Sam Crowther
292 posts


Here’s the full story. When the attacker reached out, I expected chaos. Instead, I met someone absurdly skilled, weirdly honest, and surprisingly open about why he did it. He’s from Russia. And his “job” is running a full stresser service - hundreds of servers across data centers, custom built browsers with Rust, distributed load generators, all built and managed by him. At one point he even had 479 attacks running in parallel for different customers. He walked me through how he bypassed multiple layers of protection at @dodopayments. He showed me the tooling he built. He explained how he tests hundreds of sites at once. No ransom. No extortion. Just….. “I don’t like weak security and I wanted to push you.” And honestly, he did push us. Hard. We spent 48 hours fixing gaps we didn’t know existed. He pointed out where we were strong and where we weren’t. He even shared suggestions on how to harden the stack further. The wildest part? What started as an attack turned into a conversation about infra, security, and resilience. Internet is a strange place. But sometimes the people trying to break you end up making you stronger.


@PayPal HOW THE FUCK DO YOU TURN CAPTCHA OFF ON AN ACCOUNT? I DONT FUCKING WANT TO DEAL WITH THIS BULLSHIT


Where can I file issues for @vercel's botid package/api. I followed the documentation on the setup, and yet in production, all Server Action requests were being blocked. @rauchg @cramforce I was the one trigger the server actions in a preview build on Vercel, MS Edge browser.



BotID is a new invisible CAPTCHA layer of protection that stops sophisticated bots before they reach your backend. It's built to secure critical routes such as checkouts, logins, and signups, or actions that trigger expensive calls like LLM-powered APIs. vercel.com/blog/introduci…





We removed Cloudflare's Turnstile for... - Cleaner UI ✨ - Login is 2x as fast! 🏎️


BotID is a new invisible CAPTCHA layer of protection that stops sophisticated bots before they reach your backend. It's built to secure critical routes such as checkouts, logins, and signups, or actions that trigger expensive calls like LLM-powered APIs. vercel.com/blog/introduci…



why are we filling these out

BotID is a new invisible CAPTCHA layer of protection that stops sophisticated bots before they reach your backend. It's built to secure critical routes such as checkouts, logins, and signups, or actions that trigger expensive calls like LLM-powered APIs. vercel.com/blog/introduci…





