Hacker Newsnew | past | comments | ask | show | jobs | submit | patricklorio's commentslogin

Playit - https://playit.gg Eugene, Oregon. REMOTE okay. Oregon USA only.

Looking to hire our first full time engineer besides myself. High impact role, over 100k monthly active users. Cash flow positive.

We run a global network to help people host game servers at home. Most of our backend is in Rust with Postgres DB, website is React SPA in typescript.

Engineering work touches many areas: * low level AF-XDP networking * state synchronization across 20 datacenters * custom ddos mitigation logic * product feature development * front end website dev * front end TUI dev * reliability monitoring and alerting * so much, think creating cloudflare from scratch with focus on gaming and you’re not far off

Send resume over email to apply@playit.gg. Note I (a human with limited time) will read your email and resume. Please don't send me a tailored AI resume or email to waste my time. Please.


I run playit.gg. Abuse is a big problem on our free tier. I’d get https://github.com/projectdiscovery/nuclei setup to scan your online endpoints and autoban detections of c2 servers.


Thanks for sharing this. I run packetriot.com, another tunneling service and I ended up writing my own scanner for endpoints using keyword lists I gathered from various infosec resources.

I had done some account filtering for origins coming out of Tor, VPN networks, data centers, etc. but I recently dropped those and added an portal page for free accounts, similar to what ngrok does.

It was very effective at preventing abuse. I also added mechanism for reporting abuse on the safety page that's presented.


Have you found a way to detect xworm c2c servers?


Our services were used for C2 as well. I investigated it a bit but eventually decided to just drop TCP forwarding from our free-tier and that reduced our abuse/malware reports for C2 over TCP to zero essentially.

One path I looked at was to use the VirusTotal API to help identify C2's that other security organizations were identifying and leverage that to automatically take down malicious TCP endpoints. I wrote some POCs but did not deploy them. It's something I plan on taking up again at some point next year.


Want to chat on discord? Maybe we could combine efforts to try and stop people abusing our services :). We have a few vendors sending us automated reports, maybe I could open it up for multiple projects.

feel free to give me a ping on https://discord.gg/AXAbujx @patrick.


IMO bad take. We want quality journalism to be sustainable, having AI launder stolen content and make it free with ads is not better.


Fortunately or unfortunately, the New York Times is now a gaming/recipes company with a newspaper attached to it.

Probably mostly a good thing now that I think about it - it moves the paper closer to the model of 20th century journalism (a local quasi-monopoly on news gathering and distribution funded by advertising) that was, for all its faults, pretty fucking good in retrospect.


Sure, I'd love for quality journalism to be sustainable, but that's no reason to keep ourselves ignorant while it isn't sustainable, a situation which may or may not end in our lifetimes.

Also, this is the NYT we're talking about here, the outfit that promoted the fiction about "weapons of mass destruction" in Iraq and doxxed Scott Alexander while insinuating he was a Nazi. It's not a good choice for a poster child for "quality journalism".


Provided a fake ID when trying to verify identity. Wasted my time, be cautious.


So he received the checks and mailed them to his bank but they were intercepted in the second leg and cashed out. Sounds like the fault is with the banks that cashed out the checks without adequate verification.


But how will small mom and pop banks be able to afford shiny towers downtown if they have to know every single customer? \s


Highly recommend clickhouse. You can set the partition key to be based on date and delete old data in chunks. Makes life really easy. Also found it much more performant than timescaledb out of the box. Not sure about hosted options but can imagine that translates to better performance for the dollar.


Computers outside of the US sure, but the latest chips used for AI training have export controls so not so much.


I think this is about preventing sanctioned countries or individuals using US technology we don't want them to have access too (like China not having modern GPUs). That goal seems reasonable though there's always a fear that the law is way broader than the high level intent. Why would it be "an absolute nightmare" if it's so easy to migrate?


That's the stated goal. The actual goal is more likely complete knowledge of any person using IaaS service whether domestic or foreign and what they're up to.


Yeah, mass surveillance.


I meant an absolute nightmare of a bill in general and for the IaaS providers. The US is winning the AI race because of their open ecosystem and capability to execute and these types of things hurt that bad.


I read the document a bit, it seems like this is essentially saying that services like AWS need to know the identity of their customer if they suspect they are a foreign entity.

I don't think this would cover VPNs or internet access, mainly just people spending lots of $$ on compute. Is that correct? If so it seems reasonable. If a non US group is spending lots of money using US technology to develop an AI model I do think that falls under foreign trade and should be documented.


756 MW is the peak power rate, not accumulated amount of power that will be generated per year.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: