Thanks, appreciate the star. If you hit any snag deploying it, let me know. Curious what you're mainly after, the AI-referral alerts or the crawler side?
HN user
startages
Freelance full-stack developer
I help a lot of client with their ecommerce websites (mostly WooCommerce), attacks became so common recently, could be AI, but I found the best way to deal with this is to trace the patterns in access log and block the same patterns of checkout submission, this have worked really well for me. There are a lot of card testing attacks that Stripe doesn't care to handle as well as a lot of other fraud techniques, but there is always a pattern, especially automated ones. There is country, IP range, certain behavior (eg; no js, or direct api calls..etc). I really think it's easy to deal with this if you're willing to look deeper than a dashboard.
Now it's worst, you get an PDF export of a long ChatGPT chat history with one sentence "Can you give an estimation for this?"
How's this going to burn money?
I did use AI to organize my ideas but I didn't think it was that bad, I'll modify and make it easier to read.
Anyway, in my test I saw zero requests from any Google UA after multiple Gemini and AI mode prompts that should have triggered grounding, so the working interpretation is that Gemini served from its own index/cache rather than doing a live provider-side fetch. The original phrasing was fuzzier than it should have been.
Added $http_accept and re-ran. None of them use text/markdown. Results:
ChatGPT-User/1.0 text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 Claude-User/1.0 / Perplexity-User/1.0 (empty, no Accept header) PerplexityBot/1.0 (empty, no Accept header) ChatGPT sends a Chrome-style Accept string. Claude sends a wildcard. Perplexity sends nothing at all. Gemini didn't fetch in my test.
Also worth noting: Claude-User hit /robots.txt before the page.
Yeah, that the main reason I never use services like Google Cloud if I don't have to, it's impossible to have a hard cap, and anyone pretending to be an expert, is just off. Google says that they can't provide a hard cap because that would mean shutting down all your services..bla bla, but at least give users the option.
I thought I had something wrong within my setup, I could never use Codex 5.3 while everyone else was praising it. It uses some weird terms and complex jargon and doesn't really make it clear what it was doing or planning to do unlike Opus which makes things clear, this allows me to give accurate feedback and change plans and make proper decision.
Not bad, but it sacrifices accuracy and there are risks of causing more hallucinations from having incomplete data or agent writing bad extraction logic. So the whole MCP assumes Claude is smart enough to write good extraction scripts AND formulate good search queries. I'm sure thing could expand in the future to something better, but information preservation is a real issue in my experience.
This is misleading. I'm running a live experiment here: https://project80.divcrafts.com/
There are 4 models, all receiving the exact same prompts a few times a day, required to respond with a specific action.
In the first experiment I used gemini-3-pro-preview, it spent ~$18 on the same task where Opus 4.5 spent ~$4, GPT-5.1 spent ~$4.50, and Grok spent ~$7. Pro was burning through money so fast I switched to gemini-3-flash-preview, and it's still outspending every other model on identical prompts. The new experiment is showing the same pattern.
Most of the cost appears to be reasoning tokens.
The takeaway here is: Gemini spends significantly more on reasoning tokens to produce lower quality answers, while Opus thinks less and delivers better results. The per-token price being lower doesn't matter much when the model needs 4x the tokens to get there.
WordPress Foundation is paying for the servers, so I guess they have the right to choose who gets access or not. Using the resources as a single person or a small business is not the same as using them from a hosting company with millions of websites. Other hosting companies contribute to the foundation which keeps the service running. If WPEngine isn't contributing anything, it would be unfair for other contributors/sponsors. Especially that they are making a large amount of money from it.
Working on an audio watermarking system.
I've got the API ready, which requires 2 main values: - The original file ( which can be sent as a file, or hosted internally and requested using an ID ) - The data that needs to be printed into the audio file.
The API will return a watermarked version of the audio file that you can use later to extract the same data you sent before.
It's currently being tested on a production website, will wait for feedback, improve, and create an actual service out of the API.
It's 00:16, just about to go to bed, I ran `git push` and it's not working. Check Github, says it's down, I think it's only me, maybe I'm blocked, Github can't be down. Come here to check and it's down for everyone, such a relief.
- Location: Morocco - Remote: Yes
- Willing to relocate: Depends
- Technologies: Full-stack Web Developer (PHP, SQL, jQuery, WordPress, WooCommerce, Shopify, HTML, CSS, jQuery, Tailwind, Figma, Git..etc ) + DevOps experience ( AWS, GCP, Docker ) + A little bit of experience with Python, FastAPI.
- Résumé/CV: https://docs.google.com/document/d/1_F8snhgH0wIw6ol2dIJNQuwC...
- Email: me@alikhallad.com
Also open to one-time projects.
Hello, I've sent you an email, I'm really interested in this job. Would also love to learn Japanese as a language.
- Location: Morocco
- Remote: Yes
- Willing to relocate: Depends
- Technologies: Full-stack Web Developer (PHP, SQL, jQuery, WordPress, WooCommerce, Shopify, HTML, CSS, jQuery, Tailwind, Figma, Git..etc ) + DevOps experience ( AWS, GCP, Docker ) + A little bit of experience with Python, FastAPI.
- Résumé/CV: https://docs.google.com/document/d/1_F8snhgH0wIw6ol2dIJNQuwC...
- Email: me@alikhallad.com
Also open to one-time projects.
Not bad, but I don't see where in the world would this complete with any of the established editors out there.
A chrome extension to manage my canned replies, not in a bad way. I had to write the same things over and over for my job, so I created this tool to help me save text templates that I can customize later whenever needed. Don't hate me, I'm not a customer support agent. https://chromewebstore.google.com/detail/my-canned-responses...
Why I feel Europe is only throwing legislations at every new technology without any real understanding. Also, so many rules, yet the government is exempt from all of them.
I agree with this, Google has to account for a lot of things before making anything public compared to other smaller players. Otherwise, huge fines are on the way. I hate that some policy makers don't understand anything about technology, but still try to impose rules that don't make any sense.
You should probably ask your doctor to prescribe a safe eye-drop that you can use to help with dryness. Also, use protection glasses.
Qanat is an Arabic word which translates to "Canal", but it's a little more traditional and made to transfer water for long distances between a source of water and an agriculture field for irrigation.
That's a great post. I like the idea and was trying to do something similar myself, but it just takes so much time to write a toolset that can be easily replaced with some LLM API in 30 minutes. Still, many of the point in this post are valid and have their own use cases.
I tried to switch back previously due to some issue, but when I installed the old Mail app, it was barely functional and full of issues. Once you install the new version, it will be hard to switch back. Also, it's still lacking in many areas.
That's interesting, but there should measures in place so that even if one service is down, others would still work. Everything on OpenAI just stopped working yesterday.
Well, I feel this is a little misleading. That's not just AI, it was built by combining AI with a lot of existing tools and libraries to get the job done. How's that "Nothing but AI"
There is just so much you can do with GPT-4 vision, I just hope it's more affordable.
That will be the case eventually, and not everyone can write code and make their own e2ee, so I think there has to be some sort of open source solution that allows people to implement some sort of encryption without any coding.
The error doesn't mean they are using qdrant, but it's possible
Seems right to me. That's why it's good to build with extendability in mind to allow switching easily in the future if needed.