My favorite term for this in general is "irrational exuberance". Plenty of it was seen during the most bubble-like days of the 1997-2000 dotcom boom. Anyone remember beenz and flooz?
ISP operations/back-end systems perspective, there's indeed tons of RRA files out there still getting charts drawn based off them with rrdtool, but increasingly everyone is trying to store metrics in things like influxdb and draw them using grafana. Or similar. Even Cacti, a truly old and crufty thing that's been around for a long time has migrated to drawing charts as SVGs.
Don't worry, I'm sure we can teach a slop generator how to emulate this style. LLMs already know how to use rrttool and mrtg! Coming soon to an Internet near you, faux-historical slop writeups.
edit: this entire article managed to FAIL to mention the word "Dubai" even once, if a cursory Ctrl-F is correct.
Dubai is where Vy Capital is based. Any information on who their specific investors are would be very interesting. Of course it's possible they just chose Dubai as a typical offshore money destination, but knowing specifically what groups of wealthy gulf state Arabs have put money into Vy would provide useful context.
It doesn't solve everything but the 'full' desktop version of the ublock origin plugin runs just fine in Android on Firefox. I can't even imagine using any other mobile browser now. I don't know what the situation is for iphone platform stuff these days.
> 2) There are more ads going out then can be reviewed
The "more than can be reviewed" might have been a logical conclusion in a purely human based workflow, even if you have the lowest cost per head click workers in like, an external contractor call centre type environment in Bangladesh.
As the author points out, the ordinary consumer class version of publicly available Gemini very accurately classifies the ad as malicious. I really doubt that there are THAT MANY unique new ads being submitted per day that they can't afford the compute to run them through a similar classifier.
this argument still adds nothing to discussion because companies clearly want to spend zero but earn everything, the only amount they are willing to spend is on lawyers working on shielding companies from any responsibility including obvious cases of negligence
Yes, and I've also seen the absolute shitflood of horrible ads. Every time I see somebody else's system that isn't running ublock origin or similar... They clearly are prioritizing the ad revenue over any actual "don't take a steaming dump on the Internet" ethical priorities.
Please read the article, it's not the volume of the NTP requests, they're actively sending exploit/attempt to compromise payloads. They're probing things in a way that you would ordinarily only do to your own internal infrastructure.
"They tried all kinds of exploits against me: path traversal, webshell uploads, probing software internals, probing WordPress and other CMS management endpoints, SSRF, Log4Shell, and a lot more."
This is HN plenty of us host servers at home and understand the obviously true fact that you can't really stop it forever.
But that obviously isn't what we're talking about here. We're talking about a massive multibillion dollar corporation breaking the rules of a community project they joined by committing a Jr Sysadmin grade fuck up and ghosting the people who's infrastructure they have now placed in the crosshairs of serious, enterprise grade automated vulnerability testing from a company who might now inadvertently be committing a felony.
That's a bit different than getting a few dozen lazy hits a day because some botnet got to your IP in the Shodan and saw the Plex port open.
I don't disagree with you, I have tons of things that have public interfaces (as mundane as a fully patched wordpress where the wp-admin login is accessible to external blog writers), we get tens of thousands of random shit anything per day. But the problem here is that Tesla is treating NTP pool operators like they are their internal infrastructure. Also because the attribution of the 'attacks' is fairly well known.
I don't go complaining on the internet about the absolute shitflood of compromised routers on broadband ISPs in Indonesia probing my stuff 24x7x365 because I know it would be futile. But if I found one specific american company that was repeatedly probing my stuff all the time? Maybe I'd escalate it.
reply