Live data from Hacker News

Viewing profile — djkurlander

djkurlander

HN member
Joined
Sat, Feb 14, 2026, 4:25 PM UTC
HN karma
165
Public activity
49 items

About djkurlander

No profile information was provided.

Recent public activity

  1. comment
    Comment #49197567

    Crafted that awesome response to your original query myself, and I am very human.

  2. comment
    Comment #49197334

    Good question. You can certainly proxy SIP. But what’s notable here is that the traffic comes directly from organizations that should be secure: banks, infrastructure, governments.…

  3. comment
    Comment #49185095

    Much appreciated! Trying to help out the community with the honeypot & API, and it's always fascinating what attack patterns show up.

  4. comment
    Comment #49184797

    As mentioned above, wrote the blog post myself and had AI proofread and edit. As for the honeypot itself, I'm a greybeard computer scientist, and I architected the system very deli…

  5. comment
    Comment #49184659

    Wrote the blog post myself, and used AI to clear up typos and occasionally improve wording. I have a PhD in computer science, but I was initially planning to pursue journalism inst…

  6. comment
    Comment #49184612

    Ha! Love it. Totally believe in it too.

  7. comment
    Comment #49184590

    I set up servers on the net that masquerade as a SIP relay by essentially supporting the protocol but with few authentication protections. Malware bots scan the IPv4 space looking …

  8. comment
    Comment #49184510

    The actual blog post clarifies this as well. But still in some sense these organizations share some level of responsibility if it is their machines, attacking from their ASN.

  9. comment
    Comment #49184473

    Yes - I would have expected better from these institutions as well, but there's always going to be someone who brings their rogue laptop onto the corporate net. The key is how fast…

  10. comment
    Comment #49184380

    Thanks! Just trying to keep the world safe from marauding Teddy Bears.

  11. comment
    Comment #49183965

    [flagged]

  12. story
  13. comment
    Comment #48161898

    OP here. See the hidden world of bot attacks and scanner chatter. Listen to Internet Background Radiation on a virtual Geiger counter. Here we are capturing Internet chatter across…

  14. story
  15. comment
    Comment #47911349

    The goal is to educate people (originally my kids) about one particular aspect of cybersecurity. I love it when people use the site for this purpose. Yep, with ~80 knocks coming in…

  16. comment
    Comment #47911135

    OP here. Check out the new https://knock-knock.net . v1 got 40,000+ visits from HN alone, hoping you'll find v2 worth checking out too. Watch bots trying to break into my honeypots…

  17. story
  18. comment
    Comment #47044650

    Thanks. I'd like to better understand the origin of DO's bot activity, and look forward to your report!

  19. comment
    Comment #47037916

    It has been 24 hours since this post went up, so here are some fun stats. During this time, there were 13,024 knocks on the server from 368 unique IPs. That's ~35 knocks per bot. D…

  20. comment
    Comment #47036251

    Ah, that makes sense. I’ve been wondering why DigitalOcean has so much of the bot traffic.

  21. comment
    Comment #47036195

    Hadn’t considered it, but that’s a nice idea. All of the necessary info, with time stamps, is already recorded in a SQL database, so it wouldn’t be difficult to replay events.

  22. comment
    Comment #47036145

    Thanks for pointing that out. T-Pot is cool and a more general honeypot framework. Potentially I could have built knock-knock.net on top of T-Pot.

  23. comment
    Comment #47036064

    Fail2ban would cut down on the noise quite a bit. I’ve installed it on other servers and have recommended it to others. But then we wouldn’t have all of this beautiful bot traffic …

  24. comment
    Comment #47036020

    Though strong passwords or preferably ssh keys are important, there will always be servers with weak passwords. And DO doesn’t have to side with individual abuse reporters. If they…

  25. comment
    Comment #47035896

    No, knock-knock.net is not hosted on DigitalOcean, and all 4 of my other knock-knock servers, using different providers, and distributed geographically currently have DigitalOcean …