An interesting question is to what extent they're jumping through hoops to appear as distinct, legitimate, real users. Such as:
a) using a proxy from a residential ISP somewhere
b) never putting two or more sock puppets behind the same IP. Or assuming exclusive ipv4 use, not even any two clients from within the same /20 to /18 sized netblocks.
c) a reasonably varied selection of ISPs. Also variation in ISP netblock geolocation (maxmind geoIP database or similar) based on ARIN, RIPE, APNIC etc registration data. Obviously if you're promoting something that's very tech/startup industry oriented it would not be as suspicious if you had a bunch of posters "authentically discussing it" that geolocated to the SF bay area and Seattle.
d) a reasonably varied selection of common user agents. Also intentional variation on operating system and browser fingerprinting variables.
e) intentional training to avoid writing patterns and phrases that might seem similar, when one person is driving ten accounts
f) not doing dumb stuff that gives away your time zone, like if you have a bunch of people in a GMT+4 time zone that post things regularly on a 9-5 daytime work schedule, when they're supposed to be pretending to be ordinary internet users in a USA time zone.
From a black hat network engineering perspective there are a lot of ways that one human driving 30 sock puppets can appear from 30 distinct locations, as if there were 30 real humans with 30 different operating systems/computers/browser user agents and browser fingerprints.
As to what level of analysis tools are run on the server side to detect "low effort" sock puppets, that's another question.
From the point of view of a place where fake accounts/sock puppets post things, obviously an organization like twitter has a lot more staff resources to devote to writing custom analysis and correlation tools. Specifically for the purpose of identifying common patterns in inauthentic accounts.
I presume that dang and the people who run the ycombinator admin interface can see the IP address of every poster next to the post's timestamp, and might notice in a manual fashion if a lot of suspicious posts started showing up all from the same netblocks. But then again maybe not.
If you want to see the tip of an iceberg of one method for running sockpuppets, go google "residential proxies for sale" and start looking through the slickly presented marketing material.
https://www.google.com/search?client=firefox-b-d&q=residenti...