Hacker Newsnew | past | comments | ask | show | jobs | submit | KomoD's commentslogin

Mine is not on any of the lists yet it's blocked on Xfinity. Fun!

These guys have been spamming issues in repos trying to promote this project and no disclosure whatsoever that they are associated with the project.

https://github.com/search?q=%22cloudinabottle.toml%22&type=i...


(author here) I'm checking with my team to confirm these came from us, but if so I apologize for this - posts like these should come from a real account with proper disclosure, but also these sorts of requests feel premature for a project like ours that doesn't yet have a sizeable user base.

The user was called adl-collab, when it forked repos to add implementations it made them under a branch called "andrew".

The biggest contributor to the project in the last 3mo is andrewlaack... and we can also just take a guess that "adl" in adl-collab is AnDrewLaak.


Yeah, I'll make sure this doesn't continue. To be clear there were 11 total issues posted; this was a mistake, not some huge spamming campaign.

[flagged]


This is Zack.

Thanks Andrew

Possibly andrewlaack’s clanker run amok

At least this is more informative than "Thanks Andrew".

You are also characterizing another project that was open-sourced (sandstorm) and is under active development as "long abandoned". Open source is difficult and requires a fair amount of cheerleading to engage users and make them part of the community. As a result it's hard to see your project in a positive light.

"Long abandoned" is a fair characterization of Sandstorm.

There is a loyal community of enthusiasts trying to keep it alive, but realistically not a lot of progress has been made. (Though, AI has helped them make more progress lately.)

But the original creator of Sandstorm (me) did indeed abandon it long ago (sorry).

More here: https://sandstorm.io/news/2024-01-14-move-to-sandstorm-org


There is no need to apologize for building a fantastic tool that was ahead of its time.

But "abandoned" in this contexts makes it sound like it's dead. Even if it's factually correct that the original (very busy) author stepped away and it is literally/factually true that you "abandoned it", it is also fairly misleading.

I disfavor maligning open source projects based on a misleading framing.


They also called out Sandstorm for requiring changes to the applications for them to run on the platform.

Which is true. There's no issue with honest criticism, but when it's careless or disingenuous then it it's a put reflection on the speaker.

Right, I wouldn't have mentioned it if their own platform didn't apparently have the same issue.

I mean, to be honest it does look like sandstorm development has almost stopped for the past couple of years...or am I missing something? https://github.com/sandstorm-io/sandstorm/graphs/code-freque...

No, sandstorm was deprecated years ago. I was building a platform that was similar to/inspired by sandstorm, and I closely followed it until its creator deprecated it. They now work for Cloudflare and released the 'WorkOS' project a couple weeks ago through them/for them.



Our current work is in the dev branch, we are preparing for a new release soon.

Looking at the issues, do I understand it correctly that you have some way to install directly from repositories if they contain a `cloudinabottle.toml` file?

If yes, regardless of who made the issues, that seems like terrible architecture/design there...


Please don't require app cooperation for getting apps into a bottle. I don't want to have to fight to get a file in, nor maintain my own fork.

I feel like with the capabilities of AI, I feel like they should be able to just figure this out..

> posts like these should come from a real account with proper disclosure

This line makes me think you are running a spam campaign and andrew just isn't part of it


If this is a spam campaign, it’s not a very effective one. I think you’d do well to apply Hanlon’s Razor here

I used to work for this company many years ago, and it's highly unlikely they're running a (centrally organized) spamming campaign of any type. Zack's a good guy and I'm sure he'll get it taken care of promptly.

[flagged]


Because "perfectly legal" and "socially acceptable" often diverge quite a bit.

The world would be quite miserable if "perfectly legal" would be what everyone optimizes for.


> The world would be quite miserable if "perfectly legal" would be what everyone optimizes for.

what you will find is that this is what corporations optimizes for. Therefore, you as a person, cannot compete with the corp.

That's why you need to become like a corp, or make the rules "socially acceptable" the same as "legal" (which is the best option).


Yes, but first of all, people make those decisions. And second, unlike those people, you don't need to have dissonant answers, and don't need to lie to yourself.

And you can still live quite comfortably.


[flagged]


This feels like something derailing, ragebaiting and not contributing to this platform tbh.

> [Behavior X] is encouraged in my social circles and anyone who says otherwise is weak minded

What is "weak-minded"? Seems like an awfully brittle perspective.


It's evidence of bad abstraction if you need everyone else to make changes and couple themselves directly to you.

If for some reason your services can't speak an already common language, I think it's on you to add those shims into your own project.


I don't think this approach is bad. The issues are asking if the project will accept contributions to add support, not demanding the maintainers add it.

Let's assume that they didn't have these container restrictions and could just use an ordinary docker-compose.yml, they'd still probably want to use something like OAuth2.0 for centralised login which a lot of these services won't have.

What would be better, making a massive PR to add support for it, or opening an issue to discuss it with the maintainer first?


Co-op Cloud, which has similarities, creates separate repos for its "packaging recipes". https://docs.coopcloud.tech/maintainers/catalogue/

It's 11 issues total and by one person, and the project says here in the thread the issue is being addressed. Please put down the metaphorical pitchforks and torches.

Hardly seems worth the pitchforks.

shouldn't we hold back with allegations while there's a non-0 chance this is just a user wishing their other services were supported too?

I checked, it's an Imbue employee (or someone impersonating one, which seems a bit far fetched). I could could cite my sources but it feels like doxxing / drawing too much attention to the mistake of an individual. My read is that it was a separate github account that they let an agent control.

project literally launched yesterday... come on

Disclosure would be nice but 11-12 issues in entire GitHub is hardly spam.

Looks like the account in question is deleted now - do you have the original username?

adl-collab

It's only 11 in the last 48h, on lesser known projects.

11 in 48 hours is way too many and I'd call that spam.

Yep, sarcasm is tough via text. Oops. I should've done /s but it's too late now.

Sounds like a fun llm that’s “fixing” things.

This github search returns just 11 results, and the issues are more or less reasonable. Doesn't seem that egregious.

Tell you what though, thank you for providing such a comprehensive list of cool projects to nerdsnipe me on a sunday morning!

The person doing this doesn't understand how pull requests work. The issues all say "I have a version in my fork". Open a pull request then! That's the whole point of forks on GitHub. Creating an issue first is pointless spamming akin to the classic "asking to ask". Just seems completely out of touch with open source to me.

> Creating an issue first is pointless spamming akin to the classic "asking to ask"

Many projects disagree with you on this one. It is quite common to have a policy that forbids PRs without an issue or discussion first.


I've never actually seen this. Can you link an example?

Some projects require opening an issue first.

On the plus side, I learned about some interesting projects from that GitHub query.

It's not spam if it's the first time I heard of it and it's useful. It shows they care about their project. This makes me want to try it out even more.

Meta and Google can spam their unsolicited ads to a billion users but regular people aren't allowed to promote their own projects on niche forums? This is bs. You're the problem here. Self-promoting your harmful values. You're the spammer.


Spam is, rather definitionally, undesired marketing.

If they don't desire it, it's spam for them. And they rather clearly do not desire it.

(You could also go with the stronger "unrequested marketing" definition, which makes this even more "definitely spam". CAN-SPAM rules define it this way, so that seems fair too)


No, I migrated nearly everything away from Cloudflare and over to Bunny instead.

archive.today doesn't use a real recaptcha, the cloudflare page isn't real either. it serves that as a punishment for using 1.1.1.1 DNS because the owner doesn't like that 1.1.1.1 doesn't send EDNS client subnets.

They're definitely trying to mimic the cloudflare captcha page, but...

>archive.today doesn't use a real recaptcha

How? It's loading the script from google, and the images/responses are from google to.


I recall that the 1.1.1.1 block page doesn't serve the real one,, but the challenge page that they serve normally does. Maybe I'm misremembering? or maybe they changed it.

I just tested and it's the "real" recaptcha, with requests to google and everything. It still might be "fake" in the sense that the server rejects any response, even valid ones, which is probably what's actually happening.

What do you mean by "a real recaptcha"? I just went to an archive.is page, and it's trying to load a script from www.google.com. Doesn't Google still own reCAPTCHA?

> On 14 January 2026, it emerged that archive.today had silently modified its CAPTCHA page to send repeated requests to Gyrovague, thereby causing visitors to unwittingly contribute to a DDOS attack against the blog.

https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...


It is telling that HN moderators allow links to archive.is/today

Rather than telling us that it is telling, perhaps you should tell us what it tells you and why?

Better to just ignore the anti-Russian and hasbara spam. It's being posted opportunistically. The chance to attack archive.is in an organically posted thread is probably the only reason an intermittent outage (common) of archive.is was upvoted enough to make it to the front page. Look at the top comment.

Why does it feel like everyone has just ignored/memory-holed this?

https://arstechnica.com/tech-policy/2026/02/wikipedia-bans-a...

That whole debacle is even specifically relevant to this thread because the operator of archive.today (aka archive.is) was caught using a script on its captcha page to make visitors' browsers connect to the blog they were mad at. That's how their DDOS attack worked. They used their own visitors, who naturally trusted the captcha page, to commit a crime.

For whatever reason, with the exception of Wikipedia (bless the editors), they seem to have gotten away with this, as well as with deliberately falsifying the content of "archived" pages (as described in the arstechnica article), without consequences.

So, call me crazy or a Russian bot if you want, but I think it's reasonable to be suspicious of any weird captcha behavior from this website in particular.


And HN users are being used as part of these attacks?

It tells us that the moderators of HN support copyright infringement and DDOS attacks. They are actively moderating this forum and choosing to do nothing.

They also choose to do nothing about uncharitable interpretations of their inactions. Should they act there too? Or do you prefer the hands-off approach when it suits you?

I can't control their behavior nor can you. But if you don't want to respond to the substance of my comment then perhaps you shouldn't respond?

I don't think it's very interesting even if true. I'm not that fussed about copyright infringement myself and I don't consider using archive.is (infrequently) to be condoning their DDOS.

Presumably you are and do. We differ.


This isn't about you personally. There is a public interest here.

Of course they'll say that. I'll believe it when I see it.

> It would be like asking why you don't just register smith.uk instead of smith.co.uk: because you can't

You can. Anyone can register a .uk, and you don't need to own the .co.uk


Wikipedia says "second-level domains are managed by various government agencies, and generally more strongly controlled" besides the exceptions mentioned like co.uk. Why else would anyone ever have gone for a third-level domain?

If they've recently changed that and I'm misreading Wikipedia, that doesn't change the underlying point that the answer was "you couldn't". Otherwise I've grossly misunderstood the whole post and how verisign is proposing to cancel this person's third-level domain


> High Anubis difficulty is annoying the hell out of me for several sites.

I just close the website if I see Anubis. Some have it set at reasonable difficulties (like 2)… others have it where I need to wait for like 30 seconds, I'm not wasting 30 seconds of my life for that.


the brutal truth is that if the website operator simply disabled Anubis, your page load would likely take more than 30s.

when a system was designed for 100 req/s and bots hit it with 5000 req/s, nobody entering that queue is having a good time. Anubis is the trade those operators make just to ensure your request gets serviced at all.

30s load time is already a sign that the Anubis approach is breaking down. if there's nothing else ready by the next order-of-magnitude increase in crawler load, those sites quite likely will just disappear from the public internet. hate Anubis all you want: for most of us, the realistic alternative is strictly worse.


Just look at another tab while you're waiting if you're that bothered.

It makes no difference when the registry (which is above registrars) is the one taking action.

So a game is only done if you neglect it?

I wouldn't say this is making a judgement on neglect or care. Its just making a judgement on "Do we expect any more content coming for this game". A neglected game over time will become an answer, as will a cared for game with a "We now consider our journey complete" developer post.

So just like DigitalOcean then. It's the first ASN I block when setting up a new website or server.

https://urlhaus.abuse.ch/asn/14061 https://threatfox.abuse.ch/asn/14061


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: