frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Ask HN: Do You Block DigitalOcean?

4•sugarpimpdorsey•5h ago
I have at least half their subnets blacklisted at this point. They seem to host a lot of bot traffic, port scans, and other generally unsavoury characters.

Is this the wrong approach? A losing battle of whack-a-mole?

FWIW I get a not-insignificant amount of malicious traffic from AWS, Azure, and Google but I view these providers as "too big to block" - I can't blacklist large swaths of their IP space without breaking the Internet.

Comments

ecb_penguin•5h ago
Depending on your app, yes, you can block DO. You can probably block all of AWS and GCP as well. You can take it further and block all non-residential ASNs.

You'll block some legit traffic, but the majority of normal users will not be affected.

What is the persona of your average user? Average people shopping online? None of them are connecting through weird ASNs.

Someone complaining about a VPN being blocked? It's cost-benefit, tell them tough shit.

darklake•5h ago
I've self hosted my email on DO for over 10 years on the same IP address. I am registered with Gmail so they don't block. I sometimes get blocked by major sites from whom I receive spam. I am not a fan of group punishment which is what you advocate.
mmarian•4h ago
IP blocking is a losing battle. Malicious actors can easily hop onto residential proxies.

Why do you care about that traffic? What exploits are you worried about? The answers will help you figure out what protection you'll need to set up.

fennec-posix•4h ago
The Internet is always gonna have undesirable traffic if you're facing it. The trick is to minimize your surfaces as much as possible:

- Only keep open ports/forward ports for applications you use, drop/block everything else.

- Use strict host-header checking for web services on port 80/443, drop anything to 403/404 that doesn't have a valid host-header for the website(s) you're hosting.

- Move SSH and other remote admin servers to use a non-standard port. (legit, find a random port number between 9000-65535)

- If it doesn't need to be public, allow-list it with iptables.

Unfortunately DO and other providers will never have 100% legit traffic, it's just the nature of the Internet's noise floor.

Hope this helps you or someone else!

toomuchtodo•4h ago
We block all cloud CIDRs at a financial services firm for public customer facing infra.

Altman warns there's no legal confidentiality when using ChatGPT as a therapist

https://techcrunch.com/2025/07/25/sam-altman-warns-theres-no-legal-confidentiality-when-using-chatgpt-as-a-therapist/
1•taubek•1m ago•0 comments

You won't believe what this AI said after deleting a database

https://smallcultfollowing.com/babysteps/blog/2025/07/24/collaborative-ai-prompting/
1•weinzierl•1m ago•0 comments

Jump the Shark

https://brajeshwar.com/2025/jump-the-shark/
1•furkansahin•2m ago•0 comments

Show HN: Memory Bank Templates – Cure AI Context Reset Problems

https://medium.com/lifefunk/curing-ai-amnesia-memory-banks-and-spec-driven-development-for-reset-proof-engineering-1b8e297ae2a4
1•rstlix0x0•4m ago•0 comments

DoHoT: Making practical use of DNS over HTTPS over Tor

https://github.com/alecmuffett/dohot
1•DyslexicAtheist•5m ago•0 comments

Bringing Together Clazy and Clang-Tidy

https://alex1701c.github.io/2025/07/27/clazy-clangtidy.html
2•todsacerdoti•7m ago•0 comments

Rust Changelog #296

https://rust-analyzer.github.io//thisweek/2025/07/28/changelog-296.html
1•amalinovic•12m ago•0 comments

AI intensifies battle for talent, housing and investments in San Francisco

https://www.washingtonpost.com/business/2025/07/26/ai-boom-san-francisco-tech-workers-housing/
2•JamesAdir•13m ago•0 comments

Just released my open-source project: Log Manager

https://github.com/bodyast/logManager
1•bodyast1010•14m ago•0 comments

Starling reproduces spectrogram drawing [video]

https://www.youtube.com/watch?v=hCQCP-5g5bo
1•Luc•15m ago•1 comments

Show HN: AllEars – Automate Your Phone Based on Sounds (Offline, No Cloud)

https://play.google.com/store/apps/details?id=com.cliqueraft.allears&hl=en_US
2•sanjeev309•22m ago•0 comments

The Wireless Cookbook (Early Access)

https://nostarch.com/wireless-cookbook
2•goldfish5878•24m ago•0 comments

Hello Sprout

https://daniel.haxx.se/blog/2025/07/28/hello-sprout/
5•robin_reala•24m ago•1 comments

EU age verification app to ban any Android system not licensed by Google

https://old.reddit.com/r/degoogle/comments/1mau7yl/eu_age_verification_app_to_ban_any_android_system/
1•todsacerdoti•31m ago•0 comments

Britain 'ready to fight' over Taiwan, Defence Secretary suggests

https://www.telegraph.co.uk/world-news/2025/07/27/britain-ready-to-fight-over-taiwan-china-john-healey/
2•mhga•32m ago•2 comments

How to Make Websites That Will Require Lots of Your Time and Energy

https://blog.jim-nielsen.com/2025/how-to-make-websites-that-require-lots-of-time-and-energy/
2•OuterVale•33m ago•0 comments

Control Shift: New Reality Labs Research on SEMG Published in 'Nature'

https://www.meta.com/en-gb/blog/reality-labs-surface-emg-research-nature-publication-ar-glasses-orion/
1•ndsipa_pomu•33m ago•0 comments

Working with AI: Measuring the Occupational Implications of Generative AI

https://arxiv.org/abs/2507.07935
1•eric_khun•33m ago•0 comments

Can You Trust Your Computer?

https://www.gnu.org/philosophy/can-you-trust.en.html
2•jruohonen•33m ago•2 comments

A VPN is seeing a 1,400% spike in signups as the UK's age verification law

https://mashable.com/article/proton-vpn-uk-age-verification-signups
2•benkan•35m ago•0 comments

Ask HN: Lessons from migrating off Dynamics NAV (write‑up inside)

1•edihasaj•35m ago•0 comments

Scientists look to black holes to know where we are in the Universe

https://www.space.com/astronomy/scientists-look-to-black-holes-to-know-exactly-where-we-are-in-the-universe-but-phones-and-wifi-are-blocking-the-view
1•benkan•36m ago•0 comments

Google rolls out new Gemini model that can run on robots locally

https://techcrunch.com/2025/06/24/google-rolls-out-new-gemini-model-that-can-run-on-robots-locally/
2•benkan•39m ago•0 comments

The ultimate meeting culture

https://abitmighty.com/posts/the-ultimate-meeting-culture
11•todsacerdoti•47m ago•2 comments

Show HN: AI Equalizer – Personality sliders for building a better AI friend

2•FicPeter•49m ago•1 comments

Ever had to implement SAML SSO in PHP?

https://ssojet.com/blog/mastering-saml-implementation-in-php
1•sophiabannet1•55m ago•1 comments

American musical satirist Tom Lehrer dies at 97

https://www.bbc.com/news/articles/cpv02yd2714o
1•chha•55m ago•0 comments

OpenPsion

https://linux-7110.sourceforge.net/
1•austinallegro•57m ago•0 comments

American Airlines Boeing 737 MAX Evacuated at DEN After Landing Gear Collapses

https://simpleflying.com/american-airlines-737-max-evacuated-denver-landing-gear/
1•pera•58m ago•0 comments

Can zebrafish help humans regrow hearing cells?

https://www.npr.org/2025/07/21/nx-s1-5472445/safer-beauty-bill-package-remove-toxic-chemicals-cosmestics
1•I_Nidhi•1h ago•1 comments