frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Our local GitLab server has been under attack by Anthropic Google OVH and more

https://twitter.com/MaziyarPanahi/status/1988908359378993295
4•WhereIsTheTruth•1h ago

Comments

Bender•1h ago
I saw them try to read some static files I posted here but they were instantly blocked by a combination of nftables and nginx.

    bzcat *mirror*access*bz2 | grep -c " 200 "
    283
    bzcat *mirror*access*bz2 | grep -c " 444 "
    3607
That's what made it past nftables TCP MSS and TCP window rules. The 200's were members of HN. The 444's were bots.

Does Gitlab front-end with Nginx or Haproxy?

blueflow•1h ago
Both - first haproxy, then nginx.
Bender•1h ago
The first thing I would look for is if real users both browsers and API clients are capable of doing HTTP/2.0 and if they default to that. If so that an easy win. Block anything lower than HTTP/2.0 and that will nuke most bots outside of headless Chrome. If any real clients are using HTTP/1.1 then make a separate listener/URL for those and limit access by known good CIDR blocks with a firewall assuming this is a corporate GitLab server. Or block this on HAProxy and give trusted networks a way to reach NGinx directly such as a VPN or firewall rule.

If there are archived access logs that would be a good place to try to figure this out.

In NGinx the block looks like this [1] or change it to a redirect to a static landing page.

If this is not an option then restrict repo access to approved SSH clients.

If this is not an option then put authentication on the repos hit hardest and a page that explains what the user/password is along with an acceptable use policy for using the authentication. If AI are trained to learn the authentication they will be violating the AUP written by your lawyers. Make the AI vendors give you enough money to upgrade your infrastructure to handle their load.

TL;DR find the differences between bot behavior and real people then make rules that will break the bots. There's always a difference. When all else fails block the CIDR blocks of all the known AI networks and play whack-a-mole for anything outside of their networks. Not perfect, nothing is but it will lower the load.

[1] - https://mirror.newsdump.org/nginx/inc.d/40_https2_stuff.conf...

Germany to Ban Huawei from Future 6G Network in Sovereignty Push

https://www.bloomberg.com/news/articles/2025-11-13/germany-to-ban-huawei-from-future-6g-network-i...
1•teleforce•32s ago•0 comments

Russia's first AI-powered robot walked on stage

https://fortune.com/2025/11/13/russia-ai-powered-robot-aidol-faceplants-first-public-demonstratio...
1•alrtd82•2m ago•0 comments

Only half the homes in America have cable TV anymore

https://www.businessinsider.com/cable-tv-household-50-percent-decline-brian-wieser-2025-11
1•jmsflknr•2m ago•0 comments

First Agentic System to Solve a Million-Step Reasoning Problem with Zero Errors

https://arxiv.org/abs/2511.09030
1•jarrattp31•3m ago•1 comments

Single Crystal Graphene: the 2 Dimensional super material for space elevators

https://www.azom.com/article.aspx?ArticleID=16371
1•dreadsword•8m ago•1 comments

Show HN: spymux – Spy on your tmux panes

https://github.com/terror/spymux
2•crap•9m ago•1 comments

Can ChatGPT Beat My Favorite Daily Puzzle Game?

https://www.nicksypteras.com/blog/cbs-benchmark.html
3•nsypteras•10m ago•1 comments

You misunderstand what it means to be poor

https://blog.ctms.me/posts/2025-11-14-being-poor-or-being-broke/
3•speckx•11m ago•0 comments

Moving Back to a Tiling WM – XMonad

https://wssite.vercel.app/blog/moving-back-to-a-tiling-wm-xmonad
1•weirdsmiley•14m ago•0 comments

Invest in Code, Not Companies: Welcome to the AI Token Economy

https://medium.com/@strategymat/the-era-of-ai-tokens-why-stocks-are-dead-and-the-future-doesnt-ca...
1•Mati16•15m ago•0 comments

Show HN: What if MCP agents were JIT compiled to code?

https://github.com/stanford-mast/a1
1•ardmiller•16m ago•0 comments

Coding Agents Can Manage Other Coding Agents

https://theahura.substack.com/p/coding-agents-can-manage-other-coding
2•theahura•18m ago•0 comments

NovaCustom's privacy SHIFTphone (degoogled with hardware kill switches)

https://novacustom.com/privacy-friendly-phone/
1•maltfield•20m ago•0 comments

Narrative Is the Interface

https://99d.substack.com/p/important-narratives-important-companies
1•wslh•22m ago•0 comments

LangChain Memory and Emotional Intelligence....pact-hx...pact-langchain

https://github.com/neurobloomai/pact-ax
1•neurobloom•22m ago•2 comments

Securing Runtime of L2 Base Ethereum Nodes

https://substack.bomfather.dev/p/securing-runtime-of-the-l2-base-ethereum
4•neil_naveen•24m ago•0 comments

UK charging industry could face £100M bill under business rate changes

https://www.theguardian.com/environment/2025/nov/02/uk-charging-industry-could-face-100m-bill-und...
1•PaulHoule•24m ago•0 comments

AI, the Firefox Way

https://blog.mozilla.org/en/firefox/ai-window/
2•doener•27m ago•0 comments

Manganese is Lyme disease's double-edge sword

https://news.northwestern.edu/stories/2025/11/manganese-is-lyme-diseases-double-edge-sword
2•gmays•28m ago•0 comments

Preparing for Launch

https://ifp.org/preparing-for-launch/
1•runningmike•29m ago•0 comments

Luck and Risk

https://theheasman.com/short_stories/luck-and-risk/
2•TheHeasman•31m ago•0 comments

Are Young People Screwed?

https://www.derekthompson.org/p/are-young-people-screwed-by-the-economy
4•momentmaker•35m ago•1 comments

HN homepage with links to comments ordered by most recent first

https://observablehq.com/@simonw/hacker-news-homepage
1•pramodbiligiri•36m ago•0 comments

I got myself a dumb watch

https://monocyte.blog/i-got-myself-a-dumb-watch/
1•speckx•36m ago•0 comments

US Tech Market Treemap

https://caplocus.com/
2•gwintrob•37m ago•0 comments

Google sues to dismantle Chinese phishing platform behind US toll scams

https://www.bleepingcomputer.com/news/security/google-sues-to-dismantle-chinese-phishing-platform...
2•josephcsible•37m ago•1 comments

File Pilot: Major update to Windows file manager alternative

https://filepilot.tech/starlog
1•vjekoslav•39m ago•0 comments

Amazon declares war on 'dodgy Fire Sticks'–even VPNs unable to beat the block

https://www.techradar.com/vpn/vpn-privacy-security/amazon-declares-war-on-dodgy-fire-sticks-not-e...
1•bookofjoe•40m ago•0 comments

FFmpeg Calls Google's AI Bug Reports "CVE Slop"

https://itsfoss.com/news/ffmpeg-google-fiasco/
4•speckx•41m ago•0 comments

Wargaming AI Alignment

https://twitter.com/LoganJeya/status/1989018486266593535
2•JL-Akrasia•41m ago•1 comments