably best positioned to soak up massive attacks. Therefore CF may have a unique incentive to make it sound like attacks are larger and there are more really big ones.
eviks•1h ago
> is arguably best positioned

Lying about the scale of thwarted attacks by others is the counter argument

perching_aix•13m ago
Speaking of incentives, what might be the incentives of those referring to them as Clownflare? I sure have to wonder what their biases are, and how fairly they represent the company.
move-on-by•1h ago
A couple months ago Brain Krebs, who uses Google’s Project Shield, wrote of a very similar attack. 6.3 terabits, all UDP, less then a minute.

https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with...

ksec•2h ago
If I dont want my user to have Cloudflare captcha or for example captcha dont work on my Safari 18.5 running on OpenCore Patcher MacBook 2015. What other options have I got?
nemathod•2h ago
GRE-Tunnel
VladVladikoff•2h ago
I’m confused what this would accomplish? Do GRE tunnels drop UDP packets or something?
firebird84•1h ago
You make a contract with a company that does layer 3 ddos protection, you advertise a route including their AS on a subset of your prefixes and they route to you over a GRE tunnel.
VladVladikoff•2h ago
Most websites don’t need DDOS protection. Many websites which use Cloudflare to block basic bot vulnerability scanning. You could block this type of traffic with other methods; ja3/ja4, Ip to ASN & ASN filtering, etc.
esseph•28m ago
Your first line is wrong.

While it may not impact your site, it does impact your hosting provider. As their costs go up, your costs go up. Anything on the Internet at this point needs DDoS / scraping protection. If may not drop your service, but your ISP or upstreams may blackhole your route.

The "old web" (current web) was largely based on an open exchange of information.

The "new web", post AI bot scraping, is taking its place. Websites are getting paywalls. Advertising revenue is plummeting. Hosting providers are getting decimated by the massive shift in bandwidth demand and impact to systems scraped by the bots.

zzzeek•1h ago
dont piss off any nation-states that would want to take your site down, should help
petee•51m ago
Fwiw, i have a site with nearly zero content or users; randomly it got ddos'd one day, and never happened again. I think the reasons for a ddos can be wide ranging, from just testing, to nation state, to someone is unhappy with your font choice
inetknght•36m ago
> to someone is unhappy with your font choice

Everyone hates when I set my app's fonts to courier size 8.

datameta•5m ago
Everyone is wrong or they're fans of courier new specifically
esseph•25m ago
An 11 year old with a discord account and a stolen credit card can now rent massive capabilities that can take (smaller, limited peered) entire countries offline for brief periods these days.