Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That is exactly our opinion also. We understand that some think it is a bit scary letting people test any site they want, but the fact is that anyone with a DSL connection at home can choose any site they want out there and put a lot more load on it using their home PC, than we allow anonymous users to do with our service.

We want the service to be really user-friendly and easy to get started with, and think we have reached a fairly good level of compromise where security is "good enough" without sacrificing usability.

What we could, and should do, however, is be more informative about all the security measures we have taken to prevent abuse. Because we have put a lot of man-hours into that lately, and we will continue to build more, hopefully non-intrusive, security measures all the time to try and make the service unattractive to would-be abusers.



Still, there should be a dead simple way to completely opt out of your services. E.g. check for a presence of specific file in / directory and if it's there, abort all testing.

Just keep in mind that for an average hosting provider it is far easier to null route your subnet than to sit there and assume that you will not screw up.

Also, as a side note, even if you are tracking per-IP statistics of your tests, I suspect you are not doing any detection of multihomed machines. For example, my company has a dozen of websites served from a single box, each on its own IP address. Do you seriously expect us to let your service anywhere near our boxes ?


I hear you, and you're absolutely right, we will provide an easy way to opt-out for those who want to. It's on its way.


Ok, great to hear that.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: