<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: cullenking</title><link>https://news.ycombinator.com/user?id=cullenking</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 06 Sep 2026 20:28:31 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=cullenking" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by cullenking in "Ask HN: Resources to get good at soldering?"]]></title><description><![CDATA[
<p>I learned by doing an 8 hour soldering session, building an open source ECU for an older car. By the end it was easy! Fresh joints in a kit are easier than repair so it’s a better place to start learning temp control etc.</p>
]]></description><pubDate>Sat, 05 Sep 2026 16:18:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49578022</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=49578022</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49578022</guid></item><item><title><![CDATA[New comment by cullenking in "Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot"]]></title><description><![CDATA[
<p>That’s not the pattern I am seeing, but I might be outside the norm. The majority of bot action (scraper, spam) comes from vpn providers by a long shot, ignoring (Chinese ASNs, Indian mobile ISPs etc). I see very little consumer isp action except cheap international providers, which are still swamped by vpn traffic.</p>
]]></description><pubDate>Thu, 13 Aug 2026 14:01:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49286136</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=49286136</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49286136</guid></item><item><title><![CDATA[New comment by cullenking in "Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot"]]></title><description><![CDATA[
<p>Not sure what you mean by your first comment - there is no technical reason that I know of that prevents a VPN provider from having their own ASN and address space.<p>As for the latter comment....not sure what your implication is. Yes, bot/spam mitigation is whackamole, but there are consequences for not playing the game of whackamole. Luckily residential proxies are few and far between so far, but they will grow in popularity. When they do, and I can't get by with the occasional individual residential IP ban, we'll come up with other methods to handle.<p>Luckily the signal is strong with vulnerability scanning, which makes it pretty easy to automate. The only reason to put up whole ASN mitigation (captcha/turnstile, outright bans) is just efficiency. Nothing stopping individual IP banning. The scrapers are the tricky ones, since they more easily hide in legit traffic. However legit traffic has patterns that scrapers do not emulate (at least for a service like ours with millions of pieces of user generated content that's easily walkable), so you can still pull out the signal. It's just a little trickier.<p>Definitely a continual arms race though.</p>
]]></description><pubDate>Thu, 13 Aug 2026 04:09:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=49281712</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=49281712</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49281712</guid></item><item><title><![CDATA[New comment by cullenking in "Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot"]]></title><description><![CDATA[
<p>the numbers are much smaller than traditional search but they are trending up, and they convert at almost 2x the rate of organic search inbounds. sure you can play catchup later, but the trend is quite clear. if there's one thing the last two years have taught me, my prior heuristics on now vs future don't work in 2026.</p>
]]></description><pubDate>Wed, 12 Aug 2026 23:02:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=49279761</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=49279761</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49279761</guid></item><item><title><![CDATA[New comment by cullenking in "Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot"]]></title><description><![CDATA[
<p>I did just this. Using a $2k a year database from a smaller provider that isn't maxmind, claude and I built a pretty slick ASN based categorization system. I can categorize an ASN as a residential IP, a service provider, a legit crawler/scraper, etc. For anything that is suspicious, I dynamically use turnstile to gate access to our service. Turns out there's no ISP for any VPN, they just contract with a shitload of mom and pop shady colocation services across the world.<p>We collect signals that help determine good vs bad networks. For example, large amounts of requests to .php endpoints, large amounts of empty accounts from the same /24 subnet, etc etc. All these signals let us automatically determine risk, and then put up a challenge. Authenticated users never see the challenge even if they are on a risky network (VPN 99.9% of the time), unless the network has been identified as 100% malicious, then it gets a full block.<p>Here's a small snapshot of the dashboard:<p><a href="https://cos.ridewithgps.com/screenshots/6a7c54d0-12Aug26-358916819.png" rel="nofollow">https://cos.ridewithgps.com/screenshots/6a7c54d0-12Aug26-358...</a><p>This was probably a total of 3-4 days of work, spread out over a couple months of iterative claude led hacking. I didn't know exactly what to build, but had some of the key architectural ideas in my head. Opus+Faable made easy work of it all, and ended up guiding some really slick improvements for performance.<p>I would say this has dropped about 20% of all traffic to our service, though it turns out turnstile is a massive target for bots, so replacing that with something custom is next on the list.</p>
]]></description><pubDate>Wed, 12 Aug 2026 22:04:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49279235</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=49279235</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49279235</guid></item><item><title><![CDATA[New comment by cullenking in "Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot"]]></title><description><![CDATA[
<p>See my comment in the parent - there are cheaper options, don't use maxmind!</p>
]]></description><pubDate>Wed, 12 Aug 2026 22:03:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49279224</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=49279224</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49279224</guid></item><item><title><![CDATA[New comment by cullenking in "Nearly half of LG smart TV apps contain residential proxy SDKs"]]></title><description><![CDATA[
<p>I just implemented bot and crawler detection as well as ASN based blocking for our website, because I’ve seen a massive rise in scraping coming from VPNs and other networks that mix legit and illegitimate traffic to our service. My theory is that small companies are scraping the shit out of everything and selling results to llm creators. It’s going to be interesting to see this expand into residential internet providers through holes like this… wild new world!</p>
]]></description><pubDate>Mon, 22 Jun 2026 23:51:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48638181</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=48638181</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48638181</guid></item><item><title><![CDATA[New comment by cullenking in "Cloudflare to cut about 20% of its workforce"]]></title><description><![CDATA[
<p>The people I hired in my last round, with over 600 slop and fake applicants, had honest and informal cover letters that stood out. I’m sure I passed up on real decent people as a result, but there’s no perfect way to avoid this right now.<p>It helps that we have something closer to a lifestyle business, where I can ask for a brief paragraph about your relationship to the outdoors and cycling, but that just means I had 500 slop cover letters gushing about cycling. The three that made it through were short concise honest and linked to real world activities they did.<p>Good luck, it’s a hard problem , and very very adversarial. You have true scam level applications from North Korea and India, and you have unqualified people trying to appear qualified. Sprinkled in are unqualified people who would be a good hire because of raw capability, and qualified people who are looking to do bare minimum.</p>
]]></description><pubDate>Fri, 08 May 2026 15:47:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48064803</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=48064803</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48064803</guid></item><item><title><![CDATA[New comment by cullenking in "Motherboard sales 'collapse' amid unprecedented shortages fueled by AI"]]></title><description><![CDATA[
<p>Anecdata to add to the pile...I pulled three 1u epyc gen2 servers from my production rack 1.5 years ago and replaced them with lower power alternatives for a production storage cluster. I didn't need the extra CPUs for app server stuff so they sat in my house for a while. Fast forward 1.5 years and it was making sense to upgrade some app servers to new gen stuff, get a bump in frequency and core count...when i went to spec some new servers, my normal $15k - $20k build was $55k.<p>Instead, I hittup ebay, got six used gen3 processors, found a "good deal" on a couple tb of new ram (still insanely expensive), and came out with the same overall horsepower for a total of $20k instead of $110k.<p>I know this is about consumer desktop, but seeing the comments about upgrading old hardware caused me to chime in. This is happening in the production/enterprise level in some segments.</p>
]]></description><pubDate>Thu, 07 May 2026 22:28:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48055964</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=48055964</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48055964</guid></item><item><title><![CDATA[New comment by cullenking in "The bot situation on the internet is worse than you could imagine"]]></title><description><![CDATA[
<p>We started building out a set of spam/fraud/bot management tooling. If you have any decent infrastructure in place already, this is a pretty manageable task with a mismash of techniques. ASN based blocking (ip lookup databases can be self hosted and contain ASN) for the obvious ones like alibaba etc, subnet blocking for the less obvious (see pattern, block subnet, alleviates but doesn't solve problems).<p>If you have a logging stack, you can easily find crawler/bot patterns, then flag candidate IP subnets for blocking.<p>It's definitely whackamole though. We are experimenting with blocking based on risk databases, which run between $2k and $10k a year depending on provider. These map IP ranges to booleans like is_vpn, is_tor, etc, and also contain ASN information. Slightly suspicious crawling behavior or keyword flagging combined with a hit in that DB, and you have a high confidence block.<p>All this stuff is now easy to homeroll with claude. Before it would have been a major PITA.</p>
]]></description><pubDate>Sun, 29 Mar 2026 17:22:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47565145</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=47565145</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47565145</guid></item><item><title><![CDATA[New comment by cullenking in "Making geo joins faster with H3 indexes"]]></title><description><![CDATA[
<p>Doesn’t meet all our product requirements unfortunately. We used returned hexes in certain queries, and we also hacked in directionality of line using least significant 12 bits of the hex (didn’t need that level of hex precision), and we are doing direction oriented matching and counting. For simpler use cases it’s definitely a better option. thanks for reminding me and other people reading my comment!</p>
]]></description><pubDate>Sat, 07 Feb 2026 15:01:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=46924399</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=46924399</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46924399</guid></item><item><title><![CDATA[New comment by cullenking in "Making geo joins faster with H3 indexes"]]></title><description><![CDATA[
<p>Not any differently than another indexed text field</p>
]]></description><pubDate>Sat, 07 Feb 2026 14:57:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=46924364</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=46924364</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46924364</guid></item><item><title><![CDATA[New comment by cullenking in "Making geo joins faster with H3 indexes"]]></title><description><![CDATA[
<p>We do something similar for some limited geospatial search using elastic search. We make a set of h3 indexes for each of the hundreds of millions of gps recordings on our service, and store them in elastic search. Geospatial queries become full text search queries, where a point is on the line if the set of h3 indexes contains the point. You can do queries on how many cells overlap, which lets you match geospatial tracks on the same paths, and with ES coverage queries, you can tune how much overlap you want.<p>Instead of using integers IDs for the hexes, we created an encoded version of the ID that has the property that removing a character gets you the containing parent of the cell.  This means we can do basic containment queries by querying with a low resolution hex (short string) as a prefix query. If a gps track goes through this larger parent cell, the track will have hexes with the same prefix. You don’t get perfect control of distances because hexes have varying diameters (or rather the approximation, since they aren’t circles they are hexes), but in practice and at scale for a product that doesn’t require high precision, it’s very effective.<p>I think at the end of this year we’ll have about 6tb of these hex sets in a four node 8 process ES cluster. Performance is pretty good. Also acts as our full text search. Half the time we want a geo search we also want keyword / filtering / etc on the metadata of these trips.<p>Pretty fun system to build, and the concept works with a wide variety of data stores. Felt like a total hack job but it has stood the test of time.<p>Thanks uber, h3 is a great library!</p>
]]></description><pubDate>Sat, 07 Feb 2026 05:51:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=46921666</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=46921666</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46921666</guid></item><item><title><![CDATA[New comment by cullenking in "A Broken Heart"]]></title><description><![CDATA[
<p>I do this all the time in a dumb but effective way. Add logging statements to code paths that drop timing info. Another dumb but effective way, instead of using a step through debugger, is drop "here, value is {val}". Telling claude to do this is trivial, it's quick, and it can read its own output and self-solve the problem all with just the code itself.<p>IMHO git bisect is slower, especially depending on the reload/hot-reload/compile/whatever process your actual app is using.</p>
]]></description><pubDate>Thu, 05 Feb 2026 20:16:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=46904582</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=46904582</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46904582</guid></item><item><title><![CDATA[New comment by cullenking in "Flameshot"]]></title><description><![CDATA[
<p>The above works on wayland, had to make the changes specifically when I moved over to wayland and hyprland</p>
]]></description><pubDate>Mon, 02 Feb 2026 20:23:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=46860921</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=46860921</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46860921</guid></item><item><title><![CDATA[New comment by cullenking in "Flameshot"]]></title><description><![CDATA[
<p>Flameshot is the best! I've been using it for 10+ years. I have it wired up to some hot keys in my window manager, and have it dump to s3 so I can paste around links to screenshots everywhere for work.<p><a href="https://github.com/kingcu/screendrop" rel="nofollow">https://github.com/kingcu/screendrop</a></p>
]]></description><pubDate>Thu, 29 Jan 2026 20:22:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=46816027</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=46816027</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46816027</guid></item><item><title><![CDATA[New comment by cullenking in "FAA to restrict commercial rocket launches to overnight hours"]]></title><description><![CDATA[
<p>So like texting and driving, but in the air? Flying is hard, I don’t think an automated text based system would be safer than what we have now.</p>
]]></description><pubDate>Sat, 08 Nov 2025 04:45:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=45854206</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=45854206</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45854206</guid></item><item><title><![CDATA[New comment by cullenking in "Doing Rails Wrong"]]></title><description><![CDATA[
<p>it all depends on your philosophy on dependencies. if you maintain a small set of core dependencies that are there for good reasons and are actively maintained, then rails upgrades are pretty easy. if you have a Gemfile that has a bunch of third party gems that you bring in for small problems here and there, you have to occasionally pay down that debt on version upgrades. we have an 18 year old rails codebase currently on 7.1 that hasn't proven to be a big pain for upgrades. the hardest upgrade we did was because of a core dependency that had been dead for 5 years broke with a new version of rails. but that was a story of letting technical debt ride for too long and having to pay it back.<p>this is a common problem in any complex codebase that has a culture of using third party dependencies to solve small problems. you see this conversation all the time with modern frontend development and the resulting dependency tree you get with npm etc....</p>
]]></description><pubDate>Tue, 07 Oct 2025 20:38:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=45508526</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=45508526</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45508526</guid></item><item><title><![CDATA[New comment by cullenking in "Samsung now owns Denon, Bowers and Wilkins, Marantz, Polk, and more audio brands"]]></title><description><![CDATA[
<p>Minidsp flex ht or htx paired with a buckeye 6 channel amp. As cheap as you can get premium sound quality. Not cheap but you get the software control you actually want via the minidsp</p>
]]></description><pubDate>Sat, 27 Sep 2025 17:35:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=45397792</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=45397792</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45397792</guid></item><item><title><![CDATA[New comment by cullenking in "Terence Tao: The role of small organizations in society has shrunk significantly"]]></title><description><![CDATA[
<p>Preschool is just daycare with structure, so it costs more. Optional, privately owned. Nice to do 2-3 days a week for young kids to give them more social and learning opportunites. But it’s not public school, it’s usually just a small locally owned business.</p>
]]></description><pubDate>Thu, 25 Sep 2025 04:08:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=45369190</link><dc:creator>cullenking</dc:creator><comments>https://news.ycombinator.com/item?id=45369190</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45369190</guid></item></channel></rss>