August 27 TCRF DDoS Attack Postmortem

(blog.xkeeper.net)

17 points | by panic 3 hours ago

3 comments

  • timpera 53 minutes ago

    It's a shame that so many niche websites have no other choice than moving to Cloudflare.

    > "In the process of mitigating, migrating, and updating things, we’ve made a lot of upgrades and improvements to the wiki and infrastructure: Automatic blocking of many bots and other nuisances, including Tor exit nodes"

    Is this supposed to be a good thing? What's the point of blocking Tor here?

    • VCFundedGenYer 1 hour ago

      This is why no one likes AI. It ruins wonderful passion project sites like this.

      • infotainment 1 hour ago

        > I recently added a new feature to The Cutting Room Floor: If you visit the site with a “Claude-code” user agent… it adds you to a Claude user ban list. Then, if you try and visit the site later, without Claude — maybe because you wanted to investigate the “prompt injection” page it received — you’re greeted with a special error page telling you to get out

        This guy sounds like he has spent way too much time online getting angry at imaginary enemies, and really needs to get outside and talk to some real people outside of his filter bubble.

        I actually enjoy reading TCRF, so it’s unfortunate that the owner is apparently a terminally online insane person.

        • Xkeeper 40 minutes ago

          Hi, TCRF operator here! (*she)

          This story has been escalating for over a year at this point. Originally, identified bots were given a generic "access denied" message. Then a special generic "LLM poison"-type page (some joke misinformation). Once I noticed that Claude-Code bots, specifically, were evading those blocks -- making one request, then changing their user-agent and trying again -- I started adding the persistent ban for bot misbehavior.

          That you didn't know any of this until now suggests, I think, that there isn't really much of a problem. After all, this only affects agents reporting as Claude-Code.

          The primary goal my side of this has been to interrupt and annoy LLM/AI users, and to that it has been working incredibly well.

          My previous blog post, written before this DDoS attack, went into some of the challenges of being an independent website that avoided using third-party services (outside of Linode, our host). Cloudflare was always my "last resort" — I actually signed up for an account there a bit over a year ago, during an earlier attack — and it finally became time to use that last resort.

          As for "terminally online", I guess you could say guilty as charged. I've been running communities for over 20 years and TCRF specifically for nearly 17, longer than a lot of our users have been alive. It certainly gets results.

          • jeroenhd 1 hour ago

            It's a pretty funny solution to slop bots, and it's clearly effective enough to upset the exact type of loser it's designed to reject.

            The insane part is launching a DDoS attack because some guy online insulted your favorite toy.

            • infotainment 1 hour ago

              I’d argue both sides are acting insane; there are no good guys in this story, only people who got way too worked up about software choices and started lashing out in inappropriate ways.