Hacker News new | past | comments | ask | show | jobs | submit login

What constitutes abuse? I imagine certain applications that would be fine with the server going up and down every 2 hours. That would effectively mean that they would have free service indefinitely. For example, a Tor bridge.



In general abuse is anything that is illegal under US law, causes a disruption of service or is otherwise disruptive to our ability to run the service. As far as our TOS goes, if we say it's abuse, it is. We will be very strict in our enforcement. We're hoping that backend procedures and processes we have in place will help us to profile abusers and prevent them from using the services as our goal is to prevent abuse while making the barrier to getting started as low as possible for legitimate users.

A tor bridge/relay might not be an issue but TOR exit nodes will almost certainly result in abuse complaints and action being taken.


Shhhh, you're gonna ruin it for everybody else!


We were all thinking it.


Or bitcoin miners


You would mine maybe 1 penny per day. Not worth the click.


....that's not how fraud works.

https://news.ycombinator.com/item?id=7490766

Just google aws bitcoin mining abuse and see what happens when shitty people have access to free servers.


Pretty sure it only makes sense when you can spin up AWS GPU instances, which you probably cannot do here.


When there are no costs, it makes sense spin up anything. You literally can't lose. It's just opportunity costs at that point.


Unless you missed the no API part. If it takes a person 5 clicks to launch an instance, the reward has to pay for the cost.

Why aren't people using AWS free tier to Bitcoin mine?

Seems a bad prop.


I am sure that some people did try to use the free tier, and that AWS probably has some decent controls in place to monitor for this type of activity. They are also a MASSIVE company that can absorb loss much easier than a startup. [1]

As far as the API goes, I don't know if you're aware of how hacking works, but not having an api has protected exactly no one ever. Calling your application secure because "it has a button, not an API" is completely absurd. [2]

As far as costs, you understand that people do thousands of tasks on mechanic turk for pennies right? 5 clicks to make a penny or two isn't out of the question, EVEN WITHOUT AUTOMATION, when the cost for living in some parts of the world is egregiously low. [3]

[1] https://news.ycombinator.com/item?id=6818015

[2] http://www.seleniumhq.org/docs/01_introducing_selenium.jsp

[3] http://online-job-work.com/wp-content/uploads/2013/09/mechan...


> As far as costs, you understand that people do thousands of tasks on mechanic turk for pennies right?

You still have to invest either your time or hire someone to set things up for the mechanical turk setup - the opportunity cost you pointed out earlier. And pennies per turk isn't worth it if your ROI is micropennies per turk. Depending on how much friction there is, it may be cheaper to trick your turks into running the bitcoin miner on their own computers.

Not saying there's no potential for abuse - as you say, there is - but saying there's "no costs" and that "You literally can't lose" is about as accurate as saying there's "no profits" and that "You literally can't win". Unless CPU bitcoin mining is wildly more profitable than my understanding, given that you're competing against GPU and ASIC miners.

Maybe one of the alt-currencies that are supposedly harder to GPU mine...?


Yup. The way Dply works makes it a bad value prop for abusers. It's also not the best option for someone who would be better served going with DO directly or running a permanent service. Where we think Dply shines is with the button https://dply.co/button which makes it easy for OSS projects and others to let people try out their services at no cost and without a high barrier to entry. If I am reading the readme.md of a project on Github and there is a button to let me deploy an instance of it and try it out on a real server for free I'd be tempted to click it. If 2 hours isn't enough I might add more time. Each paid server covers the cost of a lot of free ones.

Having the ability to add more time with Bitcoin or Alipay is also a plus for some people.


> Unless you missed the no API part. If it takes a person 5 clicks to launch an instance,

Or screen scraping. That's still a thing.


Yah. Except this is writing a script to mayyybbbbeee make a penny.

I understand hacking. I think this entire project is dead on arrival because it has no business value. He is offering to save me 2 cents at digital ocean and maybe profit if I pay 2x the DO price for a VM with less features. That is why this is a dead product.

Wringing your hands about being hacked to make $0.25 Bitcoin mining? That that is not the problem here.


You can likely use curl in a script to do it.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: