August 27 TCRF DDoS Attack Postmortem

27 pointsposted 10 hours ago
by panic

13 Comments

timpera

7 hours ago

It's a shame that so many niche websites have no other choice than moving to Cloudflare.

> "In the process of mitigating, migrating, and updating things, we’ve made a lot of upgrades and improvements to the wiki and infrastructure: Automatic blocking of many bots and other nuisances, including Tor exit nodes"

Is this supposed to be a good thing? What's the point of blocking Tor here?

Xkeeper

6 hours ago

Tor is one of those things that is nice in theory but, in my experience, tends to consist of about 20% legitimate users, 30% garbage traffic, and (most importantly) 50% specific, persistent, ban-dodging personas non grata.

There are only so many days one wants to wake up and click "delete user" 20 times for the latest batch of slur-filled trash from tor-exit-48012480.r0ck3t.ballz.

VCFundedGenYer

8 hours ago

This is why no one likes AI. It ruins wonderful passion project sites like this.

ndiddy

6 hours ago

It's kind of sad that we've gotten to the point where if someone decides they want to fuck with you, there's nothing you can do besides using a service like Cloudflare. I wonder how much cumulative time the "Checking your browser..." screen has wasted.

infotainment

8 hours ago

> I recently added a new feature to The Cutting Room Floor: If you visit the site with a “Claude-code” user agent… it adds you to a Claude user ban list. Then, if you try and visit the site later, without Claude — maybe because you wanted to investigate the “prompt injection” page it received — you’re greeted with a special error page telling you to get out

This guy sounds like he has spent way too much time online getting angry at imaginary enemies, and really needs to get outside and talk to some real people outside of his filter bubble.

I actually enjoy reading TCRF, so it’s unfortunate that the owner is apparently a terminally online insane person.

Xkeeper

7 hours ago

Hi, TCRF operator here! (*she)

This story has been escalating for over a year at this point. Originally, identified bots were given a generic "access denied" message. Then a special generic "LLM poison"-type page (some joke misinformation). Once I noticed that Claude-Code bots, specifically, were evading those blocks -- making one request, then changing their user-agent and trying again -- I started adding the persistent ban for bot misbehavior.

That you didn't know any of this until now suggests, I think, that there isn't really much of a problem. After all, this only affects agents reporting as Claude-Code.

The primary goal my side of this has been to interrupt and annoy LLM/AI users, and to that it has been working incredibly well.

My previous blog post, written before this DDoS attack, went into some of the challenges of being an independent website that avoided using third-party services (outside of Linode, our host). Cloudflare was always my "last resort" — I actually signed up for an account there a bit over a year ago, during an earlier attack — and it finally became time to use that last resort.

As for "terminally online", I guess you could say guilty as charged. I've been running communities for over 20 years and TCRF specifically for nearly 17, longer than a lot of our users have been alive. It certainly gets results.

moorow

4 hours ago

Out of pure curiosity, is it Claude Code only? Or other harness user agents? Just curious if there's something specific about CC that's encouraging the block.

Xkeeper

2 hours ago

It's just C-C, and solely because I noticed that it appears (a) to do its networking from the user's local network instead of a cloud server, and (b) it typically identifies itself as claude-code. It also showed up enough in my logs to be noticed; I don't go proactively searching or testing these things.

Other tools either run off of a central cloud provider, in which case they get the standard anti-AI page, or mask as a "legitimate" user agent, in which case I leave it up to the captcha/challenge.

madiling

4 hours ago

Interestingly, you could (can?) get banned from TCRF if you opened it using a link from certain websites. And you would get a unique ban message based on which website you came from.

InvisibleUp

3 hours ago

“certain websites” being Kiwi Farms, iirc. And that’s entirely because of the harassment thread they have there.

jeroenhd

8 hours ago

It's a pretty funny solution to slop bots, and it's clearly effective enough to upset the exact type of loser it's designed to reject.

The insane part is launching a DDoS attack because some guy online insulted your favorite toy.

infotainment

8 hours ago

I’d argue both sides are acting insane; there are no good guys in this story, only people who got way too worked up about software choices and started lashing out in inappropriate ways.

phoronixrly

an hour ago

There's a person who decided to ban bot traffic from their own site, and there's a person who committed a felony in response. Definitely a 'both sides' situation according to HN comments.