Live data from Hacker News

DrawAFish.com Postmortem

aldenhallak.com

81–90 of 113 posts

Re: DrawAFish.com Postmortem

#82
post #59

Earlier quoted context omitted.

IP based breaks users with CGNAT and people connecting from corporate networks In those cases you'd be denied votes since someone else used them up

The first case would be an issue yes, although this app doesn't exactly strike me as something that an insane amount of people would be connecting to from corporate networks

CGNAT is used in places other than corporate networks.

Re: DrawAFish.com Postmortem

#83
post #73

> You may have heard differently, especially if you saw my doxxing[4b] on the unsavory website. Is it pretty common to get doxxed for getting to the top of HN?

Just scroll to the bottom of this page and look at the idiots bragging about making swastika fishes. HN nurtures this community of mentally ill edgelords that we could very well do without.

At my prior work we had this garage where we could wash our cars. But once the sponge was in the wrong place and the responsible foreman shut the whole thing down. "This is why we can't have nice things" he said.

Just ignore the trolls and wait for the fish mods to ban them.

Re: DrawAFish.com Postmortem

#85
post #29

I read the HN thread first, and the first comment I saw from the author was about AI nazi symbol detector they put in... I wonder how many orders of magnitude that comment increased interest in making offensive fish? Later I saw images of the attacked site posted elsewhere and thought they were both predictable and hilarious.

A better group psychological approach might have been to only name the penis filter, ye. Then the transgressions are on the vandal who can't rationalize it is sticking it to the man, but that he is just that guy drawing swastikas.

Re: DrawAFish.com Postmortem

#87
post #7
post #2

I was one of the “lucky” few to witness the school of slur-fish. Being in security I laughed because of how egregious it was but also because I knew someone on HN with some actual time on their hands to help properly would be along soon. I also appreciate this post mortem. Vibe-coded anything in prod is a lot of my work load in IR these days but it was nice to see such a low stakes project properly documented.

People will be quick to jump on the "it was vibe coding's fault" but at least two of the issues are pretty common even in designed systems without AI - leaving in a "test admin" access and verifying tokens but not cross-checking them.

I thought checking a token against the cert is actually called verifying or is noawadys verifying just if it looks like a token it maybe a valid token?

Re: DrawAFish.com Postmortem

#88
I love the fact that you did a post mortem on a vibe-coded website

Honestly - i think often so many people take tech very seriously so seeing this is quite refreshing and genuinely interesting from small side coded project point of view.

Re: DrawAFish.com Postmortem

#90
post #2

I was one of the “lucky” few to witness the school of slur-fish. Being in security I laughed because of how egregious it was but also because I knew someone on HN with some actual time on their hands to help properly would be along soon. I also appreciate this post mortem. Vibe-coded anything in prod is a lot of my work load in IR these days but it was nice to see such a low stakes project properly documented.

Not even a screenshot, I really wanted to see the swastikarp.
Post reply on HN