Hi, TCRF operator here! (*she)
This story has been escalating for over a year at this point. Originally, identified bots were given a generic "access denied" message. Then a special generic "LLM poison"-type page (some joke misinformation). Once I noticed that Claude-Code bots, specifically, were evading those blocks -- making one request, then changing their user-agent and trying again -- I started adding the persistent ban for bot misbehavior.
That you didn't know any of this until now suggests, I think, that there isn't really much of a problem. After all, this only affects agents reporting as Claude-Code.
The primary goal my side of this has been to interrupt and annoy LLM/AI users, and to that it has been working incredibly well.
My previous blog post, written before this DDoS attack, went into some of the challenges of being an independent website that avoided using third-party services (outside of Linode, our host). Cloudflare was always my "last resort" — I actually signed up for an account there a bit over a year ago, during an earlier attack — and it finally became time to use that last resort.
As for "terminally online", I guess you could say guilty as charged. I've been running communities for over 20 years and TCRF specifically for nearly 17, longer than a lot of our users have been alive. It certainly gets results.
Out of pure curiosity, is it Claude Code only? Or other harness user agents? Just curious if there's something specific about CC that's encouraging the block.
It's just C-C, and solely because I noticed that it appears (a) to do its networking from the user's local network instead of a cloud server, and (b) it typically identifies itself as claude-code. It also showed up enough in my logs to be noticed; I don't go proactively searching or testing these things.
Other tools either run off of a central cloud provider, in which case they get the standard anti-AI page, or mask as a "legitimate" user agent, in which case I leave it up to the captcha/challenge.
Interestingly, you could (can?) get banned from TCRF if you opened it using a link from certain websites. And you would get a unique ban message based on which website you came from.
“certain websites” being Kiwi Farms, iirc. And that’s entirely because of the harassment thread they have there.
It's a pretty funny solution to slop bots, and it's clearly effective enough to upset the exact type of loser it's designed to reject.
The insane part is launching a DDoS attack because some guy online insulted your favorite toy.
I’d argue both sides are acting insane; there are no good guys in this story, only people who got way too worked up about software choices and started lashing out in inappropriate ways.
There's a person who decided to ban bot traffic from their own site, and there's a person who committed a felony in response. Definitely a 'both sides' situation according to HN comments.