frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Bulletproof host Stark Industries evades EU sanctions

https://krebsonsecurity.com/2025/09/bulletproof-host-stark-industries-evades-eu-sanctions/
78•todsacerdoti•2h ago

Comments

trhway•1h ago
Sanctions?! What sanctions? They don't even hide, right in the heart of Western Europe:

https://www.swedbank-aktiellt.se/telegram/WOzsdcJG

"AMSTERDAM, April 10, 2025

MIRhosting, a leading provider of enterprise-grade colocation and IT infrastructure services in Europe, proudly announces the launch of two dedicated, fully equipped data rooms at its newest location within the NorthC data center in Nieuwegein. This strategic expansion strengthens MIRhosting's colocation capabilities, directly addressing the growing demand for reliable and scalable colocation solutions in the greater Amsterdam region...."

hrdwdmrbl•1h ago
Sometimes it feels like the internet is still the wild west.

The EU tries to rope off a single building with velvet ropes, a doorman, ID verification, facial scans, and cookie banners, while next door it's an illegal rave in an abandoned supermarket.

devjab•35m ago
I think blaming the EU for cookie banners is wrong. Those banners are malicious disobedience, and, for the most part a legal violation. What websites should do is that they should assume you reject any tracking as their default, and then they can offer a site setting that you have to seek out, where you can agree to be tracked. What they are sort of allowed to do, is that they can prompt you with a banner, but it has to be a single no-click without requiring you to read much, but that is still not compliance. Anything more annoying is a legal violation.

The real issue is that there aren't a whole lot of consequences when it comes to tracking data. It's a legal violation, sure, but it's not a criminal violation. So it would be up to you to pursue it. In many countries you can't even file a civil lawsuit, but rather, you have to go through your national data protection agency. Which in reality likely means your complaint will be auto-rejected after five years because they need to clean up the queue.

As far as the malicious disobedience goes... well... it's probably because "all the other website do it", but you might as well just give people the option to go to a setting to turn it off. It's not like that would be any less of a legal violation than the banner.

erulabs•7m ago
If the majority of users use the system wrong, it's the system that's wrong, not the users.
iammrpayments•1h ago
It’s a little bit Ironic that they use the name of an American super hero
DFHippie•36m ago
That Elon Musk fancies himself to be. Well, that's less ironic.
dabeeeenster•1h ago
WTH is a “bulletproof host”? Been working in the industry for 30 years and never once heard it?
gnabgib•57m ago
Ars covered it in 2013, it's common in security (Risky Business, OSInt, Krebs) https://arstechnica.com/information-technology/2013/01/how-t...
nickstinemates•57m ago
It says so in the article. Isp's who ignore authorities and allow anything to happen on their networks.
david_shaw•56m ago
> WTH is a “bulletproof host”?

A "bulletproof" host or provider is the colloquial term for a business that will not reveal your identity, payment information, provide LEO access, respond to subpoenas, etc.

It's generally used by cyber-criminals as a "safe" vendor, though some privacy-minded individuals like this type of provider as well.

cptnapalm•54m ago
My mind first jump to an old video of somebody shooting a Sun Microsystems machine and the bullets did not in fact penetrate the steel.
dabeeeenster•52m ago
Thanks for the replies. Should have RTFA I guess
pessimizer•58m ago
As far as the crimes here, I see "facilitating Russian communications" and "spreading Russian narratives."

Is there anything technical about this, or is this just more censorship of Russians disguised as a hacking report?

edit: I mean, just read the list https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202...

-----

typical examples:

> RED has used its media platforms – often publishing under “redstreamnet” or “thered.stream” – to systematically spread false information on politically controversial subjects with the intent of creating ethnic, political and religious discord amongst its predominantly German target audience, including by disseminating the narratives of radical Islamic terrorist groups such as Hamas.

> During the violent occupation of a German university by anti-Israel rioters, Red personnel coordinated with the occupiers to disseminate their vandalism – which included the use of Hamas symbols – through RED’s online channels, thus providing them with an exclusive media platform.

or

> Thomas Röper is a German blogger. Through his network of online channels named “Anti-Spiegel”, he systematically disseminates misinformation about Russia’s war of aggression against Ukraine and delegitimises the Ukrainian government, especially with a view to manipulating German public sentiment regarding support to Ukraine.

or

> In particular, Voloshin has promoted Medvedchuk’s “peace plan” for Ukraine, which is linked to the Russian narrative regarding Russia’s war of aggression. In order to win-over European elected representatives to his cause, he has organised conferences with French and German parliamentarians, arguing that the “Normandy format” (France, Germany, Ukraine, Russia) has a so-called parliamentary dimension outside any official framework. The most recent event was organised by Voloshin at the French Senate on 11 February 2022 (“Peace process in Ukraine: how to break the deadlock”), a few days before the invasion of Ukraine by the Russian army.

or

> Artem Marchevskyi has played an instrumental role in disseminating concerted disinformation and biased narratives aimed at supporting the foreign policy interests of the Russian Federation and spreading its influence, including ahead of the 2024 European Parliament elections, by undermining the credibility and public image of Ukraine and its efforts to defend itself against Russia’s war of aggression.

This is all trash. This post would be enough to get me on the sanctions list, and refusing to delete this post would get the site on the sanctions list. Good luck invading Russia again, Europe, you're going to need it.

galaxy_gas•52m ago
Ignoring the narrative portion , I routinely block the PQ IP spaces which change frequently in my services. They are mass brute force and exploit attempt-abuse report is ignored, spam/exploit scan, botnet CNC

They are also UpStream of several other provider. For example https://bgp.he.net/AS215540#_prefixes

I have not seen legitimate single request from ANY ip in this. Only spam bot and brute.

dafelst•51m ago
From TFA

> Materializing just two weeks before Russia invaded Ukraine in 2022, Stark Industries Solutions became a frequent source of massive DDoS attacks, Russian-language proxy and VPN services, malware tied to Russia-backed hacking groups, and fake news.

preisschild•48m ago
This is not "censorship". These are Russian state-sponsored influence operations against countries it might want to invade (hybrid warfare)
Nihilartikel•46m ago
I did a pro bono analysis of a ddos against a dolphin protection non profit, probably a lashing out from a butthurt fishing concern. A significant amount of traffic in that attack originated from the stark asn. Interesting to see them here.
trhway•45m ago
> censorship of Russians

why not censor Russians? They had as of now already censored forever about a million of Ukranians and have shown all the intentions to do it more and more.

And Russia doesn't allow foreign propaganda inside Russia (it is a felony there), so it is absolutely normal to block Russian propaganda inside the foreign countries (and notice that nobody spreading Russian propaganda are put in jail for that in foreign countries though that would be only fair) .

yieldcrv•6m ago
this is more common and easier than people think, and I think this conflict was necessary to exposure the hubris behind global superpowers

they think they're omnipotent but really don't control the world, rendering economic sanctions and service blacklisting to be null and moot

Native ACME support comes to Nginx

https://letsencrypt.org/2025/09/11/native-acme-for-nginx
143•Velocifyer•2h ago•62 comments

Top model scores may be skewed by Git history leaks in SWE-bench

https://github.com/SWE-bench/SWE-bench/issues/465
90•mustaphah•1h ago•17 comments

Bulletproof host Stark Industries evades EU sanctions

https://krebsonsecurity.com/2025/09/bulletproof-host-stark-industries-evades-eu-sanctions/
80•todsacerdoti•2h ago•19 comments

NT OS Kernel Information Disclosure Vulnerability

https://www.crowdfense.com/nt-os-kernel-information-disclosure-vulnerability-cve-2025-53136/
70•voidsec•3h ago•13 comments

Claude's Memory Architecture Is the Polar Opposite of ChatGPT's

https://www.shloked.com/writing/claude-memory
15•shloked•49m ago•2 comments

Launch HN: Ghostship (YC S25) – AI agents that find bugs in your web app

10•jessechoe10•38m ago•2 comments

Behind the scenes of Bun Install

https://bun.com/blog/behind-the-scenes-of-bun-install
268•Bogdanp•7h ago•81 comments

'Robber bees' invade apiarist's shop in attempted honey heist

https://www.cbc.ca/news/canada/british-columbia/robber-bees-terrace-bc-apiary-1.7627532
50•lemonberry•2h ago•20 comments

Adam (YC W25) Is Hiring to Build the Future of CAD

https://www.ycombinator.com/companies/adam/jobs/q6td4uk-founding-engineer
1•HetengAaronLi•1h ago

GrapheneOS and Forensic Extraction of Data (2024)

https://discuss.grapheneos.org/d/13107-grapheneos-and-forensic-extraction-of-data
264•SoKamil•6h ago•134 comments

A tech-law measurement and analysis of event listeners for wiretapping

https://arxiv.org/abs/2508.19825
41•lapcat•2h ago•5 comments

The Helix Text Editor

https://jonathan-frere.com/posts/helix/
46•gidellav•3d ago•10 comments

CRISPR offers new hope for treating diabetes

https://www.wired.com/story/no-more-injections-crispr-offers-new-hope-for-treating-diabetes/
100•manveerc•5h ago•31 comments

Conway's Game of Life, but musical

https://www.hudsong.dev/digital-darwin
116•hudsongr•5h ago•24 comments

Making io_uring pervasive in QEMU [pdf]

https://vmsplice.net/~stefan/stefanha-kvm-forum-2025.pdf
9•ingve•1h ago•0 comments

AirPods live translation blocked for EU users with EU Apple accounts

https://www.macrumors.com/2025/09/11/airpods-live-translation-eu-restricted/
63•thm•7h ago•58 comments

Public Suffix List

https://publicsuffix.org/
30•mooreds•3d ago•4 comments

Show HN: Making a cross-platform game in Go using WebRTC Datachannels

https://pion.ly/blog/making-a-game-with-pion/
16•valorzard•1d ago•0 comments

Spiral

https://spiraldb.com/post/announcing-spiral
204•jorangreef•3h ago•69 comments

An engineering history of the Manhattan Project

https://www.construction-physics.com/p/an-engineering-history-of-the-manhattan
94•rbanffy•6h ago•53 comments

From burner phones to decks of cards: NYC teens adjusting to the smartphone ban

https://gothamist.com/news/from-burner-phones-to-decks-of-cards-nyc-teens-are-adjusting-to-the-sm...
78•geox•6h ago•96 comments

Reshaped is now open source

https://reshaped.so/blog/reshaped-oss
223•michaelmior•10h ago•42 comments

Tumult and Sympathy – The Letters of Oliver Sacks

https://www.commonwealmagazine.org/tumult-and-sympathy
8•andrewl•3d ago•1 comments

Center for the Alignment of AI Alignment Centers

https://alignmentalignment.ai
78•louisbarclay•8h ago•13 comments

Pulling an Inverse Conway Maneuver at Netflix (2023)

https://jivimberg.io/blog/2023/09/04/the-inverse-conway-maneuver/
14•thunderbong•3d ago•2 comments

Beyond package management: How Nix refactored my digital life

https://www.jimmyff.co.uk/blog/beyond-package-management-how-nix-refactored-my-digital-life/
42•jimmyff•3d ago•24 comments

Samsung taking market share from Apple in U.S. as foldable phones gain momentum

https://www.cnbc.com/2025/08/16/samsungs-us-market-share-apple-rivalry-foldable-phones.html
78•mgh2•10h ago•121 comments

Gregg Kellogg has died

https://lists.w3.org/Archives/Public/public-json-ld-wg/2025Sep/0012.html
273•daenney•7h ago•35 comments

Removing yellow stains from fabric with blue light

https://phys.org/news/2025-09-yellow-fabric-blue.html
97•bookofjoe•3d ago•67 comments

GrapheneOS accessed Android security patches but not allowed to publish sources

https://grapheneos.social/@GrapheneOS/115164133992525834
197•uneven9434•12h ago•45 comments