Live data from Hacker News

What a Hacker Stole from Me

mynoise.net

101–110 of 134 posts

Re: What a Hacker Stole from Me

#101
post #80

Feel for the guy. I had a couple of long owned domains stolen recently. They were so low value to anyone but me though, it makes me wonder why someone would bother.

Newly registered domains don't get the same recognition in search engines as older ones. That's why there's a market for stolen domains, the same is true for social media accounts

True enough. I had been pretty well established in my little niche too.

Re: What a Hacker Stole from Me

#102

You probably need to calm down a bit. Everyone who has any kind of service on the open internet sees this stuff in their logs all the time. Most of it is entirely automated. That's just how the internet works.

It being common doesn't mean it's OK, it also doesn't mean people aren't allowed to be upset by it. Casual racism and bigotry are common, "You probably need to calm down a bit" is dismissive and condescending.

It being common doesn't make it OK, but it does make it not a personal attack.

Exploit scanners are common, they are not someone attacking you personally.

I'd be surprised if the mass download and the exploit scanner were even related. Much more likely they weren't and somebody just messed up some bot they were building and fetched everything in a loop.

It's annoying, yes, but it's not personal. Nobody is attacking him personally. Feeding into that understanding of the situation isn't helpful, just like you shouldn't encourage people who believe they are the victims of gang stalking because they've seen 5 red cars this morning.

Re: What a Hacker Stole from Me

#103
post #55
post #18

Earlier quoted context omitted.

> Lovely, but naive. it’s unbelievable to me that anyone would do this to him. are you familiar with what he’s done? the amount of work he’s put into helping people? you should dig a little bit more into the story before badmouthing someone.

I love the guy, I love mynoise, but he needs to chill out. Nobody "did this to him". This is almost certainly, like 99.99% certainly, just normal internet noise and he's just never noticed before. All sites get this sort of thing.

That doesn't make it ok or less impactful. He's been running MyNoise for years and it sounds like if he had been attacked before, this one was much worse, prompting a blog post about it.

Re: What a Hacker Stole from Me

#104
post #79
post #77

Earlier quoted context omitted.

Nobody needs to rely on Cloudflare when they can use server-side solutions like Fail2ban (already mentioned). Other tools like iptables exist for more granular control over incoming traffic. There is no one-size-fits-all solution, so just pick the tool(s) that work for your situation. If your situation is so unique that no existing tool will work, you likely have the resources to write your own.

It costs a lot of time and energy, especially for a music artist, for a website that has no private data and that is not sensitive. Cloudflare has specialized people who watch 24/7 and they provide free bandwidth, all of that for 0 USD

I'm not arguing against using Cloudflare. I was responding to the assertion that we "need to collectively rely on Cloudflare" by pointing out that other options exist.

Re: What a Hacker Stole from Me

#105
post #66

Earlier quoted context omitted.

Needs to put Cloudflare (free plan) in front of the website and the problem is fixed

Maybe I’m just a curmudgeonly old fart but I’m so tired of everyone pretending like the entire internet being MiTM’d by Cloudflare is somehow a good thing. FWIF if you are looking for a decent alternative take a look at ModSecurity project by OWASP.

One good sign that your viewpoint may not be well thought through is if you find yourself claiming that any contrary opinions could only be pretense.

Re: What a Hacker Stole from Me

#106

Pentester/bug bounty hunter here. I appreciate that this is frustrating for the owner to experience, but this reads like normal internet noise to me, or at worst someone fired up burp suite and hit go on a website. Many, many commercial tools run these sorts of attacks en masse by default, some SaaS companies even do it as a product. The entire internet is being scanned constantly and many of those scanners have auto…

If a shark attacks you, it isn't personal, but it is traumatic. Also, sharks weren't made by ethically-questionable hackers. I don't see why you need to dismiss this person's legitimate trauma, seems awfully boorish of you to do so.

I read it as the opposite, trying to help them process it as not something deeply malicious targeting them. I'm thankful of the times I took something deeply, then realized it was something else and had a change of heart. This is ultimately what trauma and processing is about: something blindsided you and your initial response is a large field of shock and avoidance, then slowly you process it until you have a practical approach to deal with the thing next time, so it doesn't blindside you again.

Re: What a Hacker Stole from Me

#107

You probably need to calm down a bit. Everyone who has any kind of service on the open internet sees this stuff in their logs all the time. Most of it is entirely automated. That's just how the internet works.

Their website has been around for along time though, so they're probably very used to those automated requests. Even all the scrapers nowadays won't take up too much bandwidth so it's probably something dedicated.

Re: What a Hacker Stole from Me

#108

Earlier quoted context omitted.

If a shark attacks you, it isn't personal, but it is traumatic. Also, sharks weren't made by ethically-questionable hackers. I don't see why you need to dismiss this person's legitimate trauma, seems awfully boorish of you to do so.

> Also, sharks weren't made by ethically-questionable hackers. You don't know that.

I cannot argue with that.

Re: What a Hacker Stole from Me

#109

Earlier quoted context omitted.

If a shark attacks you, it isn't personal, but it is traumatic. Also, sharks weren't made by ethically-questionable hackers. I don't see why you need to dismiss this person's legitimate trauma, seems awfully boorish of you to do so.

I read it as the opposite, trying to help them process it as not something deeply malicious targeting them. I'm thankful of the times I took something deeply, then realized it was something else and had a change of heart. This is ultimately what trauma and processing is about: something blindsided you and your initial response is a large field of shock and avoidance, then slowly you process it until you have a practi…

That's a really good point. Now that you explain it, its not boorish but insightful. Thanks.

Re: What a Hacker Stole from Me

#110
post #66
post #50

1. Don't take it personally. They don't know or care who you are. 2. Some kind of rate limiter is becoming essential for servers. Scanning/probing is worse than rude but there's plenty of obnoxious out there. Fail2ban can easily be configured to handle simple login or vulnerability scans. If there's not something similar for web servers, it wouldn't be hard to write one. Anyone know of fail2ban or rate-limiters for w…

Needs to put Cloudflare (free plan) in front of the website and the problem is fixed

myNoise uses Cloudflare.

> myNoise is now running on a Virtual Private Server (VPS) hosted at One, with audio assets served via a CDN through Cloudflare ...

Post reply on HN